Note: The Portuguese version is the legally binding version.
Acceptable Use Policy (AUP)
Version 3.0 — Effective as of August 10, 2026
1. Scope
This Acceptable Use Policy ("AUP") applies to all users of the ChatSense platform, operated by VertexHub do Brasil Ltda, including administrators, human agents, and authorized integrators using the platform's APIs.
This AUP supplements the platform's Terms of Service and shall be interpreted in conjunction therewith. In the event of a conflict, the more restrictive provisions shall prevail.
Violations of this Policy may result in suspension or termination of the account, as detailed in Section 7 (Enforcement and Consequences).
2. Prohibited Content
It is expressly prohibited to create, transmit, store, or distribute through the ChatSense platform any content that contains or promotes:
- Hate speech, incitement to violence, harassment, or bullying — Any content that promotes hatred, discrimination, intimidation, or violence against individuals or groups
- Spam and unsolicited bulk messages — Sending commercial or promotional communications without prior consent from recipients
- Malware, phishing, and social engineering — Distribution of malicious software, fraudulent links, or attempts to deceptively obtain personal information
- Copyright or intellectual property infringement — Content that infringes on copyrights, trademarks, patents, or trade secrets of third parties
- Child sexual abuse material — Any material involving the sexual exploitation of minors, in compliance with the Brazilian Statute of the Child and Adolescent (ECA, Law 8,069/1990)
- Illegal content — Any material that violates Brazilian law or the law of the country to which the communication is destined
- Illegal products and services — Sale or promotion of illicit drugs, weapons, contraband, or any products whose commercialization is prohibited by law
- Third-party personal data without consent — Sharing, disclosure, or processing of third-party personal data without an adequate legal basis or consent from the data subject
3. Prohibited Activities
The following activities are strictly prohibited on the ChatSense platform:
- API abuse — Attempts to circumvent rate limits, automated scraping, or abusive use of API endpoints
- Reverse engineering — Decompilation, disassembly, or any attempt to discover the source code, algorithms, or data structures of the platform
- Unauthorized data access — Attempts to access, view, or manipulate data belonging to other organizations (multi-tenant isolation)
- Unauthorized load testing — Conducting benchmarks, stress tests, or load tests without prior written authorization from ChatSense
- Credential sharing — Sharing API keys, passwords, access tokens, or any authentication credentials with unauthorized third parties
- Fraudulent activities — Use of the platform to conduct fraud, scams, pyramid schemes, or any fraudulent activity
- Data mining — Systematic extraction of data from the platform for creation of competing databases or for any unauthorized purpose
- Benchmark disclosure — Public publication or disclosure of platform performance benchmarks without prior written authorization
4. Per-Channel Communication Rules
4.1 WhatsApp
- Comply with the 24-hour window for session messages
- Use only Meta-approved HSM templates for messages outside the 24-hour window
- Maintain documented opt-in from the contact before initiating conversations
- Fully comply with the WhatsApp Business Policy and the WhatsApp Commerce Policy
4.2 Instagram and Messenger
- Fully comply with the Meta Platform Policy
- Do not send promotional messages without prior opt-in from the recipient
4.3 Webchat (widget)
- Install the chat widget only on domains owned by the user and declared in the platform configuration (authorized domains)
- Do not use the widget to collect visitors' personal data without an adequate privacy notice on the website where it is embedded
4.4 Telegram
- Fully comply with the Telegram Bot API Terms of Service
- Do not send unsolicited messages to users who have not started a conversation with the bot or consented to receive them
4.5 AI Voice Calls
- Obtain the recipient's prior consent to receive automated calls
- Identify, at the start of the call, that the caller is an Artificial Intelligence system
- Inform the recipient of any recording of the call
- Respect national and state telemarketing do-not-call registries (e.g., Brazil's "Não Me Perturbe") and reasonable contact hours
4.6 Email
- CAN-SPAM compliance — Legitimate and verifiable "From" header, non-deceptive subject line, functional unsubscribe mechanism, and honor opt-outs within 10 business days
- LGPD — Regardless of any other legal bases that may apply (art. 7, Law 13,709/2018), this platform requires, as a condition of use, the data subject's prior and documented consent for sending marketing communications
5. Campaign Rules
When using the ChatSense campaign module, the user must:
- Prior consent — Obtain prior and documented consent (opt-in) from all recipients before sending any campaign
- Unsubscribe mechanism — Include a functional and accessible unsubscribe (opt-out) mechanism in all communications
- Honor opt-outs — Process and honor opt-out lists immediately, without delay
- Frequency limits — Do not exceed reasonable frequency limits to avoid recipient fatigue
- TCPA compliance (U.S.) — For campaigns targeting the United States, do not send messages to numbers registered on the Do Not Call Registry
- Do-not-call registries (Brazil) — Respect national and state telemarketing do-not-call registries (e.g., "Não Me Perturbe" and the Procon lists), where applicable to the channel used
- CAN-SPAM compliance — Fully comply with the requirements of the CAN-SPAM Act for email campaigns
- LGPD (Brazil) — Regardless of any other legal bases that may apply (Law 13,709/2018, art. 7), this platform requires, as a condition of use of the campaign module, the data subject's prior and documented consent (opt-in) for marketing communications
- GDPR (European Union) — Comply with art. 6(1)(a) of EU Regulation 2016/679, obtaining valid data subject consent
- Consent records — Maintain complete consent (opt-in) records for auditing and regulatory compliance purposes
6. AI Agent Rules
When configuring and using Artificial Intelligence agents on the platform, the user must observe the following rules:
- Transparency — Inform end customers that they are interacting with an Artificial Intelligence system, not a human being
- Security guardrails — Keep security guardrails enabled, especially
no_discrimination,no_medical_diagnosis, andno_financial_advice - Regulated sectors — Do not disable security guardrails for use in regulated sectors (healthcare, financial, legal)
- Human escalation — Keep the human escalation system enabled to ensure intervention when necessary
- Impersonation — Do not use AI agents to impersonate real persons, authorities, or institutions
- Deceptive content — Do not use AI agents to generate deceptive content, misinformation, or deepfakes
- Periodic review — Periodically review the responses and behavior of AI agents to ensure quality and compliance
- Responsible system prompts — Configure system prompts responsibly, without instructions that encourage or enable violations of this AUP
7. Enforcement and Consequences
ChatSense adopts a progressive enforcement approach for violations of this Acceptable Use Policy, according to the following levels:
7.1 Enforcement Levels
- (a) Notification — Email notification sent to the account holder, describing the identified violation and granting a period of 7 (seven) days for remediation
- (b) Temporary limitation — Application of throttling or temporary limitation of specific platform features
- (c) Suspension — Account suspension for a period of up to 30 (thirty) days
- (d) Immediate termination — Immediate termination of the agreement, without prior notice, for severe violations, including: illegal content, child sexual abuse material (CSAM), proven fraud, or threats to platform security
7.2 Reporting to Authorities
ChatSense may report to the competent authorities facts that constitute a crime or a threat to public safety, and may make available records and content of communications pursuant to a court order, under art. 10, paragraphs 1 and 2, of Law 12,965/2014 (Marco Civil da Internet) — subject to the retention duty of art. 15 — and art. 7, II, of Law 13,709/2018 (LGPD). Every disclosure made pursuant to a court order is recorded in an immutable audit trail.
7.3 Reporting Channel
To report violations of this Acceptable Use Policy or to report abuse on the platform, please contact:
Abuse report email: vertexhub@vertexhub.ai
Contact
For questions regarding this Acceptable Use Policy:
ChatSense — VertexHub do Brasil Ltda
General email: vertexhub@vertexhub.ai
Abuse reports: vertexhub@vertexhub.ai
Data Protection Officer (DPO): vertexhub@vertexhub.ai