ACCEPTABLE USE POLICY
This Acceptable Use Policy (“AUP”) forms part of the Master Service Agreement and applies to the use of VENTA Xploro POS, VENTA Admin, VENTA Insights, VENTA Captain, Xploro AI, related VENTA applications, APIs, dashboards, integrations, support systems, and future VENTA-branded services (collectively, the “Services”).
The Services are provided by XploroTech Solutions Private Limited (“XploroTech”, “Company”, “we”, “us”, or “our”).
This AUP applies to every Customer, Authorised User, administrator, employee, cashier, captain, manager, consultant, contractor, integration partner, API user, and any other person accessing or using the Services through a Customer account.
Capitalised terms not defined in this AUP have the meanings given in the Master Service Agreement.
1. Purpose
VENTA is designed to support legitimate business operations, including point-of-sale billing, order management, reservations, inventory, membership, loyalty, reporting, analytics, support, and related business processes.
This AUP protects the security, reliability, legal integrity, auditability, and lawful use of the Services.
The Customer and all Authorised Users must use the Services honestly, lawfully, responsibly, and only for authorised business purposes.
2. General Rules
You must not use, attempt to use, or permit another person to use the Services in a way that:
a. violates applicable law, regulation, tax requirement, court order, contractual obligation, or third-party right;
b. causes or may cause harm, loss, fraud, security risk, disruption, reputational damage, or legal risk to XploroTech, the Customer, another user, or a third party;
c. interferes with the security, availability, performance, integrity, or normal operation of the Services;
d. accesses or attempts to access data, accounts, reports, modules, APIs, systems, or information beyond the permissions assigned to you; or
e. violates the Master Service Agreement, Data Processing Addendum, VENTA User Terms, Xploro AI Addendum, Privacy Notice, or any other applicable VENTA policy.
3. Billing, Revenue, GST and Statutory Record Integrity
3.1 You must use billing, order, invoice, payment, discount, refund, void, cancellation, credit, inventory, loyalty, membership, reservation, and reporting features only through authorised and auditable workflows.
3.2 You must not use the Services to:
a. evade GST, tax, duties, levies, statutory obligations, or lawful reporting requirements;
b. suppress revenue, conceal sales, understate turnover, create false invoices, create duplicate invoices, generate fictitious transactions, or misrepresent business activity;
c. delete, alter, backdate, manipulate, conceal, or falsify statutory records, invoices, payments, refunds, voids, discounts, cancellations, inventory records, membership balances, loyalty transactions, or transaction history;
d. create false refunds, false discounts, sham cancellations, artificial voids, fictitious stock adjustments, false expense records, or deceptive audit trails;
e. use another user’s credentials or elevated permissions to perform unauthorised financial, billing, tax, inventory, or transaction-related actions;
f. misuse customer, supplier, employee, vendor, payment, or operational data for any unlawful purpose; or
g. assist, encourage, advise, or enable another person to carry out any prohibited activity.
3.3 VENTA does not provide a mechanism to suppress statutory records or evade tax obligations.
3.4 The Customer remains solely responsible for its GST configuration, tax classification, tax rates, invoice content, statutory records, accounting treatment, tax filings, business approvals, and legal compliance.
3.5 XploroTech is a software provider only and does not provide tax, accounting, legal, financial, or regulatory advice.
4. User Access, Credentials and Permissions
4.1 Each user must use only their own authorised account, password, PIN, authentication method, access token, device session, or login credentials.
4.2 You must not:
a. share, transfer, disclose, sell, lend, rent, or permit use of your credentials by another person;
b. use another person’s account, credentials, session, device, or access token without express authorisation through approved VENTA user-management controls;
c. impersonate another user, administrator, Customer, employee, outlet, vendor, or third party;
d. create false accounts, false identities, fake outlets, fake users, or unauthorised access profiles;
e. bypass, alter, disable, interfere with, or attempt to defeat password controls, role permissions, multi-factor authentication, session restrictions, device restrictions, audit logs, subscription restrictions, or other access controls;
f. access or attempt to access another Customer’s data, account, system, reports, tenant, outlet, or confidential information; or
g. retain access after your employment, engagement, authorisation, or relationship with the Customer has ended.
4.3 The Customer must promptly remove or restrict access for users who no longer require access to the Services.
5. Data Protection and Confidential Information
5.1 You must handle Customer Data, Personal Data, reports, invoices, business information, credentials, support information, and confidential information only for authorised business purposes.
5.2 You must not:
a. collect, upload, disclose, export, sell, share, copy, transmit, publish, or use Personal Data or confidential information without proper authority;
b. access personal, customer, employee, vendor, payment, reservation, loyalty, invoice, operational, or business data beyond what is necessary for your assigned role;
c. submit Personal Data that you are not authorised to collect, use, store, or disclose;
d. use the Services to conduct unlawful surveillance, stalking, profiling, harassment, discrimination, or unauthorised monitoring;
e. disclose confidential or commercially sensitive information to unauthorised persons; or
f. use Customer Data for personal gain, unauthorised marketing, unrelated commercial activity, or any unlawful purpose.
5.3 You must not submit, upload, store, or transmit through the Services:
a. passwords, OTPs, PINs, access tokens, private keys, API keys, secrets, or authentication credentials;
b. full payment-card numbers, CVV, magnetic-stripe data, or other sensitive payment-authentication data;
c. malware, ransomware, spyware, keyloggers, phishing tools, malicious scripts, or harmful files;
d. unlawful, infringing, defamatory, discriminatory, abusive, exploitative, or deceptive content; or
e. data that you are prohibited from sharing by law, contract, confidentiality obligation, or privacy obligation.
6. Security and Technical Restrictions
6.1 You must not:
a. probe, scan, test, or attempt to exploit vulnerabilities in the Services without XploroTech’s prior written approval;
b. perform unauthorised penetration testing, load testing, stress testing, denial-of-service activity, brute-force attacks, credential stuffing, scraping, crawling, or automated extraction;
c. introduce malicious code, viruses, worms, ransomware, spyware, bots, or harmful scripts;
d. interfere with, disrupt, overload, damage, disable, or degrade the Services, connected networks, servers, APIs, databases, devices, or third-party services;
e. reverse engineer, decompile, disassemble, copy, scrape, modify, alter, translate, create derivative works from, or attempt to discover the source code, model logic, system prompts, security controls, databases, or underlying technology of the Services, except where expressly permitted by applicable law;
f. remove, obscure, or alter copyright notices, trademarks, security labels, proprietary notices, or usage restrictions;
g. use unauthorised third-party tools, scripts, extensions, bots, emulators, or automated methods to access or interact with the Services; or
h. use the Services to build, train, operate, or support a competing product using unauthorised extraction of VENTA content, data, workflows, interfaces, Documentation, or system behaviour.
6.2 Security researchers who identify a potential vulnerability must report it responsibly to [SECURITY INCIDENT EMAIL] and must not publicly disclose, exploit, retain, or misuse the vulnerability without XploroTech’s prior written permission.
7. Xploro AI Acceptable Use Rules
7.1 Where enabled, Xploro AI may be used only for authorised business purposes, including reporting, analytics, support, help articles, troubleshooting, bug analysis, code or schema analysis, and related permitted activities.
7.2 You must not use Xploro AI to:
a. evade tax, suppress revenue, create fraudulent invoices, generate false reports, conceal statutory records, manipulate financial data, or misrepresent business activity;
b. generate or deploy harmful, unlawful, deceptive, discriminatory, defamatory, abusive, infringing, or fraudulent content;
c. access, infer, extract, summarise, reveal, or attempt to obtain data that you are not authorised to access;
d. attempt prompt injection, jailbreaks, model manipulation, instruction override, data exfiltration, privilege escalation, or circumvention of AI permissions, tenant isolation, security controls, or system safeguards;
e. request, generate, or use instructions intended to bypass access controls, compromise systems, obtain credentials, exploit vulnerabilities, distribute malware, or perform unauthorised security testing;
f. submit passwords, OTPs, PINs, payment-card data, API keys, private keys, source-code secrets, confidential credentials, or any data you are not authorised to provide;
g. submit unnecessary Personal Data, confidential information, or third-party information where a less sensitive or redacted input would reasonably serve the authorised purpose;
h. use AI output as the sole basis for tax, legal, accounting, financial, employment, regulatory, medical, or other professional decisions;
i. rely on AI output without appropriate human review and validation; or
j. use AI Services to impersonate a person, create deceptive communications, generate false evidence, or mislead customers, employees, regulators, auditors, or third parties.
7.3 AI-generated reports, answers, recommendations, forecasts, SQL, code suggestions, troubleshooting guidance, and business insights may be inaccurate, incomplete, outdated, biased, or unsuitable for a particular purpose.
7.4 You must review and validate all material AI outputs before relying on, sharing, filing, implementing, or deploying them.
7.5 You must not directly deploy AI-suggested code, SQL, database changes, configuration changes, workflow changes, or bug fixes to a production environment without appropriate human review, testing, authorisation, change logging, and rollback capability.
7.6 Xploro AI must not be used as the sole basis for modifying statutory invoices, GST records, payment records, financial ledgers, membership balances, inventory balances, transaction history, or other controlled business records.
8. API, Integration and Third-Party Use
8.1 Where the Services include APIs, integrations, webhooks, import tools, export tools, or third-party connections, you must use them only as authorised by the Customer and XploroTech.
8.2 You must not:
a. connect unauthorised applications, scripts, devices, or systems to VENTA;
b. use an API key, integration token, webhook, or connection belonging to another Customer or third party without authority;
c. use integrations to extract, alter, duplicate, suppress, or manipulate business records outside approved workflows;
d. create excessive, disruptive, abusive, or automated API calls;
e. use integrations to send spam, unlawful marketing, deceptive communications, or unsolicited messages; or
f. misuse third-party payment, delivery, accounting, messaging, AI, hardware, or cloud integrations.
8.3 Third-party services may have their own terms, limitations, charges, and privacy practices. The Customer is responsible for ensuring it has authority to connect and use those services.
9. Fair Use and Platform Protection
9.1 You must use the Services in a manner consistent with the subscription plan, purchased modules, licensed users, terminals, outlets, devices, API limits, storage limits, and other agreed commercial restrictions.
9.2 You must not:
a. circumvent subscription limits, user limits, terminal limits, location limits, device limits, API limits, storage limits, or licence restrictions;
b. share one subscription across multiple unrelated legal entities, businesses, outlets, or locations unless expressly permitted by XploroTech;
c. resell, sublicense, rent, lease, distribute, or commercially exploit the Services without XploroTech’s prior written consent; or
d. use the Services for high-risk, unlawful, or inappropriate purposes not reasonably intended by the Services.
10. Reporting Security Issues and Policy Violations
10.1 You must promptly report suspected:
a. unauthorised access or credential compromise;
b. data loss, Personal Data Breach, accidental disclosure, or unauthorised sharing;
c. fraud, misuse, tax evasion, revenue suppression, record manipulation, or suspicious transaction activity;
d. malware, ransomware, phishing, vulnerability, or cyberattack;
e. misuse of Xploro AI or suspected AI data exposure; or
f. breach of this AUP.
10.2 Reports may be made to:
Support: xplorocare@xplorotech.com
Security Incident Reporting: xploro@xplorotech.com
Privacy / Data Protection: xploro@xplorotech.com
Legal / Compliance: xploro@xplorotech.com
10.3 You must preserve relevant information and cooperate reasonably with the Customer and XploroTech during an investigation.
10.4 You must not knowingly make false, malicious, misleading, or retaliatory reports.
11. Monitoring, Investigation and Enforcement
11.1 To protect the Services, customers, users, and third parties, XploroTech may monitor, review, preserve, analyse, and investigate activity, logs, audit trails, access records, diagnostic records, security records, AI interactions, API activity, and other information processed through the Services, subject to applicable law and the Privacy Notice.
11.2 Where XploroTech reasonably believes that this AUP has been breached, XploroTech may take one or more actions, including:
a. issuing a warning;
b. requiring corrective action;
c. restricting access to a feature, module, integration, API, user account, device, or outlet;
d. removing or disabling harmful content, data, scripts, files, integrations, or access rights;
e. suspending or terminating access to the Services;
f. preserving logs, evidence, and relevant information;
g. notifying the Customer, affected parties, insurers, service providers, regulators, law-enforcement bodies, or lawful authorities where required or reasonably necessary;
h. taking legal action; or
i. taking any other reasonable action necessary to protect the Services, XploroTech, Customers, users, or third parties.
11.3 XploroTech may take immediate action without prior notice where delay could create a security, fraud, legal, financial, regulatory, operational, or safety risk.
11.4 Enforcement under this AUP does not limit any other rights or remedies available to XploroTech under the Master Service Agreement, applicable law, or equity.
12. Customer Responsibility
12.1 The Customer is responsible for ensuring that its Authorised Users comply with this AUP.
12.2 The Customer must establish appropriate internal controls for user access, discounts, refunds, cancellations, voids, billing changes, inventory adjustments, financial approvals, reporting access, AI use, and data access.
12.3 The Customer must promptly revoke access for former employees, contractors, consultants, and users who no longer require access.
12.4 The Customer is responsible for investigating and addressing misuse by its Authorised Users and cooperating with XploroTech where reasonably necessary.
13. Changes to this Policy
13.1 XploroTech may update this AUP from time to time to reflect legal, regulatory, security, technical, operational, product, or business changes.
13.2 Material updates may be notified through the VENTA Legal Centre, the Services, dashboard, email, or another reasonable electronic method.
13.3 Continued use of the Services after an updated AUP becomes effective constitutes acceptance of the updated policy, except where express re-acceptance is required by applicable law or XploroTech.
14. Contact
For questions about this AUP, contact:
Support: xplorocare@xplorotech.com
Security Incident Reporting: xploro@xplorotech.com
Privacy / Grievance Contact: xploro@xplorotech.com
Legal Notices: xploro@xplorotech.com
VENTA Legal Centre: https://www.venta-pos.com/legal


