SM Sabeemod
Access workspace
Legal

Acceptable Use Policy

Last updated 12 August 2026. This Acceptable Use Policy ("AUP") is part of the Terms of Service and applies to every Customer, workspace user and API integration.

1. Purpose

This AUP protects the integrity of the Sabeemod platform, the security of every Customer's data and the reputation of the wider SabeeApp ecosystem. It is written in plain English on purpose: enforcement should not depend on an exotic reading of a clause. If a course of conduct feels wrong to a reasonable hospitality professional, it almost certainly falls foul of this AUP even if it is not spelled out below.

2. Fair use of the API

Every module in the boutique consumes a share of Sabeemod's own API quota with SabeeApp. The Customer agrees to use the modules for their intended purpose and not for high-frequency data scraping unrelated to hospitality operations. Concretely: no more than sixty (60) full-property sync requests per hour, no more than three hundred (300) reservation-detail requests per minute, no more than one hundred (100) parallel connections per Customer. These limits are generous for real-world operations and are enforced at the platform level. If your operation genuinely needs a higher ceiling, contact us at /contact and we will provision a dedicated quota.

3. Security posture required from the Customer

The Customer agrees to keep its workspace credentials confidential, to enforce multi-factor authentication for every workspace user with an administrator role, to review the list of workspace users every ninety (90) days, and to revoke access promptly when a person leaves the organisation. The Customer agrees to notify Sabeemod within twenty-four (24) hours of any suspected compromise of a workspace account or of the SabeeApp API token associated with a Customer's account.

4. Prohibited activities

The following activities are prohibited without exception: reverse-engineering, decompiling or disassembling any module or any part of the workspace application; probing, scanning or testing the vulnerability of the platform without prior written authorisation under a bug-bounty programme; interfering with or disrupting the service, servers or networks connected to the service; introducing viruses, worms, trojan horses or any other malicious code into the workspace or its API; using the service to send unsolicited commercial communications ("spam") to guests, staff or third parties; using the service to process personal data for a purpose that is unlawful, that violates public order, or that would offend human dignity; using the service to store or transmit content that infringes third-party intellectual property rights.

5. Content responsibility

The Customer is solely responsible for the content it stores, processes or transmits through the service. Sabeemod does not pre-screen content and does not monitor content on a routine basis, but reserves the right to remove content that is manifestly unlawful upon notice from a rights holder or from a competent authority, subject to the procedures set out in Regulation (EU) 2022/2065 (Digital Services Act) where that regulation is applicable.

6. Sub-users

The Customer is responsible for the acts and omissions of every workspace user, sub-contractor and agent that it grants access to its workspace. In particular, the Customer must ensure that any sub-contractor or agent is bound by contractual obligations at least as strict as those set out in this AUP.

7. Communication with guests

Where a module sends communications to guests on behalf of the Customer (for example, post-stay review requests through Review Radar, or pre-arrival identity verification requests through Identity Verification), the Customer is responsible for ensuring that the underlying consent basis is valid, that the recipient has a genuine relationship with the Customer property, that the unsubscribe mechanism is functional and that the communication complies with local law (in particular Directive 2002/58/EC on ePrivacy and any national implementation). Sabeemod will not knowingly facilitate a communication that is manifestly unlawful.

8. Suspension for cause

Sabeemod reserves the right to suspend, with or without prior notice depending on urgency, any workspace or any specific module use that is causing an ongoing security incident, that is violating this AUP in a manner that risks harm to the platform or to third parties, or that is subject to an urgent order from a competent authority. Where prior notice is possible without amplifying the risk, Sabeemod will give the Customer a reasonable opportunity to remedy the situation before suspension.

9. Report an incident

Suspected security incidents, suspected abuse or suspected AUP violations can be reported to abuse@sabeemod.org. Reports are acknowledged within one (1) business day and triaged within three (3) business days. Reports made in good faith are treated confidentially; the identity of the reporter is not disclosed to the reported party without the reporter's prior consent.

10. Coordinated vulnerability disclosure

Sabeemod welcomes reports of security vulnerabilities in the platform. Reports can be sent to security@sabeemod.org, encrypted with the PGP key published on the /security-whitepaper page. Researchers acting in good faith and respecting the disclosure guidelines set out on that page will not be pursued under Montenegrin computer-misuse legislation. A public acknowledgement in the Hall of Fame section of the security whitepaper is offered on request.

11. Consequences of non-compliance

Non-compliance with this AUP may lead to a range of consequences proportionate to the severity of the incident: warning, temporary rate-limit reduction, temporary suspension of a specific module, temporary suspension of the entire workspace, termination of the affected module subscription, termination of the entire contract for cause. Sabeemod will always favour the least intrusive measure that adequately protects the platform and the Customer's peers.

12. Right of appeal

A Customer whose workspace has been suspended may lodge an appeal to appeals@sabeemod.org within seven (7) calendar days of the suspension. The appeal is reviewed by the Director of Sabeemod together with the Security team, and a written second-level decision is delivered within seven (7) business days.

13. Changes to this AUP

Sabeemod may update this AUP from time to time. Material changes are notified by email to the billing contact of each active Customer at least fifteen (15) days before entry into force. Continued use of the service after the effective date constitutes acceptance of the amended AUP.

14. Governing law and jurisdiction

This AUP is governed by the same law and subject to the same jurisdiction clauses as the Terms of Service.

15. Contact

All inquiries about this AUP should be sent to support@sabeemod.org. Security-sensitive inquiries and vulnerability reports should be sent to security@sabeemod.org (PGP encouraged). Abuse reports should be sent to abuse@sabeemod.org.