Acceptable Use Policy
- Version
- 1
- Effective date
What this policy is for
This policy sets out what may and may not be done with Atelye. It is part of the Terms of Service, so breaking a rule here is a breach of your agreement with us.
Two reasons it exists, and they are worth understanding rather than skimming:
- Messaging platforms impose rules on businesses. Instagram, Facebook and WhatsApp each decide who a business may message, when, and about what. If those rules are broken from your account, the consequence lands on your channel — and on our application, which every other customer depends on. This policy passes those rules through to you so that a platform-policy breach is also a contract breach, and so that we have a proportionate way to act before either of us loses access to a channel.
- Some things are wrong regardless of what a platform permits. Those are here too.
In this policy, "we" and "us" mean Murat Gözel trading as Atelye. "You" means the business with the account, and everyone acting through it.
Who this applies to
It applies to your organisation, to every member of your staff you give access to, to anyone acting on your behalf, and to anything done through your account — whether you did it, someone you authorised did it, or someone who got hold of your credentials did it.
You are responsible for the conduct of everyone you let into your account.
The rules that apply everywhere on the platform
Do not use Atelye to:
- break the law, or help anyone else break it;
- infringe anyone's rights — intellectual property, privacy, publicity or otherwise;
- impersonate another person, business or organisation, or misrepresent your affiliation with one;
- upload malware, or anything designed to damage, disable or gain unauthorised access to a system;
- attack the platform — probe, scan, penetration-test, overload, rate-limit-evade, scrape systematically, or attempt to reach data belonging to another customer;
- work around a technical control we put in place, including authorisation checks, quotas and the approval step before a message is sent;
- resell, sublicense or provide the platform as a service to a third party without our written agreement;
- build a competing product from it, or reverse-engineer it; or
- process data you have no right to process, including data obtained from a source that prohibited its reuse.
Rules for connected messaging channels
These apply to every message the platform sends on your behalf on Instagram, Facebook (Messenger) or WhatsApp.
Do not start conversations. Answer them.
Atelye is inbound only. It replies to people who have messaged you. You may not use it — or try to make it — to send an unsolicited first message to someone who has not contacted you.
That means no cold outreach: no messaging a list, no messaging people who gave you their number for another purpose, no "just checking in" to someone who never wrote to you. If a person has not started a conversation with your business on that channel, they are not someone the platform will message, and asking us to change that is not a feature request we will accept.
Do not broadcast or bulk-market
The messaging surface is for one-to-one conversation. You may not use it for campaigns, newsletters, promotional blasts, announcements to many recipients, or any other one-to-many messaging — whether sent at once or drip-fed to look like individual messages.
Promotional content inside a genuine conversation the customer started is a different thing and is fine, within the platforms' own rules.
Do not work around the messaging window
Each messaging platform allows a business to reply for a limited period after a customer's message, and the details differ per channel. Those windows are a rule, not an obstacle.
You may not attempt to extend, evade or reset a window by artificial means. In particular, do not provoke a customer into sending a message purely to reopen a window, and do not use a mechanism intended for one purpose to buy time for another.
If you need to reach a customer outside a window, use whatever the platform provides for that, under that platform's own approval process — not a workaround.
Do not claim a person wrote what a machine wrote
Some channels provide a way for a business to mark a message as coming from a human agent, and allow more time for a reply on that basis. That marking exists so that a real person can pick up a conversation a machine cannot handle.
It may be applied only to a message genuinely written by a person. Applying it to an AI-authored message — or configuring your account to apply it by default so that it lands on AI-authored messages — is a serious breach of this policy and of the messaging platform's rules. It misleads the platform and it misleads the customer.
Do not remove or falsify the AI disclosure
The platform tells your customers, at the start of a conversation, that AI is involved in answering them, and it keeps a path to a person open. You can change the wording and the language of that disclosure to suit your business. You cannot switch it off, and there is no configuration that will.
You may not:
- edit the disclosure so that it no longer conveys that AI is involved;
- remove or defeat the path to a human, or make it ineffective by never staffing it;
- state or imply to a customer that they are speaking to a person when an AI drafted the reply; or
- suppress or ignore an escalation the platform raises — including a customer's explicit request to speak to a person, which always goes to a human regardless of how confident the model was.
Our AI transparency notice is what your customers are pointed to. Do not contradict it.
Review before you send
Every AI-drafted reply is presented to your staff for review. Approving a batch of drafts without reading them is not review, and it does not shift responsibility for what your customer receives. What leaves the platform is your message.
Content and conduct that is not allowed
Do not send, upload, generate, store or solicit through the platform any content that:
- is unlawful where you are, where your customer is, or where the platform operates;
- harasses, threatens, bullies, defames or incites violence or hatred against a person or a group, including on the basis of race, ethnicity, national origin, religion, disability, sex, gender identity or sexual orientation;
- sexually exploits or endangers a child, in any form, ever;
- is sexual content involving adults where the channel prohibits it, or is sent to someone who has not asked for it;
- promotes self-harm, suicide or eating disorders;
- sells or promotes regulated or prohibited goods where doing so is not permitted — weapons, illegal drugs, prescription medicines outside a lawful channel, counterfeits, stolen goods, endangered species;
- is fraudulent or deceptive — phishing, false claims about a product or a price, fake reviews, bait pricing, deceptive urgency, or requests for credentials, card numbers or one-time codes;
- spreads deliberate misinformation about health, safety, elections or civic processes; or
- is spam in any form.
We do not read your conversations to police this. We act on reports, on platform notifications and on what a security or abuse investigation surfaces.
Do not put special-category data through the conversation surface
The conversation surface is not built to hold sensitive personal data, and you may not use it to collect or process it deliberately. That means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used to identify someone, data concerning health, and data concerning a person's sex life or sexual orientation.
If a customer volunteers something sensitive in a message — and sometimes they will — that is not your breach. What this rule prohibits is designing for it: asking for it, routing it here on purpose, or building a process that depends on it landing in a conversation. If your business needs to handle that kind of data, handle it somewhere built for it.
Data about criminal convictions and offences is treated the same way.
Keep your account secure
- Give each member of staff their own access. Do not share sign-in codes.
- Give people the least access their job needs.
- Remove access promptly when someone leaves.
- Keep the email addresses and phone numbers on your account current — that is how we reach you and how your staff sign in.
- Tell us at security@atelye.net as soon as you suspect a compromise.
The messaging platforms' own rules still apply
Connecting a channel means agreeing to that platform's rules as well as ours. Where their rules are stricter than this policy, theirs apply. Where they change, the change binds you from the day it takes effect, whether or not we have updated this document yet.
Nothing here permits something a messaging platform prohibits.
What happens if you breach this policy
Our response is proportionate to what happened. In rough order:
- We tell you, describe the problem, and give you a reasonable opportunity to fix it. This is what happens in most cases.
- We restrict a capability — for example the ability to send on a particular channel — while the problem is open.
- We suspend the account or part of it, under the Suspension section of the Terms of Service. Except where the risk is immediate, or where the law or a messaging platform leaves us no choice, we tell you first and give you a chance to put it right. A suspension is limited to what the problem requires and is lifted when it is resolved. Suspension does not delete anything.
- We terminate, for a material breach that is not fixed, or for one serious enough that no opportunity to fix it is appropriate.
We act immediately and without prior notice where there is a serious and immediate risk to a person, to another customer, to the security of the platform, or to our access to a messaging platform — and for child sexual exploitation content, which we act on at once and report where the law requires.
Where the law requires it, we will report conduct to the competent authority. Where a messaging platform requires it, we will act on their instruction.
We may also have to tell the messaging platform what happened. Their rules require it, and a breach on your channel is visible to them whether or not we say anything.
Reporting a problem
- Abuse of the platform, or a message you believe breached this policy — support@atelye.net
- A security vulnerability — security@atelye.net
- A privacy concern, or a request about your personal data — privacy@atelye.net
If you are a customer of a business that uses Atelye and you want your data deleted, the routes are set out at /legal/data-deletion.
Changes to this policy
We may update this policy as the platform, the law or the messaging platforms' rules change. A material change is published with a new version number and effective date, the version it replaces stays published in the archive, and business customers are notified at their registered contact address at least 30 days before it takes effect. Corrections that do not change meaning do not get a new version.