Legal
Acceptable use policy.
This policy sets the rules for the systems we run for clients. A website, a booking system, an assistant and an automation are all covered. The rules keep those systems safe for the people who use them.
Effective date: 13 August 2026.
Who this policy covers.
This policy applies to every system we host or operate. It applies whether we built the system or took it over.
The policy covers our client. The policy also covers the client’s own staff. The policy covers the client’s customers who use the system.
A client is responsible for everyone the client gives access to. Please pass these rules on to them.
What may not be done on our systems.
Unlawful use. Do not use a system we run to break the law. That covers unlawful content and unlawful activity.
Other people’s rights. Do not publish work that belongs to someone else. Photos, writing, music, video and trade marks all belong to someone.
Harm to people. Do not use a system to harass or threaten anyone. Hate speech is not allowed either.
Harmful code. Do not upload or send harmful code. Viruses, ransomware and hidden scripts are all harmful code.
Attacks. Do not try to break into a system. Do not try to overload a system, or the network it runs on.
Bulk messages. Do not send bulk messages to people who never asked for them. The next section covers marketing in more detail.
Scraping. Do not harvest personal details from a system. Collecting names, numbers or addresses in bulk is not allowed.
Someone else’s login. Use your own login. Do not share a login, and do not use an account that belongs to another person.
Marketing messages have their own rules.
We build WhatsApp and email systems, so this part matters. South African law is clear about marketing sent by electronic message.
Send marketing only to people who asked for it. Making a booking is not the same as asking for marketing.
Every marketing message needs an easy way to stop. Act on a stop request straight away, and keep that person off the list.
A booking channel is for bookings. Do not use a booking number or a booking inbox to send adverts.
Section 69 of POPIA covers direct marketing sent by electronic message. POPIA is the Protection of Personal Information Act 4 of 2013.
Section 45 of ECTA covers unsolicited commercial messages. ECTA is the Electronic Communications and Transactions Act 25 of 2002.
Keep a record of who agreed to marketing, and when. We will ask for that record if somebody complains.
Personal information needs a lawful reason.
A system we build may collect personal details from your customers. You need a lawful reason to collect each of those details.
Section 11 of POPIA lists the reasons that count. Consent, a contract and a legal duty are three of them.
Some information carries extra risk. Health, religion, race, politics, trade union membership and criminal records are the usual examples.
POPIA sets a higher bar for that kind of information. Do not put it into a system we run without telling us first.
A child’s information needs a proper basis as well. Sections 34 and 35 of POPIA cover a child’s information.
Talk to us before a system starts collecting any of this. We will go through the design with you.
Shared resources stay fair.
Hosting is shared. Heavy use by one system slows the service down for others.
Do not run a task that harms performance for other users. Do not mine cryptocurrency on our hosting.
Do not use hosting as a general file store. Hosting is for the site, and for the system that runs on it.
Expecting a busy period, or a large upload? Tell us first, and we will plan for it.
What we do if this policy is broken.
We would rather fix a problem than switch a system off. So we contact the client first.
We explain what we found. We then agree a fix, and a sensible time to do it in.
We act at once, without notice, in two cases only. The first case is where the law requires it.
The second case is where people face immediate risk. A live attack, or exposed personal details, are examples.
Any step we take stays as small as the problem allows. Suspending a system is a last resort, not a first move.
We put the service back to normal once the problem is sorted out.
How to report misuse.
Seen something wrong on a system we run? Email hello@trevern.com.
Tell us what you saw, and where you saw it. A link, a screenshot and a date help us act faster.
Found a security problem instead? Our security page explains how to report one.
This document explains how we work. It is not legal advice, and it does not replace advice from your own attorney.
Not sure how this applies to you.
Every setup is different. A short call is the quickest way to check these rules against your own systems.
Buying on behalf of a group? We are happy to take your team through this policy line by line.
Book a free callFree call · no obligation · one fixed quote in writing