Last updated: 14 July 2026
This Acceptable Use Policy (“AUP”) forms part of the Terms of Service. It applies to every person who accesses, submits to, integrates with, or uses the Services.
1. Use the Services only as intended
Use only the features, accounts, data, and permissions made available to you. Follow applicable law, professional duties, published instructions, robots controls, provider rules, and any written mandate or authorisation. Do not attempt to reach administrative, private, staging, internal, or restricted information without permission.
2. Illegal, fraudulent, or harmful activity
You must not use the Services to commit, encourage, facilitate, or conceal fraud, theft, money laundering, corruption, unlawful discrimination, harassment, threats, exploitation, deceptive property marketing, rights violations, or another unlawful or harmful act. Do not impersonate a person, agent, owner, company, regulator, or service provider.
3. Property and submitted content
Do not submit a property, photograph, document, review, price, location, owner or seller detail, mandate, or claim that you know is false, materially misleading, confidential without authority, unlawfully discriminatory, defamatory, infringing, or unsafe. Do not expose exact locations, identity records, access instructions, or private operational notes unless the intended restricted workflow requires them and you are authorised.
4. Privacy and communications
Do not collect, export, disclose, sell, profile, message, or otherwise use another person’s information without a lawful basis and appropriate authority. Do not send spam, bulk unsolicited messages, deceptive promotions, or repeated communications after a valid opt-out. Follow the Privacy Policy and channel-specific consent requirements.
5. Security and service integrity
You must not:
- upload malware, malicious scripts, destructive files, or code intended to monitor or interfere with another party;
- probe, scan, bypass, disable, or defeat authentication, rate limits, access controls, logging, content protections, or security measures;
- overload, flood, disrupt, degrade, or impose unreasonable load on the Services or connected providers;
- use stolen credentials, share restricted tokens, or retain credentials after authority ends;
- alter headers, identifiers, logs, or source information to conceal origin or activity; or
- assist another person to do any of the above.
6. Automated access and extraction
Do not scrape, crawl, harvest, mirror, bulk-download, aggregate, train on, or systematically query the Services except through an expressly provided feed or API, under written permission, or as allowed by applicable law and published technical controls. Approved automation must use bounded request rates, identify itself where requested, respect cache and retry guidance, and stop when permission is revoked.
7. Enforcement and reporting
We may investigate, preserve evidence, remove content, restrict features, suspend access, revoke credentials, notify affected providers or authorities, and take legal action where reasonably necessary. Where appropriate, we will consider severity, repetition, intent, risk, and whether the issue can be corrected. Report suspected misuse to ntando@boxandatlas.com.