# Acceptable Use Policy Last updated: 2026-09-16 These use rules supplement the Terms for savien. ## 1. Permitted Use savien may be used for lawful B2B processes, in particular supplier and merchant coordination, orders, catalogues, shipments, documents, communication and related analytics. savien may be used only by authorised professional users within the respective company account. ## 2. Prohibited Content and Conduct The following is not permitted: - Unlawful content or conduct. - Content that infringes third-party rights, in particular copyright, trademarks, trade secrets, privacy or personality rights. - Content containing malware, phishing, fraud, spam or misleading information. - Content contributing to violence, hate, discrimination, human trafficking, illegal drugs, false documents, money laundering or other prohibited activities. - Processing special categories of personal data under Art. 9 GDPR or data under Art. 10 GDPR without appropriate legal basis, prior agreement and safeguards. - Uploading data not required for supply chain, order, delivery, support or contractual processes. - Circumventing security, access control, role, tenant-separation or rate-limit mechanisms. - Unauthorised scraping, crawling, penetration testing, load testing or automated bulk access without prior consent. - Reverse engineering or copying the platform unless mandatory law permits it. - Sharing a personal user account with other people. Everyone who uses savien needs their own account. - Reselling, renting out or otherwise making the platform available to third parties without a separate written agreement. - Storing credentials, passwords, private keys or other secrets as content in orders, comments, documents or article fields. - Processing export-controlled or sanctions-relevant technical data without prior express agreement. - Use for sanctioned persons, organisations, countries or prohibited goods/services. - Use for weapons, dual-use items, sanctioned goods or trading activities where this violates export control, sanctions or embargo rules. - Use that endangers other customers' rights, platform security or savien availability. ## 3. Customer Content, Product Information and Documents Customers are responsible for the accuracy, lawfulness and currentness of their content, including in particular: - Product, price, tax, customs, origin, sustainability and delivery information. - Catalogues, orders, invoice and delivery documents. - Comments, attachments, product images and other files. - Data imported or synchronised through integrations such as BillBee. savien does not generally review this information and assumes no responsibility for the customer's product, tax, customs or trade compliance. ## 4. Invitations to Business Contacts Invitations are a transactional tool for initiating a specific business relationship. They are not a marketing channel. The following is not permitted: - Unsolicited bulk invitations, mailing lists, or purchased or scraped address sets. - Referral, recommendation or reach campaigns using the invitation function. - Repeated invitations to the same address after it has gone unaccepted or been declined, or where an objection has been raised. - Invitations to private email addresses without a business context. By sending an invitation, the inviting organisation confirms that it obtained the address lawfully and that the business contact is permitted. The invited person receives the information required under Art. 14 GDPR with the first message and can decline further reminders at any time. Invitations that are not accepted are deleted after they expire. savien limits the number of reminders technically and may restrict the invitation function in case of misuse. ## 5. Data and System Protection Customers must take appropriate measures to protect user accounts, credentials, API access and connected third-party accounts. This includes in particular: - strong and non-reused passwords, - MFA use where available, - timely deactivation of departing users, - role-based access on a need-to-know basis, - secure storage of API keys and third-party credentials. Suspected misuse or security incidents must be reported without undue delay to `security@savien.io`. ## 6. DSA and Abuse Reports Legal violations, illegal content or abuse may be reported to: security@savien.io support@savien.io For DSA-relevant reports, the [DSA contact and reporting channel](/en/dsa) also applies. ## 7. Security Research and Responsible Disclosure We welcome reports of security vulnerabilities. Anyone who investigates and reports a vulnerability in good faith under the rules below need not fear civil or criminal action by savien, or account suspension, because of that investigation. We will not treat such reports as a breach of these use rules. This assurance applies as long as the research: - concerns only your own accounts and your own test data, - does not access, alter, exfiltrate or publish other customers' data, - does not impair availability, in particular no load tests, DoS tests or spam tests, - involves no social engineering against staff, customers or service providers, - involves no physical attacks on infrastructure, - reports the vulnerability without undue delay and exclusively to `security@savien.io`, and - allows us a reasonable period to remediate before details are published. We acknowledge receipt of a report within five business days and keep the reporter informed of progress. Testing beyond this scope remains prohibited under section 2. Third-party rights and mandatory statutory requirements are unaffected; this assurance can only bind savien itself. Technical contact details are additionally published at `/.well-known/security.txt`. ## 8. Enforcement In case of violations, we may remove content, restrict access, suspend accounts, deactivate integrations, notify customers or terminate the contract for cause. We choose measures proportionately, considering severity, recurrence risk, impact, legal obligations and the legitimate interests of the parties involved. Where possible and legally permissible, we proceed in this order: 1. Notice of the violation with an opportunity to remedy it within a reasonable period. 2. A targeted measure limited to the specific content or function concerned. 3. Broader restriction or suspension only where less intrusive means are insufficient. When removing, restricting or suspending, we inform the affected organisation of: - the specific grounds and the content or functions concerned, - the contractual or legal basis relied on, - the scope and expected duration of the measure, - whether the decision was made by automated means, and - how to appeal. An appeal can be sent informally to `support@savien.io`. It is reviewed by a person who was not involved in the original decision, and we normally respond within ten business days. If a measure turns out to be unfounded, we lift it and restore the affected content and functions as far as this is still technically possible. While an account is suspended, we enable the customer to export their data under section 13 of the Terms, unless statutory obligations, third-party rights or an acute security incident prevent this. Immediate action without prior notice remains permissible where necessary to avert an acute security risk, to comply with a legal obligation or to prevent significant harm. In that case we provide the notice described above without undue delay. Where legally or technically required, we may preserve evidence, notify authorities or inform affected third parties. ## 9. Version of These Rules These use rules form part of the contract. The version applicable at the time of contract acceptance is recorded with document ID, version and content hash together with acceptance of the Terms.