Belvara

Legal

Acceptable Use Policy

The rules that govern responsible use of Belvara products, services, websites, applications and integrations.

Last updated: 5 October 2026 Version 1.0

Use Belvara well

A quick summary of the rules. The Acceptable Use Policy below contains the complete legal terms.

Use Belvara responsibly

Use the Services for lawful business activity and respect other Customers.

No fraud or abuse

Fraud, scams, malicious activity and attempts to bypass controls are prohibited.

Protect access

Keep credentials secure, configure permissions carefully and report vulnerabilities.

Enforcement may follow

Belvara may restrict, suspend or terminate activity that creates material risk.

Responsible use

Belvara is built for legitimate business operations. You are responsible for activity through your account, Authorised Users, integrations, API credentials and connected devices.

BELVARA ACCEPTABLE USE POLICY

1.Purpose

Belvara is designed to help legitimate businesses operate, sell, manage inventory, communicate with customers, manage payments, fulfil orders, use business tools and make better business decisions. You must not use Belvara in a way that violates law, harms another person, compromises security, abuses Belvara’s infrastructure, facilitates fraud or deception, infringes another person’s rights, interferes with another Customer, circumvents product restrictions, exploits free trials or account limits, misuses Customer Data, abuses communications functionality or materially interferes with Belvara’s ability to provide the Services.

2.Customer Responsibility

You are responsible for activity conducted through your account, workspace, API credentials, connected integrations, administrator accounts, Authorised Users, devices and credentials under your control. You must use reasonable care when granting access to employees, contractors, accountants, consultants, agents, business partners or other persons, and promptly revoke access when a person should no longer have it. Actions taken by an Authorised User using valid account access may be treated as actions of the Customer.

3.Compliance with Law

You must not use the Services for any purpose that violates applicable law or regulation. You remain responsible for determining which laws apply to your activities.

  • Fraud, cybercrime, data protection and privacy
  • Intellectual property, consumer protection and advertising
  • Communications, taxation and electronic invoicing
  • Sanctions, trade restrictions, anti-money laundering and financial crime
  • Employment and other laws applicable to your business or use of the Services

4.Fraud, Deception and Scams

You must not use Belvara to commit or facilitate fraud, operate scams, create deceptive transactions, misrepresent goods or services, create false invoices or receipts for fraudulent purposes, fabricate payment records, create misleading proof of payment, falsely represent refunds, falsify purchase records, manipulate business records to deceive another person, impersonate another business or person, engage in phishing, obtain money or information by deception, conceal fraudulent transactions or support another person’s fraudulent activity. Legitimate corrections, test data in authorised environments and lawful accounting adjustments are not prohibited merely because they modify a record.

5.Impersonation and Misrepresentation

You must not impersonate another person or business without authority, falsely claim to represent Belvara, falsely claim an affiliation, endorsement or partnership, use another person’s identity without lawful authority, create accounts using stolen or fabricated identity information or mislead others about the origin of a message, invoice, document or communication.

6.Account, Trial and Subscription Abuse

You must not create multiple accounts to evade plan limits, repeatedly create accounts to obtain additional free trials, use false identities to obtain promotional benefits, circumvent subscription restrictions, avoid legitimate charges through account manipulation, exploit billing defects, bypass seat or workspace limits, evade usage restrictions, share an account in a way that circumvents purchased-user limits or use technical measures to access features not included in your authorised plan. Belvara may consolidate, restrict, suspend or terminate accounts reasonably believed to be used for circumvention or abuse.

7.Unauthorised Access

You must not access another Customer’s account without authorisation, attempt to obtain another user’s credentials, bypass authentication, permissions or role restrictions, exploit an access-control error, access data you are not authorised to access, use another person’s session or attempt to obtain privileged access without authorisation. If Belvara inadvertently makes information accessible that you reasonably know you should not have access to, you must stop accessing it and report the issue to security@belvara.co.ke.

8.Security Attacks and Malicious Activity

You must not use the Services to distribute malware or ransomware, deliver malicious code, operate command-and-control infrastructure, compromise accounts, conduct credential stuffing or brute-force attacks, perform denial-of-service or distributed-denial-of-service attacks, flood systems with requests, exploit vulnerabilities against third parties, scan third-party networks without authority, intercept communications without lawful authority, deploy malicious scripts, interfere with security controls or otherwise undermine the confidentiality, integrity or availability of a computer system.

9.Security Testing

You must not conduct security testing against Belvara production systems unless Belvara has expressly authorised the testing or published a vulnerability-disclosure programme permitting it. You must never test another Customer’s account, access another Customer’s data, perform denial-of-service testing, intentionally degrade production availability, exploit a vulnerability beyond what is reasonably necessary to confirm it, retain Customer Data obtained through a vulnerability or publicly disclose an unresolved vulnerability in a manner that creates material risk. Security vulnerabilities should be reported to security@belvara.co.ke. Good-faith security research authorised by Belvara is not prohibited merely because it tests a security control.

10.Malware, Harmful Code and Compromised Files

You must not knowingly upload, distribute, transmit or store viruses, worms, Trojan horses, ransomware, spyware, malicious macros, credential-stealing software, destructive code or other harmful code through the Services. Belvara may quarantine, block, remove or restrict files reasonably believed to pose a security risk.

11.Spam and Unsolicited Communications

Where Belvara provides email, SMS, messaging or other communications functionality, you must not use it to send unlawful spam, unsolicited bulk messages, deceptive commercial messages, phishing messages, misleading promotions, messages using unlawfully obtained contact lists or communications that violate applicable direct-marketing rules. You are responsible for having a lawful basis or required consent, honouring opt-outs, maintaining appropriate suppression lists, complying with sender-identification rules and ensuring communications are not deceptive.

12.Contact-List Abuse

You must not purchase unlawfully obtained contact lists, upload stolen contact databases, scrape personal contact details for unlawful marketing, use Belvara to facilitate mass outreach to people you have no lawful basis to contact or evade opt-outs by importing a person again under a different list or account.

13.Privacy and Personal Data

You must not use Belvara to collect Personal Data unlawfully, disclose Personal Data without authority, access Personal Data without a legitimate business purpose, secretly monitor people in violation of law, process Personal Data inconsistently with your privacy notices or lawful basis, use stolen Personal Data, unlawfully trade Personal Data or instruct Belvara to perform unlawful Processing. You are responsible for your obligations as Controller or equivalent role under applicable data-protection law. Belvara’s Data Processing Addendum does not transfer those responsibilities to Belvara.

14.Sensitive and Restricted Data

Do not place Sensitive Personal Data or specially regulated information into the Services unless the relevant feature is designed to support it, the agreement permits it, you have a lawful basis and all required safeguards are in place. You must not use free-text fields, notes, uploads or AI prompts as an uncontrolled repository for unnecessary sensitive information. Belvara may restrict categories of data that the Services are not designed to support.

15.Intellectual Property

You must not use the Services to infringe copyright or trademarks, misappropriate trade secrets, distribute pirated material, sell counterfeit goods, copy protected content without authority or otherwise violate another person’s intellectual-property rights. You must have the rights necessary to upload, store, use, generate or distribute content through Belvara. Intellectual-property complaints may be sent to legal@belvara.co.ke.

16.Illegal Goods and Services

You must not use Belvara to sell, promote, facilitate or knowingly support transactions involving goods or services that are illegal in the applicable jurisdiction. Where a product or service is regulated rather than prohibited, you are responsible for licences, registrations, age restrictions, disclosures, permits and other legal requirements. Belvara may restrict categories of regulated activity where reasonably necessary for legal, security, payment-provider or platform-risk reasons.

17.Serious Harm and Exploitation

You must not use Belvara to facilitate, promote or materially support terrorism, violent extremist activity, trafficking, child sexual exploitation or abuse, sexual exploitation, non-consensual intimate imagery, credible threats of violence, targeted harassment that is unlawful or other serious unlawful harm. Belvara may take immediate action where it reasonably believes the Services are being used for serious harm.

18.Discrimination and Unlawful Harassment

You must not use the Services to carry out unlawful discrimination or harassment. Where Belvara functionality is used in a decision affecting a person, you remain responsible for ensuring the decision complies with applicable law.

19.Payment and Financial Misuse

You must not use Belvara’s payment-recording, reconciliation, instalment, settlement or related functionality to launder money, disguise the origin of unlawful funds, create fictitious transactions, fabricate payment confirmations, conceal fraudulent refunds, facilitate payment fraud, process stolen payment credentials, evade legal reporting duties or misrepresent whether a payment has been received or verified. Belvara records do not replace the underlying payment provider’s authoritative records where that provider controls the payment rail.

20.Lipa PolePole and Instalment Misuse

Where Belvara provides instalment or Lipa PolePole functionality, you must not use it to create deceptive repayment obligations, misstate amounts owed, impose unlawful charges, misrepresent payment status, fabricate customer consent, create sham transactions or evade consumer-credit, lending or other laws that apply to your arrangement. Belvara’s software does not itself make an unlawful credit arrangement lawful.

21.Tax and Electronic-Invoicing Misuse

You must not use Belvara tax, invoicing or electronic-invoicing functionality to fabricate taxable transactions, create false tax documents, falsify tax identifiers, intentionally misstate tax treatment, conceal transactions, evade tax, interfere with tax-authority systems or create misleading corrections. You remain responsible for the legal and tax treatment of your transactions.

22.Inventory and Business-Record Integrity

You must not knowingly use Belvara to create or maintain false business records for an unlawful or deceptive purpose. This includes deliberate falsification of stock counts, purchase records, supplier records, returns, write-offs, damages, landed costs, sales, expenses, payment records, fulfilment events or other business records. This does not prohibit legitimate corrections, reconciliation, test data or authorised adjustments.

23.Third-Party Integrations

You must not use a Belvara integration to access another person’s third-party account without authority, transmit data you are not permitted to disclose, bypass third-party access controls, violate the third party’s terms, scrape a third-party platform unlawfully, send malicious requests or use Belvara as a mechanism to attack or abuse another service. You are responsible for permissions you grant to Customer-selected integrations.

24.API Use

If Belvara provides API access, you must protect API credentials, use only documented or authorised endpoints, respect rate limits, respect scope and permission controls, implement reasonable retry behaviour and comply with applicable API documentation. You must not evade rate limits, rotate credentials to bypass restrictions, create excessive requests, intentionally generate abusive workloads, use undocumented access methods to obtain restricted functionality or use the API to obtain data you are not authorised to access.

25.Scraping and Automated Access

Unless Belvara expressly permits it, you must not use bots, scrapers, crawlers, browser automation or other automated systems to extract protected Belvara data, harvest Customer Data, copy substantial portions of the Services, evade rate limits, create accounts in bulk, submit abusive requests, probe for vulnerabilities or interfere with normal service operation. Ordinary search-engine indexing of public Belvara pages in accordance with published technical controls is not prohibited. Approved APIs and authorised integrations are not prohibited merely because they operate automatically.

26.Reverse Engineering and Competitive Abuse

Except where applicable law gives you a non-waivable right, you must not reverse engineer the Services, decompile or disassemble proprietary Belvara software, attempt to discover non-public source code, extract proprietary models or algorithms, defeat technical protections, copy non-public product architecture, use confidential Belvara information to build a competing service or systematically extract proprietary product data for competitive replication. This does not prohibit legitimate interoperability activity where applicable law expressly protects it.

27.Service Resale and Unauthorised Commercialisation

Unless Belvara expressly authorises it, you must not resell access to Belvara, sublicense the Services, rent user seats, operate Belvara as an unauthorised service bureau, sell access credentials or make your account available to unrelated third parties as a substitute for their own subscription. This does not prevent legitimate Authorised Users from using Belvara for the Customer’s business.

28.System and Resource Abuse

You must not use the Services in a manner that imposes an unreasonable burden on Belvara or another provider. Prohibited activity may include request flooding, excessive automated queries, abusive exports, intentionally oversized uploads, repeated generation designed primarily to consume resources, storage abuse, excessive background jobs, computational abuse or other activity intended to degrade performance or avoid reasonable usage controls. Belvara may apply technical limits, queues, throttling, rate limits or other controls to protect service availability.

29.Circumventing Technical Controls

You must not disable or evade security controls, manipulate client-side controls to access restricted functionality, bypass feature gates or rate limits, defeat anti-abuse systems, evade usage metering, remove required integrity checks, alter requests to obtain unauthorised access or interfere with technical safeguards.

30.Artificial Intelligence Features

Additional rules apply where you use Belvara Assistant AI or another AI-enabled Belvara feature. You must not use AI functionality to facilitate fraud, generate phishing or scam content, create or assist malware, unlawfully profile people, unlawfully infer sensitive characteristics, make unlawful discriminatory decisions, deceptively impersonate a real person, generate or facilitate unlawful content, circumvent safety controls, extract underlying models, prompts, system instructions or proprietary model information through abusive methods or use AI output as a substitute for legally required professional review.

31.High-Impact Decisions

Unless Belvara expressly provides a product designed and legally approved for the relevant purpose, you must not use Belvara AI as the sole basis for a decision that produces legal or similarly significant effects concerning an individual in employment, lending or credit, insurance, housing, education, healthcare, legal status or access to essential services. Where AI assists a business decision, you are responsible for appropriate human review and compliance with applicable law.

32.AI Inputs and Outputs

You are responsible for information you submit to AI features, ensuring you have authority to submit it, reviewing AI-generated output, checking material business decisions and complying with applicable law. Do not submit passwords, authentication secrets, payment credentials, unnecessary Sensitive Personal Data, information you are prohibited from disclosing or regulated data that the feature is not designed to handle. AI output may be inaccurate and must not be treated as automatically correct.

33.AI Safety and Model Abuse

You must not attempt to extract model weights, steal model behaviour, conduct model-extraction attacks, circumvent AI safety controls, deliberately cause the AI service to expose another Customer’s information, obtain hidden system instructions through abusive exploitation or use automated probing to degrade or destabilise an AI service. Ordinary use, testing of your own workflows and reasonable evaluation of output quality are permitted.

34.Children and Minors

Belvara’s business-management Services are not designed as services for children. You must not knowingly use Belvara in a manner that unlawfully collects, exploits, profiles or targets children. Where your own business lawfully deals with minors, you are responsible for all required permissions, safeguards and legal obligations.

35.Harassment and Abusive Communication

You must not use Belvara communications functionality to threaten another person unlawfully, stalk, intimidate, repeatedly harass, send abusive communications or facilitate targeted unlawful harassment. Legitimate debt reminders, customer-service communications and ordinary commercial disputes do not become harassment merely because the recipient dislikes them, provided they are lawful and appropriately conducted.

36.Platform Integrity

You must not interfere with another Customer’s use of Belvara, manipulate Belvara rankings, metrics or reports for fraudulent purposes, submit false abuse reports, intentionally trigger operational alerts against another Customer, abuse support channels or use the Services in a manner designed to cause Belvara to take wrongful action against another person.

37.Misuse of Support

You must not knowingly provide false security reports, harass support staff, impersonate account owners, submit fraudulent ownership claims, use support channels to social-engineer access to another account or deliberately conceal material facts in an account-recovery request. Belvara may require reasonable verification before making security-sensitive account changes.

38.Prohibited Credential Sharing

You must not publish, sell or intentionally distribute your Belvara password, API secret, authentication token, recovery code, private integration credential or other security credential in a manner that exposes the Services or Customer Data to unauthorised persons. Where Belvara provides role-based access, each user should use their own authorised access rather than shared credentials.

39.Customer Data Exports

You may export Customer Data where the Services permit it. You must not use exports to unlawfully disclose Personal Data, evade another person’s privacy rights, steal another business’s data, circumvent an access restriction or facilitate unlawful resale of Personal Data. Once you export Customer Data, you are responsible for protecting the exported copy.

40.Document Generators and Free Tools

Belvara’s calculators, templates, generators and other free resources must not be used to create fraudulent documents, impersonate another business, fabricate transactions, create false proof of payment, misrepresent legal approval, produce deceptive tax documents, violate intellectual-property rights or facilitate unlawful activity. Ordinary examples, drafts, mock documents and legitimate business documents are permitted.

41.Sanctions, Export Controls and Restricted Parties

You must not use Belvara in violation of legally applicable sanctions, export controls, trade restrictions, embargoes or prohibited-party rules. Belvara may restrict access or transactions where reasonably necessary to comply with applicable law or provider requirements.

42.Attempts and Facilitation

You must not attempt to perform a prohibited activity or knowingly help another person perform one. Belvara may treat attempted violations, coordinated abuse, facilitation, preparation for abuse or repeated suspicious behaviour as violations where reasonably justified by the circumstances.

43.Investigation and Monitoring

Belvara has no general obligation to monitor all Customer activity. However, Belvara may use reasonable technical and operational measures to detect abuse, investigate security events, investigate fraud and reports, enforce this AUP, protect Customers and infrastructure, comply with law and protect Belvara’s rights. Belvara may review relevant logs, account activity, metadata, permissions or affected content where reasonably necessary and legally permitted.

44.Reporting Violations

Suspected violations of this AUP may be reported to legal@belvara.co.ke. Security vulnerabilities or suspected security incidents should be reported to security@belvara.co.ke. General support enquiries should be sent to support@belvara.co.ke. A report should include enough information for Belvara to reasonably identify and investigate the issue.

45.Belvara’s Response to Violations

If Belvara reasonably believes this AUP has been violated, Belvara may take proportionate action including warning the Customer, requesting remediation, restricting a feature, disabling an integration, rate limiting, blocking a request, quarantining a file, removing prohibited content where legally appropriate, restricting an Authorised User, requiring credential reset, suspending an account, terminating access, preserving relevant evidence or taking another reasonable protective action. Belvara may act immediately where delay could increase security risk, expose Customer Data, enable fraud, create serious harm, violate law, threaten another person, compromise infrastructure or interfere with its ability to provide the Services.

46.Notice

Where reasonably practicable and legally appropriate, Belvara may provide notice before or after taking enforcement action. Belvara may act without advance notice where urgent action is reasonably necessary, giving notice could increase risk, law prohibits notice, a provider or authority requires immediate action or the violation creates a material threat.

47.Suspension and Termination

A serious or repeated violation of this AUP may constitute a material breach of the Belvara Terms of Service. Belvara may suspend or terminate access in accordance with the Terms of Service. Suspension may apply to a user, workspace, feature, integration, API credential, communication channel or entire account depending on the risk.

48.Preservation and Disclosure

Belvara may preserve relevant information where reasonably necessary to investigate abuse, protect security, comply with law, respond to lawful process, protect legal rights, enforce agreements or defend claims. Belvara may disclose information where required or permitted by applicable law and in accordance with the Belvara Privacy Policy.

49.Law-Enforcement and Regulatory Matters

Belvara may cooperate with lawful requests from competent authorities. Belvara may also report activity where it reasonably believes reporting is required by law or reasonably necessary to address an imminent or serious threat, subject to applicable legal requirements. Nothing in this AUP creates an obligation to report conduct where no such obligation exists.

50.Customer Remediation

Belvara may require a Customer to take corrective action before access is restored. Corrective action may include resetting credentials, removing an Authorised User, disabling an integration, stopping an abusive campaign, deleting prohibited material, correcting a misconfiguration, providing evidence of authorisation or implementing additional security controls.

51.Appeals and Review

If you believe Belvara took enforcement action in error, you may request review through support@belvara.co.ke. For formal legal disputes, use legal@belvara.co.ke. Belvara may require account verification, relevant records, an explanation of the activity, evidence of authority or remediation information before restoring access. An appeal does not automatically pause protective action where continued access creates material risk.

52.No Waiver

Belvara’s decision not to enforce this AUP in one instance does not waive Belvara’s right to enforce it later. Failure to detect prohibited activity does not constitute permission.

53.Service-Specific Rules

Certain Belvara features may have additional acceptable-use or product-specific restrictions addressing API access, AI, communications, payments, integrations, tax functionality, marketplace connectivity or regulated workflows. Where a service-specific rule conflicts with this AUP, the more specific rule controls for that feature unless the applicable agreement states otherwise.

54.Changes to this Policy

Belvara may update this AUP to reflect changes to the Services, new forms of abuse, security risks, legal requirements, regulatory guidance, new integrations, new AI capabilities or other legitimate operational needs. Material changes will be handled in accordance with the Belvara Terms of Service and applicable law. The “Last Updated” date identifies the current version.

55.Relationship with Other Belvara Documents

This AUP should be read together with the Belvara Terms of Service, Belvara Global Privacy Policy, Belvara Global Data Processing Addendum, Belvara Cookie & Tracking Technologies Policy, Belvara Subprocessor List and any applicable product-specific or enterprise terms. If this AUP conflicts with a negotiated agreement that expressly overrides it, the negotiated agreement controls to the extent of the stated conflict.

56.No Expansion of Legal Duties

Nothing in this AUP voluntarily subjects Belvara to a law that would not otherwise apply, creates a duty to continuously monitor all Customer activity, requires Belvara to investigate every report, creates a private right of action where none otherwise exists, waives Belvara’s contractual protections, limits Belvara’s lawful security or enforcement rights or obligates Belvara to provide service to activity that creates unacceptable legal, security or operational risk. Belvara may take reasonable protective action to preserve the safety, integrity and lawful operation of the Services.

57.Contact

Belvara, Nairobi, Kenya. General enquiries: hello@belvara.co.ke. Customer support: support@belvara.co.ke. Privacy and data protection: privacy@belvara.co.ke. Security: security@belvara.co.ke. Legal and abuse reports: legal@belvara.co.ke.

Something better is coming

is coming as we build Belvara. Explore the waitlist to see what’s next.

Explore the waitlist