All policies

Legal

Marketing Compliance & Acceptable Use Policy

BEEVELOPE

EMAIL MARKETING COMPLIANCE & ACCEPTABLE USE POLICY

Effective Date: 5 September 2026

PART I

INTRODUCTION, PURPOSE AND SCOPE

1. Purpose

1.1This Email Marketing Compliance & Acceptable Use Policy ("Email Marketing Policy") establishes the rules and standards governing the use of the BEEVELOPE Platform for creating, sending, automating, managing and analysing email and other electronic marketing communications.

1.2The purpose of this Policy is to:

(a) promote lawful and responsible email marketing;

(b) protect recipients from unsolicited, deceptive, fraudulent or abusive communications;

(c) protect the reputation and deliverability of the BEEVELOPE Platform;

(d) establish minimum compliance requirements for Customers and Users;

(e) establish mechanisms for preventing spam, abuse, phishing and other unlawful activities;

(f) support compliance with Applicable Laws; and

(g) establish the Company's rights to investigate, restrict or suspend activity that presents material compliance, security or deliverability risks.

2. Scope

This Policy applies to:

(a) all Customers;

(b) all Users;

(c) administrators and account owners;

(d) campaigns created through the Platform;

(e) automated email sequences;

(f) transactional or commercial communications where processed through the Platform;

(g) AI-generated marketing content;

(h) recipient lists uploaded or synchronised with the Platform;

(i) integrations with CRM or other third-party systems; and

(j) all other email-marketing functionality provided through BEEVELOPE.

3. Relationship with Other Documents

This Policy forms part of the Company's broader contractual and compliance framework and shall be read together with:

(a) the Terms of Service;

(b) the Global Privacy Policy;

(c) the Cookie Policy;

(d) the Responsible AI & AI Governance Policy;

(e) the Data Processing Agreement;

(f) the Information Security Policy;

(g) the Email Deliverability & Anti-Abuse Policy; and

(h) other applicable policies and agreements.

Where there is an inconsistency concerning email marketing compliance, this Policy shall apply to the extent of that subject matter, subject always to mandatory Applicable Laws.

PART II

DEFINITIONS

4. Definitions

For purposes of this Policy:

4.1 "Commercial Communication"

means an electronic communication whose purpose, in whole or in part, is to advertise, promote, solicit, offer, market or facilitate the sale of goods, services, products, subscriptions, events or other commercial activities.

4.2 "Recipient"

means an individual, organisation or other person to whom an email or electronic communication is directed.

4.3 "Marketing List"

means a collection of Recipient contact information used or intended to be used for sending communications through the Platform.

4.4 "Consent"

means a legally valid permission or other lawful authorisation to receive marketing communications, as recognised under Applicable Laws.

4.5 "Opt-Out"

means a request by a Recipient not to receive specified categories of marketing communications.

4.6 "Suppression List"

means a list or record maintained for the purpose of preventing further marketing communications from being sent to persons who have opted out, unsubscribed, complained or otherwise should not receive marketing communications.

4.7 "Transactional Communication"

means a communication primarily necessary to facilitate, complete or administer a transaction or service requested by a Recipient and which is not primarily promotional.

4.8 "Purchased List"

means a Marketing List obtained from a third party through purchase, rental, licence, exchange or other acquisition arrangement.

4.9 "Scraped Data"

means contact information obtained through automated extraction, harvesting or collection from websites, social-media platforms, directories or other sources without appropriate legal authority.

4.10 "Applicable Email Marketing Laws"

means all laws, regulations, regulatory guidance and legally binding requirements applicable to the relevant email or electronic marketing activity.

4.11

Capitalised terms not defined herein shall have the meanings assigned to them in the Terms of Service.

PART III

FUNDAMENTAL EMAIL MARKETING REQUIREMENTS

5. Lawful Marketing

Customers shall use BEEVELOPE only for lawful marketing and communication activities.

Customers are responsible for determining the legal requirements applicable to their campaigns based on:

(a) the location of the sender;

(b) the location and status of the Recipient;

(c) the nature of the communication;

(d) the relationship between sender and Recipient;

(e) the products or services promoted; and

(f) Applicable Laws.

6. Appropriate Permission and Lawful Basis

6.1Customers must have an appropriate lawful basis or other legally valid authorisation to send marketing communications to their intended Recipients.

6.2Where Applicable Laws require consent, Customers shall obtain valid consent before sending the relevant marketing communication.

6.3Where a jurisdiction permits an alternative legal basis or exception, including a legally recognised existing-customer or "soft opt-in" mechanism, Customers may rely upon that mechanism only where all applicable statutory conditions are satisfied.

6.4The Company does not determine whether a particular Customer's campaign satisfies the legal requirements applicable to that Customer.

7. Consent Records

Where consent is relied upon, Customers should maintain records demonstrating:

(a) who provided consent;

(b) when consent was obtained;

(c) how consent was obtained;

(d) what the Recipient agreed to receive;

(e) the identity of the organisation requesting consent;

(f) the communication channel covered by the consent; and

(g) any subsequent withdrawal or modification of consent.

The Company may request evidence of consent where reasonably necessary to investigate complaints or suspected abuse.

8. No Pre-Ticked or Deceptive Consent

Customers shall not knowingly obtain marketing consent through:

(a) pre-ticked boxes where prohibited;

(b) silence or inactivity where affirmative consent is required;

(c) misleading disclosures;

(d) deceptive interface design;

(e) hidden terms;

(f) bundled consent where prohibited; or

(g) other mechanisms designed to circumvent applicable consent requirements.

PART IV

MARKETING LISTS AND CONTACT ACQUISITION

9. Customer Responsibility for Marketing Lists

Customers are solely responsible for ensuring that every Marketing List uploaded, imported, synchronised or otherwise used through BEEVELOPE has been obtained and may be used lawfully.

10. Purchased and Rented Lists

10.1Customers shall not use Purchased Lists where doing so would violate Applicable Laws or this Policy.

10.2Where a Customer relies upon consent obtained through a third party, the Customer must independently verify that the consent:

(a) was validly obtained;

(b) covered the Customer or relevant organisation;

(c) covered the relevant communication method;

(d) was sufficiently specific;

(e) was not withdrawn; and

(f) can be demonstrated if challenged.

10.3A third party's representation that a list is "compliant", "permission-based" or "opt-in" does not by itself establish compliance.

The ICO specifically notes that purchased lists used for UK electronic marketing to individuals require valid consent covering the relevant organisation and communication method. (ICO)

11. Scraping and Harvesting

Customers shall not use BEEVELOPE to:

(a) scrape email addresses unlawfully;

(b) harvest email addresses from websites;

(c) extract contact information from social-media platforms in violation of applicable terms or law;

(d) bypass technical restrictions;

(e) collect contact information through deceptive means; or

(f) otherwise acquire contact information unlawfully.

12. Publicly Available Information

The fact that an email address is publicly available does not, by itself, establish permission to send marketing communications.

Customers must determine whether the applicable law permits marketing to the relevant Recipient based on the source, context and nature of the contact information.

This is particularly important for individual recipients in jurisdictions where prior consent or a statutory exception is required. (ICO)

PART V

CONTENT AND SENDER REQUIREMENTS

13. Accurate Sender Information

Customers shall ensure that email headers and sender information are accurate and not misleading.

The sender identity, domain and relevant routing information must not be manipulated to conceal the true origin of a communication.

This requirement is expressly reflected in the U.S. CAN-SPAM framework and UK PECR requirements. (Federal Trade Commission)

14. Non-Deceptive Subject Lines

Customers shall not use subject lines that materially misrepresent the content, purpose or nature of an email.

Examples of prohibited conduct include:

(a) false claims of urgency;

(b) deceptive account notices;

(c) misleading "Re:" or "Fwd:" representations;

(d) falsely suggesting a personal relationship; or

(e) disguising advertising as a transactional communication.

15. Identification of Commercial Communications

Where Applicable Laws require commercial communications to be identified as advertising or marketing, Customers shall provide the required disclosure in a clear and conspicuous manner.

16. Sender Identification

Customers shall ensure that marketing communications contain sufficient information to enable Recipients to understand who is communicating with them.

Customers shall not use BEEVELOPE to impersonate:

(a) another business;

(b) an individual;

(c) a governmental authority;

(d) a financial institution;

(e) a technology provider;

(f) a service provider; or

(g) any other person without lawful authority.

17. Physical or Contact Address

Where Applicable Laws require a physical postal address or other valid contact information, Customers shall include the required information in their communications.

For example, U.S. CAN-SPAM requires commercial email to include a valid physical postal address. (Federal Trade Commission)

PART VI

UNSUBSCRIBE, OPT-OUT AND SUPPRESSION

18. Unsubscribe Mechanism

Every marketing communication shall contain an appropriate and functional mechanism enabling Recipients to opt out where required by Applicable Laws.

19. Simple Opt-Out

The unsubscribe mechanism should be:

(a) clear;

(b) conspicuous;

(c) reasonably easy to use;

(d) accessible without unnecessary authentication; and

(e) available without unreasonable cost or effort.

The ICO specifically recommends that recipients be given a simple means of opting out, such as a clear unsubscribe link, and states that requiring a recipient to create or log into an account is not a simple opt-out mechanism. (ICO)

20. Processing Opt-Out Requests

Customers shall process valid opt-out requests within the period required by Applicable Laws and shall cease the relevant marketing communications thereafter.

21. Suppression Lists

21.1Customers shall maintain appropriate suppression records to prevent marketing communications from being sent to Recipients who have opted out.

21.2Where technically supported, BEEVELOPE may maintain suppression information at the Platform level to assist Customers in preventing repeated communications to opted-out Recipients.

21.3Suppression information may be retained for the limited purpose of preventing further marketing communications and complying with legal obligations.

22. No Re-Subscription Without Permission

A Customer shall not knowingly re-add a Recipient to a Marketing List after a valid opt-out unless the Recipient subsequently provides a new legally valid permission or another lawful basis exists.

PART VII

EMAIL MARKETING CONTENT STANDARDS

23. Prohibited Content

Customers shall not use BEEVELOPE to distribute content that:

(a) is unlawful;

(b) facilitates fraud;

(c) facilitates phishing;

(d) promotes malware;

(e) contains malicious code;

(f) unlawfully exploits children;

(g) promotes terrorism or violent extremism;

(h) facilitates trafficking;

(i) facilitates identity theft;

(j) unlawfully infringes intellectual property;

(k) contains deceptive representations;

(l) facilitates unlawful gambling or regulated activities where prohibited;

(m) unlawfully promotes regulated products; or

(n) otherwise violates Applicable Laws.

24. Phishing and Impersonation

BEEVELOPE shall not be used to send communications designed to fraudulently obtain:

(a) passwords;

(b) authentication credentials;

(c) financial information;

(d) payment details;

(e) security codes;

(f) identity documents; or

(g) other sensitive information.

25. Malware and Malicious Links

Customers shall not use the Platform to distribute:

(a) malware;

(b) ransomware;

(c) spyware;

(d) malicious scripts;

(e) credential-stealing pages;

(f) exploit code;

(g) malicious attachments; or

(h) links knowingly directing Recipients to malicious content.

26. Misleading Claims

Customers shall not knowingly distribute materially false or deceptive claims concerning:

(a) products;

(b) prices;

(c) discounts;

(d) guarantees;

(e) endorsements;

(f) testimonials;

(g) business relationships;

(h) regulatory status; or

(i) other material matters.

PART VIII

AI-GENERATED EMAIL MARKETING

27. AI-Generated Content

BEEVELOPE may provide AI-assisted functionality for generating or optimising:

(a) subject lines;

(b) email content;

(c) personalised communications;

(d) campaign suggestions;

(e) calls to action;

(f) segmentation suggestions; and

(g) other marketing content.

28. Customer Responsibility for AI Content

Customers remain responsible for reviewing AI-generated marketing content before distribution.

AI-generated content may contain:

(a) factual inaccuracies;

(b) unsupported claims;

(c) inappropriate personalisation;

(d) misleading statements;

(e) unintended references; or

(f) other errors.

29. No Automated Legal Compliance Guarantee

AI functionality does not constitute legal advice and does not guarantee that a campaign complies with Applicable Laws.

Customers remain responsible for determining whether a campaign is legally permissible.

PART IX

EMAIL AUTHENTICATION AND DELIVERABILITY

30. Domain Authentication

Customers should configure appropriate email authentication mechanisms for domains used with BEEVELOPE where supported, including:

(a) SPF;

(b) DKIM; and

(c) DMARC.

31. Sender Reputation

Customers shall not knowingly engage in activities that materially damage the reputation or deliverability of BEEVELOPE's infrastructure.

32. Sending Volume

The Company may establish reasonable sending limits based on:

(a) Subscription Plan;

(b) account history;

(c) sender reputation;

(d) bounce rates;

(e) complaint rates;

(f) security risk;

(g) infrastructure capacity; and

(h) Applicable Laws.

33. Bounce Management

Customers shall monitor and appropriately manage:

(a) hard bounces;

(b) repeated soft bounces;

(c) invalid addresses;

(d) inactive recipients; and

(e) other indicators of poor list quality.

The Company may impose controls where repeated sending to invalid or undeliverable addresses creates a material deliverability or infrastructure risk.

PART X

SPAM, ABUSE AND COMPLAINT MANAGEMENT

34. Prohibition on Spam

Customers shall not use BEEVELOPE to send spam or communications that are reasonably likely to constitute unlawful unsolicited commercial communications.

35. Spam Complaints

The Company may monitor complaint rates and other abuse indicators for purposes of protecting:

(a) Recipients;

(b) Customers;

(c) BEEVELOPE infrastructure;

(d) sending reputation;

(e) third-party email networks; and

(f) the integrity of the Platform.

36. Abuse Detection

The Company may use automated and manual systems to identify:

(a) abnormal sending patterns;

(b) sudden volume increases;

(c) suspicious campaigns;

(d) unusually high bounce rates;

(e) spam complaints;

(f) phishing indicators;

(g) compromised accounts;

(h) malicious content; and

(i) other abuse indicators.

37. Investigation

Where reasonably necessary, the Company may investigate suspected violations of this Policy.

Customers shall reasonably cooperate with investigations relating to suspected abuse, unlawful activity or material deliverability risks.

PART XI

HIGH-RISK ACTIVITIES AND RESTRICTED USE

38. Regulated Industries

Customers operating in regulated industries shall ensure that their campaigns comply with applicable sector-specific requirements.

This may include, depending upon the jurisdiction:

(a) financial services;

(b) healthcare;

(c) pharmaceuticals;

(d) insurance;

(e) telecommunications;

(f) gambling;

(g) alcohol;

(h) tobacco or nicotine;

(i) political communications; and

(j) other regulated sectors.

39. Political Communications

Customers shall comply with all applicable laws governing political advertising, election communications, fundraising and political messaging.

The Company may impose additional restrictions on political communications where reasonably necessary to comply with Applicable Laws or protect the Platform.

40. Sensitive or Vulnerable Recipients

Customers shall exercise heightened care when marketing to vulnerable persons or using information that could reveal sensitive characteristics.

Customers shall not use BEEVELOPE to unlawfully discriminate against individuals based upon protected characteristics.

PART XII

CUSTOMER RECORDS AND COMPLIANCE

41. Compliance Records

Customers should maintain records reasonably necessary to demonstrate compliance with applicable email marketing requirements.

Such records may include:

(a) consent records;

(b) source of contact information;

(c) date and method of collection;

(d) campaign records;

(e) unsubscribe requests;

(f) suppression records;

(g) complaints;

(h) lawful-basis assessments; and

(i) relevant Customer policies.

42. Customer Audits

The Company may request reasonable information from Customers where necessary to investigate:

(a) repeated spam complaints;

(b) suspected unlawful campaigns;

(c) phishing;

(d) abuse;

(e) regulatory complaints; or

(f) material violations of this Policy.

PART XIII

PLATFORM ENFORCEMENT

43. Warning and Corrective Measures

Where the Company identifies a potential violation, it may:

(a) issue a warning;

(b) require corrective action;

(c) require removal or modification of a campaign;

(d) restrict sending functionality;

(e) impose temporary sending limits;

(f) require additional verification; or

(g) take other reasonable protective measures.

44. Suspension

The Company may suspend or restrict an Account where reasonably necessary to:

(a) prevent unlawful activity;

(b) protect Recipients;

(c) prevent spam;

(d) protect Platform infrastructure;

(e) address security threats;

(f) investigate serious complaints;

(g) protect sender reputation; or

(h) comply with Applicable Laws.

45. Immediate Suspension

The Company may take immediate protective action where it reasonably believes an Account is being used for:

(a) phishing;

(b) malware distribution;

(c) fraud;

(d) credential theft;

(e) large-scale spam;

(f) unlawful activity;

(g) account compromise; or

(h) other conduct presenting an immediate material risk.

46. Termination

Serious or repeated violations may result in termination of the Customer's access to BEEVELOPE in accordance with the Terms of Service.

47. Cooperation with Authorities

Where legally required, the Company may cooperate with:

(a) law enforcement;

(b) regulators;

(c) courts;

(d) email service providers;

(e) cybersecurity organisations; and

(f) other competent authorities.

PART XIV

GLOBAL COMPLIANCE FRAMEWORK

48. United States

Customers sending commercial email to recipients in the United States shall comply with applicable U.S. federal and state laws.

CAN-SPAM requirements include accurate header information, non-deceptive subject lines, appropriate identification, a valid physical postal address and a mechanism for recipients to opt out of future commercial email. (Federal Trade Commission)

Customers remain responsible for compliance with any additional state or sector-specific requirements applicable to their campaigns.

49. European Union / EEA

Customers shall comply with applicable EU/EEA requirements governing electronic marketing and personal data processing.

Where consent is required, Customers shall obtain legally valid consent and maintain appropriate records.

Where applicable, Customers shall also comply with GDPR requirements relating to lawful processing, transparency, individual rights and data protection.

50. United Kingdom

Where UK PECR applies, Customers shall comply with the applicable electronic marketing requirements.

In particular, the applicable rules may differ depending upon whether the Recipient is an individual subscriber, sole trader/partnership or corporate subscriber. UK rules also require appropriate identification and a valid means of opting out. (ICO)

Customers relying upon a soft opt-in must independently ensure that all statutory requirements are satisfied.

51. India

Customers sending marketing communications to persons in India shall comply with applicable Indian privacy, information technology, consumer protection, telecommunications and electronic communication requirements applicable to their activities.

Customers shall ensure that any collection and use of Personal Data for marketing is supported by an appropriate legal basis and that applicable consent, notice, withdrawal and grievance requirements are satisfied.

52. Other Jurisdictions

Customers shall comply with applicable email marketing, privacy, electronic communications, consumer protection and anti-spam laws in other jurisdictions where their campaigns are directed.

Depending upon the relevant jurisdiction, such requirements may include specific rules concerning:

(a) consent;

(b) identification;

(c) unsubscribe mechanisms;

(d) sender information;

(e) marketing lists;

(f) cross-border transfers;

(g) recordkeeping; and

(h) regulated communications.

PART XV

THIRD-PARTY INTEGRATIONS

53. CRM and Marketing Integrations

Customers may connect BEEVELOPE to third-party CRM, marketing, sales or communication systems.

Customers remain responsible for ensuring that data synchronised from such systems may lawfully be used for email marketing.

54. Third-Party Data

The Company does not guarantee the legality or accuracy of contact information imported from third-party systems.

Customers must independently assess:

(a) the source of the data;

(b) the lawful basis for processing;

(c) marketing permissions;

(d) suppression status; and

(e) applicable contractual restrictions.

PART XVI

SECURITY, PRIVACY AND DATA PROTECTION

55. Personal Data

Email marketing campaigns may involve Personal Data, including:

(a) names;

(b) email addresses;

(c) job titles;

(d) organisation information;

(e) communication history;

(f) preferences;

(g) campaign engagement information; and

(h) other information submitted by Customers.

Such information shall be processed in accordance with the Company's Privacy Policy and applicable contractual arrangements.

56. Security

Customers shall implement reasonable security measures to protect Marketing Lists and campaign information, including appropriate controls over:

(a) Account credentials;

(b) API keys;

(c) integrations;

(d) exported lists;

(e) administrator access; and

(f) other sensitive information.

57. Compromised Accounts

Customers shall immediately notify the Company if they suspect that their Account has been compromised and shall cooperate with reasonable security measures.

The Company may temporarily restrict sending activity where reasonably necessary to prevent abuse.

PART XVII

REPORTING AND COMPLAINTS

58. Reporting Violations

Suspected violations of this Policy may be reported through the Company's designated abuse, security or compliance channels.

59. Recipient Complaints

The Company may receive complaints directly from Recipients regarding communications sent through BEEVELOPE.

Where appropriate, the Company may:

(a) investigate the complaint;

(b) contact the relevant Customer;

(c) request evidence of permission;

(d) suspend relevant sending activity;

(e) add an address to a suppression mechanism; or

(f) take other reasonable measures.

PART XVIII

POLICY GOVERNANCE

60. Monitoring and Review

The Company may periodically review this Policy to reflect:

(a) changes in Applicable Laws;

(b) regulatory guidance;

(c) technological developments;

(d) evolving spam and abuse patterns;

(e) changes in email industry standards;

(f) customer feedback; and

(g) operational experience.

61. Changes to the Policy

The Company may amend this Policy from time to time.

Material changes shall be communicated where required by Applicable Laws or the Terms of Service.

62. No Legal Advice

Information provided by BEEVELOPE concerning email marketing compliance, consent, deliverability or campaign practices is provided for general informational purposes and does not constitute legal advice.

Customers should obtain independent legal advice where necessary.

63. Customer Responsibility

Nothing in this Policy transfers the Customer's legal responsibility for its marketing campaigns to the Company.

The Customer remains responsible for:

(a) its Marketing Lists;

(b) its lawful basis;

(c) consent;

(d) campaign content;

(e) recipient selection;

(f) sender identity;

(g) unsubscribe compliance;

(h) regulatory compliance; and

(i) all actions taken through its Account.

PART XIX

FINAL PROVISIONS

64. Enforcement

The Company reserves the right to enforce this Policy proportionately and in accordance with the Terms of Service and Applicable Laws.

65. Severability

If any provision of this Policy is determined to be invalid or unenforceable, the remaining provisions shall continue to apply to the maximum extent permitted by law.

66. No Waiver

Failure to enforce any provision of this Policy shall not constitute a waiver of the Company's rights.

67. Relationship with Terms of Service

This Policy forms part of the contractual framework governing use of BEEVELOPE.

The Terms of Service shall govern matters not specifically addressed by this Policy.

68. Effective Date

This Policy shall become effective on the Effective Date stated above and remain effective until amended or replaced.

ANNEXURE A

EMAIL MARKETING COMPLIANCE CHECKLIST

Before sending a marketing campaign, Customers should confirm:

☐ The Recipient list was lawfully obtained.

☐ The Customer has an appropriate lawful basis or permission to send the communication.

☐ Consent was obtained where legally required.

☐ The Customer can demonstrate consent where required.

☐ The sender identity is accurate.

☐ The subject line is not deceptive.

☐ The communication accurately identifies the sender.

☐ Required physical/contact information is included.

☐ A functional unsubscribe mechanism is included.

☐ Unsubscribe requests are processed appropriately.

☐ Suppression lists are respected.

☐ The content does not contain prohibited material.

☐ Links and attachments have been reviewed.

☐ AI-generated content has been reviewed by a human.

☐ The campaign complies with applicable jurisdiction-specific requirements.

ANNEXURE B

MINIMUM SENDER INFORMATION

Where applicable, marketing communications should contain:

Sender identity

Valid sender email address

Accurate subject line

Required commercial/advertising disclosure

Valid physical or contact address

Clear unsubscribe mechanism

Relevant privacy notice or link

Other disclosures required by Applicable Laws

ANNEXURE C

PROHIBITED EMAIL MARKETING ACTIVITIES

The following activities are prohibited or may result in immediate restriction:

phishing;

malware distribution;

credential harvesting;

fraudulent impersonation;

unlawful scraping;

unlawful purchased lists;

spam campaigns;

deceptive subject lines;

falsified sender information;

repeated emailing after opt-out;

suppression-list circumvention;

malicious attachments;

unlawful harvesting of personal data;

fraudulent promotions;

unlawful regulated-product marketing;

abusive sending behaviour; and

attempts to circumvent BEEVELOPE's anti-abuse controls.

ANNEXURE D

COMPLIANCE RESPONSIBILITY MATRIX

AreaCustomer ResponsibilityBEEVELOPE Responsibility
Marketing listObtain lawfullyProvide platform controls
ConsentObtain and documentSupport relevant functionality
Campaign contentEnsure legalityDetect certain prohibited activity
Sender identityProvide accurate detailsTechnical sending infrastructure
UnsubscribeHonour requestsProvide/maintain relevant functionality
SuppressionMaintain appropriate listsSupport suppression mechanisms
Spam complaintsInvestigate and remediateMonitor platform-level abuse
DeliverabilityMaintain responsible practicesMaintain infrastructure controls
AI contentHuman reviewProvide AI safeguards
PrivacyEstablish lawful basisProcess data according to agreements
SecuritySecure Customer AccountSecure Platform infrastructure
Regulatory compliancePrimary responsibilityPlatform-level compliance obligations