Acceptable Use Policy
Lawful, secure, and responsible use of NOVATRADE SOLUTIONS services
- LAST UPDATED
- 13 August 2026
- COMPANY REGISTRATION
- NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Poland · KRS: 0001255864, NIP: 7011324158, REGON: 54531482500000
- CONTROLLER
- NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Poland
- CONTACT
- [email protected]
This Acceptable Use Policy ("AUP") establishes rules for lawful, secure, and responsible use of services provided by NOVATRADE SOLUTIONS Sp. z o.o.
The Polish language version of this document is the legally binding one. Where the English text differs from the Polish text, the Polish text prevails.
1. Purpose
This Acceptable Use Policy ("AUP") establishes rules for lawful, secure, and responsible use of services provided by NOVATRADE SOLUTIONS Sp. z o.o.
The purpose of this AUP is to protect:
- NOVATRADE customers;
- Authorized Users;
- third parties;
- data subjects;
- communications networks;
- payment and integration ecosystems;
- NOVATRADE systems and infrastructure
from unlawful, fraudulent, abusive, deceptive, or materially harmful activity.
This AUP forms part of the contractual framework governing use of the NOVATRADE Service.
2. Service Provider
The service provider is:
NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Poland
KRS: 0001255864
NIP: 7011324158
REGON: 54531482500000
Email: [email protected]
Phone: +48 22 273 95 89
Additional company information is available in our Legal Notice.
3. Scope
This AUP applies to use of:
- NOVATRADE software;
- customer accounts;
- Authorized User accounts;
- CRM functionality;
- APIs;
- integrations;
- automation;
- communication functionality;
- AI-assisted functionality;
- data storage;
- administrative functionality;
- other NOVATRADE digital services.
It applies to Customers and all persons using the Service through or on behalf of a Customer.
Customers are responsible for ensuring that their Authorized Users use the Service consistently with this AUP.
4. General Rule
The Service must be used:
- lawfully;
- honestly;
- for legitimate business purposes;
- in accordance with applicable agreements;
- in a manner that does not materially interfere with the security, integrity, or availability of the Service.
Customers must not use NOVATRADE to carry out activity that would be unlawful if performed without NOVATRADE.
The fact that functionality is technically available does not mean that every possible use of that functionality is permitted.
5. Compliance With Applicable Law
Customers are responsible for complying with laws applicable to their own business and use of the Service.
Depending on the activity, applicable requirements may relate to matters including:
- privacy;
- data protection;
- employment;
- electronic communications;
- direct marketing;
- intellectual property;
- taxation;
- consumer protection;
- payments;
- financial crime;
- sanctions;
- export controls;
- cybersecurity;
- other regulated activities.
NOVATRADE does not provide legal authorization for a Customer's underlying business merely by providing software to that Customer.
6. Illegal Activity
The Service must not be used to:
- commit a criminal offence;
- knowingly facilitate criminal activity;
- conceal unlawful activity;
- coordinate illegal transactions;
- store or distribute unlawful material;
- evade a lawful restriction;
- knowingly assist another person in carrying out unlawful activity.
This prohibition applies whether the unlawful activity is directed at NOVATRADE, another Customer, a third party, or an external service.
7. Fraud and Deception
Customers must not use the Service to engage in or facilitate fraud or material deception.
Prohibited activity includes using NOVATRADE to:
- impersonate another person or organization without authorization;
- create materially false business identities;
- submit intentionally false transaction information;
- obtain goods, services, money, or data through deception;
- operate scams;
- conceal fraudulent activity;
- create deceptive account records;
- fabricate evidence of a transaction;
- manipulate records for fraudulent purposes.
Ordinary correction of inaccurate business records is not prohibited.
8. Payment and Transaction Abuse
Where NOVATRADE functionality is used in connection with payments, billing, invoices, transaction records, or payment integrations, Customers must not use the Service to:
- initiate transactions without proper authorization;
- use stolen payment credentials;
- conduct card testing;
- facilitate payment fraud;
- disguise the true nature of a transaction;
- disguise the actual seller or beneficiary of a transaction;
- process transactions on behalf of an undisclosed third party where authorization is required;
- misrepresent goods or services associated with a transaction;
- manipulate transaction descriptions to evade lawful controls;
- artificially divide or restructure transactions to evade applicable controls;
- conceal the origin or destination of funds;
- facilitate money laundering;
- knowingly facilitate terrorist financing;
- abuse refunds;
- submit knowingly false chargebacks or payment disputes;
- manufacture false evidence to contest a legitimate payment;
- circumvent restrictions imposed by an applicable payment service or financial institution.
Use of NOVATRADE does not authorize a Customer to provide payment-processing or financial services to third parties where the Customer is not lawfully authorized to do so.
9. No Transaction Laundering
Customers must not use NOVATRADE to conceal the identity or activity of the actual seller, service provider, beneficiary, merchant, or commercial activity connected with a transaction.
A Customer must not use the Service to make transactions for one business appear to belong to another business where doing so would mislead:
- a customer;
- bank;
- payment provider;
- acquiring institution;
- card network;
- regulator;
- other relevant party.
NOVATRADE may restrict access where there is a reasonable basis to believe that the Service is being used for transaction laundering or comparable payment deception.
10. No Payment-Control Evasion
Customers must not intentionally use NOVATRADE to evade lawful:
- payment-provider controls;
- fraud controls;
- merchant restrictions;
- authentication requirements;
- transaction monitoring;
- account restrictions;
- sanctions restrictions;
- financial-crime controls.
This includes providing materially misleading information about:
- the Customer;
- the Customer's business;
- products or services;
- transaction parties;
- transaction purpose.
Nothing in this section prevents legitimate privacy, security, or data-minimization practices.
11. Security Abuse
Customers must not use the Service to attack, compromise, interfere with, or obtain unauthorized access to:
- NOVATRADE;
- another Customer;
- another user;
- a third-party service;
- a device;
- a network;
- an account;
- a database;
- an application.
Prohibited activity includes:
- exploiting vulnerabilities without authorization;
- bypassing authentication;
- bypassing authorization;
- privilege escalation;
- session hijacking;
- unauthorized account takeover;
- unauthorized access to data;
- unauthorized manipulation of data.
12. Malware and Malicious Code
Customers must not knowingly use the Service to create, host, distribute, transmit, deploy, or control malicious software intended to compromise systems or data.
This includes malicious:
- ransomware;
- trojans;
- credential stealers;
- botnet software;
- destructive code;
- spyware;
- malicious scripts;
- comparable malware.
This prohibition does not prevent legitimate defensive cybersecurity activity performed within an authorized environment and consistent with the Service Agreement.
13. Phishing and Credential Theft
The Service must not be used to:
- conduct phishing;
- steal credentials;
- collect passwords through deception;
- collect authentication codes through deception;
- impersonate login systems for fraudulent purposes;
- distribute credential-stealing links;
- conduct fraudulent account-recovery campaigns.
Customers must not knowingly store stolen credentials in NOVATRADE.
15. Circumvention of Security Controls
Customers must not intentionally bypass or defeat:
- authentication;
- authorization;
- rate limits;
- access restrictions;
- API controls;
- organization boundaries;
- usage limits;
- fraud-prevention controls;
- security restrictions.
This does not prevent Customers from using documented product functionality, APIs, or integrations within the scope of their agreement.
16. Organization and Account Boundaries
A Customer must access only:
- its own account;
- its own authorized organization environments;
- data the Customer is authorized to access;
- third-party environments for which valid authorization has been provided.
A Customer must not attempt to access another customer's information through:
- identifier manipulation;
- API manipulation;
- URL manipulation;
- session manipulation;
- authorization bypass;
- another technical method.
17. Excessive or Disruptive Use
Customers must not intentionally use the Service in a manner that materially degrades or disrupts the Service for others.
Prohibited activity may include:
- deliberate resource exhaustion;
- abusive automated requests;
- denial-of-service activity;
- excessive request generation intended to cause disruption;
- intentionally causing repeated infrastructure failures.
Normal high-volume legitimate business use is not prohibited merely because it uses significant resources.
NOVATRADE may contact the Customer where legitimate usage requires a different technical or commercial configuration.
18. API Use
Where API access is provided, Customers must:
- protect API credentials;
- use documented authentication methods;
- comply with applicable technical limits;
- use the API only for authorized purposes;
- restrict credentials appropriately.
Customers must not:
- publish private API credentials;
- use credentials belonging to another Customer without authorization;
- intentionally evade API controls;
- use undocumented vulnerabilities to expand API access;
- attempt to access data outside authorized scope.
19. Automated Access
Automation must be used responsibly.
Customers may use:
- APIs;
- supported integrations;
- automation functionality;
- approved technical workflows
within the permitted scope of the Service.
Customers must not use unauthorized automation to:
- scrape unrelated Customer Data;
- bypass access controls;
- evade rate limitations;
- enumerate accounts;
- probe systems;
- cause material disruption.
20. Spam
The Service must not be used to send unlawful or abusive spam.
Customers using email, SMS, or other communication functionality must comply with applicable requirements concerning:
- recipient authorization;
- consent where required;
- identification of the sender;
- marketing communications;
- unsubscribe or objection rights;
- suppression requests.
Customers must not use NOVATRADE to intentionally continue sending direct-marketing communications to a recipient after a valid applicable objection or opt-out has become effective.
21. Purchased, Harvested, and Unlawfully Obtained Contact Data
Customers are responsible for ensuring they have a lawful basis or other legal justification for contact information used through NOVATRADE.
Customers must not use the Service to conduct communications based on contact data that was:
- stolen;
- obtained through unauthorized account access;
- obtained through malware;
- collected in violation of applicable law;
- knowingly purchased from an unlawful source.
The use of legitimate business contact databases remains subject to applicable privacy and electronic-communications requirements.
22. Misleading Communications
Customers must not use NOVATRADE communication functionality to intentionally:
- impersonate another organization;
- spoof identity for fraudulent purposes;
- misrepresent the sender;
- conceal a fraudulent sender;
- send deceptive payment requests;
- send fraudulent invoices;
- falsely represent communications as being from NOVATRADE.
Legitimate use of approved domains, sender names, or customer branding is permitted where properly authorized.
23. Privacy and Personal Data
Customers must process Personal Data through the Service lawfully.
Customers are responsible for matters including:
- determining lawful purposes;
- providing required privacy notices;
- establishing required legal bases;
- respecting applicable Data Subject rights;
- controlling access to Personal Data.
Customers must not knowingly use the Service to unlawfully:
- obtain Personal Data;
- disclose Personal Data;
- sell Personal Data;
- expose Personal Data;
- monitor individuals;
- profile individuals
where the activity is prohibited by applicable law.
25. Sensitive Data
Customers must not intentionally place sensitive information into functionality that is not designed or contractually approved for that purpose.
Examples include:
- complete payment-card credentials;
- passwords;
- private authentication keys;
- government-classified information;
- highly sensitive regulated information
where the applicable NOVATRADE Service has not been approved for such processing.
Customers considering use of NOVATRADE for specially regulated data should evaluate the relevant contractual, technical, and legal requirements before doing so.
26. Intellectual Property
Customers must not use NOVATRADE to knowingly infringe:
- copyright;
- trademarks;
- patents;
- database rights;
- trade secrets;
- software licenses;
- other intellectual-property rights.
Customers must have appropriate rights to:
- documents;
- images;
- databases;
- software;
- content;
- other materials
they upload or process through NOVATRADE.
27. Unlawful Content
Customers must not knowingly use the Service to store, transmit, publish, or distribute content that is unlawful under applicable law.
Where NOVATRADE receives a legally sufficient notice, order, or other information requiring action concerning unlawful content or activity, NOVATRADE may take action required or permitted by applicable law.
NOVATRADE does not undertake a general obligation through this AUP to proactively monitor every item of Customer Data.
28. Threats and Serious Harm
Customers must not use the Service to knowingly facilitate:
- credible threats of serious violence;
- trafficking in persons;
- sexual exploitation;
- child sexual abuse;
- extortion;
- kidnapping;
- other serious criminal harm.
Where NOVATRADE becomes aware of activity requiring action under applicable law, NOVATRADE may preserve relevant records, restrict access, or cooperate with competent authorities where legally appropriate.
29. Discrimination and Harassment
The Service must not be intentionally used to conduct unlawful:
- discrimination;
- harassment;
- threats;
- targeted abuse.
This section does not make NOVATRADE responsible for determining every employment or commercial decision made by a Customer.
Customers remain responsible for ensuring that decisions made using NOVATRADE comply with applicable law.
30. Employment and Workforce Use
Where Customers use NOVATRADE for workforce administration, scheduling, performance information, or related business processes, Customers remain responsible for compliance with applicable:
- employment law;
- workplace privacy law;
- anti-discrimination law;
- working-time requirements;
- consultation obligations;
- other workforce rules.
NOVATRADE software does not independently determine whether a Customer's employment decision is lawful.
31. AI-Assisted Features
Customers may use available AI-assisted functionality for legitimate business purposes.
Customers must not intentionally use AI functionality to:
- commit fraud;
- conduct phishing;
- impersonate persons for fraudulent purposes;
- generate malicious code for unauthorized attacks;
- create deceptive transaction evidence;
- facilitate illegal activity;
- bypass security controls.
AI-generated output should be reviewed before being relied upon for material:
- financial;
- contractual;
- employment;
- legal;
- safety;
- customer-facing
decisions.
32. No Automated High-Impact Decision Assumption
The availability of automation or AI functionality does not mean NOVATRADE authorizes Customers to make every type of decision solely through automated processing.
Customers are responsible for determining whether applicable law requires:
- human review;
- additional transparency;
- a legal basis;
- an impact assessment;
- another safeguard
for their particular use.
33. Integrations
Customers are responsible for selecting and authorizing third-party integrations.
Customers must not use an integration to:
- access an account without authorization;
- extract information the Customer has no right to obtain;
- bypass third-party security;
- violate applicable third-party terms;
- conduct unlawful activity.
A Customer's authorization to use NOVATRADE does not automatically authorize use of an unrelated third-party service.
34. Third-Party Terms
Customers using third-party:
- payment services;
- communication providers;
- accounting systems;
- cloud services;
- APIs;
- integrations
must comply with applicable contractual requirements governing those services.
NOVATRADE does not authorize a Customer to circumvent a legitimate restriction imposed by a third-party provider.
35. Regulated Activities
Some Customer activities may be subject to licensing, registration, authorization, professional, industry, or regulatory requirements.
The availability of NOVATRADE software does not represent that a Customer has satisfied those requirements.
Customers are responsible for determining whether their business requires:
- a license;
- authorization;
- registration;
- professional qualification;
- regulatory approval.
NOVATRADE may request additional information or decline a use case where reasonably necessary for legal, security, contractual, or risk reasons.
36. Sanctions and Trade Restrictions
Customers must not use the Service where doing so would cause NOVATRADE to violate applicable:
- sanctions;
- export controls;
- trade restrictions;
- other binding legal restrictions.
Customers must not intentionally use false identity, routing, account, or transaction information to evade a legally applicable restriction.
37. Misrepresentation of NOVATRADE
Customers must not falsely claim that NOVATRADE:
- endorses the Customer;
- guarantees the Customer's services;
- regulates the Customer;
- licenses the Customer;
- is the Customer's employer;
- is the Customer's bank;
- is the merchant for the Customer's transactions;
- is responsible for the Customer's legal compliance
unless an applicable agreement expressly establishes the relevant relationship.
39. Account Sharing
Customers should provide individual user accounts where the Service supports individual credentials.
Customers must not share credentials in a manner that:
- defeats security;
- defeats access accountability;
- circumvents purchased-user limits;
- provides unauthorized persons with access.
Shared technical credentials may be used only where the applicable feature is designed for that purpose and appropriately secured.
40. Customer Data Integrity
Customers must not intentionally manipulate NOVATRADE records for fraudulent or unlawful purposes.
Examples include:
- fabricating service-delivery records;
- fabricating customer approvals;
- fabricating transaction records;
- backdating records for fraudulent purposes;
- altering audit-relevant information to conceal misconduct.
Legitimate correction, import, synchronization, or administrative modification of business records remains permitted.
41. Attempts Are Covered
An activity may violate this AUP even if the prohibited objective is unsuccessful.
Attempts to:
- bypass security;
- commit fraud;
- access unauthorized information;
- distribute malware;
- evade payment controls
may be treated in the same manner as completed activity where reasonably appropriate.
42. Investigations
Where NOVATRADE has a reasonable basis to suspect a material violation of this AUP, NOVATRADE may investigate the relevant activity.
An investigation may involve review of information reasonably necessary to:
- identify the account;
- understand the activity;
- determine the affected systems;
- protect the Service;
- protect other Customers;
- respond to a legal obligation;
- evaluate whether enforcement action is appropriate.
NOVATRADE does not use this section as authorization for unrestricted review of Customer Data unrelated to the suspected issue.
43. Preservation of Relevant Records
Where reasonably necessary for:
- security;
- fraud investigation;
- legal claims;
- payment disputes;
- compliance with lawful process;
- enforcement of the Service Agreement,
NOVATRADE may preserve relevant records for an appropriate period subject to applicable law and privacy requirements.
This section does not create an obligation to retain all Customer Data indefinitely.
44. Enforcement
Where NOVATRADE reasonably determines that a violation has occurred or that urgent protective action is required, NOVATRADE may take proportionate action.
Depending on the circumstances, action may include:
- contacting the Customer;
- requesting correction;
- requiring additional verification;
- restricting a particular feature;
- disabling an integration;
- revoking compromised credentials;
- restricting API access;
- removing or restricting access to unlawful material where legally appropriate;
- temporarily suspending affected access;
- terminating the Service in accordance with the applicable agreement.
NOVATRADE will seek to limit enforcement to what is reasonably appropriate to the relevant risk or violation.
45. Immediate Action
NOVATRADE may take immediate action without prior notice where delay would reasonably risk:
- material security harm;
- ongoing fraud;
- unauthorized access;
- serious unlawful activity;
- material harm to another Customer;
- infrastructure integrity;
- violation of a binding legal requirement.
Where appropriate and legally permitted, NOVATRADE will communicate with the affected Customer after urgent protective action has been taken.
46. Proportionate Enforcement
Not every violation requires termination.
Where appropriate, NOVATRADE may consider factors such as:
- seriousness;
- intent;
- duration;
- recurrence;
- affected persons;
- security impact;
- legal impact;
- Customer cooperation;
- whether the issue can reasonably be remedied.
NOVATRADE may provide an opportunity to correct a remediable issue where doing so would not expose NOVATRADE or third parties to unacceptable risk.
47. Suspension
Suspension under this AUP is governed together with the suspension provisions in the Terms & Conditions.
Where reasonably possible, a suspension should be limited to:
- the affected account;
- affected user;
- affected integration;
- affected functionality
rather than unrelated Service components.
A broader suspension may be appropriate where the relevant risk cannot reasonably be isolated.
See also: Complaints & Dispute Resolution Policy
48. Termination
Serious or repeated violation of this AUP may constitute a material breach of the applicable Service Agreement.
NOVATRADE may terminate an affected Service where permitted by:
- the Terms & Conditions;
- the applicable customer agreement;
- applicable law.
Examples of conduct that may justify termination include serious:
- fraud;
- deliberate security abuse;
- repeated unlawful activity;
- transaction laundering;
- malicious compromise of systems;
- intentional facilitation of serious crime.
49. Customer Response to Enforcement
A Customer that believes enforcement action was taken in error may contact: [email protected]
The Customer should provide:
- company name;
- relevant account;
- relevant incident or notice;
- explanation;
- supporting information.
NOVATRADE will review reasonable requests for reconsideration in good faith.
The existence of this review process does not prevent NOVATRADE from maintaining necessary protective measures while a material security or legal risk remains unresolved.
See also: Complaints & Dispute Resolution Policy
50. Reporting Abuse
Suspected abuse of NOVATRADE services may be reported to: [email protected]
Use a subject line such as: Abuse Report
Where possible, include:
- affected account or organization if known;
- relevant URL or functionality;
- description of the activity;
- relevant dates or timestamps;
- supporting information.
Do not send:
- passwords;
- complete payment-card details;
- authentication codes;
- unnecessary sensitive personal data.
51. Security Vulnerabilities
Security vulnerabilities should be reported according to the process described on NOVATRADE's Security page.
A vulnerability report is not the same as an abuse complaint.
Security testing must remain within authorized boundaries.
52. Legal Requests
NOVATRADE may respond to:
- court orders;
- binding governmental requests;
- law-enforcement requests;
- regulatory requests;
- other lawful process
where NOVATRADE is legally required or permitted to do so.
NOVATRADE will evaluate requests according to applicable law and will not knowingly disclose Customer Data solely because an informal third-party request has been made where a valid legal basis is required.
53. No General Monitoring Representation
NOVATRADE may use appropriate:
- security controls;
- abuse-prevention controls;
- logging;
- monitoring;
- investigation processes
for legitimate purposes.
However, this AUP does not represent that NOVATRADE:
- reads every Customer record;
- monitors every communication;
- reviews every transaction;
- pre-approves every integration;
- detects every policy violation.
Customers remain responsible for their own conduct and the conduct of their Authorized Users.
54. Relationship to Privacy and Data Protection
Enforcement of this AUP may involve processing information necessary to investigate:
- abuse;
- fraud;
- security incidents;
- unlawful activity;
- contractual violations.
Personal Data processed for those purposes is subject to applicable privacy and data-protection requirements.
NOVATRADE's Privacy Policy provides further information about its own processing.
Where NOVATRADE processes Customer Personal Data as a Processor, the Data Processing Agreement applies within its scope.
55. Relationship to Payment Providers
NOVATRADE may integrate with independent payment service providers.
Those providers may maintain their own:
- acceptable-use rules;
- restricted-business rules;
- payment rules;
- fraud controls;
- contractual requirements.
A Customer's compliance with this AUP does not automatically establish compliance with an independent payment provider's requirements.
Similarly, an independent payment provider's approval of a transaction does not mean that an otherwise unlawful use of NOVATRADE is permitted.
56. Relationship to the Terms & Conditions
This AUP forms part of the rules governing use of NOVATRADE.
The Terms & Conditions contain additional provisions concerning:
- accounts;
- suspension;
- termination;
- Customer responsibilities;
- prohibited use;
- liability;
- disputes.
This AUP provides more detailed rules concerning acceptable and prohibited activity.
Where a specifically negotiated agreement contains a provision concerning use of the Service, the applicable order-of-precedence provisions in the Service Agreement apply.
57. Mandatory Law
Nothing in this AUP authorizes conduct prohibited by applicable law.
Nothing in this AUP prevents NOVATRADE from taking action required by mandatory law.
Where mandatory law requires a different process for a particular enforcement, content, notice, or disclosure matter, the mandatory requirement will apply.
58. Changes to This Policy
NOVATRADE may update this AUP to reflect:
- changes to the Service;
- new abuse patterns;
- security threats;
- legal requirements;
- technical changes;
- changes to integrations.
The current version will be published on this page with its revision date.
Material changes affecting an active contractual relationship will be handled in accordance with the applicable agreement and mandatory law.
59. Contact
Questions concerning this Acceptable Use Policy may be directed to:
NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Poland
Email: [email protected]
Phone: +48 22 273 95 89
For suspected abuse, use the email subject: Abuse Report
For suspected security vulnerabilities, use the procedure described on our Security page.
- [email protected]
- PHONE
- +48 22 273 95 89