Legal documents › ViaVela Bona
ViaVela Acceptable Use Policy (AUP)
ViaVela Acceptable Use Policy (AUP)
DRAFT — for U.S. (Nebraska) counsel review. Not legal advice and not final. Have a licensed Nebraska attorney review before publishing. This AUP is referenced by and incorporated into the EULA, Subscription Agreement, Pilot Agreement, and Terms of Service. Company master (2026-09-05). Product-specific terms are supplied by the Product Schedule named in the Order; jurisdiction riders (Puerto Rico) are applied by
jurisdictions/PR.md. Attorney review required before use.
Last updated: 2026-07-10
This Acceptable Use Policy (the "AUP") governs how everyone who accesses or uses the ViaVela platform (the "Services") — including the Product's staff-facing and personnel-facing applications, the end-user-facing experience, and the relay/sync services — may use them. It is part of the contract under which you access the Services.
For Bona, the Services comprise the property-management company's office workspace (staff-facing), the maintenance-technician portal (personnel-facing), the owner and resident portals (end-user-facing), and the relay/API services.
We may update this AUP from time to time; the version in force when you use the Services applies to that use.
1. Who this applies to
- Customers that subscribe to or pilot the Services. "Customer" means the business that subscribes to the Product and that you deal with — a salon, a property-management company, a landscaping company, a clinic, or a repair shop, as identified in the applicable Product Schedule. "Product" means the ViaVela software application(s), surfaces, and features identified in the Product Schedule named in the applicable Order.
- Owners, managers, technicians, and other staff who sign in to the Services on behalf of a Customer.
- End Users (the Customer's clients / guests) who use the public end-user-facing experience.
2. Prohibited conduct
You may not, and may not encourage or allow anyone else to:
2.1 Misuse the Services
(a) Access the Services other than through the documented user interfaces or authorized APIs. (b) Attempt to gain unauthorized access to any account, system, network, or data — including by guessing credentials, replaying authentication tokens, exploiting vulnerabilities, or circumventing rate limits or lockouts. (c) Tamper with, disable, or attempt to circumvent the licensing, plan-gating, audit-logging, MFA, account-lockout, session-timeout, CSP, CORS, or any other security or usage-metering mechanism. (d) Probe, scan, or test the vulnerability of the Services without ViaVela's prior written authorization (see Section 5 for the responsible-disclosure channel). (e) Reverse engineer, decompile, disassemble, or attempt to derive the source code of the Services, except to the extent applicable law expressly permits this despite a contractual restriction. (f) Use the Services to build, train, or improve a competing product.
2.2 Misuse data
(a) Process Personal Data through the Services in violation of applicable data-protection law, the Privacy Policy, or any required consents. (b) Use the Services to collect, store, or process payment-card data outside the documented integrations (the Services do not store full PAN or CVV; attempts to enter such data into free-text fields are a breach of this AUP). (c) Mass-export client or staff data beyond what is reasonably needed for the Customer's own business operations or a lawful data-subject request. (d) Use the Services to send unsolicited marketing, spam, or messages that violate the TCPA, CAN-SPAM Act, or similar consumer-protection laws.
2.3 Harm the Services or other users
(a) Interfere with or disrupt the Services, the relay, or any third-party service or network connected to the Services. (b) Submit content or instructions designed to overload, crash, or degrade the Services, including denial-of-service patterns, infinite loops, or unbounded recursive queries. (c) Upload, transmit, or store malware, viruses, trojans, or any code or content intended to damage or surveil any system, including the devices of other users. (d) Submit content that is unlawful, defamatory, harassing, threatening, infringing, or invades another person's privacy. (e) Impersonate any person or entity, or misrepresent your affiliation with a Customer or with ViaVela.
2.4 Misuse commercial features
(a) Use one tenant's per-tenant access credentials to access, modify, or read data of another tenant.
(a) Bona has no separate technician-app or salon-key credential. Use the company-scoped session established at staff, owner, resident, or technician sign-in — enforced by structural company-scoping on every read and by-id access — to access, modify, or read data belonging to a different property-management company.
(b) Share staff or owner sign-in credentials, or use one staff account as a shared role account, except as ViaVela's documentation explicitly allows. (c) Use the Product's booking, request, payment, or checkout features to facilitate unlawful goods or services, money laundering, or tax evasion. (d) Use the messaging features to send communications you are not authorized to send under the TCPA or the CAN-SPAM Act.
(d) Use the messaging features (in-app message threads; Bona has no SMS capability) to send communications you are not authorized to send under the TCPA or the CAN-SPAM Act.
2.5 Tamper with payments and audits
(a) Forge, alter, or back-date sales, refunds, voids, payments, payroll figures, or audit-log entries. (b) Delete or edit audit-log entries through any unintended path. (c) Use the cash-tender or card-payment flow to record amounts you did not actually collect, or to disguise payment activity.
3. Responsibilities
3.1 The Customer is responsible for the acts and omissions of its staff and authorized end users when they use the Services on its behalf.
3.2 The Customer must keep its sign-in credentials, MFA devices, and per-tenant access credentials confidential and rotate them when staff turn over (see security/key-rotation-playbook.md).
3.3 Each user must promptly notify the Customer (and, where appropriate, ViaVela) of any suspected unauthorized use, compromised credential, or data incident.
4. Enforcement
4.1 If ViaVela reasonably suspects a violation of this AUP that creates an imminent risk to the security of the Services or to other users, ViaVela may immediately suspend the affected account, tenant, per-tenant access credential, device token, or pay-link, and will notify the Customer as soon as practicable.
4.2 For violations that do not require immediate suspension, ViaVela will typically notify the Customer first and give a reasonable opportunity to cure (unless prohibited by law or the cure period would harm others).
4.3 ViaVela may report violations to law-enforcement authorities, payment processors, or telecommunications providers as required by law or where necessary to protect rights and safety. ViaVela will cooperate with lawful investigations.
4.4 Repeated or material violations are grounds for termination of the Principal Agreement under its termination provisions.
5. Reporting vulnerabilities and abuse
5.1 Security vulnerabilities — please report to security@viavelahq.com. ViaVela's vulnerability-management process and severity SLAs are in security/vulnerability-policy.md. Please do not exploit the vulnerability beyond what is necessary to demonstrate it.
5.2 Abuse, messaging complaints, or other AUP violations — please report to legal@viavelahq.com.
5.3 Privacy or data-subject requests — please contact the Business you deal with directly (the Business is the controller of its own records). Platform-level questions go to legal@viavelahq.com.
6. Examples
These examples are illustrative, not exhaustive. The general principle is: use the Services for their intended business purpose, do not undermine their security or the trust of other users, and comply with applicable law.
- ✅ A Customer owner exports a CSV of their own clients to import into accounting software.
- ✅ A staff member signs out of a shared or personal device at the end of their shift.
- ✅ An End User books a real appointment or submits a real request with their own name and contact details.
- ❌ A third-party scraper iterates the public end-user experience to enumerate staff names, services, or schedules across many Customers.
- ❌ A staff member uses another staff member's PIN to clock in.
- ❌ A Customer repurposes transactional reminder messages to send marketing offers to contacts harvested elsewhere.
- ❌ A user pastes credit-card numbers into a free-text notes field.
7. Reservation
This AUP does not limit any other rights ViaVela has under the Principal Agreement, the Privacy Policy, or applicable law. ViaVela may add, change, or remove specific examples and details at any time without notice; the core prohibitions in Section 2 remain in force.
© 2026 ViaVela Solutions LLC. All rights reserved.