BEYOND ACCEPTABLE USE POLICY
Draft prepared for attorney review. Drafted 09/09/2026 against South African law. Risk rating R2. Review recommended rather than required — this policy grants Beyond rights of suspension, and clause 6 is the one that matters.
Version 1.0 · Effective 9 September 2026
This policy forms part of the Beyond Master Software Terms. It applies to the Customer and to every User the Customer gives access to. Where it uses a defined term, the definition is in those Terms.
It is short on purpose. A policy nobody reads protects nobody.
1. THE RULE UNDERNEATH ALL OF THIS
Use the Service for your own business, lawfully, and without harming anybody else who uses it. Everything below is that rule made specific.
2. YOU MUST NOT USE THE SERVICE TO
2.1 Do anything unlawful, or to help somebody else do anything unlawful.
2.2 Store, send or publish material that is unlawful, defamatory, harassing, or that infringes somebody else's intellectual property or privacy.
2.3 Store, send or publish malware, or anything designed to damage or gain unauthorised access to any system.
2.4 Send unsolicited commercial messages, in breach of section 45 of the Electronic Communications and Transactions Act 25 of 2002 or section 69 of POPIA.
2.5 Impersonate any person, or misrepresent your affiliation with any person or organisation.
3. YOU MUST NOT DO THIS TO THE SERVICE
3.1 Attempt to gain access to any part of the Service, any system supporting it, or any other customer's Workspace, that you are not authorised to access.
3.2 Probe, scan or test the vulnerability of the Service, or breach or circumvent any security or authentication measure — except under a written authorisation from Beyond, which we will generally give to a customer who asks properly.
3.3 Interfere with the Service's integrity or performance, including by overloading it, or by automated requests at a volume a person could not generate.
3.4 Copy, modify, reverse engineer, decompile or disassemble the Service, or attempt to derive its source code, except to the extent that cannot lawfully be prohibited.
3.5 Resell, sublicense, rent or otherwise make the Service available to a third party, or use it to provide a bureau or managed service to somebody else, unless we have agreed that in writing.
3.6 Use the Service to build or assist in building a competing product.
3.7 Remove or obscure any proprietary notice.
4. ACCOUNTS
4.1 Every person gets their own account. Do not share credentials, and do not create an account for a person who then hands it to somebody else.
4.2 Do not create an account for a person who has not been told that you have done so.
4.3 Tell us promptly if you believe a credential has been compromised.
5. WHAT YOU PUT IN, AND ABOUT WHOM
5.1 You must have a lawful basis under POPIA for the Personal Information you put into the Service, and you must have told the people concerned. That obligation is yours because they are your people — see clause 2 of the Operator Agreement.
5.2 Do not put Special Personal Information into the Service — health information, biometrics, race, religious or political belief, trade union membership, sexual life, or criminal behaviour — unless the Product Schedule expressly provides for it and you have a lawful basis under section 27 or an authorisation under section 28 of POPIA.
5.3 Do not put in personal information about children unless you have the consent of a competent person, as section 35 of POPIA requires.
5.4 Where the Service records employee activity, issue the monitoring notice we supply before it goes on anybody's machine. Not afterwards, and not buried in a handbook. That is a POPIA requirement and it is also the only version of this that works — monitoring people without telling them what is collected produces resentment and bad data in equal measure.
6. WHAT WE DO ABOUT A BREACH
6.1 Where the harm is to other customers or to the Service — clauses 3.1, 3.2 or 3.3 — we may suspend immediately and without notice. We will tell you as soon as we reasonably can, and why.
6.2 Otherwise we give you 7 (seven) calendar days' written notice and a chance to put it right.
6.3 Suspension is read-only and is never a lock-out. You keep access to read and export everything, including your invoices and reports. That is true even here: they are your records, and withholding them is not a sanction available to us.
6.4 Repeated or unremedied breach entitles us to terminate under clause 12.4 of the Master Software Terms.
6.5 Where we are legally obliged to report conduct to an authority, we will.
7. REPORTING A PROBLEM
If you find a security vulnerability, or believe somebody is misusing the Service, write to Info@beyondic.co.za and mark it for the attention of the Information Officer.
We will not pursue a customer who reports a vulnerability to us in good faith, does not exploit it beyond what is needed to demonstrate it, does not access another customer's data, and gives us a reasonable opportunity to fix it before telling anybody else.
8. CHANGES
This policy may be varied only by a new published version which you accept, in the manner set out in clause 18 of the Master Software Terms.
For the attorney reviewing this
- Clause 6.3. Suspension is read-only even for a serious breach. That is a deliberate commercial and ethical choice rather than an oversight, and it matches what the software actually does. Please confirm it does not weaken our position where a customer is using the Service unlawfully.
- Clause 7, the safe-harbour undertaking. Please confirm the wording is narrow enough that it cannot be read as consent to unauthorised access generally, and wide enough to be worth something to a researcher.
- Clause 3.2's carve-out for written authorisation. Confirm this does not conflict with the Cybercrimes Act 19 of 2020.
acceptable-use · v1.0 · sha256 ea172877aa866039d3d1b19e17409be45324647ea2460d8add079132cc00f1d5