MyaGuide Acceptable Use Policy
Document: Acceptable Use Policy
Version: 1.1
Effective Date: 1 June 2026
Last Updated: 12 August 2026
1. Purpose and Scope
1.1. This Acceptable Use Policy ("AUP") sets out the rules governing access to and use of the Platform by Customer and its authorized users, and, where applicable, by End Users interacting with a Digital Guest Guide or Mya.
1.2. This AUP is incorporated into, and forms part of, the Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
1.3. Violation of this AUP may result in suspension or termination of access to the Service in accordance with Section 4.
2. Prohibited Conduct
Customer must not, and must not permit or assist any third party to:
2.1. Prompt injection and AI manipulation. Submit inputs to Mya or any other AI feature of the Platform designed to override, bypass, or manipulate the system's intended behavior, instructions, or safety controls, including attempts to extract system prompts, configuration, or other AI features' internal instructions.
2.2. Reverse engineering. Decompile, disassemble, reverse engineer, or otherwise attempt to derive the source code, underlying structure, ideas, algorithms, or non-public APIs of the Platform, except to the extent such restriction is prohibited by applicable law.
2.3. Scraping and automated extraction. Use bots, scrapers, crawlers, or other automated means to extract data, content, or functionality from the Platform, other than through officially supported and authorized integrations or APIs.
2.4. Unauthorized security testing. Conduct penetration testing, vulnerability scanning, load testing, or any other security testing of the Platform without the Company's prior written authorization. Customers wishing to report a suspected vulnerability should follow the responsible disclosure process described in the Security Policy.
2.5. Credential attacks. Attempt to gain unauthorized access to any Account or system through credential stuffing, brute-force attacks, phishing, or any other unauthorized means.
2.6. Spam and unsolicited communications. Use the Platform to send unsolicited bulk communications, or communications that violate applicable anti-spam law, to End Users or any third party.
2.7. Illegal activity. Use the Platform for any purpose that is unlawful, fraudulent, or that facilitates illegal activity, or that infringes the rights of any third party.
2.8. Cross-customer data access. Attempt to access, probe, or interfere with the Account, Properties, Guide content, or Guest data of any other customer of the Company without authorization.
2.9. API misuse. Exceed authorized rate limits, circumvent usage restrictions, or use the Platform's APIs in a manner inconsistent with their documented purpose.
2.10. Malicious automation. Deploy bots, scripts, or automated agents intended to disrupt, degrade, or gain unfair advantage with respect to the Platform's availability, performance, or fair use mechanisms.
2.11. Copyright and intellectual property infringement. Upload, submit, or transmit Customer Content, including Guide content, that infringes the intellectual property rights, including copyright, of any third party.
2.12. Harmful content. Use the Platform to generate, store, or transmit content that is defamatory, discriminatory, harassing, or otherwise unlawful, or that contains malware or other harmful code.
2.13. Circumvention. Circumvent, disable, or otherwise interfere with security-related or access-control features of the Platform, including PIN protection mechanisms for guest information.
3. Customer Obligations Regarding End Users
3.1. Customer is responsible for ensuring that its use of the Platform to communicate with End Users, including via Mya, complies with applicable law, including consumer protection and anti-spam law in the relevant jurisdiction.
3.2. Customer must not use the Digital Guest Guide or Mya to collect more End User Personal Data than is reasonably necessary to deliver the Service for the relevant stay.
4. Enforcement
4.1. The Company may investigate suspected violations of this AUP and may take action it reasonably considers appropriate, including:
(a) removing or disabling access to content;
(b) issuing a warning;
(c) suspending the Account or affected functionality; or
(d) terminating the Agreement, in the case of a material or repeated violation, in accordance with the Terms of Service.
4.2. The Company will, where reasonably practicable and not prohibited by law or a legitimate security concern, provide notice before taking enforcement action and an opportunity to remedy a violation, except in cases of urgent risk to the Platform, other customers, or third parties.
4.3. The Company may report unlawful activity to competent authorities and will cooperate with lawful requests for information in connection with a suspected violation.
5. Reporting Abuse or Vulnerabilities
5.1. Suspected violations of this AUP, or suspected security vulnerabilities, should be reported to mya@myaguide.com. Security vulnerability reports made in good faith and in accordance with the responsible disclosure process in the Security Policy will not be treated as a violation of Section 2.4.
6. Relationship to Other Documents
This AUP should be read together with the Terms of Service, the Security Policy, and the AI Policy. In the event of a conflict specific to AI-related conduct, the AI Policy prevails over this AUP to the extent of that conflict.
7. Contact
Van Riemsdijk & Karman S.L. (trading as MyaGuide)
Established in Jávea/Xàbia, Spain · NIF/VAT: ESB21983580
Legal email: mya@myaguide.com
