Legal · Version 2.5.0 · Last updated 2026-07-26
Guest Talk acceptable use policy
This Acceptable Use Policy ("AUP") applies to every user of the Guest Talk hospitality SaaS platform and marketing website. It sits alongside the Terms of Service and the Data Processing Addendum and is incorporated into them by reference. The AUP is written to be short enough to read in one sitting, specific enough to be enforced consistently across our fleet, and honest about the kinds of behaviour that force us to suspend accounts.
1. Purpose and scope
The purpose of this AUP is to protect the guests, hoteliers, staff and infrastructure that share the Guest Talk platform. It applies to any use of the Service, including use by Customer's own employees, contractors, integration partners, and end guests interacting with Guest Talk messaging channels. Customer is responsible for ensuring that every person or system it grants access to the Service abides by this AUP.
2. Prohibited content
Customer must not use the Service to store, transmit, upload or make available:
- Illegal content of any kind, including content that infringes the intellectual property or personality rights of a third party, promotes terrorism or violent extremism, or facilitates human trafficking or the sexual exploitation of children.
- Malware, spyware, ransomware, cryptominers, botnet controllers, or any other malicious software or code.
- Unsolicited marketing communications, including bulk email, SMS or WhatsApp messages sent to guests without a valid legal basis under the ePrivacy Directive and GDPR (typically a soft-opt-in from an existing customer relationship, an explicit opt-in, or a strict transactional necessity).
- Phishing content, deceptive impersonation of Guest Talk, of a third-party brand, or of a public authority.
- Adult content in guest-facing communications, unless the accommodation itself is a lawfully-operated adult venue and Customer has enabled the corresponding workspace flag.
- Hate speech, incitement to violence, or content designed to harass an individual or group on the basis of protected characteristics.
- Personally identifiable information about third parties in fields for which it is unnecessary (for example, a comment field on a reservation is not the place to store passport numbers of unrelated persons).
3. Prohibited technical behaviour
Customer must not:
- Interfere with, circumvent or attempt to defeat the security or access controls of the Service, including rate limits, WAF rules, or authentication mechanisms.
- Access or attempt to access accounts, workspaces, data or infrastructure that are not authorised to Customer.
- Reverse engineer, decompile or disassemble the Service, except to the limited extent permitted by applicable law (for example, Article 6 of the Software Directive for interoperability).
- Conduct load testing, stress testing, penetration testing or vulnerability scanning against the Service without at least 10 business days' prior written notice to security@talkg.fabriza.org and an agreed test window; unauthorised testing may trigger automatic blocking and, where appropriate, reporting to competent authorities.
- Port-scan, network-map or otherwise enumerate the Service's infrastructure.
- Use the Service to mine cryptocurrency, run distributed compute workloads unrelated to hospitality operations, or otherwise consume compute or storage disproportionately relative to Customer's Subscription Term commitments.
- Automate the creation of accounts or workspaces to circumvent seat or workspace pricing.
- Use the API in a manner that materially degrades service for other customers, including bursting past the published rate limits or issuing pathological queries designed to trigger denial-of-service.
- Attempt to identify or de-anonymise the aggregate metrics we publish.
4. Guest communication rules
The messaging module makes it easy to reach guests across email, SMS, WhatsApp Business, and app-native chat. With that reach comes responsibility.
- Legal basis. Customer must ensure a valid legal basis under the ePrivacy Directive, GDPR, the CAN-SPAM Act (for US recipients), and any other applicable law for each message sent. Guest Talk exposes template categories (transactional, service, opt-in marketing) to help route messages against the correct legal basis, but the ultimate responsibility rests with Customer.
- Frequency caps. Guest Talk enforces platform-level frequency caps of five automated messages per guest per stay by default. Customers may adjust upward with documented business justification but must not exceed cadence patterns known to be considered nuisance messaging by national supervisory authorities.
- Opt-out. Opt-out signals from guests (STOP, unsubscribe, WhatsApp block) must be honoured within 24 hours; the platform propagates opt-outs automatically to the relevant guest profile.
- Quiet hours. Automated non-emergency messages are suppressed by default between 21:00 and 08:00 in the recipient's local time. Customers may override the suppression for genuinely urgent operational messages (for example, room-move notifications during a fire alarm) but not for marketing content.
- Sender identity. Sender name, business name and reply channel must accurately identify the accommodation. Impersonating another business, an OTA, or a public authority is prohibited.
- Content of automations. Marketing automations must include a clear opt-out mechanism per applicable law; the WhatsApp Business API templates provided by Guest Talk are pre-approved with the correct opt-out language for the recipient's country.
5. Data protection duties
Customer acts as controller for the personal data it uploads and processes in the Service. Customer must (a) maintain its own privacy notice covering the processing carried out through the Service, (b) obtain any consents required from data subjects, (c) implement data minimisation (do not upload categories of personal data you do not need), and (d) honour data subject rights requests received from its guests. Guest Talk supports Customer with the assistance obligations set out in the DPA.
6. Fair usage
Guest Talk pricing includes generous soft limits so that customers do not need to count individual messages. The default soft limits are:
- 50,000 outbound messages per month per property across email, SMS and WhatsApp combined.
- 10,000 API requests per minute per workspace on the read plane, 1,000 per minute on the write plane, with burst allowances of 3x for 30 seconds.
- 10 GB of file storage per property (photos, PDFs, guest documents).
- 5 concurrent OTA channel connections per property; additional channels available on request.
Customers whose usage exceeds these limits will be contacted with an enterprise pricing proposal before any throttling or overage charge. Sustained usage above 3x the soft limit without contact from Customer may trigger automatic throttling.
7. Reporting abuse
To report suspected abuse of the Guest Talk service by another customer, or to report a security concern, email abuse@talkg.fabriza.org. We aim to acknowledge every abuse report within one business day and to provide a substantive response within five business days. Reports may be submitted anonymously; where a report identifies the reporter, the reporter's identity is kept confidential unless disclosure is required by law.
8. Enforcement
Guest Talk investigates suspected AUP violations internally through a documented process. Depending on severity, the following remedies are available:
- Warning. A written notice describing the alleged violation and requiring corrective action within a specified period (typically 10 business days).
- Partial suspension. Suspension of specific features (for example, the messaging module) pending investigation.
- Full suspension. Suspension of workspace access, with Customer Data preserved and export available.
- Termination for cause. Termination under the Terms of Service in the case of material, uncured breach or severe violation.
- Referral. Referral to competent authorities where required by law (for example, for suspected child sexual abuse material).
Except in cases of urgent security risk or where mandated by law, Guest Talk provides written notice and an opportunity to be heard before imposing suspension or termination.
9. Appeals
Customers subject to an enforcement action may appeal in writing to legal@talkg.fabriza.org within 30 days. Appeals are reviewed by a member of the Guest Talk leadership team who was not involved in the original decision. The reviewer will respond within 15 business days with a decision to uphold, modify or reverse the action.
10. Coordination with law enforcement
Guest Talk cooperates with lawful requests from competent authorities under a strict process: (a) requests must be in writing and specify the legal basis; (b) requests are reviewed by legal counsel; (c) where legally permissible, Guest Talk notifies the affected Customer before disclosing personal data; (d) Guest Talk publishes an annual transparency report summarising the number and type of requests received.
11. Changes and version history
We may update this AUP from time to time. Material changes will be notified by email to workspace administrators at least 15 days in advance.
- v2.5.0 (2026-07-26) — codified fair usage soft limits; expanded guest communication rules to include quiet hours and sender identity; added coordination with law enforcement section.
- v2.4.0 (2026-03-01) — added crypto-mining and unauthorised load testing prohibitions.
- v2.3.0 (2026-01-15) — separated appeal process from enforcement path.
12. Integration partners and re-sellers
Where Customer integrates third-party software with the Service via the Guest Talk API or webhook system, Customer is responsible for the acts and omissions of that integration to the same extent as its own. Integration partners must respect the rate limits, authentication requirements and content prohibitions of this AUP. Guest Talk maintains a partner directory at /integrations; listing in that directory does not constitute a warranty by Guest Talk of the partner's compliance with this AUP.
Resellers of Guest Talk (typically boutique consultancy firms bundling the platform with implementation services) are subject to a separate reseller agreement that includes additional obligations around end-customer identification, dispute escalation and transparency of pricing. This AUP applies to end customers regardless of the sales channel through which they were acquired.
13. Guest data and honest disclosure
Customer must be honest with its own guests about the presence and role of the Service. Where a guest enquires whether their message is answered by a human or by an automation, Customer must answer truthfully; the Service should not be deployed to deceive guests as to whether they are speaking with a person. Customer may of course brand the messaging channels as its own hotel; that is not deception, that is white-labelled software working as designed.
Where Customer uses the Service to run guest surveys, incentives to leave positive reviews on public OTA platforms in a manner that violates the OTA's guest policy are prohibited. Guest Talk provides a template library of review-request messages that complies with Booking.com, Expedia, Airbnb and Google Reviews policies as they stood at the time of publication; if Customer modifies a template to a form that violates those policies, Customer bears the risk of enforcement by the OTA against the property.
14. Automation and machine learning
Guest Talk provides optional automation and machine-learning features (for example, sentiment-flagged inbox routing and language auto-detection). Customer must not use these features to make consequential decisions about individual guests (for example, refusing to accept a booking) without human review. The Guest Talk AI features are decision-support, not decision-makers, and their limitations must be respected. Customer must not train third-party models on Guest Talk output in a manner that would breach the intellectual property or confidentiality provisions of the Terms of Service.
15. Contact
Abuse reports: abuse@talkg.fabriza.org. Security disclosures: security@talkg.fabriza.org. Legal correspondence: legal@talkg.fabriza.org. Postal: Guest Talk OU, Sepapaja tn 6, 15551 Tallinn, Estonia.