What this means in plain language.
Wendesk के जिम्मेदार उपयोग के नियम — anti-spam, WhatsApp Business नीति, voice-agent सहमति आवश्यकताएं, marketplace seller आचरण, और प्रतिबंधित उद्योग। उल्लंघन से निलंबन हो सकता है।
TL;DR — संक्षिप्त संस्करण।#
- उन लोगों को message न करें जिन्होंने opt in नहीं किया। WhatsApp, SMS, email, voice — सभी।
- Wendesk का उपयोग धोखाधड़ी, ठगी, या उत्पीड़न के लिए न करें। Phishing, scams, deepfakes, harassment campaigns — account बंद, evidence preserved।
- CSAM, terrorism, और इसी तरह की content तुरंत termination trigger करती है और relevant authority को report की जाती है। कोई warning नहीं, कोई cure period नहीं।
- कुछ industries को licences की आवश्यकता होती है (gambling, pharma, financial services, alcohol)। यदि आप ऐसे क्षेत्र में काम करते हैं, तो हम documentation मांगते हैं।
- AI और voice agents के अतिरिक्त नियम हैं। Consent के बिना real people की नकल के लिए कोई deepfakes, कोई robocalls नहीं।
- यदि कुछ गलत है, तो [email protected] पर लिखें। हम 24 घंटों में acknowledge करते हैं, 72 में action लेते हैं।
1. Scope और यह किस पर लागू होता है#
यह Acceptable Use Policy ("AUP") यह govern करती है कि Wendesk को छूने वाले हर पक्ष को कैसे behave करने की अनुमति है। यह workspace owner ("आप", "Customer"), उनके द्वारा invite किए गए हर staff member, उनके द्वारा बनाई गई हर custom role, Wendesk के माध्यम से उनके द्वारा message किए गए हर end-user, और Customer के account के तहत Wendesk Marketplace पर publish किए गए हर storefront को bind करती है। Terms of Service की स्वीकृति इस AUP को reference द्वारा शामिल करती है; effective date के बाद platform के किसी भी भाग का उपयोग तब force में version से agreement constitutes करता है।
AUP हर Wendesk surface और सात solutions में से हर एक पर apply होती है: CRM, WhatsApp Growth Hub, Content Studio, Social Sharing, Marketplace, AI Voice Agent, और Email Marketing। यह चाहे activity web dashboard, WhatsApp Brain command surface, public storefront, App Store के माध्यम से integration, या mcp.wendesk.com के माध्यम से connecting Model Context Protocol client से originate हो — apply होती है।
जहाँ कोई stricter नियम किसी sector-specific addendum में exists करता है (उदाहरण के लिए, healthcare workspace के लिए Business Associate Agreement, या GDPR referencing data-processing addendum), वह stricter नियम उस activity के लिए controls करता है जिसे वह cover करता है। जहाँ कोई conflict नहीं है, दोनों apply होते हैं।
2. Prohibited content#
निम्नलिखित content Wendesk पर forbidden है, चाहे इसे कैसे, कहाँ, या किसके लिए create, store, send, या display किया गया हो। इसमें से किसी का भी detection — हमारे द्वारा, sub-processor द्वारा, या credible report द्वारा — immediate suspension और, जहाँ applicable हो, relevant authority को mandatory disclosure में result करता है।
- Child sexual abuse material (CSAM). Zero tolerance। Detection immediate account termination, evidence preservation, और National Center for Missing & Exploited Children (NCMEC), India के National Cyber Crime Reporting Portal, और किसी अन्य competent authority को reporting trigger करता है।
- Minors से जुड़ी sexual content किसी भी form में, जिसमें written depictions, AI-generated imagery, या identifiable minors के sexualised cartoons शामिल हैं।
- Terrorism या violent extremism को promote, incite, या glorify करने वाली content, जिसमें recruitment material, beheading या attack videos, और designated terrorist organisations के लिए propaganda शामिल है।
- किसी identifiable व्यक्ति, group, या location के विरुद्ध violence या imminent harm incite करने वाली content।
- Hate speech race, caste, religion, ethnicity, nationality, sexual orientation, gender identity, disability, या operative jurisdiction में अन्य protected characteristics के आधार पर लोगों को target करना।
- Doxxing — subject की consent के बिना और harassment का इरादा या effect रखते हुए private personal information (home address, phone number, government identifier, financial account details, real-time location) publish करना।
- Non-consensual intimate imagery ("revenge porn"), जिसमें consent के बिना create या distribute की गई real people की deepfaked pornographic imagery शामिल है।
- Deceive करने के लिए designed synthetic media — deepfaked audio, video, या text इस तरह publish या send किया गया जो recipient को यह believe करा सके कि यह किसी real person का genuine speech या conduct है, बिना clear और contemporaneous disclosure के कि यह synthetic है।
- Third-party intellectual-property rights का उल्लंघन करने वाली content — licence या अन्य lawful basis के बिना उपयोग किए गए copyrighted works, trademarks, या trade secrets। Repeat infringers को section 12 में procedure के तहत terminate किया जाता है।
हम इसे इतने स्पष्ट रूप से क्यों list करते हैं: क्योंकि messaging platforms scale पर पहुँचते ही internet की सबसे बुरी चीजों के लिए magnet बन जाते हैं। ऊपर की list discouragement नहीं है — यह floor है। यदि आपका business model इनमें से किसी पर निर्भर करता है, तो Wendesk गलत platform है।
3. Prohibited uses#
ऊपर content rules से independent, Wendesk के निम्नलिखित uses forbidden हैं:
- Unsolicited bulk messaging (spam). WhatsApp, SMS, email, या voice पर opt-in basis के बिना cold messaging Meta की WhatsApp Business Policy, India के TRAI Telecom Commercial Communications Customer Preference Regulations, US CAN-SPAM Act, और EU ePrivacy Directive का उल्लंघन करती है। हम इसे host नहीं करते।
- Phishing और credential harvesting. कोई messages या pages नहीं जो credentials, OTPs, या payment details extract करने के उद्देश्य से banks, government agencies, well-known brands, या individuals की नकल करते हों।
- Fraud और scams. Investment scams, advance-fee fraud, romance scams, fake-job scams, fake-courier scams, "task-based" earning schemes, और इसी तरह का deception।
- Pyramid schemes और unlawful multi-level marketing. Compensation structures जो primarily recruitment के लिए pay करते हैं न कि real product या service की sale के लिए, चाहे उन्हें कैसे भी frame किया गया हो — prohibited हैं।
- Money laundering, terrorism financing, और sanctions evasion. Wendesk major sanctions lists के खिलाफ screen करता है; उन्हें circumvent करने के लिए platform का उपयोग करने का प्रयास hard violation है।
- Unauthorized scraping या crawling Wendesk के web surfaces, अन्य tenants के public storefronts, या Wendesk के outbound network के माध्यम से किसी third-party site का।
- Reverse-engineering, decompiling, या weights या training data extract करने का प्रयास Wendesk के machine-learning models, prompt scaffolding, या proprietary algorithms से।
- Resale या sub-licensing Wendesk seats, AI quota, voice minutes, या messaging credits का उन parties को जो आपके Terms-of-Service contract से bound नहीं हैं, सिवाय तब जब आप separate written agreement के तहत authorised reseller या partner के रूप में operate करते हों।
4. WhatsApp obligations#
WhatsApp वह primary channel है जिसके आसपास Wendesk बना है। हर workspace जो WhatsApp number connect करता है — चाहे Meta के Cloud API ("Mode B") के माध्यम से या Baileys-based personal-account integration ("Mode A") के माध्यम से — Meta की WhatsApp Business Messaging Policy, WhatsApp Commerce Policy, और नीचे के नियमों का पालन करना होगा। ये obligations section 3 में prohibited-uses list के ऊपर layered हैं।
- Opt-in mandatory है। किसी number को पहला business-initiated message send करने से पहले, recipient ने उस specific business से WhatsApp पर messages के लिए Customer को clear, recorded, और demonstrable opt-in दिया होना चाहिए। Pre-checked boxes, phone-book scrape से "implied" consent, और lead-list purchases qualify नहीं होते।
- Opt-out हर जगह honored होना चाहिए।
STOP,UNSUBSCRIBEके replies, Wendesk के सात supported vernaculars में से किसी का equivalent, या WhatsApp "Block" action उसी workspace से उस number पर आगे outbound messaging permanently रोक देता है। Re-engagement के लिए fresh opt-in आवश्यक है। - Template messages approved होने चाहिए। 24-hour customer-care window के बाहर outbound messages को Meta द्वारा submitted और approved templates का उपयोग करना होगा। Template field के माध्यम से non-approved utility/marketing message send करना template rejection force करता है और workspace की quality rating को degrade करता है।
- Quality rating healthy रहनी चाहिए। Meta हर WhatsApp number को user blocks, reports, और message-delivery behaviour के आधार पर Green / Yellow / Red scale पर score करता है। Sustained Yellow rating एक Wendesk warning + template-send rate-limit trigger करती है; Red rating workspace के Green पर continuous 7-day window के लिए recover होने तक bulk dispatch की immediate suspension trigger करती है। Workspace पर Persistent Red section 11 के तहत termination ground है।
- Template categorisation honest होनी चाहिए। Meta templates को Marketing, Utility, या Authentication के रूप में classify करता है; pricing per category और per market अलग होती है। Cost dodge करने या opt-in scrutiny से बचने के लिए Utility या Authentication template के तहत marketing message submit करना misclassification है और section 11 के तहत termination ground है।
- 24-hour customer-care window discipline. Free-form messages केवल उस recipient को भेजे जा सकते हैं जिसने पिछले 24 घंटों में Customer को message किया हो; उस window के बाहर, केवल approved templates apply होते हैं। Platform यह API पर enforce करता है; timer को circumvent करना (जैसे Mode-A personal-account session पर piggy-backing करके) prohibited है।
- Non-opted-in numbers पर कोई broadcasts नहीं। Contact list import करके उसे blast करना textbook violation है। Wendesk के bulk-messaging tools recorded consent timestamp के बिना numbers पर dispatch करने से मना करते हैं।
- Mode A (personal-account QR) एक explicit risk-accept carry करता है। Baileys के माध्यम से connect करने पर आपका personal WhatsApp account उपयोग होता है; Meta उस number को अपने sole discretion पर rate-limit या ban कर सकता है। Setup पर "I accept the risk" checkbox
BusinessXIntegration.modeAriskAcceptedAtमें recorded है और workspace को bind करता है।
5. Restricted industries और compliance#
पाँच regimes हमारे और tenant के बीच shared duties carry करते हैं। नीचे का block summarize करता है कि हम क्या करते हैं और आपको क्या करना होगा। इस section का शेष भाग DPDP / GDPR baseline से परे हम जो industries restrict करते हैं उन्हें cover करता है।
उद्योग-विशिष्ट दायित्व।
Wendesk 38 उद्योगों की सेवा करता है। नीचे के पाँच नियम हमारे और tenant के बीच विशिष्ट साझा कर्तव्यों को ट्रिगर करते हैं।
| उद्योग | व्यवस्था | Wendesk क्या करता है | आपको क्या करना चाहिए |
|---|---|---|---|
| Real Estate | RERA | RERA project-ID storage, audit log, disclosure templates | Register your project; we don't list on your behalf |
| Food & Beverage | FSSAI | Allergen schema, expiry tracking, label fields | Display your FSSAI licence number on storefront |
| Pharma | CDSCO | Schedule H / H1 / X gating in marketplace; auto-block Schedule X self-fulfilment | Verify retailer licence; upload prescription proof when required |
| Healthcare | HIPAA | BAA on request; PHI auto-redaction before AI inference; 6-year audit retention | Sign BAA; mark PHI fields; obtain patient consent |
| E-commerce / Financial / Insurance | PCI-DSS | No card storage in our systems; card data tokenised by Razorpay; we hold token reference only | Don't paste card data into chat; train staff on PCI scope |
कुछ industries categorically banned नहीं हैं लेकिन restricted हैं: हम उन्हें केवल prior written approval और operative jurisdiction में relevant licensing, age-gating, और advertising rules का compliance दिखाने वाले ongoing documentation के साथ permit करते हैं। List common payment-processor restricted-business categories (Razorpay, Stripe, और similar) से draw करती है और नए edge cases encounter होने पर update होती है।
- Gambling, fantasy sports, और skill-based wagering — केवल relevant state/national licence के साथ (जैसे India में Sikkim या Nagaland licensing, UKGC, MGA, NJDGE, आदि)। Minors को या उन states को जहाँ activity illegal है, कोई promotion नहीं।
- Adult-oriented services — केवल legal, properly age-gated content के लिए permitted; minors, non-consenting adults, या trafficking depicting content के लिए कभी नहीं।
- Firearms, ammunition, और weapons accessories — केवल licensed dealers के माध्यम से अपने jurisdiction में operating; restricted weapons की civilian sales या जहाँ item unlawful हो वहाँ delivery के लिए कभी नहीं।
- Tobacco, vaping, alcohol, और cannabis — jurisdiction-dependent। Cannabis जहाँ unlawful हो वहाँ prohibited; regulated markets में appropriate licensing के साथ permitted। Alcohol और tobacco को age verification की आवश्यकता है और minors को advertise नहीं किया जा सकता।
- Pharmaceuticals और prescription products — केवल valid prescriptions वाले licensed pharmacies/practitioners के माध्यम से; India में CDSCO और Schedule H/H1/X compliance mandatory है। Prescription के बिना prescription medication की direct-to-consumer sale forbidden है।
- Financial services — lending, payments, foreign exchange, securities, insurance, और crypto को appropriate licence की आवश्यकता है (India में RBI/SEBI/IRDAI; equivalents elsewhere)। Unregulated lending और "shadow" forex platforms prohibited हैं।
- Multi-level marketing और direct-selling. केवल तब permitted जब India के Direct Selling Rules 2021 (या equivalent) के तहत registered हो, real product, real returns policy, और ऐसा compensation plan हो जो primarily recruitment-driven नहीं है।
- "Get-rich-quick", crypto-trading-courses, और signal services. केवल verifiable credentials, historical results के full disclosure, और clear risk warnings के साथ permitted। Returns की guarantees automatic decline हैं।
- Political campaigning और referendum content. Funding entity के disclosure और relevant jurisdiction के Election Commission के नियमों के भीतर permitted; voters को suppress या disenfranchise करने के लिए designed content के लिए prohibited।
Approval कैसे काम करता है: Restricted-industry workspaces signup पर या live जाने से पहले supporting documentation (licence, certification, partnership letter) upload करते हैं। Approval workspace के खिलाफ recorded होती है; sensitive features (जैसे mass WhatsApp dispatch, voice campaigns) approval आने तक disabled रहते हैं। Underlying licence वापस लेने पर approval समाप्त होती है; workspace standard restricted-industry block पर return करता है।
6. AI restrictions#
Wendesk के AI features — WhatsApp Brain, Magic Fields, Content Studio drafts, agentic workflow runs, lead-qualification scoring, voice-agent transcripts — useful या harmful outputs की ओर steer किए जा सकते हैं। इस section के नियम ऊपर के हर section के ऊपर apply होते हैं और identically apply होते हैं चाहे call हमारे included quota, Enterprise overage line, या tenant के bring-your-own-key (BYOK) provider का उपयोग करे।
- कोई mass-produced misinformation नहीं — fabricated news articles, doctored quotes, fake reviews, fake testimonials, manufactured "case studies", या astroturfing campaigns।
- Deceive करने के लिए कोई deepfakes नहीं। किसी real person की recorded consent के बिना voice cloning, statements attribute करने के लिए video face-swaps, या identifiable people की ऐसी photorealistic imagery जहाँ वे कभी नहीं थे — सभी prohibited।
- कोई spam, phishing, scam, या harassment scaffolding नहीं। Thousands of personalised cold messages, phishing pages, scam scripts, या harassment campaigns draft करने के लिए Wendesk AI feature का उपयोग violation है, चाहे messages वास्तव में हमारे channels के माध्यम से send हों या नहीं।
- कोई NSFW या sexually explicit generation नहीं। Wendesk के AI guardrails इसे refuse करते हैं; उन guardrails को bypass करने के लिए jailbreaks का प्रयास (prompt injection, role-play exploits, encoded payloads) अपने आप में violation है।
- कोई unauthorised impersonation नहीं। AI-generated content जो किसी real, identified person को अपनी capacity में बोलते हुए pretend करती है, उनकी documented consent की आवश्यकता है।
- कोई model extraction नहीं। Training data, embeddings, system prompts, या scaffolding logic reconstruct करने के लक्ष्य से Wendesk के models को probe करना violation है। Standard product use, जिसमें आपके plan limits के भीतर scripted use शामिल है, fine है।
- Healthcare workspaces — कोई भी prompt third-party model तक पहुँचने से पहले PHI auto-redacted है। उस redaction को disable या evade करना prohibited है। PHI context वैध रूप से require करने वाले prompts के लिए on-platform self-hosted Llama route का उपयोग करें।
7. Voice agent restrictions#
Voice Agent (early access) हमारे smart router के माध्यम से eight regulated telephony providers में से एक के माध्यम से automated outbound और inbound calls करता है। Voice platform पर सबसे heavily-regulated channel है; नीचे के नियम non-negotiable हैं और applicable regimes में सबसे strict reflect करते हैं।
- Outbound automated calls के लिए recipient consent mandatory है। India के TRAI National Customer Preference Register (NCPR), US Telephone Consumer Protection Act (TCPA), EU ePrivacy Directive, और किसी भी market में equivalents का पालन करें।
- Do-not-call (DND) numbers पर कोई calls नहीं उस existing-business-relationship exemption के बाहर जो properly recorded और verifiable हो।
- Caller-ID honest होना चाहिए। उन numbers को spoof करना forbidden है जो आप own या control नहीं करते। किसी भी circumstance में bank, government, या emergency-service numbers को spoof करना forbidden है।
- Calling-window discipline. Outbound campaigns recipient के local time-of-day rules का सम्मान करते हैं — India में, 09:00–21:00 IST के बाहर generally prohibited है; US में, TCPA के तहत 08:00–21:00 local time के बाहर prohibited है।
- Voice cloning के माध्यम से real individuals की कोई impersonation नहीं उस individual की recorded consent के बिना। Voice-agent persona को call की शुरुआत में automated के रूप में identify किया जाता है जब recipient पूछता है।
- कोई harassment या threatening calls नहीं। "Do not contact" reply के बाद उसी recipient को repeat-call escalation, abusive debt-collection scripts, legal action की threats जो actually pursue नहीं किए जा रहे, या किसी भी intimidate करने के लिए designed call — prohibited हैं।
- Privacy Policy के अनुसार Recordings handled. जहाँ law (जैसे sensitive calls के लिए India की two-party consent expectation) require करे वहाँ call की शुरुआत में recipient को inform किया जाना चाहिए। Recordings encrypted at rest हैं और workspace के retention setting के अनुसार retain की जाती हैं (default 90 days; healthcare के लिए 6 years)।
8. Marketplace storefront restrictions#
www.wendesk.com/m/store/[tenantSlug] के तहत Wendesk Marketplace पर publish किए गए Storefronts public commerce surfaces हैं। वे internal CRM data की तुलना में stricter content bar के अधीन हैं और इस AUP और transactions handle करने वाले payment processor के नियमों दोनों का पालन करना होगा।
- Products को हर jurisdiction के laws का पालन करना होगा जहाँ वे listed हों या shipped हों। Customer उन products को block या geo-restrict करने के लिए responsible है जहाँ उन्हें lawfully नहीं बेचा जा सकता।
- कोई counterfeit या replica goods नहीं। ऐसे items जो licence के बिना third party के brand, design, या trade dress copy करते हैं, detection या report पर remove किए जाते हैं।
- कोई stolen goods, recovered-from-crime goods, या doubtful provenance items नहीं (जैसे export documentation के बिना cultural artefacts)।
- कोई controlled substances नहीं section 5 में licensed-pharmacy carve-out के बाहर।
- Honest descriptions और honest pricing. Pricing tricks — fake "was" prices, hidden mandatory fees, drip-pricing — एक warning के बाद takedown trigger करेंगे। Prices को mandatory taxes inclusive होनी चाहिए जहाँ law require करे (जैसे consumer-facing pricing पर India GST)।
- Truthful imagery. Stock photos representative purposes के लिए use किए जा सकते हैं लेकिन listing clearly disclose करनी चाहिए जब actual item colour, finish, या grade में imagery से differ करे।
- Returns, refunds, और dispute paths storefront पर published होने चाहिए और Consumer Protection Act 2019 (India) या buyer की jurisdiction में equivalent regime का पालन करना होगा। Wendesk platform है; Customer seller of record है।
9. Security और integrity#
Wendesk की security posture हमारे और हमारे customers के बीच boundary दोनों directions में intact रहने पर depend करती है। निम्नलिखित forbidden हैं:
- Denial-of-service attacks — volumetric, application-layer, या slowloris-style — किसी Wendesk endpoint या Wendesk workspace से किसी third party के विरुद्ध।
- Brute-force या credential-stuffing Wendesk login surfaces या Wendesk के माध्यम से access किए गए third-party services के विरुद्ध।
- Prior written permission के बिना Penetration testing या vulnerability research. /security पर coordinated disclosure programme का उपयोग करें — हम पहले email मांगते हैं; consent के बिना testing India के IT Act और elsewhere के equivalent statutes के तहत unauthorised access है।
- Discovered vulnerability का exploiting उसे report करने के लिए आवश्यक minimum proof से परे। "Exfiltrate first, report later" malicious access के रूप में treated है।
- API keys, JWTs, OAuth tokens, या workspace secrets को share करना public repositories, public chat channels, या किसी भी ऐसी जगह जहाँ unauthenticated third party उन्हें read कर सके। Leaked credentials revoke किए जाते हैं; Customer leak और revocation के बीच किसी भी usage के लिए responsible है।
- Third parties पर attack के लिए Wendesk infrastructure का उपयोग — जैसे Wendesk-hosted domain से phishing send करना, custom integration के webhook handler में C2 traffic host करना, या fraud calls के launch point के रूप में outbound-call gateway का उपयोग।
- Rate limits, plan caps, या quota enforcement को circumventing multiple free या trial accounts create करके, sub-organisations rotate करके, या signups automate करके।
- Audit logs, security-event logs, या billing logs के साथ tampering platform पर stored, या cross-tenant systems की integrity में interference।
10. Account integrity, App Store, MCP, CA Partner portal#
प्रत्येक Wendesk workspace को एक single, real, identifiable Customer entity से correspond करना होगा। Platform की integrity — billing, compliance, trust & safety के लिए — इस पर depend करती है।
निम्नलिखित violations हैं: false name या false business identity के तहत accounts create करना; Wendesk-mediated transfer process से गुज़रे बिना किसी different controlling entity में account transfer करना; दूसरे पर suspension circumvent करने के लिए एक account का उपयोग करना; per-workspace caps evade करने के लिए दो या अधिक accounts coordinate करना; और दूसरे Wendesk customer की impersonating (जैसे existing brand की नकल करने वाला tenant slug या branded subdomain register करके)।
Wendesk किसी भी समय identity documentation, business registration documentation, या legitimate operation का proof मांगने का अधिकार reserve करता है, विशेष रूप से जब signals (payment-method fingerprint reuse, IP collisions, behavioural patterns) suggest करते हों कि single party limits evade करने के लिए multiple accounts operate कर रही है।
App Store integrations (90 connectors)
Wendesk App Store CRM, accounting, e-commerce, telephony, support, और marketing categories में 90 vetted integrations ship करता है। Integration connect करने से OAuth या API-key credential create होता है जो tenant के Data Encryption Key (DEK) के साथ at rest encrypted है। निम्नलिखित violations हैं: किसी third-party app का credential connect करना जो आप own नहीं करते या authorised नहीं हैं; connector के own terms का उल्लंघन करने वाले तरीके से Wendesk trust boundary के बाहर customer data exfiltrate करने के लिए connector का उपयोग; third-party platform पर spam, malware, या unsolicited communications push करने के लिए connector का उपयोग; या किसी अन्य tenant के encrypted credential को discover, replay, या extract करने का प्रयास।
MCP server (mcp.wendesk.com)
MCP server Model Context Protocol के माध्यम से authorised AI agents को Wendesk capabilities expose करता है। हर call authenticated, tenant को scoped, और audit-logged है। Violations include: credentials जो आप own नहीं करते उनसे MCP client connect करना; आपके authorised scope के बाहर data read या write करने के लिए MCP का उपयोग; official export flow के बजाय repeated tool calls के माध्यम से tenant data bulk-extract करना; और Wendesk system prompts, scaffolding, या अन्य tenants' data elicit करने के लिए designed prompts construct करना।
CA Partner portal (cabal.wendesk.com)
ca-partner custom role रखने वाले Verified Chartered Accountants को केवल tenant के financial-reporting data — invoices, GST returns, P&L, statutory ledgers — तक scoped access है। Violations include: non-financial CRM, conversational, या operational data view या extract करना; tenant के साथ signed engagement letter के बाहर tenant data का उपयोग; non-CA staff के साथ access credentials share करना; और Wendesk के अन्य tenants को up-sell, cross-sell, या solicit करने के लिए portal का उपयोग। CA Partner sessions impersonation audit के तहत recorded हैं और monthly compliance digest में tenant को surfaced होते हैं।
11. Violations report करना#
यदि आप believe करते हैं कि Wendesk workspace, marketplace storefront, आपको मिला outbound message, या Wendesk से जुड़ा कोई अन्य surface इस AUP का उल्लंघन कर रहा है, तो [email protected] पर निम्नलिखित के साथ लिखें:
- Offending surface का URL, phone number, message ID, या storefront handle।
- आपका belief क्या नियम तोड़ा जा रहा है, और क्यों का brief description (एक या दो sentences ठीक है)।
- कोई भी evidence जो आप share कर सकते हैं — screenshots, message excerpts, WhatsApp/SMS gateway द्वारा returned message ID, या timestamp।
- चाहे आप affected party, witness, या किसी अन्य की ओर से (उनकी permission के साथ) report कर रहे हों।
- Follow-up के लिए हम आप तक कैसे पहुँच सकते हैं। Anonymous tips accepted हैं; verifiable identity triage को speed करती है।
SLAs: हम हर report को 24 घंटों के भीतर acknowledge करते हैं। Initial triage और पहला action (warning, restriction, suspension, या escalation) standard reports के लिए 72 घंटों के भीतर और CSAM, ongoing fraud, या active security incidents वाले high-severity reports के लिए 4 घंटों के भीतर होता है। जहाँ report में regulated authority (cyber-crime, NCMEC, आदि) की involvement हो, हम parallel में file करते हैं।
अन्य channels: legal-process matters के लिए [email protected]; customer-support questions जो abuse reports नहीं हैं उनके लिए [email protected]। Mis-routed reports internally forward किए जाते हैं; हम किसी reporter को गलत address पर भेजने के लिए penalise नहीं करते।
12. Enforcement#
Default enforcement path graduated है। हम workspace owner को एक private, written warning के साथ शुरू करते हैं जो नियम और cure के लिए expected action (typically: activity बंद करें, content remove करें, affected parties से contact करें) name करती है। Cure window normally seven (7) days है; कुछ cases में (जैसे ongoing attack) हम immediate action require करेंगे।
यदि cure window compliance के बिना पास हो जाती है, तो हम suspension की ओर move करते हैं: workspace को outbound activity से lock किया जाता है (कोई new messages नहीं, कोई new calls नहीं, कोई marketplace listings नहीं), लेकिन data retain है और read-only review के लिए access remains है। Repeated या unrepaired violations Terms of Service के अनुसार termination में result होते हैं।
कुछ violations warning step entirely skip करते हैं और immediate suspension या termination trigger करते हैं। ये हैं: CSAM और child-safety violations; active fraud या scam campaigns; Wendesk या third parties के विरुद्ध security attacks; sanctions या AML violations; और कोई भी conduct जो third party को imminent harm का risk present करती है।
Termination पर, Wendesk Privacy Policy में ordinary retention schedule के अनुसार account data preserve करता है और retention extend कर सकता है जहाँ law, court order, या pending investigation support की आवश्यकता हो। Terminated accounts पर refunds Refund & Cancellation Policy का पालन करते हैं: AUP violation के लिए termination Customer को termination decision से पहले periods के लिए paid fees का refund entitle नहीं करती।
13. Law enforcement के साथ cooperation#
Fourteen Cloud Pvt Ltd ("Wendesk") उन jurisdictions के courts और authorities से lawful subpoenas, search warrants, court orders, और regulator requests का जवाब देता है जहाँ हम process के अधीन हैं — principally India, US sub-processors के माध्यम से routed US-residents' data के संबंध में United States, और relevant data-cooperation frameworks के तहत European Union। Received requests counsel द्वारा reviewed हैं; non-compliant requests (जैसे jurisdiction lacking overbroad demands) challenge किए जाते हैं।
जहाँ law allow करती है, Wendesk affected Customer को उनके data को target करने वाले request की notification देता है ताकि वे अपनी ओर से object कर सकें। जहाँ law notice forbid करती है (जैसे warrant के साथ non-disclosure order), हम इसके force में रहने के दौरान gag का पालन करते हैं और जैसे ही permitted हों notify करते हैं।
Wendesk government requests की volume और nature, full में, in part में, या refuse किए गए respond करने का proportion, और produced data की categories को summarize करने वाला annual transparency report publish करता है। Report anonymised और aggregated है; individual workspace data इसमें कभी disclosed नहीं होता।
14. End-users के लिए Customer responsibility#
Customer उन लोगों के AUP के लिए compliance की first line है जिन्हें वे platform पर लाते हैं। यह disclaimer नहीं है — यह structurally true है, क्योंकि Customer (workspace owner, L4) एकमात्र ऐसी party है जो अपने own staff, own customers, own end-users, और own sub-organisations को जानती है।
Concretely, Customer responsible है: workspace access वाले हर staff member यह सुनिश्चित करने के लिए कि उन्होंने इस AUP को पढ़ा और accept किया है; live जाने से पहले industry-appropriate guardrails (consent capture, calling windows, opt-in records) configure करने के लिए; अपने account के तहत publish किए गए storefronts और sub-organisations की supervising के लिए; इस AUP का उल्लंघन करने वाले users को promptly remove या suspend करने के लिए; और Wendesk द्वारा forwarded abuse complaints का उस forwarded message में stated timeframe के भीतर (normally seven days) जवाब देने के लिए।
जहाँ Customer stated window के भीतर forwarded abuse complaint पर act नहीं करता, Wendesk section 12 के तहत directly underlying user, content, या sub-organisation पर act कर सकता है। End-users को govern करने में repeated failure Customer के own account के विरुद्ध action तक escalate होती है।
15. Updates और versioning#
हम इस AUP को law, platform, sub-processors के नियमों, या हमारे encounter होने वाले threats में changes reflect करने के लिए update कर सकते हैं। Material changes — new prohibited categories, new restricted industries, enforcement ladder में changes, या consent rules में substantive amendments — workspace owner को email और dashboard में notice द्वारा effect होने से कम से कम चौदह (14) दिन पहले announced किए जाते हैं। Non-material changes (typo fixes, restructuring, clarifying examples) publication पर effect होते हैं।
हर published version इस page के top और bottom पर dated और version-numbered है। Material change के effect होने के बाद Wendesk का continued use नए version की acceptance constitute करता है। Material change accept न करने वाला Customer effective date से पहले Terms of Service के अनुसार terminate कर सकता है और Refund & Cancellation Policy के अनुसार pre-paid unused time का refund request कर सकता है।
16. Contact#
सही address इस पर depend करता है कि आपको क्या चाहिए:
- Abuse reports, AUP violations, urgent trust-and-safety matters — [email protected]
- Legal process, subpoenas, regulator correspondence, counsel से AUP interpretation questions — [email protected]
- Customer-support questions जो abuse reports नहीं हैं — [email protected]
Postal correspondence to the controller and provider:
Fourteen Cloud Pvt Ltd
Attn: Trust & Safety
Jaipur, Rajasthan, India
अंतिम बात: यह policy इसलिए exists करती है ताकि Wendesk उन customers के लिए useful रहे जो इसका अच्छी तरह उपयोग करते हैं, और उन लोगों के लिए inhospitable जो इसे weaponise करेंगे। यदि आप सद्भावना से operate कर रहे हैं, तो आप इस पृष्ठ से कभी नहीं टकराएंगे। यदि आप टकराते हैं, तो हमें लिखें — हम enforce करने के बजाय misunderstanding ठीक करना prefer करेंगे।