Acceptable Use Policy
Version 1.1 · Last updated: August 14, 2026
1. Purpose
This Acceptable Use Policy (the “AUP”) establishes the rules governing the use of the Platform, the Services, APIs, documentation, testing environments, support channels and any other resources made available by Bike Booking Engine, S.L. (hereinafter “Bike Booking Engine”, “BBE” or the “Company”).
Its purpose is to protect the security, stability, availability, integrity, reputation and proper functioning of the Platform, as well as to safeguard the legitimate rights and interests of Bike Booking Engine, its Customers, Authorized Users, employees, collaborators and third parties.
This AUP forms an integral part of the Terms of Service and is binding upon all Customers, Authorized Users and any person using the Platform under the Customer’s responsibility.
2. Scope
This Policy applies to:
- The SaaS Platform;
- Administration panels;
- Mobile applications;
- APIs;
- Technical and functional documentation;
- The help center;
- Demonstration environments;
- Beta versions;
- Integrations;
- Communications with support;
- Commercial or technical meetings; and
- Any other service, system or resource provided by Bike Booking Engine.
The obligations set out in this Policy also apply to the Customer’s employees, collaborators, contractors and Authorized Users.
The Customer is responsible for ensuring, within its sphere of control, compliance with this AUP by such persons.
3. General Principles
All use of the Platform must comply with the following principles:
- Contractual good faith;
- Legality;
- Respect for third parties;
- Reasonable use of resources;
- Security;
- Protection of intellectual property;
- Protection of personal data;
- Integrity of the Platform; and
- Responsible cooperation.
The Customer is responsible for ensuring that all persons using its Account are aware of and comply with this Policy.
4. Prohibited Activities
Without limitation, the Platform may not be used to:
- Carry out or facilitate unlawful activities;
- Commit or facilitate fraudulent activities;
- Launder money or finance unlawful activities;
- Impersonate others;
- Store, transmit or distribute illegal content;
- Distribute malware, viruses or malicious code;
- Send spam or unlawful commercial communications;
- Engage in phishing or other deceptive practices;
- Infringe intellectual property rights, privacy rights, data protection rights or other third-party rights;
- Violate applicable international sanctions or legal restrictions;
- Create fictitious or fraudulent bookings, operations or transactions;
- Fraudulently manipulate availability, prices, inventory, bookings, payments or any other information managed through the Platform;
- Enter or process personal data without an appropriate legal basis where such basis is required;
- Use data obtained through the Platform to carry out unlawful or unauthorized communications;
- Use payment Services for activities or transactions prohibited by applicable law or by the relevant payment service providers;
- Use the Platform for activities that may compromise the security or integrity of persons, property, systems or third parties;
- Violate any applicable law or regulation; or
- Use the Platform for purposes manifestly incompatible with those for which it was designed.
Bike Booking Engine may assess any conduct by taking into account not only its specific nature, but also its purpose, context, recurrence, impact and the risk created for the Platform, other Customers or third parties.
5. Abusive Use of Resources
The Customer must use Platform resources in a reasonable and proportionate manner.
Actions that intentionally or manifestly disproportionately affect the performance, availability, security or stability of the Platform are prohibited.
The following may, among other things, be considered abusive:
- Generating massive or disproportionate automated requests;
- Using scripts intended to overload the system;
- Artificial or abusive consumption of resources;
- Scraping, crawling or large-scale automated extraction of information without authorization;
- Making abusive or disproportionate API calls;
- Using functionalities for purposes other than those for which they were intended;
- Attempting to circumvent quotas, technical limits or restrictions applicable to the subscribed plan; and
- Any conduct that significantly degrades the experience of other Customers or the stability of the Services.
Bike Booking Engine may establish reasonable technical limits where necessary to protect the Platform.
Such limits may include, among others, rate limits, usage quotas, concurrency limits, storage limits, request limits, processing-volume limits or other equivalent measures.
6. Platform Security
Unless expressly authorized in writing by Bike Booking Engine, it is prohibited to:
- Perform vulnerability scans;
- Conduct penetration testing;
- Use exploitation tools;
- Attempt to circumvent security measures;
- Access or attempt to access unauthorized systems, accounts, data or resources;
- Manipulate communications;
- Intercept traffic;
- Use techniques intended to discover unauthorized internal information about the Platform;
- Alter technical logs;
- Cause or attempt to cause denial-of-service attacks;
- Exploit known or potential vulnerabilities; or
- Carry out any activity capable of compromising the security, confidentiality, integrity or availability of the ecosystem.
Security research or testing expressly authorized in writing by Bike Booking Engine and carried out strictly within the scope and conditions of such authorization shall not constitute a breach of this Policy.
Any potential vulnerability identified must be responsibly reported to Bike Booking Engine through its official contact channels.
A person identifying a potential vulnerability must refrain from exploiting it beyond what is strictly necessary to identify it, unnecessarily accessing third-party data, altering information, disrupting the Services or publicly disclosing the vulnerability before Bike Booking Engine has had a reasonable opportunity to investigate and remedy it.
7. Reverse Engineering and Development of Competing Products
Except where the relevant activities are expressly permitted by mandatory applicable law and cannot lawfully be restricted by contract, the Customer may not:
- Decompile;
- Disassemble;
- Reproduce;
- Copy;
- Imitate;
- Reconstruct;
- Systematically observe the Platform for reproduction or competitive purposes;
- Use automated tools to study its internal operation; or
- Develop competing products or services using the Platform or any of its components as a substantial reference.
This prohibition also applies to documentation, APIs, manuals, functional processes, user interfaces and other elements protected by intellectual or industrial property rights.
Nothing in this section prevents activities that cannot lawfully be restricted by contract under applicable law, including, where applicable, certain acts necessary to achieve the interoperability of an independently created program.
8. Benchmarking and Competitive Analysis
Unless expressly authorized in writing, the Customer may not use the Platform to:
- Prepare comparisons intended to develop competing products;
- Conduct systematic studies of functionalities for competitive purposes;
- Analyze internal processes for the purpose of reproducing them;
- Document functional workflows for competitive purposes; or
- Prepare benchmarking reports intended for third-party competitors.
The foregoing does not prevent reasonable internal evaluations for the purpose of deciding whether to subscribe to or legitimately use the Services.
9. Artificial Intelligence
Unless expressly authorized in writing, the Platform, its APIs, documentation, manuals, screenshots, support responses, training materials or any other content provided by Bike Booking Engine may not be used to:
- Train artificial intelligence models;
- Feed or train language models;
- Create knowledge bases intended for competing products;
- Develop virtual assistants substantially based on the Platform;
- Create automated systems that reproduce protected functionalities; or
- Use protected Bike Booking Engine content to develop substantially similar or competing products or services.
This prohibition does not prevent the Customer from legitimately using artificial intelligence tools for its own business activities, provided that such use does not involve the improper appropriation, reproduction or exploitation of Bike Booking Engine’s intellectual property, Confidential Information or trade secrets.
10. Use of APIs and Integrations
APIs must be used exclusively in accordance with official documentation and within the technical limits established by Bike Booking Engine.
It is prohibited to:
- Circumvent technical limitations;
- Access undocumented resources or endpoints where they are not intended for the Customer;
- Use private APIs without authorization;
- Automate processes intended to circumvent restrictions;
- Share API credentials with unauthorized third parties;
- Use APIs to access data for which the Customer does not have authorization;
- Use APIs for unlawful purposes or purposes incompatible with the contracted Services; or
- Make calls or run automated processes in a manner that may adversely affect the Platform.
Bike Booking Engine may apply rate limits, quotas, concurrency limits and other reasonable technical measures intended to protect the availability, security, performance and stability of the Services.
Bike Booking Engine may modify, expand, restrict, replace or withdraw APIs where reasonably necessary to ensure the security, stability or evolution of the Platform, in accordance with the Terms of Service.
11. Investigation of Potential Breaches
Bike Booking Engine may investigate activities where there are reasonable indications of a breach of this AUP, the Terms of Service, applicable law or third-party rights.
For this purpose, Bike Booking Engine may analyze, to the extent reasonably necessary:
- Technical records;
- Security logs;
- Usage patterns;
- Request volumes;
- API activity;
- Reported incidents;
- Account-related information; and
- Any other technical information reasonably necessary to investigate the potential breach.
Such activities shall be carried out in accordance with applicable law and, where they involve the processing of personal data on behalf of the Customer, the applicable DPA.
The Customer must reasonably cooperate with Bike Booking Engine where necessary to investigate security incidents, fraud, abuse or breaches of this Policy.
12. Preventive Measures and Suspension
Where Bike Booking Engine identifies a reasonable risk to the security, stability, availability or integrity of the Platform, it may adopt technical preventive measures proportionate to the identified risk.
Such measures may include:
- Temporarily limiting certain functionalities;
- Reducing or temporarily blocking certain API calls;
- Applying additional usage limits;
- Revoking or regenerating credentials;
- Blocking integrations;
- Restricting certain Authorized Users;
- Isolating potentially compromised processes or resources; or
- Temporarily suspending all or part of access to the Platform.
Where circumstances reasonably permit, Bike Booking Engine will seek to inform the Customer of the measures adopted.
In urgent situations involving security, fraud, unlawful activities, risk to third parties or Platform stability, measures may be adopted without prior notice.
The proportionate application of preventive measures under this section shall not, by itself, constitute a contractual breach by Bike Booking Engine.
13. Breaches and Termination
A breach of this AUP may result in the measures provided for in the Terms of Service.
Where a breach is capable of remedy and there is no urgency, fraud, illegality, security risk, serious harm to third parties or repeated misconduct, Bike Booking Engine may require the Customer to cease or remedy the conduct within a reasonable period.
Serious breaches may justify immediate suspension of the Services and, where appropriate, termination of the Agreement in accordance with the Terms of Service.
The following may, among others, be considered serious breaches:
- Attacks against the Platform;
- Unauthorized access attempts;
- Distribution of malware;
- Fraud;
- Phishing;
- Deliberate exploitation of vulnerabilities;
- Manifestly unlawful activities;
- Fraudulent manipulation of transactions;
- Serious infringement of third-party rights; or
- Conduct creating a significant risk to the security, availability or integrity of the Platform.
Termination of the Agreement shall in all cases be governed by the Terms of Service.
14. Amendments to the AUP
Bike Booking Engine may update this AUP where reasonably necessary as a result of:
- Legislative or regulatory changes;
- New security risks;
- Technological developments;
- Introduction of new functionalities;
- Changes to APIs or integrations;
- Emergence of new forms of abuse;
- Requirements imposed by technology providers; or
- Reasonable evolution of the Services.
Where an amendment materially affects Customers’ obligations, Bike Booking Engine shall communicate it in accordance with the procedure established in the Terms of Service.
The version in force shall be the version published or otherwise made available to the Customer by Bike Booking Engine.
15. Relationship with the Terms of Service
This AUP forms part of the contractual documentation applicable to Bike Booking Engine Services.
This Policy supplements the Terms of Service and must be interpreted together with them.
In the event of any conflict between this AUP and another contractual document, the order of precedence established in section 6 of the Terms of Service shall apply.
Nothing in this AUP limits any rights or obligations established by mandatory applicable law.
16. Contact
Questions relating to this Policy, as well as reports concerning potential abusive use, incidents or security vulnerabilities, may be addressed to:
BIKE BOOKING ENGINE, S.L.
Tax ID (NIF): B44711695
Registered office:
Avinguda Bartomeu Riutort, 57, ground floor
07610 Palma de Mallorca
Balearic Islands
Spain
Email: info@bikebookingengine.com
End of Acceptable Use Policy (AUP)
Version 1.1 — August 14, 2026