Legal

Acceptable Use Policy

Rules for responsible use of Varajen services.

Multi-tenant
Designed for tenant isolation
Audit-ready
Workflow and policy visibility
Enterprise review
Vendor onboarding support
Important: This public page is for general information only and does not replace a signed customer agreement, DPA, order form, or legal advice.
Effective and last updated: August 28, 2026
1

Authorized business use

Varajen may be used only by authorized users for lawful HR, recruiting, vendor, time, payroll, communications, analytics, and workforce operations consistent with the customer's agreement, configured roles, and applicable law.

2

Security abuse

Users may not gain unauthorized access; probe, scan, or test without written authorization; bypass tenant, role, rate, payment, or approval controls; introduce malware; interfere with availability; extract secrets; or access another person's or tenant's data.

3

Unlawful or harmful content

Users may not process content that is unlawful, fraudulent, infringing, defamatory, threatening, exploitative, or designed to facilitate harm. Spam, phishing, deceptive impersonation, credential theft, and unauthorized surveillance are prohibited.

4

Employment and discrimination

Users may not use Varajen to make unlawful discriminatory employment or workforce decisions. Customers must provide required notices, accommodations, consent, contestability, and human review for consequential decisions.

5

AI and automation

Users may not submit content they lack authority to process, attempt model extraction, generate malware, evade safeguards, or represent AI output as independently verified. Automated actions must remain within approved tenant policy and human-oversight requirements.

6

Integrations and communications

Users must respect provider terms, API limits, recipient consent, opt-out requirements, messaging laws, and job-board rules. Credentials and integration access may not be shared outside the authorized tenant context.

7

Sensitive and regulated data

Government identifiers, bank information, health information, children's data, and other regulated records may be processed only where the service, contract, customer policy, and law authorize it. Such data must not be placed in free-text fields, support tickets, or integrations not designed for it.

8

Enforcement

Varajen may investigate suspected violations, preserve relevant evidence, remove harmful content, restrict features, suspend access, or notify the customer and authorities where appropriate. Where practicable, actions are proportionate to risk and governed by the customer agreement.

9

Reporting

Report abuse through /contact/request/?type=security. Provide relevant tenant, URL, timestamp, and non-sensitive evidence; never email passwords, tokens, bank data, government identifiers, or unrelated personal records.

Enterprise procurement support

For vendor onboarding, security questionnaires, compliance review, data processing questions, or contract review, contact the Varajen team.