Queuey Acceptable Use Policy
This Acceptable Use Policy (the "AUP" or this "Policy") governs the use of the Queuey webhooks-as-a-service and event-distribution platform (the "Service"), including Queuey's client libraries and the Queuey.Client .NET SDK (the "SDK") and the Documentation, made available by Queuey AS, a company registered in Norway (organisation number 937 342 977; registered business address: c/o Sverre Senneset, Skjermvegen 66, 7023 Trondheim, Norway), website queuey.ai ("Queuey", "we", "us", "our"), to the business or organisation that has entered into the Agreement with Queuey (the "Customer", "you", "your").
This Policy forms part of, and is incorporated by reference into, the agreement between Queuey and the Customer for use of the Service (the "Agreement"), which comprises any executed Order Form, the Data Processing Agreement ("DPA"), the Cloud Service Agreement, this AUP, and the Documentation, in the order of precedence set out in the Cloud Service Agreement. Capitalised terms used but not defined in this Policy have the meanings given to them in the Cloud Service Agreement and the DPA. In the event of a conflict between this AUP and the Cloud Service Agreement on a matter of acceptable use, this AUP controls to the extent of that conflict (as permitted by the order-of-precedence provision of the Cloud Service Agreement); the general order of precedence in the Cloud Service Agreement otherwise applies.
The Service is offered exclusively to businesses and organisations acting in the course of a trade or profession. It is not offered to consumers.
Last updated: 14 August 2026 · Effective: 31 August 2026
1. Purpose and scope
1.1 The Service ingests messages and payloads (each an "Event") that the Customer or its Authorised Users submit over HTTP or via the SDK, queues and deduplicates them (using idempotency keys), retries their delivery under configurable policies, rate-limits them, and delivers them to Customer-configured HTTP destinations (each an "Endpoint"), with dead-letter handling for failures. Under the Webhooks-as-a-Service ("WaaS") feature, a producing Customer publishes Event "streams" that subscribing Integration Tenants receive. Because the Service exists to originate and transmit HTTP requests, Events, and messages to systems the Customer designates, its integrity depends on every Customer using it only for traffic the Customer is entitled to send. This Policy defines the boundaries of acceptable use.
1.2 This Policy applies to the Customer, to all of the Customer's Authorised Users, and — where the Customer participates in Queuey's Partner Program as a Partner or otherwise provisions or enables Integration Tenants — to all use of the Service by or through those Integration Tenants and their users. The Customer is responsible for ensuring that everyone who accesses or uses the Service under the Customer's account, Subscription Plan, credentials, or on the Customer's behalf complies with this Policy, and the Customer is responsible for their acts and omissions as if they were the Customer's own.
1.3 This Policy is not exhaustive. Queuey may update it from time to time in accordance with the Cloud Service Agreement to address new forms of misuse, legal requirements, or changes to the Service. Conduct that is not expressly listed here may still violate this Policy if it is unlawful, harmful, deceptive, abusive, or inconsistent with the purpose of the Service or the security and integrity of the platform or its users.
2. Prohibited content
You must not submit to, transmit through, store on, distribute via, or deliver by means of the Service any Event, payload, endpoint configuration, metadata, or other Customer Data that:
2.1 is unlawful under, or whose transmission or delivery would violate, any applicable law, regulation, sanctions regime, or export-control requirement, or any order of a court or competent authority;
2.2 infringes or misappropriates any third party's intellectual property rights, including copyright, trademark, patent, trade secret, database, or other proprietary rights, or that you do not otherwise have the right to submit, transmit, or deliver;
2.3 contains, embeds, or is designed to deliver or propagate malware, viruses, worms, trojans, ransomware, spyware, time bombs, or any other malicious, harmful, or destructive code, files, scripts, or programs, or any exploit, payload, or instruction intended to disrupt, damage, gain unauthorised access to, or degrade any system, network, data, or Endpoint;
2.4 constitutes, references, links to, or facilitates the creation or distribution of child sexual abuse material (CSAM) or any other content that sexually exploits or endangers minors. Queuey has zero tolerance for such material and will report it to the appropriate authorities and preserve related information as required or permitted by law;
2.5 violates the privacy, publicity, or other rights of any third party, or discloses another person's Personal Data or confidential information without a valid legal basis and, where required, the necessary consents and notices;
2.6 is fraudulent, deceptive, or misleading, including content that spoofs or forges message headers, source identifiers, HMAC signatures, or origin information, that impersonates any person or entity, or that misrepresents the origin, authenticity, or purpose of an Event; or
2.7 is defamatory, harassing, threatening, or that promotes or facilitates violence, terrorism, illegal weapons or drugs, human trafficking, or other serious harm, or that is otherwise objectionable and reasonably likely to expose Queuey, its Sub-processors, or other users to legal liability or reputational harm.
3. Prohibited conduct — event delivery and endpoints
Because the Service transmits HTTP requests and Events to destinations you configure, the following conduct is strictly prohibited:
3.1 Endpoint authorisation. You may configure and deliver Events only to Endpoints that you own or that you are expressly authorised by the operator of the destination system to receive delivered Events. You must not configure an Endpoint pointing to, or use the Service to send Events or HTTP requests to, any third-party system, address, host, or service that you do not own or are not authorised to deliver to. You are solely responsible for confirming and maintaining that authorisation for every Endpoint you configure, including under the WaaS feature for any stream you publish or subscribe to.
3.2 No flooding, overload, or denial-of-service. You must not use the Service to flood, overload, saturate, or degrade — or to attempt a denial-of-service or distributed denial-of-service against — any system, network, service, or Endpoint, whether your own, another Queuey customer's, or a third party's. You must not artificially inflate Event volume, retry behaviour, or request rates for the purpose of overwhelming a destination.
3.3 No probing, scanning, or attack traffic. You must not use the Service to probe, scan, enumerate, fingerprint, penetrate, or otherwise test the vulnerability of any system, network, or Endpoint, or to deliver exploit, injection, brute-force, credential-stuffing, or other attack traffic, or to circumvent or defeat any authentication or access control of a destination system.
3.4 No relay or anonymisation for attacks. You must not use the Service as an open relay, proxy, redirector, or anonymising or obfuscation layer to disguise the origin of, or to launder, traffic — including attack traffic, spam, or unlawful requests — directed at any third party.
3.5 No unsolicited or unlawful messaging. You must not use the Service to originate or deliver unsolicited bulk or commercial messages, or any messaging that violates applicable anti-spam, electronic-marketing, telecommunications, or consumer-protection laws. Where an Event triggers a message to an individual, you are responsible for having any legal basis and consents that applicable law requires.
3.6 Responsibility for what you send. You are solely responsible for the volume, content, deliverability, addressing, timing, and lawfulness of the Events and HTTP requests you send through the Service and for the configuration of your retry, rate-limit, and dead-letter policies. Queuey does not monitor the substance of the Events you send in the ordinary course and is not responsible for their content or their effect on any destination system.
3.7 No delivery to internal, private, or reserved destinations. You must not configure an Endpoint that resolves to a loopback, link-local, private/RFC 1918, carrier-grade NAT, multicast, or otherwise internal or reserved IP address, or to any cloud-provider metadata or internal management endpoint (for example 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16 including 169.254.169.254, and the IPv6 equivalents such as ::1, fc00::/7, and fe80::/10). This prohibition applies regardless of whether the address is reached directly, through a hostname that resolves to such an address, or via a redirect. Queuey may resolve, validate, refuse, or block delivery to such destinations, and may egress-filter or otherwise deny requests to them, at any time and without notice, in order to protect the Service, its infrastructure, and third parties from server-side request forgery (SSRF) and related attacks.
4. Prohibited conduct — platform integrity
4.1 No circumvention of limits. You must not circumvent, disable, defeat, or attempt to exceed any quota, rate limit, plan limit, usage limit, quantity restriction, or other technical or contractual limitation of the Service or your Subscription Plan, including by using multiple accounts, tenants, credentials, or automated means to evade a limit.
4.2 No breach of tenant isolation. The Service enforces strict per-tenant data isolation, including a separate database schema per tenant. You must not attempt to access, read, modify, or interfere with the data, schema, configuration, streams, or Events of any other tenant, Integration Tenant, or customer, or to defeat, bypass, or test the isolation, authentication, IP allow-listing, or access-control mechanisms of the Service, except to the extent of your own tenants and streams that you are authorised to access.
4.3 No unauthorised access. You must not access or attempt to access any part of the Service, any account, or any data that you are not authorised to access, and you must not use another party's credentials or share your credentials to enable unauthorised access.
4.4 No reverse engineering. You must not reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying structure, or non-public algorithms of the Service or the SDK, except and only to the extent this restriction is prohibited by mandatory applicable law (for example, limited interoperability rights under mandatory law), and then only after you have requested the relevant information from Queuey and Queuey has failed to provide it.
4.5 No unauthorised security testing. You must not conduct any penetration test, vulnerability scan, load or stress test, red-team exercise, or other security or resilience testing against the Service or its infrastructure without Queuey's prior written authorisation. Suspected vulnerabilities should be reported to Queuey in good faith as described in Section 8.
4.6 No resale or competing service. You must not resell, sublicense, rent, lease, distribute, or otherwise make the Service available to any third party except as expressly permitted under a Partner agreement with Queuey. You must not use the Service, the SDK, the Documentation, or any performance or benchmarking information about them to build, train, or operate a product or service that competes with the Service, or to copy or replicate its features or functionality.
4.7 No interference with others. You must not take any action that interferes with, disrupts, or degrades the integrity, security, availability, or performance of the Service, its infrastructure, its Sub-processors, or the use of the Service by any other customer, tenant, or user.
5. Data conduct
5.1 Rights and legal basis. You must ensure that you have all rights, permissions, consents, and a valid legal basis necessary to submit the Customer Data (including Event payloads and endpoint configuration) to the Service, to have it processed and delivered to your Endpoints and, under the WaaS feature, to Integration Tenants, and to otherwise use the Service as you do. You must not submit any data that you lack the rights to submit or transmit.
5.2 Special-category and sensitive data. Event payloads may contain Personal Data of the Customer's own customers and end users. You must not submit or transmit through the Service any special-category Personal Data (as defined in Article 9 GDPR), data concerning criminal convictions and offences, national identification numbers, financial-account or full payment-card data, or other highly sensitive Personal Data, unless you have first ensured an appropriate lawful basis and implemented appropriate safeguards for such data, and such processing is consistent with the DPA and applicable Data Protection Laws. The Service is not designed or intended to be, and must not be used as, a repository or transmission channel for such data absent those safeguards.
5.3 Compliance with the DPA and Data Protection Laws. All processing of Personal Data through the Service must comply with the DPA and with applicable Data Protection Laws, including the GDPR as incorporated into the EEA Agreement and applicable in Norway and the Norwegian Personal Data Act (personopplysningsloven). You are responsible, as controller (or as processor for your own controllers), for providing required notices to and obtaining required consents from data subjects, for the lawfulness of delivering Personal Data to your Endpoints and Integration Tenants, and for honouring data-subject rights with respect to Customer Data.
5.4 Use of the sandbox. The Service provides a sandbox for test traffic. Test, load-generation, and experimentation traffic should use the sandbox and must not use real Personal Data unless you have a lawful basis to do so and comply with this Policy and the DPA.
6. Fair use and resource abuse
6.1 The Service is provided on the basis of reasonable, good-faith use consistent with your Subscription Plan and the nature of a webhooks and event-distribution platform. Even where specific numeric limits are not stated, you must not consume Service resources — including ingestion throughput, queue depth, retry attempts, storage, compute, metrics retention, or bandwidth — in a manner that is excessive, abusive, or disproportionate relative to your Subscription Plan or that adversely affects the Service or other customers.
6.2 Abusive resource consumption includes, without limitation: generating Events solely to consume capacity; configuring retry or rate-limit policies designed to amplify traffic against a destination; sustained traffic materially exceeding the reasonable expectations of your Subscription Plan; and using automated means to generate load that the Service was not intended to bear. Where your usage requires additional capacity, you should upgrade your Subscription Plan or contact Queuey to agree appropriate terms.
7. Enforcement
7.1 Monitoring and investigation. Queuey does not routinely monitor the content of Events, but Queuey may investigate any suspected violation of this Policy and may access, review, and monitor Customer Data, configuration, and usage to the extent reasonably necessary to operate, secure, and protect the Service, to investigate a suspected violation, to respond to a complaint, or to comply with law.
7.2 Remedial actions. If Queuey reasonably believes that this Policy has been or is likely to be violated, or that the Service is being used in a manner that threatens the security, integrity, availability, or lawful operation of the Service, other customers, or third parties, Queuey may, with or without prior notice as the circumstances reasonably require, take any one or more of the following actions: (a) throttle, rate-limit, or restrict the affected traffic, streams, Endpoints, or account; (b) suspend, in whole or in part, the Customer's or an Authorised User's or Integration Tenant's access to the Service; (c) disable, block, or remove offending content, Events, Endpoints, or configuration; (d) terminate the Agreement in accordance with the Cloud Service Agreement; and (e) take such other action as Queuey considers reasonably appropriate. Queuey will seek to give notice and to use the least disruptive measure reasonably available where doing so is consistent with protecting the Service, other customers, and third parties, but reserves the right to act immediately where a delay could cause harm, legal exposure, or a security or integrity risk.
7.3 Preservation and disclosure. Queuey may preserve, and may disclose to competent authorities or affected third parties, Customer Data, configuration, logs, and other information where Queuey reasonably believes doing so is necessary to comply with applicable law, a court order, or a lawful request from a public authority, to enforce this Policy or the Agreement, to detect, prevent, or address fraud, security, or technical issues, or to protect the rights, property, or safety of Queuey, its customers, or the public. Queuey will cooperate with law enforcement and regulatory authorities as required by law.
7.4 No liability for good-faith enforcement. To the maximum extent permitted by applicable law, Queuey will have no liability to the Customer, its Authorised Users, or its Integration Tenants for any action taken in good faith to investigate or address a suspected violation of this Policy, including any throttling, suspension, removal of content, preservation, or disclosure. This limitation is subject to the carve-outs in the Cloud Service Agreement, including that liability cannot be excluded to the extent it is caused by Queuey's intent (forsett) or gross negligence (grov uaktsomhet) or for death or personal injury, which under mandatory Norwegian law cannot be contractually excluded.
7.5 Customer cooperation and cost. The Customer must cooperate with Queuey in investigating and remediating any suspected violation of this Policy and must promptly take any corrective action Queuey reasonably requests. The Customer is responsible for the costs and consequences of its violations, including as set out in its indemnification obligations under the Cloud Service Agreement.
8. Reporting abuse
8.1 To report a suspected violation of this Policy, abuse of the Service, unauthorised or attack traffic, or content of concern, contact Queuey at abuse@queuey.ai. To report a suspected security vulnerability, contact abuse@queuey.ai ; suspected vulnerabilities may also be reported to security@queuey.ai. For data-protection and privacy matters, contact privacy@queuey.ai. For other legal notices, contact legal@queuey.ai.
8.2 Please include sufficient detail to allow Queuey to identify and investigate the matter, including relevant identifiers, timestamps, Endpoints or streams involved, and a description of the conduct or content at issue. Do not include more Personal Data than is necessary for the report.
9. Relationship to the Agreement
9.1 Compliance with this Policy is a condition of the Customer's right to access and use the Service. A violation of this Policy by the Customer, any Authorised User, or any Integration Tenant for which the Customer is responsible constitutes a material breach of the Agreement, entitling Queuey to exercise the remedies set out in this Policy and in the Cloud Service Agreement, including suspension and termination.
9.2 This Policy is governed by, and construed in accordance with, the laws of Norway, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods (CISG). The parties submit to the exclusive jurisdiction of Trøndelag District Court (Trøndelag tingrett, Trondheim) as legal venue (verneting), as further set out in the Cloud Service Agreement. English is the governing language.