Last updated: 2026-08-15
1. Purpose and Scope
This Acceptable Use Policy ("AUP") governs all use of Notavia, a notification delivery service operated by Tessora LLC. It applies to every Customer, user, and organisation that accesses or sends messages through Notavia, whether via the dashboard, API, SDK, or any other integration.
This AUP is incorporated into and forms part of the Terms of Service. Capitalised terms not defined here have the meanings given in the Terms of Service.
The purpose of this AUP is to protect Recipients, third parties, and the integrity and reputation of the Notavia delivery infrastructure. Because Notavia is a shared sending platform, abuse by one Customer can affect deliverability and trust for all.
2. Prohibited Content
You must not use Notavia to send, facilitate, or enable any content that:
- Violates applicable law. Includes content that is illegal in the jurisdiction of the sender, the recipient, or the jurisdiction in which Tessora LLC operates, including content relating to illegal products, services, or activities.
- Infringes intellectual property rights. Reproduces copyrighted material, trade secrets, trademarks, or other proprietary content without authorisation.
- Is defamatory, harassing, or threatening. Content that harasses, intimidates, bullies, or threatens any individual or group.
- Is fraudulent or deceptive. Phishing, impersonation of a third party, false or misleading claims about a product or service, or any content designed to deceive Recipients as to the identity of the sender or the nature of the communication.
- Promotes malware or security exploits. Links or attachments that deploy or facilitate the deployment of malicious software, including viruses, ransomware, spyware, or adware.
- Contains adult or explicit content. Sexually explicit material, unless the Customer operates a lawfully-run adult-content platform and has received prior written authorisation from Tessora LLC.
- Relates to regulated industries without compliance. Messages related to financial products, pharmaceutical products, gambling, cannabis, firearms, or other regulated industries must comply with all applicable regulations in every jurisdiction in which they are sent, and Customers must maintain the required licences and consents.
- Promotes discrimination or hate. Content that promotes or glorifies discrimination, hatred, or violence against individuals or groups on the basis of race, ethnicity, religion, gender, sexual orientation, disability, or other protected characteristics.
- Breaches sanctions or export controls. Content, or a sending programme, directed at a person, entity, or destination that applicable sanctions or export-control law prohibits you from dealing with, or that would cause Tessora LLC to breach those laws. The Terms of Service already reserve our right to restrict or refuse the Service where sanctions or export controls require it; this bullet states the same boundary as a use rule so that a violation is enforceable under this AUP.
- Targets children. Content directed at children, or a sending programme built on a list you know or reasonably suspect consists of children. Notavia is a business-to-business service: the person who opens an account confirms they are at least 18 and acting for a business, and nothing in the product is designed for, or assessed against, the additional protections that apply to messaging children.
3. Anti-Spam and Sending Requirements
3a. Consent
You must have obtained valid, documented prior consent from each Recipient before sending marketing or promotional messages. What constitutes valid consent varies by jurisdiction (e.g., CAN-SPAM, GDPR, CASL, TCPA); it is your responsibility to understand and comply with the rules applicable to your sending.
For transactional messages (order confirmations, password resets, account security alerts, service notifications), prior consent is not always required, but the message must be genuinely transactional in nature and must not include promotional content that goes beyond what is expected in the context.
You must never send messages to:
- Lists purchased from third parties.
- Lists harvested without the knowledge of the individuals concerned.
- Email addresses or phone numbers obtained through deceptive or covert means.
- Recipients who have not provided an appropriate basis for you to contact them.
3b. Sender Identification
Every message sent through Notavia must clearly and accurately identify you (the sender). You must not use false or misleading "From" names, domain names, or phone numbers. The "From" address or number must be one you control and are authorised to use.
3c. Unsubscribe Mechanism
Every marketing or promotional message must include a clear, functional, and free-of-charge mechanism by which the Recipient can opt out of receiving further such messages. You must not add a Recipient who has opted out back to an active sending list without obtaining fresh, unambiguous consent.
Opt-out requests must be honoured promptly, and in any event within the shortest period required by the law that applies to that Recipient. There is no single global figure and we will not publish one, because the shortest applicable period is not the same everywhere. Where the GDPR or the UK GDPR applies, a Recipient's objection to direct marketing must be honoured immediately — Article 21 gives no grace period and no balancing test once the objection is made. Ten business days is the outer limit under CAN-SPAM and CASL, and it is a ceiling for those regimes rather than an allowance you can take everywhere. If you send into the EEA or the UK, treat the duty as immediate.
What Notavia gives you to honour that duty, and where the duty stays entirely yours. Two different mechanisms exist, they cover different things, and the difference decides how much of the work the platform can do for you:
- The suppression list is email only. It holds addresses, it is per environment, and the platform checks it on every email send and records the message as suppressed instead of delivering it. It also takes bounce and complaint feedback from your email provider. It does not apply to any other channel: a phone number, a chat destination, a webhook endpoint, or an in-app inbox identifier cannot be put on it, and adding an address to it does not stop a message on another channel.
- The notification-preference centre covers every channel. It is per Recipient, per category, and per channel, and the platform consults it on every send regardless of channel. Marketing email additionally carries a
List-Unsubscribeheader and a hosted one-click unsubscribe page.
The preference check is consulted on every send, but there are three ways to make it decide nothing — and two of them need no deliberate act at all. You must not use any of them to reach a Recipient who has opted out:
- A category marked critical is delivered without reading the Recipient's choice. That is by design, and it is correct for a password reset. Marketing and promotional categories must never be marked critical.
- A message sent with no category at all falls back to the
transactionalcategory, which ships critical — so an uncategorised marketing message is delivered without the Recipient's preference being read. Every marketing or promotional message must carry its own non-critical category. - A category key that does not exist, or that has been archived, resolves to nothing and the message is delivered unchecked. A typo in a category key silently disables the preference check for that send, and nothing warns you. Check the key, and re-check it after archiving a category.
You must use these controls and must not circumvent them. Where the platform enforces nothing for a channel — or decides nothing for a send, for any of the three reasons above — the opt-out duty does not shrink; it simply becomes yours to enforce in your own systems, and you remain responsible for honouring it within the period stated above.
3d. Subject Lines and Preview Text
Email subject lines must not be deceptive or misleading. They must be relevant to the content of the email.
3e. Physical Address
Where required by applicable law (e.g., CAN-SPAM for US commercial email), each message must include a valid physical postal address for your business. Your address, not ours: Tessora LLC's address identifies Tessora LLC's own correspondence and must never appear as the sender's address on a message you send through Notavia.
3f. The Channels These Duties Apply To
The duties in this section apply to every message you send, on every channel. What differs between channels is how much the platform can do for you, and we would rather set that out than let you assume a control exists everywhere.
| Channel | How it is provided | What the platform enforces for you |
|---|---|---|
| Managed sending, or bring your own provider | The preference centre, the suppression list, List-Unsubscribe on marketing mail, a hosted unsubscribe page, and bounce and complaint feedback | |
| In-app inbox | Managed | The preference centre |
| Webhook | Your endpoint | The preference centre |
| SMS | Bring your own Twilio or Vonage credentials. There is no managed SMS option | The preference centre. No suppression list, and no STOP-keyword handling: honouring an SMS opt-out is entirely your responsibility, in your own systems |
| Chat — Microsoft Teams and Discord | Your incoming webhook for the channel or room | The preference centre |
Two consequences follow, and you are bound by both:
- A channel with no suppression list is not a channel with no opt-out duty. For SMS, chat, webhook, and the in-app inbox, section 3c applies to you in full and the platform will not stop a send that breaches it.
- Do not use a channel to reach a Recipient who has opted out of another. Moving someone from email to SMS or to a chat destination after they unsubscribed is a circumvention of section 3c, and the fact that the platform cannot detect it does not make it permitted.
4. Volume, Rate, and Infrastructure Integrity
4a. Sending Volume and Rate Limits
You must not send volumes or at rates that exceed the limits for your subscription plan. Sustained sending in excess of your plan limits is not permitted without upgrading your plan.
4b. List Hygiene
You must maintain healthy sending lists. High bounce rates (hard bounces resulting from invalid addresses) and high complaint rates (spam reports) degrade deliverability for the entire platform. Tessora LLC may impose sending limits or suspend your account if your bounce rate, complaint rate, or other engagement metrics fall outside acceptable thresholds. We have not published a numeric threshold, and we will not point you at a document that does not exist; the judgement is made case by case. On the Pro, Scale and OEM plans the Deliverability page in the dashboard shows bounce and complaint rates per email provider — one set of figures for each provider we route your email through — alongside an overall attempt and failover summary. Be clear about what that is and is not: there is no single account-level bounce or complaint figure on that page, and it covers email only, which the page states for itself where other channels would otherwise be assumed. On the Free, Starter and Growth plans the page is not available to you at all: the navigation item is not shown, and the page shows an upgrade notice in place of the figures. In either case, if you want to know where you stand overall, ask us at support@saas-infrastructure.com and we will tell you.
You must promptly process bounce and complaint notifications returned by Notavia and remove problematic addresses from your active lists.
4c. No Infrastructure Abuse
You must not use Notavia to:
- Probe, scan, or test the vulnerability of Notavia systems or networks.
- Circumvent technical controls, rate limits, IP allowlists, or licence-enforcement mechanisms.
- Inject content into message queues or otherwise interfere with the operation of the platform.
- Generate artificial delivery or engagement events.
- Use the service in a way that materially degrades performance for other Customers.
4d. High-Risk and Safety-Critical Use
You must not use Notavia as the delivery mechanism for a notification on which someone's life, physical safety, or freedom from serious harm depends — including medical alerting, emergency dispatch or response, industrial or vehicle safety systems, or any use where a message that is delayed, suppressed, or never delivered could injure or kill someone.
We are not disclaiming a duty we would otherwise owe; we are telling you what this service is. Notavia routes messages through third-party providers we do not control, applies the preference and suppression gates described in section 3, and our Terms of Service state that we do not warrant that any particular notification will be delivered, opened, or acted upon. No part of the service is designed, tested, or certified for safety-critical use, and none of it is a substitute for an emergency service.
If your product genuinely needs safety-critical alerting, it needs an independent path that does not depend on us.
5. Security Obligations
You are responsible for maintaining the security of your Notavia account credentials, API keys, and any tokens that grant access to the service. You must:
- Use strong, unique credentials for your account and rotate API keys regularly or upon suspected compromise.
- Restrict API key access to the minimum scope necessary for each integration.
- Not share credentials or API keys with unauthorised persons.
- Notify Tessora LLC promptly at security@saas-infrastructure.com if you suspect that any credential has been compromised or that your account is being used without your authorisation. That is the same address we publish for vulnerability reports, and it is monitored.
Tessora LLC is not liable for losses arising from compromised credentials that result from your failure to maintain adequate security practices.
6. Consequences of Violation
If Tessora LLC determines, in its reasonable discretion, that you have violated this AUP, Tessora LLC may take one or more of the following actions:
- Warning. Issue a written warning and require you to remedy the violation.
- Rate limiting or throttling. Temporarily restrict your sending volume. This is a right we reserve; the controls we have built today are your plan's own monthly volume cap and suspension, not a targeted per-account throttle.
- Suspension. Suspend your ability to send messages or access the dashboard while an investigation is conducted.
- Termination. Terminate your subscription in accordance with the Terms of Service if the violation is serious, repeated, or not remedied after notice.
- Reporting. Report illegal activity to relevant law enforcement or regulatory authorities.
Tessora LLC will give you advance notice before taking action where it is safe and practical to do so, but reserves the right to act immediately where the violation is causing ongoing harm to Recipients, third parties, or the platform.
No refund of prepaid fees will be given where termination results from a violation of this AUP.
7. Reporting Abuse
If you believe that Notavia is being used to send you unsolicited messages, to harass you, or for any other activity that violates this AUP, please report it to us at support@saas-infrastructure.com. Provide as much detail as possible, including the message content, the sending address or number, and any identifiers visible in the notification. We take abuse reports seriously and will investigate all credible reports.
Who acts on it, and what we do not promise. That mailbox is monitored by the Tessora LLC owner role, which triages the report, decides which of the section 6 actions applies, and carries it out. There is no separate abuse team and no rota, and we deliberately publish no acknowledgement or resolution deadline: this is a small team, and we would rather make no promise than one we would miss. Our Security & Trust page says the same about vulnerability reports, for the same reason. You are not a customer of ours to report abuse to us, and we will not ask you to become one.
You do not have to come to us first. If the messages you are receiving come from a business you recognise, that business — not Tessora LLC — holds your data, chose to contact you, and is the one obliged to stop. Contacting them directly is usually faster, and it does not stop you also telling us.
8. Changes to This Policy
Tessora LLC may update this AUP from time to time to address new threats, comply with legal requirements, or reflect changes to the service.
A material change follows the Terms of Service process, not continued use. Section 16 of the Terms says a materially revised version does not bind a Business Customer merely because it kept using the Service, and that the identified version must be presented for a new affirmative acceptance. This AUP is incorporated into those Terms, so that rule governs a material change here too — a version of this section that said continued use was acceptance contradicted it, and this document is the one that defines what gets you terminated, which is the worst place for the weaker rule to sit. Material changes will also be notified by email to the address on your account.
A non-material change — a clarification, a correction, or a statement of something the platform already did — takes effect on the stated effective date after publication, and continued use is acceptance of that.
This AUP is not behind the dashboard's re-acceptance gate. The Terms of Service and the Privacy Notice are, and so is the Data Processing Agreement — for the organisation, and for a user with authority to bind it. All three are gated on the running service. A change to this AUP alone will not stop you at a screen the way a change to any of those does. This AUP is incorporated into the Terms by reference, which is a legal relationship and not a technical one — it does not make the gate fire. We do not operate a product-announcement or broadcast system and will not promise a notice we have no way to send.
9. Contact
For questions about this AUP or to report a potential violation:
Tessora LLC Abuse reports and general enquiries: support@saas-infrastructure.com Compromised credentials and vulnerability reports: security@saas-infrastructure.com