Hinweis: Dieses Dokument liegt derzeit nur auf Englisch vor. Bei Fragen wenden Sie sich bitte an support@appaloosa.io.
ACCEPTABLE USE POLICY
appaloosa.io
Last updated: October 1, 2025
1. INTRODUCTION
This acceptable use policy covers the products, services and technologies (collectively referred to as the "Services") provided by OB2J under any current agreement. It is designed to protect us, to protect our customers, and to protect the wider Internet community against unethical, irresponsible and illegal activities.
OB2J customers who engage in activities prohibited by this acceptable use policy may be liable to service suspension and account termination. In extreme cases, we may be legally required to report such customers to the competent authorities.
2. IDENTITY OF THE PUBLISHER
OB2J
Société par actions simplifiée with a share capital of 1,010.50 euros
Registered office: 9 impasse Rolland, 64200 Biarritz, France
RCS Bayonne 901 232 520
Intra-community VAT number: FR82901232520
3. PURPOSE OF THE POLICY
appaloosa.io is a mobile fleet management solution (Mobile Device Management - MDM) that allows companies to deploy applications and configurations on computers, smartphones and tablets. This policy defines the acceptable and unacceptable uses of our Services in this specific context.
4. FAIR AND REASONABLE USE
We provide our Services on the assumption that your use will be "normal and professional", in accordance with our commercial offer. If your use is considered excessive, additional fees may be charged or capacity may be restricted.
Minimum quantity: All our subscriptions require a minimum of 50 managed devices.
We are opposed to all forms of abuse, discrimination, infringement of rights, and/or any action that harms or disadvantages a group, an individual or a resource. We expect our customers and, where applicable, their users ("end users") to use our Services with a similar intent.
5. CUSTOMER RESPONSIBILITY
5.1 General responsibility
We hold our customers responsible for their own actions as well as for the actions of any person using our Services with the customer's authorisation. This responsibility also applies to any person using our Services in an unauthorised manner as a result of the customer's failure to put reasonable security measures in place.
By accepting our Services, our customers agree to guarantee compliance with this policy on behalf of any person using the Services as end users. Complaints regarding the actions of customers or their end users will be forwarded to the designated contact for the account in question.
5.2 MDM-specific responsibility
As a user of a mobile fleet management solution, the customer is specifically responsible for:
Deployed applications:
- The legality of all applications deployed through our platform
- Compliance with the software licences of the applications distributed
- The compliance of applications with the terms of use of the app stores (Apple App Store, Google Play Store, Microsoft Store)
- The security of the deployed applications and the absence of malicious software in them
Compliance with employment law:
- Compliance with the employment law applicable in the country or countries where the employees are based
- Informing employees in advance about the monitoring carried out through the managed devices
- Respect for employees' privacy and their right to disconnect
- Obtaining the necessary consent where required by law
Geolocation:
- Device geolocation may only be used in cases of declared loss or theft
- The customer must provide evidence that geolocation is expressly provided for in the employment contract or in the written agreement of the employee concerned
- Geolocation must not be used to monitor the daily movements of employees without their consent
Access security:
- The implementation of strong passwords for all administrator accounts
- The appropriate management of access rights within the organisation
- The protection of credentials and passwords against any unauthorised access
- The immediate revocation of the access rights of employees leaving the organisation
5.3 Sanctions
If a customer, its end user or any person using our Services as a result of the customer's actions breaches our acceptable use policy, we reserve the right to:
- Terminate any Service associated with the infringing account
- Terminate the account itself
- Take any corrective or preventive measure that we deem appropriate, without prior notice
To the extent permitted by law, no credit will be available for service interruptions resulting from a breach of our acceptable use policy.
6. PROHIBITED ACTIVITIES
6.1 Copyright infringement and access to unauthorised material
Our Services must not be used to transmit, distribute or store material in breach of any applicable law. This includes, without limitation:
- Any material protected by copyright, a trademark, a trade secret or any other intellectual property right used without appropriate authorisation
- Any material that is obscene, defamatory, constitutes an unlawful threat or breaches export control laws
The customer is solely responsible for any material that it enters, uploads, broadcasts, transmits, creates or publishes through or on our Services, and for obtaining the legal authorisation to use any work included in that material.
MDM-specific application:
- The deployment of pirated or counterfeit applications is strictly prohibited
- Customers must hold the appropriate licences for all deployed applications
- The customer must not use our Services to circumvent the technical protection measures (DRM) of applications
6.2 SPAM activity and unauthorised messages
Our Services must not be used for the purpose of sending bulk commercial or unsolicited messages in breach of the laws and regulations applicable in your jurisdiction ("spam"). This includes, without limitation:
- Sending spam
- Soliciting customers from spam sent from other service providers
- Collecting replies to spam sent from other service providers
MDM-specific application:
- The mass deployment of unsolicited push notifications
- Sending marketing messages through managed devices without appropriate consent
- Using the platform for aggressive marketing or unsolicited commercial communications
6.3 Unethical, exploitative and malicious activities
Our Services must not be used for the purpose of advertising, transmitting or making available any software, program, product or service designed to breach this acceptable use policy or the acceptable use policy of other service providers.
General prohibited activities:
- Accessing any account or electronic resource that the group or individual attempting access does not own or is not authorised to access (for example, "hacking", "cracking", "phreaking", etc.)
- Intentionally or negligently introducing viruses or malicious code into our Services and systems
- Intentionally engaging in activities designed to harass another group or individual
- Obtaining (or attempting to obtain) services from us with the intent to avoid payment
- The unauthorised access, alteration or destruction (or any attempt to do so) of any information concerning our customers or end users
- Using our Services to interfere with the use of our facilities and our network by other customers or authorised individuals
- Publishing or transmitting any content or link that incites violence, depicts a violent act, depicts child pornography, or threatens the health and safety of anyone
- Any breach of consumer protection laws and regulations
- Any breach of a person's privacy
MDM-specific activities that are strictly prohibited:
- Abusive monitoring of employees:
- Excessive or disproportionate monitoring of employee activities
- Access to employees' personal data without a legal basis
- Hidden monitoring or monitoring not disclosed to employees
- Use of the camera, microphone or geolocation for monitoring purposes without appropriate consent
- Deployment of malicious applications:
- Installation of spying applications (spyware, stalkerware)
- Deployment of hidden surveillance software
- Installation of keyloggers or unauthorised screen capture tools
- Deployment of applications intended to circumvent security protections
- Infringement of privacy:
- Collection of employees' personal data without a legal basis
- Access to private communications (personal emails, messages, social networks) without a legitimate reason
- Sharing employees' personal data with unauthorised third parties
- Retention of personal data beyond the necessary duration
- Non-compliance with employment law:
- Use of geolocation without an appropriate contractual clause
- Monitoring during rest periods, leave or sick leave
- Failure to respect the right to disconnect
- Failure to inform the employee representative bodies in advance (social and economic committee, staff representatives, etc.)
- Misuse of purpose:
- Use of the platform for purposes other than professional mobile fleet management
- Management of personal devices without the explicit consent of their owners
- Use of our Services to monitor persons outside the professional context
6.4 Unauthorised use of OB2J property
We prohibit the impersonation of OB2J, the representation of a significant business relationship with OB2J, or the ownership of any OB2J property (including our Services and our brand) for the purpose of fraudulently obtaining services, custom, patronage or the trust of users.
7. SECURITY RECOMMENDATIONS
Although not mandatory, we strongly recommend the following security practices:
7.1 Access management
- Use multi-factor authentication (MFA) for all administrator accounts
- Implement a strong password policy (minimum 12 characters, complexity)
- Regularly review access rights and apply the principle of least privilege
- Immediately deactivate the accounts of employees leaving the organisation
7.2 Device security
- Enforce encryption on managed devices
- Keep operating systems and applications up to date
- Configure automatic locking policies
- Enable remote wipe in the event of loss or theft
7.3 Training and awareness
- Train administrators in fleet management best practices
- Inform end users of their rights and of the policies in force
- Clearly document the acceptable use policies within your organisation
7.4 Legal compliance
- Consult a lawyer specialising in employment law before implementing any monitoring
- Declare data processing activities to the competent data protection authority (in France: CNIL)
- Inform and consult the employee representative bodies where required
- Document the legal bases of all personal data processing activities
8. PROCESS IN THE EVENT OF A BREACH
8.1 Detection and reporting
Breaches of this policy may be detected through:
- Our automated monitoring systems
- Reports from other customers or users
- Complaints from third parties
- Compliance audits
8.2 Investigation
When a potential breach is detected:
- Initial assessment: Our team assesses the seriousness and the nature of the alleged breach
- Notification to the customer: The customer is informed of the alleged breach and receives the available details
- Request for explanation: The customer has the opportunity to provide explanations or corrective measures
- Full investigation: We carry out a thorough investigation in collaboration with the customer if necessary
8.3 Corrective measures
Depending on the seriousness of the breach, we may take the following measures:
Minor breach:
- Formal written warning
- Request for immediate corrective measures
- Increased monitoring of the account for a specified period
Moderate breach:
- Formal notice to cease the prohibited activity within 48 hours
- Temporary suspension of the service until resolution
- Obligation to provide guarantees of non-repetition
- Compliance audit of the account
Serious breach:
- Immediate suspension of the service
- Termination of the contract without prior notice
- Notification to the competent authorities if required by law
- No refund for the unused period
8.4 Right of appeal
The customer may contest a suspension or termination decision by:
- Contacting our support at support@appaloosa.io within 15 days following the notification
- Providing any relevant evidence or explanation
- Proposing a detailed corrective action plan
We will review the appeal within 10 business days and communicate our final decision in writing.
9. COMPLIANCE WITH APP STORE TERMS
9.1 Apple App Store
Customers using appaloosa.io to deploy iOS applications must comply with:
- The App Store Terms and Conditions
- The App Store Review Guidelines
- The Apple Developer Enterprise Program
In particular, the following are prohibited:
- The public distribution of applications developed with an Enterprise account
- The deployment of counterfeit or pirated applications
- The breach of Apple developer licences
9.2 Google Play Store
Customers using appaloosa.io to deploy Android applications must comply with:
- The Google Play Terms of Service
- The Developer Policies
- The terms of the Android Enterprise program
9.3 Microsoft Store
Customers using appaloosa.io to deploy Windows applications must comply with:
- The Microsoft Store Policies
- The applicable Microsoft licence terms
9.4 Customer responsibility
The customer acknowledges that it is solely responsible for:
- Obtaining the appropriate licences for the deployed applications
- Compliance with the terms of use of third-party platforms
- Any breach of the app store terms resulting from its use of our Services
OB2J cannot be held liable for breaches committed by the customer with respect to third-party platforms.
10. COOPERATION WITH THE AUTHORITIES
10.1 Legal obligation
We cooperate fully with:
- The judicial authorities and law enforcement
- The data protection authorities (CNIL in France)
- The competent regulatory bodies
- Any authority legally empowered to request information
10.2 Disclosure of information
We may disclose information about a customer or its use of our Services:
- In response to a subpoena, court order or legal request
- To protect our rights, our property or our safety
- To protect the rights, property or safety of others
- In the event of a suspicion of illegal activity
10.3 Notification
To the extent permitted by law, we will endeavour to notify the customer before disclosing its information, unless:
- The notification is prohibited by law
- The notification could compromise an investigation
- There is an imminent danger to the safety of persons
11. LIMITATION OF LIABILITY
11.1 General limitation
To the extent permitted by law, OB2J cannot be held liable for:
- The customer's use of our Services
- The actions of the customer's end users
- Breaches of this policy by the customer or its end users
- The consequences of the suspension or termination of the service in the event of a breach
- Any damage resulting from a non-compliant use of our Services
11.2 Indemnification
The customer agrees to indemnify and hold harmless OB2J, its officers, directors, employees and agents against:
- Any claim resulting from the customer's use of the Services
- Any breach of this policy by the customer or its end users
- Any infringement of third-party rights by the customer
- All costs and expenses (including reasonable legal fees) incurred in defending against such claims
12. ABOUT THIS POLICY
12.1 Scope
This policy sets out a non-exhaustive list of activities and intentions that we consider unacceptable and incompatible with our brand and our values.
We reserve the right to assess each situation on a case-by-case basis and to take the measures that we deem appropriate, even if the activity is not explicitly mentioned in this policy.
12.2 Amendments
We reserve the right to amend this policy at any time by publishing the revised version on our website. The revised version will take effect from the earlier of the following events:
- The date on which the customer uses our Services after we have published the revised version on our website
- 30 days after we have published the revised version on our website
Substantial amendments will be notified by email to customers at least 30 days before they take effect.
12.3 Language
In the event of a translation of this policy into other languages, the French version prevails in the event of a divergence or a dispute.
12.4 Hierarchy of documents
This policy forms an integral part of our General Terms and Conditions of Sale. In the event of a contradiction between this policy and the General Terms and Conditions of Sale, the provisions of the General Terms and Conditions of Sale prevail, unless otherwise stated.
13. INTERPRETATION AND APPLICATION
13.1 Principles of interpretation
This policy must be interpreted in a manner that:
- Protects the rights and privacy of individuals
- Guarantees an ethical and responsible use of technology
- Complies with the applicable laws and regulations
- Maintains the security and integrity of our Services
13.2 Proportionate application
We undertake to apply this policy in a manner that is:
- Proportionate to the seriousness of the breach
- Fair towards all customers
- Consistent with the principles of natural justice
- Respectful of the right to be heard
13.3 Good faith
We will always act in good faith in the application of this policy and we expect the same from our customers.
14. RESOURCES AND ASSISTANCE
14.1 Legal compliance
For specific questions about the legal compliance of your use of our Services, we recommend consulting:
- A lawyer specialising in employment law
- A data protection officer (DPO)
- The data protection authority of your country (in France: CNIL)
14.2 Best practices
We make available to our customers:
- Documentation on fleet management best practices
- GDPR compliance guides
- Templates for usage policies
- Technical support for security questions
Access to the documentation: https://support.appaloosa.io
14.3 Support
For any question concerning this policy:
Email: support@appaloosa.io
Telephone: +33 5 18 25 12 52
Opening hours: Monday to Friday, 9am-6pm (Paris time)
15. ACKNOWLEDGEMENT AND ACCEPTANCE
By using our Services, you acknowledge that you have read, understood and accepted this Acceptable Use Policy.
You undertake to:
- Comply with all the terms of this policy
- Inform and train your end users on these terms
- Immediately notify any known or suspected breach
- Cooperate with OB2J in any investigation of a breach
16. CONTACT
For any question or concern regarding this policy, please contact us:
OB2J
9 impasse Rolland
64200 Biarritz
France
Email: support@appaloosa.io
Telephone: +33 5 18 25 12 52
Website: https://www.appaloosa.io
Data Protection Officer (DPO):
Email: dpo@appaloosa.io
17. JURISDICTION AND GOVERNING LAW
This policy is governed by French law.
Any dispute relating to the interpretation or the performance of this policy shall fall within the exclusive jurisdiction of the courts within the district of the Cour d'Appel de Pau, France.
Document updated on October 1, 2025 - Version 2.0