Knowledge ERP Acceptable Use Policy
Effective Date: July 22, 2026 Last Updated: July 22, 2026
1. Purpose
This Acceptable Use Policy (the "AUP") describes activities and content that are prohibited on the Knowledge ERP service operated by Pelton Solutions LLC d/b/a Knowledge ERP ("Knowledge ERP," "we," "us," "our"). The AUP is incorporated by reference into the Knowledge ERP Terms of Service and applies to anyone using the Service, including Customers, every individual acting under a Customer's Account (each a "User"), and anyone who interacts with a Customer's public booking pages, surveys, questionnaires, or customer portal in a way that violates this AUP. Under the Terms of Service, each Customer is responsible for imposing this AUP on its own Users and for their compliance.
By using the Service, you agree to comply with this AUP. Violations may result in content removal, suspension of email sending, suspension of integrations, API access, or public forms, Account suspension or termination, and reporting to law enforcement or rights holders, as further described below.
This AUP is not exhaustive. Knowledge ERP may determine, in good faith, that conduct or content not specifically listed here is nonetheless a violation, and may act accordingly.
2. Prohibited Content
The Service stores the business records you create — customer and vendor records, notes, CRM activity, transaction documents, survey responses, tenant-defined custom fields, and uploaded attachments. You must not enter into any record, note, free-text field, or custom field, or upload as an attachment, or transmit through the Service, content that:
2.1 Is illegal or supports illegal activity
- violates any applicable federal, state, or local law in the United States;
- depicts, promotes, or facilitates terrorism, violent extremism, or other serious crimes;
- constitutes fraud, identity theft, or financial scams (including investment, romance, advance-fee, business-impersonation, and tech-support scams), or documents or coordinates such schemes.
2.2 Sexually exploits or endangers minors — absolute prohibition
- child sexual abuse material (CSAM);
- content that sexualizes minors or depicts minors in a sexual context, in any form (illustrated, animated, AI-generated, or otherwise); or
- grooming, solicitation, or sextortion of minors.
Knowledge ERP has zero tolerance for CSAM. We report all such content to the National Center for Missing & Exploited Children (NCMEC) as required by federal law (18 U.S.C. § 2258A) and cooperate fully with law enforcement. Accounts found storing or transmitting such content will be terminated immediately and irrevocably, and we may preserve content, account data, and connection logs as required by law.
2.3 Infringes intellectual property
- content that infringes any third party's copyright, trademark, trade secret, patent, right of publicity, or right of privacy;
- pirated software, music, video, books, or games stored as attachments or distributed through the Service; tools for circumventing technical protection measures (DMCA § 1201 violations);
- records, catalogs, or documents used to sell or promote counterfeit goods or services.
If you believe content on the Service infringes your copyright, see the DMCA notice-and-takedown process described in our Terms of Service.
2.4 Promotes hate, harassment, or violence
- content that promotes violence against, threatens, or incites hatred toward a person or group based on race, ethnicity, national origin, religion, sex, gender, gender identity, sexual orientation, disability, or other protected characteristic;
- content that harasses, bullies, or stalks specific individuals — including using customer records, notes, surveys, or automated email/SMS to harass the people they describe;
- doxxing — compiling or distributing personal contact, address, or identifying information of a private individual without consent and in a way intended to cause harm or harassment;
- content that incites imminent violence or self-harm.
2.5 Is defamatory or invasive of privacy
- content that contains knowingly false statements of fact that damage a third party's reputation;
- content that reveals private, intimate, or otherwise sensitive information about an identifiable individual without lawful basis and consent (including non-consensual intimate imagery / "revenge porn"), whether in a record, a note, a custom field, or an uploaded file.
2.6 Is malicious or deceptive
- malware, viruses, worms, trojans, spyware, ransomware, or any other software designed to disrupt, damage, or gain unauthorized access to systems, data, or networks — whether uploaded as an attachment, linked from a record, or distributed via email, SMS, webhooks, or the customer portal;
- phishing content, fake login portals, fake invoices or payment requests, or content designed to deceive recipients into disclosing credentials, payment information, or personal data;
- forged or deceptive documents (quotes, invoices, purchase orders, agreements) generated through the Service to misrepresent a transaction that did not occur or to deceive a recipient about who is asking them to pay.
3. Sensitive and Regulated Data — Data Hygiene
Knowledge ERP is a general-purpose business operations platform. It is designed to hold ordinary business-contact and transaction data — names, business addresses, emails, phone numbers, orders, invoices, equipment records. It is not designed, configured, or offered as a repository for regulated or special-category personal data, and its free-text and tenant-defined fields have no safeguards appropriate to such data.
3.1 No special-category data in free-text or custom fields
You must not enter, and must instruct your Users not to enter, any of the following into notes, descriptions, comments, survey questions or answers, questionnaire fields, or any tenant-defined custom field, or upload them as attachments except where genuinely required for a lawful, ordinary business purpose and handled in compliance with applicable law:
- health or medical information of any identifiable individual (diagnoses, conditions, treatments, prescriptions, insurance claims);
- biometric identifiers or biometric data (fingerprints, faceprints, voiceprints, retina/iris scans). The e-signature captured on equipment checkouts is provided for that documented purpose only; do not store other biometric artifacts;
- government-issued identification numbers — Social Security numbers, driver's license numbers, passport numbers, taxpayer IDs of individuals — beyond what an ordinary business need genuinely requires (for example, a vendor's EIN on a vendor record is fine; a spreadsheet of employee SSNs in an attachment is not);
- full payment card numbers, card verification codes (CVV/CVC), or magnetic-stripe data — never, in any field, note, or upload. Payment card data belongs with your payment processor (your own Stripe or Square account), not in the Service;
- precise financial account credentials (online banking logins, full bank account numbers paired with authentication data);
- data revealing racial or ethnic origin, religious beliefs, sexual orientation, immigration status, or criminal history of identifiable individuals, except where you have an independent legal obligation to record it and a lawful basis for doing so.
We do not monitor the contents of your records, and we disclaim any assumption about the categories of data you store; the Data Processing Addendum allocates responsibility accordingly. If we discover prohibited data categories in your Account, we may require their removal and may suspend affected features until they are removed.
3.2 HIPAA — Protected Health Information is prohibited
Knowledge ERP is not a HIPAA-compliant platform and will not sign a Business Associate Agreement (BAA). You may not use the Service to create, receive, maintain, or transmit Protected Health Information (PHI) subject to HIPAA, and you may not operate any workflow — records, custom fields, surveys, questionnaires, booking pages, email, or SMS — that would cause Knowledge ERP to act as a Business Associate. If you are a covered entity or business associate under HIPAA, the Service is not suitable for your PHI, full stop.
3.3 Payment card data
We never store payment card numbers. Our subscription billing is processed by Stripe, and payments you collect from your own customers flow through your own Stripe or Square account under your direct agreement with that processor. Entering cardholder data into the Service (see Section 3.1) is prohibited and would place that data outside any PCI-compliant environment.
4. Prohibited Activities
You must not use the Service, your Account, the API, or any public surface of the Service to:
4.1 Attack, probe, or interfere with systems
- attempt to gain unauthorized access to Knowledge ERP systems, other Customers' Accounts or data, or third-party systems (including by credential stuffing, brute force, password-reuse exploitation, token theft, or social engineering);
- probe, scan, or test the vulnerability of the Service or its infrastructure without our express written authorization. If you want to conduct security testing (including automated scanning or penetration testing) against the Service, you must request and receive written authorization from legal@peltonsolutions.com first, and you must confine any authorized testing to your own Account and data;
- conduct, facilitate, or participate in denial-of-service or distributed-denial-of-service attacks;
- bypass or interfere with any rate limit, authentication, access control, tenant-isolation boundary, or other security measure;
- intercept, monitor, or interfere with sessions or traffic of other Users or Customers.
If you discover a security vulnerability in the Service, report it to legal@peltonsolutions.com and do not exploit it, share it, or access data beyond the minimum needed to demonstrate it.
4.2 Abuse the API or automate improperly
- use the API, or any automated means, to access, enumerate, or scrape data belonging to other tenants, or to probe for the existence of other tenants' records, subdomains, or resources;
- circumvent rate limits — including by rotating tokens, distributing requests across accounts or IP addresses, or exploiting endpoints not subject to a limit;
- automate Account creation, trial sign-ups, or other Service registration flows, including to obtain repeated free trials by creating duplicate Accounts or using multiple email addresses;
- automate interactions with other Customers' public booking pages, surveys, or portals (form spam, bulk fake bookings, survey stuffing);
- attempt to reverse engineer, decompile, or extract the source code of the Service except as expressly permitted by law.
4.3 Impersonate or deceive
- impersonate Knowledge ERP, Pelton Solutions, our personnel, or any other person, organization, or entity;
- register or use an Account subdomain that impersonates another brand, person, or organization, or that violates our subdomain naming rules (see the Terms of Service);
- forge headers, sender identities, or other technical metadata to misrepresent the origin of content or communications sent through the Service.
4.4 Resell or repackage the Service improperly
- resell, sublicense, or repackage the Knowledge ERP platform itself to third parties without our written permission. (Using the Service to run your own business — including customer-facing surfaces like the booking pages and customer portal that serve your own customers — is normal use and is permitted within the limits of your plan.)
5. Email Rules
The Service sends email on your behalf — invoices, quotes, reminders, survey invitations, appointment confirmations, portal links, and automation-rule messages — branded with your company name and delivered through our email infrastructure (Amazon SES). You are the sender of record for every message the Service sends at your direction or under your automation rules; we are the sending infrastructure. If you send email through the Service:
- the email must comply with CAN-SPAM (clear identification of commercial nature, accurate header information, a working unsubscribe honored within 10 business days, valid postal address) and, where recipients may be in Canada, CASL;
- you must have a lawful basis for emailing each recipient (e.g., consent, an existing customer relationship, or another lawful basis under applicable law);
- you must maintain a current suppression list and not email anyone who has opted out — including by re-importing opted-out addresses or re-triggering automations to them;
- you may not send to addresses harvested from public sites, scraped, purchased without consent, or otherwise obtained without permission;
- you may not use transactional or relationship messages (invoices, confirmations, reminders) as a vehicle for unrelated marketing; and
- you must promptly cooperate with abuse and spam complaints and take corrective action.
Deliverability monitoring and automatic enforcement. To protect platform deliverability for all Customers, Knowledge ERP attributes every outgoing message to the sending Account, monitors per-Account bounce and spam-complaint rates, and maintains a global suppression list. The Service automatically throttles, pauses, or disables an Account's email sending when its complaint or bounce rates exceed the thresholds we publish or reasonably set from time to time (measured over a rolling window with a minimum send volume, and adjusted as needed to protect deliverability). As an illustration, industry norms treat a spam-complaint rate above a small fraction of one percent as a serious problem, and sustained rates at that level are typically enough to suspend sending. Enforcement may occur with or without prior notice, and persistent or serious abuse may result in permanent loss of email features or Account termination. See the Terms of Service.
6. SMS Rules
SMS is sent only through your own Twilio account, connected by you, using your own numbers and your direct agreement with Twilio. Knowledge ERP does not operate the SMS channel, does not capture SMS consent, and does not provide an opt-out mechanism for SMS recipients. Accordingly, if you use SMS automations:
- compliance with the TCPA and applicable state texting laws is entirely your responsibility — including obtaining the required prior express consent (prior express written consent for marketing messages) from every recipient before any message is triggered;
- honoring opt-outs is entirely your responsibility — you must recognize and honor STOP, UNSUBSCRIBE, and equivalent requests, and remove opted-out numbers from your automation triggers and segments; do not rely on the Service to do this for you;
- you must comply with Twilio's own acceptable-use and messaging policies and applicable carrier rules (including registration requirements such as A2P 10DLC);
- you must not send SMS containing content prohibited by Section 2 or to phone numbers obtained without permission.
You are the sender of record for every SMS your automations trigger, and you agree to defend and indemnify us as the Terms of Service provide for claims arising from your messaging.
7. Outbound Webhooks and Tenant-Connected Integrations
The Service can POST your record data to any URL you nominate via outbound webhooks, and can exchange data with services you connect (QuickBooks Online, Shopify, WooCommerce, ShipStation, Gmail, Outlook, Twilio, your own Stripe or Square account). These are tenant-directed data flows: you choose the destination, and the destination's own terms and security govern what happens to the data after it leaves the Service.
- You are solely responsible for every webhook destination URL you configure — for verifying that you control or trust it, for the security of data delivered to it, and for the consequences of data arriving there. Configuring a webhook to a URL you do not control or have authorization to send data to is a violation of this AUP.
- You must keep webhook shared secrets and integration credentials confidential, and promptly remove webhooks and disconnect integrations you no longer use.
- You must not use webhooks or integrations to route data to a destination in furtherance of any activity prohibited by this AUP, or in violation of the connected service's own terms.
- You are responsible for having the right, under applicable law and your own privacy commitments, to disclose the relevant data to each destination you connect.
8. Public Forms: Booking Pages, Surveys, and Questionnaires
The Service lets you collect data from members of the public through public booking pages, open-link and invited surveys, and pre-appointment questionnaires — including through custom fields you define. The people filling in these forms are your customers and prospects; you are the controller of the data collected:
- you are responsible for the lawful collection of all data submitted through your public forms, including having a lawful basis and providing any privacy notice or disclosure required by applicable law at or before the point of collection;
- you must not use public forms to collect the sensitive data categories prohibited by Section 3 (do not put a health question, a Social Security number field, or a card-number field on a questionnaire);
- you must not knowingly collect personal information from a child under 13 through your public forms in violation of the Children's Online Privacy Protection Act (COPPA), and you must not direct booking pages, surveys, or questionnaires at children under 13. (The Service itself is offered only to Customers who are 18 or older and using it for business — see the Terms of Service);
- you must not use public forms to deceive respondents about who is collecting the data or why.
Survey invitations record open and response timestamps; you are responsible for any disclosure of that tracking your own privacy notices require.
9. Reasonable Use of Resources
Knowledge ERP plans are sold based on assumptions about normal business usage patterns. While we do not publish specific resource caps as a hard contractual limit, we may consider use of the Service "abusive" or "outside the spirit of the plan" if it:
- consistently consumes storage, compute, API, or email volume at multiples of typical Customer usage on the same plan without a clear, legitimate business reason;
- uses attachments primarily as a file-storage, file-sharing, or bulk-distribution backend unrelated to your business records (we are an ERP, not a CDN or backup target);
- causes degraded performance for other Customers;
- generates persistent abuse complaints, deliverability incidents, security alerts, or copyright/DMCA notices; or
- is part of a pattern of behavior that would normally trigger enforcement under another section of this AUP.
We will generally contact you before taking action for resource-based concerns and give you a chance to either reduce usage or upgrade to an appropriate plan.
10. Reporting Abuse
If you believe an Account, a public form, an email or SMS sent through the Service, or any other use of the Service violates this AUP or applicable law, please report it:
- General abuse: legal@peltonsolutions.com
- Spam / phishing: legal@peltonsolutions.com with subject "Phishing / Spam Report"
- CSAM: legal@peltonsolutions.com with subject "CSAM Report" (we also report to NCMEC as required by law)
- DMCA copyright notices: Pelton Solutions LLC, Attn: DMCA Agent, 101 Rainbow Drive PMB 1624, Livingston, TX 77399; legal@peltonsolutions.com (U.S. Copyright Office Registration No. DMCA-1074343). See the procedure in the Terms of Service.
Please include URLs, screenshots, message headers (for email abuse), and a description of the violation. We may need to share certain information with the reporter, the affected party, or law enforcement, as appropriate.
We do not guarantee a specific response time, but we treat urgent abuse — especially CSAM, ongoing phishing, and active malware distribution — as high priority.
11. Enforcement
When we determine, in good faith, that this AUP has been or is being violated, we may take one or more of the following actions, with or without notice depending on severity:
- request that the Customer remove or modify specific content;
- remove or disable access to specific content, records, attachments, or features;
- disable specific public forms, surveys, booking pages, webhooks, integrations, or API tokens;
- throttle, pause, suspend, or permanently disable email sending (including automatically, per Section 5);
- suspend or terminate the Customer's entire Account;
- preserve content, account information, and connection logs to comply with law and legal process;
- report the matter to law enforcement, NCMEC, payment processors, anti-abuse clearinghouses, or other appropriate parties; and
- recover from the Customer any costs Knowledge ERP incurs as a result of the violation (including legal fees and third-party fees), to the extent permitted by the Terms of Service.
We make enforcement decisions in our reasonable discretion. We may decline to enforce in any particular case without waiving our right to enforce in others.
12. Appeals
If you believe an enforcement action was taken in error, you may appeal by emailing hello@knowledgeerp.com (subject "AUP Appeal") within fourteen (14) days, including your Account subdomain, the action taken, and an explanation of why you believe the action was incorrect. We will review the appeal and respond within a reasonable time. Appeals are not available for actions required by law (for example, removals required by valid court order or in response to verified CSAM).
13. Changes to This Policy
We may update this AUP from time to time. Material changes will be communicated with reasonable advance notice (by email and/or in-product notice). The "Last Updated" date above reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated AUP.
14. Contact
Pelton Solutions LLC Attn: Knowledge ERP — Abuse / Trust & Safety 101 Rainbow Drive PMB 1624 Livingston, TX 77399
Abuse and AUP questions: legal@peltonsolutions.com General support: hello@knowledgeerp.com