Legal
Acceptable Use Policy
Version 1.0 · Effective 1 September 2026
Permanent URL of this version: https://www.oasisguestlab.ai/legal/aup/v1.0/ Current version always at: https://www.oasisguestlab.ai/legal/aup/
This policy is incorporated into the Oasis Guest Lab Terms of Service. Breaking it is a breach of that agreement and may lead to suspension under clause 9 of the Terms.
1. Why this policy exists, in one paragraph
Oasis Guest Lab runs on the official WhatsApp Business API. Access to that API depends on Meta's continued permission, given to us through our Business Solution Provider. If one client sends messages that Meta considers spam, deceptive or in breach of its policies, the consequences do not stop at that client: a phone number can be restricted, a quality rating can drop, and in a serious case our own platform access can be put at risk, which affects every other client. This policy exists so that everyone knows the line before anyone crosses it.
2. Who it applies to
This policy applies to you, to everyone on your team who uses the Service, to anyone you allow to use your account, and to any content you put into the Service, including unit data, templates and messages sent by your team through the dashboard.
You are responsible for what happens on your account.
3. Meta and WhatsApp policies, passed through
You must comply, at all times, with:
- the WhatsApp Business Messaging Policy;
- the WhatsApp Business Terms of Service;
- the Meta Platform Terms and the Meta Business Tools Terms, where they apply to you;
- any other Meta or WhatsApp policy that applies to your use of the WhatsApp Business Platform.
These are Meta's documents. Meta changes them, not us. We do not control them, we cannot vary them, and we cannot get you an exception to them. They are passed through to you as your own obligations under the Terms of Service. If Meta's policies and this policy differ, the stricter applies.
In particular, and without limiting the above:
- Opt-in. You must have the opt-in Meta requires before messaging a person, obtained in the way Meta requires, and you must keep evidence of it.
- Opt-out. You must honour a request to stop messaging, promptly and without argument, and you must tell us so we can configure the account accordingly.
- Marketing. You must not use the Service to send marketing, promotional or bulk messages unless the recipient has opted in as Meta requires and the message complies with Meta's rules for that message category.
- Prohibited goods and industries. You must not use the Service in connection with any product, service or industry that Meta prohibits.
4. What you must not do with the Service
4.1 Deception
- Do not use the Service to deceive a guest about who they are dealing with.
- Do not impersonate another business, another person, a government body or a platform.
- Do not use the Service to send messages designed to obtain payment, credentials or personal data under false pretences.
- Do not misrepresent the unit, the price, the availability or the terms of a stay.
4.2 Guest data
- Do not use guest personal data obtained through the Service for anything other than servicing that guest's stay and your own lawful, disclosed purposes as controller.
- Do not sell, rent or share guest data with a third party for that party's own marketing.
- Do not export conversation content to a system where it is not protected.
- Do not put personal data into unit data. Unit data describes a property, not a person.
- Do not use the Service to solicit health data, religious or belief data, biometric data or any other special category of data from guests.
- Do not use the Service to collect payment card details in the message thread.
4.3 Content
Do not send, or configure the AI to send, content that is unlawful, threatening, abusive, harassing, defamatory, obscene, hateful, discriminatory, or that infringes someone else's intellectual property.
Do not use the Service in a way that breaches UAE law, including law on electronic communications, content, public morals and consumer protection, or the law of any other country whose residents you are messaging.
4.4 Platform integrity
- Do not attempt to circumvent security measures, rate limits, escalation rules or access controls.
- Do not probe, scan or test the Service for vulnerabilities without our written permission, and do not run automated tooling against it.
- Do not reverse engineer, decompile, scrape, or extract our prompts, models, knowledge-layer structure or escalation logic.
- Do not resell, sublicense, white-label or provide the Service to a third party as if it were your own, unless your Order Form says you may.
- Do not connect the Service to a system, gateway or client that is not one we have approved.
- Do not use the Service to build a competing product.
4.5 Volume and abuse
- Do not use the Service for bulk messaging, blasts, cold outreach or list-based campaigns.
- Do not use it to message people who are not guests, prospective guests or your own team.
- Do not do anything that would reasonably be expected to trigger spam reports, block rates or quality-rating downgrades.
5. What you must do
- Keep unit data accurate. Access codes, entry instructions, parking, utilities, house rules, emergency contacts. Update them the day they change. The AI answers from what you give it, and a stale access code becomes a guest standing outside a locked door at midnight.
- Keep an escalation route open. A named person and a monitored channel, current with us at all times.
- Be reachable by a human for safety, security, emergencies, injury or illness, medical questions, allegations of crime, legal or regulatory matters, disputes and refunds. The Service is not an emergency service.
- Tell guests what they need to know. Where the law that applies to you requires you to tell guests that they are communicating with an automated system, tell them. You are the controller of guest data and the guest-facing privacy notice is yours to give.
- Keep credentials secure. Individual accounts for individual people. Tell us promptly if you think an account is compromised.
- Tell us about incidents. If you become aware of a security or data incident affecting the Service, tell us straight away.
6. What we may do
We may suspend the Service, in whole or in part, immediately and without prior notice, where Meta or our Business Solution Provider requires it, where your use puts our platform access or another client's service at risk, where we reasonably believe you are in breach of this policy or of applicable law, or where there is a security incident. Clause 9 of the Terms of Service sets out the whole suspension regime, including what we do when we suspend and what happens to fees.
We would always rather call you than switch you off. Where we can safely tell you first and give you a chance to fix it, we will.
Repeated or serious breach of this policy is a material breach of the Terms of Service and may lead to termination.
7. Reporting a problem
If you think someone is misusing the Service, or you have received a message you should not have, tell us: info@luxoasisadvisory.com · WhatsApp +971 58 508 9283.
8. Changes
This policy carries a version number and an effective date, and every version is archived at a permanent URL. A material change is notified at least 30 days in advance by email. A change made only to reflect a change in Meta's own policies takes effect when Meta's change does, and we will tell you as soon as we can.
Language. These documents are written in English. English is the governing language. If they are translated, the English version prevails.
This document has been prepared for review and requires sign-off by a qualified UAE lawyer before publication. It is not legal advice.