Zetta

Acceptable Use Policy

What is prohibited when using Zetta, how vulnerabilities are responsibly reported and what the consequences of misuse are; suspension, termination of the contract and, where applicable, a criminal complaint.

Last updated2026-10-05Current versionVersion2026-10-05SHA-2561daf2378c93b

01Scope

1.1. This Acceptable Use Policy forms part of the Terms and Conditions of Service and binds each customer company, each User it enables and each third party to whom it grants external access or an API key. The customer company is responsible for compliance with this Policy by all of them.

1.2. Zetta is a management system shared by many companies on the same infrastructure. The rules in this Policy exist to protect each company from the others, to protect the people whose data is loaded into the system, and to keep the service reliable for everyone.

02Prohibited uses

By using Zetta, the customer company, its Users and the third parties it authorizes undertake not to:

Security and isolation

  • (a) attempt to access, read, modify or delete data of another company, of third-party accounts or of parts of the system for which they have no permission, or probe whether such access is possible;
  • (b) breach, circumvent, disable or probe the security controls, request limits, isolation between companies, the audit log or any technical protection measure;
  • (c) share credentials, use another person's account, impersonate a User, a company, the Provider or a public agency, or tamper with the audit log;
  • (d) introduce malicious software, files containing harmful executable code or content designed to exploit vulnerabilities, or use the Platform to attack third parties;
  • (e) carry out penetration tests, vulnerability scans, load tests or any other security testing without the prior written authorization of the Provider (Section 3);

Load, automation and interfaces

  • (f) automate use of the Platform, extract data in bulk (scraping) or use the API in a way that degrades the service for other companies, exceeds the published limits or circumvents the assigned quotas;
  • (g) use API keys, webhooks or external accesses for purposes other than those authorized by the owning company, or transfer them to third parties;

Fraud, improper tax use and unlawful acts

  • (h) issue invoices that do not correspond to real transactions, use internal or non-fiscal documents in place of the tax documents required by law, alter the numbering or content of issued invoices, or use the Platform to evade tax, labor or consumer protection obligations;
  • (i) use the Platform, its online store or its collections for money laundering, terrorist financing, tax evasion, fraud, the sale of unlawful goods or services or any other activity contrary to law;
  • (j) register a company or User with false data, with another person's CUIT (tax identification number) without authorization or with an ARCA certificate that does not belong to them;

Personal data and content

  • (k) load personal data without a legal basis to process it, load sensitive data that is unnecessary for the purpose of the system, or use third-party data obtained through the Platform for purposes other than the commercial or employment relationship that justifies it;
  • (l) load or publish content that is unlawful, defamatory, discriminatory, that infringes third-party intellectual property rights or that violates people's privacy;
  • (m) send unsolicited commercial communications from the marketing, online store or CRM functions without the word "publicidad" (advertising) in the header, without a working unsubscribe mechanism or to anyone who has already asked not to receive them (Section 27 of Law 25,326 on the Protection of Personal Data (Ley 25.326); Disposición 4/2009 of the Dirección Nacional de Protección de Datos Personales), or make advertising calls to persons registered in the National "Do Not Call" Registry (Law 26,951 (Ley 26.951));

Intellectual property and resale

  • (n) copy, modify, decompile, disassemble, reverse engineer, create derivative works of or attempt to obtain the source code of the Platform;
  • (o) resell, sublicense, rent, lend or present the service to third parties as if it were their own, or offer it as a service to other companies, except under a written agreement with the Provider;
  • (p) use the trademarks of the Provider or of third parties in a way that suggests an endorsement, association or certification that does not exist;

Minors

  • (q) enable persons under 18 years of age as Users.

03Security testing and responsible disclosure

3.1. The Provider values good-faith security reports. If you find a vulnerability in the Platform, report it to hola@zetta.ar with a description of the problem, the steps to reproduce it and, if any, the impact you estimate. The address and contact keys are also listed at https://zetta.ar/.well-known/security.txt.

3.2. What we ask. Limit yourself to the minimum necessary to demonstrate the problem; do not access, download, modify or delete data of other companies or persons beyond what is indispensable to verify the flaw; do not degrade the service; do not use social engineering against staff or Users; do not exploit the vulnerability or disclose it publicly until it has been fixed; and give the Provider a reasonable period to fix it.

3.3. What we offer. Acknowledgment of receipt within 2 business days; an identified person in charge of following up on the report; priority correction according to severity; information on how it was resolved; and, if the reporter so wishes, public recognition once it has been fixed. Anyone who acts in good faith in accordance with this Section will not be reported by the Provider nor be subject to any claim for the access carried out in the course of the report. The Provider does not currently maintain a bounty program.

3.4. Security tests that go beyond what is described in Section 3.2 require prior written authorization, with an agreed scope, dates and test accounts.

04Compliance and consequences

4.1. In the event of a prohibited use, the Provider may, depending on its seriousness: (a) warn the company and require correction within a given period; (b) limit features, quotas or accesses; (c) suspend the User, the external access or the entire company; (d) terminate the contract in accordance with the Terms and Conditions. Unless the risk to the security of the Platform, of other companies or of third parties requires immediate action, the Provider gives notice beforehand and explains the reason.

4.2. When the prohibited use may constitute a crime, in particular unlawful access to a computer system or data (Section 153 bis of the Argentine Criminal Code), unlawful access to or disclosure of personal data (Section 157 bis), computer damage (Section 183) or computer fraud (Section 173, subsection 16), or affects third parties, the Provider may file the corresponding complaint or notification, preserve the evidence and cooperate with the authorities, and will inform the customer company when the law permits.

4.3. Suspension or termination for prohibited use does not entitle the company to a refund of the billed periods and does not release it from the indemnification obligations of the Terms and Conditions.

05How to report abuse

If you detect that a company or a User of Zetta is using the service in violation of this Policy, for example unsolicited email sent from a store published with Zetta, or content that infringes your rights, write to hola@zetta.ar with the subject "Abuse report" ("Denuncia de abuso"), indicating what you saw, when and how it affects you. We review each report, act in accordance with Section 4 and inform you of the outcome to the extent that confidentiality permits.

06Changes to this Policy

The Provider may update this Policy to reflect new features, new risks or regulatory changes, in accordance with the amendment procedure of the Terms and Conditions. The current version, its date and its cryptographic fingerprint appear in the header.

Contact

Write to us and we answer through the same channel.

Personal data and data subject rights

privacidad@zetta.ar

General enquiries

hola@zetta.ar

This document is published in Spanish. If you are reading a translation, the Spanish version is the only binding one.