Acceptable Use Policy

Last updated: November 1, 2025

This Acceptable Use Policy (“AUP”) governs the use of Hafinen’s platform, APIs, integrations, AI-assisted tools, and related services (collectively, the “Services”).

This AUP forms part of Hafinen’s Terms of Service.

By using Hafinen, you agree to comply with this Policy.

Failure to comply may result in suspension, restriction, or termination of access.

1. Purpose

Hafinen is designed to support lawful workforce management, recruitment, payroll, attendance, compliance, and operational workflows.

This Policy exists to protect customers, employees, candidates, administrators, third parties, Hafinen’s infrastructure, and Hafinen’s legal compliance obligations.

2. Lawful Use Requirement

You may use Hafinen only for lawful business and organizational purposes.

You must comply with employment laws, labor laws, privacy laws, data protection laws, anti-discrimination laws, tax laws, payroll regulations, biometric regulations, and intellectual property laws.

You are solely responsible for your use of the Services.

3. Prohibited Activities

You may not use Hafinen to violate applicable laws, commit fraud, impersonate another person or organization, falsify records, forge payroll records, manipulate attendance records unlawfully, fabricate employment documentation, create false hiring records, misrepresent candidate qualifications, and abuse platform workflows for unlawful purposes.

4. Recruitment and Hiring Restrictions

You may not use Hafinen to conduct discriminatory hiring, unlawfully profile candidates, violate equal opportunity laws, collect candidate data without lawful basis, retain candidate data unlawfully, and process candidate data outside lawful recruitment purposes.

Customers remain responsible for fair and lawful recruitment practices.

5. Employee Monitoring Restrictions

You may not use Hafinen for unlawful workplace surveillance.

This includes covert employee monitoring, unlawful tracking, unauthorized attendance monitoring, unauthorized location tracking, and invasive behavioral profiling.

Customers must ensure lawful employee notice and authorization where required.

6. Biometric Data Restrictions

Where Hafinen is used with biometric systems, you may not collect biometric data unlawfully, bypass consent requirements where applicable, store raw biometric data in Hafinen, use biometric systems for unauthorized surveillance, and use biometric records beyond lawful attendance or workforce purposes.

Customers remain responsible for compliance with local biometric laws.

7. Payroll and Financial Misuse

You may not use Hafinen to evade taxes, falsify payroll records, conceal compensation obligations, manipulate statutory deductions unlawfully, and create fraudulent compensation records.

Customers remain solely responsible for payroll legality.

8. Content Restrictions

You may not upload or distribute content that is unlawful, infringes intellectual property, contains malware, contains ransomware, contains viruses, contains malicious scripts, contains abusive material, contains hate speech, and contains fraudulent content.

9. Security Abuse

You may not probe or scan Hafinen systems without authorization, attempt unauthorized access, exploit vulnerabilities, interfere with platform stability, perform denial-of-service attacks, bypass access controls, intercept data unlawfully, and test production systems without permission.

Security testing requires written approval from Hafinen.

10. API and Webhook Abuse

You may not exceed reasonable API limits, abuse API endpoints, attempt credential stuffing, scrape data unlawfully, abuse webhooks, bypass rate limits, create excessive automated traffic, and reverse engineer protected APIs.

Hafinen may restrict or revoke API access.

11. AI Misuse Restrictions

You may not use Hafinen AI tools to make unlawful discriminatory decisions, automate unlawful employment decisions, generate fraudulent legal documents, create misleading HR policies, conduct unlawful profiling, produce abusive content, violate labor laws, and violate privacy laws.

AI-assisted workflows remain subject to Hafinen’s AI Usage Policy.

12. Data Privacy Obligations

You must collect data lawfully, provide required notices, obtain required consents, maintain lawful retention practices, honor lawful deletion obligations, and process personal data responsibly.

Customers act as Data Controllers for their Customer Data.

13. Service Integrity

You may not overload Hafinen systems, disrupt service availability, interfere with other customers, misuse trial environments, abuse promotional offers, and create duplicate fraudulent accounts.

14. Intellectual Property

You may not copy Hafinen software unlawfully, reverse engineer proprietary systems, resell unauthorized access, misuse Hafinen branding, and infringe Hafinen intellectual property.

15. Enforcement

Hafinen may investigate violations of this Policy.

Hafinen may suspend accounts, restrict access, revoke API credentials, remove content, report unlawful conduct, and terminate subscriptions.

Enforcement may occur without prior notice where necessary.

17. Changes

Hafinen may update this AUP from time to time.

Continued use of the Services constitutes acceptance of updates.

エクスペリエンスを向上させるために Hafinen が使用するオプションの Cookie を選択できます。セキュリティ Cookie は認証、プラットフォームのセキュリティ、不正行為の防止、およびサービスの信頼性の高い動作に不可欠であるため、必ず必要であり、常に有効になっています。設定はいつでも更新できます。

必ず必要な Cookie

これらの Cookie は、Hafinen が安全かつ確実に動作するために不可欠です。これらは、アカウント認証、ログイン セッション、CSRF 保護、安全なセッション継続性、負荷分散、およびその他のコア プラットフォーム機能をサポートします。これらの Cookie はサービスが機能するために必要なため、無効にすることはできません。

セキュリティクッキー

これらの Cookie は、不審なアクティビティの検出、不正アクセスの防止、悪用の軽減、API リクエストの検証、レート制限のサポート、プラットフォームの整合性の維持により、アカウントとサービスを保護するのに役立ちます。これらの Cookie はセキュリティのために必要であり、無効にすることはできません。

ファンクショナルクッキー

ファンクショナル Cookie はユーザーの設定を記憶し、エクスペリエンスをパーソナライズします。言語、タイムゾーン、テーマ、アクセシビリティ設定、インターフェースのカスタマイズ、ダッシュボードの設定が保存される場合があるため、サービスを使用するたびにこれらを構成する必要はありません。

分析クッキー

分析 Cookie は、サービスがどのように使用されているかを把握するのに役立ち、使いやすさ、パフォーマンス、信頼性を向上させることができます。機能の導入、ページの操作、ナビゲーション パターン、ブラウザーの互換性、クラッシュ レポート、パフォーマンス メトリックなどの情報を収集します。可能な場合、この情報は集約または匿名化されます。

パフォーマンスクッキー

パフォーマンス Cookie は、サービスの速度、安定性、応答性を向上させます。これらは、キャッシュ、コンテンツ配信の最適化、トラフィック バランシング、アセットの読み込み、および一貫した信頼性の高いユーザー エクスペリエンスの提供に役立つその他のテクノロジーをサポートしています。

コミュニケーションクッキー

通信 Cookie は、通知配信、電子メール イベント追跡、SMS 確認、およびサービス使用中のお客様への情報提供を強化するその他の運用上の通信ワークフローなど、サービス関連のやり取りをサポートします。