SUNDRITO ACCEPTABLE USE POLICY Release v1.3 — EN This Acceptable Use Policy (“AUP”) governs use of SUNDRITO and is intended to be incorporated into the Master Customer Agreement. 1. AUTHORIZED BUSINESS USE Customer and users may use SUNDRITO only for lawful, authorized business and operational purposes within the purchased scope and applicable permissions. 2. PROHIBITED ACCESS / SECURITY ACTIVITY Users must not: share credentials; impersonate another person; bypass access controls; probe or exploit vulnerabilities without written authorization; interfere with tenant isolation; use automated means that materially disrupt the Service; introduce malware; obtain or attempt to obtain another customer’s data; or access systems/features outside assigned authority. 3. PROHIBITED DATA Users must not knowingly submit data that SUNDRITO has identified as unsupported or prohibited, including unnecessary Social Security numbers, government identifiers, payment-card data, personal banking credentials, medical or immigration data, unrelated full payroll information, or passwords/secrets for unrelated systems. If a regulated/sensitive use becomes necessary, it requires a separately approved Product and legal/security review. 4. UNLAWFUL / HARMFUL CONTENT Users must not use the Service to violate law; infringe intellectual-property/privacy rights; facilitate fraud; harass, threaten or discriminate unlawfully; distribute malicious code; or create content that Customer has no authority to process. 5. EMPLOYMENT / HIGH-IMPACT DECISIONS SUNDRITO may organize training, competency, role, operational evidence or AI-assisted recommendations, but users must not treat the Service or AI output as sole legal authority for hiring, firing, compensation, discipline, protected-class decisions, immigration determinations, medical determinations or other high-impact decisions requiring independent legal/human judgment. 6. FOOD SAFETY / REGULATORY USE Operational standards, checklists and training artifacts do not constitute governmental certification, health-department approval or legal advice. Customer must maintain required licenses, food-safety programs, inspections and regulated procedures and must not represent SUNDRITO documentation as replacing them unless separately verified. 7. INTELLECTUAL PROPERTY Customer may use Customer-specific operational outputs as permitted by the Agreement, but may not copy, reverse engineer, extract, sell, publish as a competing library, or use SUNDRITO source code, generalized methodology, prompts, orchestration, generation/scoring logic or protected templates to build a competing proprietary product except to the extent a restriction is prohibited by law. 8. AUTOMATION / SCRAPING / API USE Automated access, scraping or API use is permitted only through interfaces and limits SUNDRITO has authorized. Customer must not circumvent technical limits or use automation to create unreasonable load or bulk-extract proprietary SUNDRITO methodology. 9. THIRD-PARTY RIGHTS AND CUSTOMER AUTHORITY Customer is responsible for obtaining rights and permissions for information it submits, including employee and business information, and for restricting users to appropriate organizational/location scopes. 10. ENFORCEMENT SUNDRITO may investigate suspected violations and may restrict or suspend affected access when reasonably necessary to protect the Service, Customer Data, another tenant or legal compliance. Where practicable, SUNDRITO will notify Customer and limit action to the affected scope. Material/repeated violations may constitute breach under the MSA. 11. REPORTING Suspected abuse, security issues or unauthorized access should be reported to support@sundrito.com.