Acceptable use policy
This policy exists because the value of an eFirma signature depends on nobody being able to abuse the platform that made it. It applies to everyone using the service, whether or not they pay for it, and it forms part of the terms of service.
1What you must not do
The absolute list. There is no plan on which any of this becomes acceptable.
- Send a document you have no lawful right to send, or that infringes someone else's rights.
- Impersonate a person or an organisation, or misrepresent who a document is from.
- Request a signature from someone you know has no authority to give it.
- Alter a document, its evidence or its audit trail — or attempt to make an alteration undetectable.
- Use eFirma for fraud, money laundering, or any purpose prohibited by Ethiopian law.
- Upload malicious code, or use the service to distribute it.
- Harass, threaten or repeatedly send documents to someone who has asked you to stop.
2Sending to a lot of people
Bulk sending is a feature, not a loophole. The rules that make it acceptable are the ones that keep the channel working for everyone.
- Send only to people who have a genuine relationship with your organisation, or who are legally required to receive the document.
- Make the sender identifiable in every message. A signer must know who is asking before they open anything.
- Honour a request to stop, and do not route around it by sending from a second workspace.
- Do not use signing links or passcode messages to carry marketing.
- Keep signer contact details accurate. Passcodes sent to the wrong number are a security incident, not a typo.
3Technical limits
Do not attack the service, and do not engineer around the limits it applies.
- No scanning, probing or penetration testing of the production service beyond a workspace you own — the rules for legitimate testing are on the security page.
- No attempt to bypass quotas, rate limits or plan restrictions, including by spreading one organisation's sending across multiple accounts.
- No automated collection of data from the service beyond what the API is meant to provide.
- No reselling or wrapping the service as your own without a written agreement with us.
4How we enforce it
Proportionately, with a conversation first, unless there is no time for one.
The usual order
We contact the workspace administrators, explain what we have seen, and give a period to put it right. Where it continues, we throttle sending; where it still continues, we suspend the account.
When we act immediately
Where there is ongoing harm — fraud, a compromised account, or messages going to people who never agreed to receive them — we suspend first and explain afterwards, on the same day.
What suspension does not touch
Documents already signed keep their evidence and remain verifiable. Suspension stops new sending; it does not retroactively undo what was properly signed.
Disagreeing with us
Reply to the notice, or write to [email protected]. A person reviews it, and we will say plainly if we got it wrong.
5Reporting abuse
If something reached you that should not have, tell us.
How to report
Write to [email protected] with the message or link you received and roughly when it arrived. You do not need an account, and you do not need to be the intended recipient.
What we do with it
We identify the workspace responsible, act under section 4, and — where you have asked — tell you the outcome. Reports about a document's content, rather than about how it was sent, are passed to the sending organisation.
Questions about this document, a signed copy on letterhead, or an Amharic version: [email protected]. Published in English; where an Amharic copy differs, the English version governs.
