This document is not in force yet.
What follows is the structure of the Acceptable Use Policy, written so you can see the shape of it before the language is settled. It is being prepared with counsel, it has not been adopted, and nothing on this page creates or varies an obligation on either side. The terms that currently bind your account are available on request from legal@comsky.ai — ask and we will send them the same working day, in IST hours.
What you may run on our machines, and what you may not.
One policy across the whole suite rather than one per product, because the account tree, the isolation model and the billing wallet are also defined once for the whole suite.
1. Purpose and scope
Sets out what this policy governs: every workload, record and message carried on Comsky infrastructure. It will apply to Cloud, Backup, CRM and TallyBridge as they run today, and to Telephony, Chat, Books, HRMS and Monitor from the day each one ships.
2. Who this policy binds
The account owner, every user invited under that account, and — where the account sits below a partner — the reseller’s own customers. The hierarchy runs admin to distributor to reseller to customer, and the policy follows it down.
3. Responsibility for your users
Confirms that you answer for conduct under your account, and that a reseller answers for its customers, because we escalate to the partner rather than around them. Offboarding a person removes their access across every product at once.
The categories this policy will enumerate.
Each heading below will carry a specific list rather than a general prohibition, so that a reasonable person can tell in advance whether a workload is allowed.
4. Prohibited content
Content that is unlawful in India, infringing, or sexually exploitative of children, together with the categories that follow from the Information Technology Act and the intermediary rules. Your data sits on disks inside the country, so Indian law is the law that reaches it.
5. Prohibited activities
Fraud, phishing, distribution of malware, unsolicited bulk messaging, and any attempt to defeat metering or billing. Covers use of the platform to attack a third party as well as use of it to attack us.
6. System and network integrity
No unauthorised access, scanning, denial of service, or attempts to reach another tenant’s data. Tenant scope is forced in PostgreSQL rather than left to application code, and an attempt to cross it is recorded against the account that made it.
7. Messaging, email and telephony conduct
Consent requirements, sender identity, DLT registration for Indian telecom traffic, and the carrier and WhatsApp policies that pass through to you. This section takes effect for Telephony and Chat when those products ship.
Where the rules differ by product.
Compute, storage and shared capacity raise different questions, and a single paragraph would answer none of them properly.
8. Compute and GPU workloads
What may run on GPU instances, virtual machines and bare metal, including our position on mining and on reselling raw capacity outside the partner programme. Compute is billed by the hour against a prepaid wallet, so an abusive or runaway workload spends a real balance.
9. Storage and backup content
What may be placed into per-device encrypted vaults. The backing machine has no permission to delete from its own vault, which is the point of the design and also the reason this section has to be specific about what you put there.
10. Fair use and resource consumption
The limits that apply to shared capacity, and how we raise them with you before we act on them. There is no minimum term and no lock-in, so fair use is not a lever we have any reason to use as a retention device.
11. Third parties and onward compliance
Payment gateways, SMS and WhatsApp carriers and other sub-processors are named in the Data Processing Addendum along with what each receives. Their acceptable use rules pass through to you, and this section will say which ones.
What happens when someone crosses the line.
The part of an acceptable use policy that actually matters is the part describing what we do, on what evidence, and what you can do about it.
12. Reporting a violation
Reports go to legal@comsky.ai; a security vulnerability goes to security@comsky.ai, which is acknowledged within one working day. The acknowledgement time for an abuse report is —.
13. Investigation
What we look at, and what we do not. Sign-ins, factor changes and administrative actions are written to an append-only, hash-chained trail, and staff access to production data needs an explicit, time-boxed grant that appears in your own log rather than only in ours.
14. Suspension and termination
A graduated response, from a warning through the suspension of a single workload to closure of the account, with the threshold for each stated. Notice before a non-emergency suspension: —.
15. Notice, appeal and reinstatement
How we tell you, who you reach, and what restores service. Support is staffed in IST, and an appeal is answered by a person rather than a form. Window to appeal a suspension: —.
Your data, and the paperwork behind all of this.
16. Your data during and after enforcement
Export stays available in an open format without asking us, and a deletion request is honoured and confirmed back to you. How long data is retained after an account closes, and whether a suspension pauses that clock: —.
17. Governing law and disputes
The contracting entity is Comhard Technologies Pvt Ltd, registered in Noida, Uttar Pradesh. Governing law, venue and the dispute procedure: —.
18. Changes to this policy
How a change is published, and how much warning you get before it applies to a workload you are already running. Notice period for a material change: —.
19. How to reach us
The address for policy questions is legal@comsky.ai. The officer required under the Indian intermediary rules will be named on the grievance page rather than here. Named officer: —.
Related and in the same state of preparation: terms of service, privacy policy and SLA. The controls this policy relies on are described on the security page, which is current.
Need the terms that are actually in force?
We will send you the current binding agreement, the Data Processing Addendum and the sub-processor list. Ask for all three at once and save a round trip.
Comhard Technologies Pvt Ltd, Noida. Support and legal correspondence in IST.