1. Purpose and scope
This Acceptable Use Policy ("AUP") sets out what is and is not allowed on the Sabasi Platform ("Sabasi", the "Platform").
Sabasi is OI's digital data platform for collecting, managing, analysing, visualising and publishing data, including surveys, dashboards, data sources, public sites, impact tracking, artificial intelligence features and workflow automation.
This AUP applies to account holders and the Users they authorise ("you"), and forms part of your agreement with Open Institute alongside the Terms of Service and, where applicable, the Data Processing Agreement ("DPA").
The Privacy Policy is a transparency notice you should also read. It is not part of this agreement.
Individuals who only submit responses to a survey conducted through Sabasi are not parties to this AUP. The relevant account holder is responsible for its relationship with Respondents.
By using Sabasi as an account holder or authorised User, you agree to comply with this AUP.
2. Permitted use
You may use Sabasi to collect, manage, analyse, visualise, publish and act on data, provided that your use is lawful, authorised and consistent with these Terms and applicable law.
Where personal data is involved, you must have an appropriate lawful basis under Kenya's Data Protection Act, 2019 and any other data protection law that applies to your processing.
3. Your responsibilities
Where you determine the purposes and means of processing personal data through Sabasi, you are responsible for your obligations as data controller.
You are responsible for:
- having a lawful basis for collection and obtaining consent where it is required;
- where you process children's personal data and Kenyan law applies, obtaining verifiable parental or guardian consent unless a lawful exception applies, protecting and advancing the child's rights and best interests, and applying appropriate age-verification and other safeguards;
- being transparent with Respondents about what you collect and why;
- keeping personal data accurate and collecting only what is reasonably necessary;
- honouring Respondents' applicable data protection rights and responding to their requests;
- keeping account credentials, API keys and connected integration credentials secure;
- not sharing individual login credentials between Users; and
- complying with applicable laws, including the Data Protection Act, 2019, the Children's Act, 2022 and the Computer Misuse and Cybercrimes Act, 2018.
Where OI receives a data-subject request relating to personal data for which you are the controller, OI will forward or otherwise assist with the request as required by applicable law and the DPA.
4. Prohibited content
You must not create, upload, store, publish or distribute through Sabasi content that:
- constitutes child sexual abuse material (CSAM);
- unlawfully promotes, incites or facilitates terrorism, extremist violence, hatred or violence against persons or groups;
- is unlawful, defamatory, threatening or harassing;
- facilitates serious unlawful activity; or
- infringes intellectual property or other legal rights, including copyright, trademark or confidentiality rights.
This section does not prohibit legitimate research, documentation, journalism, monitoring or data collection concerning sensitive subjects merely because those subjects include violence, terrorism, extremism or other harmful conduct.
5. Prohibited data practices
You must not use Sabasi to:
- collect or process personal data without appropriate authority and a lawful basis;
- process children's personal data without meeting applicable legal requirements and safeguards;
- collect or misuse sensitive personal data without satisfying the additional legal requirements applicable to that processing;
- import, obtain or use data that you have no legal right or authority to use;
- repurpose personal data for an incompatible or unlawful purpose;
- deliberately make sensitive or confidential personal data publicly accessible without appropriate authority; or
- use data obtained through Sabasi for unlawful discrimination, exploitation or other unlawful harm.
6. Prohibited conduct
You must not:
- introduce malware, malicious code or other harmful material;
- attempt to circumvent or defeat Platform security;
- attempt unauthorised access to Sabasi, another account or tenant, Customer Data or OI systems;
- probe, scan or test Platform vulnerabilities without OI's prior written authorisation;
- scrape, overload, disrupt or interfere with the Platform;
- circumvent quotas, usage limits, permissions or access controls;
- use Sabasi to send spam or distribute surveys or messages abusively;
- use APIs, integrations, webhooks or workflow automation to facilitate unlawful or abusive activity;
- impersonate another person or organisation without authority; or
- engage in fraud, deception or material misrepresentation through the Platform.
7. Reporting and detection
Potential violations of this AUP may be reported through any reporting mechanism made available within Sabasi or by contacting:
Reports are reviewed in accordance with the Sabasi Trust & Safety / Reporting Policy.
OI may use reasonable technical and human measures to detect malware, abuse, unlawful content or other threats to Sabasi and its users.
Where automated safety or security detection tools are deployed, their operation may vary according to the relevant feature, content type and technical environment.
Where OI becomes aware of suspected CSAM or other content that must be reported under applicable law, OI may:
- immediately restrict access to the affected content or account;
- preserve information only to the extent reasonably necessary or legally required for investigation, evidence or reporting;
- report the matter to competent authorities where required or permitted by law; and
- cooperate with lawful investigations.
OI may also make reports to appropriate child-protection organisations or other competent bodies where lawful and reasonably necessary to protect individuals from harm.
8. Enforcement
Where we reasonably believe this AUP has been breached, we may take action proportionate to the nature and severity of the issue.
This may include:
- issuing a warning or requesting corrective action;
- restricting, unpublishing or disabling content;
- disabling a survey, dashboard, public site, integration or workflow;
- restricting particular Platform functionality;
- temporarily suspending access;
- terminating an account;
- preserving information where required by law or reasonably necessary for investigation;
- returning or deleting Customer Data in accordance with applicable law, the DPA and controller instructions; or
- cooperating with competent authorities where legally required or appropriate.
Where reasonably practicable, we will provide notice and an opportunity to correct the issue before taking serious enforcement action.
We may act immediately and without prior notice where reasonably necessary to address an urgent security risk, prevent serious harm, comply with law, preserve evidence, or respond to suspected serious unlawful activity, including CSAM.
Enforcement and reporting decisions are handled in accordance with the Sabasi Trust & Safety / Reporting Policy.
9. Changes
We may update this AUP to reflect changes to Sabasi, applicable law or our safety and security requirements.
We will publish the updated version with a new effective date.
Where a change materially affects your obligations, we will provide reasonable notice where practicable.
Continued use after the change takes effect constitutes acceptance where permitted by applicable law.
10. Contact
Questions or abuse reports:
Open Institute
9 Riverside Building
P.O. Box 50474-00100
Nairobi, Kenya
Email: hello@openinstitute.africa