Acceptable Use Policy

Use CMD Ops for authorized work—not harm or hidden surveillance.

This policy protects customers, workers, the service, and the people whose information may appear in a company workspace. It forms part of the CMD Ops Terms of Service.

Effective and last updated: September 5, 2026

01

Authorized business use

Use CMD Ops only for legitimate internal business operations and only within a company, role, account, system, and record you are authorized to access. Follow applicable law, the Terms of Service, the Privacy Policy, your employer's policies, and any accepted Order Form.

02

Accounts and access

Do not share individual accounts, impersonate another person, use false identity or authority, evade a role boundary, reuse an invitation without permission, access another company, or help someone bypass authentication, company isolation, paid-feature controls, or file visibility.

Do not probe, scan, scrape, reverse engineer, or test the security of CMD Ops without prior written authorization. Good-faith security research must follow the reporting process on the Security page.

03

Workforce monitoring

Do not collect or use workforce location, time, photos, device information, or activity without a legitimate business purpose and every notice, permission, and process required by law. Do not pressure a worker to misstate consent, interfere with revocation controls, track a person outside authorized work, or use CMD Ops for stalking, intimidation, retaliation, discrimination, or covert surveillance.

Do not falsify time, breaks, assignments, approvals, locations, payroll exports, safety records, or audit history.

04

Customer and job information

Submit only information your company is permitted to use. Do not publish or expose customer addresses, phone numbers, files, photos, access instructions, or internal notes to an unauthorized person. Review visibility settings before sharing a document or enabling a portal.

05

Restricted information

Unless a signed statement of work expressly approves the data type and safeguards, do not use CMD Ops to store full payment-card numbers, bank credentials, account passwords, Social Security numbers, government identification images, medical or health records, biometric identifiers, classified information, export-controlled technical data, or information subject to a specialized regulatory security program.

Do not use CMD Ops as a system for emergency dispatch, life-safety monitoring, clinical decisions, or another purpose where delay or error could directly cause death or serious injury.

06

Illegal, harmful, or abusive content

Do not use CMD Ops to violate law or another person's rights; threaten, harass, exploit, or defraud; distribute malware; facilitate violence; infringe intellectual property; send unlawful spam; or store content that is deceptive, malicious, or unrelated to legitimate company operations.

07

Service integrity

Do not overload the service, automate requests in a way that disrupts normal use, evade storage or login limits, create accounts to avoid payment, manipulate usage records, introduce malicious code, interfere with another user's data, or use CMD Ops infrastructure to host unrelated files or public downloads.

Do not resell, sublicense, white-label, or provide CMD Ops as a service to another organization unless a written order allows it.

08

Integrations and automated actions

Use only integrations and automated actions your company is authorized to connect. Protect external credentials, respect provider terms and rate limits, review outputs before relying on them, and stop an integration if it sends data to the wrong destination. A connection to payroll, accounting, mapping, messaging, AI, or another provider does not transfer responsibility for the company's decisions.

09

Enforcement

We may investigate a credible report and limit the affected account, feature, or company when reasonably necessary to prevent harm, security risk, unlawful activity, or material policy breach. When practical, we will notify the company owner and allow a reasonable opportunity to explain or cure the issue. An urgent threat may require immediate action.

Repeated or serious violations may result in removal of prohibited content, suspension, or termination under the Terms. We will preserve lawful export and transition rights when doing so would not continue the harm or violate law.

10

Reporting misuse

Report suspected misuse to hello@retehost.com with "CMD Ops Abuse" in the subject,. Include the company, account or record involved, what occurred, when it occurred, and any immediate safety concern. Do not send passwords or full payment-card numbers.

11

Policy changes

We may update this policy to address new features, threats, or legal requirements. We will post the updated effective date and give account owners reasonable notice of a material change.