mavi finansmavi finans

Acceptable Use Policy

Rules and restrictions for using our services.

1. Purpose

This Acceptable Use Policy ("AUP") sets out the rules and restrictions that apply when you use any product or service provided by mavi finans, including mavi pay, mavi card, mavi wallet, and mavi finans banking (collectively, the "Services"). By using any of our Services, you agree to comply with this AUP. Violation of this policy may result in suspension or termination of your account, reporting to relevant authorities, and legal action where appropriate.

2. Prohibited activities

You may not use any mavi finans Service for any of the following: Illegal activities — Any activity that violates applicable laws or regulations, including but not limited to fraud, money laundering, terrorist financing, tax evasion, bribery, or corruption. Restricted businesses — Operating businesses in the following categories without explicit prior approval: - Adult content or services - Gambling, betting, or casino operations - Sale of tobacco, e-cigarettes, or vaping products - Sale of weapons, ammunition, or firearms - Sale of prescription pharmaceuticals without a valid licence - Multi-level marketing or pyramid schemes - Cryptocurrency mining operations or unregistered ICOs - Unlicensed financial services Harmful content — Distributing malware, viruses, ransomware, or any other harmful code. Engaging in phishing, social engineering, or credential theft. Abuse of the platform — Attempting to bypass payment processing fees, manipulating checkout flows, or abusing refund and dispute mechanisms. Creating multiple accounts to circumvent limits or restrictions. Intellectual property infringement — Selling or distributing copyrighted material, counterfeit goods, or products that infringe on trademarks, patents, or trade secrets without authorisation.

3. Restricted activities (mavi pay specific)

As a merchant on mavi pay, you must additionally not: - Use mavi pay to process payments for third parties without authorisation (acting as a payment facilitator) - Submit transactions without a legitimate underlying sale of goods or services - Use test or sandbox environments for production transactions - Misrepresent the nature, quality, or origin of your products or services - Fail to deliver products or services after receiving payment - Charge customers without their explicit consent - Process transactions in countries subject to comprehensive sanctions (as defined by the EU, UN, or OFAC)

4. Data and privacy obligations

If you collect, store, or process personal data through our Services, you must: - Comply with the General Data Protection Regulation (GDPR) and any other applicable data protection laws - Provide a clear and accessible privacy policy to your customers - Obtain valid consent where required before collecting personal data - Implement appropriate technical and organisational security measures - Notify us immediately if you become aware of a data breach involving data processed through our Services You must not use our Services to collect or store sensitive personal data (as defined by GDPR Article 9) unless you have obtained explicit consent and have implemented appropriate safeguards.

5. Security

You are responsible for maintaining the security of your account credentials, API keys, and webhook secrets. You must: - Use strong, unique passwords and enable two-factor authentication where available - Store API keys and webhook secrets securely — never expose them in client-side code, public repositories, or logs - Immediately notify us at security@mavifinans.sh if you suspect your credentials have been compromised - Not attempt to probe, scan, or test the vulnerability of our systems without prior written authorisation - Not interfere with or disrupt the integrity or performance of our Services

6. Enforcement

We reserve the right to investigate any suspected violation of this AUP. Enforcement actions may include: - Warning — For minor or first-time violations, we may issue a warning and request corrective action - Temporary suspension — We may suspend your access to Services while we investigate - Permanent termination — For serious or repeated violations, we may permanently terminate your account - Reporting — We may report violations to law enforcement, regulatory authorities, or financial partners as required by law - Financial remedies — We may withhold payouts, recover funds, or seek damages for violations that cause financial harm We may take enforcement action without prior notice if we determine, in our sole discretion, that there is an immediate risk of harm to our Services, our users, or third parties.

7. Reporting violations

If you become aware of any violation of this AUP, please report it immediately: Email: abuse@mavifinans.sh Subject: AUP Violation Report Please include as much detail as possible, including relevant account information, transaction IDs, and any evidence of the violation. We treat all reports confidentially. If you are reporting a security vulnerability, please follow our responsible disclosure process as described in our Security Policy.

8. Changes to this policy

We may update this Acceptable Use Policy from time to time. When we make material changes, we will notify you via email or through a notice on our website. Your continued use of the Services after the changes take effect constitutes acceptance of the updated policy. Last modified: June 2026