Waygo Inc.
This policy sets out what you may and may not do when you use the Waygo platform — the dashboard, the APIs, the maps it publishes, and any related service (together, the "Platform"). It exists to protect the organisations that use the Platform, the people whose information appears on their maps, and the Platform itself.
1. The agreement that governs your access
- Your access to the Platform is provided under, and governed by, the agreement between Waygo Inc. ("Waygo") and the organisation that provisioned your account (the "Customer Agreement"). This policy forms part of that agreement. If this policy and the Customer Agreement conflict, the Customer Agreement prevails.
- Nothing in this policy creates a separate contract between you and Waygo beyond your obligation to use the Platform in accordance with it. The organisation that provisioned your account is responsible to Waygo for your compliance.
- How we handle your own account information is described in our Privacy Policy.
2. Who this policy applies to
This policy applies to everyone who accesses the Platform using an account, an API key, or on behalf of a Waygo customer, including employees, contractors and agencies acting for a customer. Where the context requires, "you" includes the organisation on whose behalf you act.
3. Your account
- Keep your login credentials and API keys confidential. Do not share them with anyone, including colleagues — each person who needs access should have their own account.
- Use multi-factor authentication where the Platform offers it.
- You are responsible for all activity that occurs under your credentials until you tell us they have been compromised. If you suspect unauthorised access to your account or key, notify us immediately at legal@waygomaps.com and change the credential.
- By accepting this policy you confirm that you are authorised by the organisation that provisioned your account to act on its behalf within the Platform, within the role and permissions assigned to you.
- Do not attempt to access any account, data, map or resource that you have not been authorised to access, even if a technical weakness would allow it.
4. Data you upload or connect
- Upload, enter or connect only data that you have the right to use and that you have obtained all necessary consents to use. This includes personal data about exhibitors, speakers, staff, attendees and registrants: you are responsible for giving them any notice, and obtaining any consent, that privacy law requires.
- Do not upload or connect any of the following without Waygo's prior written agreement: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; genetic or biometric data; health data; data about sex life or sexual orientation; government-issued identification numbers; payment-card numbers; or data about criminal convictions or offences.
- Do not upload personal data of children under the age at which parental consent is required in the relevant jurisdiction, except where you have obtained that consent.
- When you connect a third-party system to the Platform — for example, a registration or ticketing platform — you confirm that you are authorised to connect it and that the data exchanged may lawfully be shared with Waygo for the purpose of providing the Platform. Keep the credentials for connected systems secure, and disconnect any integration you no longer need.
- Keep the data you place on the Platform accurate and up to date, and remove it when it is no longer needed.
5. Prohibited uses
You must not use the Platform, or permit anyone to use it, to:
- violate any applicable law or regulation, or facilitate anyone else doing so;
- infringe or misappropriate anyone's intellectual property, privacy, publicity or other rights;
- publish content that is defamatory, obscene, harassing, threatening, hateful or discriminatory, or that is otherwise objectionable in the context of an event or venue open to the public;
- upload, transmit or link to malware, malicious code or any material designed to interfere with the Platform or any other system;
- circumvent, disable or interfere with security features, access controls, rate limits or usage restrictions of the Platform;
- probe, scan or test the vulnerability of the Platform or any network connected to it, except as permitted in Section 8;
- scrape, crawl, harvest or bulk-extract data from the Platform, or from maps published through it, beyond the functionality the Platform provides for that purpose;
- reverse engineer, decompile or attempt to derive the source code or underlying structure of the Platform, except to the extent applicable law expressly permits;
- resell, sublicense, time-share or otherwise make the Platform available to any third party except as the Customer Agreement permits, or use it to build or benchmark a competing product;
- impersonate any person or organisation, misrepresent your affiliation, or falsify the origin of content;
- send unsolicited commercial messages, or use contact details obtained through the Platform for any purpose other than the operation of the relevant event or venue;
- use the Platform to collect personal data about individuals beyond what is needed to operate the map, or to track or profile individuals;
- interfere with any other customer's use of the Platform, or place a disproportionate load on it;
- remove, obscure or alter any proprietary notice, attribution or branding that the Platform displays.
6. Content on published maps
- Maps you publish may be viewed by the public — on websites, on mobile devices and on kiosks in physical venues. You are responsible for the content you publish, for its accuracy, and for having the right to publish it.
- Published content must be suitable for a general audience.
- Include on a map only the personal data about exhibitors, speakers and other individuals that is needed for the purpose of the map, and remove it when the law requires or the individual has a right to have it removed.
- Waygo may remove or disable access to content that it reasonably believes violates this policy or the law, and will notify you where practicable.
7. API use
- API keys are confidential. Store them securely, never embed a key with write permissions in client-side code or a public repository, and use the narrowest permission scope that the task requires.
- Respect the documented rate limits and usage guidelines. If you need higher limits, ask us.
- Do not use the API to bulk-export data you would not otherwise be entitled to access, or to redistribute Platform data to third parties except as the Customer Agreement permits.
- Rotate keys periodically, and revoke any key that is no longer needed or that may have been exposed.
8. Security research and responsible disclosure
We welcome reports of security vulnerabilities. If you find one, tell us at legal@waygomaps.com and give us a reasonable opportunity to fix it before disclosing it to anyone else. Do not access, modify or exfiltrate data that is not yours, do not disrupt the Platform or other users, and do not test the Platform in ways that go beyond what is necessary to demonstrate the issue. We will not pursue legal action against researchers who act in good faith and within these guidelines.
9. Monitoring and enforcement
- We may, but are not obliged to, monitor use of the Platform to verify compliance with this policy and to protect the Platform and its users.
- If we reasonably believe that you have violated this policy, we may take any action we consider appropriate, including removing or disabling content, restricting or suspending your access or your organisation's access, and, where the Customer Agreement permits, terminating it. We will notify you or your organisation where practicable, but may act immediately where the violation creates a risk to the Platform, its users, or third parties.
- We may inform your organisation of a violation, and we may report unlawful activity to law-enforcement or regulatory authorities.
10. Reporting violations
If you become aware of a violation of this policy, or of content on a Waygo-published map that you believe is unlawful or infringes your rights, please tell us at legal@waygomaps.com with enough detail for us to locate the content and understand the concern.
11. Changes to this policy
We may update this policy from time to time. The version number and effective date at the top of the page identify the current version, and previous versions remain available at this address. We will notify the designated contact at each customer at least thirty days before a material change takes effect. Continued use of the Platform after a change takes effect constitutes acceptance of the updated policy.
12. Contact
Waygo Inc., 41 Windhaven Terrace, Thornhill, Ontario, Canada L4J 7N8 · legal@waygomaps.com
Previous versions: none. This is the first published version.
Related: Privacy Policy · Data Processing Addendum · Sub-processors