This document forms part of the Ozibus Public Website Legal Centre. It should be read together with other policies that apply to the services and channels you use.
These API & Developer Terms apply to access to Ozibus APIs, SDKs, webhooks, developer credentials, widgets, code samples and related developer services.
12.1 Credentials and authentication
- Keep API keys, bearer tokens, signing secrets and private credentials confidential and out of public repositories, browser source and public documentation unless expressly designed to be public.
- Use separate credentials for development and production where available.
- Rotate a credential promptly if exposure is suspected.
- Do not share credentials between unrelated customers or organisations.
- Ozibus may revoke or rotate credentials where reasonably necessary for security or abuse prevention.
12.2 Permitted use
Developers may use Ozibus developer services only to integrate with and use the Services in accordance with the Agreement, product documentation, applicable law and any channel-specific rules. Access does not grant a right to resell, sublicense or provide unauthorised access to Ozibus except under a written reseller or partner agreement.
12.3 Rate limits and fair use
Ozibus may apply rate limits, quotas, concurrency limits, payload limits and abuse controls. Developers must not circumvent or intentionally distribute requests to evade those controls. Ozibus may throttle or reject requests that threaten reliability, security, cost control or fair use.
12.4 Webhooks
Customers are responsible for securing webhook endpoints, validating signatures or authentication controls provided by Ozibus, handling retries idempotently where applicable, and not relying on webhook delivery as the sole record for legally critical data unless the integration has been designed accordingly.
12.5 Security and prohibited activity
- Do not probe, scan or exploit Ozibus systems without written authorisation.
- Do not introduce malware or use the API for phishing, fraud, credential theft or unlawful surveillance.
- Do not use developer access to obtain data outside the Customer's authorised scope.
- Do not expose secret credentials in client-side applications or public examples.
- Report suspected security vulnerabilities under the Security & Responsible Disclosure Policy.
12.6 API changes and deprecation
Ozibus may add, modify or deprecate developer features. For material breaking changes to a generally available API, Ozibus will aim to provide reasonable migration notice where practicable. Emergency changes may occur without advance notice where necessary for security, legal compliance or serious platform risk.
12.7 Developer data handling
Developers must handle personal information obtained through Ozibus consistently with the Customer's authority, applicable privacy law, the DPA and the Customer's own privacy notices. Developers must not use recipient data obtained through Ozibus for unrelated profiling, resale or advertising without lawful authority.
12.8 Support and availability
Developer documentation and examples are provided to assist integration. Unless a written SLA states otherwise, code samples are illustrative and APIs are provided subject to the general service objectives and limitations in the Terms of Service.
12.9 WhatsApp channel integrations
Developers using Ozibus APIs, SDKs or webhooks to access the WhatsApp channel must not bypass or attempt to bypass recipient opt-in, template approval, customer-service windows, business verification, message categories, quality enforcement, rate limits, opt-out controls or other requirements imposed by Ozibus, Meta or WhatsApp.
An Ozibus API response indicating that a request was accepted does not guarantee that Meta/WhatsApp will accept, deliver or permit the underlying message. Status and webhook events are dependent on third-party provider behaviour and may be delayed, unavailable or changed.
Developers must not use WhatsApp user data obtained through Ozibus for unrelated profiling, advertising, resale, data enrichment or other purposes inconsistent with the Customer's instructions, applicable law or the governing WhatsApp/Meta terms.