OneBee Acceptable Use Policy

OneBee, Inc.

Version 1.0 · Effective date: September 9, 2026

This Acceptable Use Policy (the “Policy”) applies to all use of the OneBee Platform, whether under the OneBee Master Services and Subscription Agreement or the OneBee Terms of Service (each, the “Agreement”). It forms part of the Agreement. Capitalized terms not defined here have the meanings given in the applicable Agreement.

Breach of this Policy is a material breach of the Agreement.

Contents

1. Use restrictions

Customer will not, and will not permit any third party to:

(a) resell, sublicense, rent, lease, or otherwise transfer the Platform, except as expressly permitted by a written agreement with OneBee, including a OneBee Resale and Managed Services Agreement or an Order Form identifying a managed services provider;

(b) reverse engineer, decompile, or disassemble the Platform, except as applicable law permits;

(c) use the Platform to develop or train a competing product or service;

(d) circumvent a usage limit or any Entitlement;

(e) permit access by anyone other than an Authorized User, except that where an Order Form or a OneBee Resale and Managed Services Agreement designates a managed services provider, that provider's personnel may be authorized as Authorized Users, and Customer remains responsible for their acts and omissions;

(f) use the Platform in violation of applicable law;

(g) use the Platform or any Agent as the sole or automated means of making a decision producing legal or similarly significant effects on an individual, including decisions on employment, credit or lending, housing, insurance, education, healthcare, public benefits, or legal rights or status, unless a qualified individual reviews the relevant Agent output and makes the final decision and Customer's use complies with applicable law, including anti-discrimination, fair lending, and automated decision-making laws;

(h) use the Platform or any Agent to give medical, mental health, legal, financial, or other professional advice directly to individuals, or to provide crisis, emergency, or mental health support, unless a qualified licensed professional is responsible for the advice, Customer clearly discloses that recipients are interacting with an artificial intelligence system, and Customer's use complies with applicable law and professional rules;

(i) rely on the Platform or any Agent in an emergency, as the sole or determinative basis for determining the safety, roadworthiness, repair adequacy, or fitness for service of a vehicle, equipment, product, facility, or process, or for determining that any of them may be placed or returned into service, or otherwise where failure could result in death, personal injury, or harm to health or safety;

(j) submit to the Platform, or configure any Agent to retrieve or process, any Restricted Data as defined in the DPA, unless OneBee has agreed in writing in an Order Form to support it;

(k) use the Platform for, or to facilitate, any illegal activity or any violation of the rights of others;

(l) attempt to gain unauthorized access to the Platform, other accounts, or any connected system Customer is not authorized to access;

(m) probe, scan, or test the vulnerability of the Platform, or circumvent its security or authentication measures, without OneBee's prior written authorization;

(n) interfere with, disrupt, or place undue load on the Platform or its infrastructure;

(o) use the Platform to transmit malicious code or content;

(p) engage in competitive benchmarking of the Platform; or

(q) remove or obscure any proprietary notice from the Platform or its Documentation.

Clause (i) does not prohibit use for administrative, clerical, analytical, scheduling, documentation, or record-keeping workflows relating to service, parts, warranty, quoting, inventory, manufacturing, or back-office operations, provided every determination described in clause (i) is reviewed and made by a qualified individual.

Clause (j) applies regardless of whether the data is subject to any data protection law. Where Customer connects the Platform to a system that may contain Restricted Data, Customer is responsible for configuring scope, filters, and access controls so that Restricted Data is not retrieved. If Customer becomes aware that Restricted Data has been submitted, Customer will notify OneBee promptly and the parties will cooperate to delete it.

2. Customer security responsibilities

Customer will:

(a) authorize only those Connectors, Third-Party Services, accounts, data sources, and access scopes appropriate for its intended use, and where a Connector requires tenant-wide administrator consent, ensure its tenant administrator reviews and approves the requested permissions;

(b) promptly revoke credentials, authorizations, and service principals when a Connector is no longer required, when the authorizing individual no longer needs access, or on termination or expiration;

(c) provision, periodically review, and promptly deprovision access for Authorized Users, including departed or transferred personnel;

(d) enforce multi-factor authentication on the identity accounts used to access the Platform;

(e) review Agent execution records for activity inconsistent with its instructions or expectations, and promptly report suspected unauthorized or anomalous activity to OneBee;

(f) comply with the Agreement in determining which systems and Customer Data Agents may access. The rights, notices, consents, and lawful bases required for the processing of personal data are governed by the DPA, which controls over this Policy on that subject;

(g) maintain current contact information for a designated security contact; and

(h) notify OneBee without undue delay after discovering or reasonably suspecting a compromise of Customer credentials, identity accounts, Connector authorizations, connected Third-Party Services, or Customer's use of the Platform.

Customer is responsible for the configuration decisions, instructions, and access authorizations of Customer and its Authorized Users.

3. Customer-specific exceptions

An Order Form may state a Customer-specific exception to an identified provision of this Policy. Any such exception applies only to that Order Form and does not otherwise modify this Policy.

4. Enforcement

Breach of this Policy has the consequences the Agreement provides, which may include suspension, Customer's indemnity, exclusion from the liability cap, and OneBee's right to equitable relief.

5. Updates

OneBee may update this Policy as the Agreement provides. An update that materially and adversely affects Customer does not apply until the commencement of Customer's next Subscription Term Period and requires at least thirty (30) days' prior written notice. If this Policy conflicts with the Agreement, the Agreement controls.