SprintHR Acceptable Use Policy

Provider: Gleent, Inc.
Product: SprintHR
Effective Date: October 1, 2026
Version: 1.0

This SprintHR Acceptable Use Policy (the “AUP”) forms part of the terms governing access to and use of SprintHR and applies to Customers, Authorized Users, administrators, applicants, contractors, integrations, API clients, and other persons or systems that access or use SprintHR.

Capitalized terms not defined in this AUP have the meanings given in the SprintHR Customer Agreement or other applicable SprintHR terms.

By accessing or using SprintHR, you agree not to use the Services in a manner prohibited by this AUP.


1. Purpose

This AUP is intended to protect:

  • SprintHR customers and users;
  • employees, applicants, contractors, and other data subjects;
  • Gleent, Inc. and its personnel;
  • the confidentiality, integrity, and availability of SprintHR;
  • third-party systems and services connected to SprintHR; and
  • the lawful and reliable operation of the Services.

This AUP supplements the SprintHR Customer Agreement, Data Processing Addendum, Privacy Policy, AI Terms, and other applicable SprintHR terms.


2. General Rule

You must use SprintHR only for lawful, authorized, and legitimate business purposes.

You must not use SprintHR:

  • in violation of applicable law, regulation, court order, or binding governmental requirement;
  • in violation of another person’s rights;
  • outside the permissions granted to you by your organization;
  • to access, collect, process, disclose, alter, or delete information without proper authority; or
  • in a manner that materially threatens the security, reliability, availability, integrity, or lawful operation of SprintHR or another system.

3. Unauthorized Access and Security Violations

You must not:

  • access or attempt to access an account, tenant, database, system, API, file, record, or resource that you are not authorized to access;
  • obtain or attempt to obtain another user’s credentials, authentication tokens, API keys, session identifiers, recovery codes, or other security credentials without authorization;
  • bypass, disable, circumvent, probe, or interfere with authentication, authorization, role-based access controls, tenant isolation, rate limits, security controls, or technical restrictions;
  • exploit or attempt to exploit a vulnerability in SprintHR or a connected service without prior written authorization from Gleent;
  • conduct unauthorized vulnerability scanning, penetration testing, security testing, enumeration, brute-force testing, credential stuffing, or similar activity;
  • intercept communications or data without authorization;
  • introduce malware, ransomware, spyware, viruses, worms, trojans, malicious scripts, destructive code, or other harmful software;
  • interfere with or degrade the availability or performance of SprintHR, including through denial-of-service activity;
  • intentionally alter, delete, corrupt, suppress, or manipulate data without proper authority;
  • use SprintHR to attack, compromise, scan, disrupt, or gain unauthorized access to another system; or
  • knowingly facilitate another person’s unauthorized access or security violation.

If you discover a suspected security vulnerability, you must not exploit it beyond what is reasonably necessary to identify the issue. You should report it promptly to Gleent through an authorized security or support channel.


4. Unauthorized Processing or Disclosure of Personal Data

You must not use SprintHR to:

  • collect, access, use, copy, export, disclose, share, modify, or delete personal data without appropriate authority;
  • process personal data for purposes unrelated to the legitimate purposes for which you are authorized to use SprintHR;
  • disclose employee, applicant, payroll, government identification, banking, performance, health, or other personal information to unauthorized persons;
  • use another person’s personal data for harassment, intimidation, discrimination, identity theft, fraud, or other unlawful purposes;
  • intentionally expose, publish, download, distribute, or retain personal data known to have been obtained through unauthorized access;
  • defeat or bypass Customer-configured privacy, confidentiality, or access restrictions; or
  • instruct Gleent or an AI Feature to process personal data in a manner that violates applicable privacy or data-protection law.

Customers remain responsible for determining the lawful purposes and permissions applicable to Customer Data submitted to SprintHR.


5. Credential and Account Misuse

You must not:

  • share individual user credentials where account sharing is not expressly permitted;
  • impersonate another user, employee, applicant, administrator, customer, or third party without authorization;
  • create accounts using false identity information for deceptive, fraudulent, or abusive purposes;
  • use another person’s account without authorization;
  • permit unauthorized persons to use your account;
  • conceal the true origin of unauthorized activity; or
  • use compromised credentials or tokens.

Users are responsible for protecting credentials and promptly reporting suspected compromise.


6. Tenant, Role, and Permission Abuse

You must not:

  • access data belonging to another SprintHR customer or tenant without authorization;
  • use administrator privileges for purposes unrelated to legitimate organizational administration;
  • elevate your own privileges or another user’s privileges without authority;
  • change roles, permissions, payroll settings, employee records, audit information, or security settings for fraudulent, retaliatory, deceptive, or unauthorized purposes;
  • deliberately configure permissions to expose information to users who should not have access; or
  • misuse privileged access obtained through support, administration, development, integration, or maintenance functions.

Customer administrators are responsible for assigning and reviewing roles and permissions appropriate to their organization.


7. Fraud, Deception, and Misrepresentation

You must not use SprintHR to:

  • commit or facilitate fraud, theft, forgery, embezzlement, identity theft, or other unlawful conduct;
  • fabricate employment records, payroll records, attendance records, approvals, applications, documents, credentials, or audit evidence for fraudulent purposes;
  • knowingly submit materially false information to deceive an employer, employee, applicant, customer, regulator, or other person;
  • manipulate system records to conceal unauthorized activity;
  • falsely represent that content, decisions, or communications were created or approved by another person; or
  • use SprintHR to facilitate phishing, credential theft, social engineering, or similar deceptive activity.

8. Harassment, Threats, and Harmful Conduct

You must not use SprintHR to:

  • threaten, harass, stalk, intimidate, abuse, or unlawfully target another person;
  • distribute content intended to facilitate violence or credible threats of violence;
  • unlawfully discriminate against individuals or groups;
  • expose another person’s private information for the purpose of harassment or retaliation;
  • send abusive, malicious, or persistently unwanted communications through SprintHR; or
  • use employee or applicant information to cause unlawful or unjustified harm.

This Section does not prohibit lawful workplace investigations, disciplinary processes, compliance activities, or other legitimate HR functions carried out with proper authority.


9. Illegal, Infringing, or Unauthorized Content

You must not upload, store, transmit, generate, or distribute through SprintHR content that:

  • violates applicable law;
  • infringes intellectual property, privacy, confidentiality, publicity, or other legal rights;
  • contains information obtained through unlawful access or disclosure;
  • is uploaded in breach of a binding confidentiality obligation;
  • contains malicious code;
  • is intended to facilitate criminal or fraudulent activity; or
  • you do not have the legal right or organizational authority to process through SprintHR.

Customer is responsible for determining whether it has the necessary rights and authority to submit Customer Data and other content to SprintHR.


10. AI Feature Misuse

In addition to the SprintHR AI Terms, you must not use SprintHR AI Features to:

  • make unlawful discriminatory decisions;
  • intentionally generate false employment, payroll, disciplinary, investigative, or applicant records;
  • impersonate another person deceptively;
  • process personal data for an unauthorized or unlawful purpose;
  • bypass legally required human review or safeguards for significant decisions;
  • misrepresent AI-generated content as independently verified fact when material verification is required;
  • manipulate AI Features to obtain data belonging to another customer or user;
  • attempt to extract protected system prompts, credentials, confidential implementation details, model weights, or proprietary information through unauthorized means;
  • use AI Features to develop malware, facilitate unauthorized access, or compromise systems; or
  • use AI Outputs as the sole basis for significant employment decisions where applicable law or Customer policy requires human review or additional safeguards.

AI Features are decision-support tools and do not provide independent authority to perform actions outside the permissions granted through SprintHR.


11. API, Integration, and Automation Abuse

If you use SprintHR APIs, webhooks, integrations, bots, scripts, automations, or connected services, you must not:

  • exceed documented or communicated usage limits in a manner that materially harms the Services;
  • intentionally generate excessive, abusive, or disruptive traffic;
  • use undocumented methods to bypass authentication, authorization, billing, quotas, or technical restrictions;
  • scrape, harvest, or systematically extract SprintHR data except as authorized by the Customer and permitted by the Services;
  • use integrations to access data beyond the permissions granted by the Customer;
  • forge, manipulate, or replay authentication credentials or webhook events without authorization;
  • send malicious payloads to SprintHR or connected services; or
  • use an integration to circumvent this AUP or other SprintHR terms.

Gleent may impose reasonable technical limits to protect the reliability, security, and fair use of the Services.


12. Scraping, Reverse Engineering, and Technical Misuse

Except to the extent expressly permitted by applicable law or written authorization from Gleent, you must not:

  • reverse engineer, decompile, disassemble, or attempt to derive SprintHR source code;
  • copy or reproduce protected SprintHR software, interfaces, models, prompts, workflows, or proprietary technical materials;
  • scrape or systematically extract information from SprintHR outside authorized export, API, reporting, or integration functionality;
  • build or maintain an unauthorized competing service using protected SprintHR technology or confidential information;
  • circumvent licensing, subscription, feature, seat, usage, or technical restrictions; or
  • use automated tools to interfere with normal operation of the Services.

Nothing in this Section restricts lawful interoperability, security research, or other conduct that cannot legally be prohibited.


13. Resource Abuse and Service Interference

You must not:

  • consume computing, storage, network, API, AI, email, messaging, or other resources in a manner intended to disrupt or degrade SprintHR;
  • intentionally create excessive requests, jobs, files, records, events, messages, or other activity designed to exhaust service capacity;
  • use SprintHR for cryptocurrency mining or other unrelated high-resource workloads;
  • operate unauthorized bulk-email, spam, bot, crawling, or traffic-generation activity through SprintHR;
  • repeatedly trigger known failures or faults for disruptive purposes; or
  • interfere with another customer’s or user’s legitimate use of the Services.

14. Spam and Unsolicited Communications

Where SprintHR provides messaging, email, notification, recruitment, or communication functionality, you must not use it to:

  • send unlawful spam;
  • send deceptive or fraudulent communications;
  • send bulk communications to recipients without appropriate authority or lawful basis;
  • circumvent unsubscribe or opt-out mechanisms where legally required;
  • falsify sender identity; or
  • use SprintHR communications to facilitate phishing, malware distribution, fraud, or harassment.

15. Employment and HR Misuse

You must not use SprintHR to:

  • falsify payroll, attendance, leave, performance, disciplinary, recruitment, or employment records;
  • access employee or applicant records without a legitimate authorized purpose;
  • retaliate against or unlawfully target an employee or applicant using SprintHR data;
  • intentionally manipulate data or workflows to deprive another person of rights or benefits unlawfully;
  • use SprintHR to implement unlawful discriminatory employment practices; or
  • use information obtained through SprintHR for purposes outside your authorized organizational role.

Nothing in this AUP prevents Customers from carrying out lawful HR, payroll, recruitment, compliance, investigation, disciplinary, or workforce-management activities.


16. Circumvention of Restrictions

You must not attempt to evade or circumvent:

  • account suspensions;
  • feature restrictions;
  • rate limits;
  • usage limits;
  • security controls;
  • payment or subscription restrictions;
  • customer-configured approval requirements;
  • role-based access controls; or
  • enforcement actions taken under this AUP.

Creating or using additional accounts, tenants, API credentials, integrations, or identities to evade restrictions is prohibited.


17. Reporting Misuse and Security Issues

If you become aware of:

  • suspected unauthorized access;
  • credential compromise;
  • personal data exposure;
  • abusive use;
  • security vulnerabilities;
  • malicious integrations;
  • fraudulent activity; or
  • another material violation of this AUP,

you should promptly report the issue through SprintHR’s authorized support, security, legal, or privacy channels.

For privacy and personal-data concerns, contact:

[email protected]

For legal matters, contact:

[email protected]


18. Investigation and Cooperation

Gleent may investigate suspected violations of this AUP where reasonably necessary to:

  • protect the Services;
  • protect customers, users, data subjects, or third parties;
  • investigate security incidents;
  • enforce applicable agreements;
  • comply with law; or
  • prevent fraud or abuse.

Customers and Authorized Users must provide reasonable cooperation in investigations relating to their accounts, integrations, configurations, or use of the Services, subject to applicable law and contractual obligations.

Gleent will handle Customer Data accessed during an investigation in accordance with applicable privacy, confidentiality, security, and contractual obligations.


19. Enforcement

If Gleent reasonably determines that use of SprintHR violates this AUP, Gleent may take proportionate measures, including:

  • warning the Customer or Authorized User;
  • requiring corrective action;
  • temporarily restricting a feature, integration, account, or credential;
  • suspending access to affected Services;
  • revoking compromised credentials or tokens;
  • blocking malicious traffic or content;
  • preserving relevant evidence where legally appropriate;
  • terminating access where permitted by the Customer Agreement; or
  • reporting activity to appropriate authorities where required or permitted by law.

Where practicable and legally permitted, Gleent will seek to limit enforcement to the scope and duration reasonably necessary to address the violation, security risk, or abuse.

Immediate action may be taken where reasonably necessary to address an urgent security threat, unlawful activity, serious abuse, or material risk to SprintHR, a Customer, a data subject, or a third party.


20. Customer Responsibility for Authorized Users

Customer is responsible for:

  • informing Authorized Users of applicable SprintHR terms and organizational policies;
  • managing user access, roles, and permissions;
  • promptly removing or restricting access when no longer appropriate;
  • taking reasonable measures to prevent misuse through Customer-controlled accounts;
  • investigating suspected internal misuse where appropriate; and
  • notifying Gleent when Customer becomes aware of activity that materially threatens SprintHR or Customer Data.

Customer is not responsible for activity caused solely by Gleent’s breach of its obligations or by security failures outside Customer’s reasonable control.


21. Changes to this AUP

Gleent may update this AUP from time to time to address:

  • new security threats or abuse patterns;
  • changes to SprintHR functionality;
  • changes in applicable law;
  • new integrations, APIs, or AI Features; or
  • operational or security requirements.

For changes that materially affect Customer’s rights or obligations, Gleent will provide reasonable notice where required by the Customer Agreement or applicable law.

The current version and effective date will be published through the SprintHR Legal Center.


22. Relationship to Other SprintHR Terms

This AUP supplements:

  • the SprintHR Customer Agreement;
  • the SprintHR Data Processing Addendum;
  • the SprintHR Privacy Policy;
  • the SprintHR AI Terms;
  • the SprintHR Subprocessor List;
  • the SprintHR Service Level Agreement; and
  • applicable Orders or product-specific terms.

If a conflict concerns acceptable use, security misuse, or prohibited conduct, this AUP applies to that subject matter unless another binding agreement expressly provides otherwise.


23. Contact

Questions regarding this AUP may be sent to:

Gleent, Inc.
Unit 18, 2nd Floor, Sundrel Bldg.
Brgy. Sala, City of Cabuyao
Laguna, Philippines

Legal: [email protected]
Privacy / Data Protection: [email protected]