Holiday AI, Data and Acceptable Use Policy
Last updated: 8 September 2026
This Policy forms part of the Holiday Terms of Service and applies to all Customers and authorised users of Holiday.
1. Purpose
Holiday combines business data infrastructure, artificial intelligence and digital workers capable of operating across authorised business systems.
This Policy establishes the boundaries for how those capabilities may be used.
2. Customer Data Belongs to the Customer
Customers retain ownership of their Customer Data.
Holiday does not claim ownership of business information because it has been ingested, stored, normalised, structured, related, analysed or processed through Holiday.
Holiday's underlying software, schemas, architecture, data models, orchestration, agent-control technology and other platform intellectual property remain Holiday's property.
3. No Cross-Customer Training
Holiday will not use identifiable Customer Data to train a general-purpose AI model for the benefit of unrelated customers.
Customer Data may be provided to an approved AI model where necessary to perform a task requested or authorised by that Customer.
Holiday may use de-identified and aggregated technical information to understand system reliability, utilisation and performance where that information does not identify a Customer or individual.
4. Model-Agnostic Operation
Holiday may support models from multiple AI providers.
The models available through Holiday may change over time.
Holiday may select, replace, add or remove models based on factors including:
- capability;
- reliability;
- security;
- availability;
- provider terms;
- performance; and
- cost of model consumption.
Where enabled, Customers may choose which available model is assigned to particular digital workers or tasks.
5. AI Compute
AI models consume different levels of computing resources.
Use of higher-capability or more expensive models may consume available AI compute capacity more rapidly than use of lower-cost models.
Holiday may apply:
- account limits;
- digital-worker limits;
- rate limits;
- task limits;
- model restrictions; and
- AI compute allowances.
These controls exist to provide predictable, safe and sustainable operation.
Because Holiday relies on third-party AI providers, the amount or measurement of included AI capacity and the rate at which individual models consume that capacity may change if an underlying provider materially changes its pricing, usage limits or measurement methodology.
A change in underlying model economics may therefore result in a corresponding adjustment to included compute capacity or model consumption rates without changing the Customer's underlying Holiday subscription arrangement.
6. AI Outputs
Artificial intelligence is probabilistic.
Outputs may therefore:
- contain errors;
- omit information;
- incorrectly interpret information;
- be incomplete;
- be unsuitable for a particular purpose; or
- resemble outputs produced for another user.
Customers must take this into account when determining the authority granted to a digital worker and the review required for a particular task.
7. Digital Workers
Holiday digital workers may be configured with specific capabilities, credentials and business responsibilities.
Customers are responsible for deciding:
- which systems a digital worker may access;
- which information it may access;
- which credentials it may use;
- what actions it may perform;
- what financial or operational limits apply; and
- when human approval or escalation is required.
Holiday may enforce additional technical restrictions notwithstanding a Customer's requested configuration.
8. Delegated Actions
A Customer may authorise Holiday to undertake actions on its behalf.
When an authorised digital worker performs an action within the capability granted to it by the Customer, the action is treated as an authorised use of the Holiday service.
Customers should not grant a digital worker broader authority than is reasonably necessary for its role.
9. Auditability
Holiday may record digital-worker activity so that actions can be attributed and reviewed.
Depending on the applicable feature, records may include:
- the digital worker involved;
- the objective or task;
- relevant system interactions;
- authorisation information;
- model activity;
- tool or integration activity;
- timestamps;
- results; and
- other operational records.
Auditability does not guarantee that an AI-generated decision or action is correct.
10. Connected Systems
Holiday will only access a connected business system through credentials, permissions or other authority made available by or on behalf of the Customer.
Customers must not provide access they are not entitled to grant.
Holiday may restrict an integration where continued use would breach a third-party provider's terms or create a material security risk.
11. Data Minimisation and Boundaries
Holiday may configure an integration to retrieve only particular categories of information required for a digital worker or business function.
Customers are encouraged to use the minimum access reasonably necessary for the relevant function.
Access to one connected system does not necessarily give every Holiday digital worker access to that system.
Credentials and capabilities may be restricted to particular workers or functions.
12. Prohibited Uses
Holiday must not be used to:
- break applicable law;
- access a system or information without authority;
- circumvent authentication, permissions, safety controls or usage limits;
- steal, expose or misuse credentials;
- introduce malware, ransomware, destructive code or other malicious software;
- conduct phishing, fraudulent impersonation or deceptive activity;
- send unlawful spam or unsolicited communications;
- infringe intellectual property or privacy rights;
- harass, threaten or unlawfully discriminate against individuals;
- facilitate fraud or financial crime;
- interfere with the security or availability of Holiday or another system;
- probe or exploit security vulnerabilities without written authorisation;
- use another Customer's information;
- attempt to extract Holiday source code, proprietary system prompts or protected platform technology;
- or enable unlawful automated decision-making.
13. High-Impact Decisions
Holiday should not be configured as the sole decision-maker for matters that have significant legal or similarly serious effects on an individual where human involvement or another safeguard is required by law or reasonably appropriate.
Examples may include certain decisions concerning:
- employment;
- termination;
- credit;
- insurance;
- legal rights;
- health;
- safety; or
- other materially consequential matters.
Holiday may assist with information gathering, analysis, workflow and recommendations in these areas, but the Customer is responsible for implementing appropriate governance and professional oversight.
14. Financial and Accounting Actions
Holiday may be authorised to interact with financial or accounting systems.
The Customer determines the authority given to each digital worker.
Where appropriate, Customers should establish monetary limits, role restrictions, review requirements or other controls around significant financial actions.
Holiday does not provide regulated financial, tax or accounting advice merely because it processes information contained in an accounting system.
15. Security Controls
Users must not attempt to disable or circumvent Holiday controls relating to:
- permissions;
- credentials;
- digital-worker capabilities;
- usage;
- account boundaries;
- logging;
- security;
- model access; or
- authorisation.
Holiday may suspend a worker, integration, account or task where continued operation presents a material security or compliance risk.
16. Third-Party AI Providers
Holiday may provide Customer Data to third-party AI providers where necessary to perform an authorised Holiday function.
Holiday seeks to use commercial services and configurations suitable for business processing.
Holiday does not authorise an AI provider to use identifiable Customer Data supplied through Holiday for unrelated general-purpose model training where such processing is within Holiday's contractual control.
17. Changes to Providers
Holiday is not dependent on any single AI model provider.
Holiday may change the provider or model used for a function where reasonably necessary because of:
- provider availability;
- commercial terms;
- security;
- capability;
- performance;
- legal or regulatory requirements; or
- product development.
A Customer's use of Holiday does not create a contractual entitlement to continued availability of a particular third-party model.
18. Enforcement
Holiday may investigate suspected violations of this Policy.
Where reasonably necessary, Holiday may restrict a digital worker, revoke an integration, suspend an account or prevent an action.
Immediate intervention may occur where Holiday reasonably believes continued operation creates a significant security, legal or safety risk.
Where appropriate, Holiday will work with the Customer to restore operation after the issue has been resolved.
19. Customer Responsibility
Holiday provides infrastructure and tools through which Customers can delegate business functions to artificial intelligence.
Customers remain responsible for determining how those tools are deployed within their organisation and for establishing appropriate authority, governance and oversight.
20. Changes to This Policy
Holiday may update this Policy to reflect changes in its technology, model providers, applicable law, security practices or service capabilities.
Material changes will be communicated by reasonable means where practicable.
The current version will always be published at holidayworks.com.au.