Terms of Service (Admin) - Provisional Draft
Version: v3.1-admin-draft1
Date: 2026-06-24
Currency: USD
Applicable Role: Admin
PROVISIONAL - FOR UI AND NAVIGATION TESTING ONLY
This draft was prepared as a temporary Admin-role document for JZ2-1665 by reference to the existing role-based Terms of Service and current system specifications. It is not a final legal instrument. It must be reviewed and approved by the Operator and qualified UAE legal counsel before production use. Replace all placeholders before publication.
1. Scope and Acceptance
1.1 These Terms of Service (Admin) (the Terms) govern access to and use of the administrative portal and administrative functions of the Holiday Homes Auction platform (the Service).
1.2 Admin means an individual who has been expressly authorized by the operator of the Service (the Operator) to access administrative functions.
1.3 By accessing or using an Admin account, the Admin confirms that the Admin is duly authorized and agrees to comply with these Terms, the Privacy Policy, applicable internal policies, documented operating procedures, and applicable laws and regulations.
1.4 All financial amounts displayed, managed, reported, or exported through the Service are denominated in USD unless the Service expressly states otherwise.
2. Authorization and Role-Based Access
2.1 Admin access is limited to authorized personnel with an active business need.
2.2 The Operator may assign, change, restrict, suspend, or revoke Admin permissions at any time according to role, responsibility, security requirements, or operational need.
2.3 An Admin must use only the permissions assigned to that Admin and must not attempt to obtain or exercise higher privileges without written authorization.
2.4 Admin access is personal and non-transferable. Shared Admin accounts are prohibited unless the Operator has expressly approved a controlled service account for a documented technical purpose.
3. Account and Security Obligations
3.1 The Admin must keep credentials, recovery information, authentication devices, and access tokens confidential and secure.
3.2 The Admin must not disclose credentials, allow another person to use the Admin account, or reuse credentials in an insecure manner.
3.3 The Admin must use multi-factor authentication and other security controls when provided or required by the Operator.
3.4 The Admin must promptly report suspected unauthorized access, credential compromise, data leakage, malware, security weakness, or other incident through the Operator's approved incident-reporting channel.
3.5 The Admin must sign out or lock the session when the administrative portal is unattended and must not access the Service from an unapproved device or network.
4. Permitted Administrative Functions
4.1 Subject to assigned permissions and approved procedures, Admin functions may include:
- managing Admin, Owner, Holiday Home, and Affiliate accounts;
- reviewing account, licence, property, and supporting information;
- approving, rejecting, suspending, or restoring records where the Service and approved procedures allow;
- managing system settings, message templates, notifications, and operational content;
- monitoring auctions, bids, awarded properties, contracts, payment states, commissions, revenue, and reports;
- reviewing audit information and supporting investigation, customer support, and compliance activities; and
- exporting information only where the Service provides an authorized export function and the Admin has a valid operational purpose.
4.2 The availability of a function does not itself authorize its use. Each action must be within the Admin's assigned responsibility and must follow the applicable approval process.
5. Accuracy, Integrity, and Auditability
5.1 The Admin must take reasonable steps to verify information before approving, rejecting, changing, or publishing it.
5.2 Administrative actions must be accurate, necessary, proportionate, and capable of being explained by reference to an authorized request or documented procedure.
5.3 The Admin must not conceal, falsify, backdate, delete, disable, or improperly alter audit logs, payment records, contract records, review records, notifications, or other system records.
5.4 Errors must be corrected through an approved correction process. The Admin must not create an undocumented workaround that compromises traceability or data integrity.
5.5 The Operator may record and monitor Admin activity for security, audit, support, compliance, and service-improvement purposes, subject to applicable law and policy.
6. Auction, Payment, and Contract Controls
6.1 The Admin must not manipulate an auction, bid, bidder selection, deposit, winning amount, commission, payment state, or contract state for personal benefit or outside an approved operational process.
6.2 A payment shown as pending, failed, expired, cancelled, or otherwise unverified must not be treated as successfully received.
6.3 A contract must not be treated as formed or activated solely because a user reached a payment page, selected an agreement checkbox, or initiated payment. Under the current system rule, contract formation or activation occurs only after the Service verifies receipt of the Holiday Home's required final payment.
6.4 Refunds, waivers, manual payment adjustments, contract-state changes, and exceptional corrections may be performed only where the Admin is expressly authorized and the action is documented and auditable.
6.5 The Admin must not bypass controls intended to prevent duplicate payments, duplicate transactions, duplicate notifications, or unauthorized access.
7. Confidentiality and Data Protection
7.1 The Admin may access personal, commercial, property, payment, licence, contractual, and operational information only to the extent necessary for an authorized task.
7.2 The Admin must not disclose, copy, download, export, retain, or use information for a purpose unrelated to authorized Service operations.
7.3 Information must be shared only with authorized recipients through approved channels and with the minimum amount of data reasonably required.
7.4 The Admin must follow the Privacy Policy, information-security requirements, retention rules, deletion procedures, and applicable data-protection laws.
7.5 Suspected privacy or confidentiality incidents must be reported immediately. The Admin must preserve relevant evidence and must not conduct an unauthorized investigation.
8. Neutrality and Conflicts of Interest
8.1 The Admin must act impartially and must not favor an Owner, Holiday Home, Affiliate, bidder, employee, contractor, or other party for personal, financial, or improper reasons.
8.2 The Admin must not collude with a user, disclose non-public auction information, influence an award improperly, or use administrative access to obtain an unfair advantage.
8.3 An actual or potential conflict of interest must be disclosed promptly. The Admin must refrain from the affected action unless the Operator authorizes continued involvement under a documented mitigation.
9. Administrative Communications
9.1 Notifications, emails, templates, announcements, and other communications created or enabled by an Admin must be accurate, authorized, relevant, and appropriate for the intended recipients.
9.2 The Admin must not send misleading, unlawful, abusive, discriminatory, malicious, or unrelated content through the Service.
9.3 The Admin must use approved templates and variables where required and must verify recipients and material variable values before sending or enabling a communication.
10. Prohibited Conduct
The Admin must not:
- access records or functions without a legitimate operational need;
- circumvent permissions, security controls, approval controls, or segregation-of-duty requirements;
- introduce malware, perform unauthorized security testing, or interfere with Service availability;
- use production data in an unapproved environment;
- impersonate another person or misrepresent an administrative decision;
- use confidential information for personal, competitive, or third-party benefit;
- manipulate ratings, reviews, notifications, reports, commissions, or financial records;
- use the Service for unlawful activity or in a manner that infringes third-party rights; or
- instruct another person to perform an action that would breach these Terms.
11. Service Availability and Changes
11.1 Administrative functions may be changed, limited, suspended, or unavailable during maintenance, security response, incident handling, legal compliance, or system updates.
11.2 The Operator does not guarantee uninterrupted availability of the administrative portal.
11.3 The Admin must follow approved business-continuity and escalation procedures when a required function is unavailable.
12. Suspension and Termination of Admin Access
12.1 The Operator may immediately suspend or revoke Admin access where authorization ends, responsibilities change, security risk arises, misuse is suspected, or these Terms are breached.
12.2 On suspension or termination, the Admin must stop using the account and return or securely delete Operator information and access materials as instructed.
12.3 Confidentiality, data-protection, record-integrity, intellectual-property, audit, and liability obligations that by their nature should continue will survive termination of access.
13. Intellectual Property
13.1 The Service, administrative interface, software, documentation, templates, branding, and related materials are owned by or licensed to the Operator or its licensors.
13.2 The Admin receives only a limited, revocable right to use those materials for authorized administrative duties and must not copy, modify, distribute, reverse engineer, or exploit them except as expressly authorized or permitted by law.
14. Disclaimer and Responsibility
14.1 To the maximum extent permitted by applicable law, the Service is provided for authorized administrative use on an "as available" basis.
14.2 The Admin remains responsible for actions taken through the Admin account, except to the extent the action resulted solely from a Service defect or unauthorized access not caused or contributed to by the Admin.
14.3 Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited.
14.4 Employment, contractor, confidentiality, information-security, and other agreements between the Admin and the Operator remain applicable. If a conflict exists, the Operator must determine the applicable priority with legal advice where necessary.
15. Amendments
15.1 The Operator may amend these Terms to reflect legal, regulatory, security, operational, or Service changes.
15.2 The Operator may require renewed acknowledgement when material changes are made.
15.3 Continued Admin access after an effective amendment constitutes acceptance only to the extent permitted by applicable law and the Admin's governing relationship with the Operator.
16. Governing Law and Jurisdiction
16.1 These Terms are intended to be governed by the applicable laws of the United Arab Emirates and the Emirate of Dubai.
16.2 The final governing-law, jurisdiction, dispute-resolution, and enforcement wording must be confirmed by qualified UAE legal counsel before production use.
17. Operator Information and Contact
Operator: {OPERATOR_NAME}
Registered Address: {OPERATOR_ADDRESS}
Admin Support / Security Contact: {ADMIN_SUPPORT_EMAIL}
Privacy Contact: {PRIVACY_CONTACT_EMAIL}
18. Acknowledgement
By accessing the Admin portal, the Admin confirms that the Admin:
- is authorized to act as an Admin;
- has read and understood these Terms;
- will use administrative functions only for authorized purposes; and
- will comply with applicable policies, procedures, laws, and security requirements.
Drafting note: This provisional text is a specification/test artifact, not legal advice or production approval. UAE legal counsel and the project confirmation authority must approve the final wording.