In plain terms
This is the short list of things nobody may do with the systems and services we run for you. Most of it is what you would expect — nothing illegal, nothing that attacks someone else, nothing that puts other people's data at risk. It exists so that when something does happen, we both already agreed what the answer is.
This Acceptable Use Policy applies to every person who uses the Services through Client’s account, whether an employee, a contractor, or a guest. It is incorporated into the Services Agreement by the Order.
Client is responsible for the conduct of everyone who uses the Services through its account, and for making this policy known to them.
1. Nothing unlawful
Client will not use the Services to commit, assist, or conceal any unlawful act, or to violate the rights of any person.
2. Nothing that reaches systems you do not own
Client will not use the Services to access, monitor, scan, or interfere with any data, account, system, or network without authorisation from whoever owns it. That includes probing for vulnerabilities, defeating an authentication control, and intercepting traffic that is not Client’s own.
Security testing against a third party’s systems requires that party’s written permission, and Client is responsible for holding it.
3. Nothing that harms other people’s use
Client will not use the Services in a way that degrades, overloads, or interferes with the Services as delivered to anyone else, or that is reasonably likely to cause a provider we depend on to restrict or suspend our access.
4. No harvesting, no impersonation, no deceptive messaging
Client will not use the Services to:
- collect email addresses, phone numbers, or other personal information without the consent of the person it concerns;
- send messages with false or misleading sender information, headers, or identifiers;
- impersonate any person or organisation, or misrepresent an affiliation; or
- distribute software to anyone who has not knowingly agreed to install it.
5. No unlawful or abusive content
Client will not publish, transmit, or store on any system we operate, or link from one to, content that:
- sexually exploits a minor, or depicts non-consensual acts;
- incites or threatens violence, or constitutes harassment or hate speech;
- is defamatory, or violates a person’s privacy or publicity rights;
- is deceptive under the consumer protection law of any jurisdiction;
- discloses another person’s trade secrets or confidential information without the right to do so;
- infringes a copyright, trademark, or patent, or is designed to defeat a technical protection measure; or
- creates a risk to any person’s safety.
6. No malicious code
Client will not knowingly introduce, distribute, or store malware, ransomware, credential stealers, or any code designed to damage or gain unauthorised access to a system.
7. Artificial intelligence
Where Client uses an AI tool through the Services, the acceptable-use terms in section 7 of the Service Attachment for Artificial Intelligence Services also apply, including the vendor’s own policy, the restriction on decisions about individuals, and the prohibition on circumventing a tool’s safety controls.
8. Credentials and access
Client will keep its credentials confidential, will not share individual accounts between people, and will tell us promptly when someone leaves or a credential may have been exposed.
9. Regulated data
Client will not place data protected by HIPAA, GLBA, FERPA, a state privacy statute, or a comparable regime into a system or service that the Order and the Data Processing Agreement do not cover.
10. What happens if this policy is breached
We may suspend the affected Services immediately, on written notice describing the basis, where we reasonably believe a breach of this policy is occurring and creates a risk of harm, legal liability, or breach of a vendor’s terms. We will restore the Services promptly once the cause is resolved.
A breach that Client does not cure within ten (10) days of written notice is grounds for termination under the Services Agreement. Suspension or termination under this policy does not relieve Client of its obligation to pay for Services already delivered.
Where the law requires us to preserve or disclose material relating to a breach of this policy, we will do so, and will notify Client where we are permitted to.
11. Changes to this policy
We may revise this policy. Revisions are governed by section 18.2 of the Services Agreement: we publish the new version, give at least thirty (30) days’ notice before it takes effect, and where a change materially and adversely affects Client, Client may terminate the affected Order without penalty. Every prior version stays available at its own dated address.