Acceptable Use Policy
Acceptable Use Policy
Applies to everyone your organisation authorises to use our hosted services.
Last updated: 5 August 2026
This Acceptable Use Policy forms part of your contract with us - see our General Terms for how it ranks against the rest of your contract if there’s ever a conflict.
1. Using our services lawfully
You and your authorised users must comply with the law when using our services, and must not use them for anything unlawful, discriminatory, defamatory, or harmful to us or anyone else.
2. Keeping access secure
Each authorised user needs their own login — logins can’t be shared or used by more than one person. Passwords must be kept confidential, and access must be removed immediately for anyone who stops working for you.
You must not try to gain unauthorised access to any part of our services, probe or test their security, or use automated tools (such as bots or scrapers) to access them in a way that sends more requests than a person could reasonably generate manually.
You must not introduce viruses, trojans, worms or other malicious or technologically harmful material, or attack our services with a denial-of-service attack. Gaining or attempting unauthorised access to our services, or the systems they run on, is a criminal offence under the Computer Misuse Act 1990 — we’ll report it to the relevant authorities and cooperate with any investigation, and your access will end immediately.
You must not conduct or permit any text or data mining or web scraping of our services, including using any automated tool to access, copy or analyse our content or data, or any technique to extract patterns, trends or correlations from it. This clause is our express reservation of rights for the purposes of Article 4(3) of the EU Digital Copyright Directive ((EU) 2019/790), to the extent it applies.
3. What you can’t do with our content
You can’t text or data mine, scrape, or attempt to reverse engineer any part of our services or content, and you can’t allow anyone who isn’t an authorised user to access them.
Links to third-party websites or resources are provided for your convenience only — we don’t endorse them, have no control over their content, and aren’t responsible for them.
4. Fair use
Our services are licensed for your own internal business operations. You can’t resell access, provide it to third parties, or use it beyond what’s reasonably needed to run your own organisation.
5. Calling, texting and contacting patients
If you use our services to call, text or otherwise contact patients or other individuals, you’re responsible for complying with all applicable laws on marketing and electronic communications, including the Privacy and Electronic Communications Regulations 2003 and UK GDPR. This includes obtaining any consent required before sending marketing calls, texts or messages, and providing any required notice before a call is recorded. We don’t review or police the content of your calls, texts or messages, and we don’t guarantee that using our calling or texting features will, by itself, make you compliant with these laws.
6. Special-category and health data
Where our services let you store or process patient or health information, you must only do so for the purposes those services are designed for, and you remain responsible for having a lawful basis and any necessary consents to process that data under UK GDPR.
7. Reporting suspected misuse
If you become aware of, or suspect, a breach of this policy, please tell us promptly, in writing.
If you become aware of any content on our services that is illegal, or that could amount to or be connected with child sexual abuse or exploitation, or terrorist content, tell us immediately, in writing — don’t wait to raise it through your usual support channel.
8. Our trademarks
Our Trademarks page sets out how you can, and can’t, use our name, logos and trademarks — you must comply with it when using our services.
9. If you don’t comply
We can suspend or limit your access if you materially breach these terms, including non-payment, if your use risks damaging the service or degrading it for other customers, if you don’t respond within a reasonable time after we contact you about a suspected breach, or in an emergency. We’ll still charge fees during any suspension caused by your own breach.
10. User-generated content
If a product lets you or your authorised users upload, post or share content with other users of that product (rather than just with your own organisation), you keep ownership of that content, but you grant us a licence to use, store, copy and make it available as needed to provide the relevant feature. You’re responsible for making sure anything you share this way complies with this policy, and you’ll indemnify us for any loss we suffer if it doesn’t. We can remove content that doesn’t comply, and we may disclose your identity if someone claims your content infringes their rights or privacy.