Legal
Acceptable Use Policy
Last updated: 18 June 2026. This document is maintained centrally by Ffon Solutions Limited.
Acceptable Use Policy
Effective date: 15 June 2026 Last updated: 15 June 2026
This Acceptable Use Policy ("AUP") sets out what is and is not permitted when using E-Dob. It supplements and forms part of our Terms of Service. Capitalised terms have the meaning given in the Terms of Service unless otherwise stated.
This AUP applies to all users of the service, including the Customer, Authorised Users, administrators, and anyone else accessing the service through a customer account.
1. General principle
E-Dob is designed for lawful incident reporting, management, and record-keeping. You must use the service responsibly, lawfully, and only for legitimate business or organisational purposes.
You are responsible for ensuring that your use of the service, and the Content you submit to it, complies with:
- applicable law;
- your organisation’s internal policies and procedures;
- applicable data protection, confidentiality, and records management obligations;
- the Terms of Service;
- this AUP.
2. Prohibited uses
You must not use E-Dob to, or permit it to be used to:
2.1 Unlawful, harmful, or abusive content
- store, transmit, publish, distribute, or otherwise make available any Content that is unlawful, defamatory, obscene, threatening, abusive, discriminatory, hateful, or otherwise harmful;
- use the service to harass, intimidate, stalk, threaten, abuse, or exploit any person;
- upload or disseminate Content that incites violence, hatred, self-harm, or criminal activity;
- use the service in a way that infringes the rights of any person, including privacy, confidence, intellectual property, or data protection rights.
2.2 Security abuse and unauthorised access
- upload, introduce, transmit, or distribute malware, ransomware, viruses, worms, trojans, spyware, logic bombs, or any other malicious or harmful code;
- attempt to bypass, defeat, disable, impair, probe, or test the vulnerability of any security, authentication, authorisation, logging, monitoring, encryption, or access-control mechanism, except where we have expressly authorised you in writing to do so;
- access, or attempt to access, any account, data, environment, tenant, workspace, dataset, system, API, or function that you are not authorised to access;
- use stolen, shared, compromised, misappropriated, or third-party credentials;
- share login credentials, authentication codes, API keys, tokens, or account access details except where the service expressly permits such sharing through approved administrative controls;
- impersonate another person or misrepresent your identity or authority;
- interfere with or disrupt the integrity, security, availability, or performance of the service or any related network or system.
2.3 Reverse engineering and technical misuse
- reverse engineer, decompile, disassemble, decode, derive source code from, or otherwise attempt to discover the source code, algorithms, architecture, or underlying ideas of the platform or any related software, except to the extent expressly permitted by law;
- copy, reproduce, scrape, crawl, extract, harvest, or collect data from the service by automated or manual means in a way that is not authorised by us;
- use bots, scripts, or automation tools to create excessive requests, overload the service, evade rate limits, or otherwise place an unreasonable burden on our systems;
- benchmark, probe, scan, or test the service for security weaknesses without our prior written consent;
- use the service for cryptomining, credential stuffing, phishing, spam, or any other fraudulent or malicious activity.
2.4 Misuse of content and records
- enter inaccurate, fabricated, misleading, or deliberately incomplete incident information where this could affect safety, safeguarding, compliance, investigations, or legal records;
- alter, delete, conceal, destroy, or improperly withhold incident records except where authorised by applicable law, policy, or internal process;
- use the service to retaliate against, unfairly target, or maliciously report another person;
- create duplicate, false, or abusive reports for harassment, disruption, or nuisance.
2.5 Circumventing controls
- circumvent user permissions, workflow controls, approval processes, retention settings, audit trails, or any other governance control built into the service;
- disable, remove, or interfere with required notices, warnings, or record-retention functionality;
- use the service in a way that undermines the integrity of logs, audit trails, or evidence records.
3. Responsible use of incident data
Incident reports should contain only the information necessary for the incident being reported and handled appropriately.
You should not upload personal data unless it is relevant and necessary for the incident or subsequent management process.
3.1 Special category data
You must not upload special category personal data, including health data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, biometric data, sex life, or sexual orientation, unless:
- it is directly relevant to the incident or matter being recorded;
- you have a lawful basis and, where applicable, a valid Article 9 condition under UK GDPR;
- the data is processed in accordance with applicable law and your organisation’s own policies.
3.2 Criminal offence data
You must not upload criminal offence data unless it is necessary, lawful, and authorised by your organisation’s policies and applicable law.
3.3 Minimisation
You should:
- keep entries fact-based and objective;
- avoid speculation, personal opinion, or unnecessary commentary;
- redact or omit unnecessary personal data where possible;
- use the minimum data necessary to record the incident accurately.
4. Email, attachments, and file uploads
If the service permits file uploads, you must ensure that any files, images, recordings, or attachments uploaded:
- are relevant to the incident or purpose for which they are provided;
- do not contain malware or other harmful code;
- do not infringe the rights of any third party;
- do not contain unnecessary sensitive personal data.
You must not upload material that you know, or ought reasonably to know, is false, unlawful, or malicious.
5. Account security and admin responsibilities
Customers and Authorised Users must:
- keep credentials confidential;
- use strong passwords and, where available, multi-factor authentication;
- ensure accounts are allocated only to authorised personnel;
- remove access promptly when a user leaves, changes role, or no longer requires access;
- review account activity and permissions regularly;
- notify us promptly of suspected compromise, misuse, or unauthorised access.
You are responsible for activity performed through your accounts and for any access arising from your failure to secure credentials, devices, or permissions, except to the extent caused by our breach or by any liability that cannot lawfully be excluded.
6. API and integration use
Where we make APIs or integrations available, you must:
- use them only in accordance with our documentation and any usage limits we specify;
- not exceed published rate limits or quotas;
- not use integrations to harvest, exfiltrate, or repurpose data beyond the authorised purpose;
- not use APIs in a way that degrades service performance, security, or stability.
We may suspend API access where we reasonably believe it is causing harm, misuse, or material service disruption.
7. Third-party systems and credentials
If you connect E-Dob to third-party systems, you are responsible for:
- ensuring you have the right to make that connection;
- complying with the third party’s terms and policies;
- maintaining the security of third-party credentials and tokens;
- understanding any data sharing, transfer, or access implications.
We are not responsible for the security or conduct of third-party platforms, except to the extent required by law or our own breach.
8. Prohibited evasion and circumvention
You must not:
- create multiple accounts to evade suspension, enforcement, or usage limits;
- attempt to conceal identity or activity for the purpose of abuse or unauthorised access;
- use the service to test, circumvent, or exploit vulnerabilities;
- interfere with or bypass any content moderation, security, compliance, or reporting process.
9. Monitoring and investigation
We may monitor use of the service to the extent reasonably necessary to:
- protect the security and integrity of the service;
- investigate suspected breaches;
- prevent abuse, fraud, or unauthorised access;
- comply with law;
- enforce the Terms of Service and this AUP.
Any monitoring will be carried out in accordance with applicable law and our Privacy Policy.
10. Enforcement
If we reasonably believe that this AUP or the Terms of Service have been breached, we may take any action we consider appropriate, including:
- issuing a warning;
- requiring you to remove or correct Content;
- restricting, suspending, or terminating access, including immediately where necessary;
- disabling specific functionality, integrations, or API access;
- reporting the matter to the Customer’s administrator or designated contact;
- preserving evidence and audit logs;
- referring the matter to law enforcement, regulators, or other relevant authorities where appropriate.
We may take enforcement action without prior notice where:
- the breach creates a security risk;
- there is suspected unauthorised access;
- the service is being used for malicious or unlawful activity;
- immediate action is necessary to protect the service, our customers, or third parties.
11. Reporting misuse
If you become aware of any suspected misuse, breach, compromise, or unauthorised access, you must report it promptly to:
You should include, where relevant:
- a description of the incident;
- the affected account or workspace;
- the date and time of the issue;
- any logs, screenshots, or other supporting material.
12. No waiver
Our failure to enforce this AUP in any instance does not mean we waive our right to enforce it later.
13. Changes to this AUP
We may update this AUP from time to time. Where a change is material, we will provide reasonable notice before it takes effect. Continued use of the service after the effective date of any update constitutes acceptance of the revised AUP.
14. Contact
Questions about this AUP should be sent to:
GuardDog Digital Ffon Solutions Limited Email: security@e-dob.uk
Central copy: view on the E-DOB Trust Centre →