Acceptable Use Policy
Placeholder draft · Last updated 7 July 2026
Placeholder draft — this document has not yet completed legal review and is not legal advice. Final text must be reviewed before client contracting.
1. Purpose
This Acceptable Use Policy sets out basic rules for acceptable use of OgmaQ while the formal customer agreement remains subject to legal review. It supports the Terms of Service and the Privacy Policy. Where a signed customer agreement applies, that agreement's terms take precedence.
2. Authorised users
Accounts are for the authorised users of the subscribing customer organisation. Customers are responsible for managing their users' access and for their users' compliance with this policy.
3. Prohibited access and security misuse
Users must not:
- attempt to access another tenant's data or any data they are not authorised to access;
- probe, scan, bypass or disrupt the service, except through the responsible disclosure process;
- carry out denial-of-service activity or otherwise degrade the service for others;
- introduce malware or malicious files;
- abuse, share or compromise credentials;
- scrape the service or misuse its APIs or data exports beyond agreed use;
- treat a published data link URL as a credential — do not share a link URL beyond its intended recipients, and do not use published data links to publish restricted, sensitive or special-category data.
4. Prohibited content
Users must not upload or enter:
- unlawful content, or content that infringes another party's rights;
- malicious files, or content designed to disrupt or compromise the service;
- content that violates applicable law or the customer's own policies.
5. Sensitive data restrictions
Sensitive data is restricted by default. Unless separately agreed in writing with OgmaQ and supported by appropriate legal, security and contractual terms, customers and users must not upload or enter into OgmaQ: patient data; protected health information (PHI); special-category personal data under the GDPR; biometric data; genetic data; children's data; payment card data; government identification numbers; passwords or secrets; or any data the customer is not authorised to process in OgmaQ.
OgmaQ's default intended use is operational escalation support for customer-controlled manufacturing and quality workflows. It is not intended by default for patient records, clinical records, medical records, official GMP records, electronic signatures, validated QMS records, CAPA records, deviation records, or other regulated records — unless separately agreed and validated by the customer for a defined intended use under a separate controlled arrangement.
6. Customer responsibilities
Customers are responsible for:
- deciding what data their users enter into the service;
- ensuring they have a lawful basis and the authority to process that data in OgmaQ;
- configuring access, roles and permissions appropriately;
- training their users on acceptable use;
- minimising unnecessary personal data in escalation records, comments, descriptions and attachments;
- keeping official GMP records in their validated QMS unless separately agreed;
- ensuring uploaded attachments are appropriate for OgmaQ's agreed intended use;
- where published data links are used, controlling who may create them and where link URLs are shared, and revoking published data links that are no longer needed.
7. Attachments and free-text fields
Users should avoid placing unnecessary personal data, patient information, special-category data, secrets, passwords, or unrelated confidential material in free-text descriptions, comments or attachments. Escalation records should carry only the information needed to triage, track and close the escalation.
8. Service protection and suspension
Placeholder: OgmaQ may need to suspend or restrict access where use creates a security risk, a legal risk, a risk of service disruption, or a material breach of acceptable-use requirements. The detailed suspension and enforcement rights will be defined in the applicable customer agreement and during legal review.
9. Reporting misuse
Report suspected misuse or abuse to [email protected], or [email protected]. Suspected security vulnerabilities should be reported through responsible disclosure at [email protected]. These role-based aliases route to the OgmaQ team; [email protected] is the general contact if you are unsure which to use.
10. Legal review status
This policy is a placeholder draft pending legal review. It is not legally final and will be reviewed and confirmed by qualified counsel before client contracting. It does not create, and should not be read as, any compliance certification or assurance claim.