Acceptable Usage Policy

Effective 16 September 2026

This Policy protects the security, availability and lawful use of Aspirium Services. It applies to customers, authorised users and anyone using a Service through a customer account. It forms part of the Agreement and should be read with the Terms of Service.

1. Scope and responsibility

1.1 Application  This Acceptable Usage Policy applies to all Services supplied by Aspirium Ltd, including hosting, websites, email, domains, support, migrations, website care, digital tools, marketing tools and artificial-intelligence features. Customer, you and your have the meanings given in the Terms of Service.

1.2 Responsibility for users  You are responsible for use of the Services through your account, credentials, websites, applications, mailboxes and authorised users. You must take reasonable steps to ensure that your employees, contractors, visitors and other users comply with this Policy.

1.3 Upstream services  Hosting Services are supplied through Stablepoint, currently operated by hosting.com UK Services Ltd, and may depend on other infrastructure suppliers. You must comply with reasonable technical, security, content and resource restrictions that apply to the upstream platform. Aspirium may enforce an upstream restriction where necessary to continue supplying the Services, protect the platform or comply with law.

1.4 No monitoring obligation  We may investigate suspected misuse but are not required to monitor all content or activity. Our failure to act on one occasion does not prevent us from acting later.

2. Lawful and responsible use

2.1 Applicable law  You must use the Services lawfully in every jurisdiction that applies to you, the content, the recipient and the relevant server or provider. You must obtain any licence, consent, permission or regulatory approval required for your activities.

2.2 Rights of others  You must not use the Services to infringe intellectual-property rights, privacy rights, confidentiality, data protection rights, contractual rights or any other rights of another person. You must have authority to upload, publish, distribute and process all content and data you place in the Services.

2.3 Accurate identity  You must not impersonate another person, misrepresent your identity or authority, falsify contact details, conceal the origin of communications, or use misleading domain, sender or account information.

2.4 Harmful conduct  You must not use the Services to threaten, harass, exploit, defraud or unlawfully discriminate against another person, or to publish unlawful defamatory, abusive, sexually exploitative or otherwise illegal material.

3. Prohibited content and activities

You must not use or permit the Services to store, publish, transmit, promote or facilitate:

  • malware, ransomware, spyware, viruses, malicious scripts, exploit kits or other harmful code;
  • phishing, credential theft, identity fraud, financial fraud, counterfeit activity or deceptive schemes;
  • child sexual abuse material, sexual exploitation, trafficking or content whose possession or distribution is unlawful;
  • unlawful hate material, credible threats, incitement to violence or instructions intended to enable serious harm;
  • pirated software or media, unlawful streaming, copyright infringement, counterfeit goods or unauthorised distribution of protected material;
  • the sale, supply, promotion or facilitation of unlawful drugs, weapons, controlled goods or services;
  • cryptocurrency mining, botnets, command-and-control systems or activity intended to conceal or distribute malicious computing;
  • denial-of-service activity, traffic flooding, mail bombing or deliberate interference with a network, service or user;
  • unlawful gambling, lotteries, financial promotions or regulated services without the approvals required by law; or
  • any activity that exposes Aspirium, an upstream supplier, another customer or the public to a material legal, security or reputational risk.

3.1 Adult content  You must obtain our written approval before using a Hosting Service for lawful adult content. Approval may be refused or withdrawn where the content, age-assurance arrangements, payment activity, jurisdiction or upstream platform makes the use unsuitable. Illegal sexual content is always prohibited.

3.2 Regulated services  We may require evidence of licences, registrations, professional status, consumer protections or other authority before or during the supply of Services to a regulated business. We may restrict or end an affected Service if adequate evidence is not provided.

4. Security and network misuse

You must not attempt, assist or permit:

  • unauthorised access to an account, system, device, network or data;
  • port scanning, vulnerability scanning, penetration testing or security probing without prior written authority from the system owner and Aspirium where our infrastructure may be affected;
  • interception, monitoring, alteration or disclosure of communications or data without lawful authority;
  • circumvention of authentication, rate limits, access restrictions, licence controls, security controls or usage limits;
  • operation of an open proxy, public VPN, Tor exit node, open relay, traffic-redirection service or similar anonymisation service unless the Order expressly permits it;
  • use of compromised credentials, stolen data or systems that you know or reasonably should know are insecure; or
  • testing or activity likely to impair the availability, integrity or confidentiality of the Services or another person’s systems.

4.1 Security duties  You must use strong unique credentials, enable multi-factor authentication where available and appropriate, maintain software and devices for which you are responsible, restrict administrative access, and promptly address known vulnerabilities or compromise.

4.2 Compromised Services  If we reasonably believe a Service has been compromised, we may reset credentials, quarantine files, block traffic, disable scripts, suspend access or require remediation. You must cooperate promptly and must not restore infected or insecure content without addressing the cause.

5. Email and electronic messaging

5.1 Permitted purpose  Hosted email is intended for ordinary business communication and transactional messaging within plan and platform limits. It is not a bulk-email or cold-marketing platform unless the Order expressly states otherwise.

5.2 Consent and law  You must comply with applicable privacy and electronic-marketing law, including the Privacy and Electronic Communications Regulations where relevant. You must maintain an appropriate lawful basis, honour objections and suppression requests, and include clear sender identification and an effective unsubscribe method in non-transactional marketing where required.

5.3 Prohibited messaging  You must not send unsolicited bulk email, spam, purchased-list campaigns, messages to harvested addresses, misleading communications, mail bombs, phishing messages, malware or communications sent through unauthorised accounts. You must not forge headers or use an address or domain without authority.

5.4 Reputation and limits  You are responsible for mailing-list quality, bounce handling, complaints, authentication and sender reputation. We or an upstream supplier may queue, reject, rate-limit or block messages or sending accounts to protect deliverability, users and platform reputation. Email delivery and inbox placement are not guaranteed.

5.5 Compromised scripts  You must secure website forms, content-management systems and scripts against spam and unauthorised sending. We may disable a compromised form, mailbox, script or website until it is secured.

6. Resources and shared hosting

6.1 Plan limits  You must remain within the storage, CPU, memory, process, database, bandwidth, mailbox, sending, inode and other limits stated in the Order, Service description, control panel or reasonable written notice. A description such as unlimited remains subject to normal website and email use, technical limits and this Policy.

6.2 Fair use  You must not use resources in a way that materially affects server stability, security or service quality for another user. We may require optimisation, restrict a process, move a Service, request an upgrade or apply a temporary limit where use is sustained, abnormal or harmful.

6.3 Storage restrictions  Unless the Order expressly permits it, shared hosting must not be used primarily as an offsite backup facility, personal cloud, file-sync platform, media archive, download repository, software mirror, video-streaming platform or general file-storage service. Files must be reasonably connected with the operation of the hosted websites, email or contracted application.

6.4 Local backups  Customer-generated backups must be kept to a reasonable minimum and should be downloaded to independent storage. We may remove redundant, stale or excessive local backup files where reasonably necessary to protect platform capacity, after notice where practicable.

6.5 Intensive workloads  Shared hosting must not be used for cryptocurrency mining, high-volume computation, persistent background processing, game servers, public proxying, large-scale crawling or another workload unsuitable for the platform. Scheduled tasks, database queries and automated processes must be configured so that they do not create excessive load.

7. Websites applications and data

7.1 Supported use  You must maintain valid licences and comply with the terms applicable to software, themes, plugins, fonts, images, integrations and other materials. You must not install unsupported, nulled, malicious or unlawfully obtained software.

7.2 Updates  You are responsible for application and content updates unless the Order expressly includes them. You must address urgent security updates within a reasonable period and remove abandoned or unnecessary software that creates a material risk.

7.3 Personal data  You must collect and use personal data lawfully and apply appropriate access, retention and security controls. You must not place patient-identifiable information, health data, payment-card data or other sensitive information in a Service that is not suitable and expressly permitted for that processing.

7.4 Forms and uploads  Public forms, file uploads, APIs and login pages must use reasonable anti-abuse and security controls. You must not knowingly expose passwords, secret keys, private records or sensitive personal information through publicly accessible files, repositories, logs or directories.

8. Digital AI design and marketing tools

8.1 Authorised use  You may use optional digital tools only for lawful business purposes and within the applicable plan, licence and provider terms. You must not share access outside the authorised organisation, resell access unless permitted, defeat technical controls or automate use in a way that harms availability or exceeds reasonable limits.

8.2 AI inputs  You must not submit patient-identifiable information, special-category data, criminal-offence data, passwords, payment-card data, confidential third-party material or other restricted information to an AI feature unless a written Order and the Data Processing Agreement expressly authorise it.

8.3 AI outputs  You must review and verify AI output before use. You must not use an Aspirium AI feature to make a solely automated clinical decision, provide unreviewed medical advice, impersonate a real person deceptively, create unlawful discriminatory material, infringe rights or facilitate prohibited activity.

8.4 Marketing and analytics  You must use marketing, analytics and design tools lawfully, respect platform permissions and third-party rights, and obtain any consent required for tracking, advertising, mailing lists, testimonials, photographs and patient or staff information.

9. Reports complaints and investigations

9.1 Reporting abuse  Suspected abuse may be reported through our published contact or support channels. A report should identify the affected domain, account, message, IP address or content and include enough information for us to assess it. Knowingly false or abusive reports are prohibited.

9.2 Investigation  We may review relevant account information, transaction records, logs, support records and hosted content where reasonably necessary to investigate a credible complaint, security incident, suspected breach, upstream request or legal obligation. We will handle personal data in accordance with our Privacy Policy and Data Processing Agreement.

9.3 Cooperation  You must provide accurate information and reasonable cooperation, preserve relevant evidence, stop prohibited activity and take corrective action. We may refer a matter to Stablepoint, another supplier, a rights holder, a regulator or law-enforcement body where lawful and reasonably necessary.

9.4 Rights complaints  We may disable or remove access to content in response to a credible intellectual-property, privacy, court or regulatory complaint. Where appropriate, we may pass the complaint to you and allow a reasonable response, but urgent action may be taken without prior notice.

10. Enforcement

10.1 Protective action  Where we reasonably believe this Policy has been breached, we may warn you, require remediation, apply a limit, block traffic or email, quarantine or remove content, reset credentials, suspend part or all of a Service, or terminate under the Terms of Service. We will choose action proportionate to the risk and circumstances where reasonably possible.

10.2 Urgent cases  We may act without advance notice where delay could cause harm, continued illegality, data loss, security compromise, service disruption, reputational damage to shared infrastructure or breach of an upstream requirement. We will explain the action afterwards where lawful and practicable.

10.3 Opportunity to remedy  For a non-urgent and remediable breach, we will normally identify the problem and provide a reasonable opportunity to correct it. A cure period is not guaranteed where misuse is serious, repeated, deliberate or likely to affect another person or the platform.

10.4 Restoration  We may require evidence of remediation, security changes, removal of content, an upgrade or payment of reasonable costs caused by the breach before restoring a Service. Restoration is subject to the Terms and any upstream platform decision.

10.5 Data and backups  Suspension or investigation does not guarantee that content, email or backups will remain recoverable. You must maintain independent copies of important data in accordance with the Terms of Service.

11. Changes and contact

11.1 Policy changes  We may update this Policy to reflect changes in law, security threats, Services, technology or supplier requirements. We will publish the current version and its effective date. Material adverse changes affecting an existing subscription will be handled under the change provisions in the Terms of Service.

11.2 Questions  Questions about this Policy or reports of suspected misuse should be submitted through the contact details at aspirium.co.uk/contact or through the Aspirium client area.