1. Purpose
This policy applies to all customers and users of ClassControl.
2. Prohibited activity
- Unauthorised access or attempted access.
- Credential sharing, impersonation or account misuse.
- Uploading malware or harmful code.
- Interfering with availability or security controls.
- Unreasonable scraping, automated extraction or load generation.
- Illegal, fraudulent, abusive or rights-infringing use.
- Accessing health information without a legitimate role-based need.
3. Security testing
Security testing must not be conducted against production systems without prior written authorisation. Potential vulnerabilities should be reported under the Responsible Disclosure Policy.
4. Enforcement
Eatwell Tech Solutions may investigate suspected misuse and may restrict or suspend access where reasonably necessary to protect users, customers or the service.
Document status:
This document is provided as an operational draft for ClassControl.
Commercial terms, supplier arrangements and legal obligations should
be reviewed by a qualified UK solicitor before contractual reliance.