Acceptable Use Policy
Version 2026-08-v1. Last updated 8 August 2026. Effective from 8 August 2026.
Acceptable Use Policy
Version 2026-08-v1. In force from 8 August 2026.
This policy forms part of your agreement with Siege One Limited trading as OtisIO ("we", "us", "our"). It is referred to in the Terms of Service and, where you have one, in your Master Services Agreement. Words defined in those documents have the same meaning here.
It applies to everyone who uses your workspace, including your administrators, your managers, your workers, and anyone you invite. You are responsible for what the people in your workspace do.
1. Why this policy exists
1.1 OtisIO holds real information about real people: where they worked, when, what they were paid, and in some workspaces their photograph or a biometric template. Misuse of the platform harms those people first and the platform second.
1.2 This policy is short and specific on purpose. If something is not listed here but is plainly dishonest, unlawful or harmful, do not do it.
2. Who may use the service
2.1 The service is provided for business use. Each named user account must belong to one identified individual. Accounts must not be shared between people.
2.2 A shared clock-in device or kiosk is not a shared account. The device is shared; the person clocking in is still identified.
2.3 You must not create an account for a person who does not know it exists, except where you are setting up a worker record for someone you employ or engage and you will tell them.
2.4 You must not let anyone use the service if we have told you their access is suspended or terminated.
2.5 Minimum age. You must not create a user account for anyone under 16. Where your workforce includes workers aged 16 or 17, you must have considered whether they understand what is recorded about them, and you must not enable biometric clock-in for them.
3. Keeping your workspace secure
You must:
3.1 keep credentials confidential, and not write them down anywhere others can find them;
3.2 use a unique password that you do not use on any other service;
3.3 enable two-factor authentication for every administrator account, and we strongly recommend enforcing it workspace-wide;
3.4 remove access promptly when someone leaves or changes role;
3.5 grant each person the least access they need to do their job, and review that periodically;
3.6 tell us without delay at security@otisio.com if you believe an account has been compromised, or that someone has accessed your workspace who should not have;
3.7 keep the devices your people use reasonably secure, with a screen lock and current software.
You must not:
3.8 share an administrator account between people;
3.9 attempt to access another customer's workspace, another user's account, or any part of the platform you have not been given access to;
3.10 disable, circumvent or interfere with any security control, rate limit, audit log or access control in the service;
3.11 remove, obscure or falsify any audit record.
4. Using the service lawfully and fairly
You must not use the service:
4.1 to break any law, or to help anyone else break the law;
4.2 to infringe anyone's intellectual property, privacy or other rights;
4.3 to harass, bully, threaten, intimidate or discriminate against anyone;
4.4 to send messages that are abusive, obscene, defamatory, or that would reasonably be considered offensive by their recipient;
4.5 to send unsolicited marketing to anyone. The messaging features exist for you to communicate with your own workforce about work. They are not a marketing channel;
4.6 to store or transmit material that is unlawful, including indecent images, material that incites violence, or material subject to a court order;
4.7 in a way that misleads anyone about who you are or who sent a message;
4.8 to compete with us, to build a competing product, or to benchmark the service for publication, without our prior written consent.
5. Personal data and monitoring
This section matters more than the rest. You are the data controller for the personal data in your workspace. We are your processor. The Data Processing Agreement sets out the legal detail; this section sets out what we will not tolerate.
You must:
5.1 have a lawful basis for everything you record about a person, and where the data is special category data, an Article 9 condition as well;
5.2 tell your workers, in plain language, what the system records about them, who can see it, how long it is kept, and how to object;
5.3 keep personal data no longer than you need it, and have a retention position you can explain;
5.4 handle requests from your workers about their own data, and deal with them within the statutory time limits;
5.5 only give access to attendance, location and HR data to people who need it for their role.
You must not:
5.6 use the service to monitor people covertly. Monitoring your workforce without telling them is very difficult to justify and is a matter the Information Commissioner takes seriously;
5.7 use the service to monitor people outside their working time;
5.8 use clock-in location, patrol records or photographs for a purpose you have not told your workers about;
5.9 upload personal data about people who have nothing to do with your workforce or your operations. In particular, do not use this system as a record system for your customers, patients, service users, tenants or clients;
5.10 enter special category data into free-text fields (notes, chat, shift comments) without a lawful condition for it. Health information about a named worker in a shift note is still health data;
5.11 use the service to make a decision that produces a legal or similarly significant effect on a person solely by automated means, without a human reviewing it;
5.12 export personal data from the service and then handle it in a way that would breach this policy or your own obligations.
6. Content you put into the service
6.1 You are responsible for everything uploaded into your workspace by anyone in it.
6.2 You must not upload:
- malware, or anything designed to disrupt, damage or gain unauthorised access to any system;
- material you do not have the right to store or share;
- payment card numbers, full bank details in free-text fields, or other data the service is not designed to hold;
- anything that would put us in breach of a law or a third party's rights.
6.3 We do not routinely review the content of your workspace, and we do not read your messages. That does not make you any less responsible for what is in there.
7. Fair use of the platform
7.1 The service is provided on a fair-use basis. You must not:
- use automated tools to scrape, crawl or bulk-extract data from the service, other than through an interface we provide for that purpose;
- place an unreasonable or disproportionate load on the platform;
- resell, sublicense, rent out or provide the service to anyone outside your organisation as if it were your own, unless we have agreed that in writing;
- create accounts to evade a plan limit, a trial limit or a suspension;
- use the service to store data that is unrelated to your workforce, for example as a general file archive or backup destination.
7.2 Storage and messaging allowances are set by your plan. Where you exceed them, we will tell you and give you a reasonable chance to reduce usage or move to a plan that fits.
8. Security research
8.1 We welcome genuine reports of security problems. Send them to security@otisio.com.
8.2 You may not test the security of the platform without our prior written consent. That includes penetration testing, vulnerability scanning, denial of service testing and social engineering of our people.
8.3 If you find a vulnerability accidentally, tell us, do not exploit it, do not access anyone else's data, and do not publish it before we have had a reasonable opportunity to fix it.
8.4 If you follow 8.1 to 8.3 in good faith, we will not treat your report as a breach of this policy and we will not pursue you for it.
9. What happens if you breach this policy
9.1 Ordinary breaches. We will tell you, explain what needs to change, and give you a reasonable period to fix it. If it is not fixed, we may suspend the affected feature or the workspace.
9.2 Serious breaches. We may suspend access immediately, without prior notice, where we reasonably believe that:
- there is a live security risk to the platform or to another customer;
- personal data is being processed unlawfully and someone is being harmed;
- the service is being used for something unlawful;
- a biometric rule in section 5A is being breached;
- we are required to act by law or by a regulator.
9.3 Where we suspend without prior notice, we will tell you as soon as we reasonably can and explain why, unless a law or a regulator prevents us.
9.4 We will keep any suspension as narrow as is reasonable. Where the problem is one feature, we will suspend that feature rather than the whole workspace.
9.5 We will not delete your data as a response to a breach of this policy, except where we are legally required to, or where continuing to hold it is itself the unlawful act. Where we suspend, your data remains and you can still export it, unless doing so would itself be unlawful.
9.6 Persistent or deliberate breach is a material breach of your agreement and may lead to termination under it.
9.7 Suspension under this policy does not entitle you to a refund or a service credit, and does not pause your fees.
10. Reporting a problem
10.1 To report misuse of the service, contact legal@otisio.com.
10.2 To report a security issue, contact security@otisio.com.
10.3 To report a data protection concern, contact privacy@otisio.com.
10.4 If you are a worker whose employer uses OtisIO and you have a concern about what is recorded about you, please raise it with your employer first: they control the data and they decide what is collected. If you cannot resolve it with them, you can contact us at privacy@otisio.com and we will pass it on, and you can complain to the Information Commissioner's Office at ico.org.uk.
11. Changes to this policy
11.1 We may update this policy. We will give you at least 30 days' notice of a material change, by email to your administrators and by notice in the product.
11.2 Changes needed urgently for legal, regulatory or security reasons may take effect immediately, and we will tell you as soon as we can.
11.3 The current version is always available at https://otisio.com/acceptable-use.
Siege One Limited, company number 17110871, registered office 38 Angelica Avenue, Stotfold, Hitchin, England, SG5 4HH. Version 2026-08-v1, 8 August 2026.
Acceptable Use Policy version 2026-08-v1, effective 8 August 2026. Generated on 13 September 2026. Source text SHA-256 898c0f4c1e003133.