Acceptable Use Policy
Version 1.0 · In force from 2026-08-22
We are ITSM Ltd, a company incorporated in England and Wales with company number 17339600 and registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF ('we', 'our' or 'us'). We supply software-as-a-service products under our trading names, including ImproveDesk and Fulfilra. The product you have been given access to is your Service, and its Service Schedule describes it.
This acceptable use policy (AUP) sets out the rules that apply to you personally when you use a Service under an organisation's subscription. It is written first for the people who are given access by someone else — colleagues invited into an organisation — but it applies to every User, including the person who accepted the Head Agreement on the organisation's behalf, in their personal capacity.
Please read it before you accept it. If you do not want to agree to it, do not use the Service, and tell whoever invited you.
IN SHORT
This summary is here to help you read the rest. It is not part of this AUP and does not change it — where the summary and the clauses differ, the clauses apply.
- Use the Service for your Organisation's work in it, and for nothing else.
- Your account is yours alone. Do not share it, and tell us at once if you think someone else has used it.
- Do not put in material your Organisation has not asked you to record — other people's confidential or copyright material especially.
- What you record belongs to your Organisation, not to you. What you did is recorded against your account, with the date and time; the Service Schedule says what is kept and whether entries can ever be removed.
- If you break these rules, your access can be ended — by us, by your Organisation, or by both. We will normally give you a chance to put things right first.
- What we owe you if something goes wrong is capped at £100, apart from the things the law does not let us cap. That is clause 9, and it is worth reading in full.
1. KEY TERMS
| Term | Meaning |
|---|---|
| AUP | this Acceptable Use Policy, as published at the address in the Service Schedule and changed from time to time under clause 12. |
| Business Day | a day other than a Saturday, Sunday or public holiday in England. |
| Content | anything you record, upload or submit in the Service. Content forms part of your Organisation's "Client Data" under the Head Agreement. |
| Head Agreement | the SaaS Terms and Conditions between us and your Organisation, together with the Service Schedule for your Service, under which the Service is supplied. Your Organisation is called the "Client" in those documents, and you are one of its "Users". |
| Organisation | the organisation whose subscription you use and which has given you access to the Service. |
| Personnel | our officers, employees, contractors (including subcontractors) and agents. |
| Provider, we, us, our | ITSM Ltd, company number 17339600, trading under the Brand named in the Service Schedule. |
| Purpose | the purpose of the Service, as stated in the Service Schedule. |
| Records | the content your Organisation records in the Service — its Client Data — as described in the Service Schedule. |
| Service | the ITSM Ltd product you have been given access to, including its website, its application, and any documentation we supply for it, as identified in the Service Schedule. |
| Service Schedule | the schedule for your Service, published alongside the Head Agreement. |
| User, you, your | you, as an individual who has been given access to the Service under the Organisation's subscription. |
2. WHO THIS POLICY IS FOR, AND HOW YOU ACCEPT IT
(a) This AUP applies to you if you have been given access to the Service under an Organisation's subscription — whether you were invited by someone else, or you are the person who accepted the Head Agreement on the Organisation's behalf and also use the Service yourself.
(b) You accept this AUP by ticking the box that refers to it when you set your password or first sign in. That is how we ask for your agreement, and it is the acceptance we rely on.
(c) If you were given access without being asked to tick that box — for example because your Organisation created your account before we introduced it — you agree to this AUP by continuing to access the Service after we have made it available to you and told you it applies. We will not treat you as having accepted it before then, and we will not rely on clause 9 to limit what we owe you unless you have had a fair opportunity to read it first.
(d) When you accept it, we record the fact. The record holds your user ID, your Organisation's ID where the Service records one, the name (or slug) and version of each document you accepted, the context in which you accepted it where the Service records one, and the date and time — and nothing else. It is our evidence of your agreement, and the version number in it is what lets you tell later exactly which wording you agreed to. Our Privacy Policy explains how we handle information about you.
(e) This AUP starts on the earlier of the date you accept it and the date you first access the Service, and continues until your access ends or it is terminated under clause 10.
(f) If you do not accept this AUP you must not access, use or otherwise view the Service, and you should tell the person in your Organisation who invited you.
(g) The Service is not intended for unsupervised use by anyone under 18 years old. Please do not access the Service if you are under 18, or if you have previously been suspended or prohibited from using it.
3. HOW THIS POLICY FITS WITH OUR OTHER TERMS
(a) The Service is supplied to your Organisation under the Head Agreement. You are not a party to the Head Agreement and this AUP does not make you one. It does not give you a subscription, and it gives you no rights against us other than the licence in clause 4.
(b) This AUP is the acceptable use policy referred to in the Head Agreement, and it applies to every User of every Service. It is a standalone document so that you can read and agree to the rules that bind you personally without having to read your Organisation's subscription agreement.
(c) If anything in this AUP is inconsistent with the Head Agreement, then as between us and your Organisation the Head Agreement prevails, and as between you and us this AUP prevails. This is the document we asked you to read and accept, so it is the one that governs what you personally owe us; we will not rely on the Head Agreement to hold you to a stricter obligation than this AUP sets out.
(d) Two other documents also apply to you, and you accept them alongside this one:
(i) our Website Terms of Use, which govern your use of the public pages of our websites; and
(ii) our Privacy Policy, which explains what we do with personal data.
Our Cookie Policy explains the cookies each Service sets. There is nothing to accept in it. The addresses of all four documents are listed in the Service Schedule for your Service.
(e) Your Organisation may have its own rules about how you use the Service — what belongs in it, what must not go into it, and who may see it. Those rules are between you and your Organisation. Where they are stricter than this AUP, follow them.
4. YOUR LICENCE TO USE THE SERVICE
4.1. WHAT YOU MAY DO
(a) We grant you a revocable, worldwide, royalty-free, non-exclusive and non-transferable licence to use the Service for the Purpose, for as long as your Organisation gives you access to it.
(b) You must only use the Service: (i) within the limits of the Purpose; (ii) in a manner that complies with clause 5; and (iii) in compliance with any other restriction notified to you in writing by your Organisation or by us from time to time.
4.2. WHAT THE LICENCE IS NOT
(a) The licence is personal to you. You acquire no ownership of the Service or any part of it, and all intellectual property rights in the Service remain with us or our licensors.
(b) As between you and us, Content belongs to your Organisation, not to you. Recording something in the Service does not make it your personal record, and clause 11 explains what happens to it when your access ends.
(c) If you give us feedback, comments or suggestions about the Service, we may use, incorporate and exploit that feedback for any purpose without restriction or compensation. Giving us feedback grants you no right, title or interest in the Service.
5. WHAT YOU MUST NOT DO
You must not do any of the following, unless your Organisation or we have approved it in writing beforehand — and we may give or withhold approval in our absolute discretion:
(a) record special category personal data — information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data used to identify someone, or data concerning health, sex life or sexual orientation — or information about criminal offences or alleged offences, unless your Organisation has told you that the Service is used for that purpose;
(b) upload any harmful, discriminatory, defamatory, maliciously false, offensive, explicit, inappropriate, illicit, illegal, pornographic, sexist, homophobic or racist material to the Service;
(c) upload any material that is owned or copyrighted by a third party;
(d) make copies of the Service;
(e) adapt, modify or tamper in any way with the Service;
(f) remove or alter any copyright, trade mark or other notice on or forming part of the Service;
(g) create derivative works from, translate or reproduce the Service;
(h) publish or otherwise communicate the Service to the public, including by making it available online or sharing it with third parties;
(i) sell, loan, transfer, sub-license, hire or otherwise dispose of the Service to any third party;
(j) decompile or reverse engineer the Service or any part of it, or otherwise attempt to derive its source code;
(k) attempt to circumvent any technological protection mechanism or other security feature of the Service, except where you do so in good faith, without accessing or altering anyone else's data, without degrading the service for others, and where you report what you find to us promptly and privately in accordance with clause 13;
(l) permit any other person to use or access the Service through your account;
(m) intimidate, harass, impersonate, stalk, threaten, bully or endanger any other user of the Service, or distribute unsolicited commercial content, junk mail, spam, bulk content or harassment in connection with the Service;
(n) share your account details with any other person — any use of your account by another person is strictly prohibited;
(o) use the Service for any purpose other than the Purpose, including by using it in a manner that is illegal or fraudulent or that facilitates illegal or fraudulent activity; or
(p) act unlawfully or maliciously towards us, towards another user, or towards your Organisation, or use the Service to do so.
5.1. HOW THIS WORKS IN PRACTICE
(a) Your Organisation's instructions are its approval. Your Organisation decides what belongs in its Records. Where it has asked you to record particular information in the organisation it has given you access to, we treat that instruction as its approval in writing for the purposes of clauses 5(a) and 5(c), and you do not need to ask us as well.
(b) Using your role is not "permitting access". Clause 5(l) is about giving other people your access. It does not stop you using the features your role gives you: if your role lets you invite colleagues into your Organisation, inviting them is approved use, not a breach.
(c) When you are not sure, ask before you upload. The things people record in these Services often describe events that involve people, and what you write stays in your Organisation's records. If you are unsure whether something belongs there — an entry that names a colleague, a supplier's confidential document, a third party's copyright material — ask your Organisation first, not afterwards.
(d) Honest criticism is not a breach. Nothing in clause 5(p) stops you giving an honest opinion about the Service, raising a concern with a regulator or other authority, reporting a security issue to us in good faith, or saying anything you are required by law to say.
6. YOUR ACCOUNT
(a) Your account is yours alone. Keep your password and any other credentials secret, and do not let anyone else sign in as you.
(b) If your role requires two-step verification, you must set it up and keep it working. The Service Schedule says which roles this applies to for your Service.
(c) You must immediately notify us at support@itsm-ltd.com of any unauthorised use of your account, password or email address, or of any other breach or potential breach of the Service's security.
(d) You are responsible for what is done under your account, except to the extent it results from our breach of this AUP or our negligence.
7. WHAT IS RECORDED, AND WHAT YOUR ORGANISATION CONTROLS
This clause is here because you should know it before you accept, not because it grants anyone a new right.
(a) The Service keeps a record of actions taken in it, held against the account that took them, with the date and time. The Service Schedule describes what is recorded for your Service, how long it is kept, and whether entries can ever be edited or removed — for some Services they cannot be removed individually by anyone, including us, because the record is the evidence the product exists to produce.
(b) People in your Organisation whose role permits it can read those records, and can produce reports or exports from them. Those outputs identify the people who acted.
(c) Your Organisation controls your access. It can change your role or remove your access at any time, and it does not need our agreement or yours to do so.
(d) Where Content includes personal data, your Organisation is the controller of that data and we process it on your Organisation's instructions under clause 11 of the Head Agreement. Requests about personal data held in your Organisation's Records go to your Organisation.
(e) None of this affects the rights you have over your own personal data — the data we hold about you as a user of the Service. Our Privacy Policy explains those rights and how to exercise them.
(f) Where your Service sends data elsewhere on your Organisation's instructions — for example, where Fulfilra creates and links an issue in your Organisation's own Jira Service Management site — the Service Schedule describes what is sent, and what happens to it afterwards is governed by your Organisation's own arrangements with that provider, not by this AUP.
8. WHAT WE DO NOT PROMISE
(a) We do not guarantee, and to the maximum extent permitted by law make no warranty, that: (i) the Service will be free from errors or defects; (ii) the Service will be accessible or available at all times; or (iii) any information provided through the Service is accurate or true.
(b) You must take your own precautions to ensure that the way you access the Service does not expose you to the risk of hacking, malware, ransomware, viruses, malicious computer code or other forms of interference.
(c) Subject to clause 9(a), we do not accept responsibility for any unauthorised use of, or destruction, loss, damage or alteration to, your data or information, or to your computer systems, mobile phones or other electronic devices, arising in connection with your use of the Service.
9. LIABILITY AND INDEMNITY
(a) Nothing in this AUP limits or excludes our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited or excluded. Nothing in this AUP affects any right you have that cannot lawfully be excluded, and any exclusion or limitation in this clause 9 applies only so far as the law allows.
(b) This clause is about what we owe YOU, personally. What we owe your Organisation is a separate question, governed by clause 13 of the Head Agreement, and the figure there is larger because your Organisation is the party that pays us. If something goes wrong that affects your Organisation's data or its use of the Service, that is their claim under their agreement, not yours under this one.
(c) Subject to paragraph (a), and to the maximum extent permitted by applicable law, our total liability to you for loss or damage of any kind, however arising — whether in contract, tort (including negligence), statute, equity, indemnity or otherwise — arising from or relating in any way to the Service or this AUP is limited to £100 in aggregate. This includes the transmission of any computer virus.
(d) Subject to paragraph (a), and to the maximum extent permitted by applicable law, neither we nor our Personnel will be liable for any incidental, special or consequential loss or damage, or for damages for loss of data, business or business opportunity, goodwill, anticipated savings, profits or revenue, arising under or in connection with the Service, this AUP or their subject matter.
(e) Subject to paragraph (a), all express or implied representations and warranties given by us or our Personnel are excluded to the maximum extent permitted by applicable law. Where any law implies a condition, warranty or guarantee into this AUP which may not lawfully be excluded, then to the maximum extent permitted by applicable law our (and our Personnel's) liability for breach of it is, at our option, limited to: (i) in the case of goods, their replacement, the supply of equivalent goods, or their repair; and (ii) in the case of services, the supply of the services again, or the payment of the cost of having them supplied again.
(f) You indemnify us and our Personnel in respect of all liability for loss, damage or injury suffered by any person arising from, or in connection with, your use of the Service or your breach of this AUP (or both), except to the extent the loss, damage or injury is caused by our breach of this AUP or our negligence.
(g) To the extent that any applicable law restricts how far liability may be excluded under this AUP — including sections 2, 3 and 11 of the Unfair Contract Terms Act 1977 and their equivalents in any other jurisdiction — the exclusions and limitations in this clause 9 are limited accordingly, and the remainder continues in full force and effect.
10. IF YOU BREACH THIS POLICY
(a) We or your Organisation (or both) may end your access to the Service and terminate this AUP — as an individual User, and without terminating the Head Agreement:
(i) by notice to you, if you are in breach of any term of this AUP and have failed to remedy the breach within 10 Business Days after being given notice of it; or
(ii) immediately, where the breach is a breach of clause 5, is not capable of remedy, or is one your Organisation asks us to act on immediately — including where we or your Organisation reasonably suspect that you are about to commit such a breach. Paragraph (i) governs every other breach.
(b) Where we consider it the more proportionate response, we may suspend your access instead of terminating it. Suspending your access is not a waiver of our right to terminate under paragraph (a).
(c) This AUP terminates automatically, and your licence to the Service is immediately revoked, if the Head Agreement expires or is terminated — save for any continuing retrieval right stated in the Service Schedule (for example, the right of ImproveDesk Users to retrieve evidence packs that were issued before termination).
11. WHEN YOUR ACCESS ENDS
(a) On expiry or termination of this AUP you must: (i) immediately stop using the Service; and (ii) return or destroy any documentation we supplied to you, and remove the Service from any materials in your care, custody or control that feature it.
(b) Content stays with your Organisation. We do not give you a personal copy of it, and we are not liable to you or to any other person for any loss of data or information when your access ends. If you need a copy of something you recorded, ask your Organisation before your access ends — afterwards we will act only on your Organisation's instructions.
(c) The records described in clause 7(a) are not deleted when your access ends. They are your Organisation's records.
(d) Expiry or termination does not affect any right that has accrued to either of us up to that date, any obligation already performed, or any obligation which expressly or by implication survives termination. Clauses 4.2, 8, 9, 11 and 14 survive termination of this AUP.
12. CHANGES TO THIS POLICY
(a) We may change this AUP. The current version is always the one published at the address in the Service Schedule, which shows its version number and the date it came into force.
(b) We give you at least 30 days' notice of any change to this AUP, in the same way as clause 19 of the Head Agreement. Your continued use of the Service after a change has come into force represents your agreement to be bound by this AUP as amended; if you do not agree, stop using the Service and tell your Organisation before the change takes effect.
(c) The record described in clause 2(d) cites the version you accepted, so you can always compare what you agreed to with what is published now.
13. REPORTING MISUSE AND CONTACTING US
(a) If you become aware of misuse of the Service by any person, of any security problem, or of Content that breaches clause 5, please tell us immediately at support@itsm-ltd.com.
(b) If your report concerns Content in your Organisation's Records, tell your Organisation as well. Those Records are your Organisation's, and we will not change or remove anything in them except on your Organisation's instructions or where the law requires us to act.
(c) If you think we have applied this AUP wrongly to you — for example by suspending or ending your access when you do not believe you were in breach — write to us at support@itsm-ltd.com and say so. We will look at it again and reply.
(d) For anything else about this AUP, write to us at support@itsm-ltd.com, or at ITSM Ltd, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.
14. GENERAL
14.1. GOVERNING LAW AND JURISDICTION
This AUP is governed by the law of England and Wales. Each party irrevocably submits to the exclusive jurisdiction of the courts of England and Wales, and courts of appeal from them, in respect of any proceedings arising out of or in connection with this AUP, and irrevocably waives any objection to venue on the basis of inconvenient forum.
14.2. THIRD PARTY RIGHTS
This AUP does not give rise to any rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms, except that your Organisation may enforce clauses 5 and 10 against you. That exception exists because clause 5 sets the rules your Organisation relies on, and clause 10 gives your Organisation the power to end your access; without it, that power would be unenforceable by the party the clause names.
14.3. WAIVER
No party may rely on the words or conduct of any other party as a waiver of any right unless the waiver is in writing and signed by the party granting it.
14.4. SEVERANCE
Any term of this AUP which is wholly or partially void or unenforceable is severed to the extent that it is void or unenforceable. The validity and enforceability of the remainder is not affected.
14.5. ASSIGNMENT
You cannot assign, novate or otherwise transfer your rights or obligations under this AUP without our prior written consent.
14.6. FURTHER ACTS AND DOCUMENTS
Each party must promptly do all further acts and execute and deliver all further documents required by law, or reasonably requested by the other party, to give effect to this AUP.
14.7. ENTIRE AGREEMENT
This AUP, read together with the documents named in clause 3(d), embodies the entire agreement between you and us in relation to your personal use of the Service, and is subject to the order of precedence in clause 2(c) of the Head Agreement. It supersedes any prior negotiation, conduct, arrangement, understanding or agreement, express or implied, in relation to that subject matter. It does not affect the Head Agreement between us and your Organisation.