Legal · last updated 13 September 2026
Acceptable use policy
DeskBridge services must be used lawfully, by authorised people, and within the security and service boundaries agreed with the client.
Who this applies to
This policy applies to website visitors, account holders, client administrators, contractors and anyone using a DeskBridge-provided or DeskBridge-managed route. Clients must ensure their authorised users understand it.
Identity and access
- Use only your own assigned account and approved authentication method.
- Do not share passwords, recovery codes, security keys, sessions or privileged access.
- Do not bypass access controls, tenant boundaries, monitoring, expiry dates or approval workflows.
- Report suspected compromise, mistaken access or former-user access promptly.
Prohibited activity
- Illegal, fraudulent, abusive, harassing, infringing or deliberately deceptive activity.
- Malware, credential theft, phishing, spam, denial-of-service activity or unauthorised security testing.
- Accessing, changing, exporting or disclosing information without authority.
- Introducing unapproved software, integrations, forwarding rules, storage routes or AI tools.
- Attempting to discover another tenant’s information, secrets, internal paths or protected operational data.
- Using the service to create or distribute material that unlawfully harms another person or organisation.
Data and communications
- Use the approved location and classification for client information.
- Do not place secrets or sensitive personal data into general support, enquiry or AI prompts unless the authorised process explicitly requires it.
- Respect retention, legal hold, export, sharing and deletion controls.
- Do not use DeskBridge communications for unsolicited bulk messaging or misleading sender identities.
Enforcement
DeskBridge may block an action, preserve evidence, restrict or suspend access, isolate a session or refer the matter to an authorised client contact where reasonably necessary to protect users, tenants or the service. Urgent protective action may precede notification. Contractual remedies and lawful reporting obligations still apply.
Questions and authorised testing
Ask the Helpdesk before attempting an unusual or high-risk action. Security testing requires prior written authorisation defining systems, timing and methods.