Legal
Acceptable Use Policy
The rules for lawful, fair, and responsible use of Native Keeper and workforce data held in the Service.
Last updated: 10 June 2026 · Version 1.0
1. Introduction
This Acceptable Use Policy ("AUP") sets out what you can and cannot do when using the Native Keeper service (the "Service"), which is operated by NeonStack Ltd (company number 16933096, registered in England and Wales) ("Native Keeper", "we", "us", or "our").
This AUP forms part of, and is incorporated by reference into, our Terms of Service. By using the Service, you agree to follow it. Violating this AUP can result in features being disabled, your account being suspended or terminated, and — in serious cases — referral to regulators or law-enforcement authorities.
Native Keeper is an HR and workforce compliance platform. Its purpose is to help employers manage their people responsibly, meet compliance obligations, and treat their workforce fairly. This AUP is written with that purpose in mind. Where a use of the Service would cause harm to workers, breach data-protection law, or undermine the fair treatment of individuals, that use is not acceptable — even if it might be technically possible.
We keep this Policy intentionally direct. If you're unsure whether something is allowed, contact us at legal@nativekeeper.com before doing it.
2. Who this applies to
This AUP applies to:
You, the Native Keeper account holder
Anyone using your account, including Admin Users, team members, and collaborators
The content of any record, document, or configuration you create using the Service
The way you use workforce data collected or held through the Service
You are responsible for ensuring everyone who uses your account complies with this AUP.
3. Lawful and fair use of workforce data
This is the central purpose of this AUP. Because Native Keeper holds Personal Data about your workforce — often including sensitive information — you agree to use the Service in a way that respects the rights of those individuals.
3.1 Lawful basis and notices
You must:
Have a lawful basis for every category of Personal Data you upload to the Service, under UK GDPR, EU GDPR, or the equivalent data-protection law in your jurisdiction
Provide appropriate privacy notices to the workforce whose data you hold, including disclosing Native Keeper as your Processor and explaining how their data is used
Have additional lawful bases for Special Category Personal Data (health, disability, sickness records, trade-union membership, ethnic origin, biometric data) under Article 9 UK/EU GDPR or equivalent
Have additional lawful bases for Criminal-Offence Data (DBS certificates, background-check results, spent-conviction disclosures) under Article 10 UK GDPR or equivalent, together with a condition under Schedule 1 DPA 2018 for UK Controllers
Maintain any appropriate policy document required by law where relying on a condition that requires one
Consult with, inform, or obtain consent from workers, works councils, or trade unions where required by your local employment law
Honour data-subject rights requests from your workforce within statutory timeframes, using the tools we provide
3.2 Right to Work and immigration data
If you use the Service to hold Right to Work evidence or other immigration-related documents:
Collect and check documents in the manner required by your local law (in the UK, in accordance with Home Office guidance)
Do not use the Service to profile, screen, or make employment decisions on the basis of nationality, ethnic origin, or perceived immigration status in a way that constitutes unlawful discrimination
Retain such documents only for the period lawfully required
Ensure access is limited to individuals in your organisation with a legitimate need to see them
3.3 Special Category and Criminal-Offence Data
Sensitive data (health, sickness, disability, DBS certificates, background checks) must be:
Uploaded only where there is a clear, lawful reason
Restricted to Admin Users who have a legitimate business need to see it
Retained only for as long as lawfully justified
Never used as the basis for unlawful discrimination
3.4 Data minimisation
You must not use the Service to collect or hold more workforce data than you actually need for a legitimate purpose. Extensive collection "just in case" is a common cause of data-protection breaches and is not an acceptable use.
4. What you must not use the Service for
You may not use the Service to do — or to enable, encourage, or facilitate any other person to do — any of the following.
4.1 Illegal activity
Anything that violates applicable law in the United Kingdom, the country where you are established, or the country where a Data Subject is located
Processing Personal Data without a valid lawful basis under applicable data-protection law
Money laundering, terrorist financing, sanctions evasion, or any activity restricted under UK, EU, US, or UN sanctions regimes
Modern slavery, human trafficking, forced labour, or labour exploitation
Tax evasion or fraud against any government
4.2 Harm to workers and individuals
Using workforce records to harass, intimidate, stalk, or threaten a worker or former worker
Using data held in the Service to retaliate against workers who have exercised a legal right (for example, whistleblowing, raising a grievance, taking family leave, joining a trade union, or refusing an unlawful instruction)
Using the Service to facilitate unlawful discrimination on the basis of any protected characteristic under applicable law (race, ethnicity, national origin, religion, sex, gender, gender reassignment, sexual orientation, marital status, pregnancy, disability, age, or any other protected characteristic in your jurisdiction)
Using the Service to hold or share data with intent to prevent an individual from finding work elsewhere (informal "blacklists")
4.3 Unlawful workforce surveillance
Using the Service to monitor workers in a way that is unlawful or disproportionate under your local law
Combining data held in Native Keeper with covert surveillance data to build worker profiles beyond what is lawful
Failing to inform workers of monitoring where a duty to inform applies
Extending compliance-tracking features into forms of monitoring the platform was not designed for and that are unlawful in your jurisdiction
4.4 Misrepresentation and falsification
Falsifying compliance records, including forging training certificates, editing document metadata to misrepresent expiry dates, or presenting inaccurate records to regulators, inspectors, auditors, or insurers
Uploading fake or altered background-check documents
Recording completion of training or certifications that did not occur
Misrepresenting any Native Keeper report to any third party
4.5 Data-protection violations
Uploading Personal Data of individuals who have exercised a valid right to erasure (unless a lawful exception applies)
Ignoring or bypassing data-subject rights requests from your workforce
Sharing workforce data with third parties who have no lawful basis to receive it
Cross-referencing workforce data across accounts, employers, or organisations without a lawful basis
Collecting data from children below the age of digital consent in the applicable jurisdiction without appropriate parental consent or another lawful basis
Using the Service to hold Personal Data whose collection or retention would be unlawful in the country where the Data Subject is located
4.6 Improper access and unauthorised use
Granting Native Keeper access to any individual who is not entitled to see the records they will access
Retaining access for individuals who have left your organisation
Sharing account credentials among individuals
Impersonating any person or organisation
Attempting to access Personal Data belonging to another Native Keeper customer
4.7 Security threats and abuse
Distributing malware, viruses, or malicious code through uploaded files
Hosting links to known malicious URLs
Attempting to gain unauthorised access to the Service, other customers' accounts, or any underlying infrastructure
Probing, scanning, or testing the vulnerability of the Service except as part of an authorised disclosure (see Section 7)
Defeating or attempting to defeat authentication, rate-limiting, or other security mechanisms
Using the Service for DDoS, traffic amplification, or as part of any botnet
Scraping, framing, mirroring, or systematically extracting data from the Service using automation in violation of our Terms of Service
4.8 Intellectual property infringement
Uploading documents you are not licensed to hold or share
Using third-party brand names or logos in ways that suggest false affiliation
Infringing another party's copyright, trademark, patent, or trade-secret rights
4.9 Adult and harmful content
Uploading pornographic, sexually explicit, or grossly offensive content
Uploading content that depicts or promotes violence, self-harm, terrorism, or the sexual exploitation of any person
4.10 Resource abuse and circumvention
Operating multiple accounts to evade plan limits, pricing, suspensions, or other restrictions
Sharing accounts in ways that materially exceed reasonable per-account use
Submitting fraudulent payment information or initiating fraudulent chargebacks
Reselling, sublicensing, or providing the Service to third parties except as expressly permitted by your plan
Using the Service to build a competing product
5. Use in regulated industries
Where you use the Service in a regulated industry — including care, healthcare, education, transport, financial services, security, childcare, or any other regulated sector — you remain responsible for meeting your specific regulatory obligations. Native Keeper provides technical and organisational controls that many regulated employers use to meet their record-keeping obligations, but:
We do not hold industry-specific certifications (for example, a specific CQC certification)
We do not guarantee that our defaults meet any particular regulator's expectations
Ultimate responsibility for regulatory compliance sits with you
You must not misrepresent Native Keeper's status to any regulator. When required to disclose your use of a Processor to a regulator or inspector, do so accurately.
6. What we do when this Policy is violated
We tailor our response to the severity of the violation. Possible actions include:
Severity
Typical action
Minor or first-time, low-risk
Email warning with required remediation
Material violation
Suspending the specific feature or restricting the affected area
Repeated or serious violation
Suspending or terminating your account
Egregious violation (falsification of compliance records, unlawful discrimination, unlawful surveillance, use of the Service to harm workers, or serious data-protection breaches)
Immediate termination without notice, preservation of relevant data, and reporting to the relevant authorities — including the Information Commissioner's Office (ICO), the Home Office, HMRC, sector regulators, or law-enforcement authorities as appropriate
We may take action without prior notice where we reasonably believe a violation poses an imminent risk of harm to workers, to Native Keeper, to our other customers, to our infrastructure, or to third parties.
We may also:
Preserve records relevant to a violation for investigation
Cooperate with regulators, law-enforcement, and affected Data Subjects where legally required
Refuse refunds of fees paid for any portion of a suspended or terminated service
Retain logs and evidence of the violation as required for our own legal defence
Important: Consistent with Section 3 of our Terms of Service, suspension or termination for AUP violation does not deprive you of the ability to export your data. Access to your existing data for a reasonable period (usually at least 30 days) is preserved except where preserving that access would perpetuate the violation or breach a legal obligation.
These remedies are in addition to, and not in place of, any other rights we have under the Terms of Service or applicable law.
7. Reporting abuse and responsible disclosure
7.1 Reporting a violation of this AUP
If you believe Native Keeper is being used in violation of this AUP — whether by an employer, another user of a customer's account, or otherwise — please report it to us.
Type of report
Contact
Misuse of the Service or violations of this AUP
Data-protection concerns (for example, if you believe an employer is holding your data unlawfully)
legal@nativekeeper.com — see also Section 11 of the Privacy Policy
Intellectual-property infringement
legal@nativekeeper.com with subject "IP infringement"
Security vulnerability in Native Keeper itself
legal@nativekeeper.com — see Section 7.2
Regulator communication
legal@nativekeeper.com — will be routed to our legal team immediately
When reporting, please include a clear description, any relevant identifiers (customer name, record type, dates), and any evidence (screenshots, correspondence). We respond as quickly as we can, and within hours for the most serious categories.
We do not disclose the identity of reporters except where legally required.
7.2 Responsible security disclosure
We welcome reports of security vulnerabilities in the Service. If you believe you have found one:
Email legal@nativekeeper.com with subject "Security disclosure" and details
Give us a reasonable opportunity to address the issue before disclosing publicly (we aim to acknowledge within 2 business days and provide an initial assessment within 7 days)
Do not access, modify, or delete data belonging to anyone other than yourself
Do not perform testing that could degrade the Service for other customers (DoS, brute force, fuzzing of production)
Do not demand payment as a condition of disclosure
Researchers acting in good faith under these rules will not be subject to legal action by us. We will publicly thank you (with your consent) and may, at our discretion, offer rewards for impactful disclosures.
7.3 If you are a worker whose data is held in Native Keeper
If you are an employee, worker, contractor, or other individual whose data is held in Native Keeper by an employer, and you believe your data is being processed unlawfully:
First, raise it with your employer directly. Your employer is the Controller of your data and the primary party responsible for its lawful use.
If unresolved, you may complain to the Information Commissioner's Office (in the UK) or your local supervisory authority.
You may also contact us at legal@nativekeeper.com. While we will not override our customer's instructions without proper grounds, we take reports seriously and may take action under this AUP where a customer's use is unlawful.
8. Changes to this Policy
We may update this AUP from time to time as new misuse patterns emerge or as law evolves. When we do, we'll update the "Last updated" date and maintain a changelog at the bottom of this page. Significant changes will be notified by email or in-product notice.
Because the AUP is a safety and lawful-use document, we may make changes with immediate effect where necessary to address new categories of misuse or to reflect changes in law. The version in force at the time of any use of the Service applies to that use.
9. Contact
For questions about this AUP that aren't reports of a violation:
Email: legal@nativekeeper.com
Postal address: NeonStack Ltd, The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD