Legal

Acceptable Use Policy

The rules for lawful, fair, and responsible use of Native Keeper and workforce data held in the Service.

Last updated: 10 June 2026 · Version 1.0

1. Introduction

This Acceptable Use Policy ("AUP") sets out what you can and cannot do when using the Native Keeper service (the "Service"), which is operated by NeonStack Ltd (company number 16933096, registered in England and Wales) ("Native Keeper", "we", "us", or "our").

This AUP forms part of, and is incorporated by reference into, our Terms of Service. By using the Service, you agree to follow it. Violating this AUP can result in features being disabled, your account being suspended or terminated, and — in serious cases — referral to regulators or law-enforcement authorities.

Native Keeper is an HR and workforce compliance platform. Its purpose is to help employers manage their people responsibly, meet compliance obligations, and treat their workforce fairly. This AUP is written with that purpose in mind. Where a use of the Service would cause harm to workers, breach data-protection law, or undermine the fair treatment of individuals, that use is not acceptable — even if it might be technically possible.

We keep this Policy intentionally direct. If you're unsure whether something is allowed, contact us at legal@nativekeeper.com before doing it.

2. Who this applies to

This AUP applies to:

You, the Native Keeper account holder

Anyone using your account, including Admin Users, team members, and collaborators

The content of any record, document, or configuration you create using the Service

The way you use workforce data collected or held through the Service

You are responsible for ensuring everyone who uses your account complies with this AUP.

3. Lawful and fair use of workforce data

This is the central purpose of this AUP. Because Native Keeper holds Personal Data about your workforce — often including sensitive information — you agree to use the Service in a way that respects the rights of those individuals.

3.1 Lawful basis and notices

You must:

Have a lawful basis for every category of Personal Data you upload to the Service, under UK GDPR, EU GDPR, or the equivalent data-protection law in your jurisdiction

Provide appropriate privacy notices to the workforce whose data you hold, including disclosing Native Keeper as your Processor and explaining how their data is used

Have additional lawful bases for Special Category Personal Data (health, disability, sickness records, trade-union membership, ethnic origin, biometric data) under Article 9 UK/EU GDPR or equivalent

Have additional lawful bases for Criminal-Offence Data (DBS certificates, background-check results, spent-conviction disclosures) under Article 10 UK GDPR or equivalent, together with a condition under Schedule 1 DPA 2018 for UK Controllers

Maintain any appropriate policy document required by law where relying on a condition that requires one

Consult with, inform, or obtain consent from workers, works councils, or trade unions where required by your local employment law

Honour data-subject rights requests from your workforce within statutory timeframes, using the tools we provide

3.2 Right to Work and immigration data

If you use the Service to hold Right to Work evidence or other immigration-related documents:

Collect and check documents in the manner required by your local law (in the UK, in accordance with Home Office guidance)

Do not use the Service to profile, screen, or make employment decisions on the basis of nationality, ethnic origin, or perceived immigration status in a way that constitutes unlawful discrimination

Retain such documents only for the period lawfully required

Ensure access is limited to individuals in your organisation with a legitimate need to see them

3.3 Special Category and Criminal-Offence Data

Sensitive data (health, sickness, disability, DBS certificates, background checks) must be:

Uploaded only where there is a clear, lawful reason

Restricted to Admin Users who have a legitimate business need to see it

Retained only for as long as lawfully justified

Never used as the basis for unlawful discrimination

3.4 Data minimisation

You must not use the Service to collect or hold more workforce data than you actually need for a legitimate purpose. Extensive collection "just in case" is a common cause of data-protection breaches and is not an acceptable use.

4. What you must not use the Service for

You may not use the Service to do — or to enable, encourage, or facilitate any other person to do — any of the following.

4.1 Illegal activity

Anything that violates applicable law in the United Kingdom, the country where you are established, or the country where a Data Subject is located

Processing Personal Data without a valid lawful basis under applicable data-protection law

Money laundering, terrorist financing, sanctions evasion, or any activity restricted under UK, EU, US, or UN sanctions regimes

Modern slavery, human trafficking, forced labour, or labour exploitation

Tax evasion or fraud against any government

4.2 Harm to workers and individuals

Using workforce records to harass, intimidate, stalk, or threaten a worker or former worker

Using data held in the Service to retaliate against workers who have exercised a legal right (for example, whistleblowing, raising a grievance, taking family leave, joining a trade union, or refusing an unlawful instruction)

Using the Service to facilitate unlawful discrimination on the basis of any protected characteristic under applicable law (race, ethnicity, national origin, religion, sex, gender, gender reassignment, sexual orientation, marital status, pregnancy, disability, age, or any other protected characteristic in your jurisdiction)

Using the Service to hold or share data with intent to prevent an individual from finding work elsewhere (informal "blacklists")

4.3 Unlawful workforce surveillance

Using the Service to monitor workers in a way that is unlawful or disproportionate under your local law

Combining data held in Native Keeper with covert surveillance data to build worker profiles beyond what is lawful

Failing to inform workers of monitoring where a duty to inform applies

Extending compliance-tracking features into forms of monitoring the platform was not designed for and that are unlawful in your jurisdiction

4.4 Misrepresentation and falsification

Falsifying compliance records, including forging training certificates, editing document metadata to misrepresent expiry dates, or presenting inaccurate records to regulators, inspectors, auditors, or insurers

Uploading fake or altered background-check documents

Recording completion of training or certifications that did not occur

Misrepresenting any Native Keeper report to any third party

4.5 Data-protection violations

Uploading Personal Data of individuals who have exercised a valid right to erasure (unless a lawful exception applies)

Ignoring or bypassing data-subject rights requests from your workforce

Sharing workforce data with third parties who have no lawful basis to receive it

Cross-referencing workforce data across accounts, employers, or organisations without a lawful basis

Collecting data from children below the age of digital consent in the applicable jurisdiction without appropriate parental consent or another lawful basis

Using the Service to hold Personal Data whose collection or retention would be unlawful in the country where the Data Subject is located

4.6 Improper access and unauthorised use

Granting Native Keeper access to any individual who is not entitled to see the records they will access

Retaining access for individuals who have left your organisation

Sharing account credentials among individuals

Impersonating any person or organisation

Attempting to access Personal Data belonging to another Native Keeper customer

4.7 Security threats and abuse

Distributing malware, viruses, or malicious code through uploaded files

Hosting links to known malicious URLs

Attempting to gain unauthorised access to the Service, other customers' accounts, or any underlying infrastructure

Probing, scanning, or testing the vulnerability of the Service except as part of an authorised disclosure (see Section 7)

Defeating or attempting to defeat authentication, rate-limiting, or other security mechanisms

Using the Service for DDoS, traffic amplification, or as part of any botnet

Scraping, framing, mirroring, or systematically extracting data from the Service using automation in violation of our Terms of Service

4.8 Intellectual property infringement

Uploading documents you are not licensed to hold or share

Using third-party brand names or logos in ways that suggest false affiliation

Infringing another party's copyright, trademark, patent, or trade-secret rights

4.9 Adult and harmful content

Uploading pornographic, sexually explicit, or grossly offensive content

Uploading content that depicts or promotes violence, self-harm, terrorism, or the sexual exploitation of any person

4.10 Resource abuse and circumvention

Operating multiple accounts to evade plan limits, pricing, suspensions, or other restrictions

Sharing accounts in ways that materially exceed reasonable per-account use

Submitting fraudulent payment information or initiating fraudulent chargebacks

Reselling, sublicensing, or providing the Service to third parties except as expressly permitted by your plan

Using the Service to build a competing product

5. Use in regulated industries

Where you use the Service in a regulated industry — including care, healthcare, education, transport, financial services, security, childcare, or any other regulated sector — you remain responsible for meeting your specific regulatory obligations. Native Keeper provides technical and organisational controls that many regulated employers use to meet their record-keeping obligations, but:

We do not hold industry-specific certifications (for example, a specific CQC certification)

We do not guarantee that our defaults meet any particular regulator's expectations

Ultimate responsibility for regulatory compliance sits with you

You must not misrepresent Native Keeper's status to any regulator. When required to disclose your use of a Processor to a regulator or inspector, do so accurately.

6. What we do when this Policy is violated

We tailor our response to the severity of the violation. Possible actions include:

Severity

Typical action

Minor or first-time, low-risk

Email warning with required remediation

Material violation

Suspending the specific feature or restricting the affected area

Repeated or serious violation

Suspending or terminating your account

Egregious violation (falsification of compliance records, unlawful discrimination, unlawful surveillance, use of the Service to harm workers, or serious data-protection breaches)

Immediate termination without notice, preservation of relevant data, and reporting to the relevant authorities — including the Information Commissioner's Office (ICO), the Home Office, HMRC, sector regulators, or law-enforcement authorities as appropriate

We may take action without prior notice where we reasonably believe a violation poses an imminent risk of harm to workers, to Native Keeper, to our other customers, to our infrastructure, or to third parties.

We may also:

Preserve records relevant to a violation for investigation

Cooperate with regulators, law-enforcement, and affected Data Subjects where legally required

Refuse refunds of fees paid for any portion of a suspended or terminated service

Retain logs and evidence of the violation as required for our own legal defence

Important: Consistent with Section 3 of our Terms of Service, suspension or termination for AUP violation does not deprive you of the ability to export your data. Access to your existing data for a reasonable period (usually at least 30 days) is preserved except where preserving that access would perpetuate the violation or breach a legal obligation.

These remedies are in addition to, and not in place of, any other rights we have under the Terms of Service or applicable law.

7. Reporting abuse and responsible disclosure

7.1 Reporting a violation of this AUP

If you believe Native Keeper is being used in violation of this AUP — whether by an employer, another user of a customer's account, or otherwise — please report it to us.

Type of report

Contact

Misuse of the Service or violations of this AUP

legal@nativekeeper.com

Data-protection concerns (for example, if you believe an employer is holding your data unlawfully)

legal@nativekeeper.com — see also Section 11 of the Privacy Policy

Intellectual-property infringement

legal@nativekeeper.com with subject "IP infringement"

Security vulnerability in Native Keeper itself

legal@nativekeeper.com — see Section 7.2

Regulator communication

legal@nativekeeper.com — will be routed to our legal team immediately

When reporting, please include a clear description, any relevant identifiers (customer name, record type, dates), and any evidence (screenshots, correspondence). We respond as quickly as we can, and within hours for the most serious categories.

We do not disclose the identity of reporters except where legally required.

7.2 Responsible security disclosure

We welcome reports of security vulnerabilities in the Service. If you believe you have found one:

Email legal@nativekeeper.com with subject "Security disclosure" and details

Give us a reasonable opportunity to address the issue before disclosing publicly (we aim to acknowledge within 2 business days and provide an initial assessment within 7 days)

Do not access, modify, or delete data belonging to anyone other than yourself

Do not perform testing that could degrade the Service for other customers (DoS, brute force, fuzzing of production)

Do not demand payment as a condition of disclosure

Researchers acting in good faith under these rules will not be subject to legal action by us. We will publicly thank you (with your consent) and may, at our discretion, offer rewards for impactful disclosures.

7.3 If you are a worker whose data is held in Native Keeper

If you are an employee, worker, contractor, or other individual whose data is held in Native Keeper by an employer, and you believe your data is being processed unlawfully:

First, raise it with your employer directly. Your employer is the Controller of your data and the primary party responsible for its lawful use.

If unresolved, you may complain to the Information Commissioner's Office (in the UK) or your local supervisory authority.

You may also contact us at legal@nativekeeper.com. While we will not override our customer's instructions without proper grounds, we take reports seriously and may take action under this AUP where a customer's use is unlawful.

8. Changes to this Policy

We may update this AUP from time to time as new misuse patterns emerge or as law evolves. When we do, we'll update the "Last updated" date and maintain a changelog at the bottom of this page. Significant changes will be notified by email or in-product notice.

Because the AUP is a safety and lawful-use document, we may make changes with immediate effect where necessary to address new categories of misuse or to reflect changes in law. The version in force at the time of any use of the Service applies to that use.

9. Contact

For questions about this AUP that aren't reports of a violation:

Email: legal@nativekeeper.com

Postal address: NeonStack Ltd, The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD