1. Purpose and responsibility
This Acceptable Use Policy applies to every customer, administrator, user, integration, and person using a Union Software service. The customer is responsible for its users and for content, audiences, workflows, and connected services it controls.
2. Illegal, harmful, or abusive activity
- Do not use the service to violate a law, court order, collective agreement, binding union rule, intellectual-property right, privacy right, or contractual duty.
- Do not threaten, harass, exploit, defame, discriminate unlawfully, facilitate violence, or publish intimate or highly sensitive information without authority.
- Do not impersonate another person, conceal the source of a message deceptively, commit fraud, or submit information you know is materially false.
- Do not distribute malware, phishing, credential theft, ransomware, or instructions intended to compromise systems or people.
- Do not use the service for surveillance or profiling that is unlawful or incompatible with the customer’s representational and governance responsibilities.
3. Security and platform integrity
- Do not probe, scan, or test a vulnerability without written authorization, bypass access controls, or access another tenant or user without permission.
- Do not interfere with availability, overload the service, evade usage limits, introduce malicious code, or use automated access outside documented interfaces.
- Do not share credentials, resell access without authorization, or allow an account to be used by a person who has not been approved by the customer.
- Good-faith security reports should be sent privately to our contact address and must avoid privacy violations, disruption, extortion, and public disclosure before reasonable remediation.
4. Email, SMS, voice, and campaigns
- Send only to recipients for whom the customer has the consent, relationship, or other lawful authority required in the applicable jurisdiction.
- Use accurate sender identity and contact details. Do not use purchased, scraped, harvested, or unlawfully shared lists.
- Include and honour required unsubscribe methods, suppression choices, quiet hours, frequency limits, carrier rules, and sender-registration requirements.
- Do not send deceptive, fraudulent, abusive, or prohibited content, or content likely to cause provider blocking or harm shared service reputation.
- Maintain records reasonably sufficient to demonstrate consent and compliance. Platform status labels are tools and are not a legal determination.
5. Sensitive and regulated information
Use only an appropriate enabled module and permission model for medical, disability, financial, government identifier, grievance, discipline, organizing, bargaining, election, or other highly sensitive information. Do not place payment-card security codes, account passwords, or information prohibited by an order form in free-text fields or ordinary messages.
A customer may not use the service for data subject to a specialized legal regime, such as protected health information regulated by HIPAA, unless Union Software has expressly agreed in writing to the required terms.
6. Enforcement
We may investigate suspected violations, preserve relevant evidence, limit a message or integration, remove unlawful content, or suspend affected access. We will consider the severity, risk, customer response, and whether a narrower measure is available. We will give notice where practicable and may report conduct where legally required.
7. Reporting a concern
Report suspected abuse to legal@unionsoftware.com. Include the workspace or sending organization, message or event identifiers, dates, and a concise description. Do not include unrelated sensitive records.