Prepared for review: 30 September 2026. Status: draft, not effective.
1. Purpose and applicability
This draft is intended to support a signed service agreement. It describes responsible use of StaffWorkspace and must be reviewed with customer terms before it becomes binding. The marketing website itself does not provide access to employee accounts.
2. Authorised business use
Use the service only for legitimate, authorised workplace administration. Maintain accurate company details and ensure invited users have an appropriate role. Do not impersonate another employer or employee, reserve misleading company addresses, or use a workspace to deceive people into disclosing credentials or money.
3. Prohibited technical activity
Do not access another tenant, evade access restrictions, extract data without authority, distribute malware, exploit vulnerabilities, disrupt service or overload systems. Automated activity must comply with the agreed interface and limits. Security research requires an agreed scope and must avoid access to personal data; this draft grants no general penetration-testing permission.
4. Personal data and monitoring
Do not collect excessive information, enable covert or unlawful monitoring, or use photo or location tools outside an assessed workplace purpose. Do not use the platform for unlawful discrimination, retaliation, surveillance of private activity, or unsupported automated employment decisions. Employee consent, where sought, must not be assumed freely given solely because the employer presents a checkbox.
5. Content and communication
Do not upload unlawful material, infringe rights, harass colleagues, send spam, distribute malicious files or publish another person’s private records without authority. Customer administrators should establish appropriate reporting and review procedures. This policy is not a basis for suppressing lawful worker rights or disclosures protected by applicable law.
6. Credentials and access
Use individual accounts where supported, protect authentication factors and promptly remove unnecessary access. Do not post passwords, API keys or payroll records in announcements or public links. Notify the appropriate administrator of suspected compromise. The existence of this policy does not establish that every desired technical control has already been implemented.
7. Reporting and response
Report website issues to info@staffworkspace.com without attaching sensitive employee records or exploit data. A secure reporting channel and operational security contact must be established for the application. Proposed responses should be proportionate to the risk, respect mandatory rights, preserve relevant evidence and allow remediation where appropriate. The signed agreement must govern suspension and appeal procedures.