ITSM Ltd SaaS legal set — Part 3
Acceptable Use Policy
Version 2.0 · In force from 24/09/2026
Supersedes Acceptable Use Policy version 1.2.
We are ITSM Ltd, a company incorporated in England and Wales with company number 17339600 and registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF (“we”, “our” or “us”). We supply software-as-a-service products under our trading names. The product you have been given access to is your Service. Its Service Schedule describes it, and the Annex to this AUP, printed after clause 14, sets out the rules that are specific to it.
This acceptable use policy (AUP) sets out the rules that apply to you personally when you use the Service as a member of an organisation. It is written first for the people who are given access by someone else — a colleague or a volunteer, invited into an organisation — but it applies to every User, including the person who accepted the Head Agreement on the organisation's behalf, in their personal capacity.
Please read it before you accept it. If you do not want to agree to it, do not use the Service. If you have already joined an organisation through an invitation, clause 2(f) says what to do.
In short
This summary is here to help you read the rest. It is not part of this AUP and does not change it — where the summary and the clauses differ, the clauses apply.
- Use the Service for your Organisation's records, within the Purpose the Annex states, and for nothing else (clause 4.1 and section A1).
- Your account is yours alone. Keep what you sign in with to yourself — where the Service signs you in by a link sent to your email, keeping that mailbox secure is what keeps your account secure — and tell us at once if you think someone else has used it. That is clause 6, and section A2 says how signing in works.
- Do not put in material your Organisation has not asked you to record. Think twice about photographs of people, and about anything that cannot be removed once it is in — clauses 5 and 7.
- What you record belongs to your Organisation, not to you. Clause 7 and the Annex say what is and is not attributed to your account, who in your Organisation can see your details, and which records cannot be edited or deleted one at a time afterwards.
- If you break these rules, your access can be ended — by us, by your Organisation, or by both. We will normally give you a chance to put things right first (clause 10).
- What we owe you if something goes wrong is capped at £100, apart from the things the law does not let us cap. That is clause 9, and it is worth reading in full.
- The Annex after clause 14 holds the rules specific to your Service. It is part of this AUP, and you accept it with the rest.
1. Key terms
| Term | Meaning |
|---|---|
| Annex | the annex to this AUP for your Service, printed after clause 14. It forms part of this AUP and is accepted with it. |
| AUP | this Acceptable Use Policy, as published at the address in the Service Schedule and changed from time to time under clause 12. |
| Business Day | a day other than a Saturday, Sunday or public holiday in England. |
| Content | anything you record, upload or submit in the Service. Content forms part of your Organisation's “Client Data” under the Head Agreement. |
| Head Agreement | the SaaS Terms and Conditions between us and your Organisation, together with the Service Schedule for your Service, under which the Service is supplied. Your Organisation is called the “Client” in those documents, and you are one of its “Users”. |
| Organisation | the organisation set up in the Service that has given you access to it, whether or not it has bought a Subscription. |
| Personnel | our officers, employees, contractors (including subcontractors) and agents. |
| Provider, we, us, our | ITSM Ltd, company number 17339600, trading under the brand the Annex names. |
| Purpose | the purpose of your Service, as stated in the Annex. |
| Records | your Organisation's Records as the Head Agreement defines them: the content your Organisation records in the Service and the documents the Service generates from it, as the Service Schedule describes. |
| Section (of the Annex) | one of the Annex's divisions, labelled A1 to A7. Every Service's annex to this AUP has the same seven, with the same subjects, so where this AUP refers to section A2, A3 and so on, it means the division with that number in the annex for your Service — B2, B3 and so on in an annex lettered B. |
| Service | the application you reach after signing in, the documentation we supply for it and the documents it generates, as identified in the Annex and the Service Schedule. The public pages of our website are governed by our Website Terms of Use instead. |
| Service Schedule | the Service Schedule for your Service. Each Service has its own. |
| User, you, your | you, as an individual who has been given access to the Service as a member of an Organisation, or who has signed in to it. |
2. Who this policy is for, and how you accept it
(a) This AUP applies to you if you have been given access to the Service as a member of an Organisation — whether you were invited by someone else, or you set the Organisation up and use the Service yourself. It also applies if you have signed in to the Service but do not yet belong to any Organisation.
(b) You accept this AUP by ticking one box. After you sign in, and before any page of your Organisation's area of the Service opens, the Service shows you each document you have not yet accepted in its current version, and you tick one box to accept them all. It asks again whenever we publish a new version. If you are an owner of any Organisation, or you do not yet belong to one, you are also shown the SaaS Terms and Conditions and the Service Schedule, which make up the Head Agreement; a member who owns no Organisation is shown only this AUP. If you join through an invitation, you first see the invitation — the organisation's name, your role and what you will be able to see — and you join by pressing its button. You are asked to accept straight afterwards, before any of the Organisation's pages open.
(c) If you are ever given access without being asked to tick that box, you agree to this AUP by continuing to access the Service after we have made it available to you and told you it applies. We will not treat you as having accepted it before then, and we will not rely on clause 9 to limit what we owe you unless you have had a fair opportunity to read it first.
(d) When you tick the box, we record it. The record holds your user ID, the slug and version of each document you accepted, the date and time, and a random reference for the record itself — and nothing else. There is one record for each document and version you accept, and it is tied to you, not to any Organisation: if you have already accepted the current version of a document, you are not asked for it again when you join another Organisation. It is our record that you agreed to those versions. The owners of your Organisation cannot see it. It cannot be edited or deleted from inside the Service, and it is deleted when your account is deleted. On request we will tell you which version you accepted and send you its text. Our Privacy Policy explains how we handle information about you.
(e) This AUP starts when you accept it under paragraph (b), or when paragraph (c) applies, and continues until your access ends or it is terminated under clause 10.
(f) If you do not accept this AUP you must not access, use or otherwise view the Service. If you joined an Organisation through an invitation before you were asked, leave it or, where the Service offers no way to leave (section A6 says whether yours does), ask one of its owners to remove you. Until you have left or been removed you remain a member, and your details stay visible to its other members as section A6 describes.
(g) The Service is not intended for use by anyone under 18 years old. Please do not access the Service if you are under 18, or if you have previously been suspended or prohibited from using it.
3. How this policy fits with our other terms
(a) The Service is supplied to your Organisation under the Head Agreement. You are not a party to the Head Agreement and this AUP does not make you one, and we will not rely on the Head Agreement to hold you to a stricter obligation than this AUP sets out. It gives you no right to the Service other than the licence in clause 4.
(b) This AUP is the acceptable use policy referred to in the Head Agreement. It applies to every User of each Service for which we publish it, together with that Service's Annex. It is a standalone document so that you can read and agree to the rules that bind you personally without having to read the Head Agreement.
(c) If anything in this AUP is inconsistent with the Head Agreement, then as between you and us this AUP prevails, and as between us and your Organisation the Head Agreement prevails.
(d) Our Website Terms of Use govern your use of the public pages of our website; you are not asked to tick them. Our Privacy Policy, which explains what we do with personal data, and our Cookie Policy, which explains the cookies the Service sets, are notices we give you: there is nothing to accept in either. The addresses of all of these documents are listed in the Service Schedule.
(e) Your Organisation may have its own rules about how you use the Service — what belongs in it, what must not go into it, and who may see it. Those rules are between you and your Organisation. Where they are stricter than this AUP, follow them.
4. Your licence to use the Service
4.1 What you may do
(a) We grant you a revocable, worldwide, royalty-free, non-exclusive and non-transferable licence to use the Service for the Purpose, for as long as your Organisation gives you access to it.
(b) You must only use the Service: (i) within the limits of the Purpose; (ii) in a manner that complies with clause 5; and (iii) in compliance with any other restriction notified to you in writing by your Organisation or by us from time to time.
4.2 What the licence is not
(a) The licence is personal to you. You acquire no ownership of the Service or any part of it, and all intellectual property rights in the Service remain with us or our licensors.
(b) As between you and us, Content belongs to your Organisation, not to you. Recording something in the Service does not make it your personal record, and clause 11 explains what happens to it when your access ends.
(c) Documents the Service generates for your Organisation are your Organisation's to use. What it may do with them, and the rule against removing the notices they carry, are set out in section A3 of the Annex.
(d) If you give us feedback, comments or suggestions about the Service, we may use, incorporate and exploit that feedback for any purpose without restriction or compensation. Giving us feedback grants you no right, title or interest in the Service.
5. What you must not do
You must not do any of the following, unless your Organisation or we have approved it in writing beforehand — and we may give or withhold approval in our absolute discretion:
- (a) record special category personal data — information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data used to identify someone, or data concerning health, sex life or sexual orientation — or personal data relating to criminal convictions and offences (including alleged offences) or related security measures, except where your Organisation has told you to record it, and then only to the extent its purposes require;
- (b) upload a photograph or recording of an identifiable person who has not been told it is being taken and kept, unless your Organisation has satisfied itself that it may do so;
- (c) upload any harmful, discriminatory, defamatory, maliciously false, offensive, explicit, inappropriate, illicit, illegal, pornographic, sexist, homophobic or racist material to the Service;
- (d) upload any material that is owned or copyrighted by a third party without the rights to do so;
- (e) make copies of the Service, other than copies of documents the Service generates for your Organisation, which section A3 governs;
- (f) adapt, modify or tamper in any way with the Service — which does not stop you amending a document the Service has generated for your Organisation, on its behalf, under clause 4.2(c) and section A3;
- (g) remove or alter any copyright, trade mark, watermark or other notice on or forming part of the Service or of a document it generates;
- (h) create derivative works from, translate or reproduce the Service — which does not stop your Organisation adapting a document the Service has generated for it, under clause 4.2(c) and section A3;
- (i) publish or otherwise communicate the Service to the public, including by making it available online or sharing it with third parties — other than documents the Service generates for your Organisation, which it may publish and share as section A3 allows;
- (j) sell, loan, transfer, sub-license, hire or otherwise dispose of the Service to any third party — other than giving or sending a document the Service generates for your Organisation to anyone it chooses, as section A3 allows;
- (k) decompile or reverse engineer the Service or any part of it, or otherwise attempt to derive its source code;
- (l) attempt to circumvent any technological protection mechanism or other security feature of the Service, except where you do so in good faith, without accessing or altering anyone else's data, without degrading the service for others, and where you report what you find to us promptly and privately in accordance with clause 13;
- (m) permit any other person to use or access the Service through your account, or forward a sign-in link to anyone;
- (n) intimidate, harass, impersonate, stalk, threaten, bully or endanger any other user of the Service, or distribute unsolicited commercial content, junk mail, spam, bulk content or harassment in connection with the Service;
- (o) use the Service for any purpose other than the Purpose, including by using it in a manner that is illegal or fraudulent or that facilitates illegal or fraudulent activity; or
- (p) act unlawfully or maliciously towards us, towards another user, or towards your Organisation, or use the Service to do so.
5.1 How this works in practice
(a) Your Organisation's instructions are its approval. Your Organisation decides what belongs in its Records. Where it has asked you to record particular information in the organisation it has given you access to, we treat that instruction as its approval in writing for the purposes of clauses 5(a), 5(b) and 5(d), and you do not need to ask us as well. For clause 5(a), an instruction permits you to record the data; it does not give your Organisation a lawful basis for holding it, which remains your Organisation's responsibility under the Head Agreement.
(b) Using your role is not “permitting access”. Clause 5(m) is about giving other people your access. It does not stop you using the features your role gives you: if your role lets you invite people into your Organisation, inviting them is approved use, not a breach.
(c) When you are not sure, ask before you upload. What you record stays in your Organisation's Records, and some of it cannot be removed from inside the Service (clause 7(c)). If you are unsure whether something belongs there — an entry that names someone, a note about someone's health, a supplier's confidential document, a third party's copyright material, a photograph that shows people — ask your Organisation first, not afterwards. Section A4 says what this means for what you can upload to your Service.
(d) Honest criticism is not a breach. Nothing in clause 5(p) stops you giving an honest opinion about the Service, raising a concern with a regulator or other authority, reporting a security issue to us in good faith, or saying anything you are required by law to say.
6. Your account
(a) Your account is yours alone. Keep whatever you sign in with secret, and do not let anyone else sign in as you. Section A2 says how you sign in to your Service.
(b) Where your Service signs you in by a link sent to your email address, your account is exactly as secure as the mailbox it signs in from. Keep that mailbox secure, do not forward a sign-in link to anyone, and do not let anyone else open one that was sent to you. Sign out when you have finished on a device other people use; section A2 says what signing out does in your Service.
(c) Where the Service Schedule says a role requires two-step verification, you must set it up and keep it on. Section A2 says whether any role in your Service does.
(d) You must immediately notify us at support@itsm-ltd.com of any unauthorised use of your account or email address, or of any other breach or potential breach of the Service's security.
(e) You are responsible for what is done under your account, except to the extent it results from our breach of this AUP or our negligence.
7. What is recorded, and what your Organisation controls
This clause is here because you should know it before you accept, not because it grants anyone a new right.
(a) What is attributed to your account. Section A6 lists which actions the Service attributes to your account, which it does not, and who in your Organisation can see your details.
(b) What is not. Do not assume the Service keeps a log of who did what inside it unless section A6 says it does. If your Organisation needs to know who entered something, it should say so in the entry.
(c) What cannot be changed afterwards. Some records cannot be edited or deleted one at a time from inside the Service — not by you, not by an owner of your Organisation, and not through the application by anyone. Section A7 and section 9 of the Service Schedule list them, and what does remove them. We remove or amend one by hand only on your Organisation's instruction or where the law requires us to. Write them as you would write a minute: assume they are permanent.
(d) People in your Organisation whose role and access permit it can read your Organisation's Records, and can produce the reports and exports the Service offers from them. Those outputs contain whatever the Records contain, including the names in them.
(e) Your Organisation controls your access. It can change your role, narrow what you can see to part of the Organisation, or remove your access at any time, and it does not need our agreement or yours to do so. Section A6 says whether the Service tells you when that happens.
(f) Where Content includes personal data, your Organisation is the controller of that data and we process it on your Organisation's instructions under clause 11 of the Head Agreement. Requests about personal data held in your Organisation's Records go to your Organisation.
(g) None of this affects the rights you have over your own personal data — the data we hold about you as a user of the Service. Our Privacy Policy explains those rights and how to exercise them.
8. What we do not promise
(a) We do not guarantee, and to the maximum extent permitted by law make no warranty, that: (i) the Service will be free from errors or defects; (ii) the Service will be accessible or available at all times; or (iii) any information provided through the Service is accurate or true.
(b) Nothing the Service produces is legal or professional advice, or a certification. Section A3 says what that means for your Service.
(c) You must take your own precautions to ensure that the way you access the Service does not expose you to the risk of hacking, malware, ransomware, viruses, malicious computer code or other forms of interference.
(d) Subject to clause 9(a), we do not accept responsibility for any unauthorised use of, or destruction, loss, damage or alteration to, your data or information, or to your computer systems, mobile phones or other electronic devices, arising in connection with your use of the Service.
9. Liability and indemnity
(a) Nothing in this AUP limits or excludes our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited or excluded. Nothing in this AUP affects any right you have that cannot lawfully be excluded, and any exclusion or limitation in this clause 9 applies only so far as the law allows.
(b) This clause is about what we owe YOU, personally. What we owe your Organisation is a separate question, governed by clause 13 of the Head Agreement, and the figure there is larger. If something goes wrong that affects your Organisation's data or its use of the Service, that is its claim under its agreement, not yours under this one.
(c) Subject to paragraph (a), and to the maximum extent permitted by applicable law, our total liability to you for loss or damage of any kind, however arising — whether in contract, tort (including negligence), statute, equity, indemnity or otherwise — arising from or relating in any way to the Service or this AUP is limited to £100 in aggregate. This includes the transmission of any computer virus.
(d) Subject to paragraph (a), and to the maximum extent permitted by applicable law, neither we nor our Personnel will be liable for any incidental, special or consequential loss or damage, or for damages for loss of data, business or business opportunity, goodwill, anticipated savings, profits or revenue, arising under or in connection with the Service, this AUP or their subject matter.
(e) Subject to paragraph (a), all express or implied representations and warranties given by us or our Personnel are excluded to the maximum extent permitted by applicable law. Where any law implies a condition, warranty or guarantee into this AUP which may not lawfully be excluded, then to the maximum extent permitted by applicable law our (and our Personnel's) liability for breach of it is, at our option, limited to: (i) in the case of goods, their replacement, the supply of equivalent goods, or their repair; and (ii) in the case of services, the supply of the services again, or the payment of the cost of having them supplied again.
(f) You indemnify us and our Personnel in respect of liability for loss, damage or injury suffered by any person arising from your breach of this AUP or your unlawful use of the Service, except to the extent it is caused by our breach of this AUP or our negligence.
(g) To the extent that any applicable law restricts how far liability may be excluded or limited under this AUP — including sections 2, 3 and 11 of the Unfair Contract Terms Act 1977, sections 62, 65 and 68 of the Consumer Rights Act 2015, and their equivalents in any other jurisdiction — the exclusions and limitations in this clause 9 are limited accordingly, and the remainder continues in full force and effect.
10. If you breach this policy
(a) We or your Organisation (or both) may end your access to the Service and terminate this AUP — as an individual User, and without terminating the Head Agreement:
- (i) by notice to you, if you are in breach of any term of this AUP and have failed to remedy the breach within 10 Business Days after being given notice of it; or
- (ii) immediately, where the breach is a breach of clause 5, is not capable of remedy, or is one your Organisation asks us to act on immediately — including where we or your Organisation reasonably suspect that you are about to commit such a breach. Paragraph (i) governs every other breach.
(b) Where we consider it the more proportionate response, we may suspend your access instead of terminating it. Suspending your access is not a waiver of our right to terminate under paragraph (a).
(c) If the Head Agreement expires or is terminated, your licence to the Service ends with it and this AUP terminates automatically — except that, for as long as clauses 15.3(a) and 15.4(a) of the Head Agreement let your Organisation keep reading, downloading and exporting its Records, the Users it authorises may keep doing so, and this AUP continues to apply to that use.
11. When your access ends
(a) On expiry or termination of this AUP you must: (i) immediately stop using the Service; and (ii) return or destroy any documentation we supplied to you, and remove the Service from any materials in your care, custody or control that feature it. Paragraph (ii) does not apply to documents the Service generated for your Organisation, whether downloaded or printed: they are your Organisation's to keep and rely on (clause 4.2(c)).
(b) Content stays with your Organisation. We do not give you a personal copy of it, and we are not liable to you or to any other person for any loss of data or information when your access ends. If you need a copy of something you recorded, ask your Organisation before your access ends — afterwards we will act only on your Organisation's instructions.
(c) Removing you from an Organisation deletes only your membership of it and the access settings that went with it. The records described in clause 7, including what section A6 says is attributed to your account, are not deleted when your access ends. They are your Organisation's records.
(d) Expiry or termination does not affect any right that has accrued to either of us up to that date, any obligation already performed, or any obligation which expressly or by implication survives termination. Clauses 4.2, 8, 9, 11 and 14 survive termination of this AUP.
(e) Where the Service does not offer a way to leave an Organisation, or to delete your own account — section A6 says whether yours does — ask one of the Organisation's owners to remove you, or write to us at [support@itsm-ltd.com](mailto:support@itsm-ltd.com) to have your account deleted. Deleting your account removes your memberships and the access settings that went with them, your acceptance records and any invitations you issued. It does not delete any Organisation or its records; section A6 says what happens to the links to your account.
12. Changes to this policy
(a) We may change this AUP, including its Annex. The current version is always the one published at the address in the Service Schedule, which shows its version number and the date it came into force.
(b) We give you at least 30 days' notice of any change to this AUP, by email to every person with access to the Service, in the same way as clause 19 of the Head Agreement. Whenever we publish a new version, the Service asks you to accept it before any page of your Organisation's area opens. If you do not agree to a change, do not accept it: stop using the Service and tell your Organisation before the change takes effect.
(c) The record described in clause 2(d) cites the version you accepted. Only the current version is published, so on request we will tell you which version you accepted and send you its text.
13. Reporting misuse and contacting us
(a) If you become aware of misuse of the Service by any person, of any security problem, or of Content that breaches clause 5, please tell us immediately at support@itsm-ltd.com.
(b) If your report concerns Content in your Organisation's Records, tell your Organisation as well. Those Records are your Organisation's, and we will not change or remove anything in them except on your Organisation's instructions or where the law requires us to act. If a photograph should never have been uploaded, tell us, and we will pass it to your Organisation promptly and, on its instruction, remove it by hand.
(c) If you think we have applied this AUP wrongly to you — for example by suspending or ending your access when you do not believe you were in breach — write to us at support@itsm-ltd.com and say so. We will look at it again and reply.
(d) For anything else about this AUP, write to us at support@itsm-ltd.com, or at ITSM Ltd, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.
14. General
14.1 Governing law and jurisdiction
This AUP is governed by the law of England and Wales. Each party irrevocably submits to the exclusive jurisdiction of the courts of England and Wales, and courts of appeal from them, in respect of any proceedings arising out of or in connection with this AUP, and irrevocably waives any objection to venue on the basis of inconvenient forum.
14.2 Third party rights
This AUP does not give rise to any rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms, except that your Organisation may enforce clauses 5 and 10 and the Annex against you. That exception exists because clause 5 and the Annex set the rules your Organisation relies on, and clause 10 gives your Organisation the power to end your access; without it, that power would be unenforceable by the party the clause names.
14.3 Waiver
No party may rely on the words or conduct of any other party as a waiver of any right unless the waiver is in writing and signed by the party granting it.
14.4 Severance
Any term of this AUP which is wholly or partially void or unenforceable is severed to the extent that it is void or unenforceable. The validity and enforceability of the remainder is not affected.
14.5 Assignment
You cannot assign, novate or otherwise transfer your rights or obligations under this AUP without our prior written consent.
14.6 Further acts and documents
Each party must promptly do all further acts and execute and deliver all further documents required by law, or reasonably requested by the other party, to give effect to this AUP.
14.7 Entire agreement
This AUP, including its Annex, embodies the entire agreement between you and us in relation to your personal use of the Service, subject to clause 3(c), which governs how this AUP relates to the Head Agreement; as between us and your Organisation, clause 2(c) of the Head Agreement applies. It supersedes any prior negotiation, conduct, arrangement, understanding or agreement, express or implied, in relation to that subject matter. It does not affect the Head Agreement between us and your Organisation.
Annex A — Martyn's Law Evidence Kit
This Annex applies where your Service is the Martyn's Law Evidence Kit. It forms part of this AUP, you accept it with the rest, and it changes only as clause 12 allows. Its divisions are called sections; a clause number means a clause of the body of this AUP above.
A1. The Service and its Purpose
The Service is the Martyn's Law Evidence Kit, which we supply under that brand. Its Service Schedule describes it. In this Annex a “premises” is what the Service's screens call a venue.
The Purpose is: to record and evidence a premises' public-protection procedures and the decisions, drills, refresher sessions, incident reviews and annual reviews that relate to them.
Recording drills, refresher sessions and reviews is good practice — not required at standard tier, and every tier the Service shows is a plain-English guide, not a legal determination (section 1(c) of the Service Schedule). The Service is not aimed at premises in the enhanced tier, which should seek professional advice.
A2. Signing in
- There is no password on this Service. You sign in by asking for a link, which is emailed to the address on your account. The link works once, expires, and is cancelled if you ask for a newer one.
- Signing out ends every session of your account, on every device, not only the one you are using. If you think someone else has used your account, sign out, then tell us under clause 6(d).
- No role in this Service requires two-step verification, and there is none for signing in to it, because there is no password for it to protect. That makes your mailbox the thing to protect: clause 6(b) applies, and turning on two-step verification for your mailbox, where your mail provider offers it, is the most useful thing you can do. Section 8(e) of the Service Schedule says the same from our side.
- Our support portal is a separate system. It has its own sign-in, by email address and password, and section 5 of the Service Schedule says who has an account on it. What this section says about passwords does not apply to it. Clause 5(m) does: do not share your portal password or let anyone else sign in with your portal account.
A3. Procedure packs and other documents the Service generates
- The documents the Service generates are its procedure packs and, where your Organisation has held the subscription that includes them, its evidence packs and estate roll-ups. Section 1(g) of the Service Schedule lists them.
- A procedure pack generated for your Organisation is your Organisation's to adopt, amend, print, publish and rely on — that is what it is for. Its evidence packs and roll-ups may be shown to whoever it chooses: its insurer, its trustees, a licensing officer or the regulator, for example. Clauses 5(e), 5(f), 5(h), 5(i) and 5(j) do not stop you doing any of that on your Organisation's behalf.
- The templates and the software that generate these documents remain ours.
- Every generated document carries the notice “Template for adoption by the responsible person — not certified advice.” Do not remove it, and do not present a generated document as advice, a certification, or a determination of any premises' tier.
- Nothing the Service produces is legal advice, certification, or a determination of any premises' tier under the Terrorism (Protection of Premises) Act 2025. Every tier the Service shows is a plain-English guide, not a legal determination. Responsibility for a premises' procedures rests with its responsible person.
A4. Photographs
- You can attach a photograph to an entry in a premises' drill log. A photograph is stored the moment you choose it, before the entry is saved. If you then choose a different photograph, or clear your choice, or the entry is not saved, the photograph you chose stays stored, is attached to no record, and cannot be removed from inside the Service. An entry can go unsaved because you leave the page, because saving fails, or because that premises is not covered by a live evidence log or estate subscription. The Service checks that only when you press save, not when you choose the photograph. So decide before you choose the file, not when you press save.
- Once stored, a photograph cannot be deleted from inside the Service by anyone (section A7).
- Photograph the room, not the people in it, or do not photograph at all: a drill log is perfectly good evidence without a photograph. If a photograph would show an identifiable person, clause 5(b) applies — and take particular care before photographing children.
- If a photograph should never have been uploaded, report it under clause 13(b).
A5. Key holders and other people's details
- The names and telephone numbers of a premises' key holders, and the names typed into records, are other people's personal data. Enter only people who know their details are being kept, and why.
- Once a procedure pack has been generated, the key-holder details in it stay in that version even after you edit them out of the premises profile, because a pack version cannot be changed. A new version reflects the profile as it is when you generate it. Section 9 of the Service Schedule says the same.
- Any free-text field — a decision's considerations, a drill, refresher or incident-review note, a review note, a premises' layout notes — can end up holding information about someone's health or about a suspected offence, such as a note that a named person needs help to evacuate. Clause 5(a) applies to what you write there: record it only where your Organisation has told you to, and only as much as its purposes need.
A6. What is attributed to your account, and who can see you
- Attributed to your account. The Service records which account created an Organisation, which account issued an invitation and which account accepted it, and which account generated each version of a procedure pack, each with the date and time. Your membership of an Organisation holds a copy of your email address. Your acceptance records under clause 2(d) are yours. When an Organisation first buys something, the buyer's email address becomes the billing email held by our payment processor, Stripe, unless a billing contact is named for an invoiced purchase; and a card purchase also passes Stripe the identifier of the account that started it. Our database provider's photograph store also records which account uploaded each photograph.
- Not attributed. Decision records, drill and refresher logs, incident reviews and annual review records carry the names your Organisation types into them — who decided, who took part, who reviewed — and not the identity of the account that entered them. So the Service is not a log of who did what inside it, and it should not be relied on as one.
- Premises profiles — name, type, capacity, address, layout notes, exits, assembly points, key-holder contacts and the SIA-notification details — can be changed or archived by anyone with access to that premises. A change overwrites what was there, and the Service does not record who made it. A procedure pack version keeps the premises' name, type, capacity, address, layout notes, exits, assembly points and key-holder contacts as they were when that version was generated. It does not keep the SIA-notification details, so an earlier pack version is not a record of when the Security Industry Authority was notified.
- Who can see you. Your email address, your role, what you can see and the date you joined are shown to every other person in your Organisation, whatever part of it they are limited to.
- Changes to your access are notified by email. When an owner saves a change to your role or access, the Service emails you your role and what you can now see, and when an owner removes you from the Organisation it emails you to say so (clause 7(e)). The email does not say which owner made the change; ask one of the Organisation's owners if you need to know. Section 6(f) of the Service Schedule says more.
- Leaving, and deleting your account. The Service offers no way to leave an Organisation or to delete your own account: an owner removes you, and we delete an account when you write to us (clause 11(e)). An Organisation's last owner cannot be removed through the Service, so another owner has to be appointed first.
- If your account is deleted, the links to it in the Service's own records — which account created an Organisation, accepted an invitation or generated a pack version — are cleared, and clause 11(e) says what is deleted with it. Deleting it does not clear our database provider's record of which account uploaded each photograph, the account identifier Stripe was given with a card purchase, or your email address where it is the billing email Stripe holds, and it does not by itself close an account in our support portal (section 5 of the Service Schedule). An invitation that was addressed to your email address is not deleted either, unless the account that sent it has itself been deleted: it keeps that address, and the date it was accepted if it was, and the owners of the Organisation that sent it can still read it through the database, although the Service's screens list only invitations still waiting to be accepted.
A7. Records that cannot be changed, and what does remove them
- For clause 7(c), these cannot be edited or deleted one at a time from inside the Service: decision records; drill, refresher and incident-review logs, and the photographs stored for them (including one stored but never attached, section A4); annual review records; each version of a procedure pack; and your acceptance records. Section 9 of the Service Schedule is the full list.
- One thing does remove them, and it is not one at a time: deleting a premises deletes everything recorded against it in one act, including its records and its pack versions. An owner, or a member with access to the whole organisation, can do that through the database; the Service has no button for it, and it is not reversible. It does not remove the premises' photographs, which stay stored. Section 9 of the Service Schedule lists what else it affects.
- Apart from that, we remove or amend a record by hand only on your Organisation's instruction or where the law requires us to, and we write down that we did it and confirm it to your Organisation in writing.