Acceptable Use Policy

Using services we manage.

This policy sets out what is and is not acceptable on infrastructure, connectivity, cloud tenancies and AI services that Numata manages or provides under contract.

Scope
Managed services
Enforcement
Suspension on abuse
Reporting
Service desk
Review
Annual
Last reviewed
July 2026
On this page
  1. Prohibited activity
  2. Shared responsibility
  3. Enforcement
  4. Reporting abuse

Applies to Clients and their users on Numata managed services.

Prohibited activity

Users of services we manage must not:

  • Break the law of any jurisdiction in which the service is used, including data protection, export control and sanctions law.
  • Distribute malware, run unauthorised penetration tests, or attempt to bypass security controls we operate.
  • Send unsolicited bulk email or use managed platforms for phishing or fraud.
  • Store or transmit material that infringes copyright or is unlawful to hold.
  • Use managed AI services to generate unlawful content, to make decisions about people without human review, or to process personal information outside the agreed purpose.

Shared responsibility

Numata operates and monitors the controls documented in the service description. The client remains responsible for who it grants access to, for the content its users create, and for approving changes we recommend. Where the client declines a recommended control, we record the decision and the residual risk.

Enforcement

Where we detect abuse that puts a platform, other clients or a person at risk, we may isolate the affected account or system without prior notice and will notify the client contact immediately. We will always take the least disruptive action that contains the issue.

Reporting abuse

Suspected abuse, phishing or a security concern on a service we manage should be reported to the service desk. Security researchers can report vulnerabilities through the Trust Centre.

Questions about our policies or a procurement pack?

Contact us