Skip to content

Managed Cloud Acceptable Use Policy

The rules that keep your instance, our platform and every other customer's service safe, lawful and fast.

Last updated

This Acceptable Use Policy (the “AUP”) applies to everyone who uses a Stockovaa Managed Cloud service: the account owner, every member of staff you give an account to, and anyone acting on your behalf, including a consultant or developer you engage.

It forms part of the Managed Cloud Terms of Service. You are responsible for making sure the people who use your instance know what is in here.

This policy is about behaviour, not about how much you use the product. We are not looking for reasons to charge you more. We are protecting the service you and other customers pay for.

You may not use a Managed Cloud instance to:

  • Break any applicable law or regulation, or help someone else do so.
  • Sell prohibited, counterfeit, stolen or fraudulently obtained goods, or to launder money.
  • Store or distribute malware, run exploits, or scan, probe or attempt to breach the security of any system.
  • Attempt to reach another customer's instance, database, backups or files.
  • Circumvent licence limits, tamper with product identification, or reverse engineer the software except where a law expressly permits it and no contractual restriction may lawfully prevent it.
  • Send unsolicited bulk messages, or harvest contact data without a lawful basis.
  • Infringe someone else's intellectual property or privacy rights, or store defamatory, harassing or unlawful content.
  • Resell, sublicense or white-label the service to other businesses without a written reseller agreement with us.
  • Deliberately interfere with the platform, including denial-of-service activity, automated abuse or excessive polling.
  • Mine cryptocurrency, run unrelated workloads, or use the instance as general-purpose file storage or a media host.

You must also have a lawful basis for the personal data you put into the instance about your customers, staff and suppliers. As between us you are the controller of that data. See the Data Processing Agreement.

  • Give each person their own account. A shared login makes your audit trail worthless, and it is usually the first thing that goes wrong in a dispute with a member of staff.
  • Use strong, unique passwords, and enable multi-factor authentication where the product offers it.
  • Grant the least access each role needs, and remove accounts the same day somebody leaves.
  • Do not share credentials with us. Our team never needs your password and will never ask for it.
  • Tell us immediately at security@stockovaa.com if you suspect an account has been compromised.

You are responsible for activity carried out under your accounts, including by staff and by anyone you gave access to. We hold privileged administrative access ourselves, and how that is governed is described in clause 5 of the Privacy Policy.

We operate your instance, so anything unusual running inside it becomes our problem at three in the morning. This clause is how we keep that manageable without stopping you extending the system.

  • Do not install, upload or execute code on the instance yourself. Tell us what you want and we will assess and deploy it.
  • Custom code, plugins and integrations must be reviewed by us before they go on a production instance. We will not unreasonably refuse.
  • Anything that bypasses the application's permission model, writes directly to the database, or disables a security control will be refused.
  • You are responsible for licensing and for the security of third-party code you ask us to install.
  • Where custom code prevents an update from being applied cleanly, remediation is chargeable work unless a maintenance agreement covers it. See clause 5 of the Terms of Service.
  • We may remove or disable custom code without notice where it is causing an outage, a data-integrity problem or a security risk. We will tell you as soon as we have.

Bring us the integration early rather than late. A conversation at the design stage costs an hour. The same conversation after it is built can cost a rebuild.

Your instance sends receipts, invoices, statements and notifications. Sending reputation is shared infrastructure, so one customer sending badly damages delivery for everybody.

  • Send only transactional messages your recipients expect, such as receipts, order updates, invoices and statements.
  • Marketing campaigns must go through a dedicated marketing platform, not through the instance, unless we have agreed a separate sending arrangement with you.
  • Do not import a purchased or scraped contact list.
  • Honour unsubscribe requests, and keep your bounce and complaint rates low. We monitor both.
  • We may throttle or suspend outbound sending from an instance whose complaint or bounce rate threatens delivery for other customers, and we will tell you why.
  • Your instance is sized for the locations, staff and transaction volume recorded on your order form. Growing past it is good news, and it needs a resizing conversation rather than silence.
  • Automated and API access must respect the published rate limits. Ask us before running a bulk import or an unusual reporting job so we can plan for it.
  • Bulk exports, large report runs and data migrations should be scheduled outside your own trading hours where possible.
  • We may throttle activity that threatens the stability or performance of the platform, and we will contact you rather than let it degrade quietly.
  • Sustained use materially beyond the size on your order form may require a plan change. We will tell you what we are seeing and give you the numbers before we ask for anything.

We would rather resize your instance than throttle it. Tell us before the busy season, not during it.

  • Do not run penetration tests, vulnerability scans or load tests against your instance without written agreement from us first. We will usually say yes, and we need to know so we do not treat it as an attack.
  • Report a suspected vulnerability privately to security@stockovaa.com. Give us a reasonable opportunity to fix it before disclosing it publicly.
  • We will not pursue anyone who reports a vulnerability in good faith and does not exploit it, access data that is not theirs, or degrade the service.
  • Do not use another customer's data, or data you accessed accidentally, for any purpose. Tell us instead.

The remedy here is different from a subscription product, and the difference is in your favour. You own your licence. We cannot and do not take it away for a breach of this policy. What we can withdraw is the service.

StepWhen we use it
We contact youThe default. Most breaches are a misunderstanding or a member of staff who was not told.
We throttle or disable the specific activityWhere it is actively degrading service or creating risk, and waiting is not safe.
We suspend the serviceFor a serious breach, an active security threat, or repeated failure to fix something after notice.
We withdraw the managed serviceFor a severe or persistent breach. Clause 9 of the Terms of Service then applies in full: your licence survives and you get a free export of your data.
We report itWhere the law requires it, or where the activity is criminal.

We use reasonable judgment and, wherever it is safe to do so, we tell you first and give you a chance to put it right. Where we have to act immediately, we will explain what we did and why as soon as we can.

Suspected abuse of a Stockovaa service? Report it to abuse@stockovaa.com and we will investigate.

  • We may update this policy as new kinds of abuse appear. The date at the top of this page is a real revision date.
  • Material changes are notified to the account owner by email at least 30 days before they take effect.
  • A change made to address an urgent security threat may take effect immediately, and we will say so when we notify you.

Ask first. Nobody has ever been in trouble here for checking, and it is far cheaper than unwinding something after it is built.

Managed Cloud team
managed@stockovaa.com