This policy forms part of the Terms of Service. It applies to everyone who uses Conformiq, including people your organisation invites and anyone you share a project with.
The point of it is simple: Conformiq holds compliance records that people rely on to decide whether a machine is safe to use. Don't do anything that undermines that.
You must not
Misuse the records
- Enter dates, report numbers or examiner details you know to be wrong.
- Record a thorough examination or inspection that did not happen.
- Upload a certificate you know to be forged, altered, or issued for a different machine.
- Present a Conformiq record as if it were a report of thorough examination.
- Sign a weekly check as someone else, or on a machine you did not look at.
Misuse other people's data
- Upload personal data you have no lawful basis to hold.
- Upload special category data — health records, biometric data — into free-text or photograph fields.
- Use contact details in the system to send marketing.
- Share sign-in credentials, or keep access for someone who has left.
Attack or abuse the service
- Probe, scan or test the security of the service without our written permission.
- Attempt to reach another organisation's data.
- Scrape the public QR portal, or automate requests against it.
- Reverse-engineer, decompile, or copy the service to build a competing product.
- Introduce malware, or upload files intended to cause harm.
- Place unreasonable load on the service, or resell access to it.
Break the law
- Use Conformiq for anything unlawful, fraudulent, harassing or defamatory.
- Infringe anyone's intellectual property.
Reporting a problem
If you find a security vulnerability, tell us at [TO CONFIRM — security contact email, e.g. security@conformiq.co.uk] before telling anyone else. We will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.
To report misuse of an account, email [TO CONFIRM — support email].
What happens if this is breached
Depending on how serious it is, we may contact the account admin, remove content, suspend a user or the whole account, or terminate the subscription. Where the law requires it we will report it. Suspension for a genuine security risk can happen without notice.
We will always tell an admin what we did and why.