Legal
Acceptable Use Policy
Last updated: 30 June 2026
This Acceptable Use Policy sets out what customers and users must not do when using SyftOS. It should be read alongside the SyftOS Terms of Service, Privacy Notice, Data Processing Agreement, AI Data Use Statement, Sub-processor List and Security and Trust Statement.
1. Purpose and status
This Acceptable Use Policy (“Policy”) explains the rules that apply when using SyftOS, including the SyftOS platform, digital workers, workflows, integrations, agents, departments, APIs, documentation, early access workspaces, pilot workspaces and related services.
SyftOS is operated by Techshift Digital Ltd, company number 15218025, registered office 1 The Briars, Waterberry Drive, Waterlooville, England, PO7 7YH.
This Policy is incorporated into and forms part of the SyftOS Terms of Service, is governed by the laws of England and Wales, and is intended to protect customers, users, third parties, connected systems, Techshift Digital Ltd and the integrity of the SyftOS platform. Capitalised and defined terms have the meanings given in the Terms of Service. If there is any conflict between this Policy and the Terms of Service, the stricter requirement applies unless agreed otherwise in writing.
2. Plain-English summary
This summary is provided for convenience only and does not limit or override the full terms set out in the sections below, which prevail in the event of any inconsistency.
| Rule | Meaning |
|---|---|
| Use SyftOS lawfully | Do not use SyftOS for illegal, harmful, abusive, deceptive, infringing or unauthorised activity. |
| Only connect data you are allowed to use | You must have the right and authority to connect systems, upload data, process documents and run workflows. |
| Do not bypass governance | Do not try to bypass approval gates, audit logs, permissions, usage limits or security controls. |
| Keep humans responsible | Do not use SyftOS to make final high-risk decisions without appropriate human review and legal/compliance controls. |
| Do not abuse AI or automation | Do not use SyftOS for spam, phishing, malware, credential theft, mass scraping or deceptive automation. |
| Respect limits and safety controls | Excessive usage, security abuse, platform disruption or misuse may lead to suspension or termination. |
3. Who this Policy applies to
This Policy applies to all customers, users, administrators, invited users, trial users, pilot users, design partners and anyone else who accesses or uses SyftOS.
SyftOS is intended for business and professional use only. It is not directed at, or intended for use by, individual consumers or anyone under the age of 18.
Customers are responsible for ensuring that their users, employees, contractors, agents and authorised representatives comply with this Policy.
4. Lawful and authorised use
You may only use SyftOS for lawful business purposes and in accordance with the SyftOS Terms of Service, applicable documentation, applicable laws, third-party service terms and any written agreement with Techshift Digital Ltd.
You must not use SyftOS to:
- violate any applicable law, regulation, court order, contractual obligation or third-party right;
- process, access, copy, disclose or use data without the necessary authority, permission or lawful basis;
- misrepresent your identity, organisation, authority, affiliation or intentions;
- assist, encourage, enable or conceal illegal activity;
- avoid legal, regulatory, employment, financial, tax, data protection or compliance obligations;
- breach applicable export-control or economic-sanctions laws, or make SyftOS available to sanctioned persons or in restricted territories.
5. Account, access and integration responsibilities
You are responsible for your SyftOS account, workspace configuration, users, permissions, connected integrations, API keys, credentials and approval settings.
You must:
- keep account credentials, API keys, tokens and integration secrets secure;
- only invite users who are authorised to access the relevant workspace and data;
- remove access promptly when users leave or no longer need access;
- only connect third-party services where you have authority to do so;
- ensure that workflows, digital workers and integrations are configured appropriately for your business and legal obligations;
- review outputs and proposed actions before relying on them or approving them.
6. Prohibited activities
You must not use SyftOS for any of the following activities.
| Category | Examples |
|---|---|
| Illegal or harmful activity | Using SyftOS to break the law, evade enforcement, enable fraud, facilitate unlawful conduct or cause harm to people, property, systems or organisations. |
| Spam, phishing or deception | Sending spam, phishing messages, scams, deceptive outreach, impersonation, social engineering, fake reviews, fake engagement or misleading automated communications. |
| Malware or cyber abuse | Creating, distributing, testing or assisting malware, ransomware, spyware, credential theft, botnets, exploit code, unauthorised scanning or unauthorised access. |
| Credential or secret misuse | Collecting, extracting, exposing, storing or misusing passwords, access tokens, API keys, private keys, session cookies or other secrets except through approved secure platform features. |
| Unauthorised scraping or data harvesting | Scraping, harvesting, extracting, enriching or combining data where you do not have the right to do so or where it breaches law, terms or reasonable expectations. |
| Harassment or abuse | Generating or sending abusive, threatening, harassing, hateful, discriminatory, sexually exploitative or otherwise harmful content. |
| Infringement | Using SyftOS to infringe intellectual property, breach confidentiality, copy protected materials unlawfully or misuse third-party content. |
| Platform abuse | Overloading, disrupting, reverse engineering, probing, bypassing, attacking, interfering with or attempting to gain unauthorised access to SyftOS or related systems. |
7. AI, automation and digital worker restrictions
SyftOS is a governed digital workforce platform. It is not intended to remove customer responsibility for oversight, review and decision-making.
You must not use SyftOS or its AI functionality to:
- make final legal, medical, financial, employment, insurance, housing, credit, education, immigration, criminal justice or similarly high-impact decisions without appropriate human review, professional advice and lawful controls;
- represent AI-generated content as human-created where that would be deceptive or unlawful;
- generate or approve automated actions that you have not reviewed where review is required by law, contract, policy or common sense;
- bypass human approval gates, trust controls, risk controls, audit records, permission boundaries or workflow restrictions;
- use digital workers to manipulate, deceive, pressure or unlawfully profile individuals;
- use SyftOS to create autonomous systems that act outside agreed permissions or intended platform controls.
You must also comply with the acceptable-use and usage policies of the third-party AI providers used by SyftOS. Customers remain responsible for deciding which workflows to enable, which systems to connect, which actions to approve and how outputs are used.
8. Sensitive, regulated and high-risk data
Unless agreed separately in writing with Techshift Digital Ltd, you must not intentionally use SyftOS to process highly sensitive, regulated or high-risk data where SyftOS has not been expressly configured or approved for that use case.
This may include:
- special category personal data, such as health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership or information about sex life or sexual orientation;
- criminal offence data or background-check information;
- children’s data;
- payment card data, full bank credentials, passwords, private keys or authentication secrets;
- regulated financial advice data, medical advice data, legal advice files or employment decision data;
- data subject to strict contractual, professional, regulatory or national security restrictions.
Where sensitive data is unavoidable, you must ensure you have a lawful basis, appropriate notices, internal approval, safeguards and any written agreement required with Techshift Digital Ltd.
9. Connected systems and third-party services
SyftOS may connect to third-party systems such as email, chat, project management, CRM, finance, storage, code hosting, support or productivity tools.
When using connected systems, you must:
- comply with the third-party provider’s terms, policies and usage limits;
- only grant permissions that are appropriate for the intended workflow;
- avoid connecting personal, private or unrelated systems unless authorised;
- ensure users understand what data may be read, written, proposed, approved or audited;
- review any proposed write action before approval unless you have intentionally configured permitted automation.
10. Code governance and developer workflows
Where SyftOS is used for code governance, repository review, pull request review, approval evidence or related developer workflows, you must not use it to:
- introduce, conceal, approve or distribute malicious code, backdoors, credential theft, unauthorised telemetry or harmful software;
- bypass repository permissions, branch protection, review requirements or security controls;
- misrepresent who reviewed or approved a code change;
- use SyftOS as a substitute for appropriate engineering, security, compliance or legal review where such review is required;
- connect repositories or codebases where you do not have authority to do so.
11. Security testing and vulnerability reporting
You must not perform penetration testing, vulnerability scanning, load testing, scraping, automated probing, denial-of-service testing or similar security testing against SyftOS without prior written approval from Techshift Digital Ltd.
If you discover a vulnerability, suspected security issue, exposed secret, data incident or platform misuse, please report it promptly to security@syftos.com (interim fallback: mathew@techshift.digital). The prohibition above continues to apply; however, if you nonetheless discover a vulnerability and, acting in good faith, you (a) report it promptly to that address, (b) give us a reasonable opportunity to investigate and respond before any disclosure, and (c) do not access, modify or delete data that is not yours or degrade the service, then we will not bring or support a civil claim against you in respect of that good-faith research. This is not authorisation or consent to test, access or scan SyftOS, and it does not affect any criminal liability or the rights of third parties.
12. Usage limits, fair use and cost abuse
SyftOS may apply usage limits, rate limits, token limits, run limits, action limits, storage limits, integration limits, approval limits, fair use limits and other technical or commercial controls.
You must not attempt to avoid, manipulate or exceed these limits, including by creating duplicate accounts, splitting usage across workspaces, automating excessive requests, repeatedly retrying failed jobs, generating unnecessary large outputs or running workflows in a way designed to consume disproportionate resources.
Techshift Digital Ltd may throttle, pause, limit, suspend or require a revised commercial agreement where usage creates security, operational, cost, performance or reliability concerns.
13. Early access, pilots and trials
SyftOS may be provided through early access, approved pilot workspaces, design partner access, evaluation access or trial access at Techshift Digital Ltd’s discretion.
During early access, pilots or trials, Techshift Digital Ltd may impose additional restrictions, including time limits, usage limits, feature restrictions, workspace restrictions, integration restrictions, data limits, approval requirements and additional review requirements.
There is no public self-serve free trial at launch. Any trial, pilot or evaluation access may be modified, suspended or withdrawn if this Policy is breached or if usage creates operational, security, commercial or legal concerns.
14. Enforcement
If Techshift Digital Ltd reasonably believes that this Policy has been breached, or that use of SyftOS creates risk to customers, third parties, connected systems, SyftOS or Techshift Digital Ltd, it may take appropriate action.
This may include:
- warning the customer or user;
- requiring changes to configuration, workflows, integrations or usage;
- throttling, rate limiting or disabling particular workflows, agents, actions or integrations;
- suspending or restricting access to a workspace, account or feature;
- removing or disabling content where necessary;
- terminating access in accordance with the SyftOS Terms of Service;
- notifying affected customers, providers, regulators or law enforcement where required or appropriate.
Action taken under this section is in addition to our rights under the Terms of Service and, except as required by law, is taken without liability to you and without refund. Where reasonably possible we will give notice and an opportunity to remedy before suspension, except where immediate action is necessary for security, legal, abuse, non-payment or urgent operational reasons.
15. Reporting misuse
Misuse, security issues, abuse, suspected breaches of this Policy or concerns about SyftOS use can be reported to Techshift Digital Ltd at: support@syftos.com (general), legal@syftos.com (legal notices), privacy@syftos.com (privacy matters) or security@syftos.com (security reports). During our early access period, mathew@techshift.digital is the interim fallback for any of these.
16. Changes to this Policy
Techshift Digital Ltd may update this Acceptable Use Policy from time to time, including to reflect product changes, legal requirements, security requirements, AI provider requirements, customer feedback, new integrations or changes in platform risk.
Where changes are material, Techshift Digital Ltd will take reasonable steps to notify affected customers or publish the updated Policy through the SyftOS website, documentation, application or other appropriate channel. Continued use of SyftOS after an update takes effect means you accept the updated Policy.