# Acceptable Use Policy

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** Robert — Security Lead  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Define permitted and prohibited use of Touch2Sign information systems, devices, and data by all personnel. This policy protects Touch2Sign, its customers, and personal data processed through the eSignature and eWitness platform.

## 2. Scope

Applies to all Touch2Sign employees, contractors, interns, and third parties who:

- Use company-issued or personal devices to access Touch2Sign systems  
- Have access to production AWS, GitHub, customer data, or internal tools  
- Represent Touch2Sign in customer support or sales contexts  

## 3. Permitted use

Touch2Sign systems may be used for:

- Performing authorised job duties related to the Touch2Sign platform  
- Accessing customer data strictly as required for support, engineering, or compliance — with logging  
- Development and testing in non-production environments using synthetic or anonymised data  
- Communicating with customers, vendors, and regulators in a professional manner  
- Reasonable personal use of company communication tools where it does not interfere with work or violate this policy (minimal, non-sensitive)  

## 4. Prohibited use

The following are **strictly prohibited**:

### 4.1 Security and data

- Sharing passwords, MFA tokens, signing PINs, API keys, or break-glass credentials  
- Bypassing access controls, authentication, or audit logging  
- Accessing customer documents or personal data without a legitimate business need  
- Exporting customer data to personal devices, personal cloud storage, or unapproved tools  
- Installing unauthorised software on devices used to access production systems  
- Connecting production credentials to public code repositories, chat logs, or AI tools without approval  

### 4.2 Customer data and content

- Using customer-uploaded documents for any purpose other than providing the Touch2Sign service  
- Retaining customer document copies outside approved systems after support case closure  
- Disclosing customer document content to unauthorised third parties  

### 4.3 Regulated and restricted data

- **Uploading, processing, or storing US HIPAA Protected Health Information (PHI)** on the Touch2Sign platform — see **HIPAA Scope Policy**  
- Processing data subject to sanctions or export control restrictions without legal approval  
- Using the platform to store or transmit illegal content, malware, or material that violates applicable law  

### 4.4 Conduct

- Harassment, discrimination, or offensive communications via company systems  
- Impersonating customers, signers, or colleagues  
- Sending unsolicited bulk email (spam) from Touch2Sign domains or infrastructure  
- Cryptocurrency mining, torrenting, or other resource abuse on company or production infrastructure  
- Attempting to probe, scan, or test vulnerabilities on production without authorisation from the Security Lead  

## 5. Customer data handling

| Requirement | Detail |
|-------------|--------|
| Minimum necessary | Access only the data required to resolve the ticket or task |
| Tenant isolation | Never cross-reference or compare data across customer organisations without authorisation |
| Support access | Document reason in ticket system; use admin audit trail |
| Test data | Use synthetic data in dev/staging — never copy production DB to local machines without encryption and approval |
| AI tools | Do not paste customer PII or document content into external AI services unless approved (see vendor policy for Anthropic/Bedrock) |

## 6. PHI and health data

Touch2Sign is **not** a HIPAA-covered entity or business associate by default. Personnel must:

- Not upload PHI to the platform  
- Not advise customers that Touch2Sign is HIPAA-compliant unless a separate BAA is executed  
- Escalate any customer request involving health records to Legal and the DPO  

## 7. Sanctions and export compliance

Personnel must comply with applicable sanctions regimes (EU, UK, US OFAC) and export control laws. Prohibited activities include:

- Providing the Touch2Sign service to sanctioned individuals, entities, or countries where prohibited  
- Processing payments or identity verification for prohibited parties  
- Circumventing geo-restrictions or customer screening controls  

Suspected sanctions issues must be reported to legal@touch2sign.com immediately.

## 8. Monitoring

Touch2Sign reserves the right to monitor use of company systems and networks to the extent permitted by law, including:

- Authentication and access logs  
- Email and Slack on company accounts  
- CloudTrail and application audit logs  

Users should have no expectation of privacy when using Touch2Sign systems for activities that violate this policy.

## 9. Reporting violations

Report suspected violations to:

- Manager or Security Lead  
- security@touch2sign.com  
- Anonymous reporting channel: [define if applicable]  

Good-faith reporting is protected; retaliation is prohibited.

## 10. Consequences

Violations may result in:

- Revocation of system access  
- Disciplinary action up to termination  
- Contract termination for contractors  
- Civil or criminal liability where applicable  

## 11. Related documents

- Information Security Policy  
- HIPAA Scope Policy  
- Remote Working Policy  
- Data Classification Policy  

## 12. Review

This policy is reviewed **annually** and acknowledged by all staff on joining and after material updates.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO / Security Lead | Electronic | 11 July 2026 |
