Acceptable Use Policy
Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Security Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
1. Purpose
Define permitted and prohibited use of Touch2Sign information systems, devices, and data by all personnel. This policy protects Touch2Sign, its customers, and personal data processed through the eSignature and eWitness platform.
2. Scope
Applies to all Touch2Sign employees, contractors, interns, and third parties who:
- Use company-issued or personal devices to access Touch2Sign systems
- Have access to production AWS, GitHub, customer data, or internal tools
- Represent Touch2Sign in customer support or sales contexts
3. Permitted use
Touch2Sign systems may be used for:
- Performing authorised job duties related to the Touch2Sign platform
- Accessing customer data strictly as required for support, engineering, or compliance — with logging
- Development and testing in non-production environments using synthetic or anonymised data
- Communicating with customers, vendors, and regulators in a professional manner
- Reasonable personal use of company communication tools where it does not interfere with work or violate this policy (minimal, non-sensitive)
4. Prohibited use
The following are strictly prohibited:
4.1 Security and data
- Sharing passwords, MFA tokens, signing PINs, API keys, or break-glass credentials
- Bypassing access controls, authentication, or audit logging
- Accessing customer documents or personal data without a legitimate business need
- Exporting customer data to personal devices, personal cloud storage, or unapproved tools
- Installing unauthorised software on devices used to access production systems
- Connecting production credentials to public code repositories, chat logs, or AI tools without approval
4.2 Customer data and content
- Using customer-uploaded documents for any purpose other than providing the Touch2Sign service
- Retaining customer document copies outside approved systems after support case closure
- Disclosing customer document content to unauthorised third parties
4.3 Regulated and restricted data
- Uploading, processing, or storing US HIPAA Protected Health Information (PHI) on the Touch2Sign platform — see HIPAA Scope Policy
- Processing data subject to sanctions or export control restrictions without legal approval
- Using the platform to store or transmit illegal content, malware, or material that violates applicable law
4.4 Conduct
- Harassment, discrimination, or offensive communications via company systems
- Impersonating customers, signers, or colleagues
- Sending unsolicited bulk email (spam) from Touch2Sign domains or infrastructure
- Cryptocurrency mining, torrenting, or other resource abuse on company or production infrastructure
- Attempting to probe, scan, or test vulnerabilities on production without authorisation from the Security Lead
5. Customer data handling
| Requirement |
Detail |
Minimum necessary |
Access only the data required to resolve the ticket or task |
| Tenant isolation |
Never cross-reference or compare data across customer organisations without authorisation |
| Support access |
Document reason in ticket system; use admin audit trail |
| Test data |
Use synthetic data in dev/staging — never copy production DB to local machines without encryption and approval |
| AI tools |
Do not paste customer PII or document content into external AI services unless approved (see vendor policy for Anthropic/Bedrock) |
6. PHI and health data
Touch2Sign is not a HIPAA-covered entity or business associate by default. Personnel must:
- Not upload PHI to the platform
- Not advise customers that Touch2Sign is HIPAA-compliant unless a separate BAA is executed
- Escalate any customer request involving health records to Legal and the DPO
7. Sanctions and export compliance
Personnel must comply with applicable sanctions regimes (EU, UK, US OFAC) and export control laws. Prohibited activities include:
- Providing the Touch2Sign service to sanctioned individuals, entities, or countries where prohibited
- Processing payments or identity verification for prohibited parties
- Circumventing geo-restrictions or customer screening controls
Suspected sanctions issues must be reported to legal@touch2sign.com immediately.
8. Monitoring
Touch2Sign reserves the right to monitor use of company systems and networks to the extent permitted by law, including:
- Authentication and access logs
- Email and Slack on company accounts
- CloudTrail and application audit logs
Users should have no expectation of privacy when using Touch2Sign systems for activities that violate this policy.
9. Reporting violations
Report suspected violations to:
- Manager or Security Lead
- security@touch2sign.com
- Anonymous reporting channel: [define if applicable]
Good-faith reporting is protected; retaliation is prohibited.
10. Consequences
Violations may result in:
- Revocation of system access
- Disciplinary action up to termination
- Contract termination for contractors
- Civil or criminal liability where applicable
11. Related documents
- Information Security Policy
- HIPAA Scope Policy
- Remote Working Policy
- Data Classification Policy
12. Review
This policy is reviewed annually and acknowledged by all staff on joining and after material updates.
Approval
| Name |
Role |
Signature |
Date |
Robert |
CEO / Security Lead |
Electronic |
11 July 2026 |