eddy.docs
ActiveOwner: DanUpdated: 11 Jun 2026

Acceptable Use Policy

Eddy Works Acceptable Use Policy — counter-draft applying the redraft guide (Kindrik draft set, 27 May 2026). British spelling per legal-pack register.

COUNTER-DRAFT — Eddy Works, 11 June 2026. Counter-draft to the Kindrik Partners draft of 27 May 2026. British spelling. Published here for review — not yet approved by counsel and not yet in force.

What this means

The plain-English summaries in each section ("What this means") are for ease of reading only. They are not legally binding. The full clauses above each summary govern.

This Acceptable Use Policy ("AUP") governs your use of the Eddy platform ("Service"). It forms part of the Terms of Use. Capitalised terms not defined here have the meanings given in the Definitions.

By using the Service, you agree to comply with this AUP.

1. Technical prohibitions

You must not use the Service to:

1.1

Attack or compromise systems:

  1. transmit malware, ransomware, trojans, or other malicious code;
  2. conduct port scanning, vulnerability scanning, or network probing of the Service or third-party systems;
  3. perform denial-of-service or distributed denial-of-service attacks;
  4. attempt to gain unauthorised access to any part of the Service, another user's account, or any third-party system;
  5. introduce code intended to interfere with, disrupt, or destroy any software, hardware, or data.
1.2

Circumvent controls:

  1. bypass, disable, or interfere with any security or access-control mechanism in the Service;
  2. attempt to extract, scrape, or harvest data from the Service in bulk except via an authorised API or export function;
  3. use automated tools to access the Service in a manner that exceeds reasonable use or places unreasonable load on infrastructure;
  4. frame or embed any part of the Service or Website in another application or website without our prior written consent.
1.3

Infringe intellectual property:

  1. upload, transmit, or make available content that infringes any third party's intellectual property rights;
  2. publish or distribute another Organisation's Private Template or Partner Template without authorisation.

What this means

Do not hack, overload, or scrape the platform, and do not upload content you do not have the right to share. Do not try to break into other accounts or bypass security controls.

2. Prohibited content and data

You must not use the Service to store, process, or transmit:

2.1

Tier 1 — Prohibited without a separate written agreement:

  1. payment card data requiring PCI DSS-certified infrastructure (e.g. raw primary account numbers);
  2. protected health information governed by HIPAA or equivalent health-data legislation, unless Eddy Works has separately agreed to provide HIPAA-compliant infrastructure;
  3. biometric data used for the purpose of unique identification of a natural person, where specialist infrastructure is required;
  4. genetic data for health or identification purposes where specialist infrastructure is required;
  5. children's clinical or welfare data relating to individuals under 13, without a separate safeguarding agreement;
  6. life-critical automated decisions — do not use the Service for automated decisions that directly affect a person's physical safety, access to emergency services, or other life-critical outcomes, without human review and appropriate safeguards;
  7. any data category that, by applicable law, requires infrastructure-grade security controls that Eddy Works has not expressly agreed to provide.
2.2

Tier 2 — Permitted with safeguards (Customer is responsible):

The following data categories may be processed via Eddy where you have a lawful basis, have taken appropriate safeguards, and have confirmed your obligations as data controller:

  • workplace health and safety incident data;
  • equality, diversity, and inclusion survey data;
  • trauma-informed training records;
  • employment-related process data (performance reviews, disciplinary records);
  • educational records (grades, conduct, welfare) where the educational institution is the data controller;
  • sector-specific compliance data for which the Customer (not Eddy Works) holds the relevant regulatory permission.

Eddy Works does not certify that use in any specific regulated sector is lawful. You remain responsible for your own compliance obligations.

2.3

Always prohibited:

  1. content that is illegal under applicable law;
  2. child sexual abuse material (CSAM) or any content that sexualises minors;
  3. content that constitutes unlawful harassment, defamation, or discrimination;
  4. content designed to facilitate physical violence against a specific individual or group.

What this means

Some categories of sensitive data — such as payment card numbers, HIPAA health information, and biometric identification data — cannot be processed through Eddy without a separate written agreement. Other sensitive categories (HR records, safeguarding data, compliance data) are permitted if you have a lawful basis and accept responsibility. Illegal content and anything that sexualises or endangers people is always prohibited.

3. Eddy-specific human-process prohibitions

Because the Service is designed for structured, multi-person processes, the following process-design and use patterns are prohibited regardless of content:

3.1

Surveillance and coercion:

  1. designing a Map for the covert monitoring of employees or individuals beyond what is lawful and disclosed;
  2. using the Service to coerce, intimidate, or unduly pressure Participants — for example, structuring a Map so that a participant cannot decline or exit without consequences not disclosed at the point of invitation;
  3. using the Service to conduct surveillance of Participants' behaviour beyond what is necessary for the stated Process purpose.
3.2

Misleading invitations:

  1. inviting Participants to a Session under a false or misleading description of the Process purpose — for example, framing a data-collection Process as something unrelated;
  2. impersonating another Organisation or person in a start link, invitation, or Session screen;
  3. sending electronic transmissions through the Service that do not correctly identify the sender.
3.3

Discriminatory Maps:

  1. designing Maps with screening criteria, routing logic, or outcomes that unlawfully discriminate on the basis of a protected characteristic (race, gender, age, disability, religion, sexual orientation, or other characteristics protected under applicable law).
3.4

Template publishing:

  1. publishing another Organisation's Private Template or Partner Template to the public commons without authorisation;
  2. publishing a Template that embeds confidential information, personal data, or proprietary content belonging to a third party;
  3. publishing a Template that is designed to facilitate a prohibited activity listed in this AUP.
3.5

Governance bypass:

  1. using the Service to circumvent or obscure a legally required governance or approval process that the Map was designed to replace or represent.

What this means

Because Eddy powers real-world processes with real people, some misuse patterns are specific to how the platform works. You must not design processes that covertly monitor or coerce participants, invite people under false pretences, build discriminatory routing logic, publish another organisation's private templates, or use Eddy to disguise or bypass a required governance step.

4. Age

The Service is available to users aged 13 and over. Users under 18 must have guardian or school consent. You must not invite or facilitate access for individuals under 13. Where a Process is designed for under-18 participants, the Customer is responsible for obtaining appropriate consent and complying with applicable children's data-protection requirements.

What this means

Eddy is for users aged 13 and over. Under-18s need parental or school consent. If your process involves people under 18, you are responsible for obtaining the appropriate consent and meeting children's data-protection requirements.

5. Compliance with laws and sanctions

You must use the Service in accordance with all applicable laws and regulations, including data protection, employment, anti-discrimination, export control, and sector-specific regulations applicable to your use case.

You must not knowingly permit access to the Service by individuals who are subject to, or who are located in countries subject to, sanctions imposed by the European Union, United Nations, New Zealand, Australia, or the United Kingdom.

What this means

Your use of the Service must comply with all laws that apply to you — including data protection, employment, anti-discrimination, and any sector-specific regulations relevant to your processes. You must not give access to individuals or entities subject to applicable sanctions.

6. Reporting and enforcement

6.1

If you become aware of a violation of this AUP, please report it to abuse@eddy.works.

6.2

We reserve the right to investigate suspected violations and, where appropriate, to:

  1. remove or disable access to content that violates this AUP;
  2. suspend or terminate access for the violating account or Organisation;
  3. notify relevant authorities.
6.3

We will exercise these rights for defined purposes: support (at Customer request), security incidents, abuse reports, legal obligations, and integrity of the Service. We will act proportionately and will notify the Customer where it is lawful and safe to do so.

6.4

We will not use AUP enforcement rights as a pretext for accessing Customer Content for commercial purposes.

6.5

If your access is suspended or terminated for an AUP violation, you may appeal to legal@eddy.works within 14 days. We will review and respond within a reasonable time.

What this means

If you see something that breaches this AUP, please report it. We can investigate, remove content, or suspend access where needed — but only for defined operational reasons, proportionately, and not as a pretext for commercial purposes. If your access is suspended, you have 14 days to appeal.

7. Changes to this AUP

We may update this AUP from time to time. Material changes will be notified in accordance with clause 3 of the Terms of Use.

What this means

If we materially update this policy, we will notify you in line with the notice process in the Terms of Use (at least 30 days for material changes).

On this page