Acceptable Use Policy
/acceptable-use·Effective from: [go-live date]·Version 0.1 (draft)
This policy tells you what you may and may not do when using the PTC CRM. It sits alongside the Terms of Use — you agree to both when you log in. It applies whether you are on the office network, working from home, or travelling.
3.1 You must
- Use the System only for legitimate work relating to Premier Trust Corporation Ltd and Acer Prime Law engagements.
- Keep your password confidential and change it if you suspect it has been seen by anyone else.
- Log out of shared or public devices at the end of every session.
- Report a suspected security incident (phishing email, lost laptop, unexpected pop-up, colleague acting oddly on the System) to Alan McAloon and privacy@acerprimelaw.co.uk within 24 hours.
- Follow the “clear desk” rule — do not leave party dossiers, KYC documents or ledger printouts unattended.
- Verify a client’s bank details out-of-band (voice call to a known number) before making a payment based on data entered into the System.
3.2 You must not
- Log in through anyone else’s account or let anyone else log in through yours.
- Copy or export client data to personal email accounts, personal cloud storage, USB sticks, or messaging apps.
- Use the System to store personal, family or non-firm records.
- Upload malicious files or attempt to test the System’s security without prior written permission from Alan McAloon.
- Attempt to bypass access controls, tenancy isolation, role checks or audit logging — including by using developer tools or the Supabase console directly.
- Reverse-engineer, decompile or rehost any part of the System.
- Impersonate another person or misuse the “party” record to store hate-speech, defamation, or content that would embarrass the firm if made public.
- Use the System to process personal data of individuals who are not connected to a matter, trust, or engagement of the firm.
3.3 Voice recording and transcription
The System includes a voice-note feature that sends the audio to Deepgram for transcription. Before you start recording a client meeting, you must:
- Tell every person in the room that the meeting is being recorded and transcribed.
- Confirm that everyone is content — if any attendee is not, do not start the recording.
- Delete a recording that captured content unrelated to the matter (for example, a private aside).
3.4 Personal devices
The System is accessed through a browser. If you use a personal device, that device must have full-disk encryption enabled, an automatic screen lock of five minutes or less, and up-to-date operating-system security patches. When you leave the firm, we may ask you to demonstrate that you have logged out on every personal device.
3.5 Automated tools and AI assistants
- Do not paste client data into public AI tools (e.g. ChatGPT, Claude, Gemini, Copilot Chat) without written approval.
- Do not scrape or bulk-download from the System without written approval.
- Do not connect unapproved browser extensions, RPA tools, or agents to the System.
3.6 Consequences of breach
We take acceptable-use breaches seriously. Depending on severity, a breach may lead to a warning, suspension of access, disciplinary action, termination of engagement, referral to the SRA, or a report to law enforcement. We will investigate incidents fairly and give you a chance to respond before taking irreversible action.
3.7 Reporting other people’s misuse
If you notice that another user is breaching this policy, report it to Alan McAloon in confidence. You are protected from retaliation for good-faith reports — this includes reports under the Public Interest Disclosure Act 1998.
