Jobdeck

Jobdeck — acceptable use policy

Version 1.0, published 31 August 2026 · SHA-256 2ccb1fb6e58e44f8 · DRAFT: not yet reviewed by a lawyer

What this policy is for

This policy sets out what you may not do with Jobdeck. It is short and it is deliberately specific: a policy that prohibits "misuse" without saying what misuse is gives us discretion we should not have over an account somebody's business depends on.

It forms part of our terms of service.

1. Things that are not allowed

Do not use Jobdeck to break the law. That includes storing or distributing material that is unlawful to hold, using it to defraud somebody, or using it to harass a person.

Do not put other people's personal data in without a basis for it. You are the controller of the client records, photographs and contact details you enter. You need a lawful basis for holding them and for the way you use them. We are your processor and we act on your instructions; we cannot supply the basis on your behalf.

Do not attack the service or the people on it. No attempts to gain access to another workspace, another account, or infrastructure you have not been given. No automated traffic designed to degrade the service for others. No probing for vulnerabilities outside the disclosure route below.

Do not resell or white-label the service without a written agreement with us. Using it to run your own business is exactly what it is for; using it as the back end of a product you sell to others is a different arrangement and needs to be agreed.

Do not circumvent the plan limits. Sharing one editor seat between several people, creating multiple free workspaces to avoid a seat count, or automating around a metered limit are all breaches. If a limit is in your way, the answer is to tell us — we would rather change a limit that is wrong than police one that is.

2. Things that are allowed, and sometimes assumed not to be

  • Automating your own workflow through the tools we provide, at ordinary volumes.
  • Exporting everything, at any time, for any reason — including in order to leave.
  • Storing photographs of work, sites and equipment, which is most of what a trades

business needs to store.

  • Giving a customer a login to see their own jobs, where that feature is available on your

plan.

  • Keeping records for as long as your own obligations require, which is often longer than

you expect.

3. Security research

If you find a vulnerability, tell us before you tell anybody else, and we will not take action against you for having looked. Send the details to the address in our legal notice with "security" in the subject.

Please do not access another customer's data in the course of testing. If you do so accidentally, stop, tell us what you saw, and delete it. We would rather know.

We do not currently run a paid bug bounty. We will credit you publicly if you want us to.

4. What happens if this policy is breached

We deal with breaches proportionately and we tell you what we are doing.

  • For most breaches we contact you, explain the problem, and give you a reasonable time to

put it right.

  • For a breach that is causing active harm — an attack in progress, unlawful material — we may

suspend access first and explain immediately afterwards.

  • We end the agreement only where a material breach has not been put right, or where the

breach is serious enough that no remedy is realistic.

Suspension is not deletion. A suspended workspace keeps its data and keeps the export route open, so a dispute about a policy breach never becomes a dispute about your business losing its records.

5. Reporting something

If you believe another customer is using Jobdeck in breach of this policy, tell us at the address in our legal notice. Tell us what you saw and where. We will look at it, and we will not tell the other party who reported it.

A complaint about how we handle personal data has its own route and its own statutory deadline, described on the data complaint page.


Every version of this document is kept. The version you accepted is recorded against your order with a checksum of the exact text, and we can produce it on request.