← Back to home

Acceptable use policy

What the service may and may not be used for. This forms part of the terms of service, and it applies to everyone your school invites into its account.

Last updated
26 July 2026
Effective from
26 July 2026

Draft — not yet reviewed by legal counsel

This document describes how the product actually works, but it has not been reviewed by a qualified lawyer and some company details are still outstanding. It is published for transparency and is not yet a binding legal document. Anything marked ▲ to be supplied is a known gap.

The principle

This system holds records about children. That single fact sets the standard: use it for running your school, treat what you can see as confidential, and do not go looking for records you have no professional reason to open.

The rules below are specific, but they are all downstream of that.

You must not

Misuse access to records

  • Look up pupils, guardians or staff for reasons unconnected to your role. Curiosity is not a professional reason, and every access is logged.
  • Share credentials, or let someone else act under your login. The audit trail your school relies on is only as honest as this rule.
  • Extract records to take to another organisation, or retain them after leaving the school.
  • Use medical, dietary or safeguarding information for any purpose other than the pupil’s welfare.

Put unlawful or harmful content into the system

  • Content that is unlawful, defamatory, harassing, discriminatory or abusive.
  • Anything that infringes someone else’s intellectual property or privacy rights.
  • Malware, or files designed to disrupt or gain unauthorised access to any system.
  • Using the messaging or notice features to send bulk unsolicited commercial email.

Interfere with the service

  • Attempt to access another school’s data, or to circumvent the tenant and campus scoping that separates customers.
  • Attempt to escalate your own permissions beyond what your role has been granted.
  • Probe, scan or load-test the service without our prior written permission — see the disclosure route below for the legitimate way to do this.
  • Scrape the service, or access it through automated means other than a documented interface, in a way that degrades it for others.
  • Reverse-engineer, decompile or attempt to derive the source code, except where the law permits it regardless of this clause.

Resell or misrepresent

  • Resell, sub-licence or provide the service to a third party as if it were your own.
  • Create accounts for schools or organisations you are not authorised to represent.
  • Exceed the campus, pupil or staff limits of your package by creating additional accounts to work around them.

Reporting a security issue — do this instead

Your school’s responsibility

The school is responsible for the conduct of everyone it invites into its account, and for removing access promptly when someone leaves. If you become aware that this policy is being breached from your account, tell us and take steps to stop it.

What happens if this is breached

Proportionate to what has happened, we may:

  • contact the school’s administrators to resolve it;
  • suspend an individual user’s access;
  • suspend the account — which walls the portal but retains all data, so a resolved issue restores access intact;
  • terminate the agreement under the terms of service, honouring the 30-day data export window;
  • report the matter to law enforcement where we are required to.

Where there is an immediate risk to a child, to data, or to the service, we may act first and explain afterwards. Otherwise we will contact the school before suspending anything.

Contact

Report misuse or ask a question about this policy: info@axurs.com. Security disclosures: Security contact address — to be supplied.