Acceptable Use Policy
This policy covers what SMP CRM may and may not be used for. It applies to everybody in your organization and to anybody you grant access to.
Do Not
- Use the Service to send unsolicited bulk email, or to store lists acquired for that purpose in breach of the law where you or the recipients are.
- Store regulated data the Service is not built for. In particular, **do not put protected health information, payment card numbers, or government identification numbers into customer records or notes.** The Service is not built to hold them and we make no representation that it meets any regulatory standard covering them.
- Attempt to reach another organization's data, or to probe the isolation between organizations. If you believe you have found a way to, tell us rather than continuing.
- Use the Service to harass anybody, or to store material that is unlawful where you are.
- Resell access to the Service, or share a single sign-in between severa people. Users are per person; that is what makes a sign-in record mean anything.
A Note on the Regulated-Data Prohibition
Saying "do not put protected health information here" is a prohibition and a remedy. It is not a shield. If a covered entity actually routes such information through the Service, the law may look at what happened rather than at what we asked for. If you are in that position, talk to us before you start rather than after.
Reporting
If you see something being done through SMP CRM that breaches this policy, tell us. Contact details are on our website.
What Happens If You Breach It
We may suspend or close an account. Where circumstances allow it we will tell you first and give you a chance to put it right. Where the breach puts other customers at risk, we may act immediately.