Governing policy · POL-03

Acceptable Use Policy

Version 1.0 · effective 13 July 2026 · owner: Jonny Allum

OwnerJonny Allum
Version1.0 · Effective 13/07/2026 · Review annually (July)
Applies toThe operator, and any future contractor or collaborator given access to JonnyAI systems

1. Purpose

Sets the rules for using business systems and accounts. Today this binds one person; it exists so that the first contractor, virtual assistant or collaborator inherits clear rules on day one rather than folklore.

2. Accounts and identity

  • Business accounts (GitHub, Google Cloud, Supabase, Stripe, Resend, Anthropic, registrar, Resend, social) are used only for business purposes and secured per POL-01 (MFA, password manager).
  • No shared logins. A collaborator gets their own account with the minimum role needed (POL-04), never the owner credentials.
  • Personal and client work stay separated: client deliverables live in client-designated repos/accounts; JonnyAI IP stays in JonnyAI accounts.

3. Data handling

  • Tenant data is viewed only for support, debugging or onboarding, with the tenant's knowledge, and never copied out of the platform except for an agreed export (SOP-10) or a logged support action (SOP-07).
  • Special category data (care vertical) is never used in demos, screenshots, marketing material or test fixtures. Demo content uses the fictional workspaces (Meridian FM, Oakhaven Care, seeded Southernbrook demo).
  • No production credentials or tenant data on personal devices beyond the managed, encrypted workstation and phone.

4. Communications

  • Business email is sent from business domains. Marketing sends follow POL-12 (consent-first, working unsubscribe).
  • Never discuss one client's business, pricing or data with another.

5. AI tools

  • AI coding assistants and agents may be used for development, subject to POL-05: no secrets in prompts, no tenant personal data pasted into third-party tools outside the platform's own governed AI seam.
  • AI-generated client deliverables are reviewed by the operator before they ship — the operator, not the model, is accountable for the output.

6. Unacceptable use

  • Circumventing security controls (POL-01 §5).
  • Using platform access to browse tenant data out of curiosity.
  • Installing unlicensed software or using pirated assets in client work.
  • Any use of company systems that is unlawful or would embarrass a client.

Violations by a future collaborator end access immediately and are handled under their contract; violations by the operator are logged in the risk register with corrective action (the same evidence discipline as POL-01 §6).

← All documents & policiesQuestions? hello@jonnyai.co.uk