| Owner | Jonny Allum |
| Version | 1.0 · Effective 13/07/2026 · Review annually (July) |
| Applies to | The operator, and any future contractor or collaborator given access to JonnyAI systems |
1. Purpose
Sets the rules for using business systems and accounts. Today this binds one person; it exists so that the first contractor, virtual assistant or collaborator inherits clear rules on day one rather than folklore.
2. Accounts and identity
- Business accounts (GitHub, Google Cloud, Supabase, Stripe, Resend, Anthropic, registrar, Resend, social) are used only for business purposes and secured per POL-01 (MFA, password manager).
- No shared logins. A collaborator gets their own account with the minimum role needed (POL-04), never the owner credentials.
- Personal and client work stay separated: client deliverables live in client-designated repos/accounts; JonnyAI IP stays in JonnyAI accounts.
3. Data handling
- Tenant data is viewed only for support, debugging or onboarding, with the tenant's knowledge, and never copied out of the platform except for an agreed export (SOP-10) or a logged support action (SOP-07).
- Special category data (care vertical) is never used in demos, screenshots, marketing material or test fixtures. Demo content uses the fictional workspaces (Meridian FM, Oakhaven Care, seeded Southernbrook demo).
- No production credentials or tenant data on personal devices beyond the managed, encrypted workstation and phone.
4. Communications
- Business email is sent from business domains. Marketing sends follow POL-12 (consent-first, working unsubscribe).
- Never discuss one client's business, pricing or data with another.
5. AI tools
- AI coding assistants and agents may be used for development, subject to POL-05: no secrets in prompts, no tenant personal data pasted into third-party tools outside the platform's own governed AI seam.
- AI-generated client deliverables are reviewed by the operator before they ship — the operator, not the model, is accountable for the output.
6. Unacceptable use
- Circumventing security controls (POL-01 §5).
- Using platform access to browse tenant data out of curiosity.
- Installing unlicensed software or using pirated assets in client work.
- Any use of company systems that is unlawful or would embarrass a client.
Violations by a future collaborator end access immediately and are handled under their contract; violations by the operator are logged in the risk register with corrective action (the same evidence discipline as POL-01 §6).