Acceptable Use Policy

Last updated: June 2026

Contents

1. Purpose of this Policy

This Acceptable Use Policy ("Policy") establishes the standards governing the appropriate and responsible use of the Cortextual platform and related services.

Cortextual is designed as an enterprise platform that enables organisations to organise institutional knowledge, improve operational visibility, facilitate collaboration, and responsibly adopt artificial intelligence. The continued security, availability, and integrity of the Services depend upon all users using the platform responsibly and in accordance with consistent operational standards.

This Policy describes the behaviours and practices expected of Customers and Authorised Users when accessing or using the Services. Its purpose is not only to identify prohibited activities but also to promote the secure, lawful, ethical, and responsible use of the platform.

This Policy forms part of the contractual framework governing the Services and should be read together with the Terms of Service, Privacy Notice, Security & Trust, and Responsible AI & AI Transparency Statement.

2. Scope and Application

This Policy applies to every organisation subscribing to the Services and to all individuals authorised to access or use the Cortextual platform on that organisation's behalf, including employees, administrators, contractors, consultants, temporary workers, and other Authorised Users.

The Policy applies whenever the Services are accessed, regardless of the device used, the location of the user, or the method of access. It also applies to all functionality made available through the platform, including AI-enabled features, APIs, integrations, administrative tools, collaboration features, mobile applications, and future functionality introduced as part of the Services.

Customers are responsible for ensuring that all Authorised Users are aware of and comply with this Policy.

3. Guiding Principles

The Cortextual platform has been developed to support secure collaboration, responsible innovation, organisational governance, and the effective management of organisational knowledge.

Accordingly, all users are expected to use the Services responsibly, lawfully, professionally, and in a manner that respects the rights of other users, protects organisational information, preserves platform security, and supports the continued availability of the Services.

The principles described throughout this Policy are intended to support these objectives while providing Customers with flexibility to configure the platform in accordance with their own internal governance frameworks and operational requirements.

4. Appropriate Use of the Services

The Services may be used only for legitimate business purposes consistent with the Customer's internal governance framework, applicable laws, and the contractual arrangements governing the use of the Services.

Users should access only those parts of the platform that they are authorised to use and should handle organisational information responsibly, respecting applicable confidentiality obligations, security controls, and organisational policies.

Customers are expected to configure appropriate user permissions, manage access rights responsibly, review user access periodically, and implement internal governance processes that are appropriate to the nature of the information processed through the platform.

The Services should not be used in any manner that may compromise platform security, interfere with the rights of other users, undermine the integrity of organisational information, or adversely affect the operation of the Services.

5. Responsible Use of Artificial Intelligence

Artificial intelligence functionality available within Cortextual is intended to support organisational productivity, facilitate access to organisational knowledge, and assist users in analysing information more efficiently.

Users should exercise appropriate professional judgement when using AI-enabled functionality and should independently review AI-generated outputs before relying upon them in circumstances involving legal, financial, employment, compliance, regulatory, or other significant organisational decisions.

AI functionality should not be used to generate misleading information, facilitate unlawful activities, deliberately circumvent organisational controls, or otherwise undermine the responsible use of artificial intelligence within the Customer's organisation.

The use of AI-enabled functionality is further governed by Cortextual's Responsible AI & AI Transparency Statement, which should be read together with this Policy.

6. Security Requirements

The security of the Cortextual platform depends upon the responsible actions of every Customer and Authorised User. While Cortextual implements comprehensive technical and organisational measures to protect the platform and Customer Data, Customers also play an essential role in maintaining a secure operating environment.

Customers are expected to establish appropriate internal access controls, assign permissions in accordance with business need, regularly review user access, and promptly revoke access where users no longer require it. Account credentials must be kept confidential and should not be shared, reused inappropriately, or disclosed to unauthorised individuals.

Users must take reasonable steps to protect the devices and networks used to access the Services and should promptly report any suspected compromise of credentials, unauthorised access, security vulnerabilities, or other incidents that may affect the security or integrity of the Services.

Customers and Authorised Users must not intentionally bypass, disable, interfere with, or attempt to circumvent any authentication mechanisms, security controls, access restrictions, monitoring systems, or protective measures implemented by Cortextual.

Additional information regarding Cortextual's security programme is available in our Security & Trust documentation.

7. Protection of Customer Data

The Cortextual platform has been designed to enable organisations to securely manage organisational information. The quality, integrity, and lawful use of Customer Data remain the responsibility of the Customer.

Customers should ensure that all information made available through the Services has been obtained lawfully, is accurate to the best of their knowledge, and may be processed through the platform in accordance with applicable laws, contractual obligations, and internal organisational policies.

Authorised Users should access Customer Data only where required for legitimate business purposes and only to the extent authorised by the Customer. Information obtained through the Services should be treated in accordance with applicable confidentiality obligations and should not be disclosed, copied, exported, or otherwise used for unauthorised purposes.

Customers are responsible for determining appropriate retention periods, access permissions, and governance procedures relating to the information they manage through the platform.

Further information regarding the processing of personal information is available in our Privacy Notice.

8. Prohibited Activities

To protect the security, availability, integrity, and lawful operation of the Services, Customers and Authorised Users must not engage in activities that could reasonably be expected to compromise the platform, other users, or the rights of third parties.

Without limitation, prohibited activities include using the Services for unlawful, fraudulent, deceptive, or malicious purposes; attempting to gain unauthorised access to accounts, systems, networks, or information; interfering with or disrupting the operation of the Services; introducing malware, malicious code, ransomware, spyware, or other harmful software; conducting penetration testing or vulnerability scanning without Cortextual's prior written authorisation; circumventing technical restrictions or security controls; attempting to reverse engineer, decompile, or otherwise derive the underlying source code of the platform except where expressly permitted by applicable law; and using the Services in a manner that infringes the intellectual property, privacy, confidentiality, or other legal rights of any person.

Users must not upload, transmit, or otherwise make available information that they are not legally entitled to process through the platform, nor should they use the Services to distribute unlawful content, facilitate cybercrime, impersonate another individual or organisation, or deliberately interfere with another customer's use of the Services.

The use of AI-enabled functionality to generate deceptive content, facilitate fraud, intentionally mislead individuals, circumvent organisational governance processes, or support activities that are unlawful or contrary to applicable professional or regulatory standards is likewise prohibited.

The examples described above are intended to illustrate unacceptable conduct and should not be interpreted as an exhaustive list of prohibited activities.

9. Fair Use and Platform Integrity

Cortextual is designed to provide reliable enterprise services to multiple customers operating within a shared cloud environment. Responsible use of shared infrastructure is therefore essential to maintaining platform performance and service availability.

Customers should use the Services in a manner consistent with their subscribed services and should avoid activities that unreasonably consume shared resources, intentionally degrade platform performance, interfere with other customers, or otherwise affect the stability or availability of the Services.

Customers must not use automated processes, bots, scripts, or other technologies to interact with the Services in a manner that exceeds reasonable operational limits, bypasses platform restrictions, or adversely affects the performance or security of the Services unless such activity has been expressly authorised by Cortextual.

Where Cortextual reasonably determines that particular activities present an immediate risk to platform stability, information security, or service availability, Cortextual may take proportionate operational measures to protect the Services, including temporarily limiting or suspending the relevant activity while the matter is investigated.

10. Monitoring and Enforcement

Cortextual may monitor the operation of the Services to the extent reasonably necessary to maintain platform security, investigate suspected misuse, ensure compliance with applicable contractual obligations, protect Customer Data, detect malicious activity, comply with legal requirements, and support the reliable operation of the platform.

Monitoring activities are conducted in accordance with applicable law, our Privacy Notice, and our Security & Trust documentation.

Where Cortextual reasonably believes that this Policy has been breached, it may investigate the relevant circumstances and take appropriate action proportionate to the nature and severity of the issue. Such action may include requesting corrective measures, temporarily restricting access to particular functionality, suspending affected user accounts, removing unlawful content where appropriate, notifying the relevant Customer administrator, or, in serious cases, suspending or terminating access to the Services in accordance with the Terms of Service.

Cortextual will, where reasonably practicable and appropriate, seek to work collaboratively with Customers to resolve issues before taking enforcement action, particularly where concerns arise from misunderstanding, configuration issues, or unintentional misuse.

Enforcement measures are intended to protect the security, integrity, and availability of the Services for all Customers and should not be interpreted as limiting any additional rights or remedies available under the applicable contractual arrangements.

11. Reporting Misuse and Security Concerns

Maintaining a secure, trustworthy, and reliable platform is a shared responsibility between Cortextual and its Customers. We encourage Customers and Authorised Users to promptly report any suspected misuse of the Services, security vulnerabilities, unauthorised access, policy violations, or other activities that may affect the integrity, availability, or security of the platform.

Reports may relate to suspected breaches of this Policy, unlawful activity, misuse of AI-enabled functionality, compromised user accounts, potential security vulnerabilities, inappropriate access to Customer Data, or any other matter that may require investigation.

Cortextual treats all reports seriously and will investigate them in accordance with the nature of the issue, applicable legal requirements, and our internal security and incident management procedures. Where appropriate, we may engage with the reporting party, affected Customers, security researchers, or competent authorities to investigate and resolve the matter.

Where a reported issue concerns a potential technical security vulnerability, users are encouraged to review our Security & Trust documentation, including our Vulnerability Disclosure process, before conducting any testing or research activities.

Individuals reporting concerns in good faith will not be subject to adverse action solely because they have responsibly reported a suspected issue.

12. Relationship with Other Trust Centre Documents

This Policy forms one component of Cortextual's broader governance framework and should not be interpreted in isolation.

The acceptable use of the Services is closely connected with information security, privacy protection, responsible artificial intelligence, organisational governance, and contractual obligations. Accordingly, this Policy should be read together with the following documents, each of which addresses a different aspect of the operation and governance of the Cortextual platform:

Terms of Service, which establish the contractual relationship governing access to and use of the Services.

Privacy Notice, which explains how personal information is processed by Cortextual.

Security & Trust, which describes the technical and organisational safeguards implemented to protect the platform and Customer Data.

Responsible AI & AI Transparency Statement, which sets out the principles governing the design, operation, and oversight of AI-enabled functionality.

Cookie Notice, which explains the use of cookies and similar technologies across the Cortextual website and platform.

Together, these documents provide a comprehensive governance framework intended to promote transparency, security, regulatory compliance, and responsible use of the Services.

13. Changes to this Policy

Technology, cybersecurity threats, artificial intelligence, regulatory expectations, and the Services provided by Cortextual continue to evolve. Accordingly, this Policy may be amended from time to time to reflect changes in applicable legislation, recognised industry standards, operational practices, security requirements, or the functionality of the Services.

Where changes materially affect the obligations of Customers or Authorised Users, Cortextual will use reasonable efforts to provide appropriate notice through the platform, customer portal, email communications, or other suitable communication channels.

The most current version of this Policy will always be available through the Cortextual Trust Centre. Customers are encouraged to review this Policy periodically to remain informed about the standards governing the appropriate use of the Services.

Continued use of the Services following the effective date of an updated version of this Policy constitutes acceptance of the revised Policy to the extent permitted by applicable law and the contractual arrangements governing the Services.

14. Contact

Questions regarding this Policy, the appropriate use of the Services, or any matter relating to platform governance may be directed to Cortextual using the contact details below.

Legal & Compliance

Email: legal@cortextual.com

Questions relating specifically to information security, suspected vulnerabilities, or cybersecurity matters may also be submitted through the reporting channels described in our Security & Trust documentation.

Questions regarding privacy or the processing of personal information should be directed to our Privacy Team in accordance with the contact information provided in our Privacy Notice.

Closing Statement

Cortextual is committed to maintaining a platform that enables organisations to innovate responsibly while protecting their information, supporting sound governance, and maintaining the confidence of customers, users, and business partners.

This Policy is intended not merely to prohibit inappropriate behaviour, but to establish shared expectations that promote secure collaboration, responsible innovation, and the long-term integrity of the Cortextual platform. By adhering to these principles, Customers and Authorised Users contribute to a trusted environment in which organisations can confidently manage knowledge, leverage artificial intelligence, and achieve their operational objectives.