Delegate HQ — Acceptable Use Policy
Version: 1.0 Effective date: 16 September 2026 Last updated: 16 September 2026
1. Purpose
This Acceptable Use Policy ("AUP") protects Delegate HQ, its Customers, users and infrastructure from misuse.
It forms part of the Delegate HQ Terms of Service.
It applies to every Customer and Authorised User.
2. General requirement
You must use Delegate HQ lawfully, responsibly and consistently with the rights of others.
You must not use Delegate HQ in a way that creates unreasonable security, operational or legal risk for Delegation HQ, another Customer or any other person.
3. Unlawful activity
You must not use Delegate HQ to:
- commit, facilitate or promote unlawful conduct;
- store or distribute material where doing so is unlawful;
- infringe another person's legal rights; or
- intentionally assist another person to engage in prohibited conduct.
4. Unauthorised access
You must not:
- access or attempt to access another Customer's tenant or Customer Data;
- access another user's account without authority;
- bypass or attempt to bypass authentication;
- bypass roles, permissions or authorisation controls;
- defeat tenant-isolation controls;
- exploit an access-control error;
- use credentials that you are not authorised to use; or
- continue accessing information after becoming aware that you are not authorised to access it.
Attempting to access another Customer's data is considered a serious breach of this AUP.
5. Security testing
You must not conduct vulnerability scanning, penetration testing, exploitation, automated security testing or similar activity against Delegate HQ without prior written authorisation from Delegation HQ.
If you accidentally discover a potential vulnerability, stop any activity that could increase access or impact and report the issue privately.
A good-faith report does not authorise continued exploitation or access to Customer Data.
6. Malware and harmful content
You must not knowingly upload, distribute, execute or introduce:
- malware;
- ransomware;
- viruses;
- malicious scripts;
- destructive code; or
- other material designed to compromise systems, accounts or data.
7. Disruption and excessive use
You must not intentionally:
- disrupt or degrade Delegate HQ;
- overload infrastructure;
- interfere with another user's access;
- circumvent reasonable rate limits;
- generate abusive levels of automated traffic; or
- use the service in a manner reasonably likely to impair availability for others.
Legitimate ordinary use of Delegate HQ is not prohibited merely because it involves substantial Customer Data or normal business activity.
8. Automation and scraping
You must not use bots, scripts, crawlers, scraping tools or other automated systems to access Delegate HQ in a manner that:
- circumvents intended functionality;
- bypasses technical controls;
- extracts data without authority;
- creates unreasonable load;
- violates another person's rights; or
- breaches these Terms.
Automation expressly provided or approved by Delegation HQ is permitted within applicable limits.
9. Credentials and accounts
Each user should use their own authorised account.
You must not:
- share personal credentials between users;
- sell or transfer credentials;
- impersonate another user;
- conceal unauthorised access; or
- knowingly allow an unauthorised person to use your account.
Suspected credential compromise must be reported promptly.
10. Customer Data and third-party rights
You must not submit Customer Data unless the Customer has appropriate authority to process that information through Delegate HQ.
You must not knowingly use Delegate HQ to infringe:
- copyright;
- trade marks;
- confidentiality obligations;
- privacy rights;
- contractual rights; or
- other intellectual-property or legal rights.
11. Personal and sensitive information
Delegate HQ may legitimately contain personal information relevant to delegations, positions, organisational responsibilities and governance.
It is not intended as a general repository for unrelated highly sensitive information.
You should not unnecessarily enter information such as:
- passwords;
- banking credentials;
- tax file numbers;
- passport details;
- detailed medical records; or
- criminal-history information
unless functionality is expressly designed and approved for that purpose.
12. Impersonation and authority
You must not:
- impersonate another person or organisation;
- falsely claim to represent an organisation;
- misrepresent your authority;
- create misleading accounts; or
- knowingly enter information in a manner intended to falsely represent a person's delegation, authority or appointment.
13. Resale and sublicensing
A standard Delegate HQ subscription is for the Customer's own authorised use.
You must not resell, sublicense, commercially redistribute or provide Delegate HQ as your own service without Delegation HQ's prior written agreement.
This does not prevent legitimate use by the Customer's employees, contractors or other Authorised Users within the scope of the Customer's subscription.
14. Intellectual property
You must not:
- copy or reproduce Delegate HQ except as permitted by law or agreement;
- reverse engineer the service except to the extent a right to do so cannot lawfully be excluded;
- remove proprietary notices;
- misappropriate Delegate HQ source code, designs or documentation; or
- use Delegation HQ branding in a manner that falsely implies endorsement or affiliation.
15. Circumvention
You must not intentionally circumvent:
- subscription restrictions;
- security controls;
- permissions;
- rate limits;
- technical safeguards; or
- restrictions intended to protect Customers, users or the service.
16. Reporting security concerns
If you discover a suspected vulnerability, accidental cross-tenant access or other security issue:
- stop accessing information beyond what was necessary to recognise the issue;
- do not copy, alter or disclose Customer Data;
- preserve reasonable information necessary to explain the issue; and
- report it promptly to Delegation HQ.
Security reports should be sent to security@delegatehq.com.au, or support@delegatehq.com.au if the security address is unavailable.
17. Investigating misuse
Delegation HQ may investigate suspected violations of this AUP.
Where reasonably necessary, this may involve reviewing relevant account, audit, security and technical information.
Investigations will be conducted consistently with applicable privacy, confidentiality and contractual obligations.
18. Suspension
Delegation HQ will ordinarily provide notice and a reasonable opportunity to remedy an ordinary breach.
However, access may be suspended immediately where reasonably necessary to address:
- attempted or actual cross-tenant access;
- compromised accounts;
- serious security threats;
- unlawful activity;
- fraud;
- malware;
- material service disruption;
- serious or deliberate circumvention of security controls; or
- another urgent risk to Delegate HQ, Customers or users.
Where practicable, Delegation HQ will notify the affected Customer promptly.
19. Cooperation
Customers must reasonably cooperate with Delegation HQ in investigating serious security or misuse incidents involving their accounts.
This may include resetting credentials, removing unauthorised users or correcting unsafe account configurations.
20. Proportionate enforcement
Delegation HQ will seek to respond proportionately to violations.
An accidental minor breach will not ordinarily be treated in the same way as deliberate exploitation, unlawful conduct or attempted access to another Customer's data.
Nothing in this section prevents immediate action where necessary to protect people, systems or data.
21. Changes to this AUP
Delegation HQ may update this AUP.
Material changes affecting existing Customers will ordinarily be notified consistently with the change provisions in the Delegate HQ Terms of Service.
Urgent security or legal changes may take effect sooner where reasonably necessary.
22. Contact
Questions about permitted use:
Security reports:
security@delegatehq.com.au, or support@delegatehq.com.au if the security address is unavailable.
Legal enquiries:
Delegation HQ ABN 56 321 616 581 PO Box 4 Officer VIC 3809 Australia
