Last updated: 23 July 2026. View change log.
This Annex forms part of the IT Master Services Agreement between you and Cultrix Limited (“Cultrix”, “we”, “us”), and sets out the scope, responsibilities and limits that apply to the Acceptable Use Policy.
The AUP helps protect you, your users and us from security incidents, data loss and misuse of technology. It applies to everyone who accesses or uses the Services we manage under your Order.
1. Scope and applicability
This AUP applies to:
- all employees, contractors and third parties who use the systems and Services we manage under your account;
- all devices, networks, cloud services and applications that we manage or support for you;
- use of the internet, email, messaging and collaboration tools provided under your Order.
You are responsible for making sure your users understand and follow this AUP.
2. General acceptable use
Users must:
- use systems, applications and data only for legitimate business purposes and in line with your internal policies;
- follow reasonable security guidance we provide, including patching, security updates and policy changes;
- take reasonable care to avoid actions that could compromise systems, data or networks;
- promptly report suspected security incidents, data loss or unusual behaviour to your nominated contacts and to us.
3. Unacceptable use
Users must not:
- try to bypass or disable security controls, including antivirus, EDR, firewalls, DNS filtering or access controls;
- install unauthorised software or hardware on managed devices or networks;
- use systems or Services for illegal activity, harassment, discrimination, or any form of abuse;
- deliberately introduce malware, ransomware or other malicious code into any system;
- use business systems for excessive personal use that harms performance, security or productivity;
- share company data with unauthorised parties, or store it on unapproved personal services or devices.
4. Accounts, passwords and authentication
Users must:
- keep passwords and authentication factors confidential and not share them with others;
- use strong, unique passwords and, where provided, password managers your organisation approves;
- use multi-factor authentication (MFA) wherever it is enabled or required;
- not use shared accounts unless these are explicitly approved and controlled;
- notify your internal support or us promptly if they suspect an account has been compromised.
5. Email, messaging and internet use
Users must:
- take care when opening attachments or clicking links, especially in unsolicited or unexpected messages;
- not use business email for unlawful, offensive or fraudulent communications;
- avoid visiting websites that are clearly inappropriate, malicious or unrelated to business needs;
- follow guidance from phishing simulations and awareness training where provided.
6. Data protection and confidentiality
Users must:
- handle personal and confidential data in line with your organisation’s data protection policies;
- store business data only in approved locations (for example managed file shares, Microsoft 365 or Google Workspace);
- avoid copying data to personal USB drives, personal cloud storage or unmanaged devices unless explicitly authorised;
- lock screens when devices are left unattended.
7. Devices, remote access and BYOD
Where you use mobile devices, remote access or bring-your-own-device (BYOD) arrangements:
- devices accessing business systems should be enrolled in your agreed mobile device management (MDM) solution, where applicable;
- users must keep devices updated and protected with antivirus and security patches;
- remote access should only be via approved VPNs or secure gateways;
- local security features (for example PINs, biometrics or encryption) must not be disabled.
8. Monitoring and logging
To protect systems and data, we and your organisation may monitor:
- system and network activity (for example firewall logs, EDR telemetry and access logs);
- use of business email and collaboration tools; and
- security alerts generated by managed tools and platforms.
We carry out monitoring in line with applicable law. It is aimed at protecting systems, detecting misuse and responding to incidents, not at unreasonable surveillance of individuals.
9. Reporting incidents and suspected breaches
Users must promptly report:
- suspected phishing or malicious emails;
- lost or stolen devices;
- suspected account compromise or unusual activity;
- accidental data loss or unauthorised data disclosure.
Incidents should be reported through your internal processes and, where appropriate, to us via the Service Desk.
10. Breaches of this AUP
Breaches of this AUP may:
- increase security risk for your organisation and other customers; and
- lead to restriction or suspension of affected accounts, devices or Services where this is necessary to protect systems and data.
Disciplinary action for users is a matter for your organisation’s internal policies. We may require specific users or devices to be restricted or remediated where their behaviour presents an ongoing risk.
11. Changes to this Annex
We may update this AUP to reflect changes in the Services, security best practice or legal requirements. We will publish updated versions on our website and, for material changes, give reasonable notice.