This Acceptable Use Policy applies to all users of CentreFlow, including account holders (centre managers) and all staff users created within a centre. By using CentreFlow, you agree to these rules.
1. Purpose
CentreFlow is designed solely for managing the operational activities of legitimate tuition and learning centres in the United Kingdom. This policy sets out the boundaries of acceptable use to protect all users, the platform, and the individuals whose data is stored within it.
2. Prohibited Activities
Unlawful Use
You must not use CentreFlow for any activity that is unlawful, including but not limited to:
- Processing personal data without a lawful basis under UK GDPR
- Storing data relating to activities that are illegal in England and Wales
- Engaging in fraud, identity theft, or deception
- Violating any applicable legislation, including the Computer Misuse Act 1990
Credential Sharing and Account Misuse
- You must not share your login credentials with any person not authorised to use your account
- Each staff member must have their own individual user account
- You must not create accounts for individuals who are not staff at your centre
- You must not use another person's credentials to access CentreFlow
Data Misuse
- You must not use CentreFlow to store data unrelated to your tuition centre operations
- You must not export, copy, or transfer student or parent data outside of CentreFlow for unauthorised purposes
- You must not use data accessed through CentreFlow to contact individuals for purposes unrelated to your tuition centre
Technical Misuse
- You must not attempt to circumvent any security measure, access control, or authentication mechanism
- You must not attempt to access another centre's data, accounts, or systems
- You must not use automated tools to scrape, extract, or harvest data from the platform
- You must not attempt to reverse engineer, decompile, or replicate any part of the CentreFlow software
- You must not introduce malware, viruses, or harmful code into the platform or its infrastructure
- You must not conduct denial-of-service attacks or attempt to overload our systems
Communication Misuse
- You must not use any messaging or email functionality within CentreFlow to send unsolicited communications (spam)
- You must not use the platform to harass, threaten, or abuse any individual
3. Responsibility for Staff Users
Account holders (centre managers) are responsible for the actions of all staff users created within their centre. If a staff user violates this policy, responsibility may also lie with the account holder who granted them access.
4. Consequences of Misuse
Violation of this policy may result in:
- Immediate suspension or termination of access without refund
- Referral to relevant law enforcement authorities where unlawful activity is suspected
- Legal action where CentreFlow or third parties have suffered harm
5. Reporting Misuse
If you suspect misuse of CentreFlow, please report it to us at security@centreflow.co.uk.
6. Contact
Questions about this policy: legal@centreflow.co.uk