NEWScaffEngine — the 3D builder. Model the scaffold before anyone leaves the yard

ScaffoldOptix

Legal

Acceptable Use Policy

What ScaffoldOptix may and may not be used for — and the two things we act on without warning.

Version 1.0 · Last updated 23 September 2026

1. Scope

This policy applies to all use of ScaffoldOptix, and forms part of our Terms of Service.

It applies to you and to every Authorised User you permit to access a product. You are responsible for your Authorised Users' compliance with it.

Capitalised terms have the meanings given in the Terms of Service.

2. General principle

Use the products lawfully, for their intended business purpose, and in a way that does not harm other users, the service, or any individual whose data you hold in it.

3. Prohibited uses

3.1 Breaking the law

You must not use any product to:

  • commit, facilitate or conceal any criminal offence
  • breach any law, regulation, court order or regulatory requirement
  • infringe any third party's intellectual property, privacy or other rights
  • falsify, backdate or fabricate any record, inspection, assessment, certificate, signature or audit trail
  • create or store any record intended to mislead a regulator, inspector, auditor, insurer or client
  • unlawfully discriminate against any individual

The fourth and fifth points are taken particularly seriously. Our products exist to create reliable compliance records. Using one to manufacture a false record undermines the purpose of the service, devalues every honest customer's records, and in several of our sectors is a criminal offence.

3.2 Misusing personal data

  • uploading personal data you have no lawful basis to process
  • uploading special category or criminal offence data without a valid Article 9 or Article 10 condition
  • using a product to monitor or track individuals in a way that breaches data protection or employment law
  • accessing records about individuals where you have no legitimate business need to do so
  • uploading personal data belonging to a different organisation, or that you obtained unlawfully
  • extracting personal data for a purpose unconnected with the reason it was collected

3.3 Attacking or degrading the service

  • attempting to gain unauthorised access to any part of a product, its infrastructure, or another customer's data
  • probing, scanning or testing the vulnerability of a product without our prior written consent
  • circumventing authentication, authorisation, tenant isolation, rate limiting or usage controls
  • introducing malware, ransomware, worms, logic bombs or any other malicious code
  • conducting a denial of service attack, or any activity that places a disproportionate load on the infrastructure
  • scraping, crawling or harvesting data other than through our documented interfaces and within published limits
  • using a product in a way that interferes with any other customer's use of it

3.4 Misusing the licence

  • reselling, sublicensing, white-labelling or providing a product as a service to third parties without our written agreement
  • sharing account credentials between individuals, or using a shared generic login where individual accounts are available
  • using a product to build, benchmark for, or assist in developing a competing product
  • reverse-engineering, decompiling or disassembling a product, except so far as that restriction cannot lawfully be excluded
  • removing, obscuring or altering any proprietary notice or branding

3.5 Uploading harmful content

  • content that is unlawful, defamatory or obscene, or that promotes violence or discrimination
  • any image, video or material depicting the abuse or exploitation of any person, and in particular any child
  • content that infringes a third party's rights

If we become aware of material depicting the abuse or exploitation of a child, we will preserve it, report it to the appropriate authorities, and suspend the account immediately. We will not give prior notice where doing so would prejudice an investigation.

4. Requirements for this product

  • Designs and calculations must be reviewed and signed off by a competent person before erection. You must not use the Product to bypass that review.

5. Security expectations

You must:

  • issue individual accounts rather than shared logins
  • remove access promptly when a user leaves your organisation or changes role
  • review user roles and permissions periodically
  • not store your account credentials in plaintext or share them by insecure means
  • report any suspected compromise of your account to security@optixgroup.co.uk without undue delay

Multi-factor authentication is not yet available on our products. It is on our roadmap and listed in Schedule 3 of the Data Processing Agreement among the measures we have not yet built. Until it ships, credential hygiene matters more than usual, and we would rather say that than imply a control we do not have.

6. Vulnerability reporting

If you discover a security vulnerability in a product, report it to security@optixgroup.co.uk.

We ask that you:

  • give us reasonable time to investigate and remediate before public disclosure
  • do not access, modify or delete data belonging to anyone else
  • do not degrade the service while testing

We will not pursue action against good-faith researchers who follow those three points.

7. Enforcement

If we believe this policy has been breached, we may:

  • contact you to resolve the matter
  • remove or restrict access to specific content
  • suspend the affected user account
  • suspend your organisation's access under clause 12 of the Terms of Service
  • terminate the agreement for material breach
  • report the matter to law enforcement or the relevant regulator

We will normally contact you first and give you the opportunity to resolve the issue. We may act immediately and without notice where there is an active security threat, a legal obligation to act, a risk to another customer, or material within clause 3.5 depicting the abuse of a child.

We will limit any action to the narrowest scope reasonably necessary, and restore access once the issue is resolved. Suspension or termination under this policy does not entitle you to a refund.

8. Reporting misuse

To report a breach of this policy, email abuse@optixgroup.co.uk with details of the product, the conduct concerned, and any evidence you hold.

9. Changes

We may update this policy. Material changes will be notified to account holders at least 30 days before taking effect.