Legal
Acceptable Use Policy
How the service may and may not be used, and what happens if that is breached.
DRAFT for review by a Nigerian legal practitioner — not published. Forms part
of the Agreement; lowest in the order of precedence (Subscription Terms clause 1).⚠ The Nigerian service is not currently running. This is an instrument for
re-launch.Prohibitions are specific and proportionate and enforcement is graduated,
because breach of this policy is a ground for suspension, and suspending a
practice’s access to its own files and client account records is a serious step.
Version: [[ x.y ]] · Effective: [[ date ]]
1. What this policy is for
This policy sets out how the Service may and may not be used, to keep it secure,
available and lawful for every firm that relies on it. It applies to the Firm and to
everyone the Firm allows to use the Service.
2. You are responsible for your users
The Firm is responsible for its users’ compliance, for keeping credentials secure,
and for telling us promptly if it believes an account has been compromised.
3. Prohibited use — security
You must not:
- attempt to gain unauthorised access to the Service, to another customer’s data, or
to any system or network connected to the Service; - attempt to circumvent, disable or test any authentication, authorisation,
isolation or rate-limiting measure; - carry out penetration testing, vulnerability scanning or load testing without
our prior written permission — we will consider reasonable requests, and we
would rather work with you than find out afterwards; - introduce malware, or upload material designed to damage or disrupt any system;
- attempt to decompile, reverse engineer or derive the source code of the Service,
except to the extent the law expressly permits despite this restriction; - use the Service to attack, probe or send unsolicited bulk messages to anyone.
If you find a security vulnerability, please tell us at
[[ security contact ]]. We will not pursue a researcher who reports a genuine
issue in good faith, does not access or remove other customers’ data, and gives us a
reasonable opportunity to fix it before disclosing it.
4. Prohibited use — legal and content
You must not use the Service:
- for any unlawful purpose, or to store or transmit unlawful material;
- to infringe anyone’s intellectual property rights;
- to store or transmit material you have no right to hold;
- to harass, threaten or defame any person;
- in a way that breaches the Nigeria Data Protection Act 2023 or the
GAID 2025, or that breaches an obligation you owe to your own client or under
the Rules of Professional Conduct.
Data protection duties travel with your use of the Service. In particular, if
you deploy cookies or tracking tools on any site or platform, GAID Article 19
applies — including the requirement for a conspicuous banner that a visitor is not
required to scroll to see, a genuine “accept or reject” choice for anything beyond
necessary cookies, identification of the organisation responsible, and an
explanation of how to withdraw consent.
5. Prohibited use — access and resources
You must not:
- share credentials, or allow anyone outside the Firm to use the Service, except as
the Order permits; - resell, sublicense or provide the Service as a service to third parties without our
written agreement; - use automated means to extract data at a scale or rate that degrades the Service
for others — the export tools exist for this; please use them; - deliberately consume resources in a way designed to disrupt the Service.
A note on volume. We do not impose hidden usage traps. If your legitimate use
grows beyond what the Order contemplates, we will talk to you about it — we will not
suspend you for succeeding.
6. Things this policy deliberately does not prohibit
For the avoidance of doubt, none of the following breaches this policy:
- storing privileged, confidential or sensitive client information, including
information about alleged criminal conduct — the Service is built for exactly this; - client account and financial records of any volume, retained for as long as
your professional obligations require; - exporting your own data at any time, including in bulk, through the tools
provided; - criticising the Service publicly, or discussing it with the Nigerian Bar
Association, the Nigeria Data Protection Commission, your auditor or your insurer; - using the Service for any area of legal practice that is lawful.
Internal: this clause is deliberate. For a product holding privileged files, a
firm needs to know that ordinary professional use cannot trigger enforcement — and
that raising a concern with its regulator or with the Commission certainly cannot.
7. What happens if this policy is breached
Our response will be proportionate.
- Normally we will contact you first, explain the problem, and give you a
reasonable opportunity to put it right. - If the breach continues, or is serious, we may suspend the affected access
under Subscription Terms clause 9, telling you what we are doing and why. - We may suspend without prior notice only where there is a genuine and immediate
risk — for example an active security compromise, or where the law requires it.
We will tell you as soon as we can afterwards and explain why. - We will restore access promptly once the cause is resolved.
- Termination for material breach is governed by Subscription Terms clause 10.
We will not suspend an entire firm’s access over a single user’s isolated breach
where a narrower measure will address it. A legal practice cut off from its files and
its client account records cannot serve its clients or meet its professional
obligations, and we treat that as a serious step rather than a routine remedy.
8. Reporting
To report misuse, a security issue, or a concern about another user’s conduct,
contact us at [[ contact ]].
9. Changes
We may update this policy. Where a change materially increases your obligations we
will give at least [[ N ]] days' notice, in line with Subscription Terms clause 6.
Open items
| ref | item |
|---|---|
G-EWDOC2 |
Security, abuse and general contact addresses — must be real and monitored |
| — | Notice period in clause 9 |
| — | Confirm the reverse-engineering carve-out against Nigerian copyright/software law [[ not read at source ]] |
| — | Review by a Nigerian legal practitioner |