Acceptable Use Policy
Platform — all users
1. Purpose & who this applies to
This Acceptable Use Policy sets the rules for everyone who uses the ClinicalFlow platform — patients, clinicians, pharmacists, clinic and pharmacy staff, and administrators. It protects patients, your colleagues, and the integrity of clinical data. Breaching it may lead to suspension, account closure, and where appropriate referral to a professional regulator or the authorities.
2. You must
- Use the Platform only for legitimate, authorised purposes connected to your role;
- Provide accurate information and keep your records and access rights current;
- Protect your credentials, enable and use multi-factor authentication, and never share your login;
- Access only the data you need for your role (least privilege) and respect patient confidentiality;
- Report any suspected security incident, data breach or misuse immediately (see section 6).
3. You must not
- Access, copy, export or share data you are not authorised to, or use patient data for any purpose other than the care or function you are authorised to perform;
- Share, sell or transfer your account, or attempt to use someone else's;
- Attempt to bypass, disable or probe security controls, access controls or audit logging;
- Introduce malware, scrape or bulk-extract data, or place excessive automated load on the Platform;
- Use the Platform unlawfully, or to harass, defraud, or impersonate;
- Remove, alter or falsify any clinical, prescribing or controlled-drug record except through the Platform's proper, audited functions.
4. Extra duties for clinical & privileged users
If you hold a clinical, prescribing, pharmacy or administrative role with elevated access, you also: - owe a professional duty of confidentiality and must act within your registration and scope; - must handle controlled-drug records and prescriptions strictly in line with the law and your organisation's procedures; - must use any “break-glass” or override access only when genuinely necessary, with a recorded reason — every such access is logged and reviewed.
5. Monitoring & audit
For safety, security and legal compliance, activity on the Platform is logged in a tamper-evident audit trail, and access to clinical data is recorded. We review logs for misuse. By using the Platform you acknowledge this monitoring, which is carried out lawfully and proportionately.
6. Reporting concerns
Report security issues, suspected breaches or misuse to security@cannexis.org without delay. Security researchers should follow our Responsible Disclosure Policy.
7. Consequences
We may suspend or remove access, notify the relevant organisation, regulator (e.g. GMC, GPhC, ICO) or authorities, and take legal action, where this policy is breached. Serious breaches involving patient data are treated with the utmost seriousness.
Data Protection Officer: LHI Consulting — info@lhiconsult.com · c/o Cannexis Biopharma Ltd, 142-143 Parrock Street, Gravesend, Kent, DA12 1EY
