Skip to content

Legal

Acceptable use policy

What is not allowed, how to report abuse, and what enforcement actually looks like. Including the fact that we contact you first when it looks like a mistake.

Last updated 1 July 2026. In this document, Projexio, “we”, “us” and “our” mean the provider of the Projexio service, and “you” means the customer or visitor.

1. Purpose and scope

This policy sets out what you may not do with Projexio. It forms part of our Terms of Service and applies to you, to everyone you invite into your workspace, and to anyone using the service through your account, including your clients.

The list below is not exhaustive. If something is clearly harmful, unlawful or abusive, treat it as prohibited even if it is not named here.

2. Content you may not store or transmit

You may not use the service to store, send or make available:

  • Material that is unlawful in your jurisdiction or ours, or that promotes unlawful activity.
  • Material that infringes anyone's copyright, trademark, patent, trade secret or other proprietary right.
  • Child sexual abuse material. We report this to the relevant authorities and terminate the account immediately and without notice.
  • Material that harasses, threatens, defames or incites violence against a person or group.
  • Malware, ransomware, exploit code intended for unauthorised use, or credential-harvesting content.
  • Deceptive material designed to impersonate a person or organisation for fraudulent purposes, including phishing content.
  • Personal data you have no lawful basis to process, or special category data where you have not met the additional conditions that apply to it.

3. Conduct that is not permitted

You may not:

  • Attempt to access another customer's workspace, data or account, whether or not you succeed.
  • Probe, scan or test the vulnerability of the service except under our responsible disclosure process.
  • Circumvent authentication, rate limiting, permissions, plan limits or metering.
  • Interfere with the service or its infrastructure, including denial-of-service attacks and deliberate resource exhaustion.
  • Reverse engineer, decompile or disassemble the service except to the extent that right cannot lawfully be excluded.
  • Resell, sublicense or provide the service to a third party as your own product, unless we have agreed to it in writing.
  • Use the service to build or train a competing product, or to benchmark it for publication without our written consent.
  • Share a single login between multiple people to avoid paying for seats. Client collaborators are free, so there is no legitimate need for this.
  • Use automated means to scrape the service beyond what our API and its published rate limits allow.
  • Send unsolicited bulk messages through any notification or invitation feature.

4. Fair use of shared resources

Storage, API rate limits and file size limits are published per plan on the pricing page. Those are the boundaries, and we do not apply hidden ones beneath them.

If your usage is materially disproportionate in a way that degrades the service for others, we will contact you to discuss it before taking any action. In practice this is rare and is usually a misconfigured integration rather than intent.

Automated activity should identify itself through the API rather than driving the web interface. This is not a technicality: scripted browser activity is indistinguishable from an attack and will be rate limited as one.

5. Your responsibility for your users and clients

You are responsible for the conduct of everyone you invite, including client collaborators who do not pay for a seat. Free access does not mean unaccountable access.

  • Make sure the people you invite understand this policy where their role makes it relevant.
  • Use roles and per-item visibility to limit access to what each person needs. This is the main tool available to you for reducing risk.
  • Remove access promptly when someone leaves your organisation or a project ends.
  • Have a lawful basis for any personal data you put into the service about your clients or their staff.

6. Reporting a violation

To report abuse of the service or a security vulnerability, email support@projexio.org with as much detail as you can safely provide. Put “Abuse” or “Security” in the subject line so we can prioritise it. Good-faith vulnerability research that respects user privacy and avoids service disruption is welcome.

We acknowledge abuse reports within two business days. We will not disclose your identity to the party you reported unless we are legally required to.

If you believe content in the service infringes your copyright, send us the material's location, a description of the work, your contact details, and a statement that you have a good faith belief the use is unauthorised and that your report is accurate.

7. How we enforce this

Our aim is to fix the problem, not to catch people out. Where a violation looks like a mistake or a misconfiguration, we contact you first and give you a reasonable opportunity to resolve it.

Where the violation is serious or the risk is immediate, we act first and explain afterwards. Escalation generally runs as follows:

  • Notice to the account owner describing the issue and what needs to change.
  • Restriction of the specific capability being misused, where that is technically possible.
  • Suspension of the account, with your data preserved and export available.
  • Termination, with the export window set out in the Terms of Service.

We terminate immediately and without notice for child sexual abuse material, for active attacks on our infrastructure or other customers, and where we are legally compelled to.

If you believe we have acted wrongly, reply to the notice we sent. A person will review it, and we will reverse the decision if we got it wrong.

8. Changes to this policy

We update this policy as new categories of abuse appear. The date at the top of the page reflects the current version.

Material changes are notified to account owners by email at least 30 days in advance, in line with the Terms of Service. Changes required for legal or immediate safety reasons may take effect sooner.

Questions about this document

Email support@projexio.org, or use the contact page.