Acceptable Use Policy
Last updated: 15 July 2026
This policy applies to use of Bridge Admissions. The Customer must ensure that all authorised users follow it.
Users must not use the service to:
- break any law or infringe another person’s rights;
- access, disclose or alter information without authority;
- harass, discriminate against, threaten or harm any person;
- upload malware, malicious scripts or harmful content;
- probe, scan or test security without written permission;
- bypass access controls, usage limits or account restrictions;
- share passwords or use another person’s account;
- send unlawful or unsolicited bulk messages;
- upload content that is knowingly false, defamatory, obscene or infringing;
- use automated methods that create unreasonable load;
- reverse engineer, decompile or copy the service except where law cannot exclude that right;
- use the service to make solely automated decisions producing legal or similarly significant effects unless the Customer has separately ensured that this is lawful and contractually agreed;
- enter excessive or irrelevant sensitive information.
Children’s and sensitive information
Users should record only information that is necessary, accurate, professionally written and appropriate for an admissions record.
Sensitive notes must be restricted to staff who genuinely need access. The service should not be used as the school’s primary safeguarding, medical or emergency-response system unless this has been expressly agreed and appropriately configured.
Communications
Users are responsible for checking recipients, attachments and content before sending communications. Templates and automated suggestions must be reviewed by an authorised person.
Security reporting
Suspected vulnerabilities or compromise must be reported promptly to [SECURITY EMAIL]. Users must not publicly disclose a vulnerability before the Supplier has had a reasonable opportunity to investigate and address it.
Enforcement
The Supplier may remove content, restrict functions or suspend affected access where reasonably necessary to protect people, data, systems or legal compliance. Where practicable, the Supplier will notify the Customer and allow remediation.