Acceptable use policy

Draft for review

This document is a working draft prepared in-house. It has not been reviewed or approved by a solicitor and it is not yet in force. Anything in [square brackets] is a placeholder for a fact still to be confirmed. Do not rely on it, and do not treat it as legal advice. Questions to hello@restorable.cloud.

Version: draft. Effective date: [effective date]. This policy forms part of the terms of service.

1. What this is for

Restorable holds a great deal of other people's mail and files, and it gives your technicians a single search box across all of it. That is the point of the product and it is also its main risk. This policy is short and it is about that risk rather than about boilerplate.

2. Authority

  • Connect a Microsoft 365 tenant only where the organisation that controls it has authorised you to back it up. An administrator's consent in the tenant is a technical step, not a substitute for that authority.
  • Do not connect a tenant you have gained access to through a compromised or borrowed administrator account.
  • Tell us promptly if you lose the right to back up a tenant, and disconnect it.

3. Use of search, restore and export

  • Explorer searches across every client an account can see. Use it for a legitimate operational or contractual purpose: a restore, a support request, an investigation your client has asked for, or a lawful request you are obliged to answer.
  • Do not use it to read a person's mail out of curiosity, to monitor an individual without a lawful basis, or to gather material about a competitor, an employee or a client.
  • Every search with a term is written to the audit log with the name of the person who ran it, and that log is visible to your own owners and admins. That is intentional.
  • Give each person the lowest role that lets them work. Read-only exists for a reason, and so does restricting an API key to particular clients.
  • Do not export data to somewhere your own agreement with your client does not permit.

4. Content

A backup product stores whatever is in the source, and we do not inspect it. So this section is about deliberate use of the service, not about what happens to arrive in a mailbox.

  • Do not use Restorable as a store or distribution point for material you have created or gathered for an unlawful purpose, or for material whose possession is itself unlawful.
  • Malware that is already sitting in a customer's mailbox will be backed up, and that is not a breach of this policy. Deliberately using the service to warehouse or distribute malware is.
  • Do not use the service to circumvent a legal hold, a preservation order, or a disclosure obligation, whether yours or your client's.

5. The platform

  • Do not probe, scan, load test or attempt to breach the service or its infrastructure without our written permission. Ask us first: we would rather hear from you than from an alert. Report anything you find to hello@restorable.cloud.
  • Do not attempt to reach another customer's account, data or keys, and tell us at once if you find that you can.
  • Do not share accounts between people, resell or sublicense access outside the customers you manage, or misrepresent Restorable's features, security model or ownership to your own clients. In particular, do not describe it to a client as zero knowledge; the security page explains the key model accurately.
  • Use the API within reason. Poll no more often than you need, respect rate limits and retry-after responses, use the cursor rather than refetching whole lists, and send an idempotency key where one is accepted. Fair use limits are [API rate limits].
  • Do not use the service in a way that damages Microsoft's tenants or breaches Microsoft's own terms, including running manual backups repeatedly in a way that provokes throttling for a client.

6. Enforcement

If we believe this policy has been breached we will normally contact your account's owners first and give you a chance to put it right. Where there is a real and immediate risk to the service, to another customer, or to anyone's data, we may suspend an account, an API key or a tenant connection straight away and explain afterwards. Serious or repeated breaches are grounds for termination under the terms of service. Suspension does not delete your data, and it does not affect your ability to read your own bucket with your own passphrase and recovery bundle.

Where we are required by law to disclose or preserve information, we will do so, and we will tell you unless we are prohibited from doing so.

7. Reporting a problem

Report suspected misuse, a security issue or content that concerns you to hello@restorable.cloud. Include enough detail that we can act on it.