Skip to main content
FeaturesComparePricingGuidesSecurity
Sign inJoin the list →
FeaturesComparePricingGuidesSecuritySign inJoin the list →

Acceptable Use Policy

Last updated: 14 July 2026

1. Purpose

This policy protects HollyHR, its customers and the people whose employment data is held in the service. It applies to every user, account, API key, integration and uploaded file.

2. Use HollyHR lawfully and for legitimate HR work

You must not use HollyHR to break the law, infringe another person's rights, discriminate unlawfully, harass or harm a person, or store content you have no right or lawful reason to process.

HollyHR is HR software, not an employee-surveillance product. Do not use it for covert or disproportionate monitoring, automated employment decisions without appropriate human review, or the collection of personal data unrelated to a legitimate employment purpose.

3. Protect accounts and organisation boundaries

  • Keep sign-in links, MFA codes, backup codes and API keys confidential.
  • Use the minimum role and API scope needed for the job.
  • Do not access, test or attempt to infer another customer's data.
  • Do not bypass rate limits, access checks, export controls or security warnings.
  • Tell HollyHR promptly if credentials, data or access may have been compromised.

4. Do not attack or disrupt the service

You must not introduce malware, scan or probe without written permission, overload the service, scrape it at a harmful rate, reverse engineer protections, impersonate another user, interfere with logs or use HollyHR infrastructure to attack another service.

Good-faith security research must be agreed in writing before testing. Contact info@hollyhr.com with the proposed scope.

5. Uploaded files and communications

Do not upload malicious files, unlawful content, third-party confidential material without authority, or special-category data that your organisation has no documented purpose for holding. Do not use HollyHR messages, invitations or integrations for spam, phishing or deceptive communications.

6. APIs, webhooks and AI tools

API keys and connected AI tools must respect the same permissions and purposes as a human user. Do not use automated access to build an unauthorised employee database, make unreviewed high-impact employment decisions, extract data for model training without a lawful basis, or copy HR data into a destination that your organisation has not assessed.

You remain responsible for reviewing automated output and for the security and data handling of systems you connect to HollyHR.

7. Fair use and enforcement

Usage must stay within published plan limits and reasonable service-protection limits. HollyHR may rate-limit, restrict or suspend activity where reasonably necessary to protect people, customers or the service. Where practicable, we will explain the issue and allow it to be corrected before termination.

Serious illegality, deliberate security abuse or immediate risk may require action without advance notice. Enforcement under this policy does not limit rights in the Terms of Service.

8. Questions and reports

Report suspected abuse or a security issue to info@hollyhr.com using the prefilled security subject. General questions can go to info@hollyhr.com.

Holly

Simple, modern HR for small UK teams. Free to start, fair as you grow, easy to leave.

Product

Time offWho's awayPeople recordsDocumentsOnboardingPricingAI & API

Compare

vs Breathevs CharlieHRvs Sense HRvs Sage HRvs BambooHRBest HR software UK

Solutions

For foundersFor HR managersFor office managersUp to 10 peopleFrom spreadsheetsFor payroll bureauxFor accountants

Resources

GuidesTemplate checklistsFree UK toolsHR glossaryBlogHelp & contact

Company

Why HollyHRSecurityNo lock-inAboutRequest a walkthroughEarly access
© 2026 HollyHR · Built for small UK teamsPrivacyTermsDPASub-processorsCookies