Acceptable Use Policy
Last updated: 14 July 2026
1. Purpose
This policy protects HollyHR, its customers and the people whose employment data is held in the service. It applies to every user, account, API key, integration and uploaded file.
2. Use HollyHR lawfully and for legitimate HR work
You must not use HollyHR to break the law, infringe another person's rights, discriminate unlawfully, harass or harm a person, or store content you have no right or lawful reason to process.
HollyHR is HR software, not an employee-surveillance product. Do not use it for covert or disproportionate monitoring, automated employment decisions without appropriate human review, or the collection of personal data unrelated to a legitimate employment purpose.
3. Protect accounts and organisation boundaries
- Keep sign-in links, MFA codes, backup codes and API keys confidential.
- Use the minimum role and API scope needed for the job.
- Do not access, test or attempt to infer another customer's data.
- Do not bypass rate limits, access checks, export controls or security warnings.
- Tell HollyHR promptly if credentials, data or access may have been compromised.
4. Do not attack or disrupt the service
You must not introduce malware, scan or probe without written permission, overload the service, scrape it at a harmful rate, reverse engineer protections, impersonate another user, interfere with logs or use HollyHR infrastructure to attack another service.
Good-faith security research must be agreed in writing before testing. Contact info@hollyhr.com with the proposed scope.
5. Uploaded files and communications
Do not upload malicious files, unlawful content, third-party confidential material without authority, or special-category data that your organisation has no documented purpose for holding. Do not use HollyHR messages, invitations or integrations for spam, phishing or deceptive communications.
6. APIs, webhooks and AI tools
API keys and connected AI tools must respect the same permissions and purposes as a human user. Do not use automated access to build an unauthorised employee database, make unreviewed high-impact employment decisions, extract data for model training without a lawful basis, or copy HR data into a destination that your organisation has not assessed.
You remain responsible for reviewing automated output and for the security and data handling of systems you connect to HollyHR.
7. Fair use and enforcement
Usage must stay within published plan limits and reasonable service-protection limits. HollyHR may rate-limit, restrict or suspend activity where reasonably necessary to protect people, customers or the service. Where practicable, we will explain the issue and allow it to be corrected before termination.
Serious illegality, deliberate security abuse or immediate risk may require action without advance notice. Enforcement under this policy does not limit rights in the Terms of Service.
8. Questions and reports
Report suspected abuse or a security issue to info@hollyhr.com using the prefilled security subject. General questions can go to info@hollyhr.com.