Acceptable Use Policy
What you and the people you invite may not do with the platform.
- Version
- 0.8
- Effective date
- Not set — in force for the pilot
- Source
- legal/ACCEPTABLE_USE_POLICY.md
DocSync — Acceptable Use Policy
⚠️ PRE-RELEASE DRAFT — NOT LEGAL ADVICE — NOT SETTLED BY AN AUSTRALIAN LAWYER
What this is. A pre-release draft, written by an engineering process from a factual audit of the DocSync codebase. Not reviewed or settled by an Australian legal practitioner, and not legal advice to anyone. There is no registered company name, ABN, ACN or registered address yet: the bracketed placeholders are real gaps, listed at the end.
And it is nonetheless live, which is why the paragraph above matters. This policy forms part of the Terms of Service, which every user must tick a box to accept before an account is created, so it binds through them; and it is served, without a login, at
docsync.tech/legal/acceptable-use.What happens next. A settled version will be issued once an Australian legal practitioner has reviewed this pack and every placeholder is filled, and everyone will be asked to accept that version. Until then, and this is a rule we hold ourselves to rather than an instruction to you: we will not put this document into a tender or present it as a settled commercial commitment.
Document version: 0.8 · Effective date: [EFFECTIVE DATE]
This policy forms part of the DocSync Terms of Service. Defined words have the meaning given in those Terms. It is short on purpose — a policy nobody reads protects nobody.
In one line: use DocSync to run your jobs, not to break the law, break the platform, or get at somebody else's data.
Changes to this policy. We give you at least 30 days' written notice before a change to this policy, the same as for any change to the Terms of Service, and if a change materially and adversely affects you, you may terminate before it takes effect and we will refund the unused portion of anything you have prepaid. See Terms of Service §12.
1. Who this applies to
You, and every User you invite — your staff, your subcontractors, your consultants, anyone you add to a project or the directory, and anyone using a share link you created. You are responsible for what they do in your account.
2. The rules
2.1 Nothing illegal
Do not use DocSync to store, send, or do anything unlawful. That includes content that is defamatory, harassing, or that breaches somebody's intellectual property, confidence or privacy.
2.2 No malware
Do not upload, link to, or transmit malicious code — viruses, ransomware, trojans, web shells, crypto-miners, or anything designed to disrupt, damage, or gain unauthorised access to a computer system. DocSync does not scan uploads for malware. If you upload an infected file it will sit in your project and it will be there when your colleague downloads it.
2.3 Never try to reach another customer's data
Do not attempt to access, probe, enumerate or interfere with any company account, project or record that is not yours. Do not attempt to escalate your own permissions, forge or replay a token, or bypass a permission check.
A note on how the platform behaves, so nobody thinks a probe is harmless research: DocSync returns "not found" for anything you are not entitled to see — never "forbidden". A record in another customer's account and a record that has never existed look identical to you. That is deliberate: it stops the platform leaking whether something exists. It also means you can learn nothing useful by probing, and every attempt is recorded. Do not try.
2.4 No security testing without permission
Do not run vulnerability scanners, penetration tests, fuzzers, credential-stuffing tools or load tests against DocSync without our prior written consent. If you find a security problem, tell us at [SECURITY CONTACT EMAIL] — we would rather hear it from you than from an attacker, and we will not pursue anyone who reports a genuine issue in good faith and does not exploit it.
2.5 No scraping or bulk extraction outside the documented API
Use the web application, or the documented API described in the OpenAPI specification published by the Service. Do not scrape pages, drive the application with a browser automation tool to extract data in bulk, or run automated requests at a volume that degrades the Service for anyone else.
You do not need to scrape. There is a supported way to get everything out: a company owner can run a full export from Company settings → Data & privacy → Export, which produces every record, every table and, if you ask for them, every file. Use that.
2.6 No reselling, no reverse engineering
Do not resell, sublicense, rent, timeshare, or provide DocSync as a service to anyone outside your business. Do not publish a benchmark or comparative performance test of the Service without our consent, not to be unreasonably withheld. Do not copy, decompile, disassemble or reverse engineer the Service, except to the extent the law says you may despite this clause.
Inviting your own subcontractors, consultants and clients to work on your projects is normal use and is not reselling.
What this means, and what it does not: you are a construction business. Nothing here stops you building your own software, or evaluating DocSync against something else and deciding internally. The only thing we ask is that you do not publish a performance comparison without talking to us first — and we will not unreasonably refuse. The reverse-engineering carve-out is there on purpose: Australian copyright law gives you rights to interoperate and to correct errors, and this clause does not take them away.
2.7 Do not present AI output as professional certification
DocSync's AI features produce drafts — there are eight of them: an assistant answer, an RFI draft, a defect-resolution note, an RFI chase note, a transmittal chase note, a submittal escalation note, a project-health summary and a weekly review. They are text a human is expected to read, correct and then save. (They are switched on in the pilot deployment today. If your company has AI switched off, this rule applies from the moment an owner switches it on.)
Do not present AI-generated content as a certification, a sign-off, a compliance statement, an inspection result, engineering advice, or the professional opinion of a licensed person. Do not put AI output into a compliance certificate, an ITP hold-point release, an electrical, façade, steel, lot or pour certificate, a handover dossier, or any statutory notice, unless an appropriately qualified human has read it, agrees with it, and is signing it as their own work.
Why this is in a use policy and not just a disclaimer: if an AI-drafted sentence ends up in a certificate a certifier signs, the certifier owns it. Make sure the certifier actually read it.
2.8 Look after other people's personal information
DocSync holds more personal information than most construction software, and some of it is sensitive. Before you put it in, make sure you are entitled to.
- Injury and health records. The Service records a named person's injury, which part of their body was hurt, the nature of the injury, whether they received medical treatment or died, and how many days they were off work. *That is health information and it is sensitive information under the Privacy Act 1988 (Cth).* There is no separate permission level for it — anyone with access to the incidents tool can read it.
What we actually recommend, given what DocSync does not yet have. Until there is multi-factor authentication, encryption at rest and off-site encrypted backups, keep injury detail in DocSync to the minimum your WHS obligations require, restrict the Incidents tool to the smallest possible group, and hold any medical certificate, diagnosis or treatment record outside DocSync. This is stronger than "set your permissions accordingly" because the facts are stronger: there is no multi-factor authentication for anyone including us, nothing is encrypted where it is stored, and the only backup sits on the same server as the thing it backs up. Those are disclosed in the Terms of Service §15 and they are the reason for this advice.
- People who never signed up. Witness statements, site visitor logs, safety violations issued against a named person, vendor contacts, share-link recipients and external signers are all records about identifiable people who have no DocSync account and no way to be told. Telling them, where the law requires it, is your job.
- Photos and video of people. Site photos routinely capture faces, vehicle plates and whiteboards with names. The blur tool in photo markup is an overlay, not a redaction — it is drawn over the image for display and export, and the original file is preserved byte-for-byte with the face fully visible, including in an export. If a face must actually be removed, do it before you upload. Photos also retain their original camera metadata, which can include GPS coordinates and device identifiers.
- Timesheets. Hours, approvals, approval notes and applied pay rates are employment records about named individuals. Under s 535 of the Fair Work Act 2009 (Cth) you must keep employee records for seven years. Export them before you delete a DocSync account — a deletion destroys them seven to eight days after the request.
2.8A Photograph location data may be workplace surveillance
Read this one if your workers take photos on their phones.
When a photo is uploaded, DocSync extracts the GPS coordinates the camera wrote into the file, stores them as ordinary columns on the photo record, and can plot the photo on a map. That is capable of being tracking surveillance of an employee, because it records where a named person was and when.
Surveillance of employees is regulated separately from privacy law, and the rules differ by State. In New South Wales, tracking surveillance of an employee under the Workplace Surveillance Act 2005 (NSW) requires at least 14 days' prior written notice to the employee and a notice on the device being tracked; Victoria and other States have their own surveillance-devices legislation. The site walkthrough video feature raises the same question for optical surveillance.
DocSync does not manage any of this for you, does not know who your employees are, and does not send any notice. You must satisfy yourself that you are permitted to collect and use this information, and give whatever notice the law in your State requires, before you rely on it.
If you would rather not have it at all: strip location data from photos before uploading, or turn location services off on the site phones.
2.9 Do not put things in that should not be there
Custom fields and free-text notes will accept anything you type. Do not put in:
- passwords, API keys, or any other credential;
- tax file numbers, Medicare numbers, or credit-card or bank-account numbers;
- health information about anyone other than in the incident/injury tools designed for it;
- anything you would not want appearing in an export, a CSV, a PDF, an email notification, or a record produced to an adjudicator.
Free text ends up in more places than you expect — exports, PDFs, emailed notifications and scheduled reports, and, where AI features are switched on for your company, in a prompt sent to an overseas AI provider. AI features are switched on in the pilot deployment today, so free text does reach an overseas provider when someone uses one of those features. Automatic redaction removes email addresses, Australian phone numbers and ABN-shaped numbers before a prompt is sent, and it cannot recognise a person's name, an address, or free text generally.
2.10 Share links are a credential — treat them like one
An external share link gives anyone holding it read access to a project's progress, photos, documents and drawings, without signing in, until it expires or you revoke it. It is normally sent by ordinary unencrypted email. Do not post one publicly, do not use one as a substitute for giving somebody an account, and revoke the ones you no longer need.
2.11 Do not overload or interfere
Do not deliberately degrade the Service: no denial-of-service, no request floods, no attempts to exhaust storage, no interference with any other customer's use. Sign-in and password reset are rate limited; do not try to work around it.
There is currently no per-account storage quota. Do not treat that as an invitation to use DocSync as bulk file storage unrelated to your projects.
2.12 Email and messaging
Do not use DocSync's notification, share, invite or scheduled-report features to send spam, marketing, or anything else that would breach the Spam Act 2003 (Cth). Only invite people who expect to hear from you about a project.
2.13 No impersonation
Do not create an account or a directory contact in someone else's name, sign a record as someone else, or misrepresent who you are or who you act for. Signatures, sign-offs and approvals in DocSync are recorded against a person and chained into a tamper-evident ledger; they are meant to be evidence.
3. What happens if the rules are broken
We would rather fix a problem than switch you off. The normal process is:
- We tell you. Written notice describing the conduct, the clause it breaches, and what needs to change.
- You get 7 days to fix it. (Shorter if the breach is serious and continuing — we will say how long and why.)
- If it is not fixed, we may suspend the affected User, the affected feature, or the account. We will suspend the narrowest thing that solves the problem — one User or one feature before the whole account.
Suspension is not deletion. Your data is not touched, and your export right continues. If suspension stops you running an export yourself, ask and we will run one for you.
The emergency exception
We may suspend immediately, without notice, only where we reasonably believe it is necessary to:
- stop an imminent and serious risk to the security or integrity of the Service or another customer's data;
- stop material harm to a person; or
- comply with a law, court order or regulator direction.
If we do, we will tell you as soon as reasonably practicable and in any event within 24 hours, explain why, and work with you to restore service as quickly as we safely can. Where we have told you in advance of a period during which the operator is unavailable, that period does not count towards the 24 hours and we will tell you within 24 hours of the operator's return — and we will not use that carve-out to delay a notification we are able to make.
If you think we got it wrong
Email [CONTACT EMAIL]. The dispute process in the Terms of Service applies, and we will restore access as soon as the cause is resolved. We will not use a suspension as leverage in a commercial dispute.
4. Reporting
- Security issues: [SECURITY CONTACT EMAIL]
- Misuse of the Service, or content that breaches this policy: [CONTACT EMAIL]
- Privacy concerns: see the Privacy Policy at
docsync.tech/legal/privacy
Placeholder register
| Placeholder | What it is | Notes |
|---|---|---|
[EFFECTIVE DATE] | Date this version takes effect | |
[CONTACT EMAIL] | General contact and misuse reports | Must be monitored; not a no-reply@ address |
[SECURITY CONTACT EMAIL] | Security reports | Does not exist yet — there is no security.txt and no published vulnerability disclosure policy |
The contracting entity is referred to as "we" throughout; it is named in the Terms of Service as [LEGAL ENTITY NAME]. No corporate name, ABN, ACN or address has been inferred from the product name "DocSync" or the domain docsync.tech.
Notes for the reviewing lawyer
- There is no automated suspension mechanism in the software. There is no
suspendedflag on a company and no payment gate. A suspension today is a manual operator action. The right is reserved in §3, but §3 describes a process a person performs, not a product feature. - §2.5 "documented API" means the OpenAPI specification the API publishes and the generated TypeScript client in
packages/api-client. There is no published rate limit for ordinary API use. Rate limiting is applied to sign-in, registration, token refresh, password reset, the deep health check, the public share surface and the member/invite surface, among others — this list is not exhaustive and the word "only" that stood here previously was wrong. If a customer asks "what is the limit" for ordinary API use, there is not one to quote. - §2.8 photo blur is grounded: photo markup is rendered as a composite over the original and is never baked into it, and the original blob's content hash is deliberately kept byte-identical for evidentiary reasons. The original, unblurred image is what a tenant export contains. This is correct for evidence and dangerous for anyone who believes they redacted a face, so it is stated as a use rule rather than buried in a privacy policy.
- §2.3 relies on the platform-wide rule that cross-tenant access returns 404, never 403.
- §2.7 is grounded in the fact that AI output is never persisted or auto-saved: the draft service writes no rows, and every AI surface returns text a human edits and saves through the tool's own form.
- Unfair contract terms: §3 is drafted with notice, a cure period, proportionality, a narrowly scoped emergency exception with a 24-hour tell-you obligation, and a preserved export right, specifically because a broad unilateral suspension right in a small-business standard-form contract is the kind of term the regime reaches.
- §2.6 was narrowed in this revision. It previously read "do not use it to build or benchmark a competing product" — imported US SaaS boilerplate. A restraint on a construction company's ability to build software serves no interest of ours that confidentiality and intellectual property do not already serve, and a broad restraint on a small business in a standard-form contract is the shape the unfair-contract-terms regime targets. The reverse-engineering carve-out is unchanged: it correctly preserves ss 47B–47F of the Copyright Act 1968 (Cth).
- §2.8A (photograph location data) is new and is grounded in the product: EXIF GPS is extracted on upload, stored as first-class columns on the photo record, and plotted on a map. That is capable of being tracking surveillance of an employee. The obligation is allocated to the customer here because DocSync does not know who anybody's employees are and sends no notice; the Workplace Surveillance Act 2005 (NSW) is the strictest of the State regimes and is the one named.
- §2.8's health-information advice was strengthened from "set your permissions accordingly" to concrete advice, because the underlying facts — no multi-factor authentication, nothing encrypted at rest, the only backup on the same disk — are stronger than the original wording admitted. Two product changes would move this further than any drafting can: an elevated permission tier for injury sub-records, and a consent flag on the injury record. Neither is built.
End of draft. Prepared for review by an Australian legal practitioner. Nothing in this document has been sent, published, executed or committed.