Policies
Acceptable Use Policy
Automation makes whatever you point it at happen faster. This page sets out what we will build, what we won't, and the conditions attached to systems we deliver.
1. Who this applies to
This policy applies to everyone who uses this website, and to every client engagement. It forms part of our Terms of Service. It exists because the systems we build act at scale and without hesitation, which makes the question of what they are pointed at a real one.
2. What we will not build
We decline engagements — including profitable ones — that involve:
- Deception about automation. Systems designed to make an automated agent pass as a specific real person, or to deny being automated when asked.
- Unsolicited contact at scale. Cold calling, texting or emailing people who have not consented and have no existing relationship with the client, or contact that ignores do-not-call and suppression registers.
- Impersonation. Systems that imitate another business, a public body, a financial institution or a named individual.
- Fraud and manipulation. Anything intended to obtain money, credentials or personal data by deception, including fabricated reviews, testimonials, records or receipts.
- Unlawful surveillance. Monitoring of employees, customers or the public that is unlawful in the relevant jurisdiction, or covert monitoring without required notice.
- Automated decisions with serious consequences and no human in the loop. Decisions on credit, insurance, employment, housing, benefits, immigration status or clinical care taken by a system with no meaningful human review or route to challenge.
- Circumventing controls. Bypassing security measures, scraping in breach of terms or applicable law, defeating rate limits, or evading platform enforcement.
- Discriminatory targeting. Systems that select or exclude people on the basis of protected characteristics where that is unlawful.
- Harassment or abuse. Automation used to intimidate, threaten, dox or repeatedly contact someone who has asked it to stop.
- Regulated activity we are not qualified for. Systems presenting themselves as giving legal, financial, tax, insurance or medical advice.
- Prohibited sectors. Work for businesses whose primary activity is unlawful in the relevant jurisdiction, or which we are prohibited from serving under sanctions or by our own providers' terms.
If a request falls into one of these categories, we say so plainly and decline. We will usually suggest a lawful alternative that achieves the legitimate part of the objective, where one exists.
3. Conditions attached to what we deliver
Systems we build are delivered on the basis that you will:
- Use them only for the purpose described in the statement of work
- Comply with the laws applying to your sector and jurisdiction, including data protection, marketing, employment and consumer law
- Comply with the terms of the third-party platforms the system depends on
- Retain the human oversight steps built into the system rather than removing them
- Not repurpose the system for an activity in section 2
4. Automated communications
Where we build a system that speaks or writes to people, we build in as standard:
- Disclosure. The system identifies itself as an automated assistant at the start of the interaction and confirms it if asked directly.
- A route to a human. A caller or user can always reach a person, and the system does not obstruct that request.
- Opt-out handling. Requests to stop being contacted are recorded and honoured across channels.
- Consent-aware contact. Outbound contact runs only against lists you confirm have a lawful basis, with suppression lists applied.
- Recording notice. Where calls are recorded or transcribed, the required notice is given.
These are not optional extras and we do not remove them on request.
5. Human oversight
For any step with a financial, contractual, legal or safety consequence, we design an approval gate so a person confirms before the action is taken. Examples include posting a financial entry, sending a contractual commitment, issuing a refund, or changing a customer's account status.
You may ask us to design a fully automated variant where the risk genuinely is low, and we will discuss it. We will not remove an oversight step simply to increase throughput on a process where an error is expensive to reverse.
6. Data you provide
When you give us access to systems or supply data for testing, you confirm that you have the authority to do so and a lawful basis for us to process it for the agreed purpose. Please do not send us special category data, credentials belonging to individuals, or third-party confidential information unless it has been agreed in the engagement and covered by a data processing agreement.
7. Use of this website
You may not use this website to transmit malicious code, attempt unauthorised access, probe or scan the infrastructure, place excessive automated load on it, or submit enquiries that are fraudulent, abusive or unlawful.
8. Enforcement
If we become aware that a system we built is being used in breach of this policy, we will raise it with you and give you a reasonable opportunity to correct it. Where the breach is serious or is not corrected, we may suspend support, decline further work and terminate the engagement in accordance with our Terms of Service. Where the law requires it, we will report the matter to the relevant authority.
Termination for breach of this policy does not entitle you to a refund of fees for work already delivered and accepted.
9. Reporting a concern
If you believe a system we built is being misused, or you have received automated contact you consider improper, please tell us: info@steelbridge-solutions.com. We investigate every report and respond within 5 business days.
If you have identified a security vulnerability in something we operate, please report it to the same address and give us a reasonable opportunity to fix it before disclosing it publicly. We will not pursue action against good-faith security research that respects user privacy and avoids service disruption.