Acceptable use policy

Last updated 18 Jul 2026 · version 0.2 (draft)

Draft — pending legal review. This wording is a working placeholder and must be approved by counsel for each corridor before launch.

1. Use the platform for referrals only

Accounts exist to create, receive, and manage patient referrals. Using the platform for marketing, recruitment, data harvesting, or any purpose unrelated to a real referral is prohibited.

2. Share the minimum necessary

Attach only the records relevant to the referral. Do not upload records of patients who are not the subject of the case, and do not paste patient-identifying information into fields not designed for it (for example, message subjects or support forms).

3. Keep your account yours

Credentials must not be shared, and multi-factor authentication must not be circumvented. Access on behalf of a colleague — including cover arrangements — requires that colleague’s own account and role.

4. No off-platform workarounds

The platform exists so referrals never travel by email. Exporting case data to personal storage, emailing records to receiving teams, or otherwise routing around the platform’s controls breaches this policy and may breach data-protection law.

5. Security testing

Do not probe, scan, or test the platform’s security without written authorisation. Good-faith vulnerability reports are welcome via the responsible-disclosure route on the security page.

6. Enforcement

Breaches may lead to suspension or closure of the account, notification of the clinician’s employing or registering body where professional obligations are engaged, and — where the law requires — notification of regulators. All enforcement actions are logged.

Questions about this document? Contact LibaMed Ltd, Cardiff, Wales — we aim to respond within two working days.