Responsible Use
Acceptable Use Policy
Rules for using MedSpaOS responsibly, lawfully, and in a way that protects clinics, patients, staff, and the service.
Last updated: September 2, 2026
1. Allowed use
You may use MedSpaOS to manage authorized clinic operations, patient and appointment workflows, staff access, transactions, communications, and approved integrations in accordance with your plan and applicable law.
2. Prohibited conduct
- Accessing another tenant, account, device, or record without authorization.
- Uploading malware, harmful code, unlawful content, or information you do not have the right to process.
- Attempting to probe, scan, reverse engineer, bypass controls, or disrupt the service.
- Using the service for fraud, harassment, discrimination, unlawful surveillance, or deceptive marketing.
- Using AI output as a replacement for qualified clinical judgment or required review.
- Sharing credentials, evading usage limits, or reselling access without written permission.
3. Patient and regulated data
Only authorized personnel may enter or access patient information. Customers must configure role permissions, obtain required notices and consents, follow applicable retention rules, and use approved integrations. Do not place secrets, payment-card data outside supported payment fields, or highly sensitive information in free-text fields unless the workflow is designed for it.
4. Enforcement
We may investigate suspected violations and restrict, suspend, or terminate access when reasonably necessary to protect users, data, or the service, comply with law, or prevent harm. Where practical, we will provide notice and an opportunity to remediate. We may preserve and disclose relevant information when legally required.
5. Reporting
Report suspected abuse, compromised credentials, or security issues to security@medspaos.com. For privacy requests, contact privacy@medspaos.com.
This page is provided for product and operational transparency. It is not legal advice. Have qualified counsel review the applicable agreement before relying on it in a live service.