Acceptable Use Policy

Version 1.0 · Issued September 2026

Account security, prohibited use, data hygiene, API conduct and communications sent through the platform.

Document Acceptable Use Policy, version 1.0
Published at rentalize.com/legal/aup
Status Incorporated into the Master Subscription Agreement by clause 1.3. A breach of this policy is a breach of clause 10.5 of that agreement
Applies to The Customer, its personnel, its permitted Affiliates, and every person to whom the Customer grants access to the platform, including landlords, tenants and contractors
Applies from The date of the Order Form

This policy exists because the platform is multi-tenant. What one customer does on shared infrastructure can affect every other customer on it. The rules below are the minimum needed to keep that from happening. They are not a general code of conduct and they do not restrict ordinary business use.

1. Status and changes

1.1 This policy is incorporated into the Master Subscription Agreement by clause 1.3 of that agreement. Capitalised terms not defined here carry the meaning given there.

1.2 Rentalize may issue a new version on 30 days written notice in accordance with clause 1.4 of the Master Subscription Agreement. No new version reduces the service the Customer receives or increases the Charges.

1.3 Where this policy conflicts with the Master Subscription Agreement, that agreement prevails.

2. The Customer is responsible for its users

2.1 The Customer is responsible for compliance with this policy by everyone it grants access to, including its own personnel, any Affiliate listed in the Order Form, and the landlords, tenants and contractors who use the portals.

2.2 The Customer shall bring the substance of this policy to the attention of its personnel, and shall make it available to portal users through its own terms of use.

2.3 The Customer shall notify Rentalize promptly on becoming aware of any breach of this policy, whether by its own personnel or by a portal user.

3. Account security

3.1 User accounts are personal to the individual. Credentials shall not be shared, and generic or shared accounts shall not be created for groups of people.

3.2 The Customer shall remove or disable accounts for individuals who leave its employment or who no longer require access, within 5 Working Days.

3.3 The Customer shall not disable, circumvent or attempt to circumvent multi-factor authentication, session controls, password policy or any other security feature of the platform.

3.4 The Customer shall notify Rentalize immediately on becoming aware of any actual or suspected compromise of an account, and shall cooperate with the resulting investigation.

3.5 Access shall be granted on the principle of least privilege, and the Customer shall review its own user list and permissions at least annually.

4. Prohibited use

The platform shall not be used to:

  • store, process or transmit material that is unlawful, defamatory, obscene, harassing, or that infringes the intellectual property or privacy rights of any person
  • send unsolicited commercial communications in breach of applicable law, including the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011
  • send communications that impersonate any person, or that misrepresent their origin
  • store or transmit malicious code, or anything designed to disrupt, damage or gain unauthorised access to any system
  • attempt to gain unauthorised access to the platform, to its underlying infrastructure, to any other customer’s data, or to any account the user is not entitled to use
  • circumvent access controls, tenancy separation, usage limits, rate limits or metering
  • carry out load testing, penetration testing, vulnerability scanning or any other security testing without prior written consent, which Rentalize will not unreasonably withhold and will normally grant subject to an agreed window and scope
  • resell, sub-licence or otherwise make the platform available to any person other than as permitted by clause 3.1 or 3.6 of the Master Subscription Agreement
  • use the platform to provide a service to a third party whose properties the Customer does not manage
  • process personal data for purposes unrelated to the management of the properties in the Customer’s portfolio
  • do anything restricted by clause 15.7 of the Master Subscription Agreement, which protects the design, data model, workflows and other know-how embodied in the platform

5. Data hygiene

5.1 The Customer shall not upload special category data or criminal offence data into free text fields where a structured field is provided for the purpose.

5.2 The Customer shall not use the platform as a general document repository for material unrelated to the properties, tenancies and parties it manages.

5.3 The Customer shall not upload data it has no lawful basis to process, or that it has obtained in breach of any obligation owed to a third party.

5.4 The Customer shall apply its own retention policy using the platform’s archiving and deletion functionality. Rentalize does not determine retention periods for Customer Data.

6. API, integrations and automation

6.1 API access is subject to the fair use allowances stated in the Order Form. Where an allowance is exceeded, clause 11.4 of the Master Subscription Agreement applies: the excess is charged at cost or proportionate rate limiting is applied. The platform is not suspended for exceeding a fair use allowance.

6.2 API credentials shall be treated as confidential, shall not be embedded in client side code or in any publicly accessible repository, and shall be rotated promptly where compromise is suspected.

6.3 Automated scripts shall respect published rate limits, shall back off on error responses rather than retrying immediately, and shall not poll more frequently than the documented guidance.

6.4 The Customer shall not use the API, or any automated process, to extract the platform’s structure, schema or content systematically, otherwise than to export its own data.

6.5 Third party tools connected to the platform by the Customer are the Customer’s responsibility. Rentalize may require disconnection of any integration that in its reasonable opinion threatens the security, integrity or performance of the platform.

7. Communications sent through the platform

7.1 The Customer is the sender of every email, SMS and portal message generated from its account, and is responsible for its content and for compliance with applicable law.

7.2 The Customer shall not use the platform for bulk marketing to recipients who are not its tenants, landlords, contractors or applicants.

7.3 The Customer shall honour opt outs and shall maintain accurate contact data. Persistent high bounce or complaint rates threaten the sending reputation of the shared infrastructure, and Rentalize may require corrective action.

8. What happens on a breach

8.1 Rentalize will normally raise a suspected breach with the Customer, describe what it has seen, and agree corrective action. Most matters under this policy are resolved that way.

8.2 Where a breach threatens the security, integrity or availability of the platform for the Customer or for any other customer, Rentalize may suspend the account or an individual user account under clause 12.8 of the Master Subscription Agreement. Suspension is limited in scope and duration to what is necessary, notification is immediate, and access is restored as soon as it is safe to do so.

8.3 A material breach of this policy is a material breach of the Master Subscription Agreement for the purposes of clause 18.2 of that agreement.

8.4 Liability arising from a breach of this policy by the Customer is not subject to the cap at clause 17.6 of the Master Subscription Agreement, in accordance with clause 17.7(c).

8.5 Where Rentalize is required by law to preserve or disclose material, or to report a matter to a regulator or law enforcement body, it will do so and will notify the Customer unless prohibited.

9. Reporting

Security concerns, suspected vulnerabilities and suspected misuse should be reported to [email protected]. Rentalize acknowledges a report within one Working Day and will not pursue any claim against a person who reports a vulnerability in good faith, does not access or alter data beyond what is necessary to demonstrate it, and does not disclose it publicly before a fix is available.

Version history

Version Date Change
1.0 September 2026 Initial issue, replacing the acceptable use clause previously carried inside the master agreement

Questions about this document

This document is published so that it can be read before an Order Form is signed and referred to at any time afterwards. The version stated in a signed Order Form is the version that applies to that customer for its initial term, and superseded versions stay available at the same address.

Rentalize Software Limited

Email: legal@rentalize.com