Acceptable use policy
Version 2026-08-27 · Effective 27 August 2026
This policy forms part of our Terms of service. It applies to every user of a SchoolRota portal. Breaching it can lead to suspension or revocation of your tenant.
Use the service for school operations
SchoolRota is licensed for managing duty rotas, lesson cover, and related operations for the organisation named in your Order. Do not use it to run services for another organisation, resell access, or provide a bureau service, unless we have agreed that in writing.
Prohibited content and conduct
You must not use the service to:
- break any law, or infringe anyone's intellectual property, privacy, or other rights;
- harass, bully, threaten, defame, discriminate against, or endanger any person, including using rota allocation to victimise a member of staff;
- upload unlawful, obscene, or abusive material, or malware, or content unrelated to school operations;
- store special category personal data, medical records, safeguarding disclosures, or pupil records in free text fields. The service is not designed or hardened for that purpose. Use your MIS or safeguarding system instead;
- upload personal data you have no lawful basis to process, or personal data of anyone who is not a member of your staff or a person you engage to carry out duties;
- impersonate another person, organisation, or school, including in a subdomain or display name;
- send unsolicited bulk email through the service, or use notification features for marketing.
Security
You must not:
- attempt to access another tenant's data, another user's account, or any part of our systems you have not been granted access to;
- probe, scan, or test the vulnerability of the service, or defeat authentication or rate limiting;
- run penetration or load testing without our prior written consent. If you want to test, contact security@schoolrota.com and we will agree a scope and window;
- share credentials, tokens, API keys, or unauthenticated PDF or calendar links outside your organisation;
- introduce malware, or use the service to stage an attack on any third party.
If you find a security issue, please report it responsibly to security@schoolrota.com rather than publishing it, and give us a reasonable opportunity to fix it.
Fair use, automation, and APIs
- Use the APIs and integrations we publish. Do not scrape the interface, drive it with headless browsers, or bulk-extract data by automated means.
- Do not place unreasonable load on the service, bypass rate limits, or run automated jobs at a frequency that degrades performance for other tenants.
- Do not create accounts or duplicate tenants to work around seat limits or trial limits.
- Do not use the service, or data or output from it, to train or evaluate machine learning models, or to build a competing product.
Notifications and exports
Rota PDFs, calendar feeds, and email digests are intended for staff at your organisation. Treat links as confidential, rotate them if they are shared beyond your staff, and remove leavers promptly so notifications stop.
How we enforce this policy
If we believe this policy has been breached we may remove content, restrict a feature, suspend a user, or suspend or revoke the tenant, as set out in section 10 of the Terms of service. Where practical we contact the account owner first and give a chance to fix the problem. We act without prior notice where there is a risk to any person, to other customers, or to the security of the service, or where the law requires it.
Reporting a problem
Report misuse to hello@schoolrota.com, or security issues to security@schoolrota.com.