Acceptable Use Policy

What Kiko may and may not be used for. It applies to every user in your workspace, including administrators.

Last updated 1 September 2026

Kiko is a demonstration product. This document is written as a realistic sample and is not a binding agreement. Do not rely on it as legal advice.

1. Scope

This policy applies to everyone who signs in to a Kiko workspace, to anything uploaded into one, and to any use of our APIs and exports. It sits alongside the Terms and Conditions; where a term there is stricter, the stricter one applies.

Your organisation is responsible for the conduct of its users. Passing this policy on to administrators and to anyone given a payroll or people data role is the practical way to meet that responsibility.

2. Data you may not put into a workspace

Kiko is built for employment records. Some categories of data need protections this platform does not claim to provide, and some you may simply have no lawful basis to hold.

  • Personal data you have no lawful basis to process, including data about a person with no employment or candidate relationship to your organisation.
  • Payment card numbers. Kiko is not a cardholder data environment and must not be used as one.
  • Health records beyond what a leave, insurance or statutory filing actually requires.
  • Government identifiers belonging to people outside your workforce.
  • Material that is unlawful to hold, or that you are under an order to destroy.

3. Conduct that is not allowed

The following will be treated as misuse of the service.

  • Attempting to reach another organisation's workspace, or any record your role was not granted.
  • Sharing a login. Named accounts are what make the audit trail meaningful.
  • Circumventing approval steps, period locks or maker and checker separation, including by editing data directly through an integration to avoid a control.
  • Scraping, bulk harvesting or re-selling data about people in the workspace.
  • Uploading malware, or using the service to distribute it.
  • Load testing, scanning or penetration testing without our written permission. See the Security page for how to arrange it.

4. Monitoring boundaries

Attendance, location and device signals exist so that time and pay can be calculated correctly. They are not a surveillance product.

Do not use Kiko to track employees outside working hours, to infer protected characteristics, to build a covert performance file a person cannot see, or to monitor anyone who has not been told that monitoring happens. Several of these are unlawful in the jurisdictions we operate in, independently of this policy.

Where the platform records a location or a device, the employee can see the same record you can. That is deliberate and we will not remove it on request.

5. Fair use of APIs and exports

Rate limits, export size caps and concurrency limits protect everyone on shared infrastructure. Work within them rather than around them.

If a legitimate integration needs more headroom, ask us and we will raise the limit or give you a better shaped endpoint. Rotating credentials to multiply an allowance is misuse.

6. Enforcement

Where we can, our first step is to tell your administrator and give you a chance to put it right. We would rather fix a misconfigured integration than suspend an account.

Where the service or other customers are being actively harmed, or where we are obliged to act, we may suspend the account or the specific capability first and explain immediately afterwards. Suspension for misuse does not entitle you to a refund for the suspended period.

7. Reporting misuse

If you believe a Kiko workspace is being used against this policy, write to abuse@kiko.co. Include the workspace, what you observed and when. We acknowledge within one business day.

Still have a question?

Bring it to the demo and we will answer it on the call, or write to legal@kiko.co.

Book a demo