1Who we are and how to contact us

The Services and the website at oboloo.com are operated by oboloo Limited, a company registered in England and Wales under company number 12420854, with its registered office at 7 Bell Yard, London, WC2A 2JR (“oboloo”, “we”, “us”). Questions about this Policy, and reports under section 13, should be sent to support@oboloo.app.

Back to top

2Who this Policy applies to

2.1This Policy applies to everyone who accesses or uses the Services or the website, including: (a) Customers and their Authorised Users, on the Free Plan or a Plus Plan; (b) Supplier Users accessing the Supplier Portal; (c) anyone connecting to the Services through our API, MCP server or an integration; and (d) visitors to oboloo.com. In this Policy these are all “users” or “you”.

2.2By using the Services or the website you agree to this Policy. If you do not agree, you must not use them. The Services are provided for business use only.

2.3Each Customer is responsible for making sure that its Authorised Users and the Supplier Users it invites comply with this Policy. A breach by a user is treated as a breach by the Customer.

2.4Supplier Users accept this Policy, and the Supplier Portal terms in clause 6.1 of the Terms, by accessing the Supplier Portal.

Back to top

3Related documents

3.1This Policy is one of the Policies that form part of the Agreement between oboloo and each Customer, together with the Terms, the Data Processing Agreement at oboloo.com/dpa and the Privacy and Cookies Policy at oboloo.com/privacy-cookies-policy. If this Policy conflicts with the Terms, the Terms apply.

3.2Our security practices and the public summaries of our internal information security policies are published at oboloo.com/data-and-security.

Back to top

4Definitions

Content
Anything you upload, enter, post or send through the Services or the website, including documents, supplier and contract records, questionnaire responses, sourcing submissions, savings records, messages and comments.
System Abuse
Any action that breaches this Policy or threatens the security, integrity or availability of the Services, including unauthorised access, misuse of resources and interference with operations.
Terms, Services, Customer, Authorised User, Supplier User, Supplier Portal, Free Plan, Plus Plan, AI Features
Have the meanings given in the Terms.
Back to top

5Prohibited uses

You must not use the Services or the website, or allow anyone else to use them, to do any of the following:

  • anything unlawful or fraudulent, or anything that breaches a law, regulation or sanction that applies to you;
  • harm, harass, intimidate, defame or discriminate against any person;
  • upload, store or send Content that infringes a third party's intellectual property, confidentiality or privacy rights, or that you do not have the right to use;
  • send spam, phishing messages, chain letters or unsolicited marketing, including by using supplier invitations, sourcing events or messaging features to contact suppliers for purposes other than the Customer's own procurement;
  • upload or transmit viruses, malware, spyware or any other harmful code;
  • attempt to gain unauthorised access to the Services, our systems, another Customer's Tenant, another user's account or our internal administrative tools, or to bypass any authentication, access control or security measure;
  • carry out penetration testing, vulnerability scanning or load testing of the Services without our prior written consent;
  • launch denial-of-service attacks, overload our infrastructure or interfere with the operation of the Services;
  • use bots, scrapers, crawlers or other automated means to access the Services or extract Content, other than through the API in accordance with section 8;
  • copy, modify, reverse engineer, decompile or create derivative works of the Services, or extract oboloo Content in bulk;
  • use the Services to build, train or improve a competing product, or publish benchmarks of the Services without our written consent;
  • resell, sublicense, rent or otherwise make the Services available to any third party, other than to Supplier Users through the Supplier Portal;
  • share a user account or licence between people, or link an account to a shared or group mailbox;
  • impersonate any person or organisation, or misrepresent your identity, affiliation or authority;
  • avoid or try to avoid fees, usage limits or quotas;
  • use supplier data obtained through the Services for any purpose other than the Customer's own procurement, including selling, licensing or publishing supplier lists;
  • upload special category personal data, criminal offence data or data about children without our prior written agreement;
  • use the Services for any activity where a failure of the Services could lead to death, personal injury or serious physical or environmental damage.
Back to top

6Content standards

6.1All Content must be accurate where it states facts, genuinely held where it states opinions, and lawful in England and Wales and in any country from which it is uploaded or to which it is sent.

6.2Content must not be defamatory, obscene, offensive, hateful or discriminatory; must not promote violence or illegal activity; must not include child abuse material; and must not contain personal data beyond what is needed for the Customer's procurement purposes.

6.3Suppliers' sourcing submissions, pricing and documents are confidential to the sourcing process. Customers must not disclose one supplier's submission to another supplier except as the sourcing event rules or the law allow.

6.4We may review, moderate, restrict or remove Content that we reasonably believe breaches this Policy, and will tell the Customer where practicable. We do not routinely review Content.

Back to top

7Account security

You must:

  • keep your login credentials secret and never share them;
  • use a strong, unique password and enable two-factor authentication, or sign in through Microsoft single sign-on where your organisation has set it up;
  • use your account only as the named individual it was issued to;
  • tell us immediately at support@oboloo.app if you suspect that your account, your credentials or an API key have been compromised;
  • if you are a Customer administrator, keep user roles and permissions current and remove access promptly when a user leaves or changes role;
  • keep the devices, browsers and networks you use to access the Services secure and up to date.
Back to top

8API, MCP server and integrations

8.1Anyone accessing the Services through our API or MCP server must: (a) use unique credentials for each integration and keep API keys confidential; (b) stay within the published rate limits, and accept that we may throttle or suspend access that exceeds them; (c) use HTTPS for all requests; (d) not bypass authentication or access controls; and (e) follow the API Documentation.

8.2If you connect a third-party service to the Services, including an external AI assistant such as ChatGPT, Microsoft Copilot or Claude through our MCP server, you are responsible for that service, for the data you allow it to access, and for your agreement with its provider. Only grant it the access it needs.

8.3Misuse of the API or MCP server may result in immediate suspension of the credentials involved, and further action under section 12.

Back to top

9Fair use

9.1The Services are subject to reasonable fair use limits on storage, file size, email volume, supplier invitations, API calls and similar measures, as described in the Documentation. These limits exist to keep the Services fast and reliable for all Customers.

9.2You must not upload disproportionately large files (for example high-resolution video) without our prior agreement. If you need more storage or capacity, ask us; additional capacity may carry a fee.

9.3Where usage substantially exceeds normal business use for an organisation of your size, we may ask you to reduce it, offer additional capacity for a fee, or apply technical limits after giving notice.

Back to top

10Supplier Portal

10.1Supplier Users must: (a) use only the invitation and authentication code sent to them, and not forward it to anyone else; (b) submit accurate and complete information and documents that they have the right to provide; (c) use the Supplier Portal only to respond to the Customer that invited them; and (d) not use automated tools to submit responses.

10.2The Supplier Portal terms in clause 6.1 of the Terms also apply. We may suspend or remove a Supplier User who breaches this Policy, and will tell the Customer when we do so.

Back to top

11AI Features

Where the Services include AI Features, you must not: (a) use them to generate unlawful, infringing, defamatory or harmful content; (b) attempt to extract our prompts or system instructions, or to manipulate the AI Features into ignoring their instructions or safeguards; (c) input data that you are not permitted to process; or (d) rely on AI output without reviewing it. AI output is a draft for your review, not advice.

Back to top

12Monitoring and enforcement

12.1We may monitor use of the Services, including access logs, usage data and API activity, to operate and secure the Services, to investigate suspected breaches of this Policy and to produce Usage Data. We do not routinely review the content of Customer Data.

12.2Any breach of this Policy is a material breach of the Terms. Depending on the seriousness of the breach we may: (a) ask you to stop or correct the activity; (b) remove or restrict access to Content; (c) throttle or revoke API credentials; (d) suspend a user, a Supplier User or an entire Account under clause 18 of the Terms; (e) terminate the Agreement under clause 8 of the Terms; (f) recover our reasonable costs of investigation and enforcement; and (g) report the matter to law enforcement or a regulator and cooperate with their investigation.

12.3Where practicable we will give notice and an opportunity to put things right before suspending. Where a breach creates an immediate risk to the Services, to other customers or to any person, we may act first and explain afterwards.

Back to top

13Reporting violations and security issues

13.1If you become aware of a breach of this Policy, report it to support@oboloo.app.

13.2If you believe you have found a security vulnerability in the Services, report it to support@oboloo.app with enough detail for us to reproduce it. Do not exploit the vulnerability, access or modify data that is not yours, disrupt the Services, or disclose the issue publicly before we have had a reasonable opportunity to fix it. We will acknowledge good-faith reports within two Business Days and will not take legal action against researchers who follow these rules.

Back to top

14Changes to this Policy

We may update this Policy from time to time in accordance with clause 17 of the Terms. The current version, with its version number and date, is always published at oboloo.com/acceptable-use-policy. Material changes will be notified to Customers by email or within the Services at least 30 days before they take effect.

Back to top

15Legal terms and approval

15.1This Policy forms part of the Terms and is governed by the law of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales, as set out in clause 19.13 of the Terms.

15.2This Policy is owned by the Board of Directors of oboloo Limited and is reviewed at least annually as part of our ISO/IEC 27001 aligned policy set.

VersionDateSummary of changes
4.0October 2026Rewritten to align with Terms of Service version 4.0. Business use only. Plus Plan naming. Supplier Portal, API and MCP server, AI Features and responsible disclosure sections added. Contact updated to support@oboloo.app. Consumer and minors provisions removed.
3.0December 2025Previous version.

Approved by the Board of Directors of oboloo Limited in October 2026. This Policy applies to oboloo.com, oboloo.app and all related subdomains operated by oboloo Limited.

Back to top