LEGAL & COMPLIANCE
Licences & permitted use
Draft for counsel review · Last updated 24 September 2026
1. Who this guide is for
This guide applies to institutions, administrators, staff, learners, guardians, implementation partners, contractors, integration providers and other third parties who access, configure, connect to or use InstiServe. Your organisation is responsible for authorising your account and assigning the right role and permissions.
2. Licence to use InstiServe
Subject to an active subscription or other written agreement, InstiServe grants the authorised customer a limited, non-exclusive, non-transferable, non-sublicensable and revocable right to access and use the platform during the agreed term for the customer's internal educational and administrative purposes. Individual users may use InstiServe only for the institution or organisation that authorised them.
No ownership in the platform, source code, models, documentation, branding or other InstiServe intellectual property is transferred to a user or customer.
3. Permitted educational use
- Manage authorised admissions, teaching, assessment, records, finance, communication and student-service workflows.
- Upload and process content that you own, are licensed to use, or are otherwise legally permitted to process.
- Invite approved users, assign least-privilege roles and use supported integrations for legitimate institutional purposes.
- Export customer data through supported features, subject to privacy, records-retention and confidentiality obligations.
4. Prohibited use
You must not:
- share credentials, bypass access controls, probe security, introduce malware or interfere with the platform or another tenant;
- copy, resell, sublicense, frame or commercially exploit InstiServe except where a written partner agreement expressly allows it;
- reverse engineer, decompile or attempt to obtain source code except to the limited extent that applicable law cannot exclude that right;
- use InstiServe to infringe intellectual-property, privacy or publicity rights, or to facilitate unlawful discrimination, harassment, fraud or academic misconduct;
- upload content or personal data without a lawful basis and required notices, permissions or consents;
- misrepresent InstiServe output as a guaranteed academic, legal, medical, financial or regulatory decision.
5. Institution and user content
Customers and their users retain ownership of content and data they lawfully submit. They grant InstiServe the limited rights needed to host, copy, transmit, secure, back up, display and otherwise process that content to provide, support and improve the contracted service. The customer remains responsible for content accuracy, retention instructions, permissions and the rights of learners, guardians, staff and other data subjects.
6. Children and education records
Institutions must apply the laws and policies that govern children, education records and sensitive information in their jurisdictions. Accounts for minors must be authorised and supervised as required by the institution and applicable law. Do not place unnecessary sensitive information in Community messages, free-text fields or third-party integrations.
7. Integrations and third-party services
Optional integrations may be governed by separate provider terms, privacy notices, fees and technical limits. Connecting a service authorises the necessary exchange of data for the selected function. The customer is responsible for confirming that the provider, configuration and data transfer are approved for its use. InstiServe does not grant rights to third-party brands, content, software or services.
8. Open-source software notices
InstiServe includes open-source components. Those components remain governed by their respective licence texts and notices. Where an open-source licence grants rights that differ from this guide, that licence controls for the relevant component. Copyright notices, attribution and licence files must not be removed. A current component notice may be requested from legal@instiserve.org.
9. APIs, automation and partner access
API keys, webhooks and automation credentials are confidential and must be stored securely, rotated when exposed and used only within documented limits. Partners may access customer environments only with written customer authority, appropriate confidentiality and data-processing terms, and permissions limited to the work being performed. Automated use must not overload the service, scrape unrelated data or evade safeguards.
10. InstiServe name and branding
InstiServe names, logos, product appearance and related marks may not be used in a way that suggests endorsement, partnership or ownership without written permission. Customers may accurately state that they use InstiServe. Approved partners must follow the current brand guidelines and any partner agreement.
11. Suspension, termination and data return
Access may be restricted or suspended where reasonably necessary to address security threats, unlawful use, material breach or risk to other users, subject to the applicable agreement and law. When access ends, export and deletion rights, retention periods and any transition support are governed by the customer's agreement and applicable legal obligations.
12. Reporting concerns and requesting permission
Report suspected infringement, credential exposure, security issues or misuse promptly. For licensing permissions, partner use, brand approval or a copy of third-party notices, contact legal@instiserve.org. Include your organisation, intended use, affected material and requested timeframe.
Review before adoption
This draft deliberately avoids selecting governing law, courts, warranty exclusions, liability caps, payment terms and formal notice mechanics. Qualified counsel should align those provisions with InstiServe's customer agreement, privacy notice, actual deployment practices and target jurisdictions before this page is treated as binding terms.