Acceptable Use Policy
1. Scope
This policy applies to every Tenant, every Authorised User, and any third party accessing the Vedge Service on a Tenant’s behalf.
2. Prohibited conduct
You must not:
- Upload or process data for which you lack a lawful basis, patient consent, or a supervisory relationship required by Ghanaian health-professions law.
- Use the Service to practise or facilitate medicine, dentistry, pharmacy, optometry, nursing, or any regulated profession without the applicable council’s current licensure.
- Upload child sexual abuse material, content inciting violence, malware, phishing material, or content that violates Ghanaian criminal law.
- Transmit unsolicited commercial communications (“spam”) to patients or third parties through any Vedge-delivered channel.
- Impersonate another person, misrepresent your affiliation, or tamper with clinical records to obstruct investigation or audit.
3. Lawful PHI use
- Upload patient data only when you have the lawful basis and notice described in the DPA and §§20, 27 DPA 2012.
- Do not export or forward clinical records outside the Service in a way that breaches your own retention, access, or confidentiality obligations.
- Controlled substances: prescribe and dispense only in accordance with the Narcotics Control Commission Act 2020.
- Where you act as a data processor for another controller (e.g. a lab sub-contracting diagnostic work), ensure your back-to-back contract mirrors the flow-downs in our DPA.
4. Security boundaries
- Do not probe, scan, or attempt to penetrate the Service outside a written coordinated disclosure agreement with Vedge.
- Do not attempt to access records outside your Tenant context, bypass rate limits, or interfere with other tenants’ use of the Service.
- Report security concerns responsibly to security@tryvedge.com.
5. Automation + rate limits
Programmatic access to the Vedge API is permitted within published rate limits and the feature flags on your subscription plan. Do not circumvent limits, schedule bulk operations to coincide with known peak windows in a manner that degrades other tenants, or scrape the UI where an API exists.
6. Enforcement
Vedge enforces this AUP proportionately. For first-time minor breaches we will contact the Tenant admin. For serious or repeated breaches — especially those that put other tenants or patients at risk — we may suspend Authorised User access, suspend the Tenant account, or terminate the subscription under §12 of the Terms of Service.