Acceptable Use Policy
Last updated: 13 September 2026
The rules for using Comsky HRMS responsibly — what is permitted, what is prohibited, and how we enforce this policy to protect everyone on the platform.
This document is a standard template provided for convenience. It is not legal advice and should be reviewed and adapted by qualified legal counsel before you rely on it.
1. Purpose & scope
This Acceptable Use Policy (the “AUP”) sets out the rules for using Comsky HRMS, operated by Comhard Technologies Pvt Ltd. It applies to every customer and Authorised User and is incorporated into our Terms & Conditions. Its purpose is to protect the Service, our customers, their employees and third parties. If any provision here conflicts with the Terms, the Terms prevail.
2. Your responsibilities
You are responsible for how the Service is used within your workspace. In particular, you must:
- Use the Service only for lawful business purposes and in compliance with all applicable laws;
- Ensure your Authorised Users comply with this AUP;
- Keep sign-in credentials confidential and promptly report any suspected unauthorised access;
- Have the necessary rights, notices and lawful basis for any personal data you upload or process;
- Configure roles and permissions so that access to sensitive data (such as payroll and PII) is appropriately restricted.
3. Prohibited activities
You must not, and must not permit anyone to, use the Service to:
- Violate any law or regulation, or infringe the intellectual-property, privacy or other rights of any person;
- Upload, store or transmit malicious code, or content that is unlawful, defamatory, harassing, obscene or otherwise objectionable;
- Send unsolicited or unauthorised messages, spam, or bulk communications in breach of applicable law;
- Attempt to gain unauthorised access to the Service, other customers’ data, or any related systems or networks;
- Probe, scan or test the vulnerability of the Service, or breach or circumvent any security or authentication measure, without our prior written consent;
- Reverse engineer, decompile or disassemble the Service, or copy, resell or sublicense it, except to the extent permitted by law;
- Interfere with or disrupt the integrity or performance of the Service, or impose an unreasonable or disproportionately large load on it;
- Use automated means to scrape or extract data beyond the documented API and its limits;
- Misrepresent your identity or affiliation, or use the Service to impersonate any person or entity;
- Use the Service to store or process data for which you have no lawful basis, or in violation of the DPDP Act or other data-protection law.
4. Data & content standards
You are solely responsible for the accuracy, quality and legality of Customer Data and for obtaining any consents required to process it. Do not upload data you are not authorised to handle, and do not use the Service to process special categories of data in ways that are prohibited or that exceed the permissions and notices your employees are entitled to.
5. Fair use & API limits
The Service, including its public REST API and webhooks, is subject to reasonable usage limits and rate limits to protect availability for all customers. You must not circumvent these limits. We may apply, adjust or enforce rate limits and fair-use thresholds, and may throttle or suspend activity that threatens the stability or security of the Service.
6. Security obligations
You must take reasonable steps to secure your workspace, including using strong authentication through Comsky Identity, promptly deprovisioning users who no longer need access, and safeguarding any API keys you generate. You must not disable, interfere with, or attempt to defeat any security, audit or tenant-isolation feature of the Service.
7. Third-party services & integrations
When you connect the Service to third-party systems (for example, Tally, banking channels or statutory portals), you are responsible for your use of those services and for complying with their terms. You must not use an integration in a way that violates this AUP or any third party's rights or terms.
8. Monitoring & enforcement
We may, but are not obliged to, monitor use of the Service for compliance with this AUP. If we reasonably believe a violation has occurred, we may:
- Investigate and request that you remedy the violation;
- Remove or disable access to offending content or configuration;
- Suspend or restrict access to the affected workspace or user, in whole or in part;
- Terminate the Subscription for material or repeated violations, as provided in the Terms;
- Cooperate with law-enforcement authorities where required by law.
Where practicable and appropriate, we will give notice before taking action, but we may act immediately where necessary to protect the Service, other customers or third parties.
9. Reporting abuse
To report a suspected violation of this AUP, a security vulnerability, or any abuse of the Service, please contact us at abuse@comsky.in. Please include enough detail for us to investigate. Do not attempt to validate a suspected vulnerability in a way that would itself breach this AUP.
10. Changes to this AUP
We may update this AUP from time to time to address new risks or requirements. Material changes will be notified by posting the updated AUP with a new “Last updated” date and, where appropriate, additional notice. Continued use of the Service after an update takes effect constitutes acceptance of the revised AUP.
Related: Terms & Conditions · Privacy Policy · SLA