Skip to main content

Acceptable Use Policy

Last updated: 11 July 2026

Version 2.0  |  Effective from 11 July 2026

This policy sets out the rules for using Squigggle. It forms part of, and should be read with, our Business Terms (if you are a business) or our Consumer Terms (if you are a consumer).

This Acceptable Use Policy (“Policy”) applies to everyone who uses Squigggle, the electronic-signature service provided by N90 Labs Limited (“N90 Labs”, “we”, “us”). It forms part of your agreement with us — our Business Terms if you are a business, or our Consumer Termsif you are a consumer (in each case, your “Terms”). Capitalised terms have the meanings given in your Terms. In this Policy, “Content” means any documents, data, files or other material you upload to, submit to, or generate through the Service.

Who this Policy applies to

  • This Policy applies to customers, their Authorised Users, and to Signatories who view, verify or sign documents through the Service. Signatories are also subject to the Signatory Terms of Use, which address conduct during the signing process.
  • You are responsible for ensuring that everyone using the Service through your account complies with this Policy.

General principle

You may use the Service only for lawful purposes and in line with this Policy and your Terms. You must not use the Service in any way that is unlawful, fraudulent, or harmful, or that interferes with anyone else’s use of it.

Prohibited content

You must not upload, send or sign any Content that:

  • is unlawful, defamatory, obscene, or infringes anyone’s intellectual property or privacy rights;
  • contains malware, or is designed to interfere with, damage or gain unauthorised access to any system or data;
  • is fraudulent, or misrepresents your identity or your authority to act; or
  • you do not have the rights or permissions to upload, send or process.

Restricted and prohibited data

You must not include full payment card numbers, or related cardholder data such as the card security code, in any document or other Content you upload to the Service, and you must ensure your Authorised Users and Signatories do not do so. The Service is not designed to hold cardholder data or to fall within the scope of the PCI DSS.

You may include special-category personal data (as defined in Article 9 of the UK GDPR — for example, data about health, racial or ethnic origin, religious or philosophical beliefs, or biometric data) or personal data about criminal offences (Article 10) only where you have a lawful basis and, where required, an Article 9 condition for doing so. You are responsible for ensuring you have that basis and condition, and for complying with data-protection law in respect of that data, which, if you are a business, we process on your behalf as processor under the Data Protection Addendum; if you are a consumer, we handle as controller under our Privacy Policy.

Prohibited conduct

You must not:

  • use the Service to impersonate any person or to obtain a signature by deception;
  • attempt to gain unauthorised access to the Service, other accounts, or any associated systems or networks;
  • probe, scan, or test the vulnerability of the Service, or breach its security or authentication measures, without our written permission;
  • interfere with or disrupt the Service, or impose an unreasonable load on it;
  • scrape or harvest data from the Service except as we expressly permit; or
  • use the Service as a substitute general-purpose file-storage or backup service. The Service is for preparing, sending, signing and retaining signed documents and their audit trails; it is not intended for bulk storage of files unrelated to that purpose.

No AI/ML training on the Service or its Content

You must not use the Service, or any Content belonging to other users, to train, fine-tune or develop any machine-learning or artificial-intelligence model. This restriction also forms part of your Terms.

Our own commitment not to train cross-customer or general-purpose models on your Content is set out in our Privacy Policy (and, for business customers, in the Business Terms).

Security and your account

You must keep your credentials secure, must not share OTPs, and must tell us promptly if you become aware of any unauthorised use of the Service or any security vulnerability.

Reporting and enforcement

If you become aware of any use of the Service that breaches this Policy, please report it to legal@squigggle.io.

We may investigate suspected breaches and may remove or disable access to Content, and suspend or terminate access, in accordance with the suspension, termination and content-removal provisions of your Terms. Where practicable and lawful, we will give notice before doing so.

To the extent permitted by law, and subject to the limits on liability in your Terms (and to your rights as a consumer), we are not liable to you for any action we take in good faith to enforce this Policy, or for any failure or delay in enforcing it against another user.

Changes to this Policy

We may update this Policy from time to time. Material changes are handled in the same way as changes to your Terms, including the separate-notice protection for consumers set out in the Consumer Terms.

Document control

  • Version 1.0 — March 2026 (superseded)
  • Version 2.0 — 11 July 2026 (current version)