Synapse — acceptable use policy


Change history

Version Date Author Summary of changes
1.0 April 2026 Richard Atkin Initial issue

Contents

  1. Purpose and scope
  2. Who this policy applies to
  3. Permitted uses
  4. Prohibited uses
  5. Data handling obligations
  6. User responsibilities
  7. Monitoring and privacy
  8. Reporting obligations
  9. Policy compliance and review

1. Purpose and scope

This policy governs the acceptable use of Synapse by all Conscia UK employees. It describes what Synapse may and may not be used for, the obligations that apply when using it, and the responsibilities that come with access.

This policy should be read alongside the Synapse Security Policy, which describes the technical controls that protect the platform.


2. Who this policy applies to

This policy applies to every Conscia UK employee who has been granted access to Synapse, regardless of their role, seniority, or how they access the platform (web UI or Webex bot).

Access to Synapse is a privilege extended by Conscia UK for business purposes. It may be withdrawn at any time.


3. Permitted uses

Synapse is provided to support Conscia UK employees in their day-to-day work. Permitted uses include, but are not limited to:

Research and knowledge - Researching Cisco products, technologies, and competitive positioning - Searching the Conscia knowledge base for service descriptions, capabilities, and case studies - Looking up current CVEs, bugs, or technical advisories - Searching the web for up-to-date technical or commercial information

Commercial and sales support - Looking up Cisco orders, contracts, part codes, and deal details in CCW - Generating ITGL quote documents from Cisco CCW deals - Querying NetSuite sales and purchase records - Researching project history and client deployments

Productivity and document work - Drafting, reviewing, editing, and improving documents, proposals, and emails - Summarising long documents or extracting key information from attachments - Creating presentations, reports, and structured outputs - Translating or reformatting content

Technical assistance - Troubleshooting technical problems with Cisco, Microsoft, or other vendor products - Writing, reviewing, and explaining code - Running data analysis or file processing tasks in the code sandbox - Generating scripts, configurations, or automation

Internal systems - Searching and reading your own Microsoft 365 email, calendar, and files - Querying Autotask support tickets - Searching the internal projects database

Professional development - Discussing career development, communication, and professional skills - Practising presentations or preparing for meetings


4. Prohibited uses

The following uses of Synapse are prohibited.

4.1 Prohibited data — security-classified and regulated client data

This is the most important restriction in this policy.

You must not input into Synapse any data relating to clients or projects that require background checks, security clearance, or other regulatory approval processes. This includes:

If you are working on an engagement that involves — or may involve — security clearances, protective markings, or other regulatory data handling requirements, you must not use Synapse in connection with that work unless you have received explicit written authorisation from the policy owner confirming that its use is appropriate.

If you are unsure whether a particular piece of data falls into this category, do not submit it, and seek guidance from the policy owner before proceeding.

4.2 Prohibited data — sensitive personal data

You must not submit the following categories of personal data to Synapse:

General personal data (names, job titles, email addresses, professional context) arises naturally in the course of normal use and is acceptable where it is relevant to the business task.

4.3 Prohibited uses — conduct

You must not use Synapse to:

4.4 Prohibited uses — commercial actions

Synapse provides read access to commercial systems but cannot and must not be used as a substitute for proper commercial process. You must not rely on Synapse outputs alone to:

All such actions must go through the established commercial process regardless of what Synapse has produced.

4.5 Accuracy reliance

Synapse can and does make mistakes. You must not submit Synapse-generated content to a client, use it to inform a technical action, or make a business decision based on it without appropriate validation. The degree of validation required should be proportionate to the risk — a customer-facing proposal or a technical configuration deserves more scrutiny than an internal draft.


5. Data handling obligations

5.1 Minimise what you share

Share only the data that Synapse needs to complete the task. If a document contains more information than is required, consider extracting the relevant sections rather than uploading the full document.

5.2 Your data is yours

Your conversations, uploaded files, and AI memory are stored under your own account and are not visible to other users through normal platform operation. You are responsible for the data you submit and the outputs you act on.

5.3 AI-generated outputs

Outputs produced by Synapse are generated by an AI model. They may contain inaccuracies, outdated information, or plausible-sounding but incorrect statements. You are responsible for reviewing and validating any output before acting on it or sharing it externally.

Synapse outputs used in customer-facing documents, proposals, technical designs, or communications must be reviewed for accuracy by a suitably qualified person before delivery.

5.4 Retention

Conversation history is retained in Synapse until you delete it. You should periodically review and delete conversations that are no longer needed, particularly those containing sensitive commercial or personal information.


6. User responsibilities

6.1 Account security

6.2 Appropriate use

6.3 Staying informed


7. Monitoring and privacy

Conscia UK monitors Synapse usage for the purposes of security, operations, and policy compliance. Monitoring includes:

Monitoring is carried out for legitimate operational and security purposes and in accordance with applicable law. Users should have no expectation that their use of Synapse is private.

Synapse does not log the full content of your messages or AI responses in an accessible form for routine review — but conversation content is stored in S3 under your account and may be accessed by platform administrators in the course of a security investigation or incident response.


8. Reporting obligations

8.1 Suspected security incidents

If you suspect that Synapse has been accessed without authorisation, that your account has been compromised, or that platform security has been breached in any way, you must notify a platform administrator as soon as possible.

8.2 Policy violations

If you become aware that this policy is being violated by another user, you should report this to the policy owner.

8.3 Unexpected or harmful outputs

If Synapse produces an output that appears to be factually dangerous, harmful, or in breach of this policy, do not act on it and report it to the policy owner. Include the conversation context where possible.

8.4 Feature requests

Feature requests and suggestions for improving Synapse are welcome. You can submit a feature request directly in the Synapse chat: "Please log a feature request for..."


9. Policy compliance and review

9.1 Compliance

All users within scope of this policy are required to comply with its requirements. This policy does not replace or supersede any other Conscia UK employment, conduct, or data protection policy — it applies in addition to them.

9.2 Reporting violations

Policy violations should be reported to the policy owner. The policy owner will assess the nature and severity of any reported violation and determine an appropriate response in accordance with Conscia's standard procedures.

9.3 Exceptions

Exceptions to this policy may be granted in writing by the policy owner, with a documented business justification. Exceptions will not be granted where doing so would conflict with Conscia's legal or regulatory obligations.

9.4 Policy review

This is a living document. It will be updated as the platform evolves or as new risks, use cases, or regulatory requirements arise. All updates will be recorded in the change history table. The policy owner is responsible for communicating material changes to all users.