Rare360 Acceptable Use Policy
Document Owner: Data Protection & Information Security Manager
Approved By: Rare360 Executive Management
Effective Date: January 1, 2026
Review Cycle: Annually
Version: 1.0
1. Purpose
The purpose of this Acceptable Use Policy ("Policy") is to establish the requirements for the secure, ethical, and appropriate use of Rare360's information systems, devices, networks, applications, cloud services, and information assets.
This Policy is intended to protect the confidentiality, integrity, and availability of Rare360's information while supporting compliance with applicable legal, contractual, and regulatory obligations.
2. Scope
This Policy applies to:
-
Employees
-
Contractors
-
Consultants
-
Temporary personnel
-
Volunteers
-
Third-party service providers granted access to Rare360 systems
-
Any individual using Rare360-managed or authorized information systems
The Policy applies regardless of whether access occurs from company premises, home offices, or other remote locations.
3. General Responsibilities
Users are responsible for:
-
Protecting Rare360 information assets.
-
Using systems only for authorized business purposes.
-
Complying with all company security and privacy policies.
-
Reporting suspected security incidents immediately.
-
Exercising reasonable care when handling confidential information.
4. Authorized Use
Rare360 systems may be used only for legitimate business activities, including:
-
Research participant recruitment
-
Study administration
-
Client communications
-
Business operations
-
Administrative functions
-
Approved collaboration with clients, partners, and service providers
Limited personal use is permitted only if it:
-
Does not interfere with business operations;
-
Does not consume excessive resources;
-
Does not violate any law or company policy;
-
Does not create a security risk.
5. User Accounts
Each user shall:
-
Use only individually assigned accounts.
-
Maintain the confidentiality of login credentials.
-
Use strong passwords or passphrases.
-
Enable multi-factor authentication where required.
-
Never share usernames or passwords.
-
Immediately report suspected credential compromise.
Users shall not:
-
Create unauthorized accounts.
-
Circumvent authentication controls.
-
Use another person's credentials.
6. Protection of Confidential Information
Users shall protect confidential and restricted information at all times.
Examples include:
-
Research participant information
-
Personal information (PII)
-
Health-related information
-
Client information
-
Contracts
-
Financial information
-
Internal business records
-
Authentication credentials
Confidential information shall be accessed only when required for authorized business purposes.
7. Data Handling
Users shall:
-
Access only the information necessary to perform assigned duties.
-
Store business information only in approved systems.
-
Use secure methods when transmitting confidential information.
-
Verify recipients before sending confidential information.
-
Secure devices when unattended.
-
Follow Rare360's data retention and destruction requirements.
Users shall not:
-
Copy confidential information to unauthorized storage locations.
-
Use personal cloud storage services for business information without authorization.
-
Download excessive amounts of participant data.
-
Remove security protections from company information.
8. Email and Electronic Communications
Business email and messaging systems shall be used professionally and responsibly.
Users shall not:
-
Send offensive, discriminatory, or harassing communications.
-
Transmit malicious software.
-
Open suspicious attachments or links.
-
Forward confidential information without authorization.
-
Use company email for unlawful purposes.
Phishing attempts or suspicious communications shall be reported immediately.
9. Internet Use
Internet access is provided for legitimate business purposes.
Users shall not intentionally access or distribute content that is:
-
Illegal;
-
Malicious;
-
Fraudulent;
-
Sexually explicit;
-
Violent or abusive;
-
Discriminatory or hateful;
-
Intended to facilitate unauthorized access to computer systems.
Users shall not download unauthorized software or applications.
10. Mobile Devices
Rare360 authorizes limited use of a secure Android mobile device to communicate with research participants who prefer mobile communications.
Users of authorized mobile devices shall:
-
Protect the device with a strong PIN or password.
-
Maintain current operating system updates.
-
Enable device encryption.
-
Lock the device when unattended.
-
Report lost or stolen devices immediately.
Only the minimum information necessary shall be accessed or stored on mobile devices.
11. Remote Work
Personnel working remotely shall:
-
Use secure internet connections whenever practicable.
-
Prevent unauthorized viewing of confidential information.
-
Protect company devices from unauthorized access.
-
Maintain physical security of devices.
-
Follow all applicable security policies.
Confidential information shall not be discussed where unauthorized individuals may overhear.
12. Software Installation
Only approved software may be installed on company-managed devices.
Users shall not:
-
Install unauthorized applications.
-
Disable security software.
-
Circumvent operating system security controls.
-
Install software that infringes intellectual property rights.
13. Artificial Intelligence (AI) Tools
The use of AI tools must protect participant privacy and confidential information.
Users shall not enter confidential participant information, client confidential information, or other sensitive data into publicly available AI systems unless expressly authorized and protected by an appropriate agreement and security controls.
AI-generated content used for business purposes should be reviewed by an appropriate individual for accuracy, completeness, and compliance before use.
14. Fraud Prevention
Personnel involved in research recruitment shall:
-
Verify respondent eligibility in accordance with study procedures.
-
Report suspected fraudulent participation.
-
Follow established quality assurance procedures.
-
Protect the integrity of research data.
15. Monitoring
Rare360 reserves the right, to the extent permitted by applicable law, to monitor the use of company systems to:
-
Protect company assets.
-
Investigate security incidents.
-
Detect unauthorized activities.
-
Ensure compliance with company policies.
-
Meet legal and contractual obligations.
Users should have no expectation of personal privacy when using company systems, except as required by applicable law.
16. Incident Reporting
Users shall immediately report:
-
Lost or stolen devices.
-
Suspected malware.
-
Unauthorized access.
-
Phishing attempts.
-
Accidental disclosure of confidential information.
-
Password compromise.
-
Any suspected information security incident.
Prompt reporting helps reduce risk and supports effective incident response.
17. Prohibited Activities
The following activities are prohibited unless expressly authorized:
-
Unauthorized access to systems or data.
-
Attempting to bypass security controls.
-
Sharing passwords or authentication credentials.
-
Downloading confidential information without a business need.
-
Using company resources for unlawful purposes.
-
Introducing malicious code.
-
Using company systems to harass, discriminate against, or threaten others.
-
Violating intellectual property rights.
-
Conducting unauthorized vulnerability scanning or penetration testing.
-
Removing or altering security logs or audit records.
18. Violations
Violations of this Policy may result in:
-
Revocation of system access.
-
Disciplinary action.
-
Termination of employment or contractual relationship.
-
Legal action where appropriate.
-
Notification to clients or regulatory authorities where required by law or contract.
19. Exceptions
Any exception to this Policy must be approved by Executive Management or the designated Information Security Manager. Approved exceptions should be documented, include a business justification, identify compensating controls, and be reviewed periodically.
20. Policy Review
This Policy will be reviewed at least annually and updated as necessary to reflect changes in:
-
Business operations
-
Technology
-
Information security risks
-
Applicable laws and regulations
-
Client contractual requirements
21. Questions
Questions regarding this Policy should be directed to:
Rare360
Email: admin@rare360.life
Website: https://www.rare360.life
User Acknowledgement
All personnel with access to Rare360 information systems are expected to read, understand, and comply with this Acceptable Use Policy. Compliance with this Policy is a condition of continued access to Rare360 systems and information resources.
