Lawful, secure and responsible use

Acceptable Use Policy

This policy protects Thintech's public website, visitors and systems while providing a clear route for responsible security reporting.

Policy status and scope

Last reviewed and effective from 11 July 2026.

This policy applies to thintech.co.uk, its public pages, search, FiNN, enquiry forms, downloadable material and public-facing technical endpoints. It does not grant access to customer systems, managed services, hosted environments or any non-public system.

Customer services are governed by the relevant proposal, order, service schedule and signed agreement. If a customer agreement incorporates a separate acceptable-use policy, that agreement takes priority for the contracted service.

By using the website, you agree to comply with this policy and the Website Terms of Use. If you act for an organisation, you confirm that you are authorised to do so.

Permitted use

  • Browse the website and use its search for lawful personal or internal business purposes
  • Download brochures, reports and other material for genuine evaluation of Thintech's services
  • Use FiNN and the enquiry forms for legitimate questions, support routing and business enquiries
  • Link to public pages in a fair and lawful way that does not imply endorsement or association
  • Use accessibility technology and ordinary search-engine indexing that respects published technical controls and does not degrade the service

Prohibited security and access activity

  • Access, attempt to access or help another person access any account, data, system, service or administrative function without explicit authorisation
  • Probe, scan, enumerate, intercept or test the website, its hosting, connected systems or suppliers without prior written authorisation from Thintech
  • Bypass authentication, authorisation, robots instructions, rate limits, technical restrictions or other security controls
  • Use stolen, guessed, shared or automated credentials, or carry out password spraying, credential stuffing, phishing or social engineering
  • Introduce malware, exploit code, malicious payloads or material intended to damage, alter, monitor or take control of a system
  • Carry out denial-of-service activity or make requests at a volume or pattern that could impair availability, performance or another person's use
  • Establish persistence, alter or delete data, conceal activity, exfiltrate information or exploit a suspected vulnerability beyond the minimum accidental observation

Prohibited content and communications

  • Use the website for activity that is unlawful, fraudulent, deceptive or contrary to applicable sanctions or regulatory requirements
  • Submit content that is defamatory, threatening, harassing, discriminatory, obscene, abusive or intended to incite violence or other criminal activity
  • Submit child sexual abuse material, terrorist content or any material whose possession, creation or distribution is unlawful
  • Infringe intellectual property, privacy, confidentiality, data-protection or other rights belonging to Thintech or another person
  • Impersonate another person, conceal the true origin of a message or misrepresent your identity, authority or relationship with an organisation
  • Send spam, unsolicited promotions, chain messages, fraudulent enquiries or material intended to mislead Thintech, its staff, customers or suppliers

Automation, scraping and bulk extraction

Do not use bots, crawlers, scraping tools, data-mining systems or automated agents to copy, harvest or systematically extract website content, contact details or datasets unless this is permitted by our robots instructions, required by law or agreed by Thintech in writing.

Do not use website content to train, benchmark or populate a commercial artificial-intelligence system or competing dataset without written permission, except where the law expressly permits that use.

Automated access must never evade controls, create an unreasonable load, interfere with service availability or prevent fair access by other visitors.

Information submitted to Thintech

Only submit information that is lawful, relevant and reasonably necessary for your enquiry, and that you are authorised to provide. You are responsible for the accuracy and legality of your submission.

Do not submit passwords, authentication codes, private keys, payment-card details, live exploit code, customer confidential information, special-category personal data or detailed production-system data through FiNN or a standard enquiry form. Contact Thintech first to agree a suitable secure channel.

You give Thintech the limited permission needed to receive, store, review and route your submission and to use relevant service providers for that purpose. Personal information is handled under the Privacy Policy.

Responsible vulnerability disclosure

This policy does not authorise active security testing. If you become aware of a suspected vulnerability during ordinary use, stop testing and report it promptly to the Information Security Officer at security@thintech.co.uk.

Your report should include the affected URL or service, a clear description, the date and time observed, the potential impact and the minimum steps needed to reproduce the issue. Do not include unnecessary personal data, credentials or confidential customer information.

Do not access additional data, establish persistence, alter or delete information, disrupt a service, use social engineering, test third-party systems or disclose the issue publicly before a coordinated approach has been discussed with Thintech.

Thintech will acknowledge, validate and prioritise reports and will provide proportionate updates where reasonably practicable. This process is not a bug-bounty programme and no payment or reward is offered unless agreed in writing.

Enforcement and cooperation

Where misuse is suspected, Thintech may reject a submission, remove material, rate-limit requests, block or suspend access, preserve relevant evidence and take other proportionate steps needed to protect people, data and services.

Thintech may notify hosting or technology providers, affected organisations, regulators or law-enforcement authorities where this is lawful and appropriate. We reserve all legal rights and remedies.

Where reasonably possible and safe, action will be proportionate to the nature, impact and persistence of the suspected breach. Immediate action may be taken where security, legality or service availability is at risk.

Changes, interpretation and contact

We may update this policy to reflect changes in law, risk, technology or website functionality. Changes apply prospectively from the date published on this page.

If any part of this policy is found unenforceable, the remaining provisions continue to apply. Obligations concerning security, confidentiality, intellectual property and investigation survive the end of access.

Security incidents, vulnerability reports and questions about this policy should be sent to the Information Security Officer at security@thintech.co.uk. General enquiries should be sent to info@thintech.co.uk.

Related website policies

Report a security concern

Contact Thintech's Information Security Officer. Do not send passwords, live credentials or unnecessary personal data.

Email security@thintech.co.uk

Trusted for regulated environments

Security and procurement assurance

Built for mid-market organisations where governance, resilience and accountable delivery matter.

ISO 27001:2022 certifiedInformation Security Management SystemCertificate 27083-ISMS-001 - View PDF
Crown Commercial Service supplierSupporting compliant public-sector procurementAssurance for regulated buyers