Acceptable Use Policy – Healthcare and Research Environments
Rules for responsible use by professional users, with particular focus on health/genomic data protection, security and correct use of RUO functions.
Regulatory and governance references
- Regulation (EU) 2016/679
- Regulation (EU) 2024/1689 for AI use cases
- Regulations (EU) 2017/745 and 2017/746 where a future medical intended purpose triggers product law
- Customer security policies and research protocol
References indicate the design framework and must be verified against the current legislation, implementing measures, national law and the parties’ actual roles at implementation time.
1. Purpose of the Policy
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
RTO and RPO, if offered, must be expressly stated in the SLA and aligned with the architecture. Without executed values they cannot be inferred from public material; disaster recovery and application restoration should be tested periodically where required by the continuity plan.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
2. Authorised Users and Individual Accountability
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
3. Permitted Data and Minimisation
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Each processing operation must respect purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality. Configuration should avoid unnecessary free-text fields, uncontrolled copies and excessive transfers; synthetic or properly anonymised data should be preferred for testing and training where feasible.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
4. No Unnecessary or Unlawful Data
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
5. Use of AI and RUO Functions
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
The current intended purpose must be reflected in product materials, manuals and onboarding. Any change introducing a medical, diagnostic, prognostic, predictive or therapeutic purpose requires a new software qualification analysis and, where applicable, an MDR/IVDR pathway and reassessment under the AI Act.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
6. No Unauthorised Clinical Use
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
The RUO configuration must not be used as a substitute for a medical device, IVD, validated report or healthcare professional judgement. Customers must prevent experimental outputs from being placed in clinical records or used for treatment without the necessary validation and regulatory pathway.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
7. Credential and Device Security
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
8. No Circumvention of Security Controls
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
9. Uploads, Files and Malicious Content
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Documentation is version controlled and may be updated to reflect technical, scientific or regulatory change. Databases imported by the customer remain subject to the rights and restrictions applicable to their source; the existence of an import feature does not grant UESE rights over the content or guarantee that the source may lawfully be reused.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
10. APIs, Automation and Abnormal Loads
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Integrations must be inventoried and authorised. The customer must determine what data may leave its environment, which credentials are used, who governs APIs and which terms apply to the recipient; tokens, endpoints and secrets must be managed with least privilege and appropriate rotation.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
11. Confidentiality, Exports and Sharing
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
12. Security Monitoring and Verification
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
13. Violations, Suspension and Remediation
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
14. Reporting and Contacts
The platform is intended for authorised professional personnel and may be used only for purposes consistent with the project, research protocol and instructions of the relevant organisation. Each user is accountable for credentials, actions and compliance with RUO limitations, security rules and the necessity principle.
Unauthorised access, control circumvention, malicious code, unauthorised scraping, unlawful discrimination or profiling and any activity compromising availability, integrity or confidentiality of systems or data are prohibited.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
For requests concerning data processed within a customer project, UESE may need to direct the data subject to the competent controller. For commercial or technical enquiries, use the dedicated stakeholder form and do not submit patient data.
Request informationWebsite owner and corporate contacts
UESE ITALIA S.p.A. · Piazza Trivulziana 4/A · 20126 Milano (MI) · Italy · P. IVA / C.F. IT04398760274 · REA MI 2679515 · sales@uese.it · +39 02 5656 8416.