Hulo Global Support

HULO Global Limited

Acceptable use policy

What you may and may not do with HULO Global websites, hosted services, software, licence portals and support channels.

Last updated: 16 September 2026

This policy sets the standards for using anything HULO Global Limited (“HULO”) provides: our websites, the hosted PayrollOS service, our Vendure plugins and their licence portal and licence server, our APIs, documentation, and our support and contact channels (together the “Services”). It forms part of the Website terms of use, the PayrollOS subscription terms and the plugin licence terms. Breaching it is a breach of those terms.

1. Lawful and honest use

You must use the Services only for lawful purposes and in compliance with all laws that apply to you, including data-protection, consumer-protection, tax, employment, export-control and anti-money-laundering laws. You must not use the Services to do, or to help anyone do, anything that infringes the rights of others, that is fraudulent, or that would bring HULO into disrepute.

You must give us accurate information when you register, order or apply, keep it up to date, and not impersonate any person or organisation or misrepresent your affiliation with anyone.

2. Prohibited content

You must not upload, store, send, publish or link to material through the Services that:

  • is unlawful, defamatory, harassing, threatening, abusive, hateful or discriminatory;
  • is obscene, pornographic or sexualises minors;
  • infringes any copyright, trade mark, database right, patent, trade secret, privacy or other right;
  • contains malware, spyware, ransomware or any code designed to disrupt, damage or gain unauthorised access to systems or data;
  • consists of unsolicited bulk or commercial messages, or material that facilitates them;
  • promotes or facilitates illegal goods or services, violence or self-harm;
  • contains personal data you have no lawful basis to process, or special-category data that the relevant Service has not been designed to hold.

3. Prohibited activity

You must not:

  • attempt to probe, scan, penetrate or test the vulnerability of the Services or any related system, or breach any security or authentication measure, other than under our Vulnerability disclosure policy;
  • access or attempt to access any account, licence, data or system that you are not authorised to use, or exceed the access you have been granted;
  • interfere with the proper working of the Services, including by overloading them, sending malformed requests, or launching denial-of-service attacks;
  • use automated tools (bots, scrapers, crawlers, scripts) to access the Services except through documented APIs and within any published rate limits, or to submit forms;
  • reverse-engineer, decompile, disassemble or otherwise attempt to derive the source code of software we provide in object-code form, except to the extent the law expressly allows;
  • circumvent, disable or tamper with licence checks, activation, usage limits, watermarks or any other technical protection measure in our software;
  • share, sell, sublicense, lend or transfer licence keys, accounts or credentials except as the applicable licence expressly permits, or use a licence on more installations, channels, domains or seats than it covers;
  • use the Services to build a competing product, or to benchmark them for publication without our written consent;
  • remove or obscure any proprietary notices;
  • collect or harvest information about other users or customers;
  • use the Services to store or transmit data in breach of a contract or duty you owe to someone else.

4. PayrollOS and payroll data

Payroll and HR data is sensitive. If you use the hosted PayrollOS service you must: hold a lawful basis to process the personal data of the people whose records you enter; give employees any privacy information the law requires; enable multi-factor authentication where available and keep credentials secure; only grant access to people who need it; remove access promptly when someone leaves; and take care to submit accurate figures to HMRC and pension providers. You remain the controller of that data and responsible for its accuracy and for the payroll outcomes.

5. Vendure plugins, licence portal and licence server

Licences are issued to a named customer for the domains, channels or installations stated on the licence. You must not: run a licensed plugin on additional production domains without extending the licence; use a trial or development licence in production; share licence keys publicly or with anyone outside your organisation and its contractors working on your store; or make automated calls to the licence server other than those the plugins themselves make. We may deactivate keys that are being used in breach of this policy and reserve the right to refuse future licences.

6. Support channels and forms

Support, contact and job-application forms are for genuine requests. Do not send abusive messages, spam, marketing, or content unrelated to the purpose of the form, and do not send passwords, full card numbers, recovery codes or other secrets by email or through a form. We may stop responding to abusive or repeated vexatious contact.

7. Resource usage and fair use

Where a Service has published limits (API rate limits, storage, message volumes, request sizes), you must stay within them. Where no limit is published we may still take action against usage that is excessive compared with typical use of that Service and that degrades it for others, after trying to contact you first.

8. Reporting and enforcement

Report suspected breaches of this policy to [email protected]. We will investigate and may, depending on the seriousness, warn you, remove or disable content, throttle or suspend access, deactivate licences, terminate your account or contract, report the matter to law enforcement or regulators, and pursue legal remedies. Where practical we will tell you before taking action and give you a chance to fix the problem; we will not do so where that would be unlawful, would prejudice an investigation, or where the breach is serious.

We may change this policy at any time by updating this page. Continued use of the Services after a change means you accept the change.