Acceptable Use Policy
Last Updated: 28-SEP-2026 · Version: 1.5
1 WHO THIS POLICY APPLIES TO.
1.1 This Acceptable Use Policy ("Policy") applies to every individual who accesses or uses the ZenQMS application, including app.zenqms.com, any production, sandbox, UAT/test or beta environment, the ZenQMS Auditor Share, ZenSign, the ZenQMS Public API and any ZenQMS mobile application (together, the "Software"). This Policy also applies to the ZenQMS Support Portal at support.zenqms.com (the "Support Portal") when you access it through the Software or using your account credentials, and in that case references in this Policy to the Software include the Support Portal.
1.2 Access to the Software is licensed to organizations, not to individuals. Your organization's written agreement with ZenQMS LLC ("ZenQMS") governs the Software. This Policy states the rules that apply to you personally as a user, and supplements that agreement — it does not replace it, reduce it, or create any separate contract between you and ZenQMS for the Software.
1.3 If anything in this Policy conflicts with your organization's written agreement with ZenQMS, that agreement controls.
1.4 This Policy does not govern the ZenQMS marketing website, which is covered by the ZenQMS Website Terms of Use.
2 WHICH AGREEMENT GOVERNS YOUR ORGANIZATION.
2.1 Which agreement applies depends on what agreement your organization has most recently executed. If you are not sure, ask your ZenQMS system administrator or contact legal@zenqms.com.
2.2 ZenQMS updated its Master Subscription Agreement on 23-SEP-2026. The updated Master Subscription Agreement superseded the original ZenQMS Application Terms of Service previously approved 12-OCT-2018 with its announcement to all users.
A. Unless your organization’s Order Form, Statement of Work, or a separately executed amendment or side letter provides otherwise, the new Agreement— together with EXHIBIT I to it and your organization's Order Form and Statement of Work — governs your organization's use of the Software and supersedes any earlier ZenQMS terms of service. Where your organization has also executed a ZenQMS Data Processing Addendum or a ZenQMS Business Associate Addendum, those addenda form part of that agreement. A copy is available from your organization's contract owner, or on request from legal@zenqms.com.
B. The terms of the superseded agreement are no longer offered to new customers. Those terms continue to govern any organization that has not executed an Order Form referencing the current Master Subscription Agreement. The agreement is provided for reference so that organizations still operating under it can find it here: https://hubs.ly/Q04y1GTb0. If your organization is operating under those terms, contact your ZenQMS account manager or legal@zenqms.com to transition to the current Master Subscription Agreement.
2.3 In every case, this Policy applies to you as an individual user, whichever agreement governs your organization.
3 YOUR ACCOUNT AND CREDENTIALS.
3.1 Your user account is personal to you. Do not share your credentials with anyone, and do not use anyone else's.
3.2 A user account may not be used concurrently by more than one person. User rights may be transferred from one person to another by your administrator, but may not be shared.
3.3 Keep your credentials secure and comply with your organization's password and authentication requirements. Multi-factor authentication is required where your organization has enabled it.
3.4 Tell your administrator and ZenQMS immediately if you believe your credentials have been compromised or your account has been accessed without authorization. Report this to ZenQMS at help@zenqms.com, which is monitored on a twenty-four hour basis for urgent security issues.
3.5 Access only the accounts, sites and records you have been authorized to access, and only for your organization's internal business purposes.
4 ELECTRONIC SIGNATURES AND REGULATED RECORDS.
4.1 The Software maintains records and electronic signatures that your organization relies on for regulatory compliance, including under 21 CFR Part 11 and EU Annex 11. Accordingly, the following rules apply to you:
A. You must apply electronic signatures personally, using your own credentials. Never ask another person to sign on your behalf and never sign on behalf of another person.
B. No automated agent, script, bot or artificial-intelligence feature may apply an electronic signature. Signatures must be applied by an individual human being. This applies both to ZenQMS AI Features and to any AI model, agent or automated process your organization operates itself.
C. Where you use an automated agent, script or software process to interact with the Software (including through the Public API), it must operate under your direction and be attributed in the Software to your named user account. Its use must also stay within any fair use or usage limitations in your organization's agreement with ZenQMS, and must not be used to circumvent applicable user limits or to give access to individuals who are not licensed users. You remain responsible for everything it does.
D. Do not take any step intended to defeat, obscure or falsify the audit trail, a signature manifestation, a date/time stamp, or the attribution of any action to a user.
E. Do not misrepresent the review, approval or authorship of any record.
5 ACCEPTABLE USE.
5.1 You will use the Software only:
A. for your organization's internal business purposes (which include sales and marketing of your organization's own products and services) and within the scope your organization has licensed;
B. in accordance with your organization's own policies, procedures and training; and
C. in compliance with applicable law and regulation, including United States export control and sanctions laws, which may prohibit use of the Software in certain sanctioned or embargoed countries.
6 PROHIBITED CONDUCT.
6.1 Except where applicable law prohibits such restrictions, you will not:
A. use the Software in violation of applicable law, or to store or transmit material that is unlawful, infringing, defamatory, obscene, threatening or otherwise tortious, or to send spam or otherwise send messages in violation of applicable law;
B. upload or transmit malicious code, or take any action designed to disrupt, degrade or gain unauthorized access to the Software or to any other customer's data;
C. attempt to access, or actually access, the data of another ZenQMS customer, or any account, environment or record you have not been authorized to use;
D. conduct any security, integrity, penetration, vulnerability or similar testing on the Software, or use any software tool designed to automatically emulate the actions of a human user (such tools are commonly referred to as robots) in conjunction with the Software;
E. circumvent or attempt to circumvent any access control, permission, rate limit, license limit, content filter or safety control;
F. copy, reverse engineer, decompile, disassemble or create derivative works of the Software, reverse engineer or create derivative works of the Software documentation, or access either in order to build a similar or competing product or service (or contract with a third party to do so);
G. license, sublicense, sell, resell, rent, lease, distribute, time-share or otherwise make the Software available to any third party, other than as permitted by your organization’s agreement with ZenQMS;
H. use the Software, or any ZenQMS proprietary material within it (including ZenAI Content), to develop, train, fine-tune or benchmark any artificial-intelligence or machine-learning model, or a competing product or service; this does not restrict your organization's use of its own Customer Data, AI Input or AI Output, in which it retains all right, title and interest; or
I. remove, obscure or alter any proprietary notice in the Software or in any document or export produced by it.
7 CONTENT YOU SUBMIT.
7.1 You are responsible for the content you submit to the Software and for confirming you are entitled to submit it.
7.2 Submit only content that belongs in a regulated quality system and that falls within the scope your organization has licensed.
7.3 Do not submit protected health information (PHI) to any part of the Software that ZenQMS has not expressly designated as HIPAA Eligible Software in a fully executed Order Form under an executed ZenQMS Business Associate Addendum, or that has not been configured in accordance with that Addendum and any security configurations ZenQMS requires in writing. Your organization — not ZenQMS — configures which users may access PHI, and that configuration is the principal means by which the HIPAA minimum necessary standard is applied inside your account.
7.4 The Software is designed, developed and maintained for use in regulated life sciences quality operations, and ZenQMS's technical and organizational security measures apply in full to special categories of personal data within the meaning of Article 9 of the GDPR — data concerning health, genetic data, biometric data used to identify a person, and data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, and data concerning a person's sex life or sexual orientation — to data relating to criminal convictions and offences, and to personal data of patients or clinical trial subjects. Whether such data is submitted is your organization's decision: it is responsible for qualifying the Software for that use and for configuring user permissions accordingly. Submit such data only where your organization has instructed you that it may be and, where the data is subject to the GDPR, where your organization has executed a ZenQMS Data Processing Addendum.
7.5 Follow your organization's instructions on what may be submitted, and on the use of any personal data.
8 ARTIFICIAL INTELLIGENCE FEATURES.
8.1 Where your organization has enabled ZenQMS AI Features, the following apply:
A. AI Output is a draft. AI Features are decision-support tools. AI Output must be reviewed by a suitably qualified person before it is relied on, approved, or signed. Do not treat AI Output as reviewed or approved when it has not been.
B. AI Output is not quality, regulatory, scientific, medical or legal advice, and does not replace your organization's own judgement or procedures.
C. No AI Feature may apply an electronic signature (see Section 4).
D. What you submit to an AI Feature is your organization's decision. Do not submit any of the categories of data described in Section 7, or protected health information, as AI Input except where your organization's policies and, where applicable, an executed Data Processing Addendum or Business Associate Addendum permit it.
E. Do not use an AI Feature to generate content you are not entitled to submit, or to develop, train, fine-tune or benchmark any artificial-intelligence or machine-learning model or a competing product or service.
F. Do not attempt to circumvent, disable or defeat any human-review control, rate limit, content filter or safety control applied to an AI Feature, and do not disguise automated activity as human activity.
G. Where an AI Feature is used to generate or materially modify content within a module of the Software that maintains an audit trail, use of that AI Feature is recorded in the audit trail, together with the user who invoked it and the date and time.
H. Where your organization's Order Form specifies AI Credits or another consumption-based entitlement, use of the metered AI Features is limited to that entitlement, and ZenQMS may apply reasonable rate limits to protect availability for all customers.
I. ZenQMS does not use your organization's Customer Data, AI Input or AI Output to train, fine-tune or otherwise develop any artificial intelligence or machine learning model that is made available to any other customer or to any third party. ZenQMS will contractually prohibit each provider of a model or service used to deliver the AI Features from retaining, using or training on Customer Data, AI Input or AI Output for any purpose other than providing the applicable service to ZenQMS. Processing of Customer Data by AI Features is not, and does not generate, System Data as defined in Section 17 of the Master Subscription Agreement; ZenQMS's separate rights in anonymized and aggregated System Data are set out in that Section.
J. ZenQMS may suspend access to an AI Feature where it reasonably determines that use of that feature violates this Section 8 or presents a material risk to the security, integrity or availability of the Software. ZenQMS will give your organization notice and, where the circumstances reasonably permit, an opportunity to cure before suspending; where they do not, ZenQMS will notify your organization promptly after suspending. Any such suspension is limited to the affected AI Feature and does not affect access to the remainder of the Software.
9 MONITORING, LOGGING AND AUDIT TRAIL.
9.1 Your activity in the Software — including logins, record changes and electronic signature events — is recorded in the audit trail with the date, time and your user account, together with the creation, modification and deletion of records including pre- and post-change values, and data access and export events; security-relevant events on ZenQMS infrastructure are logged and monitored. Audit logging is applied by ZenQMS in accordance with 21 CFR Part 11 and EU Annex 11 and cannot be reduced or disabled by you or by your organization. Your organization may review your activity in accordance with its own policies and applicable law, and instructs ZenQMS how long the audit trail is retained to meet its own record-retention obligations.
10 IF THIS POLICY IS BREACHED.
10.1 Breach of this Policy may lead to suspension or termination of your access by your organization or, in accordance with your organization's agreement with ZenQMS, by ZenQMS. Serious breaches may also have consequences under your organization's own policies and under applicable law.
11 PRIVACY.
11.1 ZenQMS's handling of personal data, including its use of cookies and similar technologies, is described in the ZenQMS Privacy Policy. Where ZenQMS processes personal data on your organization's behalf, it does so as a processor on your organization's instructions and, where applicable, under an executed ZenQMS Data Processing Addendum. Protected health information is governed by an executed ZenQMS Business Associate Addendum; neither this Policy nor the Privacy Policy modifies that addendum.
12 CHANGES TO THIS POLICY.
12.1 ZenQMS may update this Policy from time to time by posting a revised version with a new "Last Updated" date, and will not make changes that materially reduce the protections given to customers under their written agreements. Updating this Policy does not amend your organization's agreement with ZenQMS, which can be changed only as that agreement provides.
13 CONTACT.
13.1 Questions about this Policy: legal@zenqms.com
13.2 Support: help@zenqms.com or support.zenqms.com
13.3 Security concerns: help@zenqms.com (a security error is a Level 1 – Urgent issue with a one-hour response target)
13.4 ZenQMS LLC, 40 Coulter Ave, Suite 265, Ardmore, PA 19003, USA