This policy sets out the rules for using the Menovia health and safety
platform. It applies to the Menovia web application and the Menovia mobile app
(com.menovia.mobile), both operated by Menovia Ltd.
It forms part of the End-User Terms you accept when you first sign in. If you have been asked to accept those terms, this is the policy they refer to.
1. Purpose
To set clear, reasonable rules for use of the Menovia platform by organisations and their users, protecting service integrity, security, and compliance.
2. Who this applies to
Everyone who accesses Menovia's web and mobile applications, across all six roles: Platform Admins, Consultancy Admins, Consultants, Client Admins, Client Managers, and Employees within customer organisations.
3. Acceptable use requirements
- Lawful use only; no content or actions that violate applicable UK law.
- No unauthorised access, scanning, probing, or security testing of Menovia or third-party systems.
- No credential sharing; each user must sign in with their own individual account.
- Use only approved client applications (the Menovia web and mobile apps) and supported browsers.
- Do not upload malware, or content that infringes intellectual property rights.
- Only store personal data necessary for the platform's purpose. Avoid special category data unless it is operationally required by your organisation and permitted by law.
- Respect tenant boundaries; do not attempt to access another organisation's data.
- Report suspected security issues to your organisation's administrator promptly, and do not exploit them.
4. Prohibited activities
- Attempting to bypass authentication or authorisation controls.
- Reverse engineering or extracting source code from the platform.
- Overloading the service with unreasonable traffic, or with automated scripts not approved by Menovia.
- Uploading highly sensitive data types that are not required for health and safety operations, for example payment card data.
5. Data protection and privacy
- Personal data processed in Menovia is subject to UK GDPR. Your organisation remains the data controller.
- Menovia processes that data under a Data Processing Agreement (DPA).
- You must follow your organisation's data handling policies, and only access data necessary for your role.
For detail on what personal data the platform holds and how it is handled, see our Platform Privacy Policy.
6. Security practices for users
- Keep your devices updated, and protected with a passcode or biometrics.
- Enable operating-system disk encryption (BitLocker or FileVault) on devices used to access Menovia.
- Use a strong, unique password for your Menovia sign-in, not reused from any other service. Multi-factor authentication is not currently available on customer accounts, so password strength carries the full weight of account security.
- Log out from shared devices, and report a lost or stolen device to your organisation.
7. Monitoring and enforcement
- Menovia may log and monitor activity for security and operational purposes. Audit logging is scoped to your own organisation.
- Violations may result in suspension or termination of access, and notification to your organisation's administrators.
- Illegal activity may be reported to the relevant authorities.
8. Reporting concerns
Report misuse or suspected security issues through your organisation's administrator. Platform-wide incidents can be reported to Menovia at info@menovia.co.uk, which is the same contact route the End-User Terms give for reporting security concerns.
9. Changes to this policy
This policy may be updated to reflect changes to the platform or to legal requirements. Material changes will be communicated to organisation administrators.
10. Contact
- General and security reports: info@menovia.co.uk
- Privacy and data protection: privacy@menovia.co.uk
- Post: Menovia Ltd, Clockwise, Yorkshire House, Greek Street, Leeds, LS1 5SH
Effective from 2 April 2026. Next scheduled review: 2 April 2027.
