Acceptable Use Policy
Guidelines for proper and responsible use of company systems, devices, networks, and data
Last Updated: September 2026
Policy Statement
This Acceptable Use Policy (AUP) defines the rules and guidelines for appropriate use of POPS.GG (CASH.BH LTD) technology resources, including computers, networks, email, internet access, mobile devices, and applications. All employees, contractors, and third parties with access to company systems must comply with this policy.
The purpose of this policy is to protect company assets, ensure security, maintain productivity, and comply with legal and regulatory requirements. Violation of this policy may result in disciplinary action up to and including termination of employment or contract.
Scope
This policy applies to:
- All employees (full-time, part-time, temporary)
- Contractors and consultants
- Third parties with system access
- All company-owned devices and systems
- Personal devices used for company business (BYOD)
- Remote and office-based work
Acceptable Use
Company systems and resources may be used for:
- Authorized business activities and job responsibilities
- Professional development and training related to job role
- Reasonable personal use that does not interfere with work duties
- Communication with colleagues, customers, and business partners
- Accessing approved cloud services and applications
- Remote work and business travel (with proper security measures)
Prohibited Activities
The following activities are strictly prohibited:
Security Violations
- Sharing passwords or user credentials with others
- Attempting to access unauthorized systems or data
- Bypassing or disabling security controls
- Installing unauthorized software or applications
- Connecting unauthorized devices to the network
- Using personal file sharing or cloud storage for company data
- Downloading or installing pirated software
- Attempting to hack, crack, or circumvent security measures
Data Misuse
- Unauthorized access to confidential or sensitive information
- Copying company data to personal devices without authorization
- Sharing proprietary information with unauthorized parties
- Using company data for personal gain
- Transmitting confidential data over unsecured channels
- Storing customer data on personal devices
Inappropriate Content
- Accessing, storing, or distributing pornographic material
- Gambling or gaming websites (except job-related research)
- Hate speech, discriminatory, or harassing content
- Illegal content of any kind
- Material that violates copyright or intellectual property
Network Abuse
- Excessive personal internet use affecting bandwidth
- Streaming video/audio for non-business purposes
- Cryptocurrency mining on company equipment
- Operating personal businesses using company resources
- Mass distribution of spam or chain emails
- Port scanning or network reconnaissance
Legal & Compliance Violations
- Activities that violate laws or regulations
- Fraudulent, deceptive, or misleading activities
- Harassment, intimidation, or hostile communications
- Unauthorized disclosure of confidential information
- Insider trading or securities violations
- GDPR or data protection regulation violations
Email & Communication Guidelines
Professional Email Use
- Use company email for business communications
- Maintain professional tone and language
- Do not use company email for personal mass mailings
- Be cautious of phishing attempts and suspicious emails
- Do not open unexpected attachments or click suspicious links
- Use encryption for sensitive information
- Include appropriate disclaimers in external emails
Instant Messaging & Collaboration Tools
- Use approved collaboration services designated by the company
- Do not share sensitive information in public channels
- Maintain professional conduct in all communications
- Do not use personal messaging apps for business communications
- Be aware that all communications may be monitored and archived
Social Media
- Do not disclose confidential company information on social media
- Personal opinions should not be presented as company positions
- Follow company social media policy for professional accounts
- Do not engage in social media during work hours (except job-related)
- Report any security incidents observed on social media
Internet & Web Browsing
Guidelines
- Internet access provided primarily for business purposes
- Reasonable personal use permitted during breaks
- Visiting inappropriate websites is prohibited
- Downloading files requires caution and virus scanning
- Remote access to production systems is by SSH with key-based authentication only; passwords are not accepted.
- All internet activity may be logged and monitored
- Report suspicious websites or phishing attempts
Device Security Requirements
Company-Owned Devices
- Physical Security: Never leave devices unattended in public places
- Screen Lock: Enable automatic lock after 5 minutes of inactivity
- Strong Passwords: Use complex passwords (minimum 12 characters)
- Encryption: Full disk encryption required on all laptops
- Updates: Install security updates within 7 days of release
- Antivirus: Keep antivirus/EDR software active and updated
- Lost/Stolen: Report immediately to security@pops.gg
- Personal Use: Limited personal use permitted, subject to monitoring
Laptop Security
- Use cable locks in public areas
- Never check laptops as airline baggage
- Avoid working on sensitive data in public view
- Use privacy screens in public locations
- Backup important data regularly
- Do not repair devices yourself - report immediately to security@pops.gg
Mobile Device Security
- Enable biometric authentication (fingerprint/Face ID)
- Use strong passcode (minimum 6 digits)
- Install only approved business applications
- Do not jailbreak or root devices
- Enable remote wipe capability
- Keep device OS and apps updated
- Be cautious with app permissions
- Report lost/stolen devices immediately
Bring Your Own Device (BYOD)
Employees may use personal devices for work purposes under the following conditions:
Eligibility & Enrollment
- BYOD enrollment must be approved by the company director
- Device must meet minimum security requirements
- Devices must have encryption, screen-lock and remote-wipe enabled
- Acknowledgment of BYOD terms and conditions
- Supported devices: iOS 15+, Android 12+, Windows 10+
Security Requirements
- Device Controls: Devices must have encryption, screen-lock and remote-wipe enabled
- Passcode: Strong passcode/PIN required
- Encryption: Device encryption must be enabled
- Updates: Keep OS and security patches current
- Lock Screen: Auto-lock after 5 minutes maximum
- Work Profile: Separate work and personal data containers
- Approved Apps: Only install work apps from approved list
Company Rights
- Remote wipe of company data (not personal data)
- Right to disable access to company systems
- Monitoring of company data and applications
- Enforcement of these device security requirements
- Inspection of device security settings
User Responsibilities
- Maintain device security at all times
- Report lost/stolen devices immediately (within 2 hours)
- Do not share device with others
- Backup personal data regularly (company not responsible)
- Unenroll device before selling or disposing
- Keep encryption, screen-lock and remote-wipe enabled and updated
- Separate work and personal activities
Prohibited on BYOD Devices
- Jailbreaking (iOS) or rooting (Android)
- Storing customer payment card information
- Accessing company systems from untrusted networks using shared or password-only credentials
- Installing unauthorized mobile apps
- Sharing company credentials with personal apps
Device Termination
Upon termination of employment or BYOD enrollment:
- All company data will be remotely wiped
- Access to company systems will be revoked
- Company accounts and data must be removed from the device
- Personal data remains on device (not affected by wipe)
- Employee retains ownership of device
Remote Work Security
Home Office Security
- Secure home Wi-Fi with WPA3 or WPA2 encryption
- Use strong, unique Wi-Fi password
- Change default router credentials
- Keep router firmware updated
- Create separate guest Wi-Fi network
- Physical security of home office area
- Privacy when on video calls (consider background)
- Secure physical documents (locked drawer/cabinet)
Remote Access Requirements
- Mandatory: Remote access to production systems is by SSH with key-based authentication only; passwords are not accepted.
- Keep SSH private keys protected with a passphrase and never share them
- Enable multi-factor authentication on all hosted and admin accounts
- Report suspected credential or key compromise immediately
Public Spaces & Travel
- Avoid accessing sensitive data in public places
- Use privacy screen on laptops in public
- Never leave devices unattended
- Be aware of shoulder surfing
- Use hotel safe for devices when not in room
- Avoid using public computers for company business
- Only connect to company systems over encrypted channels (HTTPS/SSH) on public Wi-Fi
- Report suspicious activity or device tampering
Data Handling & Storage
Approved Storage Locations
- Approved cloud storage designated by the company
- Company-issued devices with encryption
- Approved collaboration services designated by the company
Prohibited Storage
- Personal email accounts (Gmail, Yahoo, etc.)
- Personal cloud storage (Dropbox personal, iCloud personal)
- USB drives (except encrypted, approved drives)
- External hard drives without authorization
- Personal devices (unless enrolled in BYOD)
- Public file sharing sites
Data Classification Handling
- Confidential Data: Encrypted storage, secure transmission, need-to-know access
- Internal Data: Access controls, approved systems only
- Public Data: May be shared externally per company policy
- Label sensitive documents appropriately
- Do not leave confidential documents on printers
- Shred confidential papers before disposal
Monitoring & Privacy
Notice of Monitoring
By using company systems, you acknowledge and consent to:
- All activities on company systems may be monitored, logged, and audited
- Email, internet usage, and file access may be reviewed
- Security tools monitor for threats and policy violations
- There is no expectation of privacy on company systems
- Personal use of company systems subject to monitoring
- Monitoring for legal, security, and business purposes
- Collected data retained per company retention policy
BYOD Privacy: On BYOD devices, only company data and work profile activities are monitored. Personal data and personal app usage are not monitored.
Policy Violations & Consequences
Violation Reporting
- Employees must report suspected policy violations
- Report security incidents immediately to security@pops.gg
- Report suspicious activity or phishing attempts
- Whistleblower protections apply to good-faith reports
- Reports may be made by email to compliance@pops.gg
Disciplinary Actions
Violations may result in disciplinary action including:
- Minor Violations: Verbal warning, mandatory retraining
- Moderate Violations: Written warning, temporary access suspension
- Serious Violations: Access revocation, unpaid suspension, termination
- Criminal Violations: Termination, law enforcement referral, prosecution
Discipline is determined based on severity, intent, history, and business impact. Management discretion applies to all violations.
Policy Acknowledgment
All employees, contractors, and third parties must acknowledge this policy:
- Read and understand this Acceptable Use Policy
- Sign acknowledgment upon hire/engagement
- Re-acknowledge annually
- Re-acknowledge after material policy updates
- Acknowledgment recorded by the company