{% extends "withoutnav_template.html" %} {% block page_title %} Terms of use – GOV.UK Notify {% endblock %} {% block maincolumn_content %}

Terms of use

To accept these terms, you must be the service manager for your service. If you’re not the service manager, you’ll need to invite them.

Summary

If we accept your service onto GOV.UK Notify, we agree to:

You agree:

Before you can send real messages:

Our side of the agreement

We agree to send all the messages you pass to us

We will send all the messages you pass to us, as long as they meet our guidelines.

We endeavour to provide continuous uptime for both accepting messages and sending them.

We’ve made sure that GOV.UK Notify can handle large volumes of messages. For email and text messages we have several delivery providers concurrently integrated. This provides GOV.UK Notify with real-time failover capability.

GOV.UK Notify is supported 24/7 for high-priority issues. We provide a ticketing system and escalation routes for service teams to address incidents.

You’ll be able to see how our service is performing on our status page.

We agree to keep your data secure

GOV.UK Notify (as a whole, including subcontractors) currently store personal data for up to 1 year, and non-personal data indefinitely.

GOV.UK Notify has been through an information assurance process to assess information risks, to determine appropriate treatments for those risks and to obtain risk acceptance from the Cabinet Office Senior Information Risk Officer (SIRO). This work includes the completion of a Privacy Impact Assessment to ensure compliance with the Data Protection Act.

We do not conduct, or enable, analysis of when the same recipient (mobile number, email or postal address) is contacted by multiple Government organisations. We may do so if required by law enforcement.

We maintain appropriate technical and organisational measures to protect data. We make sure our subcontractors follow the same procedures.

Cabinet Office act as data processor, as parent organisation of GOV.UK Notify. Your organisation remains the data controller.

We’ll never transfer or store data on servers outside of the European Economic Area.

We agree to give you three months’ notice if we change these terms

We’ll email you if you need to change these terms. We’ll tell you clearly what is changing and when the change will come into effect.

This includes when any of our email, text message or postal providers change.

Your side of the agreement

You agree not to compromise the security of GOV.UK Notify

You agree to get your service assured through your organisation’s information assurance (security) process. You don’t need to include assurance of GOV.UK Notify or our delivery partners, since we’ve already done that - we can share the work we’ve done.

You must tell us immediately if you have any security breaches. This is so we can make sure other services are not affected.

You must follow industry best practices for keeping your API keys secure.

You must ensure you have obtained correct levels of consent - both to send messages but also for how data is shared in order to do so.

You must not perform any load testing on GOV.UK Notify, since we’ve already done it.

You agree not to use GOV.UK Notify to send marketing messages

GOV.UK Notify is for sending transactional messages.

Transactional messages relate directly to something the user did. For example:

  • The user completed a transaction, you send them a confirmation email
  • The user got an MOT a year ago, you remind them that it’s about to expire
  • The user signed up for email alerts, you send them email alerts

You don’t need to ask permission to send messages that directly relate to a transaction. By using a transaction, a user is implicitly agreeing to receive messages about that transaction.

Marketing messages don’t relate directly to something the user did. For example:

  • Telling users about your webinar
  • Sending users government advice
  • Continuing to update someone about a service they no longer use

You must agree not to use GOV.UK Notify to send marketing messages.

If you do use GOV.UK Notify to send marketing messages, we may refuse to accept further messages for delivery.

You agree to send messages consistent with our design patterns, style guide and information security guidelines

Your messages must follow our design patterns, style guide and information security guidelines.

Your messages must not contain any personal, or otherwise sensitive, information.

You agree to use GOV.UK Notify delivery data to continuously improve the quality of your contact data

When you send messages through GOV.UK Notify, we provide feedback on the status of every text message, email and letter.

You agree to use our delivery data to check (and potentially remove) bounced email addresses, mobile numbers and postal addresses from your database.

You agree to ensure your user’s personal data is kept accurate and up to date, in line with Data Protection Act principles.

If you have consistently high bounce rates, we will investigate and may refuse to accept further messages for delivery. This is to protect delivery rates for other services using GOV.UK Notify.

Requesting to go live

Before you can send real messages:

  • you must tell us approximately how many text messages, emails and letters you plan to send
  • you must ensure you have obtained consent to both send messages themselves, but also share data in order to do so
  • if you plan to send more than 250,000 text messages per year or any number of letters, your organisation must agree to pay any costs you run up using GOV.UK Notify
  • we will check the messages you plan to send to make sure they meet our guidelines

You must tell us how many text messages, emails and letters you plan to send

You must estimate how many text messages, emails and letters you plan to send each year, including any spikes or seasonal variation.

We will make sure GOV.UK Notify is easily able to handle your estimated sending volume.

Your organisation must agree to pay any costs you run up using GOV.UK Notify

If you plan to send more than 250,000 text messages per year or any number of letters, your organisation must agree to pay these costs by signing a memorandum of understanding.

If you plan to send fewer than 250,000 text messages per year or you only plan to send email, you don’t need a memorandum of understanding.

We’ll check your templates before you can go live

We’ll check your templates to make sure they are transactional, not marketing, and follow our design patterns, style guide and information security guidelines.

Leaving GOV.UK Notify

You can remove your service from GOV.UK Notify at any time. Contact us and we’ll delete your account.

Any data that you have processed through GOV.UK Notify will be deleted as part of the existing data deletion processes.

{% endblock %}