{% extends "withoutnav_template.html" %} {% block page_title %} Terms of use – GOV.UK Notify {% endblock %} {% block maincolumn_content %}
To accept these terms, you must be the service manager for your service. If you’re not the service manager, you’ll need to invite them.
If we accept your service onto GOV.UK Notify, we agree to:
You agree:
Before you can send real messages:
We will send all the messages you pass to us, as long as they meet our guidelines.
We endeavour to provide continuous uptime for both accepting messages and sending them.
We’ve made sure that GOV.UK Notify can handle large volumes of messages. For email and text messages we have several delivery providers concurrently integrated. This provides GOV.UK Notify with real-time failover capability.
GOV.UK Notify is supported 24/7 for high-priority issues. We provide a ticketing system and escalation routes for service teams to address incidents.
You’ll be able to see how our service is performing on our status page.
GOV.UK Notify (as a whole, including subcontractors) currently store personal data for up to 1 year, and non-personal data indefinitely.
GOV.UK Notify has been through an information assurance process to assess information risks, to determine appropriate treatments for those risks and to obtain risk acceptance from the Cabinet Office Senior Information Risk Officer (SIRO). This work includes the completion of a Privacy Impact Assessment to ensure compliance with the Data Protection Act.
We do not conduct, or enable, analysis of when the same recipient (mobile number, email or postal address) is contacted by multiple Government organisations. We may do so if required by law enforcement.
We maintain appropriate technical and organisational measures to protect data. We make sure our subcontractors follow the same procedures.
Cabinet Office act as data processor, as parent organisation of GOV.UK Notify. Your organisation remains the data controller.
We’ll never transfer or store data on servers outside of the European Economic Area.
We’ll email you if you need to change these terms. We’ll tell you clearly what is changing and when the change will come into effect.
This includes when any of our email, text message or postal providers change.
You agree to get your service assured through your organisation’s information assurance (security) process. You don’t need to include assurance of GOV.UK Notify or our delivery partners, since we’ve already done that - we can share the work we’ve done.
You must tell us immediately if you have any security breaches. This is so we can make sure other services are not affected.
You must follow industry best practices for keeping your API keys secure.
You must ensure you have obtained correct levels of consent - both to send messages but also for how data is shared in order to do so.
You must not perform any load testing on GOV.UK Notify, since we’ve already done it.
GOV.UK Notify is for sending transactional messages.
Transactional messages relate directly to something the user did. For example:
You don’t need to ask permission to send messages that directly relate to a transaction. By using a transaction, a user is implicitly agreeing to receive messages about that transaction.
Marketing messages don’t relate directly to something the user did. For example:
You must agree not to use GOV.UK Notify to send marketing messages.
If you do use GOV.UK Notify to send marketing messages, we may refuse to accept further messages for delivery.
Your messages must follow our design patterns, style guide and information security guidelines.
Your messages must not contain any personal, or otherwise sensitive, information.
When you send messages through GOV.UK Notify, we provide feedback on the status of every text message, email and letter.
You agree to use our delivery data to check (and potentially remove) bounced email addresses, mobile numbers and postal addresses from your database.
You agree to ensure your user’s personal data is kept accurate and up to date, in line with Data Protection Act principles.
If you have consistently high bounce rates, we will investigate and may refuse to accept further messages for delivery. This is to protect delivery rates for other services using GOV.UK Notify.
Before you can send real messages:
You must estimate how many text messages, emails and letters you plan to send each year, including any spikes or seasonal variation.
We will make sure GOV.UK Notify is easily able to handle your estimated sending volume.
If you plan to send more than 250,000 text messages per year or any number of letters, your organisation must agree to pay these costs by signing a memorandum of understanding.
If you plan to send fewer than 250,000 text messages per year or you only plan to send email, you don’t need a memorandum of understanding.
We’ll check your templates to make sure they are transactional, not marketing, and follow our design patterns, style guide and information security guidelines.
You can remove your service from GOV.UK Notify at any time. Contact us and we’ll delete your account.
Any data that you have processed through GOV.UK Notify will be deleted as part of the existing data deletion processes.