Home  /  Acceptable Use Policy
Legal

Acceptable Use Policy

Last updated: May 21, 2026 Lexcom Systems Group

Overview

This Acceptable Use Policy ("AUP") governs the use of Lexcom Systems Group's managed IT services, network infrastructure, software platforms, and related technology resources provided to clients. It supplements your Master Services Agreement or Statement of Work and is incorporated into those agreements by reference.

The purpose of this policy is to protect the security, reliability, and integrity of Lexcom's services and the organizations that rely on them.

Scope

This policy applies to:

  • All client employees, contractors, and third-party agents who access or use Lexcom-managed services or infrastructure
  • All systems, networks, applications, and data managed by Lexcom on a client's behalf
  • All communication channels provided or monitored by Lexcom

Clients are responsible for ensuring that all authorized users within their organization are aware of and comply with this policy.

Permitted Use

Lexcom-managed services and infrastructure may be used for:

  • Legitimate business operations and activities consistent with your organization's purpose
  • Authorized communication, collaboration, and productivity tools
  • Accessing cloud services and applications within approved vendor agreements
  • Remote work and access to organizational resources by authorized personnel
  • Business continuity activities and authorized disaster recovery testing
Note: Any use outside normal business operations should be pre-approved with your Lexcom account manager.

Prohibited Activities

The following activities are strictly prohibited on Lexcom-managed systems and networks:

Security violations

  • Unauthorized access to systems, accounts, or data — including those of other organizations
  • Circumventing security controls, authentication mechanisms, or access policies
  • Introducing malware, ransomware, or any malicious code
  • Conducting port scans, vulnerability assessments, or penetration tests without prior written authorization from Lexcom
  • Intercepting network traffic or attempting to capture credentials

Harmful or illegal content

  • Storing, transmitting, or distributing illegal content of any kind
  • Harassment, hate speech, or content that threatens or intimidates individuals
  • Copyright infringement, including unauthorized distribution of software or media
  • Fraudulent communications including phishing simulations without written Lexcom authorization

Network and resource abuse

  • Activities that degrade network performance for other clients or systems
  • Operating cryptocurrency mining software on managed infrastructure
  • Running unauthorized servers, proxies, or relay services
  • Mass email distribution or spam operations
  • Using Lexcom resources for commercial activities not related to your contracted business

Data misuse

  • Exfiltrating or copying data to unauthorized external locations without approval
  • Sharing confidential client or organizational data with unauthorized parties
  • Violating applicable data protection laws, including PIPEDA, PIPA, HIPAA, or GDPR where applicable

Security Obligations

All users of Lexcom-managed services are required to:

  • Use strong, unique passwords and enable multi-factor authentication where required by policy
  • Report suspected security incidents, phishing attempts, or policy violations to Lexcom immediately
  • Lock workstations when unattended and secure mobile devices with a PIN or biometric
  • Use only Lexcom-approved methods for remote access — do not use unauthorized VPNs or remote desktop tools
  • Store organizational data only in Lexcom-approved and managed locations
  • Complete required security awareness training as scheduled

Monitoring

As part of providing managed IT services, Lexcom monitors network traffic, system events, and security alerts on client-managed infrastructure. This monitoring is performed to:

  • Detect and respond to security incidents and anomalous activity
  • Maintain service availability and performance
  • Ensure compliance with this AUP and applicable security policies
  • Fulfill obligations under client compliance frameworks (HIPAA, PCI DSS, etc.)

Monitoring is conducted in accordance with applicable law and client agreements. Users of Lexcom-managed systems should have no expectation of privacy in connection with activities conducted on those systems.

Reporting Violations

If you observe or suspect a violation of this policy, report it immediately through your organization's designated IT contact or directly to Lexcom:

Reports made in good faith will be treated confidentially. Lexcom does not tolerate retaliation against individuals who report suspected violations.

Enforcement

Violations of this policy may result in:

  • Immediate suspension of access to Lexcom-managed services
  • Notification to the client organization's management or legal team
  • Remediation costs charged to the client organization
  • Termination of the service agreement in cases of material breach
  • Reporting to law enforcement where activities are illegal

The appropriate response will depend on the nature and severity of the violation. Lexcom reserves the right to take any action necessary to protect the security and integrity of its services and other clients.

Policy Updates

Lexcom may update this Acceptable Use Policy at any time to reflect changes in services, legal requirements, or security best practices. Updated versions will be published at lexcom.com and lexcom.ca. Continued use of Lexcom services after a policy update constitutes acceptance of the revised terms.

Contact

Questions about this policy should be directed to your Lexcom account manager or:

Lexcom Systems Group — Security & Compliance

Email: security@lexcom.com

Phone: 877‑539‑2663