All legal documents

Acceptable Use Policy

Placeholder Acceptable Use Policy for the Capsules.com public website and B2B customer portal, operated by Capsules UK Ltd. Covers prohibited uses (unlawful activity, IP infringement, security circumvention, scraping, reverse engineering, credential sharing, malware, misrepresenting identity/authority, misuse of customer documents/COAs), content standards for submitted material, account security, suspension and termination for breach, reporting misuse, data protection, changes, and UK governing law. Written for UK-first launch under UK GDPR, the Data Protection Act 2018, and PECR, with bracketed [PLACEHOLDER] markers for company number, registered address, contact/DPO emails, ICO registration, and governing-law venue. Requires legal review before publication.

Draft — pending legal review

This is placeholder content prepared for internal review and is not legal advice. It must be reviewed and approved by a qualified legal professional before publication. Items marked [PLACEHOLDER] require specific information.

Last updated: 22 June 2026

Introduction

This Acceptable Use Policy ("Policy") sets out the terms on which you may access and use the Capsules.com public website (the "Website") and the private customer portal (the "Portal"), together referred to in this Policy as the "Services". The Services are operated by Capsules UK Ltd, a company registered in England and Wales ([PLACEHOLDER: registered company number]), whose registered office is at [PLACEHOLDER: registered address] ("we", "us", "our").

Capsules.com is a business-to-business supplier of empty two-piece HPMC and gelatin capsules to trade customers such as manufacturers, contract packers, and brand owners. The Services are intended for use by businesses and their authorised personnel only, and are not directed at consumers. By accessing or using the Services you confirm that you are acting in the course of a business and that you accept and will comply with this Policy.

This Policy should be read together with our Terms of Use, Terms of Sale (where applicable), Privacy Notice, and Cookie Notice. Where you access the Portal under a trade account, this Policy applies in addition to any account or supply agreement between us and your organisation. If there is a conflict between this Policy and a signed supply agreement, the signed agreement prevails in respect of the matters it covers.

Who This Policy Applies To

This Policy applies to every person who accesses the Website, and to every individual user who is granted access to the Portal under a company trade account. Where access is provided to your organisation, you are responsible for ensuring that each of your personnel who uses the Services does so in accordance with this Policy, and for the acts and omissions of those users as if they were your own.

Portal access is granted at company level, with individual contacts and user accounts created beneath each approved company. Each user must use their own credentials and must be properly authorised by your organisation to act on its behalf. Access to the Portal is subject to our approval of your trade account application and may be varied, suspended, or withdrawn in accordance with this Policy and our other terms.

General Standards Of Use

You must use the Services only for lawful business purposes connected to the legitimate evaluation, sourcing, ordering, and administration of empty capsule products and related documentation. You must comply with all applicable laws and regulations, including UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and any laws governing the products you manufacture or place on the market.

You must not use the Services in any way that breaches this Policy, that is unlawful or fraudulent, that has any unlawful or fraudulent purpose or effect, or that could damage, disable, overburden, or impair the Services or interfere with any other user's use of them. You are responsible for ensuring that all information you provide to us through the Services is accurate, current, and not misleading.

Prohibited Uses

You must not use, or attempt to use, the Services for any of the purposes or activities described below. This list is not exhaustive; conduct of a similar nature that undermines the security, integrity, lawful operation, or intended business purpose of the Services is also prohibited.

  • Unlawful activity: using the Services in breach of any applicable law, regulation, or industry requirement, or to facilitate any unlawful act, including using empty capsule products or product documentation in connection with the manufacture or supply of products that are unlawful in the relevant market.
  • Intellectual property infringement: copying, reproducing, republishing, framing, scraping, harvesting, or otherwise exploiting any part of the Services, our content, branding, product data, specifications, or documentation in a way that infringes our or any third party's intellectual property, confidentiality, database, or other rights.
  • Security circumvention: attempting to gain unauthorised access to the Services, any server, system, or database on which they are hosted, or any account, company record, order, invoice, or document that you are not authorised to access.
  • Probing and testing: probing, scanning, or testing the vulnerability of the Services, or breaching or attempting to breach any authentication, access control, or security measure, without our prior written authorisation.
  • Scraping and automated access: using any robot, spider, crawler, scraper, or other automated means to access, monitor, copy, or extract data from the Services, or placing an unreasonable load on our infrastructure, except for search-engine indexing of the public Website where permitted by our robots directives.
  • Reverse engineering: decompiling, disassembling, reverse engineering, or otherwise attempting to derive the source code, structure, or underlying ideas of the Services, save to the extent such restriction is prohibited by law.
  • Credential sharing: sharing, transferring, selling, or otherwise disclosing your login credentials or any magic-link or single sign-on access, or permitting any person who is not an authorised user of your organisation to access the Portal using your account.
  • Malware and harmful code: uploading, transmitting, or introducing any virus, trojan, worm, logic bomb, ransomware, or other material that is malicious, harmful, or technologically damaging.
  • Misrepresenting identity or authority: impersonating any person or entity, misstating your affiliation with any person or entity, creating an account using false information, or representing that you are authorised to act for a company, contact, or trade account when you are not.
  • Misuse of customer documents: misusing, altering, falsifying, redistributing, or relying outside its intended purpose any Certificate of Analysis (COA), specification, regulatory document, batch-traceability record, invoice, pricing, or other document or data made available through the Portal.
  • Disclosure of confidential pricing: disclosing customer-specific catalogues, agreed pricing, quotes, or hosted payment links to any third party, or using them other than for your organisation's own internal procurement purposes.
  • Interference and circumvention of controls: bypassing, disabling, or interfering with any feature that restricts or controls access, or attempting to access regions, accounts, price lists, or documents outside the scope of your authorisation.
  • Unsolicited or unlawful communications: using the Services to send unsolicited marketing, spam, or other communications in breach of PECR or applicable law, or to harvest contact details for such purposes.

Content And Submission Standards

These content standards apply to any material you submit to or through the Services, including trade account application notes, company and contact details, support messages, order requests, purchase order references, and any text, files, or attachments you upload ("Submitted Content"). The standards apply to each part of any Submitted Content as well as to its whole.

You must ensure that any Submitted Content is accurate (where it states facts), genuinely held (where it states opinions), and complies with applicable law. Submitted Content must relate to the legitimate business purpose for which the relevant feature is provided. You are solely responsible for Submitted Content and for the consequences of submitting it, and you confirm that you have all rights and consents necessary to submit it to us.

  • Be unlawful, defamatory, obscene, offensive, hateful, harassing, threatening, or inflammatory.
  • Infringe any third party's intellectual property, confidentiality, privacy, or other rights.
  • Contain personal data of any individual unless you are authorised to share it with us for the stated purpose and have a lawful basis for doing so.
  • Be deliberately false, misleading, or designed to deceive, including false statements of company identity, authority, or product requirements.
  • Contain any virus, malicious code, or material intended to interfere with the Services or other users.
  • Promote, or seek documentation in support of, any unlawful product, end use, or activity.
  • Constitute unsolicited advertising, promotional material, or any form of similar solicitation.

We are not obliged to review or monitor Submitted Content, but we may do so, and we may remove, refuse, or restrict any Submitted Content that we reasonably consider to breach this Policy, without notice and at our discretion. Removing Submitted Content does not limit any other rights or remedies available to us.

Account Security And Responsibilities

You are responsible for maintaining the confidentiality of your access credentials and for all activity that takes place under your account. You must keep your sign-in details, magic links, and any single sign-on access secure, must not allow others to use your account, and must use the Services only on devices and networks you reasonably believe to be secure.

You must notify us promptly if you become aware of, or reasonably suspect, any unauthorised access to or use of your account, any loss or compromise of credentials, or any other breach of security affecting the Services. If we believe that account security has been compromised, we may suspend access and require you to reset your credentials before access is restored.

Availability And Changes To The Services

We provide the Services on an "as available" basis and do not guarantee that the Services, or any content or document within them, will always be available, uninterrupted, or error-free. We may suspend, withdraw, or restrict the availability of all or any part of the Services for business or operational reasons, including maintenance, security, and the protection of our systems and data.

Information and documents made available through the Portal, including catalogues, pricing, ETAs, dispatch status, tracking, and regulatory documents, may be updated from time to time. You must rely only on the current version applicable to your account, and must not rely on cached, exported, or out-of-date copies for compliance or commercial decisions where a current version is available to you.

Monitoring

We may monitor and record use of the Services, including access logs, security events, and Portal activity, to operate the Services securely, to detect and prevent misuse, to comply with our legal obligations, and to protect our rights and those of our customers. Any monitoring and any processing of personal data will be carried out in accordance with applicable data protection law and our Privacy Notice.

Suspension And Termination For Breach

If you breach, or we reasonably suspect that you have breached, this Policy, we may take any action we consider appropriate and proportionate. This includes issuing a warning, removing or restricting Submitted Content, suspending or terminating your individual user access or your organisation's trade account, and restricting access from particular accounts, devices, or networks.

  • Immediate, temporary, or permanent withdrawal of your right to use the Services.
  • Immediate, temporary, or permanent removal of any Submitted Content.
  • Issuing a warning to you or to your organisation's account administrator.
  • Suspension or closure of individual user accounts or of the company trade account.
  • Disclosure of relevant information to law enforcement authorities where we reasonably consider this necessary or are required to do so by law.
  • Legal proceedings against you or your organisation for reimbursement of all costs on an indemnity basis (including reasonable administrative and legal costs) resulting from the breach.
  • Any other action we reasonably deem appropriate in the circumstances.

Where practicable and appropriate, we will give notice of suspension or termination, but we may act without prior notice where we consider it necessary to protect the security or integrity of the Services, to comply with law, or to protect us, our customers, or third parties. Suspension or termination under this Policy does not affect any rights or obligations that have already accrued, including obligations under any supply agreement or in respect of placed orders or issued invoices.

Reporting Misuse

If you become aware of any use of the Services that breaches this Policy, including security concerns, suspected unauthorised access, misuse of documents, or content that does not meet our content standards, please report it to us as soon as possible so that we can investigate.

Type of reportContact
General misuse or content concerns[PLACEHOLDER: misuse/abuse contact email]
Security vulnerabilities or suspected unauthorised access[PLACEHOLDER: security contact email]
Data protection and privacy matters[PLACEHOLDER: DPO / data protection contact email]

When reporting, please provide enough detail to allow us to identify and investigate the issue, including the date and time, the account or page concerned where known, and a description of what you observed. Please do not test or exploit any suspected vulnerability beyond what is necessary to demonstrate it, and do not access, alter, or download data that does not belong to your organisation.

Data Protection

We process personal data in connection with the Services in accordance with UK GDPR, the Data Protection Act 2018, and our Privacy Notice. The Information Commissioner's Office (ICO) is the supervisory authority for the United Kingdom. Our ICO registration reference is [PLACEHOLDER: ICO registration number]. Any questions about how we handle personal data should be directed to [PLACEHOLDER: DPO / data protection contact email].

Changes To This Policy

We may amend this Policy from time to time to reflect changes in our Services, our business, applicable law, or good practice. The version published on the Website or made available through the Portal is the version that applies to your use of the Services at that time, and we recommend that you review this Policy periodically.

Where changes are material, we will take reasonable steps to bring them to the attention of account administrators, for example by notice within the Portal or by email to the registered account contact. Your continued use of the Services after a change takes effect constitutes acceptance of the amended Policy.

Governing Law And Jurisdiction

This Policy, its subject matter, and its formation are governed by the laws of England and Wales. You and we agree that the courts of [PLACEHOLDER: governing-law venue, e.g. England and Wales] have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Policy, subject to any non-excludable rights you may have under applicable law.

Contact Us

This Policy is operated by Capsules UK Ltd. Questions about this Policy, or about acceptable use of the Services generally, can be sent to us using the details below.

DetailInformation
CompanyCapsules UK Ltd
Registered company number[PLACEHOLDER: registered company number]
Registered address[PLACEHOLDER: registered address]
General enquiries[PLACEHOLDER: general contact email]
Data protection contact[PLACEHOLDER: DPO / data protection contact email]
Last updated[PLACEHOLDER: date this Policy was last updated]

This document is placeholder content prepared for internal drafting purposes and must be reviewed and approved by a suitably qualified legal professional, with all bracketed placeholders completed, before it is published or relied upon.