Zemio Logo

Platform Policies

Version 2026-04-14

Operational platform rules, acceptable use standards, and security-related user responsibilities.

Platform Policies

1. Purpose

These Platform Policies supplement the Zemio Terms of Service and describe operational rules for the use of the service.

2. Authorized Use Only

Zemio may only be used by:

  • approved customer organizations;
  • authorized representatives of such organizations;
  • users who have been invited, assigned, or otherwise permitted to access a customer organization within Zemio.

Access to the service is personal to the authorized user account and may not be shared.

3. Customer Administrator Responsibilities

Customer administrators must:

  • assign access rights only to persons with a legitimate organizational need;
  • regularly review memberships and permissions;
  • remove or update access without undue delay when a user changes role or leaves the organization;
  • ensure that uploaded documents and entered data relate only to legitimate expense-report workflows;
  • maintain accurate organization settings, including reviewer and contact details where used.

4. Permitted Content

Users may upload and process only content that is relevant to legitimate expense-report administration, such as:

  • receipts;
  • invoices;
  • supporting images;
  • PDFs and comparable documentation related to reimbursement requests.

Users must not upload content that is unrelated to the service purpose or clearly inappropriate for the agreed organizational use case.

5. Prohibited Conduct

Users must not:

  • attempt to gain unauthorized access to data, accounts, or infrastructure;
  • upload malware, scripts, or harmful payloads;
  • interfere with the security, integrity, or availability of the service;
  • use the service for spam, unlawful activity, or infringement of third-party rights;
  • circumvent role restrictions or organization boundaries;
  • use the service as a general-purpose file archive unrelated to expense administration.

6. Security Expectations for Users

Users and customer organizations are expected to:

  • protect access to their Microsoft account;
  • use current devices and software where reasonably possible;
  • avoid sharing devices or sessions in insecure contexts;
  • report suspected unauthorized access or security incidents without undue delay.

7. Monitoring and Operational Safeguards

Zemio may use operational logging and error monitoring that is reasonably necessary to maintain security, detect incidents, and operate the service.

Zemio does not intend to use session replay or non-essential behavioral tracking in production. If this changes, the relevant legal documentation and settings will be updated before activation.

8. Enforcement

Zemio may investigate suspected violations of these Platform Policies and may take proportionate measures including warnings, temporary restrictions, suspension, or termination for cause where justified.

9. Relationship with Customer Instructions

Where Zemio acts as processor for customer data, customer organizations remain responsible for determining whether specific data should be entered into the service and for ensuring that their users act in accordance with internal organizational policies.

10. Updates

Zemio may update these Platform Policies where reasonably necessary for security, legal compliance, or operational development of the service.