2. Electronic acceptance
Before first use, the user must affirmatively agree to the current Terms, Acceptable Use Policy, and Platform Confidentiality Agreement. The agreement box will not be selected in advance. If a user does not agree, access is not authorized.
Becchio Group may retain a record identifying the user and organization, the date and time, the documents and versions accepted, and technical information used to verify the agreement. A new acceptance may be required after a material update.
3. Credential security
Users must keep passwords, passkeys, recovery codes, and other credentials confidential; use multifactor authentication when required; use unique credentials; and prevent anyone else from using their identity. Credentials may not be shared, pooled, published, or stored insecurely.
Actions performed through an account are attributed to that account unless Becchio Group receives timely evidence of compromise. Becchio Group will never ask a user to send a password by email.
4. Role and workspace boundaries
Access is limited to assigned roles, Client workspaces, records, features, time periods, and business purposes. A visible or technically reachable resource is not authorized merely because a user can locate it. Users may not test boundaries, change identifiers, enumerate records, or attempt to reach another Client's data.
Automated access requires a credential issued for that purpose and must follow documented rate, scope, and identification requirements.
5. Organization responsibilities
An organization that requests or administers accounts must designate authorized users, grant the least access reasonably needed, review access periodically, and promptly request removal when a user's role or relationship changes. The organization is responsible for lawful instructions and for the conduct of users it authorizes.
6. Suspected compromise
Immediately stop using a suspected compromised credential and report unauthorized access, loss of a device, misdirected Client Data, phishing, or an unexpected authentication event to security@becchiogroup.com. Cooperate with reasonable containment, credential rotation, investigation, and notification steps.
7. Suspension, records, and termination
Becchio Group may restrict, revoke, or suspend an account, token, or session to contain risk, protect Client Data or intellectual property, enforce legal terms, comply with a Client instruction or law, or investigate suspected misuse. Access ends when authorization, the engagement, or the account ends.
Security, audit, and legal-acceptance records may be retained after account closure when reasonably necessary for compliance, fraud prevention, dispute resolution, or protection of legal rights.