Pocket Docket — legal

Acceptable use policy


This policy sets out what you may and may not do with Pocket Docket. It forms part of your agreement with Pocket Docket Ltd (company number NI742827, registered office 137 York Road, Belfast, BT15 3GZ), and "we", "us" and "our" mean that company. "You" means the business that subscribes and everyone who uses the service through that subscription.

It is short on purpose. If you are running a normal business and using Pocket Docket to look at your own numbers, you will not come near any of it.

1. One business, one subscription

A subscription covers one business — one Xero organisation and the people who work in that business.

2. Do not resell it

You may not resell, sublicense, rent, white-label, or otherwise make Pocket Docket available to anyone else, whether for money or not. That includes running it as a service for your own clients.

If you are an accountant and you want your clients on Pocket Docket, that is a conversation we want to have — there is a partner route. Do it that way rather than putting your clients behind your own subscription.

3. Do not extract the service

You may not:

You can always get your own data out. Ask us and we will give it to you in a usable form. This clause is about the software, not about your figures.

4. Do not attack the security

You may not attempt to get around the device binding, the link signing, the rate limits, or any other access control — including by tampering with a link key, replaying a token, or accessing a dashboard you were not given.

If you think you have found a security flaw, tell us at security@pocketdocket.co.uk. We will take it seriously, we will not threaten you, and we will tell you what we did about it. Testing you tell us about first is welcome. Testing you do not is not.

5. Only process data you are entitled to process

You must not put data into Pocket Docket, or instruct us to read data, that you have no right to process. That includes accounting records belonging to a business you do not act for and have not been authorised by.

You are the controller of the personal data in your ledger. We are your processor. That means the lawfulness of what is in there is yours to stand behind — you must have your own lawful basis, you must have told the people concerned what you do with their data, and you must not use Pocket Docket in a way that breaks a promise you made to them.

Do not put special category data — health information, and the other categories the law treats as sensitive — into free-text fields in your ledger. Pocket Docket is not built for it and there is no reason for it to be there.

6. Communications the service drafts are yours

Kipp drafts invoices and payment-chasing emails. You are the sender of every one of them. You read it, you approve it, you send it, and it goes out under your business's name.

So you must not use the service:

Debt chasing is regulated behaviour and the responsibility for it sits with you. An AI drafted it; you sent it.

7. No published benchmarking

You may not publish, or provide to a third party, any benchmark test, performance comparison or competitive analysis of Pocket Docket without our written consent. Say what you like about your experience of using it — that is not what this is about.

8. Do not breach Xero's terms

Your Xero organisation is yours, under your own agreement with Xero. You must not use Pocket Docket in any way that breaches that agreement or Xero's developer or API terms. If Xero withdraws or restricts your access, we cannot restore it and the service will stop working for you.

9. Fair use

Pocket Docket is priced as a flat monthly subscription, which only works if usage is broadly normal. We apply rate limits to dashboard requests, sync frequency and AI questions.

Ordinary use will never hit them. If your use is genuinely heavy and legitimate, tell us and we will find a sensible answer — we would rather raise a limit than argue about one. What we will not absorb is automated or abusive volume, and we may throttle it without notice to protect the service for everyone else.

10. What happens if you breach this policy

Depending on what has happened, we may:

  1. tell you, and give you a reasonable chance to put it right — this is what happens in almost every case;
  2. suspend your access, or part of it;
  3. terminate your subscription, under the termination provisions of your agreement.

We will suspend without warning only where we have to — an active security threat, a legal requirement, a risk to other customers, or something plainly unlawful. Where we suspend, we will tell you why, tell you what would end the suspension, and lift it as soon as the reason is gone.

Suspension under this policy is separate from anything to do with billing. We can suspend for an acceptable-use breach whether or not your payments are up to date, and the fact that your subscription is paid in full is not an answer to a breach. Equally, a billing problem is a billing problem — it is not an acceptable-use breach and it will not be handled as one.

Suspension does not stop the charges running, unless we say otherwise.

11. Changes

We may change this policy. Where a change materially restricts what you can do, we will give you reasonable notice by email before it takes effect.

12. Questions

If you are not sure whether something is allowed, ask us at support@pocketdocket.co.uk before you do it. We would much rather answer a question than send a warning.


Pocket Docket Ltd · registered in Northern Ireland, company number NI742827 · registered office 137 York Road, Belfast, BT15 3GZ

Version 1.0 · in force from 21 August 2026

© 2026 Pocket Docket Ltd · Registered in Northern Ireland, company number NI742827 · Registered office: 137 York Road, Belfast, BT15 3GZ · ICO registration ZC223982