Skip to main content
Mentum
Browse JobsCompaniesSalariesFor EmployersFor UniversitiesLog inSign up
Loading...
Loading...
Mentum

Transparent, skills-based job matching.

Browse JobsCompaniesSalariesFor EmployersFor UniversitiesLog inSign up

© 2026 Mentum. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyLegalTrust CentreAI TransparencyHelp CentreProduct updatesContact

Apprenticeship vacancies provided under the Open Government Licence v3.0. Contains public sector information.

← Back to Legal

Acceptable Use Policy

Last reviewed 14 July 2026 · Next scheduled review 11 May 2027

Controller of record: Mentum. Contact: privacy@mentumjobs.com (data protection); dpo@mentumjobs.com (DPO routing); security@mentumjobs.com (security reports); support@mentumjobs.com (abuse, appeals, general).

Regulatory anchors: UK Equality Act 2010 (ss. 4–12, s. 20, Sch. 9, ss. 158/159); Computer Misuse Act 1990 (ss. 1, 3); Online Safety Act 2023 (Sch. 7 priority categories); Privacy and Electronic Communications Regulations 2003, Reg. 22; UK GDPR & Data Protection Act 2018; Modern Slavery Act 2015; Employment Agencies Act 1973 & Conduct of Employment Agencies and Employment Businesses Regulations 2003.

1. Summary and scope

This policy sets out what users of the Mentum platform may and may not do. It supplements the Terms of Service; where it is more specific, it governs.

Mentum is a platform where candidates share sensitive personal data in exchange for a fair shot at matching roles. Employers access that data in a position of comparative power. The prohibitions in §§ 4–5 protect that exchange; the carve-outs ensure the rules are not themselves a tool of exclusion.

This policy does not create rights for third parties who are not Mentum users or employer account-holders.

2. Who this policy applies to

This policy applies to every person or entity that creates or uses a candidate or employer account on Mentum, accesses any platform surface (authenticated or not) through any client or tool, or conducts security research involving Mentum infrastructure. “User” means any person or entity within these categories. Employer account obligations extend to all team members operating under a shared account.

3. How this policy fits with the Terms of Service and Privacy Policy

Terms of Service (/terms). The Terms set the contractual framework — account obligations, intellectual property, liability limits, governing law. This policy expands on the prohibited-conduct section (Terms § 9) with operational specificity. In a conflict, this policy governs on permitted and prohibited conduct; the Terms govern on contractual liability.

Privacy Policy (/privacy). The authoritative record for personal-data processing, legal bases, data-subject rights, and retention. This policy cross-references it where a prohibition touches UK GDPR or the Data Protection Act 2018 but does not repeat its substance.

AI Transparency Notice (/ai-transparency). Explains the matching pipeline, CV parser, advisor, and AI data flows. Read alongside §§ 4.5 and 5.1 of this policy.

Adjacent documents: Data Processing Agreement — Sub-processor list — Cookie notice — Model Card.

4. Prohibited content

4.1 Illegal job postings, illegal work arrangements, and modern-slavery indicators

Employers must not post, and candidates must not accept, any role that would constitute an illegal work arrangement under the law of England and Wales.

This prohibition covers:

  • Advertising or facilitating any arrangement that constitutes modern slavery, forced labour, or trafficking as defined by the Modern Slavery Act 2015.
  • Requiring candidates to work without pay as a condition of assessment, probation, or as a precursor to a paid role (including unpaid “trial shifts” of unreasonable duration).
  • Advertising roles that require candidates to misrepresent their immigration status or right to work in the United Kingdom.
  • Facilitating or encouraging right-to-work fraud — including both candidates misrepresenting their status and employers turning a blind eye to documentary evidence.
  • Advertising roles for which no genuine vacancy exists, where the primary purpose of the listing is data harvesting, lead generation, or marketing.

This rule does not prohibit: lawful, time-limited unpaid internships compliant with the National Minimum Wage Act 1998; lawful work-experience placements; or immigration-sponsored roles where the sponsorship pathway is disclosed in the listing.

4.2 Discriminatory criteria in job listings

Employers must not include criteria in job listings that would constitute direct or indirect discrimination under the Equality Act 2010 on the basis of any protected characteristic (age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, or sexual orientation — ss. 4–12).

This prohibition covers:

  • Specifying that applicants must be of a particular nationality, ethnicity, or religion where this is not a Genuine Occupational Requirement.
  • Using age-coded language (e.g. “recent graduate”, “young and energetic”, “mature professional”) that functions as a proxy exclusion for a protected characteristic.
  • Specifying requirements that have the effect of excluding disabled candidates where a reasonable adjustment would remove the barrier (Equality Act 2010 s. 20).
  • Including any requirement relating to pregnancy, maternity, or parental leave history.
  • Including any requirement relating to a candidate's gender, gender reassignment, sexual orientation, or civil partnership status.

This rule does not prohibit: Genuine Occupational Requirements with the legal basis stated (Equality Act 2010 Sch. 9); positive-action measures under ss. 158–159; lawful immigration-sponsorship conditions stated in the listing; or language requirements that are a proportionate means of achieving a legitimate aim. Mentum may request evidence before publishing or reinstating a listing.

4.3 Pay-to-apply, upfront fees, deposit, and training-bond schemes

Employers and any third party operating through Mentum must not, in connection with a vacancy listed on or sourced from the platform:

  • Charge, or request a commitment to pay, any fee from a candidate as a condition of applying, being considered, or commencing employment.
  • Request or require a deposit, equipment bond, uniform bond, or training-cost repayment agreement that falls outside the lawful limits set by the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003.
  • Direct candidates to purchase training, certifications, or materials from a connected party as a condition of a role.
  • Withhold earned wages or post-date payment as a form of improper retention.

This rule does not prohibit: lawful training-cost repayment clauses under the Conduct Regs 2003; legitimate salary-sacrifice schemes offered transparently as part of a total compensation package.

4.4 MLM, pyramid, and no-genuine-vacancy “opportunities”

Users must not post any listing or send any message on Mentum that promotes:

  • Multi-level marketing (MLM) or network-marketing structures where income is derived primarily from recruitment rather than product or service sales.
  • Pyramid schemes or any arrangement that constitutes an illegal trading scheme under the Trading Schemes Act 1996.
  • Roles that are framed as “self-employment” or “entrepreneurship” opportunities but in practice require a candidate to pay for stock, kits, or licences to participate.
  • Listings where no genuine, specific, filled vacancy is available at the time of posting.

4.5 Fraudulent, misleading, or fabricated profile and CV content

Candidates must not submit, and must not attempt to game the matching pipeline with, false profile data.

This prohibition covers:

  • Fabricating or materially exaggerating employment history, job titles, responsibilities, or dates of employment.
  • Claiming qualifications, certifications, or licences that are not held.
  • Submitting a CV that was written by, or substantially generated by, an AI tool in a way that misrepresents the candidate's genuine experience, skills, or credentials — specifically, using AI-generated mock work histories or invented qualifications to inflate match scores.
  • Submitting a CV that belongs to, or was written for, a different person.
  • Claiming a right to work in the United Kingdom that is not held.

This rule does not prohibit: using AI writing tools, editing tools, or professional CV services to improve the presentation of genuine experience; translating or describing equivalent international qualifications as accurately as possible. Mentum will not penalise candidates for differences in degree nomenclature or for employment gaps attributable to caring responsibilities, disability, illness, or other protected circumstances (Equality Act 2010 — indirect discrimination via sex and disability). Per-application CV tailoring that inflates profile data is a deliberate non-feature of Mentum; the platform scores structured data, not persuasion.

4.6 Sexually explicit, violent, hateful, or harassing content

Users must not upload, post, or transmit content that:

  • Is sexually explicit, pornographic, or intended to sexually harass another user.
  • Contains credible threats of violence or threats to property.
  • Constitutes hate speech — content that threatens, incites hatred towards, or dehumanises a person on the basis of a protected characteristic under the Equality Act 2010 or the Public Order Act 1986.
  • Constitutes harassment of another user within the meaning of the Protection from Harassment Act 1997 — including a course of conduct communicated through the platform that causes alarm or distress.
  • Would constitute illegal content or content harmful to adults under Schedule 7 of the Online Safety Act 2023, in particular content in the fraud and harassment priority categories.

This rule does not prohibit lawful expressions of opinion, criticism of working conditions, professional disagreement, or negative feedback given in good faith.

4.7 Content that infringes intellectual property or breaches confidentiality

Users must not upload, post, or transmit:

  • Content that infringes the copyright, trade marks, database rights, or other intellectual property of a third party.
  • Content that discloses another party's trade secrets or confidential information in breach of a contractual or equitable duty of confidence.
  • Content that reproduces another person's CV, cover letter, or profile data without their consent.

5. Prohibited behaviour

5.1 Unauthorised access, scraping, automated extraction, and credential abuse

Users must not access Mentum in any way that is not authorised (Computer Misuse Act 1990 ss. 1, 3). This covers:

  • Scraping, crawling, or extracting data by any automated means — including headless browsers, browser automation frameworks, and AI agents acting on a user's behalf — without prior written consent.
  • Accessing another user's account, profile data, match pipeline, or messages without authorisation.
  • Using credentials, tokens, or session cookies belonging to another user.
  • Reverse-engineering, decompiling, or disassembling any part of the platform.
  • Using Mentum for competitive intelligence — for example, signing up as an employer to harvest candidate salary expectations, or as a candidate to map a competitor's hiring pipeline.

This rule does not prohibit: assistive technology — screen readers (JAWS, NVDA, VoiceOver), switch-control devices, eye-tracking, voice-control software, browser translation extensions, and AI-assisted writing tools supporting a disability or language barrier — is expressly permitted (Equality Act 2010 s. 20). Search-engine crawling of public pages is permitted; crawling authenticated surfaces is not.

5.2 Automated signups, fake accounts, sock-puppet accounts, and role-impersonation accounts

Users must not:

  • Create accounts using automated scripts or bots. Signups are rate-limited to 5 per 5 minutes per user or IP, and 3 per hour per normalised email address.
  • Create candidate accounts to act as a recruiter or talent scout without disclosing the employer relationship.
  • Create employer accounts to impersonate a different entity, harvest candidate data, or misrepresent a vacancy.
  • Create fake or substantially fictitious accounts for any purpose, or allow a third party to create accounts on your behalf without your active, ongoing knowledge and consent.

5.3 Multiple accounts

Each person may hold at most one candidate account and one employer account on Mentum at any one time.

This rule does not prohibit: holding one account of each type simultaneously (a candidate who also posts jobs); re-registering after involuntary account loss from illness, bereavement, or technical failure — contact support@mentumjobs.com and Mentum will transfer history where possible (Equality Act 2010 — disability, sex). Creating a second account to evade an active suspension is a violation regardless of the stated reason.

5.4 Off-platform contact intended to evade safeguarding, fees, or platform controls

Users who make initial contact through Mentum must not subsequently solicit the other party to conduct recruitment activity, agree a placement, or exchange personal contact details outside the platform for the purpose of circumventing Mentum's safeguarding controls, messaging policies, or any future fee arrangement.

This rule does not prohibit: sharing a professional profile link (e.g. LinkedIn) for due-diligence during an active, consented match; requesting an accessible communication channel where required by a disability (Equality Act 2010 s. 20); or continuing a professional relationship through ordinary channels once a match has concluded. The prohibition targets use of Mentum as a prospecting mechanism while deliberately bypassing the platform for the substantive interaction.

5.5 Harassment, threats, doxxing, and retaliation

Users must not engage in conduct that constitutes harassment, threats, doxxing, or retaliation in connection with a Mentum interaction — whether that conduct takes place on the platform or externally.

This prohibition covers:

  • Sending threatening, abusive, or persistently unwanted messages through the Mentum chat system.
  • Publishing or threatening to publish another user's private personal information (doxxing) in connection with a Mentum interaction.
  • Retaliating against a user who has submitted a complaint, declined a match, or exercised a right under this policy or the Terms.
  • Harassing, threatening, or intimidating a user outside the platform where the conduct originates from, or is in response to, a Mentum interaction (Online Safety Act 2023 Sch. 7 — harassment as a priority harmful communication category).

Communication style — directness, brevity, or atypical social phrasing — is not itself a breach. Mentum assesses conduct against content (threats, abuse, slurs, coordinated harassment), not against a particular cultural or neurotypical register (Equality Act 2010 — disability: neurodivergence; race: cross-cultural register).

5.6 Spam, unsolicited commercial communications, and PECR Reg. 22 breaches

Users must not use the Mentum messaging system to send:

  • Unsolicited commercial communications unrelated to an active, consented match interaction.
  • Bulk messages sent to multiple recipients using scripted or semi-automated tools.
  • Marketing communications from a business to a candidate who has not consented to receiving them, in breach of PECR Regulation 22.
  • Phishing messages, messages containing malicious links, or messages designed to induce a recipient to disclose credentials or personal data.

Mentum rate-limits chat messages to 30 per minute per user.

5.7 Circumventing rate limits, idempotency controls, security controls, or anti-abuse mechanisms

Users must not attempt to circumvent any technical control Mentum operates:

  • Rotating email addresses, IP addresses, phone numbers, or device fingerprints to defeat per-user or per-IP rate limits.
  • Using plus-tags, subaddressing, or aliasing to defeat per-email signup limits. Email normalisation strips plus-tags and resolves googlemail.com aliases before rate-limit accounting.
  • Resubmitting requests with different payloads to an Idempotency-Key-protected endpoint to trigger duplicate side effects.
  • Submitting crafted inputs or triggering repeated expensive AI operations to exhaust the platform's daily AI spend budget.

5.8 Interference with platform infrastructure, security testing without coordination, and denial-of-service

Users must not:

  • Conduct denial-of-service or resource-exhaustion attacks.
  • Inject malicious content — SQL injection, XSS, SSRF, or similar — into any input surface. XSS patterns are logged as security events.
  • Upload malware, exploit payloads, zero-bomb archives, decompression bombs, or files with embedded scripts. All uploads are scanned by ClamAV, which fails closed when unavailable.
  • Conduct security testing without prior coordination via the coordinated-disclosure route at § 13.

6. Candidate-specific obligations

In addition to the general rules above, candidates agree to:

  • Maintain an accurate, up-to-date profile. Materially stale or misleading profiles harm both the candidate and employers who rely on them.
  • Use messaging only for genuine communication relating to an active or recently concluded match. Chat is available only after a match has been mutually accepted, scheduled for interview, or progressed to a hire.
  • Treat employer-disclosed information — salary data, interview processes, company-specific detail — as confidential and not use it for competitive intelligence or disclose it to a competitor of that employer.
  • Not upload another person's CV or a CV fabricated to represent a different person.
  • Represent right-to-work and immigration status honestly; update the profile promptly and notify support@mentumjobs.com if status changes.

7. Employer-specific obligations

In addition to the general rules above, employers agree to:

  • Post only genuine, current vacancies the employer is authorised to fill.
  • Use candidate data — profile fields, match scores, CV content, messages — exclusively for recruitment in relation to the specific vacancy that generated the match. Use for LinkedIn enrichment, external prospecting, data brokering, or any unrelated purpose is prohibited (UK GDPR Art. 5(1)(b) purpose limitation).
  • Not approach a candidate through any external channel solely because their data appeared on Mentum, unless the candidate has consented to that channel as part of an active match interaction.
  • Provide accurate job descriptions, salary ranges, work-arrangement terms, and location. Listings that materially misrepresent role details after a match is accepted may be removed without notice.
  • Make hiring decisions on relevant, non-discriminatory criteria. A Mentum match score is a signal, not a decision; it carries no legal weight and may not be used as the sole basis for rejection or selection (see the AI Transparency Notice § 3).
  • Comply with the Equality Act 2010 throughout the hiring process, including reasonable adjustments for disabled candidates (s. 20).
  • Maintain appropriate technical and organisational measures for any candidate data extracted from the platform (UK GDPR controller obligations).

8. Assistive technology and accessibility (explicit allow-list)

The following tools are expressly permitted and are not treated as a violation of § 5.1:

  • Screen readers: JAWS, NVDA, VoiceOver, TalkBack, and equivalents.
  • Switch-control devices, eye-tracking, and head-tracking input hardware.
  • Voice-control software: Dragon NaturallySpeaking, Voice Control (macOS/iOS), Voice Access (Android), and equivalents.
  • Browser translation extensions.
  • AI-assisted writing tools used to support a disability or language barrier — provided the content reflects genuine experience and does not constitute fabrication under § 4.5.
  • Browser zoom, high-contrast mode, forced-colour mode, and other display-accessibility overrides.

Grounded in Equality Act 2010 s. 20. If you use an assistive tool not listed above and are uncertain whether it is permitted, contact support@mentumjobs.com before use.

9. Platform-enforced limits you may notice

This section is informational. The limits below are operational controls; they are not the legal substance of this policy. Exceeding them does not automatically constitute a violation, but attempting to circumvent them does (§ 5.7).

  • Signup: 5 requests per 5 minutes per user or IP; 3 per hour per normalised email address.
  • Login: 5 per minute per IP; 20 per hour per email address. Five failed attempts in 15 minutes triggers a 15-minute account lockout; 10 failed attempts in 24 hours triggers a 1-hour lockout. Login-failure responses are padded to a minimum of 500 ms to prevent email enumeration by timing.
  • Forgot-password: 3 per 15 minutes per IP; 3 per hour per email.
  • Account deletion: 1 request per hour per account.
  • CV upload: 5 per hour per candidate; maximum file size 10 MB; PDF, DOCX, RTF, and TXT formats only. Files undergo magic-byte verification and ClamAV scanning.
  • Other candidate documents: 10 uploads per hour per candidate.
  • Chat messages: 30 per minute per user.
  • AI suggest-reply: 5 per minute and 30 per day per candidate.
  • Data export (subject access request): 1 per hour per user.
  • Public job search: 30 per minute per IP.
  • Candidate block-company list: capped at 20 entries, enforced atomically to prevent race-condition bypass.

These limits are configured by environment variable and may change without notice.

10. Enforcement

10.1 Detection

Detection combines: automated rate-limit and anomaly signals; security-event logging including XSS-attempt events, login-failure sequences, and file-upload integrity failures; user reports (§ 12); and periodic manual review. Pre-release adversarial harnesses cover cross-tenant authorisation, timing oracles, upload abuse, and AI prompt-injection.

Mentum does not use AI to moderate user content. Detection is based on technical signals, rate data, and human review.

10.2 Response ladder

Mentum's response to a suspected violation is proportionate to the severity, recurrence, and context. The general ladder is:

  1. Warning. A notice is sent to the registered email address explaining the potential violation and the required change. No account restriction is applied. Appropriate for first-instance, low-severity, or ambiguous violations.
  2. Feature restriction. A specific capability (e.g. messaging, job posting, CV upload) is temporarily suspended pending review or a cure period.
  3. Account suspension. The account is suspended for a fixed period. Access to the platform is blocked; data is retained pending the outcome of any appeal.
  4. Permanent removal. The account is permanently removed. Where the violation is serious (fraud, harassment, modern-slavery indicators, repeated breaches), this step may be taken without prior warning or without traversing earlier steps.

Mentum reserves the right to skip any step in the ladder where the violation is sufficiently serious, ongoing, or where delay would cause harm to another user or to the platform. Employers or candidates who are the subject of regulatory investigation may have their accounts suspended pending the outcome of that investigation.

10.3 Service-role and database-level enforcement primitives

All enforcement actions are implemented at the database layer and are reversible by service-role only. Account suspension is implemented as a long-duration soft block that preserves data for appeal; bulk soft-ban of abusive accounts is performed through a service-role administrative procedure. Content removal is performed by a service-role operator and logged in the audit trail.

10.4 Emergency action and content removal

Where content constitutes an active safety threat, illegal content under the Online Safety Act 2023, or must be removed under a law-enforcement or court order, Mentum will act immediately without traversing the standard ladder.

For urgent safety matters: security@mentumjobs.com, subject line “URGENT SAFETY”.

11. Appeals process

Users who believe an enforcement action was taken in error or was disproportionate may appeal by emailing support@mentumjobs.com with the subject line “Account appeal — [account email]” within 30 days, setting out the facts, the basis for the appeal, and any supporting evidence. Mentum will acknowledge within 5 working days and respond within 30 days; if additional time is needed, Mentum will notify the appellant.

Mentum is operated by a single developer; the appeals process does not involve a separate team. If you believe the appeal has been handled unfairly, you may refer to the Information Commissioner's Office (ico.org.uk/make-a-complaint) for data-protection matters, or to the courts of England and Wales for contractual matters.

12. Reporting abuse

Email support@mentumjobs.com, subject line “Abuse report”. Include: the type of violation (section reference where possible), the reported account identifier where known, and any evidence (screenshots, message excerpts, listing URLs). Reports are treated in confidence; Mentum will not disclose the reporter's identity to the subject except where required by law. Mentum will prioritise reports involving safety risks, illegal content, and modern-slavery indicators.

13. Coordinated vulnerability disclosure

To report a potential security vulnerability: email security@mentumjobs.com with a description, reproduction steps, impact assessment, and proof-of-concept material. Do not exploit the vulnerability, access unauthorised data, or disclose publicly before Mentum has had 90 days to address it. Do not conduct automated scanning (port scanning, fuzzing, load-generation) against production endpoints without prior written approval.

Mentum will acknowledge within 72 hours. There is no paid bug-bounty programme; responsible disclosures will be credited publicly if the reporter consents. Full programme details are published in the repository's SECURITY policy.

14. Mentum's commitments to proportionality and transparency

  • Proportionality. Enforcement actions will be proportionate to the severity of the violation. Mentum will not take permanent action for a first-instance, good-faith mistake.
  • Notice. Where safe and lawful to do so, Mentum will notify the affected user of an action and its reason at or before the time it takes effect.
  • No chilling effect on rights. This policy will not be applied in a way that discourages users from exercising rights under UK GDPR, the Equality Act 2010, or the Online Safety Act 2023 — including the right to complain or report concerns to a regulator.
  • Audit trail. All enforcement actions and content-removal decisions are logged and retained for at least 12 months.
  • Policy changes. Material changes will be notified by email and in-app notice at least 14 days before they take effect (Terms of Service § 14).
  • Public register. Mentum does not publish a public register of enforcement actions at this stage; this will be reassessed as user volume justifies it.

15. Changes to this policy

Mentum may update this policy to reflect changes in applicable law, platform features, or enforcement practice. Material changes will be communicated in accordance with § 14. The last-reviewed date is shown in the document header.

16. Contact

  • Abuse and appeals: support@mentumjobs.com
  • Data protection and privacy: privacy@mentumjobs.com
  • DPO-routed enquiries: dpo@mentumjobs.com
  • Security reports and CVD: security@mentumjobs.com

Supervisory authority for UK data protection matters: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk/make-a-complaint.


Related: Terms of Service | Privacy Policy | AI Transparency Notice | Model Card | Data Processing Agreement | Sub-processors | Cookies