Acceptable Use Policy
Sets out the activities that are prohibited on the Services. The Customer is responsible for ensuring that all Users comply with this AUP at all times.
A1Purpose
- This Acceptable Use Policy ("AUP") sets out the activities that are prohibited on the Services. The Customer is responsible for ensuring that it, its employees, agents, contractors, end users and any other person who uses the Services through the Customer's connection (collectively, "Users") complies with this AUP at all times.
- Breach of this AUP is a material breach of the Agreement and may result in the suspension or termination of the Services in accordance with the Terms of Service.
- We may amend this AUP from time to time to reflect changes in law, regulatory requirements, or operational practice. Material changes will be notified to the Customer at least thirty (30) days in advance, save where the change is required by law or to address an immediate security or stability risk.
A2Compliance with Law
The Customer must not use the Services, and must ensure that no User uses the Services, in any manner that:
- breaches any applicable law of the United Kingdom or of any jurisdiction in which the Services are received or accessed;
- infringes the Intellectual Property Rights of any third party;
- breaches the Online Safety Act 2023, the Computer Misuse Act 1990, the Communications Act 2003 (including section 127), the Protection from Harassment Act 1997, or the Investigatory Powers Act 2016;
- breaches the UK GDPR, the Data Protection Act 2018 or the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"); or
- breaches any sanctions or export control regime to which we or the Customer are subject.
A3Prohibited Content
The Customer must not transmit, store, host, distribute, link to, or otherwise make available via the Services any Content which:
- constitutes, depicts, facilitates or promotes child sexual abuse material ("CSAM"), or is otherwise illegal under the Protection of Children Act 1978 or the Coroners and Justice Act 2009;
- constitutes terrorism content, terrorist publications, or material likely to encourage acts of terrorism within the meaning of the Terrorism Acts 2000 and 2006;
- is obscene, defamatory, threatening, harassing, or stirs up hatred on the grounds of race, religion, sexual orientation, disability or gender identity;
- infringes copyright, trade marks, design rights, patents, database rights, rights in confidence or any other Intellectual Property Right;
- contains malware, ransomware, worms, trojans, key-loggers, time-bombs, cancelbots, spyware, or any other malicious code; or
- is otherwise unlawful or actionable under the laws of England and Wales.
A4Network Abuse and Security
The Customer must not, and must not permit any User to:
- gain or attempt to gain unauthorised access to any computer system, network, account, server, data or service ("hacking");
- conduct, or knowingly facilitate, denial-of-service or distributed denial-of-service attacks, traffic amplification or reflection attacks, or any similar conduct intended to disrupt the operation of any service;
- scan, probe or test the vulnerability of any system or network without the documented prior consent of its operator;
- intercept, monitor, or examine any data or traffic on the network without lawful authority;
- engage in IP address or AS number spoofing, route hijacking, route leaking, or the announcement of prefixes which the Customer is not authorised to originate;
- forge or falsify TCP/IP headers, email headers, or any element of message routing or attribution information;
- engage in port-scanning of third-party hosts other than for legitimate, authorised security testing;
- operate open relays, open recursive DNS resolvers vulnerable to amplification, open proxies, or any service that materially contributes to abuse of third-party networks; or
- use the Services to host, command, control, or exfiltrate data to or from a botnet.
The Customer is responsible for the security of its own systems and the systems of its Users. We are not obliged to monitor traffic for security threats, but we may do so where reasonably necessary for the protection of our network or our other customers.
A5Email, Messaging and Anti-Spam
- The Customer must not send, relay or facilitate the sending of unsolicited bulk or commercial electronic communications ("Spam") in breach of PECR or equivalent law in the recipient's jurisdiction. The Customer warrants that any direct marketing it sends complies with the consent and information requirements of PECR and the UK GDPR.
- The Customer must not harvest email addresses or other contact details, send messages with forged or misleading sender information, or otherwise breach the published anti-abuse policies of any major email provider.
- We reserve the right to filter, rate-limit or block traffic that we reasonably believe to be Spam, malware-bearing or part of a phishing campaign.
A6Routing and BGP Hygiene
Where the Customer receives BGP transit or peering with us, the Customer must:
- only announce IP prefixes that the Customer is the registered holder of, or for which it has documented authorisation from the registered holder (e.g. a Letter of Authority);
- maintain accurate route objects in an authoritative IRR database (RIPE, RADb, ARIN or other recognised registry) and accurate ROAs in the RPKI for all prefixes announced;
- not announce more-specific prefixes for the purpose of route hijack, traffic interception or denial of service;
- apply ingress and egress filtering on its network in accordance with BCP 38 (RFC 2827) and BCP 84 (RFC 3704) to prevent the propagation of spoofed source addresses; and
- co-operate with us in good faith to investigate and remediate any routing incident affecting our network or the wider internet.
We may filter, suppress, or refuse to propagate any prefix announced by the Customer which is inconsistent with the IRR or RPKI, or which we reasonably believe to be the subject of a route hijack, leak or other misconfiguration.
A7High-Risk and Restricted Uses
- Some Services may be used in environments where failure could lead to death, personal injury, or environmental damage (such as the operation of nuclear facilities, life-support systems, air traffic control, or emergency services dispatch) ("Life-Critical Use"). The Customer must notify the Company in writing prior to deploying any Service for a Life-Critical Use. Upon receipt of such notification, the parties shall agree in writing any additional technical, operational or contractual requirements appropriate to that use case. The Customer acknowledges that the standard Services and standard SLA commitments may not, without such agreement, be sufficient for Life-Critical Use, and that the Company accepts no liability for loss or damage arising from Life-Critical Use where the Customer has failed to notify us in advance.
- Use of the Services for the operation of public electronic communications networks or services regulated by Ofcom remains the responsibility of the Customer, including any obligations under the General Conditions of Entitlement, the Online Safety Act 2023, and the Investigatory Powers Act 2016.
A8Reporting Abuse
- Reports of suspected abuse should be sent to [email protected]. Reports concerning CSAM should additionally be reported to the Internet Watch Foundation at iwf.org.uk. Reports concerning terrorism content may be made to the Counter Terrorism Internet Referral Unit at gov.uk/report-terrorism.
- We aim to acknowledge bona fide abuse reports within one (1) Business Day and to take proportionate action where the report is substantiated.
A9Enforcement
Where we reasonably believe that the Customer or a User has breached this AUP, we may, without prejudice to any other right or remedy, take any one or more of the following actions:
- require the Customer to remediate the breach within a specified period;
- filter, throttle or null-route traffic associated with the breach;
- suspend the affected Service in whole or in part;
- terminate the Agreement in accordance with the Terms of Service; and/or
- disclose information about the breach to law enforcement, regulators, or affected third parties to the extent permitted or required by law.