Skip to content

Acceptable Use Policy

Current published document for ParadoxNetworks services and website visitors.

Effective date
Document
POLICY / AUP
Jump to a section18 sections

By using our services, you agree to comply with our Acceptable Use Policy (“AUP”), so please read it carefully. This policy works alongside our Terms of Service.

1. Prohibited Activities

You are prohibited from using our services to publish content or participate in activities that are illegal under applicable law, harmful to others, or could potentially expose us to liability. This includes, but is not limited to:

1.1 Security and Access Violations#

  • 1.1.1 Unauthorised Network Scanning: Conducting port scans, vulnerability assessments, or security testing on systems or networks without explicit authorisation.
  • 1.1.2 Unauthorised Access: Attempting to gain unauthorised access to accounts, systems, or networks, or attempting to penetrate security measures.
  • 1.1.3 Identity Fraud: Engaging in phishing, spoofing, or any form of identity theft or fraudulent impersonation.
  • 1.1.4 Phishing and Social Engineering: Hosting phishing pages, distributing phishing kits, conducting credential harvesting, or facilitating social engineering attacks.

1.2 Malicious Software and Network Attacks#

  • 1.2.1 Malicious Code: Distributing, uploading, or facilitating the spread of viruses, worms, Trojan horses, ransomware, or other malicious software.
  • 1.2.2 Botnet and Malware Distribution: Hosting, distributing, or operating command and control (C&C) servers for botnets, malware, or other malicious software.
  • 1.2.3 Network Attacks: Facilitating or conducting Denial of Service (DoS), Distributed Denial of Service (DDoS), or other attacks that disrupt network services.
  • 1.2.4 Open and Abusable Services: Operating services that can be used for reflection or amplification attacks (including open DNS resolvers, NTP servers responding to monlist, memcached, SSDP, SNMP, chargen, and similar UDP services reachable from the public internet) is prohibited. Such services must be closed, rate-limited, or restricted to known clients. We may filter or null-route affected addresses without notice where an open service is being used in an attack.
  • 1.2.5 Unauthorised Security Testing: Testing third-party systems (including penetration testing, vulnerability scanning, or stress testing) without their explicit authorisation is prohibited. Testing against your own infrastructure is permitted only with prior written notice to noc@pdxnet.co.uk and within the agreed scope and window.

1.3 Communications and Spam#

  • 1.3.1 Unsolicited Communications: Distributing spam, unsolicited bulk emails, or other unwanted communications.
  • 1.3.2 Spam and Email Abuse: Operating open relays, generating backscatter, harvesting email addresses, or engaging in email abuse practices that violate anti-spam regulations.
  • 1.3.3 Email Authentication: Customers sending email from our network are required to publish valid SPF, DKIM, and DMARC records for the sending domain. Outbound port 25 is blocked by default and unblock requests follow the process in our Terms of Service Section 10.

1.4 Intellectual Property and Content#

  • 1.4.1 Copyright Infringement and Piracy: Distributing, downloading, or facilitating the distribution of copyrighted material without authorisation. Customers receiving copyright infringement notices must immediately cease the infringing activity. Continued infringement after notice may result in immediate service termination.
  • 1.4.2 Intellectual Property Infringement: Violating intellectual property rights, including copyright, trademark, or patent infringement.

1.5 Illegal Goods, Services, and Fraud#

  • 1.5.1 Illegal Goods and Services: Facilitating the sale, distribution, or promotion of illegal goods or services, including drugs, weapons, stolen goods, counterfeit merchandise, or services that violate applicable law.
  • 1.5.2 Fraud and Scams: Engaging in or facilitating fraudulent schemes, including pyramid schemes, investment fraud, romance scams, advance-fee fraud, or other deceptive practices.

1.6 Illegal Content and Discrimination#

  • 1.6.1 Illegal Content: Publishing, hosting, or distributing content that is illegal under applicable law, including illegal escort services and non-consensual intimate imagery. Adult content and pornography are permitted only when fully compliant with UK law, including the age assurance duties in Part 5 of the Online Safety Act 2023 and the consent of all participants.
  • 1.6.2 Hate Speech and Discrimination: Promoting, facilitating, or engaging in hate speech, discrimination, or harassment based on protected characteristics including race, ethnicity, religion, gender, sexual orientation, disability, or national origin.

1.7 Cryptocurrency and Resource Abuse#

  • 1.7.1 Cryptocurrency Mining: Cryptocurrency mining of any form (including proof-of-work, proof-of-space, and similar resource-intensive consensus mechanisms) is prohibited on all VPS, dedicated, and shared services, regardless of whether the underlying resources belong to the customer. Mining within colocation services is permitted only where the customer's equipment stays within their committed power, cooling, and bandwidth allocations as set out in Section 8. Sustained overuse of these allocations will result in throttling, additional charges, suspension, or termination.

1.8 Customer Responsibility#

  • 1.8.1 Third-Party Liability: Customers are responsible for the actions of all authorised users of their account. Customers may not resell, redistribute, or allow third parties to use services for prohibited activities.

2. Child Sexual Abuse Material (CSAM)

ParadoxNetworks Limited has a zero-tolerance policy for child sexual abuse material (CSAM) and any content depicting the exploitation or abuse of minors. This is a serious criminal offence and a severe violation of this policy.

2.1 Prohibited Activities#

  • 2.1.1 Publishing, distributing, possessing, or facilitating access to CSAM
  • 2.1.2 Creating, producing, or commissioning content depicting the exploitation or abuse of minors
  • 2.1.3 Grooming, soliciting, or facilitating the abuse of minors
  • 2.1.4 Any activity that sexualises, exploits, or harms children

2.2 Mandatory Reporting#

ParadoxNetworks Limited will:

  • 2.2.1 Immediately suspend or terminate services upon discovery of CSAM or child exploitation
  • 2.2.2 Preserve all data and evidence for law enforcement, overriding any standard data deletion policies
  • 2.2.3 Report content to the Internet Watch Foundation (IWF) (the UK hotline at iwf.org.uk) and to the National Crime Agency (NCA) / CEOP as appropriate
  • 2.2.4 Where content concerns US-hosted infrastructure or US persons, also report to the National Center for Missing & Exploited Children (NCMEC)
  • 2.2.5 Report violations to other relevant law enforcement authorities
  • 2.2.6 Cooperate fully with investigations
  • 2.2.7 Not provide advance notice before reporting to authorities

Customers acknowledge that ParadoxNetworks Limited will not hesitate to report suspected child exploitation to law enforcement and will not provide warning or opportunity to delete evidence.

3. Blacklist Policy

You are prohibited from utilising our services in a manner that results in us or our resources being subjected to blacklisting or blocking. We retain the right to suspend or terminate your services, account, and any access to our network or physical infrastructure. Engaging in operations or reselling services on behalf of or in connection with individuals or entities listed on Spamhaus lists (including SBL, XBL, DBL, ROKSO, and AS-DROP) will be regarded as a breach of this policy. We also rely on other widely-used reputation feeds (for example Spamcop and SORBS) and our own internal reputation data when evaluating abuse and reseller eligibility.

abuse@pdxnet.co.uk is our published abuse contact (RFC 2142) and is reflected in the abuse-c attribute of our RIPE objects.

3.1 Abuse Reporting and Customer Cooperation#

Customers who discover abuse or violations occurring on their account must immediately report such activity to abuse@pdxnet.co.uk. Customers are required to:

  • 3.1.1 Promptly report any suspected abuse or policy violations
  • 3.1.2 Cooperate fully with ParadoxNetworks Limited investigations
  • 3.1.3 Preserve evidence and logs related to suspected abuse
  • 3.1.4 Implement reasonable security measures to prevent unauthorised use
  • 3.1.5 Notify ParadoxNetworks Limited immediately upon discovering account compromise

Failure to report known abuse or cooperate with investigations may result in service suspension or termination.

3.2 Monitoring and Logging#

ParadoxNetworks Limited reserves the right to monitor network traffic, account activity, and service usage to detect and prevent violations. Customers acknowledge that:

  • 3.2.1 Account activity may be monitored for compliance purposes
  • 3.2.2 Logs may be retained for abuse investigation and law enforcement cooperation
  • 3.2.3 Monitoring may include automated detection systems and manual review
  • 3.2.4 Evidence of policy violations may be shared with law enforcement
  • 3.2.5 Customers have no expectation of privacy in activities that violate this policy

Traffic and abuse-related logs (including netflow records, connection logs, and abuse case records) are retained for 6 months, after which they are deleted. Logs are retained beyond this period only where required by law, by a valid legal order, or where they form part of an open abuse investigation, in which case they are deleted once the matter is closed. Billing and account data follows the retention period in Terms of Service Section 15.3.

3.3 Abuse Response Times#

Customers must acknowledge and act on abuse notices we forward to them within:

  • 3.3.1 4 hours for active incidents, including outbound attack traffic, active phishing pages, malware distribution, and botnet command and control
  • 3.3.2 24 hours for all other abuse reports

Where a customer does not respond within these windows, or where an incident is causing ongoing harm to third parties or to our network, we may suspend the affected service, null-route the affected addresses, or filter the traffic without further notice. We aim to restore service promptly once the issue is resolved and confirmed.

3.4 Appeals and Reinstatement#

Customers who believe a suspension was made in error may appeal by emailing abuse@pdxnet.co.uk with the service details and the basis of the appeal. We aim to review appeals within 2 business days. Where a suspension was made in error, service is restored at no charge. Repeat suspensions arising from the same unresolved issue may attract the reactivation fee in Terms of Service Section 4.5, and we may decline to reinstate services where a violation is serious or repeated.

3.5 Resellers#

Customers who resell our services to their own end users must:

  • 3.5.1 Impose terms on their end users that are at least as restrictive as this AUP
  • 3.5.2 Publish and monitor their own abuse contact, and keep it accurate in RIPE and WHOIS records for any resources we assign to them
  • 3.5.3 Act on abuse notices we forward within the timeframes in Section 3.3, including identifying and suspending the responsible end user
  • 3.5.4 Retain the records needed to identify the end user responsible for traffic from any address assigned to them

Resellers remain fully responsible to us for the conduct of their end users. Persistent failure to handle end-user abuse is a breach of this policy and may result in suspension or termination of the reseller's own services.

4. Prohibited Network Activities

4.1 Tor Nodes#

The use of Tor Exit, Tor Relay, and Tor Bridge nodes on our network using our IP address space is strictly prohibited. This restriction prevents abuse complaints, IP reputation damage, and blacklisting of our network resources. Violation will lead to the immediate suspension and/or termination of services.

4.2 VPN, Proxy, and Anonymisation Services#

Private VPN and proxy services for your own use, or for a defined set of known users (for example a corporate remote-access VPN), are permitted. Public or commercial VPN, proxy, and anonymisation services, including free or open exit nodes and services offered to anonymous members of the public, require our prior written approval.

Where approval is given, the operator must:

  • 4.2.1 Keep records sufficient to identify the user responsible for traffic at a given time, and produce them in response to an abuse report or valid legal request
  • 4.2.2 Block outbound port 25 and other commonly abused ports on their service
  • 4.2.3 Publish and monitor a working abuse contact, and act on notices within the timeframes in Section 3.3

Open proxies, open SOCKS servers, and services that make anonymous relaying available to the public without any means of identifying the responsible user are prohibited.

5. BGP Usage Policy

BGP services are provided under strict compliance policies to ensure the stability and security of our network and the wider internet.

5.1 BGP Configuration and Use#

5.1.1 Route Announcements#
  • 5.1.1.1 All BGP route announcements must be accurate, necessary, and authorised. Only prefixes owned by the customer or explicitly allowed by the prefix owner should be announced.
5.1.2 Route Registry Accuracy and RPKI#
  • 5.1.2.1 Customers must maintain accurate IRR records for all prefixes they announce.
  • 5.1.2.2 Customers must publish Route Origin Authorisations (ROAs) via RPKI for all announced prefixes. ParadoxNetworks Limited operates Route Origin Validation (ROV) and drops RPKI-invalid prefixes received from customers.
5.1.3 Prevention of Route Leaks#
  • 5.1.3.1 Customers must implement appropriate prefix filters (incoming and outgoing) to prevent route leaks and mis-announcements.
5.1.4 Coordination and Notification#
  • 5.1.4.1 Significant BGP changes or planned large-scale announcements must be pre-coordinated with our network operations team.
5.1.5 Downstream Network Restrictions#
  • 5.1.5.1 Downstream transit for networks deemed bad (at our sole discretion) is not permitted, including any ASN listed on the Spamhaus AS-DROP list. Failure to comply may result in BGP session suspension or service termination.

5.2 BGP Community Usage#

5.2.1 Community Support#
  • 5.2.1.1 Community tags are provided for managing traffic flows and routing policies. Use must follow the published community guide.
5.2.2 Prohibited Uses#
  • 5.2.2.1 Manipulating communities to circumvent traffic engineering, cause unnecessary route propagation, or otherwise destabilise the network is prohibited.

5.3 Monitoring and Compliance#

5.3.1 Monitoring#
  • 5.3.1.1 We actively monitor BGP sessions for anomalies, misconfigurations, and policy violations. Sessions in violation may be temporarily suspended pending resolution.
5.3.2 Compliance#
  • 5.3.2.1 Failure to comply may result in temporary suspension or permanent termination of BGP services.

6. IP Address Allocation

ParadoxNetworks Limited is a RIPE NCC member and assigns IPv4 and IPv6 addresses to customers from its own resources. Addresses are assigned for use with an active service, they are not sold and no ownership passes to the customer.

6.1 Assignment and Justification#

  • 6.1.1 Addresses are assigned on the basis of documented technical need, in line with RIPE NCC policy. Customers must provide reasonable justification for the size of an assignment and for any subsequent increase.
  • 6.1.2 We record assignments in the RIPE database as required by RIPE policy. Customers must supply accurate contact and organisation details for these records and keep them up to date.
  • 6.1.3 Assignments are tied to the service they were issued with. They may not be sold, leased, sublet, transferred, or announced from another network without our prior written approval.

6.2 Utilisation and Reclamation#

  • 6.2.1 Customers must make active use of assigned addresses. We may audit utilisation and request evidence of use.
  • 6.2.2 We may reclaim addresses that are unused, substantially under-utilised, or no longer justified, giving reasonable notice and a period to renumber except where reclamation is required to address abuse or a legal obligation.
  • 6.2.3 On cancellation or termination of a service, all addresses assigned with it are reclaimed and returned to our pool. Addresses may be reissued to other customers after a quarantine period.

6.3 Reputation#

  • 6.3.1 Customers are responsible for the reputation of addresses assigned to them for the duration of their service. Conduct that results in listing on a blocklist is dealt with under Section 3.
  • 6.3.2 We make no guarantee about the prior reputation or listing history of reissued addresses. Where an assigned address is listed on arrival, we will assist with delisting or, where delisting is impractical, reassign an alternative address.
  • 6.3.3 Requests for reverse DNS delegation and for correction of geolocation data are handled by noc@pdxnet.co.uk. We cannot guarantee the accuracy or update timescales of third-party geolocation databases.

6.4 Customer-Owned Address Space#

  • 6.4.1 Customers announcing their own address space through our network must provide a valid Letter of Authority and maintain accurate IRR records and ROAs, in line with Section 5.

7. Resource Usage Policy

7.1 Fair Use of Resources#

7.1.1 CPU and RAM Usage#
  • 7.1.1.1 Activities that consistently consume excessive CPU or RAM may degrade performance for other users. We reserve the right to limit CPU resources for processes that negatively impact server performance.
7.1.2 Bandwidth#
  • 7.1.2.1 Bandwidth is monitored monthly per customer using 5-minute samples across the calendar month.
  • 7.1.2.2 VPS and Bare Metal Fair Use: Unless the plan or order form specifically states otherwise, bandwidth on VPS and bare metal services is subject to a fair-use cap of 100 Mbps measured at the 95th percentile, applied to inbound and outbound traffic separately and evaluated against the higher of the two. Usage above this level may be throttled or, in cases of sustained abuse, result in suspension. Higher committed bandwidth is available on request. Regional transit costs vary, so VPS services in the Asia-Pacific and Oceania regions are measured on volume instead, with a monthly allowance of 3 TB of combined inbound and outbound traffic; beyond that, port speed moves to 100 Mbps until the next calendar month, and additional transfer is available on request.
  • 7.1.2.3 IP Transit (Committed): Transit customers on a committed plan are billed on the 95th percentile against the committed rate stated in their order form, with overage billed per Mbps over the commit at the rate in the order form (see also Section 9 and Terms of Service Section 6.2).
  • 7.1.2.4 IP Transit (Pay-As-You-Go): PAYG transit customers have no committed rate; usage is billed per Mbps on the 95th percentile measurement at the published PAYG rate.

7.2 Monitoring and Enforcement#

7.2.1 Automated Monitoring#
  • 7.2.1.1 Automated systems monitor and manage resource usage across all hosted services.
7.2.2 Notification of Excessive Use#
  • 7.2.2.1 Customers whose usage threatens platform stability will be notified and offered options to reduce usage or upgrade.
7.2.3 Remedial Actions#
  • 7.2.3.1 In significant overuse cases, we may temporarily suspend services or auto-upgrade to a higher plan with customer agreement.

8. Colocation Services Policy

8.1 Power Consumption#

8.1.1 Power Allocation#
  • 8.1.1.1 Each colocation customer is allocated a specific amount of power based on their service plan.
8.1.2 Monitoring and Compliance#
  • 8.1.2.1 Power usage is monitored. Customers exceeding their allocation may be subject to additional charges or required to upgrade.
8.1.3 Energy Efficiency#
  • 8.1.3.1 Customers are encouraged to use energy-efficient equipment to minimise consumption and support sustainability.

8.2 Cooling and Heat Density#

  • 8.2.1 Customers must operate equipment within the cooling and heat-density envelope of the cabinet and facility. Heat output exceeding the rated kW per cabinet may require relocation to a higher-density configuration at additional cost.

8.3 Equipment Restrictions#

  • 8.3.1 No equipment posing a fire, chemical, or electrical safety risk (including customer-supplied UPS units, standalone battery banks, lithium-ion energy storage, modified power supplies, or non-rack-mountable consumer hardware) may be installed without prior written approval. Embedded or manufacturer-supplied batteries integrated into standard server hardware (for example RAID controller battery backup units, NVRAM/RTC coin cells, and BBUs shipped as part of OEM enterprise equipment) are not affected by this restriction.
  • 8.3.2 Customer-supplied UPS units (battery-backed power) are not permitted in our colocation service. Power resilience is provided at the facility level. Customers requiring on-site backup power must arrange this with us in advance.

8.4 Cabling and Labelling#

  • 8.4.1 All cabling must follow tidy cable management practices (front-to-back airflow preserved, no obstruction of perforated tiles).
  • 8.4.2 Each cable must be labelled at both ends with the customer name and circuit ID. Unlabelled cabling may be removed during housekeeping.

For further details on colocation access and additional terms, refer to the Terms of Service.

9. IP Transit Services Policy

9.1 Usage and Bandwidth#

  • 9.1.1 Fair Use: Customers are expected to use IP Transit within the allocated bandwidth limits and not exceed agreed-upon capacity without prior arrangement.
  • 9.1.2 Traffic Management: ParadoxNetworks Limited may implement traffic management policies to ensure equitable access and network efficiency.

9.2 Source Address Validation (BCP38)#

  • 9.2.1 Customers must implement source address validation in line with BCP38 / RFC 2827. Only traffic with source addresses from prefixes the customer is authorised to announce will be accepted on transit links. Spoofed source traffic will be filtered or, in cases of sustained abuse, the session will be suspended.

9.3 Security and Compliance#

  • 9.3.1 DDoS Protection: In the event of a DDoS attack, we will implement protective measures by blackholing traffic to the affected IPs down to the most specific /32 (IPv4) or /128 (IPv6) prefix.
  • 9.3.2 Lawful Use: All use of IP Transit must comply with applicable laws and regulations, including data protection and copyright.

10. UK Broadband Provisions

10.1 Ofcom Compliance#

ParadoxNetworks Limited operates in accordance with the Ofcom General Conditions of Entitlement and signs up to the Ofcom Voluntary Code of Practice on Broadband Speeds for residential and business broadband services.

10.2 Service Quality and Performance#

  • 10.2.1 Reasonable Speeds: Broadband services are provided at speeds consistent with the purchased service plan. Actual speeds may vary due to network conditions, equipment, and usage patterns.
  • 10.2.2 Service Availability: We aim for 99.5% uptime, measured monthly. Scheduled maintenance is excluded.
  • 10.2.3 Performance Monitoring: Customers may request performance reports.

10.3 Fair Usage and Traffic Management#

  • 10.3.1 Fair Usage Policy: All broadband services are subject to fair usage policies. Excessive usage that impacts network performance may result in traffic management or throttling.
  • 10.3.2 Traffic Management Transparency: Practices and impacts will be communicated transparently.
  • 10.3.3 Notification of Changes: Customers will be notified of policy changes with reasonable notice.

10.4 Complaints and Dispute Resolution#

Complaints are handled per the procedures in our Terms of Service. If a complaint cannot be resolved or remains open after 8 weeks, customers may refer it to Ombudsman Services: Communications, the Ofcom-approved ADR provider for the communications sector (https://www.ombudsman-services.org/sectors/communications).

10.5 Service Suspension and Termination#

  • 10.5.1 Suspension: Reasonable notice is provided before suspension for non-payment or policy violations, except in emergency or serious breach.
  • 10.5.2 Termination Notice: At least 30 days' written notice for material contract changes or termination, in line with Ofcom General Condition C1, except in cases of serious breach or emergency.
  • 10.5.3 Data Deletion: Service-related data is deleted immediately on termination per our Terms of Service.

10.6 Billing and Charges#

  • 10.6.1 Transparent Pricing: Charges are clearly itemised. Customers receive detailed invoices.
  • 10.6.2 Price Changes: At least 30 days' notice. Customers may cancel without penalty if they do not accept increases.
  • 10.6.3 Billing Disputes: Customers may dispute charges within 30 days of invoice. Disputed amounts do not accrue interest pending resolution.

11. General Compliance and Enforcement

11.1 Adherence to Policies#

Customers must use services in full compliance with our Terms of Service and this AUP. This includes maintaining the security of their systems and not engaging in activities that could harm our network, other customers, or the broader internet.

11.2 Responsibility for Compliance#

It is the customer's responsibility to understand and adhere to all applicable policies and guidelines.

11.3 Consequences of Violation#

Violations may lead to:

  • 11.3.1 Temporary suspension of services
  • 11.3.2 Permanent termination of services
  • 11.3.3 Other actions as deemed necessary to maintain integrity and security

12. Reporting Violations

12.1 How to Report#

Misuse of services can be reported to abuse@pdxnet.co.uk. ParadoxNetworks Limited investigates reports and takes appropriate action.

We may not always be able to share investigation outcomes with reporters for privacy, security, or operational reasons. Where we are required to inform an affected data subject under UK GDPR, we will do so. Law enforcement requests should go to legal@pdxnet.co.uk.

12.2 Notice and Takedown (Hosting)#

ParadoxNetworks Limited operates the hosting safe harbour set out in regulation 19 of the Electronic Commerce (EC Directive) Regulations 2002. To submit a notice (for example, copyright infringement, defamatory content, or other unlawful material), please email abuse@pdxnet.co.uk with the following:

  • 12.2.1 Your full name, organisation, and contact details
  • 12.2.2 A description of the work or right alleged to be infringed (or the law alleged to be breached)
  • 12.2.3 The URL or IP address of the material
  • 12.2.4 A statement made in good faith that you believe the material is unlawful, and that the information in your notice is accurate
  • 12.2.5 Where applicable, a statement that you are the rights holder or are authorised to act on their behalf

We aim to acknowledge notices within 2 business days and to act on valid notices promptly. Submission of false or abusive notices may itself give rise to legal liability.

14. Disclaimer of Liability

ParadoxNetworks Limited is not responsible for content transmitted or stored on its network by users. Users are solely responsible for their actions and content.

15. Unfair Contract Terms Act 1977

All terms and conditions in this AUP are subject to the fairness and liability provisions in our Terms of Service.

16. Electronic Commerce Regulations 2002

ParadoxNetworks Limited is registered as a service provider under the Electronic Commerce Regulations 2002. We maintain clear identification of our business, transparent pricing in line with Section 2.3 of our Terms of Service (consumer prices inclusive of VAT; business prices and stated fees exclusive of VAT), and accessible complaint handling procedures. Customers may refer unresolved complaints to an approved Alternative Dispute Resolution (ADR) provider.

17. Limitation Period

Claims arising from this AUP are subject to the limitation period in our Terms of Service.

18. Changes to the Policy

ParadoxNetworks Limited may update or modify this AUP at any time. Users will be notified of changes. Continued use after such changes constitutes acceptance.