View Categories

HOSTING ACCEPTABLE USE POLICY

20 min read

Effective Date: 01 February 2026

Applicable To: All clients, partners, licensees, resellers and authorised shared-service operators using Fludnox hosting and infrastructure services.

This Hosting Acceptable Use Policy (“Policy”) sets out the rules governing the use of hosting, server, network, email, DNS, storage, content-delivery and related infrastructure services supplied by The Xdemór Group Limited under the Fludnox brand.

In this Policy, “You” and “Your” refer to the business, organisation or professional using the Services and any person authorised to act on its behalf. “Fludnox”, “We”, “Us” and “Our” refer to The Xdemór Group Limited acting under the Fludnox brand. “Services” means the applicable Fludnox hosting and infrastructure services. “Content” means all websites, applications, code, files, databases, email, communications, media and other material stored, processed or transmitted through the Services.

1. Application of this Policy #

1.1 Contractual Status #

This Policy forms part of the contractual framework governing the Services and applies together with the Shared Services Terms of Service, the Fludnox Hosting and Infrastructure Policy, the applicable Order Form or Individual Agreement and any other policy incorporated into the Services.

You must ensure that Your employees, contractors, administrators, customers, end users and any other person using the Services through Your account comply with this Policy. You remain responsible for their use of the Services as if that use were Your own.

1.2 Acceptance #

You accept this Policy when You order, activate, renew, access or use any Fludnox hosting or infrastructure Service.

Where You use the Services on behalf of another person or make them available to downstream users, You represent that You have authority to do so and that You have imposed appropriate contractual and acceptable-use requirements on those users.

1.3 Upstream Infrastructure Requirements #

Some Services rely on third-party hosting, network, data-centre, software, security, email, domain or content-delivery infrastructure. You must comply with any technical, security, licensing or acceptable-use restriction that Fludnox expressly notifies You applies to Your Service.

Fludnox remains responsible for defining the obligations applicable between You and Fludnox. No third-party terms are incorporated into Your agreement solely because Fludnox uses that third party to deliver part of the Services.

Where an upstream provider requires immediate action to protect infrastructure, comply with law, address abuse or prevent service disruption, Fludnox may restrict, isolate, migrate, suspend or discontinue the affected component. Where reasonably practicable, Fludnox will provide notice before taking materially adverse action.

Any upstream terms intended to bind You directly must be expressly identified in the applicable Order Form, Individual Agreement or service-specific schedule.

2. Lawful Use #

2.1 General Requirement #

You must use the Services only for lawful purposes. You must not use, permit or assist the use of the Services in a manner that violates applicable legislation, regulation, court order, regulatory requirement or legally binding third-party right.

You are responsible for determining which laws apply to Your business, Content, users, communications and intended markets. The fact that Content can technically be hosted or transmitted through the Services does not mean that Fludnox has approved its legality or regulatory status.

2.2 International Use #

Where Your website, application or service operates in, targets or processes data from more than one jurisdiction, You must comply with the laws applicable to the relevant activity and territory.

You must not use the Services to avoid legal restrictions, regulatory supervision, sanctions, export controls, licensing requirements or enforcement measures that would otherwise apply to You.

2.3 Required Permissions #

You must obtain and maintain all licences, registrations, permissions, consents and regulatory approvals required for Your use of the Services.

Fludnox may require reasonable evidence of Your identity, business activity, authority, licence, regulatory status, ownership of Content or right to use particular software, data, domains or intellectual property.

Failure to provide reasonably requested evidence may result in restriction or suspension of the affected Service.

3. Prohibited Content and Activities #

3.1 Illegal and Harmful Activity #

You must not use the Services to create, host, publish, store, transmit, promote, advertise, sell, distribute or facilitate Content or activity that is unlawful, fraudulent, deceptive, malicious or intended to cause harm.

This includes Content or activity involving phishing, credential theft, identity theft, financial fraud, impersonation, scams, unlawful investment schemes, unlawful pyramid or Ponzi schemes, counterfeit goods, stolen property, unlawful marketplaces, evasion of sanctions or other activity designed to obtain money, property, access or information through deception.

3.2 Intellectual Property and Confidential Information #

You must not use the Services to infringe or misappropriate copyright, trade marks, patents, database rights, design rights, trade secrets, confidential information or any other intellectual property or proprietary right.

You must not host or distribute pirated software, warez, unauthorised media, counterfeit products, licence circumvention tools, stolen source code, unauthorised copies of subscription content or links primarily intended to facilitate access to infringing material.

The use of peer-to-peer systems, torrent trackers, torrent portals or similar systems is prohibited where their purpose or material use is the unauthorised distribution of protected content.

Intellectual-property complaints will be handled under the Fludnox Abuse and Content Complaint Procedure.

3.3 Privacy and Personal Data #

You must not use the Services to unlawfully collect, disclose, sell, publish, monitor, identify or distribute personal data, private communications, account credentials, financial information, medical information or other confidential information.

Doxxing, unlawful surveillance, credential dumps, stolen databases, unauthorised tracking and the publication of personal information for harassment, intimidation, fraud or harm are prohibited.

Your processing of personal data must comply with the laws applicable to Your activities, including the UK GDPR and the Data Protection Act 2018 where applicable:

https://www.legislation.gov.uk/eur/2016/679/contents

https://www.legislation.gov.uk/ukpga/2018/12/contents

3.4 Sexual Content and Protection of Children #

Child sexual abuse material, grooming, sexual exploitation of children, trafficking, coercive sexual content and any material that unlawfully depicts, promotes or facilitates sexual abuse are strictly prohibited.

Any suspected child sexual abuse material or sexual exploitation of a child may be preserved and reported to the relevant competent authorities without prior notice where required or permitted by law.

Adult sexual content is not permitted on standard or shared hosting Services unless Fludnox has expressly approved the proposed use in writing and confirmed that the applicable infrastructure and upstream provider permit it. Approval may be refused or withdrawn where the Content creates legal, security, reputational or upstream compliance risk.

3.5 Violence, Terrorism and Unlawful Extremism #

You must not use the Services to promote, instruct, fund, recruit for or materially support terrorism, unlawful extremist activity, organised violence or the commission of a criminal offence.

Content containing violence or hateful expression is prohibited where it is unlawful, constitutes a credible threat, incites violence or criminal activity, targets a person for unlawful harassment or is used to facilitate harm.

3.6 Regulated and High-Risk Activities #

You must not use the Services to offer, promote or facilitate regulated goods or services without all required legal authority.

This includes unlicensed financial services, unlawful gambling, unlawful pharmaceutical or medical supply, unlawful weapons trading, controlled substances, illegal payment services and other activities requiring regulatory permission.

Fludnox may require prior written approval for lawful but high-risk or heavily regulated activities where the use may affect infrastructure security, upstream-provider compliance or the legal exposure of Fludnox.

4. Security and Network Abuse #

4.1 Unauthorised Access #

You must not access, attempt to access, test, interfere with or use any account, device, server, network, database, application or system without the express authority of its owner.

This prohibition applies whether the target belongs to Fludnox, an upstream provider, another Fludnox client, You or any third party. Access to Your own account does not authorise You to bypass isolation, privilege, resource or security controls.

Unauthorised access, unauthorised acts intended to impair a computer and the making or supply of tools for computer misuse may constitute offences under the Computer Misuse Act 1990:

https://www.legislation.gov.uk/ukpga/1990/18/contents

4.2 Scanning and Security Testing #

You must not conduct port scanning, vulnerability scanning, penetration testing, password attacks, credential stuffing, brute-force activity, exploit testing or similar security assessment against any system unless You have the system owner’s express written authorisation.

Fludnox may require You to provide evidence of that authorisation and details of the scope, source addresses, testing window and responsible contact before testing begins.

Security testing against Fludnox infrastructure, shared infrastructure or another client’s environment is prohibited unless expressly authorised by Fludnox in writing.

4.3 Malicious Software and Compromised Systems #

You must not knowingly or recklessly host, execute, transmit, distribute or facilitate malware, ransomware, spyware, viruses, worms, Trojan horses, malicious scripts, remote-access malware, destructive code, credential-stealing software or code designed to compromise, damage, encrypt, disrupt or gain unauthorised control over another system.

Botnets, command-and-control systems, malware distribution points, exploit kits, malicious redirects and infrastructure used to manage compromised devices are prohibited.

You must take reasonable steps to prevent Your Service from being compromised. If Your Service is compromised, You must cooperate with remediation instructions and take prompt action to contain and remove the threat.

4.4 Denial of Service and Traffic Manipulation #

You must not initiate, facilitate, coordinate, advertise or provide infrastructure for denial-of-service attacks, distributed denial-of-service attacks, stressers, booters, amplification attacks, ping floods, mail bombs or other activity intended to exhaust or impair a service or network.

You must not generate artificial traffic, fraudulent clicks, simulated engagement, false referrals, automated advertisement interactions or other traffic designed to manipulate analytics, advertising, ranking, payment or reward systems.

4.5 Identity and Address Manipulation #

You must not forge, conceal or materially falsify IP addresses, email headers, sender identities, domain identities, routing information, signatures, technical identifiers or account ownership information for deceptive, abusive or unlawful purposes.

The legitimate use of privacy, proxy or security technology does not permit impersonation, fraud or concealment of prohibited activity.

4.6 Proxies, Relays and Tunnelling #

Open proxies, open mail relays, open DNS resolvers, public traffic-relaying services and unauthorised tunnelling services are prohibited.

TOR exit nodes, public VPN services, GRE tunnels, traffic-obfuscation services and similar systems may be operated only where expressly permitted by the applicable Service and approved by Fludnox in writing.

Any approval may include restrictions on access, traffic, logging, abuse response, resource use and legal compliance.

4.7 Circumvention of Controls #

You must not bypass or attempt to bypass resource limits, process restrictions, access controls, security measures, licence restrictions, account isolation, suspension controls or other technical limits applied to the Services.

You must not use shell access, scheduled tasks, scripts, containers, virtualisation or other methods to obtain privileges or functionality not included in Your Service.

5. Email, Messaging and Anti-Spam Requirements #

5.1 Permission-Based Communications #

You must not use the Services to send unsolicited commercial communications, unsolicited bulk email, spam, mail bombs or messages sent to recipients who have not been lawfully obtained and appropriately authorised for the relevant communication.

Where You send marketing or bulk communications, You must comply with all applicable electronic-marketing, privacy and direct-marketing requirements, including the Privacy and Electronic Communications Regulations 2003 where applicable:

https://www.legislation.gov.uk/uksi/2003/2426/contents

You must maintain accurate and verifiable records demonstrating the lawful source of recipient contact information and any consent, subscription, opt-in or other lawful permission relied upon.

You must provide relevant records to Fludnox where reasonably requested in connection with an abuse complaint, security investigation, upstream-provider request or legal compliance review.

Where You cannot provide reasonable evidence that a mailing list was lawfully obtained and used, Fludnox may treat the affected communications as unsolicited.

5.3 Sender Identification and Opt-Out #

Commercial and bulk messages must accurately identify the sender and must not contain forged or misleading headers, domains, routing information, subject lines or sender details.

Where legally required, messages must include a clear and functional mechanism enabling recipients to unsubscribe or object. Opt-out requests must be implemented promptly and must not be ignored, obstructed or reversed without a new lawful basis.

5.4 Prohibited Email Practices #

You must not use the Services to operate an open relay, conceal the origin of messages, send through unauthorised third-party accounts, use purchased or scraped mailing lists, distribute spam-supporting software, host pages advertised through spam or receive replies on behalf of a separate spam operation.

Automated domain warm-up, simulated engagement and reputation manipulation using unverified recipients, artificial interaction networks or third-party warm-up tools are prohibited.

5.5 Email Reputation #

You are responsible for the reputation of Your sending domains, accounts, lists and communications.

Where Your conduct results in material complaint rates, excessive bounces, delivery blocks, domain blacklisting or IP blacklisting, Fludnox may limit sending, isolate the affected account, change an IP address, require remediation or suspend email services.

Fludnox is not required to restore sending privileges until it is satisfied that the cause has been corrected and that reinstatement will not create a continuing reputation or compliance risk.

6. Resource Use and Platform Integrity #

6.1 Fair Use #

You must use shared resources reasonably and in accordance with the purpose and limits of the applicable Service.

You must not use processor capacity, memory, storage, bandwidth, database connections, input and output operations, concurrent processes or other resources in a manner that materially degrades infrastructure performance or interferes with another client.

Technical limits may be applied automatically and may vary by plan, platform or upstream provider.

6.2 Shared Hosting Restrictions #

Shared hosting is intended for websites, web applications and ordinary business email. Unless expressly approved in writing, You must not use shared hosting for continuous batch processing, video encoding, media transcoding, public file exchange, high-volume crawling, search indexing, persistent daemons, game servers, public chat servers, intensive data analysis or other sustained computing workloads.

Scheduled tasks must not be configured at a frequency or volume that creates persistent or disproportionate load.

Where Your workload is unsuitable for shared hosting, Fludnox may require optimisation, migration to a virtual or isolated server or purchase of a more suitable Service.

6.3 File Storage, Backups and Archives #

Standard hosting must not be used primarily as a remote backup system, general file-storage platform, cyberlocker, public download repository, media archive, software distribution archive or long-term email archive.

Files stored within a hosting account must be reasonably connected to the operation, administration or Content of the hosted website or application.

Backups maintained for Your own purposes must comply with applicable storage limits and must not interfere with operational backups or the stability of the hosting platform.

6.4 Mining and Distributed Computing #

Cryptocurrency mining, proof-of-work processing, distributed mining, browser mining and other virtual-currency generation are prohibited.

Folding, distributed scientific computing and similar resource-intensive programmes are prohibited on shared infrastructure unless expressly approved for a dedicated environment.

6.5 Crawlers and Automated Access #

Automated crawlers, scrapers, indexers and social-media collection tools must not be operated in a manner that violates law, third-party terms, robots restrictions, access controls or applicable resource limits.

High-volume or continuous crawling is prohibited on shared hosting unless expressly approved in writing.

6.6 Content-Delivery Services #

A content-delivery Service may be used only for the websites, domains, files and purposes permitted by the applicable Service description.

You must not use a Fludnox content-delivery Service to distribute unrelated bulk files, pirated material, malware, unlawful streaming content or material hosted outside the authorised origin environment unless the Service expressly permits external origins.

7. Account and Credential Security #

You must maintain the confidentiality and security of all account credentials, API keys, recovery codes, encryption keys and administrative access details.

You must not share privileged credentials except with authorised persons who require access for a legitimate purpose. Shared or generic administrator accounts should not be used where individual accounts are available.

You must notify Fludnox without undue delay if You suspect unauthorised access, credential compromise, malware, account takeover or another security incident affecting the Services.

You remain responsible for activity carried out through Your accounts and credentials except to the extent that the activity results directly from a breach of Fludnox’s own contractual security obligations.

8. Third-Party Content and User-Generated Services #

8.1 Responsibility for User Content #

Where Your website, application or service allows users to submit, upload, publish, advertise, sell, communicate or distribute Content, You remain responsible for administering that service and responding to unlawful or prohibited use.

The fact that You did not personally create the Content does not remove Your obligations under this Policy.

8.2 Reporting Mechanism #

You must maintain a clear and effective mechanism through which users, rights holders and affected persons can report unlawful, infringing, abusive or privacy-violating Content.

You must monitor that mechanism, maintain a responsible contact, investigate complaints within a reasonable period and take proportionate action where a complaint is substantiated.

You must preserve relevant records where reasonably necessary for investigation, legal compliance or defence of a claim.

8.3 Failure to Address Complaints #

Fludnox may restrict, remove or disable access to Content, suspend the affected Service or require corrective action where You fail to respond adequately to a credible complaint.

Where a complaint creates an immediate security, legal or personal-safety risk, Fludnox may act before contacting You.

Detailed complaint, evidence, counter-notice and escalation procedures are governed by the Fludnox Abuse and Content Complaint Procedure.

8.4 Online Safety Obligations #

Where You operate a user-to-user service, search service, forum, social platform, marketplace, messaging service or another service within the scope of the Online Safety Act 2023, You are responsible for determining and complying with Your duties under that legislation:

https://www.legislation.gov.uk/ukpga/2023/50/contents

Fludnox does not assume Your role as operator of the relevant service merely by supplying hosting or infrastructure.

8.5 Advertising and Resold Space #

Where You sell or provide advertising, web space, accounts or other hosted capacity to a third party, You remain responsible for the resulting Content and use.

You must not allow advertising or third-party use that would breach this Policy if carried out directly by You.

9. Resellers, Partners and Shared-Service Operators #

Where You resell, sublicense, manage or make the Services available to downstream clients or users, You must impose written acceptable-use terms that are no less protective than this Policy.

You must maintain current identification and contact information for downstream clients, operate an effective abuse-response process and cooperate promptly with Fludnox investigations.

You must not permit a downstream user to continue prohibited activity after You become aware of it or receive a reasonable instruction from Fludnox to restrict it.

Fludnox may communicate directly with a downstream user where reasonably necessary to address an urgent security, legal, abuse or service-continuity issue. Direct operational communication does not create a separate contractual relationship between Fludnox and that downstream user.

You remain responsible for the acts and omissions of downstream users in relation to the Services.

10. Investigation and Cooperation #

10.1 No General Monitoring Obligation #

Fludnox does not routinely review all Content and does not undertake a general obligation to monitor every activity conducted through the Services.

Fludnox may investigate where it receives a complaint, security alert, upstream notice, legal request or other information indicating a possible breach.

10.2 Investigation Measures #

For the purpose of an investigation, Fludnox may review relevant logs, metadata, configurations, processes, files or Content; request information or evidence; preserve relevant records; temporarily restrict access; isolate an affected system; or refer the matter to an upstream provider.

Any access to Content will be limited to what Fludnox reasonably considers necessary for the investigation, protection of the Services or compliance with law.

10.3 Client Cooperation #

You must cooperate with a reasonable investigation and provide accurate information within the period specified by Fludnox.

You must not destroy, conceal, alter or fabricate evidence relating to an actual or suspected violation.

Failure to cooperate, failure to respond within a reasonable period or provision of materially false information may itself result in suspension or termination.

10.4 Disclosure and Reporting #

Fludnox may disclose relevant information to an upstream provider, competent authority, law-enforcement body, regulator, court, affected service provider or other authorised recipient where required by law or reasonably necessary to prevent or investigate unlawful activity, security threats or serious abuse.

Any disclosure of personal data remains subject to applicable data-protection law and the Shared Services Privacy Policy.

11. Enforcement #

11.1 Available Measures #

Where Fludnox reasonably believes that this Policy has been or is likely to be breached, it may issue a warning, request evidence, require remediation, remove or disable Content, block traffic, restrict email sending, throttle resources, revoke privileged access, isolate a Service, change an IP address, suspend the affected Service or terminate the applicable contractual arrangement.

Fludnox may apply a measure to the affected component only or to the entire account where the violation is systemic, repeated or cannot be safely isolated.

11.2 Immediate Action #

Fludnox may act without prior notice where it reasonably believes that delay would increase the risk of unlawful activity, fraud, security compromise, data loss, personal harm, infrastructure disruption, network blacklisting, upstream suspension or regulatory exposure.

Immediate action may apply to phishing, malware, botnets, child sexual abuse material, unauthorised access, denial-of-service activity, credential theft, open relays, open proxies, serious spam activity and other conduct presenting comparable risk.

11.3 Remediation Period #

Where a violation is capable of correction and does not require immediate action, Fludnox may provide a reasonable period for remediation.

The length of that period will depend on the severity, urgency, recurrence and effect of the violation. A remediation period does not waive Fludnox’s right to impose restrictions necessary to protect infrastructure or third parties while remediation is pending.

11.4 Reinstatement #

Suspended Services will not be reinstated automatically.

Fludnox may require evidence that the violation has been corrected, credentials have been secured, malicious Content has been removed, affected software has been patched, downstream users have been restricted or other reasonable controls have been implemented.

Reinstatement may be refused where the violation is serious, repeated, deliberate or creates an unacceptable continuing risk.

11.5 Charges, Refunds and Data Handling #

Suspension or termination under this Policy does not remove payment obligations already incurred. Refund rights, if any, are governed by the Shared Services Terms of Service and the applicable Order Form.

Data export, backup availability, deletion and end-of-service handling are governed by the Fludnox Backup and Data Recovery Policy, the Fludnox Migration, Suspension and Termination Procedure and the Shared Services Data Processing Agreement.

12. Reporting Abuse #

Reports concerning suspected abuse, unlawful Content, intellectual-property infringement, phishing, malware, spam or other violations should be submitted through the designated reporting mechanism identified in the Fludnox Abuse and Content Complaint Procedure.

Where the designated form is unavailable, an operational report may be sent to support-fludnox@shared-services.co.

A report should identify the affected domain, URL, IP address or account; describe the alleged violation; provide supporting evidence; state the reporting party’s relationship to the matter; and include current contact information.

Knowingly false, materially misleading or abusive reports may be rejected and may themselves constitute a breach where submitted by a Client or authorised user.

Formal legal notices must be sent to legal@xdemor.com. A support ticket or abuse report does not constitute a formal legal notice unless Fludnox expressly confirms otherwise.

13. Changes to this Policy #

Fludnox may amend this Policy to reflect changes in law, regulation, security threats, abuse patterns, technology, upstream-provider requirements or the Services.

Except where an urgent exception applies, Fludnox will provide reasonable notice before a material amendment takes effect.

A shorter notice period or immediate amendment may apply where required by law, a competent authority, security, abuse prevention, an urgent upstream requirement or protection of service continuity.

Continued use of the affected Services after the effective date of a notified amendment constitutes acceptance of the amended Policy.

This Policy and any non-contractual obligations arising from it are governed by the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction, subject to any mandatory rule that cannot lawfully be excluded.

This Policy operates together with the contractual documents published through the Shared Services Policy Portal at https://policies.shared-services.co/, including the Shared Services Terms of Service, the Fludnox Hosting and Infrastructure Policy, the Fludnox Backup and Data Recovery Policy, the Fludnox Abuse and Content Complaint Procedure and the Fludnox Migration, Suspension and Termination Procedure.