# ANNEX 2
# COMPLAINTS HANDLING AND TAKEDOWN PROCEDURE

to the Public Agreement (Offer) for the Provision of Hosting Services by LLC «HOST VDS»

Version **1.0** of **17 September 2026**

---

> **This is a translation.** The authentic version is the Ukrainian one
> (<https://www.zevshost.net/legal/abuse>). In case of discrepancy, the Ukrainian text prevails.

<!-- -->

## 1. General

**1.1.** This Annex sets out how the Provider handles reports of infringements
committed using resources provided to Customers, and how measures are applied.

**1.2.** The Provider handles reports under **two independent procedures**:

| Procedure | Basis | Section |
|---|---|---|
| **A. Copyright** | Article 56 of the Law of Ukraine «On Copyright and Related Rights» — a formalised procedure with mandatory statutory deadlines | Section 3 |
| **B. General abuse procedure** | The Agreement and Annex 1 — all other infringements | Section 4 |

**1.3.** A report that does not meet the formal requirements of Article 56 may be
left without consideration under Procedure A, but this **does not release the
Provider from considering it under Procedure B** where the report discloses
indications of a breach of the Agreement.

**1.4. Single intake point:** **abuse@hostvds.net**.
Postal address: 01021, м. Київ, вул. Мечникова, буд. 8, кімн. 22, Печерський район.

**1.5.** Every report is assigned a unique reference. The reporter receives an
automatic acknowledgement with the reference and the procedure under which the
report will be handled.

**1.6.** All periods run from actual receipt of the report, Kyiv time (Europe/Kyiv),
and **do not pause on weekends or public holidays**, except for periods expressly
expressed in business days.

---

## 2. Classification and baseline response times

| Class | Examples | Initial response | Measures |
|---|---|---|---|
| **P0 — critical** | Child sexual abuse material; an active cyberattack from our resources; indications of activity under Art. 255⁴ of the Criminal Code | **within 1 hour** | Immediate shutdown, preservation of evidence, notification of law enforcement |
| **P1 — high** | Phishing, malware, C2 panel, ongoing spam campaign | **within 4 hours** | Content blocking or suspension, demand to the Customer |
| **P2 — medium** | Copyright infringement, content complaints, amber-category AUP breaches | **within 24 hours** | Procedure A or a demand to the Customer with a set deadline |
| **P3 — low** | Contested content, load complaints, yellow category | **within 3 business days** | Correspondence, demand to remedy |

**2.1.** The Provider determines the class on the basis of the report's content. The
reporter may suggest a class, but this is not binding on the Provider.

**2.2.** The Provider is under no obligation to carry out general monitoring of
Content (clause 6.3 of the Agreement). The duty to act arises upon receipt of a
report containing sufficient information to identify the infringement.

---

## 3. Procedure A: copyright takedown notices

> This procedure fully reproduces the mechanism of Article 56 of the Law of Ukraine
> «On Copyright and Related Rights». The deadlines in it are **mandatory** and
> cannot be varied by agreement of the parties.

### 3.1. Requirements for a notice

A takedown notice submitted directly to the Provider as a hosting service provider
is accepted for consideration **only if all of the following are satisfied**:

**3.1.1. Grounds for approaching the Provider** (part seven of Article 56). Such
grounds are:
- the website owner failed to take, or took only in part, the actions required by
  parts three, five or six of Article 56; **or**
- the website and WHOIS contain no information about the website owner sufficient to
  approach them.

The notice must substantiate the existence of such grounds. In the first case it must
additionally state when the notice was sent to the website owner, when the owner
should have acted, and how the claimant established the owner's contact details.

**3.1.2. Submission through a representative.** The notice is submitted **solely
through an attorney (advocate) or an intellectual property representative (patent
attorney)**, with a copy of the document evidencing their authority.

**3.1.3. Content of the notice** (paragraphs 1, 4, 5, 7 of part two of Article 56):
1) claimant identification details: name, place of residence or registered address,
   email or postal address; for legal entities — registration details, register
   particulars, registration number;
2) a hyperlink to the digital content or to the web page through which access was
   interactively provided;
3) a demand to disable access to the digital content and/or to prevent its further
   placement;
4) a statement by the claimant that the information is accurate and that the
   existence of the rights has been verified by the attorney or patent attorney
   through whom the notice is submitted.

**3.1.4. Form of the notice** (part fourteen of Article 56):
- **paper** — bearing the handwritten signature of the attorney or patent attorney,
  sent by registered mail with acknowledgement of receipt; **or**
- **electronic** — bearing a mandatory **qualified electronic signature** of the
  attorney or patent attorney, **with a simultaneous unsigned plain electronic copy**
  sent to the same address.

> **Note.** If the QES-signed notice differs in content from the plain electronic
> copy sent to the same addressee, the notice is deemed **not submitted**.

### 3.2. The Provider's deadlines under Procedure A

| Step | Provider's action | Deadline |
|---|---|---|
| 1 | Leaving the notice without consideration, stating the ground (where grounds under 3.3 exist) | **24 hours** |
| 2 | Sending the Customer a copy of the notice with an explanation of its rights, obligations and the consequences of inaction | **24 hours** |
| 3 | Awaiting the Customer's action | **24 hours** from dispatch of the copy |
| 4 | **Disabling access to the content itself** if the Customer has not acted | immediately after step 3 expires |
| 5 | Notifying the claimant and the Customer of the measures taken | **48 hours** from receipt of the notice |
| 6 | Forwarding the claimant a copy of the Customer's refusal | **48 hours** from receipt of the refusal |
| 7 | **Restoring access** if the claimant has not supplied confirmation that court proceedings have been commenced | **10th business day** from dispatch of the copy of the refusal to the claimant |

### 3.3. Grounds for leaving a notice without consideration

The Provider leaves a notice without consideration (part eight of Article 56),
notifying the claimant within 24 hours and stating the legal ground, where:

1) the notice does not meet the requirements of part seven of Article 56 (clause 3.1
   of this Annex);
2) the Provider does not provide services or resources for hosting the website
   concerned;
3) the claimant approached the Provider in the absence of the grounds under part
   seven of Article 56.

### 3.4. The Customer's obligations under Procedure A

Upon receiving a copy of the notice from the Provider, the Customer must **within 24
hours**:

- **either** disable access to the specified digital content and notify the Provider
  of the measures taken;
- **or** send the Provider a reasoned refusal meeting the requirements of part five
  of Article 56 and containing: details of the Customer sufficient to bring a claim
  (name, registered address or place of residence, email or postal address; for legal
  entities — registration details); identification of the content; and the ground for
  refusal.

The only permissible grounds for refusal are (part four of Article 56):
1) the Customer holds the right to use the content and provides documentary evidence
   (unless it is the primary rightsholder);
2) the notice does not comply with the requirements of Article 56.

**The Customer's inaction results in the Provider blocking the content itself.** The
Provider bears no liability to the Customer for this (part two of Article 57 of the
Law).

### 3.5. Scope of measures

The Provider disables access **solely to the digital content identified in the
notice**. Access to an entire web page is restricted only where disabling access to
the individual content item is technically impossible (part thirteen of Article 56).

### 3.6. Content of the notification of measures taken

The notification sent to the claimant contains (part twelve of Article 56):
- details of the Provider;
- **the full information about the Customer provided by it to the Provider, without
  any change or distortion**: full name, address of residence (registered address),
  correspondence address, telephone number, email address and any other contact
  information available;
- a copy of the Customer's refusal, if one was received.

> The Customer is hereby informed and agrees that, where a notice under Article 56 is
> submitted in respect of it, its contact details will be passed to the claimant to
> the extent expressly prescribed by law. This constitutes a lawful basis for
> processing personal data and does not require separate consent.

### 3.7. False notices

A claimant is liable for supplying knowingly false information about holding property
rights. The Provider records instances of false notices and may take them into
account when assessing further reports from the same claimant; the Customer may claim
damages directly from the claimant.

---

## 4. Procedure B: general abuse procedure

### 4.1. Requirements for a report

A report is considered if it contains:
1) the reporter's contact details (name, email address);
2) precise identification of the resource: IP address, domain name, URL;
3) a description of the infringement;
4) evidence: logs with timestamps and time zone, full email headers, screenshots,
   malware samples;
5) the date and time of detection with the time zone.

**4.1.1.** Anonymous reports are considered where they contain sufficient evidence for
the Provider to verify independently. This applies above all to P0 and P1 reports.

**4.1.2.** Automated reports from recognised organisations (Spamhaus, CERT-UA,
Shadowserver, APWG, IWF, NCMEC, national CERTs, domain registrars) are accepted in
X-ARF format or in the sender's own format without additional requirements.

### 4.2. Handling

**Step 1. Registration and classification** — within the initial response time under
Section 2.

**Step 2. Verification.** The Provider verifies the infringement using available
technical means (requesting the public URL, analysing network traffic, checking node
system logs). The Provider **does not access the Customer's Content** beyond what is
necessary for verification and does not access private data without the grounds set
out in clause 15.4 of the Agreement.

**Step 3. Measures.**

| Class | Action |
|---|---|
| **P0** | Immediate suspension of the Service (clause 12.3 of the Agreement). Preservation of evidence under clause 8.5 of the Agreement. Notice to the Customer within 24 hours. Notification of law enforcement under Annex 6 |
| **P1** | Blocking the specific resource or suspending the Service. Immediate notice to the Customer with a demand to remedy within 24 hours |
| **P2** | Demand to the Customer to remedy within 24–72 hours depending on the nature of the issue. On failure — suspension under clause 12.2 of the Agreement |
| **P3** | Demand to the Customer with a reasonable deadline, normally 5 business days |

**Step 4. Response to the reporter** — on the measures taken or on refusal with
reasons:

| Class | Response deadline |
|---|---|
| P0 | 24 hours |
| P1 | 48 hours |
| P2 | 5 business days |
| P3 | 10 business days |

**Step 5. Closure** with the outcome recorded in the register under clause 10.6 of
Annex 1.

### 4.3. Special procedure for fraud indicators (Article 255⁴ of the Criminal Code)

**4.3.1.** Reports disclosing indications of the activity described in Section 3 of
Annex 1 are handled **as class P0 regardless of the source of the report**.

**4.3.2.** The moment such a report is received is recorded to the minute and
constitutes **the moment the Provider acquired information** about possible unlawful
activity. From that moment all of the Provider's actions are logged.

**4.3.3.** Sequence of actions:
1) immediate suspension of the Service without prior notice;
2) preservation of system logs, network data and, where technically feasible, an
   image of the virtual server — for 90 days (clause 8.5 of the Agreement);
3) recording in the register: the time information was received, the source, its
   content, the measures taken, the time of each action, and the officer who took the
   decision;
4) notice to the Customer within 24 hours demanding an explanation within 3 business
   days (clause 8.2 of the Agreement);
5) notification of law enforcement under Annex 6;
6) as a result: restoration of the Service if the suspicion is not confirmed, or
   termination of the Agreement under clause 8.4 of the Agreement.

> **Why this matters.** Part three of Article 255⁴ of the Criminal Code of Ukraine
> establishes liability for supplying services to a fraudulent organised group by a
> person **who was aware of the unlawful nature of its activity**. The Provider
> cannot be aware of what it does not know; but once reliable information has been
> received, inaction becomes evidence of awareness. That is why the response must be
> immediate and documented.

**4.3.4.** A Provider that voluntarily informs a law enforcement authority of the
creation or activity of such an organised group and actively assists in exposing the
persons involved relies on the ground for release from criminal liability provided by
part seven of Article 255⁴ of the Criminal Code of Ukraine.

### 4.4. Abuse of the reporting procedure

**4.4.1.** The Provider may decline to consider reports that:
- are submitted systematically and are manifestly unfounded;
- are aimed at unfair competition or at pressuring the Customer;
- concern a dispute about rights that must be resolved by a court (for example, a
  dispute over domain ownership or the content of a publication).

**4.4.2.** The Provider **is not an arbiter** in disputes about the content of
information. Where the assessment of content is contested (defamation, disputes about
honour and dignity, value judgments), the Provider acts only on the basis of a court
decision or another binding decision.

---

### 4.5. Reports received through an Infrastructure Operator

> In practice this is the most common scenario for dedicated servers: the complaint
> reaches not the Provider but the Infrastructure Operator — OVHcloud, Hetzner, Scaleway,
> WorldStream, MevSpace, myLoc — which then gives the Provider its own, usually very short,
> deadline to act.

**4.5.1.** A demand from an Infrastructure Operator is handled **at class P1 or
higher** regardless of the content of the complaint, and at class P0 where
indicators under Section 3 of Annex 1 are present.

**4.5.2. Shortened deadlines.** The period allowed by the Infrastructure Operator
is decisive and **prevails over the periods set out in Section 4 of this Annex**.
The Customer is allowed:

| Period allowed by the Operator | Period given to the Customer |
|---|---|
| up to 4 hours | **1 hour** |
| 4 to 12 hours | **4 hours** |
| 12 to 24 hours | **8 hours** |
| over 24 hours | the general rules of Section 4 apply |

The remaining time is used by the Provider to verify remediation and respond to the
Operator. If the Customer has not remedied the breach within the period allowed, the
Provider suspends the Service under clause 12.3.7 of the Agreement so as to prevent
the Operator from shutting the equipment down.

**4.5.3.** Where the period allowed by the Operator does not permit advance notice
to the Customer, the Provider suspends the Service immediately and notifies the
Customer within 24 hours (clause 12.3 of the Agreement).

**4.5.4. Disclosure to the Operator.** To process the complaint the Provider passes
the Infrastructure Operator the information needed to evidence the measures taken
and, upon the Operator's express demand supported by its own rules, also the
Customer's identification and contact details. The legal basis is performance of
the contract and legitimate interest (Annex 4).

**4.5.5.** The Provider cannot override an Infrastructure Operator's decision to
shut equipment down. In such a case the Provider takes reasonable steps to restore
the Service or migrate it to another platform (clause 5.10 of the Agreement), and
the Provider's liability to the Customer is governed by clause 13.9 of the
Agreement.

**4.5.6.** If the Infrastructure Operator's demand proves unfounded, the Provider
restores the Service and extends the paid period by the duration of the suspension
(clause 12.6 of the Agreement).

---

## 5. Customer objections

**5.1.** The Customer may send a reasoned objection to the measures taken to
abuse@hostvds.net, quoting the report reference.

**5.2.** The Provider reviews the objection within **3 business days** (for class P0 —
within 24 hours).

**5.3.** If the objection is well-founded, the Provider restores the Service and
extends the paid period by the duration of the suspension (clause 12.6 of the
Agreement).

**5.4.** For Procedure A the objection process is governed by clause 3.4 of this Annex
and has mandatory statutory deadlines.

---

## 6. Transparency

**6.1.** The Provider publishes an **annual transparency report** with anonymised
statistics:
- number of reports by class and category;
- number of measures applied;
- number of services restored following objections;
- number of state authority requests and number complied with (Annex 6).

**6.2.** The report is published at `/legal/transparency` no later than 31 March of
the year following the reporting year.

---

## 7. Contacts

| Purpose | Address |
|---|---|
| All complaints and abuse reports | **abuse@hostvds.net** |
| Notices under Article 56 of the Law «On Copyright and Related Rights» | **abuse@hostvds.net** |
| Law enforcement requests | admin@zevshost.net or abuse@hostvds.net |
| Customer technical support | support@zevshost.net |
| Postal address | 01021, м. Київ, вул. Мечникова, буд. 8, кімн. 22, Печерський район |
| Telephone | +380 44 233 50 44 |
