This is a translation. The authentic version is the Ukrainian one (https://www.zevshost.net/legal/aup). In case of discrepancy, the Ukrainian text prevails.
1.1. This Policy sets out what the Customer may and may not do using the Services. It forms an integral part of the Agreement.
1.2. The Policy applies to the Customer, to everyone to whom the Customer has granted access to the provided resources, and to all Content regardless of who placed it.
1.3. The Customer is responsible for compliance with this Policy by its users, clients and subcontractors to the same extent as for its own acts. The existence of the Customer's own agreement with an end user does not release the Customer from liability to the Provider.
1.4. Categories of prohibitions and consequences:
| Category | Marker | Consequence |
|---|---|---|
| Red | 🔴 | Immediate suspension without warning + termination of the Agreement; funds treated under clause 13.10 (losses and penalty retained, remainder refunded) (clauses 8.3, 8.4, 12.3, 13.10 of the Agreement) |
| Amber | 🟠 | Suspension with warning, remedy period of at least 24 hours (clause 12.2 of the Agreement) |
| Yellow | 🟡 | Written demand to remedy; on repetition — escalation to the amber category |
2.1. Copyright. 🔴/🟠 The Customer is prohibited from placing digital content in breach of the copyright and/or related rights of third parties. The Customer must provide accurate and correct information about itself, including contact details, and inform the Provider without delay should they change.
This term reproduces part one of Article 57 of the Law of Ukraine «On Copyright and Related Rights» and is mandatory for hosting agreements.
The category depends on the nature of the infringement: systematic commercial piracy (warez archives, torrent trackers, streaming of third-party video, sale of third-party software) — 🔴; isolated instances — 🟠 with the procedure under Annex 2.
2.2. Accuracy of data. 🟠 Account data must correspond to reality. Use of another person's data, fictitious persons, nominee owners or disposable email addresses to conceal identity constitutes a breach.
2.3. Public contact details. 🟡 A Customer that is a business entity and hosts a website must publish on it or in WHOIS its full name, full address, email address and telephone number — as required by part eleven of Article 56 of the Law of Ukraine «On Copyright and Related Rights». Failure to publish this information deprives the Customer of the ability to handle takedown notices itself and results in claimants approaching the Provider directly.
2.4. Infrastructure Operator rules. 🟠 The Customer must comply with the acceptable use rules of the Infrastructure Operator on whose equipment its Service is hosted (clause 5.9 of the Agreement). Those rules apply in addition to this Policy; where they conflict, the stricter rule applies.
The current rules of the Infrastructure Operators are available at
/legal/infrastructure. Unfamiliarity with them does not excuse non-compliance.
Why this matters most for dedicated servers. An Infrastructure Operator is not a party to the Agreement and is under no obligation to give the Customer time to remedy a breach. It can shut the server down on its own (clause 5.10 of the Agreement), and the Provider cannot always prevent that technically. That is why an Operator's demands are actioned first and on short deadlines — see Section 4.5 of Annex 2.
This Section is introduced in connection with the adoption of Law of Ukraine No. 4986-IX of 16 September 2026 (signed by the President of Ukraine on 17 September 2026), which adds Article 255⁴ to the Criminal Code of Ukraine (entering into force on the day following its publication). The prohibitions in this Section are contractual and apply irrespective of that date.
Breach of any clause of this Section is a ground for immediate shutdown, termination of the Agreement and notification of law enforcement; the treatment of funds paid is governed by clause 13.10 of the Agreement.
It is strictly prohibited to use the Services for:
3.1. Fraudulent call centres. Deploying, operating, hosting or supporting the infrastructure of fraudulent call centres, in particular: - auto-dialling systems (predictive dialers) used to deceive individuals; - VoIP gateways, SIP proxies, PBXs and trunking services serving fraudulent calling campaigns; - caller ID spoofing services; - CRM systems, "agent panels", script platforms and lead-tracking systems designed to support fraudulent calls; - systems for distributing and monitoring the work of such a call centre's agents.
3.2. Phishing and identity spoofing. Creating, hosting, distributing or supporting resources imitating banks, payment systems, government bodies, delivery services, crypto services, exchanges, marketplaces, mail services or any other persons in order to obtain personal data, payment instrument details, passwords or authentication codes. This also covers phishing kits, data-harvesting panels, and services for intercepting one-time passwords or bypassing two-factor authentication.
3.3. Unlawful data. Storing, processing, selling or distributing: - unlawfully obtained personal data and databases; - payment card details, dumps, CVVs, bank statements; - information constituting banking secrecy; - individual account information, passwords, tokens or authentication codes obtained without their owners' consent; - compromised accounts and stealer logs.
3.4. Financial pyramids and pseudo-investments. Hosting or supporting financial pyramids, HYIP projects, pseudo-brokerage and pseudo-investment platforms, "trading dashboards" with fictitious quotes, fake trading terminals, or "deposit boosting" schemes.
3.5. Money laundering and mule schemes. Providing infrastructure for money laundering, operating money-mule accounts, routing payments from fraudulent transactions, "warming up" payment credentials, or automated structuring of transfers.
3.6. Malware and attack tooling. Hosting or distributing viruses, trojans, stealers, ransomware, botnet command-and-control panels, exploit packs, keyloggers, covert mining tools, or providing services for their development, configuration or support.
3.7. Recruitment. Posting job advertisements, advertising or any materials aimed at enlisting persons into the activity described in this Section or into facilitating it.
3.8. Circumvention. Creating new Accounts or using nominees or intermediaries to circumvent previously applied measures.
4.1. Child pornography, child sexual abuse material and any material exploiting children. Discovery of such material results in immediate shutdown, preservation of evidence and notification of law enforcement without prior notice to the Customer.
4.2. Material containing calls for the violent change of the constitutional order, seizure of state power, or encroachment on the territorial integrity of Ukraine.
4.3. Propaganda, justification or denial of the armed aggression against Ukraine, glorification of those who carried it out; terrorist content; instructions for manufacturing weapons and explosives.
4.4. Incitement of national, racial or religious hatred; calls for genocide; propaganda of totalitarian regimes in forms prohibited by law.
4.5. Trafficking in human beings, organs, narcotics, weapons or forged documents; services for producing forged documents.
4.6. Material whose distribution is prohibited by a court decision or by a binding decision of an authorised state body.
5.1. Mass distribution of electronic messages without the free, verifiable and revocable consent of recipients (spam) is prohibited. This covers email, messengers, SMS, comments, feedback forms and any other channel.
5.2. It is prohibited to host on the Provider's resources any elements (web pages, forms, images, scripts, DNS records) referenced by spam campaigns sent from other resources.
5.3. Use of compromised or purchased address lists, automated address harvesting, and mailings with forged sender headers are prohibited.
5.4. Requirements for legitimate mailings. A Customer conducting legitimate mailings must: - retain evidence of each recipient's consent (date, time, IP, method); - provide an effective unsubscribe mechanism in every message; - process unsubscribes within 3 business days; - configure SPF, DKIM and DMARC for its own domains; - keep the complaint rate below 0.1% and the hard bounce rate below 5%.
5.4.1. How the metrics are measured. The complaint rate is the ratio of complaints to delivered messages over 7 consecutive days. The data sources are, in order of priority:
1) Google Postmaster Tools — for mail sent to Gmail addresses;
2) feedback loop reports from mail operators with which the Provider has an
arrangement;
3) Spamhaus and other recognised reputation lists;
4) the Provider's mail system logs.
The hard bounce rate is calculated from the Provider's mail system logs over the same period.
At the Customer's request the Provider supplies the data on which the metric was calculated and allows at least 72 hours to remedy before applying restrictions — except where the campaign is ongoing and is harming third parties or poses an immediate threat to the reputation of the Provider's subnets.
5.5. The Provider may limit the number of outbound SMTP connections and the volume of outbound mail, and may require the use of an external mailing service.
5.6. A breach of clauses 5.1–5.3 that results in the Provider's IP addresses or subnets being blocklisted is a ground for termination of the Agreement and indemnity under clause 13.6 of the Agreement.
6.1. 🔴 Carrying out or participating in any attacks is prohibited: DoS/DDoS, amplification, brute force, port scanning of third-party networks, ARP/DNS spoofing, traffic interception, unauthorised penetration testing.
6.2. 🔴 Unauthorised access to third-party information systems and any acts covered by Chapter XVI of the Criminal Code of Ukraine are prohibited.
6.3. 🟠 Use of the Provider's resources as an open proxy, open DNS resolver, open mail relay or TOR exit node without the Provider's prior written approval is prohibited.
6.4. 🟠 The Customer must prevent compromise of its own resources. Where compromise results in the Customer's resources participating in attacks on third parties, the Provider suspends the Service until the problem is resolved.
6.5. 🟡 Announcing IP addresses provided by the Provider through the Customer's own autonomous systems, or transferring them to third parties, without written approval is prohibited.
6.6. 🟡 The Customer must configure reverse DNS records for outbound mail correctly and must not use IP addresses in a way that harms the reputation of the Provider's subnets.
7.1. Resource allocations are set by the tariff plan. Sustained excess use is a ground for moving to a higher plan or for suspension.
7.2. Shared hosting. Prohibited: sustained CPU load above the limit stated in the plan; using the account as file storage unrelated to the hosted website; running background processes unrelated to serving the website; using shared hosting for video or audio streaming.
7.3. VPS/VDS and dedicated servers. The Customer may use the provided resources freely within the plan. Prohibited: excessive disk or network load degrading other customers on the same node; use of resources not covered by the plan by circumventing technical limits.
7.4. Mining. 🟠 Cryptocurrency mining is prohibited on shared hosting and on VPS plans with shared CPU resources. On dedicated servers and VPS with dedicated cores, mining is permitted subject to written approval and compliance with the power consumption limits of the plan. Covert mining on third-party devices (browser-based or via malware) is always prohibited — 🔴.
7.5. 🟡 The Provider notifies the Customer of approaching limits at least 72 hours before applying restrictions, except where the load poses an immediate threat to other customers.
The activities below are not prohibited but require compliance with additional conditions. Breach of the conditions escalates the activity to the amber category.
| Activity | Conditions |
|---|---|
| VPN services, proxies for end users | Written approval; logging as required by law; a published acceptable use policy for its own users; a published abuse contact |
| Public file sharing, cloud storage | A complaints and takedown mechanism; public contact details; response to the Provider within 24 hours |
| Mail services for third parties | Compliance with Section 5; SPF/DKIM/DMARC; an anti-spam procedure of its own |
| Forums, social networks, UGC platforms | Moderation; complaints mechanism; public owner contact details |
| Adult content (lawful) | Age verification; absence of any material under Section 4; separate approval by the Provider |
| Crypto services, exchangers | Approval; confirmation of compliance with AML legislation in the Customer's jurisdiction; absence of indicators under 3.4–3.5 |
| Betting, gambling | A licence issued by an authorised body; a copy provided to the Provider |
| Penetration testing, security research | Written approval; written authorisation from the owner of the tested system; scope limitation |
9.1. The Customer updates its operating system and application software itself. Use of versions unsupported by the vendor and carrying known critical vulnerabilities is a ground for a remediation demand.
9.2. Default and empty passwords for internet-facing services are prohibited.
9.3. The Customer must maintain a working abuse address and respond to the Provider within 24 hours (clause 7.1.7 of the Agreement).
9.4. Interference with the Provider's hypervisor, monitoring and virtualisation systems, attempts to escape the virtual environment, and circumvention of the plan's technical limits are prohibited.
10.1. The Provider selects the least onerous measure sufficient to stop the breach. Blocking individual content takes precedence over blocking a website; blocking a website takes precedence over suspending the entire Service.
10.2. For 🟡 and 🟠 breaches the Provider sends a notice stating what has been breached, what action is required, by when, and the consequences of inaction.
10.3. For 🔴 breaches the measure is applied immediately and notice is sent within 24 hours.
10.4. The Customer may appeal a measure by sending a reasoned objection to abuse@hostvds.net. The Provider reviews it within 3 business days. If the measure proves unjustified, the Service is restored and the paid period is extended by the duration of the suspension (clause 12.6 of the Agreement).
10.5. A decision to terminate the Agreement for a 🔴 breach is taken by an authorised officer of the Provider and documented with the ground, the evidence and the date.
10.6. The Provider maintains a register of measures applied, recording the date, time, ground, source of information and actions taken. The register is retained for at least 3 years and serves as evidence of the Provider's good faith.
11.1. Amendments to this Policy are published and take effect in the manner set out in Section 21 of the Agreement.
11.2. Expansion of the list of prohibitions caused by a change in legislation takes effect on the date the relevant provision enters into force (clause 21.4 of the Agreement).