HomeLegal › Acceptable Use Policy

Acceptable Use Policy

What you may and may not run on WebsNP servers, and what happens when a line is crossed.

Last updated 7 August 2026 Effective 7 August 2026 8 sections Print or save as PDF
In short

Run a lawful site, do not spam, do not attack anyone, and do not use a shared plan as if it were a private server. Break those and we act in proportion, from a warning to immediate termination for the serious cases in Section 2.

1.Who and What This Covers

This Acceptable Use Policy applies to every WebsNP service: shared and reseller hosting, VPS and cloud instances, dedicated servers, business email, domains and anything hosted on our network. It applies to you as the account holder, to anyone you give access to, and to every end customer of a reseller.

If you resell our services, enforcement against your customer is your responsibility. We contract with you, not with them, so their activity counts as yours. We recommend passing this policy through in your own terms.

This policy sits alongside our Terms and Conditions. Where a term is defined there, it carries the same meaning here.

2.Prohibited Content and Activity

Immediate termination, no refundContent in this section is removed on discovery and the account is terminated without notice. Where the law requires it, we also report to the relevant authority.
  • Child sexual abuse material. Reported to law enforcement without exception.
  • Content promoting terrorism or inciting violence against a person or group.
  • Fraud infrastructure: phishing pages, fake login portals, carding sites, cryptocurrency drainer scripts, counterfeit storefronts, or anything designed to obtain money or credentials by deception.
  • Malware distribution: viruses, ransomware, trojans, keyloggers, botnet controllers, exploit kits or droppers.
  • Piracy at scale: warez, cracked software, key generators, illegal streaming or file-sharing hubs, or systematic distribution of copyrighted work you do not own.
  • Illegal marketplaces: controlled substances, weapons, stolen data, forged documents or trafficked goods and services.
  • Non-consensual or unlawful sexual content of any kind, including material published without the subject's consent.

Adult content that is lawful in Nepal and in your own jurisdiction, produced with consent, and age-gated is not prohibited, but it must be declared before you order because it is not permitted on all plan types.

3.Network and Security Conduct

Our network is shared infrastructure. Anything that endangers it endangers every other customer on it, so the following are prohibited whether the target is inside or outside our network:

  • Denial of service attacks, amplification or reflection attacks, and participation in a botnet.
  • Port scanning, vulnerability scanning or penetration testing against systems you do not own, and against ours without written authorisation from us first.
  • Intercepting traffic, spoofing packets or headers, ARP or DNS poisoning, and IP or MAC address hijacking.
  • Attempting to escape your account, container or virtual machine, or to reach another customer's files, processes or data.
  • Running open relays, open proxies, open recursive DNS resolvers or malicious Tor exit nodes.
  • Brute forcing credentials, whether ours, yours or a third party's.
Authorised security testingLegitimate testing of your own hosted application is welcome. Open a ticket first with the target, the window and your source addresses, so our automated defences do not read your test as a live attack and null-route you mid-run.

4.Email, Spam and Bulk Sending

Sending unsolicited bulk email from our network gets our IP ranges blacklisted, which breaks email delivery for every customer sharing them. We treat it as one of the most serious breaches of this policy.

  • Every recipient must have given verifiable opt-in consent. Purchased, scraped, harvested and rented lists are not consent.
  • Every bulk message must carry a working one-click unsubscribe, honoured within 48 hours, and a genuine physical or business address.
  • Forged headers, misleading subject lines, false sender identities and untraceable relay chains are prohibited.
  • Mailing lists must be closed-loop and confirmed. Re-adding an unsubscribed address is a breach.
  • Do not advertise a site hosted with us in spam sent from somewhere else. Spamvertising counts as spam on our network.

Shared and reseller plans carry an outbound limit of 500 messages per hour per account. If your legitimate sending exceeds that, use a dedicated sending service or ask us about a plan with a dedicated IP and proper SPF, DKIM and DMARC alignment. A listing at Spamhaus, SpamCop, Barracuda or an equivalent reputation service that traces back to your account is grounds for immediate suspension until it is resolved.

5.Fair Resource Use on Shared Plans

Shared and reseller hosting is priced on the assumption that no single account monopolises a server. These limits keep the neighbourhood fast for everybody:

ResourceShared and reseller limitWhat happens at the limit
CPUSustained use above your plan allocation for more than 90 secondsProcess throttled, then queued
RAM and entry processesPer-plan allocationNew processes deferred until capacity frees
Disk I/O and inodesPer-plan allocationThrottled, and backups pause above the inode ceiling
MySQLNo single query above 30 seconds, no persistent unindexed table scansQuery killed, repeat offenders reviewed
Outbound email500 messages per hourQueued, then blocked for the hour
Cron frequencyNo more often than every 5 minutesJob disabled

The following do not belong on a shared plan at all: public file-sharing, backup or media dumps unrelated to a website, cryptocurrency mining or nodes, torrent trackers and seedboxes, game servers, public proxies or VPN exits, video streaming or transcoding at scale, and load or stress testing.

Storage and bandwidth advertised as unlimited are for the normal operation of a website. They are not a general-purpose storage locker, and content not linked from your own site is out of scope.

We would rather move you than cut you offIf your site outgrows a shared plan, we will tell you which VPS or dedicated option fits and credit unused time from the current plan toward it. Suspension for resource use is a last resort, not a sales tactic.

6.Your Security Obligations

Most compromises we clean up start inside the account, not on the server. You are responsible for:

  • Keeping your CMS, themes, plugins and libraries patched. An outdated WordPress plugin is the single most common cause of a hacked site on our network.
  • Using strong, unique passwords, and enabling two-factor authentication where we offer it.
  • Removing abandoned installations, staging copies and unused accounts. Forgotten software is unpatched software.
  • Keeping your own copy of your data. Our backups are a courtesy, not a substitute, as set out in the Terms and Conditions.
  • Telling us promptly if you suspect a compromise, so we can contain it before it spreads.

If your account is compromised and is attacking others or sending spam, we will suspend it to stop the damage, then work with you to clean and restore it. Suspension in that situation protects you as much as the network.

7.How We Enforce This Policy

Enforcement is proportionate. We would rather have a fixed site than an empty server:

  1. Notice. For most first issues you get an email describing the problem and a reasonable window to fix it, usually 24 to 72 hours.
  2. Throttle or isolate. Where the issue is affecting neighbours, we limit the offending process or take the single site offline while the rest of your account keeps running.
  3. Suspension. Applied when the issue is live and harmful, such as an active attack, an open spam cannon or a phishing page. Restored once resolved.
  4. Termination. Reserved for Section 2 content, repeat breaches, and cases where you are unreachable while damage continues.

We skip straight to suspension or termination when the law requires it or when delay would cause real harm to a third party. Services terminated for breach are not refundable, as set out in Section 4.5 of the Terms and Conditions.

If you believe an action was taken in error, reply to the enforcement ticket with your evidence. We read every appeal, and we do reverse decisions when we get one wrong.

8.Reporting Abuse

To report content or activity on our network that breaches this policy, open a ticket marked Abuse or email our abuse address. Include the URL or IP address, the date and time with a time zone, a description of what you observed, and any headers or logs you have. Accurate reports with evidence get acted on fastest.

Copyright complaints should identify the specific infringing URL, the original work, and your relationship to the rights holder. We pass valid notices to the customer and act where the complaint stands up.

We do not disclose customer identities in response to a report. Where a request for customer data is legally binding and properly served, we comply with it and, unless legally prohibited, tell the customer.