This Acceptable Use Policy (AUP) applies to everyone who uses a BPHOST service, including your staff, your developers, your clients if you resell, and anyone else you give access to. It forms part of our Terms of Service.
The purpose is not to police you. It is to keep a shared platform stable, keep our IP ranges out of spam blocklists, and keep you from inheriting someone else's bad day.
1The short version#
- Everything you host must be lawful — in South Africa and wherever your audience is.
- Do not send unsolicited bulk email, from our network or pointing back at it.
- Do not use a shared account in a way that degrades service for others.
- Keep your software patched. A compromised site is a problem for the whole server.
- If you are unsure whether something is allowed, ask us first. That conversation is free; a suspension is not.
2Prohibited content#
You may not store, host, publish, link to or transmit:
- Child sexual abuse material. Absolutely and without exception. We report it to the authorities immediately and terminate without notice, refund or warning.
- Content that infringes copyright, trade marks or other intellectual property — including pirated software, films, music, books, courses, cracks, keygens, licence generators, and sites whose purpose is to index or distribute them.
- Pornographic and sexually explicit material. We do not host adult content of any description.
- Malware — viruses, trojans, ransomware, exploit kits, droppers, or command-and-control infrastructure.
- Phishing — pages imitating a bank, a payment provider, a courier, a government service or any other organisation in order to harvest credentials, card details or identity documents.
- Fraudulent schemes — Ponzi and pyramid schemes, fake stores, advance-fee fraud, bogus investment or "guaranteed returns" offers, and counterfeit goods.
- Hate speech and incitement — content that advocates violence against, or hatred of, a person or group, including anything prohibited under section 16(2) of the Constitution.
- Harassment material — doxxing, stalking, revenge pornography, or content targeting a private individual.
- Hacking, cracking and warez material, including tutorials whose evident purpose is unauthorised access to systems the reader does not own.
3Prohibited activity#
You may not use a BPHOST service to:
- Attack or probe other systems — port scanning, vulnerability scanning, brute-force or credential stuffing attacks, or any attempt to gain unauthorised access, whether the target is on our network or elsewhere.
- Participate in denial-of-service attacks, as a source, a relay or a booter service.
- Run cryptocurrency miners or any other workload whose purpose is to consume CPU for profit, including browser-based miners served to your visitors.
- Operate open proxies, open relays, anonymising services, VPN exit nodes or Tor relays.
- Run public file-sharing, torrent trackers, seedboxes or media streaming services for content you do not own.
- Circumvent resource limits, suspensions, or the technical controls on your account.
- Misrepresent your identity — forging headers, spoofing IP addresses, or impersonating another person or organisation.
- Interfere with another user's service or attempt to access another account's data.
Security research and penetration testing against systems you own or have written authorisation to test is fine — tell us in advance so our monitoring does not treat it as an attack.
4Email and anti-spam#
Spam is the fastest way to get an entire server's IP range blocklisted, which is why we are strict here.
- You may only send bulk or marketing email to recipients who opted in. Purchased, scraped, rented or "appended" lists are not permitted, whatever the seller told you.
- Every marketing message must identify you and carry a working unsubscribe mechanism, and unsubscribes must be honoured promptly. This is also what the CPA and ECTA require.
- Do not send from forged or misleading headers, and do not use a hosted script as an anonymous mailer.
- Outbound mail limits apply on shared hosting to contain compromised accounts. If you have a legitimate need for higher volume, talk to us — and for genuine bulk sending, use a dedicated email service provider rather than a hosting account.
- Set up SPF, DKIM and DMARC for your domain. We will help. Without them your mail will struggle to be delivered regardless of what we do.
- Mailing lists must be confirmed opt-in and must keep a record of consent.
Spam sent to our network is not your responsibility, but spam advertising a site hosted with us is — even if it was sent from somewhere else.
5Resource usage#
Shared hosting divides one machine among many accounts. Plans described as "unlimited" or "unmetered" mean we do not impose an arbitrary cap — they do not mean one account may take the whole server.
We will contact you where an account is causing problems through:
- Sustained CPU, memory or disk I/O consumption that affects other accounts.
- Excessive inode counts — typically millions of tiny files, often a runaway cache or log.
- Long-running or runaway processes, or unattended background daemons.
- Unoptimised database queries hammering the server.
- Using the account as remote backup, file storage, archiving or media distribution for material not part of a hosted website.
Our first step is always a conversation. Usually it is a plugin, a cron job or a bot, and we fix it together. Where usage genuinely needs more machine, we will recommend a VPS or dedicated server rather than simply throttling you.
6Keeping your account secure#
Most compromises we deal with are outdated software, not broken servers. You are responsible for:
- Updating your CMS, themes, plugins and any custom code — promptly, not eventually.
- Removing abandoned installations. That old staging copy of WordPress nobody has patched since 2019 is how attackers get in.
- Strong, unique passwords for hosting, control panel, FTP, database and application logins.
- Correct file and directory permissions, and not leaving writable upload directories executing scripts.
- Telling us as soon as you suspect a compromise.
If we detect a compromised account we may suspend it to stop the damage spreading, and we will tell you what we found and what to do about it. Where we can help you clean it up, we will.
7Copyright complaints#
If you believe material hosted by us infringes your copyright, submit a takedown notice through our abuse report form, including:
- Your name, address and contact details.
- Identification of the work you say is infringed.
- The exact URLs of the material complained of.
- A statement that you have a good-faith belief the use is not authorised by the rights holder or the law.
- A statement that the information in the notice is accurate, and that you are the rights holder or authorised to act for them.
- Your signature.
We handle notices in line with the take-down procedure under Chapter XI of ECTA. We will act on a valid notice and notify the account holder, who may respond. Knowingly making a materially false claim carries liability for damages under section 77 of ECTA.
If your content was removed and you believe that was wrong, tell us through the legal enquiry form with your reasons, and we will review it.
8Reporting abuse#
To report spam, phishing, malware, copyright infringement or anything else on this page, use our abuse report form. Include headers, URLs, timestamps and any evidence you have — the more specific the report, the faster we can act.
We investigate every report. We will not tell the reporter what action we took on someone else's account, but we do act.
9How we enforce this policy#
Our response is proportionate to what we find. In most cases that means we contact you first and give you a chance to fix it.
- Notice. We explain the problem and set a reasonable deadline.
- Suspension. Where the problem is ongoing, urgent, or not addressed, we suspend the service. Your data is retained and the service is restored once it is resolved.
- Immediate suspension without notice. Reserved for active attacks, ongoing spam runs, phishing, malware distribution, compromised accounts, and anything unlawful — situations where waiting causes real harm to other people.
- Termination. For serious or repeated breaches.
We will always tell you what action we took and why, except where the law prevents us. Accounts terminated for breach of this policy are not refunded, and we may report unlawful activity to the relevant authorities.
BPHOST decides what constitutes a breach of this policy, acting reasonably.
10If you think we got it wrong#
We do get it wrong sometimes — an automated signal misfires, or a legitimate campaign looks like a spam run. If your service was suspended and you believe it was a mistake, reply to the notice or open a ticket and tell us why. A person will look at it.
We would rather reinstate a wrongly suspended client quickly than defend a bad call.
11Changes to this policy#
Threats and abuse patterns change, so this policy does too. The effective date at the top of the page shows the current version, and material changes are notified as set out in our Terms of Service.
Questions about this document
If anything here is unclear, ask us — we would rather explain it up front than have you agree to something you do not understand.
- General enquiries
- Contact form
- Privacy requests
- Privacy request form
- Abuse reports
- Abuse report form








