Back to OzVPS
Legal

Acceptable Use Policy

Last updated 25 June 2026

This Acceptable Use Policy ("AUP") governs your use of services provided by OzVPS (ABN 58 947 584 850), including our VPS hosting and our Enhance-powered Web Hosting. It exists to protect our network, our customers, our upstream providers and the wider internet community. Violations may result in immediate suspension or termination of your services without refund, and in serious cases referral to law enforcement.

OzVPS determines whether conduct or content breaches this AUP at our sole and reasonable discretion. Where this AUP gives examples (using "including", "such as", or similar), those examples are illustrative and not exhaustive. If you are unsure whether a planned use is acceptable, ask us in writing before signing up.

Read this first · Strictly not allowed

OzVPS is an Australian hosting business for legitimate Australian workloads. The following uses are not welcome on our network at any plan level and will result in immediate suspension:

  • Tor exit nodes, Tor relays and other anonymising infrastructure
  • Commercial VPN services: running a VPN endpoint to resell or share with the public
  • Streaming, IPTV, video-on-demand or media-piracy services of any kind (including "private" services and re-streams of paid content)
  • Torrent trackers or seedboxes distributing copyrighted material
  • Public DNS resolvers, open proxies or open SMTP relays
  • Cryptocurrency mining or hash-rental of any kind
  • Adult content sites, escort directories or "cam" platforms
  • Bulk-email senders, "mail marketing" platforms or any outbound unsolicited mail
  • Game-cheat, account-generator, credential-stuffing or "booter / stresser" services
  • HYIP, ponzi, "investment", "forex signals" or cryptocurrency-scam sites

Personal-use VPNs for yourself or your immediate family on a single VPS are fine. Anything that looks like a commercial VPN, anonymising service or media-piracy operation is not.

1. Prohibited activities

You agree not to use OzVPS services, or to permit any other person to use them, for any of the following:

  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks, including reflection / amplification participation
  • Attempting to bypass, overwhelm or test rate limits or any other security control of OzVPS or our upstream providers
  • Port scanning, vulnerability scanning, fuzzing or brute-force attacks against any third-party system without prior written authorisation from the system owner
  • Penetration testing, security research or red-teaming against OzVPS infrastructure (network, control panels, billing systems) without our prior written authorisation
  • Circumventing the security measures of any system, including credential stuffing, session hijacking, exploitation of disclosed or undisclosed vulnerabilities
  • Any activity that materially degrades network performance, hypervisor performance or storage performance for other customers
  • Account fraud, identity misrepresentation, providing false ABN/registration details, or chargeback fraud
  • Sending unsolicited bulk email (spam), operating as an open relay, laundering mail through third-party SMTP services, or any practice contrary to the Spam Act 2003 (Cth)
  • Hosting links, redirectors, "drop sites" or staging infrastructure for phishing, scam, malware or social-engineering campaigns
  • Automated scraping, harvesting or crawling of third-party services in breach of their terms or applicable law
  • Harassment, stalking, doxxing, intimidation or coordinated targeting of any individual or group
  • Running services explicitly listed in the box above
  • Selling, advertising, brokering or facilitating illegal goods or services, including illicit drugs and controlled substances, weapons, firearms, ammunition or explosives, counterfeit goods, forged or fraudulent documents and identification, or pirated software and licence keys
  • Trading in stolen, leaked or unlawfully obtained data, including payment-card data, "fullz", carding services, or compromised account credentials
  • Selling, brokering, publishing or otherwise distributing other people's personal information (including compiled mailing lists, scraped contact databases or bulk identity records) without the consent or other lawful basis required under the Privacy Act 1988 (Cth) and the Australian Privacy Principles
  • Money laundering, terrorism financing, sanctions evasion, or facilitating any of these
  • Dealing with, or directing services or content at, persons, entities or jurisdictions subject to Australian or applicable international sanctions, or supplying age-restricted goods or services (such as alcohol, tobacco, gambling or adult goods) without the age and identity verification required by law
  • Operating an unlicensed gambling, lottery, wagering or "investment" scheme, including any such service targeting Australian residents without the licence required under Australian law
  • Developing, selling or distributing malware, ransomware or exploits, or offering "hacking-as-a-service", "spam-as-a-service" or attack-for-hire in any form
  • Circumventing, or making, selling, distributing or providing a service to circumvent, a technological protection measure (such as DRM, copy-control or access-control on software, games, films or other works) in breach of the Copyright Act 1968 (Cth)
  • Any activity that is unlawful in Australia or in the jurisdiction where the service is delivered, or that is reasonably likely to expose OzVPS to legal, regulatory or reputational risk

2. Prohibited content

The following content is strictly prohibited on our network:

  • Child sexual abuse material (CSAM) or any child-exploitation content. This is reported to the Australian Centre to Counter Child Exploitation (ACCCE) and other authorities
  • Content that incites violence, terrorism or genocide, or that promotes a designated terrorist organisation
  • Content that infringes copyright, trade mark, patent, design or other intellectual property rights you do not own or have a current licence to distribute
  • Malware, command-and-control infrastructure, exploit kits, phishing kits, infostealers, RATs and remote-access trojans
  • Material classified RC (Refused Classification) or X 18+ under the Australian Classification scheme
  • Non-consensual intimate imagery, "deepfake" intimate imagery, or any image-based abuse covered by the Online Safety Act 2021 (Cth)
  • Defamatory, knowingly false or grossly misleading material directed at an identifiable person or business
  • Personal information (including health, financial or identity records) processed in breach of the Privacy Act 1988 (Cth) or comparable laws

3. Customer responsibility

You are solely responsible for everything that happens under your account and on any service you operate using OzVPS infrastructure, whether the activity is performed by you, your employees, your contractors, your customers, your end-users or by anyone who has obtained access to your services (whether authorised or not).

If you resell, host third-party customers or operate a multi-tenant application on OzVPS, you must enforce an acceptable-use standard with your own users that is at least as strict as this AUP, and you are responsible for promptly investigating and remedying abuse complaints relating to those users.

4. Account security

You must keep your OzVPS account credentials, API keys and SSH keys secure. You must enable available account-security features (such as two-factor authentication on the client area) where offered. Compromise of your credentials, including third-party use of leaked passwords, does not relieve you of responsibility for activity performed under your account.

5. IP and network reputation

OzVPS allocates IP addresses to customers from address space we have a responsibility to keep clean. You agree not to engage in conduct that causes our IP space to be listed on public blocklists (e.g. Spamhaus, SORBS, abuseipdb), to be filtered by major email providers, or to be subject to upstream null-routing requests. If an allocated IP becomes listed as a result of your activity, you must cooperate with our delisting process and we may reclaim that IP and reissue you a new one at our discretion.

6. Resale and account sharing

Sub-letting, white-labelling or reselling OzVPS services to third parties is permitted only with our prior written consent. Account sharing is limited to your immediate organisation. You may not advertise an OzVPS service as your own without identifying OzVPS as the underlying provider where reasonably required.

7. Copyright complaints and takedown

OzVPS responds to credible copyright-infringement complaints under the Australian Copyright Act 1968 (Cth) and to comparable notices from international rights-holders where appropriate. Complaints must identify:

  • The copyrighted work allegedly infringed
  • The specific URL(s) or content on our network claimed to infringe
  • Your contact details and authority to act for the rights-holder
  • A statement, made in good faith, that the use is not authorised

Send complaints to [email protected]. Repeat infringers will have their services terminated.

8. Fair use on Web Hosting plans

Your transfer is not metered. We don't count gigabytes, we don't sell you a monthly allowance, and you will never get a bill for traffic. A busy month is a good thing and we won't charge you for it.

The space is for your website. Your disk is for files that are part of a working site and reachable through it. It is not for the storage of backup archives, nor any data that is not directly related to and accessible through the website itself. Media libraries for a site hosted somewhere else, personal cloud storage and file dumps belong on a VPS, and we'll help you move them there.

Some workloads are perfectly legitimate but do not belong on a shared server. These are not prohibited, they simply need a VPS, and we will help you move across:

  • Personal cloud storage, file sync or backup tools such as Nextcloud, ownCloud or Seafile
  • Media libraries or asset stores that serve a site hosted somewhere else
  • Software that needs root, a custom system package, a specific runtime version or a non-standard stack
  • Long-running daemons, queue workers or background processes that must stay resident
  • Game servers, or anything that needs its own ports, firewall rules or dedicated IP address
  • Applications that consistently exceed the per-site CPU, memory or disk-speed limits below

This is a different list from the prohibited services in section 1. Those are not permitted anywhere on our network, including on a VPS. Moving a prohibited service to a VPS does not make it acceptable.

Every account has resource limits. CPU, memory, disk speed, processes and file count are capped per website so one site can't degrade the server for everyone else. Your live usage is visible in your control panel at any time. If a site keeps hitting a limit we'll tell you which one and why, and either help you fix it or help you move up.

How we enforce this. Where something on your account is degrading the service for other customers, our usual first step is to rate limit that one site and contact you with what we saw. Where we believe you have crossed a line, our usual approach is to contact you, give you a reasonable opportunity to put it right, and talk it through. Deleting customer data is a last resort, not a first or second response. Where we restrict an account under this section, data already stored generally remains in place and retrievable.

The exceptions, stated plainly. This section describes how we normally handle fair-use and resource problems. It is not a guarantee of notice or of a grace period, and it does not limit our rights under section 9 (immediate termination) or section 13 (enforcement and discretion). We may act immediately, without notice, and may suspend, restrict access to or remove content or an account where:

  • We are directed to by a court, regulator, law-enforcement agency or upstream provider, or are otherwise required to by law
  • The content is unlawful, or we reasonably suspect it is, including child abuse material, phishing, malware distribution or sanctions breaches
  • There is an active security incident, compromise or attack, whether originating from your account or directed at it
  • Continuing would put our network, our other customers, our upstream providers or our own legal position at material risk
  • The account is being used fraudulently, or payment has been reversed or disputed

Outbound email is limited on every plan to protect the mail reputation of everyone here. The limit applies to your whole account. If you need to send bulk email, use a service built for it and we'll help you set it up.

If you're unsure whether something is allowed, ask before you build it. You'll get a straight answer, not a shrug.

9. Immediate termination

Certain violations result in immediate termination without warning, including:

  • Child exploitation material, reported to law enforcement
  • Outbound DDoS attacks, "booter / stresser" services or participation in attack-for-hire
  • Operation of botnet command-and-control infrastructure
  • Hosting of phishing kits or active phishing campaigns
  • Knowingly hosting malware, infostealers or remote-access trojan infrastructure
  • Repeat or wilful breach of this AUP after a prior warning
  • Use of the service that places OzVPS or its upstream providers at material legal or regulatory risk

Where immediate termination occurs, all prepaid amounts in respect of the terminated services are forfeited and no refund is payable.

10. Resource use

Your VPS resources (CPU, memory, disk I/O, network) are dedicated within the bounds of your plan. Sustained 100% utilisation of shared host resources (e.g. CPU steal or disk I/O affecting neighbours) may result in your VPS being throttled, migrated to a less crowded host, or asked to upgrade.

11. Reporting abuse

To report a violation of this AUP, contact [email protected]. We investigate every report and respond within one business day. Please include the affected IP address or domain, the nature of the abuse and any relevant timestamps (AEST preferred).

12. Cooperation with authorities

OzVPS cooperates with the Australian Federal Police (AFP), state and territory police, the Australian Communications and Media Authority (ACMA), the Office of the eSafety Commissioner, the Office of the Australian Information Commissioner (OAIC) and international law-enforcement agencies in the investigation of unlawful activity on our network, as required under the Criminal Code Act 1995 (Cth), the Telecommunications (Interception and Access) Act 1979 (Cth), the Online Safety Act 2021 (Cth), the Privacy Act 1988 (Cth) and other applicable laws. Where required by law or by lawful direction, we may preserve, access or disclose customer data and content without prior notice to the customer.

13. Enforcement and discretion

Enforcement of this AUP is at OzVPS's sole and reasonable discretion. We may, without prior notice:

  • Suspend or terminate any service that we reasonably believe is being used in breach of this AUP
  • Null-route, filter or rate-limit traffic to or from a customer service
  • Remove or quarantine specific content
  • Reclaim and reissue IP addresses
  • Decline to restore a terminated service
  • Decline to provide future services to a customer who has breached this AUP

Action taken under this AUP does not entitle you to any refund, credit or other compensation, and is separate from the service-level target in our Terms of Service.

14. Indemnity

You indemnify OzVPS, its operators, employees, contractors and upstream providers against all claims, losses, damages, fines, penalties and legal costs (on a full-indemnity basis) arising from or in connection with your breach of this AUP, your content, or any use of your services by third parties. This is in addition to the indemnity in our Terms of Service.

15. Changes to this policy

We may update this AUP from time to time to reflect operational, legal or regulatory changes. Material changes will be announced via the client area and by email. Continued use of the service after a change constitutes acceptance of the updated policy.