Acceptable Use Policy
1. Purpose and Scope
This Acceptable Use Policy (“AUP”) defines the mandatory rules and boundaries governing the use of all web hosting, server environments, technical support, maintenance packages, and cloud services (“Services”) provided by Step3 Digital Ltd (“Step3”, “we”, “our”) to clients, their authorized users, and end-users (“Client”, “you”, “your”).
This AUP forms an integral part of the Step3 Master Terms and Conditions. By utilizing our Services, you agree to comply strictly with this policy. You are responsible for ensuring that all users, content managers, and third-party contractors accessing your site or infrastructure comply with this AUP.
2. Prohibited Content
You must not use Step3 infrastructure to host, transmit, store, link to, or distribute any content that is illegal, harmful, or infringes third-party rights. Prohibited content includes, but is not limited to:
- Illegal Material: Content that breaches any applicable local, national, or international law, regulation, or statutory code (including the UK Online Safety Act, Computer Misuse Act 1990, and Data Protection Act 2018).
- Intellectual Property Infringement: Unauthorized distribution, copying, or hosting of copyrighted materials, trademarks, patents, trade secrets, or pirated software (“nulled” WordPress themes, plugins, or software keys).
- Malicious & Harmful Code: Viruses, trojans, worms, logic bombs, ransomware, spyware, rootkits, or any software designed to compromise or disrupt digital environments.
- Defamatory & Harassing Content: Material that is unlawful, defamatory, libelous, threatening, harassing, abusive, obscene, or incites violence, hatred, or discrimination.
- Phishing & Fraud: Content designed to deceive users, impersonate financial institutions or brands, harvest credentials, or execute fraudulent financial activities.
- Unregulated High-Risk Activities: Content promoting illegal online gambling, unlicensed financial services, weapons manufacture, or illicit drug distribution.
3. Prohibited System & Network Activities
Clients must not engage in any activity that degrades, disrupts, or compromises the security, stability, or performance of Step3’s infrastructure or interconnected third-party networks. Prohibited activities include:
- Excessive Resource Consumption: Consuming CPU cores, RAM, I/O operations, disk storage, or bandwidth to an extent that jeopardizes server stability or causes performance degradation for other tenants on shared infrastructure (“noisy neighbor” abuse).
- Unsolicited Bulk Messaging (Spam): Sending unsolicited marketing emails, bulk messages, or hosting open mail relays. Using Step3 servers in a manner that causes Step3 IP addresses or domain names to be listed on global spam blacklists (e.g., Spamhaus) is strictly prohibited.
- Cryptocurrency & Background Mining: Utilizing server allocations for cryptocurrency mining, distributed computing projects, or unapproved background daemons.
- Unauthorized Security Testing: Conducting port scans, vulnerability probes, stress testing, or Distributed Denial of Service (DDoS) simulations against Step3 or client environments without explicit prior written authorization from Step3.
- Credential & Access Abuse: Attempting to bypass system authentication, access unauthorized data, probe administrative ports, or escalate local server privileges.
4. Client Security & Application Hygiene Obligations
Where Step3 provides hosting or maintenance services, the Client maintains ongoing operational responsibilities:
- Credentials: You must maintain strict password hygiene, enforce multi-factor authentication (MFA) on administrative accounts, and prevent unauthorized third-party access to site control panels.
- Third-Party Code: You must not upload or execute unlicensed, legacy, unsupported, or pirated third-party plugins, scripts, or themes on Step3 hosting environments.
- Compromised Environments: If your web application becomes compromised due to weak passwords or unapproved third-party code introduced by your team, Step3 reserves the right to isolate the site immediately to prevent lateral network contamination.
5. Rights of Monitoring & Content Takedown
- Monitoring Rights: Step3 is under no general obligation to monitor client content. However, we reserve the right to review server logs, resource usage metrics, and files where suspected violations of law, security breaches, or server instabilities occur.
- Takedown Requests & Notices: Step3 will comply with lawful court orders, law enforcement directives, statutory takedown notices, and credible notices of copyright infringement or defamation under English law.
6. Emergency Suspension & Enforcement
Step3 reserves the right to take swift enforcement action to protect its infrastructure, IP reputation, staff, and other clients.
- Immediate Suspension: Step3 may suspend, restrict, isolate, or terminate access to your hosting environment or services immediately and without prior notice if:
- We reasonably suspect your site is actively hosting malware, executing outbound attacks, or engaged in phishing;
- Your resource usage threatens the immediate stability of shared hosting infrastructure;
- We receive formal notice from law enforcement or statutory regulators; or
- You commit a material breach of this AUP.
- Remediation & Chargeable Work: Following an emergency suspension, Step3 will notify you of the cause. If technical intervention is required by Step3 to clean compromised code, remove malicious files, or remediate blacklist listings caused by Client negligence, such work shall be chargeable at Step3’s standard Pay-As-You-Go (PAYG) rate.
7. Limitation of Liability for Enforcement Actions
To the maximum extent permitted by English law, Step3 Digital Ltd shall accept no liability whatsoever for any loss of revenue, lost profits, business interruption, loss of data, or reputational damage incurred by the Client or any third party as a direct or indirect result of Step3 exercising its right to suspend, restrict, or remove services in good faith under this AUP.
8. Client Indemnification
You agree to defend, indemnify, and hold harmless Step3 Digital Ltd, its directors, officers, and employees against any third-party claims, liabilities, damages, losses, or costs (including legal fees) arising out of or connected with your breach of this Acceptable Use Policy or any illegal, infringing, or malicious content hosted on your environment.
9. Policy Updates & Inquiries
To report a suspected violation of this policy or submit a legal takedown notice, please contact Gary Brindley immediately at gary.brindley@step3.digital.