Skip to main content

Legal

Acceptable Use Policy

The rules for what can run on our platforms. They exist to keep every customer's service fast, reachable and out of trouble — not to catch anyone out.

Last updated: 11 August 2026

Template document — not yet legal advice

This document is a template provided for information only. It has not yet been checked by a qualified legal adviser, and it must be reviewed by one before this site goes live. Nothing here is legal advice, and nothing here is a substitute for it. Where this document differs from the signed agreement, order form or statement of work between you and Coffee Cup Solutions Ltd, that signed agreement takes precedence.

1. Scope and purpose

This acceptable use policy (AUP) applies to everyone who uses services provided by Coffee Cup Hosting Services, a trading name of Coffee Cup Solutions Ltd. It forms part of our terms of service.

It applies to you as the customer, and to anyone you allow to use the service — your staff, your contractors, your own clients and end users, and anyone using credentials issued under your account. You are responsible for their use of the service as if it were your own.

We are not in the business of policing what our customers publish, and we do not routinely inspect the content of hosted systems. This policy sets the outer limits: the things that put other customers, our network, our upstream suppliers or the law at risk.

2. General principles

  • Use the service lawfully, and in a way that does not harm others.
  • Do not use it in a way that damages our reputation, our IP address reputation, or our relationships with upstream providers.
  • Do not consume shared resources in a way that degrades the service for other customers.
  • Keep your systems and credentials secure, and act promptly when something goes wrong.

3. Prohibited content

You must not use the service to store, publish, transmit or link to material that:

  • is unlawful under the law of England and Wales, or under the law of any jurisdiction in which it is knowingly made available;
  • constitutes child sexual abuse material, or any other content whose possession or distribution is a criminal offence;
  • incites, promotes or facilitates terrorism, violence, or hatred against a person or group on the basis of a protected characteristic;
  • infringes another person's copyright, trade marks, database rights, design rights or other intellectual property;
  • is defamatory, harassing, or constitutes stalking, bullying or the intentional distribution of intimate images without consent;
  • discloses another person's personal data unlawfully;
  • is designed to deceive — phishing pages, fraudulent shops, fake login portals, counterfeit goods, or content impersonating another person or organisation;
  • consists of malware, ransomware, exploit kits, credential dumps, or tooling whose primary purpose is unauthorised access to systems;
  • facilitates unlawful gambling, the unlicensed sale of controlled substances or medicines, or the unlicensed provision of financial services.

Adult content that is lawful in the United Kingdom is not automatically prohibited, but it must be declared to us before it is hosted, must be appropriately age-gated, and may not be suitable for every platform. Please ask us first.

4. Prohibited activity

You must not use the service to:

  • gain or attempt to gain unauthorised access to any system, account, network or data, whether ours or anyone else's;
  • scan, probe or test the vulnerability of systems you do not own or have written authorisation to test;
  • intercept, monitor or modify traffic that is not yours;
  • launch or participate in a denial-of-service attack, or operate command-and-control infrastructure for a botnet;
  • forge or falsify headers, sender addresses, packet source addresses or any other identifier;
  • circumvent authentication, rate limits, licensing controls or usage restrictions on any system;
  • operate open mail relays, open proxies, open recursive DNS resolvers, or other services that can be abused for reflection or amplification attacks;
  • run anonymising exit nodes or public VPN endpoints without our prior written agreement;
  • mine cryptocurrency, or run equivalent speculative compute workloads, without our prior written agreement;
  • resell, sublicense or share the service outside the terms of your agreement.

5. Email, messaging and anti-spam

Unsolicited bulk or commercial messaging causes rapid, lasting damage to the deliverability of every customer sharing our sending reputation, so we treat it seriously.

You must not send, or allow to be sent from your service:

  • unsolicited bulk email, SMS or instant messages, whether commercial or not;
  • marketing that does not comply with the Privacy and Electronic Communications Regulations 2003 and UK GDPR;
  • messages to purchased, scraped, rented or otherwise unverified address lists;
  • messages with forged headers, misleading subject lines or a disguised sender identity;
  • messages that do not identify the sender or that lack a working unsubscribe mechanism, where one is required;
  • mail to addresses that have unsubscribed, hard bounced or complained.

If you run a mailing list, use confirmed opt-in, keep evidence of consent, honour unsubscribes promptly, and monitor your bounce and complaint rates. If you intend to start sending at volume from a new service, tell us in advance so we can help you warm it up and get authentication — SPF, DKIM and DMARC — configured properly.

We may apply outbound rate limits, filtering and reputation monitoring to protect the platform. Sudden unexplained changes in sending volume may trigger an automatic hold while we check with you.

6. Security testing and vulnerability research

Security testing of your own hosted service is allowed, and encouraged, on the following terms:

  • tell us in writing before the test, giving the target scope, the source addresses and the testing window;
  • test only assets that are yours, within the service we provide to you;
  • do not include denial-of-service, volumetric load or stress testing without separate written agreement — this affects shared infrastructure;
  • do not attempt to reach other customers' data, the hypervisor, the management network or our internal systems;
  • stop immediately and tell us if you inadvertently gain access to something outside your scope, and do not retain, copy or disclose anything you find.

If you believe you have found a vulnerability in our platform, please report it to support@coffeecupsolutions.com rather than exploiting or publishing it. We will acknowledge the report, keep you informed, and will not pursue action against anyone who reports a genuine issue in good faith and gives us a reasonable opportunity to fix it.

7. Resource usage

Your service has an allocation of CPU, memory, storage, bandwidth and, where relevant, inodes, database connections or concurrent processes. The allocation is set out in your order form.

  • Do not deliberately exceed your allocation, or engineer around limits that are in place.
  • On shared platforms, do not run processes that starve other tenants — runaway cron jobs, unbounded crawlers, poorly indexed queries hammering a shared database, or long-running background jobs that should be on a dedicated resource.
  • Do not use hosting or backup storage as a general-purpose file distribution, media streaming or archive service unless that is what you have bought.
  • Keep software you control reasonably up to date. Out-of-date, unpatched applications are the single most common cause of compromise, and a compromised site becomes everyone's problem.

If your service consistently outgrows its allocation, that is a sizing conversation, not a breach. We will tell you what we are seeing and recommend an appropriate change rather than letting you find out through degraded performance.

8. Reporting abuse

To report content or activity on our network that you believe breaches this policy, email support@coffeecupsolutions.com or ring 0118 384 2175. Please include:

  • the URL, IP address, domain or email address concerned;
  • full message headers, where the report relates to email;
  • timestamps with the time zone;
  • a short description of what you believe is happening, and any evidence you can share.

We investigate every credible report. We will acknowledge it, and we will tell you the outcome where we are able to, bearing in mind our confidentiality obligations to our customers.

9. What happens if this policy is breached

Our response is proportionate to what has happened, how serious it is, and whether it appears deliberate. In most cases the first step is a phone call or an email asking you to fix something. Depending on the circumstances we may:

  • contact you and ask you to remove content or stop an activity within a stated period;
  • apply technical measures such as rate limiting, filtering or blocking a specific address or process;
  • suspend the affected part of the service, or the whole service, in line with the suspension provisions of our terms of service;
  • remove or disable access to specific content where we are legally required to do so, or where the content is manifestly unlawful;
  • terminate the agreement for material breach, where the breach is serious or repeated;
  • report the matter to law enforcement or a relevant authority where we are required to, or where we reasonably believe a serious criminal offence has been committed.

Where there is an immediate risk to our platform, to other customers, or to third parties — an active compromise, an outbound attack, or content whose possession is itself an offence — we may act first and tell you immediately afterwards. We will always limit the action to what is necessary and restore the service as soon as the cause is dealt with.

You are responsible for the charges arising from any additional work, upstream penalties or third-party costs we incur as a result of a breach of this policy attributable to your service.

10. Changes to this policy

We update this policy from time to time as threats, law and our supply chain change. The date at the top of this page shows when it was last revised, and we will notify customers of material changes before they take effect.

11. Questions

If you are not sure whether something you want to run is acceptable, ask us before you build it. We would far rather have that conversation early than have to interrupt a live service. Email hello@coffeecupsolutions.com or ring 0118 384 2175.