ACCEPTABLE USE POLICY (AUP)
Version: 1.0 | Effective date: 14.09.2026
TABLE OF CONTENTS
- Scope, applicability and definitions
- General principle of lawfulness
- Prohibited content
- Prohibited technical activities
- E-mail and commercial communication rules
- Resource usage
- Service-specific rules
- IRC rules
- IP addresses and network reputation
- Application and account security
- Reseller rules
- Monitoring and investigation
- Reporting abuse
- Consequences of violation
- Abuse-related fees
- Changes to this policy
1. SCOPE, APPLICABILITY AND DEFINITIONS
1.1. This Acceptable Use Policy ("AUP") sets out the rules for using all services provided by S.C. CROCKY S.R.L. (CUI RO50515950, J2024020698007, Str. Drăgaica nr. 5, sat Balasan, mun. Băilești, jud. Dolj, Romania), operating under the trade names "CrockyHost" and "Crocky" (the "Provider").
1.2. The AUP forms an integral part of the General Terms and Conditions of Service (the "Terms"), published at https://crocky.host/legal/terms-of-services, and applies to all Clients, their end users and any person accessing or using the Services, regardless of the type of Service (shared hosting, reseller, managed WordPress, WaaS, VPS, NAT VPS, game servers, dedicated servers, domain names, web design and maintenance services).
1.3. Capitalised terms not defined here have the meaning given in the Terms. In case of conflict between the AUP and the Terms, the AUP prevails with respect to usage rules and the Terms in all other respects.
1.4. The Client is responsible for compliance with the AUP by all persons to whom they directly or indirectly grant access to the Services (employees, collaborators, their own customers, website users, players on game servers).
2. GENERAL PRINCIPLE OF LAWFULNESS
2.1. The Services may be used exclusively for lawful purposes, in accordance with: (a) the laws of Romania; (b) the laws of the European Union; (c) the laws of the state where the server is physically located (currently France, Germany, Poland or another EU member state, depending on the Upstream Provider); (d) the laws of the state of residence of the Client and their end users; (e) the terms of use and abuse policies of the Upstream Providers (OVHcloud, Contabo, Scaleway) and of software vendors.
2.2. The absence of an express prohibition in this AUP does not mean an activity is permitted if it is illegal, harmful to third parties or to the Provider's infrastructure, or contrary to the purpose of the Service. In case of doubt, the Client shall obtain the Provider's prior written consent.
3. PROHIBITED CONTENT
3.1. It is strictly prohibited to use the Services to store, publish, transmit, distribute, promote or facilitate access to:
- (a) child sexual abuse material (CSAM), in any form, including artificially generated content, drawings or text, as well as any content that sexualises minors. Such cases are reported immediately to the competent authorities (DIICOT, Europol, INHOPE), and all of the Client's Services are terminated without notice, without refund and without any possibility of data recovery;
- (b) content infringing intellectual property rights: pirated software, licence keys, cracks, keygens, warez, unauthorised distribution of films, music, books, games, fonts, premium themes or plugins ("nulled"), illegal streaming sites, torrent trackers or indexes for protected content, unlicensed "IPTV" services;
- (c) malicious software and attack infrastructure: malware, ransomware, viruses, trojans, rootkits, spyware, exploit kits, command and control (C2) servers, phishing infrastructure, spoofed login pages (banks, e-mail services, social networks, institutions), card testing or carding scripts, collections of stolen credentials;
- (d) content inciting hatred, violence or discrimination on grounds of race, ethnicity, nationality, religion, sex, sexual orientation, disability or other protected characteristics; terrorist or extremist content; threats; harassment; disclosure of a person's personal data for intimidation purposes (doxxing);
- (e) fraud and scams: pyramid schemes, Ponzi schemes, HYIPs, cryptocurrency scams, fictitious online shops, counterfeits, forged documents, sale of fake reviews, "get rich quick" schemes;
- (f) pornographic or adult content, except with the Provider's prior written approval, exclusively on VPS and Dedicated Servers, in compliance with applicable law (including age verification), the Upstream Provider's terms and with an absolute prohibition of the content under point (a) and of non-consensual content;
- (g) gambling, betting, lotteries or online casinos without a valid licence issued by the competent authority (in Romania, ONJN) for the targeted jurisdictions;
- (h) illegal products and services: drugs and prohibited substances, weapons, ammunition, explosives, unauthorised medicines, money laundering services, forged documents;
- (i) personal data obtained unlawfully or processed without a legal basis, including purchased e-mail or telephone databases, lists scraped without consent, stolen data;
- (j) content infringing a person's rights to their image, privacy or dignity, including intimate images distributed without consent;
- (k) any other content that is illegal under the laws referred to in art. 2.1.
4. PROHIBITED TECHNICAL ACTIVITIES
4.1. The following activities are prohibited on all Services, regardless of type:
- (a) attacks and intrusions: port or vulnerability scanning, brute-force attacks, denial of service (DoS, DDoS, amplification) or participation therein, against any system, including the Provider's, regardless of whether the target system "consented", except for penetration tests authorised in writing by the Provider and by the owner of the target system;
- (b) cryptocurrency mining or any proof-of-work or proof-of-space activity, "plotting", as well as running blockchain network nodes consuming disproportionate resources, on any Service, including VPS and Dedicated Servers;
- (c) operating Tor exit nodes, public, open or commercial VPN or proxy services (including SOCKS, HTTP proxies, Shadowsocks, WireGuard/OpenVPN offered to third parties), anonymising relays, residential proxies or proxy farms. Using a personal VPN for the Client's own administrative access to a VPS or Dedicated Server is permitted;
- (d) operating botnets, command and control servers, flood scripts, "stress tester", "booter" or "IP stresser" services, regardless of claimed legitimacy;
- (e) unauthorised access to accounts, data or resources of other Clients or of the Provider; circumventing or manipulating resource limits, CageFS, LVE or other isolation mechanisms; exploiting Platform vulnerabilities; privilege escalation;
- (f) reselling Service resources to third parties on Shared Hosting, Managed WordPress, WaaS, NAT VPS and Game Servers, except for Reseller Services or with the Provider's written consent. Reselling is permitted without prior consent on VPS and Dedicated Servers (for example by installing Proxmox, Virtualizor or LXC containers on a Dedicated Server or VPS and making the resulting virtual machines or containers available to third parties), subject to compliance with Section 11 (reseller rules);
- (g) forging headers, identity, IP address or the origin of any communication; IP spoofing; using unallocated MAC or IP addresses;
- (h) aggressive crawling, scraping or scanning of third-party websites that ignores robots.txt, generates disproportionate load or collects personal data without a legal basis;
- (i) torrents and file sharing: running BitTorrent clients, seedboxes, eDonkey/eMule servers or other peer-to-peer networks, as well as trackers, on any Service, except on VPS and Dedicated Servers for the distribution of the Client's own or legally licensed content, with prior written approval;
- (j) anonymous network servers (I2P, Freenet), mixing nodes, "bulletproof hosting" or services that deliberately conceal their operator;
- (k) using the Services to circumvent geographic restrictions, international sanctions or embargoes;
- (l) creating fraudulent automated accounts, orders or transactions, card testing, using stolen payment data or mass-registering accounts on third-party services;
- (m) running scripts or processes that operate permanently in the background (daemons), unrelated to the contracted Service, on Services that do not permit this (see Section 7).
5. E-MAIL AND COMMERCIAL COMMUNICATION RULES
5.1. Spam prohibition. It is prohibited to send unsolicited commercial messages (spam) by e-mail, SMS, contact forms, comments, instant messaging, push notifications or any other channel, from or through the Services, as well as to promote by spam a website hosted by the Provider, even if the spam is sent from other servers ("spamvertising").
5.2. Consent. Any commercial communication sent through the Services must comply with Romanian Law no. 506/2004, art. 13 GDPR, Directive 2002/58/EC and the equivalent legislation of the recipients' states. The Client must be able to prove, for each recipient, prior express consent (opt-in), its date and source. The following are prohibited: purchased, rented, automatically harvested or third-party sourced address lists; implied opt-out; addresses taken from WHOIS or public websites.
5.3. Mandatory requirements for commercial messages: genuine and complete identification of the sender; a functional, free unsubscribe mechanism, processed within 48 hours at most; a non-misleading subject line; valid and authenticated sending addresses (SPF, DKIM, DMARC).
5.4. Technical limits on Shared and Reseller Hosting: maximum [100] messages per hour per cPanel account and [500] per day; maximum [50] recipients per message; bulk mailing scripts and lists of more than [500] subscribers are prohibited; for newsletters and campaigns the Client shall use a specialised service (for example Mailchimp, Brevo, Amazon SES). Limits for VPS, Game Servers and Dedicated Servers are set out in Section 7.
5.5. Filtering. The Provider may scan outgoing messages for spam, malware and phishing, may hold or block suspicious messages and may temporarily suspend the e-mail function of an account generating complaints, mass bounces or the listing of IP addresses on blacklists. The Provider does not guarantee deliverability of messages to third-party servers.
5.6. Compromised accounts. The Client is responsible for spam sent from their compromised accounts (weak passwords, outdated applications, unprotected forms). The account is suspended until the cause is remedied and all passwords are changed.
5.7. Mail servers on VPS and Dedicated Servers. Port 25 may be blocked by default upon activation; unblocking is granted on request, after verification, with the obligation to correctly configure reverse DNS, SPF, DKIM and DMARC. Operating an open relay or mail servers for third parties without written consent is prohibited.
6. RESOURCE USAGE
6.1. The Client undertakes not to use the Services in a manner that adversely affects the operation of the infrastructure or the Services of other Clients ("noisy neighbour"). The resource limits of each Service are those in the accepted offer, in the control panel and in the Annexes to the Terms.
6.2. The Provider may throttle, isolate, temporarily suspend or stop processes, scripts, cron jobs, databases or Services generating abnormal CPU, memory, I/O, network connection or traffic consumption, notifying the Client as soon as possible. In emergencies (impact on other Clients or on the infrastructure), intervention may be immediate, without prior notice.
6.3. "Unlimited" usage. Where a plan is described as having "unlimited" space or traffic, this means without a preset limit under normal and reasonable use for the purpose of the Service. It does not mean: use as file storage, archive, external backup, mirror, CDN, distribution of large files (video, ISO, archives, games), streaming, or consumption disproportionate to the average of Clients on the same infrastructure. The Provider may require a reduction in consumption or an upgrade to a higher Service, with a reasonable compliance period.
6.4. The following are prohibited on all shared Services (Shared Hosting, Reseller, Managed WordPress, WaaS): processes running permanently in the background, game servers, bots, scanners, streaming services, chat servers, proxies and any application requiring a dedicated listening port.
7. SERVICE-SPECIFIC RULES
7.1. Shared Hosting, Reseller, Managed WordPress, WaaS. In addition to the general rules: (a) stored content must be an integral part of the hosted websites; files unrelated to the website (archives, backups of other systems, collections of downloadable files) may be deleted after 48 hours' notice; (b) cron jobs have a minimum frequency of 5 minutes and a maximum duration of 5 minutes; (c) default limits: [250,000] inodes per account, [2 GB] per database, [100] messages/hour; (d) the following scripts are prohibited: file hosting, public image hosting, public URL shorteners, public pastebins, download mirrors and any service open to anonymous users that can be abused; (e) PHP versions without official support are provided "as is" and at the Client's risk.
7.2. VPS (Virtualizor, Proxmox). (a) The Service is unmanaged; the Client is responsible for operating system security; (b) sustained CPU usage above [50]% on average over 24 hours, permanent intensive I/O or other patterns affecting the node may lead to throttling, notification and, if persistent, a requirement to upgrade to a higher Service or suspension; (c) e-mail: maximum [500] messages per hour per VPS, in compliance with Section 5; (d) IRC is permitted in accordance with Section 8; (e) mining, Tor exit, public VPN/proxy, booters and torrents (except as per art. 4.1(i)) are prohibited.
7.3. NAT VPS. A Service with a shared IPv4 address and reduced resources, intended for personal use, development, testing or lightweight applications. In addition to the VPS rules, the following are prohibited: IRC (servers, bots or bouncers), public game servers, proxies, VPN, torrents, seedboxes, crawlers, scanners, mail servers (ports 25, 465 and 587 are blocked for outgoing traffic), streaming services, any high-traffic public service.
7.4. Game Servers (Pterodactyl / WISP.gg). (a) The container may be used exclusively for the contracted game server and for tools directly related to it (web maps, statistics panels, Discord bots for the server); (b) mining, proxies, IRC servers, web applications unrelated to the game and automation scripts for third-party services are prohibited; (c) the Client complies with the licensing conditions of the game (Minecraft EULA, Steam terms, FiveM licence, publishers' policies) and does not host pirated or illegally modified versions; (d) monetisation is permitted in compliance with the law, including the prohibition of paid loot boxes where the law qualifies them as gambling; (e) servers attracting persistent DDoS attacks affecting the node may be temporarily suspended; (f) using the game server for communications or content under Section 3 is prohibited.
7.5. Dedicated Servers (OVHcloud resale). In addition to this AUP, the OVHcloud acceptable use policy and abuse policy apply in full. IRC (per Section 8) and, with prior written approval, legal adult content and distribution of the Client's own content via torrents are permitted. Mining, Tor exit, public VPN/proxy, booters and everything under Sections 3 and 4 remain prohibited. E-mail: no preset limit, subject to Section 5 and the OVHcloud policy.
7.6. Domain names. Domain names may not be registered or used for purposes under Section 3, for typosquatting, cybersquatting, phishing, malware distribution or infringement of third-party trademarks. The Domain Registration Agreement applies.
8. IRC RULES
8.1. Running IRC servers (ircd), bouncers (BNC/ZNC), bots or IRC clients is permitted exclusively on VPS and Dedicated Servers, under the following conditions:
- (a) it is prohibited on Shared Hosting, Reseller, Managed WordPress, WaaS, NAT VPS and Game Servers;
- (b) the operated IRC network may not exceed [100] simultaneously connected users without the Provider's prior written approval;
- (c) IRC bots may not be used for flooding, spam, scanning, data harvesting, attacks or channel takeovers; IRC botnets and any bot controlling third-party systems are prohibited;
- (d) the IRC server must have an identifiable contact operator and must comply with the rules of the network it connects to (if applicable);
- (e) the Client understands that IRC servers are frequent DDoS targets; where an attack affects the node, the infrastructure or other Clients, the Provider may temporarily stop the Service (null-route) without notice and without liability, or may require migration to a Service with superior DDoS protection or cessation of the IRC activity;
- (f) repeated attacks attracted by an IRC server may lead to withdrawal of permission to run IRC on the Service concerned.
9. IP ADDRESSES AND NETWORK REPUTATION
9.1. Allocated IP addresses remain the property of the Provider or the Upstream Provider and may be changed with reasonable prior notice for technical, commercial or security reasons. IP addresses may not be announced via BGP, transferred or used outside the Service for which they were allocated.
9.2. The Client undertakes not to cause, through their own conduct or that of their users, the listing of the Provider's IP addresses on blacklists (RBL, DNSBL, Spamhaus, UCEPROTECT, Google Safe Browsing, anti-phishing lists) or the degradation of the reputation of address blocks.
9.3. Additional IP addresses are allocated subject to availability, against payment, on the basis of a technical justification (for example SSL certificates with dedicated IP, name servers, distinct applications). IP addresses are not allocated for: circumventing blocks, rotation for scraping, bulk e-mail sending, proxy services.
9.4. Reverse DNS (PTR) is configured on request for VPS and Dedicated Servers, only to domain names owned or managed by the Client.
10. APPLICATION AND ACCOUNT SECURITY
10.1. The Client is responsible for updating and securing the applications, themes, plugins, scripts, libraries and operating systems they install or use, for using strong and unique passwords, for enabling two-factor authentication where available and for monitoring their own content.
10.2. The Provider may: (a) block or disable files, plugins, themes or software versions with known and actively exploited vulnerabilities; (b) suspend compromised accounts generating spam, phishing, malware or attacks, until full remediation by the Client (clean-up, updates, password changes); (c) require the Client to provide evidence of remediation before reactivation.
10.3. The Client shall not share access credentials with unauthorised persons and shall notify the Provider immediately upon becoming aware of any unauthorised access or security incident.
10.4. Installing software that collects data from website users without informing them and, where required, obtaining their consent (keyloggers, hidden trackers, unlawful fingerprinting) is prohibited.
11. RESELLER RULES
11.1. Clients reselling the Services or their resources to third parties (including through WHMreseller, WHM accounts, virtual machines or containers created on VPS or Dedicated Servers) undertake to: (a) impose on their own customers usage conditions at least as restrictive as this AUP; (b) verify the identity and good faith of their own customers; (c) respond to the Provider's abuse requests within 24 hours at most and apply the requested measures (suspension, content removal); (d) provide their own customers with their contact details and their own privacy policy; (e) not create sub-accounts with limits more permissive than those in this AUP without approval.
11.2. The reseller remains fully liable to the Provider for violations committed by their customers, whether or not they know their real identity, and remains the Provider's sole point of contact; the Provider has no contractual relationship with the reseller's customers. Repeated or unmanaged violations may lead to suspension or termination of the entire reseller account.
12. MONITORING AND INVESTIGATION
12.1. The Provider does not proactively monitor Client Content and has no general monitoring obligation. The Provider does, however, automatically monitor the technical parameters of the infrastructure (resource consumption, traffic, connections, e-mail patterns, malware signatures through Imunify360 and WAF) for security and stability.
12.2. The Provider may investigate any reasonable suspicion of an AUP violation, upon notice from a third party, an authority, an Upstream Provider or on the basis of its own systems, and may, for this purpose, access Client Content strictly to the extent necessary, in compliance with confidentiality and data protection law.
12.3. The Provider may retain, during the investigation and thereafter, the data necessary as evidence, and may provide the competent authorities, as required by law, with the requested data (logs, identification data, content).
13. REPORTING ABUSE
13.1. Anyone may report abuse to abuse@crocky.host, which is also the single point of contact within the meaning of Regulation (EU) 2022/2065 (DSA). Accepted languages: Romanian and English.
13.2. A useful report contains: (a) a description of the abuse and the reasons why the content or activity is considered illegal or contrary to the AUP; (b) the exact URL, IP address, date and time (with time zone), full e-mail headers or relevant logs; (c) the notifier's contact details; (d) a good faith statement regarding the accuracy of the information. Copyright reports shall identify the protected work and the rights holder.
13.3. The Provider acknowledges receipt of the report, reviews it diligently and objectively, takes appropriate measures depending on severity (usually within 2 business days, and immediately for serious cases) and informs the notifier and the Client of the decision and the means of redress, in accordance with Section 17 of the Terms.
13.4. Abusive, manifestly unfounded or repetitive reports may be ignored, and bad faith notifiers may be blocked.
14. CONSEQUENCES OF VIOLATION
14.1. Depending on the severity, repetition and impact of the violation, the Provider may, at its sole discretion and without being required to go through every step: (a) send a warning with a remediation deadline (usually 24 to 72 hours); (b) remove, block or quarantine the content concerned; (c) limit the resources or functionality of the Service (for example disabling e-mail); (d) temporarily suspend the Service or the Account; (e) terminate the Service or the Account without notice and without refund; (f) refuse future Orders and block the creation of new Accounts by the same person; (g) notify the competent authorities; (h) retain data as evidence; (i) recover from the Client the damages and costs caused, in accordance with the Terms.
14.2. Serious violations, leading to immediate termination without notice and without refund: art. 3.1(a), (c), (d), (e), (h); art. 4.1(a), (b), (c), (d), (e), (g); proven mass spam or phishing; any violation causing suspension of the Service by an Upstream Provider; any violation committed after a previous warning for the same conduct.
14.3. Suspension or termination for AUP violation does not entitle the Client to any refund, credit or compensation, and issued Invoices remain due. Data of Services terminated for AUP violation may be deleted immediately or retained as evidence, at the Provider's discretion.
14.4. Suspension of a Service by an Upstream Provider following an abuse report is binding on the Provider, who will forward to the Client the notice and the remediation deadline imposed by the Upstream Provider and is not liable for the consequences if the report is founded.
15. ABUSE-RELATED FEES
15.1. The Provider may charge the Client the following fees, which represent actual handling costs and are not penalties:
| Situation | Fee |
|---|---|
| Investigation of a confirmed abuse attributable to the Client | [50] EUR/hour, minimum 1 hour |
| Delisting and investigation of an IP address listed through the Client's fault | [25] EUR per incident |
| Clean-up of a compromised account, at the Client's request | [50] EUR/hour |
| Reactivation of a Service suspended for AUP violation (if the Provider accepts reactivation) | [15] EUR |
| Costs, fines or penalties imposed on the Provider by Upstream Providers, registries or authorities due to the Client's conduct | full amount, plus [10]% administrative costs |
15.2. Fees are invoiced separately and are due 7 days after issue. For Consumers, fees apply only to the extent they correspond to actual, proven costs caused with fault.
16. CHANGES TO THIS POLICY
16.1. The Provider may update this AUP with notice to the Client by e-mail and display in the Account at least 30 days before it takes effect, in accordance with Section 23 of the Terms. Changes required by law, by Upstream Providers or necessary for the security of the infrastructure may take effect immediately.
16.2. The current version is permanently published at https://crocky.host/legal/acceptable-use-policy. Continued use of the Services after the changes take effect constitutes acceptance thereof.
16.3. Questions regarding the interpretation of the AUP may be sent to contact@crocky.host. The Provider recommends requesting prior clarification for any use that is not obviously covered by the purpose of the Service.
