This policy sets out what you may and may not do with services supplied by Apaxon Limited trading as ApaxonHost. It applies to every service on your account and to anyone you give access to. It forms part of the Terms of Service.
The short version: don't break the law, don't send spam, don't attack anyone, and don't leave software unpatched until it becomes someone else's problem.
1. Prohibited content and activity
You must not use our services to host, transmit, link to or facilitate:
- material that is illegal under the law of England and Wales, or in the
jurisdiction where it is accessed;
- child sexual abuse material — reported to the [Internet Watch
Foundation](https://www.iwf.org.uk) and to law enforcement, with immediate termination and no refund;
- content that incites violence, terrorism, or hatred against a group;
- material that infringes copyright, trade marks or other intellectual
property rights;
- phishing pages, fraudulent shops, fake invoices, or any other content
designed to deceive people into handing over money or credentials;
- malware, ransomware, exploit kits, keyloggers, or command-and-control
infrastructure;
- open proxies, open mail relays, Tor exit nodes, or anonymised traffic
relays;
- cryptocurrency mining, or any workload whose purpose is to consume CPU
rather than serve a site;
- adult content of any kind on shared hosting plans (it is not
prohibited by law, but the traffic and abuse profile is unsuitable for a shared environment).
2. Email and anti-spam
Sending unsolicited bulk email from our network is prohibited without exception, and applies equally to mail sent from our servers and to mail sent elsewhere that advertises a site hosted with us.
If you send marketing email you must:
- hold recordable evidence of opt-in consent for every recipient, in
line with UK GDPR and PECR;
- include a working, one-click unsubscribe link and honour it within 48
hours;
- identify the sender accurately — no forged headers, no misleading
subject lines, no from-addresses on domains you do not control;
- keep bounce and complaint rates low, and stop sending to an address
after a hard bounce.
Shared hosting has an outbound limit of 500 messages per hour per account. If you need more than that, use a dedicated transactional provider — that is a better outcome for your deliverability as well as for the rest of the server.
3. Security obligations
You are responsible for keeping your applications secure. That means:
- applying security updates to WordPress, its themes and its plugins, and
to any other application you install — promptly, not eventually;
- removing software you no longer use, rather than leaving it dormant and
unpatched;
- using strong, unique passwords, and enabling two-factor authentication
where it is available;
- not storing unencrypted payment card data on our servers under any
circumstances.
Compromised accounts get suspended. We would much rather help you clean one up than take it offline, so tell us the moment you suspect a problem — we do not penalise anyone for reporting a compromise early.
4. Network abuse
You must not:
- run port scans, vulnerability scans or penetration tests against
systems you do not own, or against ours without prior written consent;
- take part in denial-of-service attacks, whether as source, amplifier or
coordinator;
- attempt to access another customer's account, files or processes;
- attempt to escape the account's isolation, escalate privileges, or
interfere with server monitoring or logging.
5. Resource use
Shared hosting is shared. Where a plan advertises "unlimited" storage or bandwidth, it means we apply no fixed numeric cap in normal use — not that one account may consume an entire server.
Specifically, do not use your hosting account as:
- a file-distribution, backup or archive service unrelated to a website
you run;
- a media-streaming origin;
- a batch-processing or rendering worker.
Where usage degrades service for other customers we will contact you first and work through optimisation or an upgrade. Throttling or suspension is a last resort, reserved for severe impact where you have not engaged with us.
6. Reporting abuse
Report anything you believe breaches this policy to abuse@apaxonhost.com. Please include the URL or IP address, the time and time zone, and the relevant headers or log lines — that detail is usually the difference between acting in an hour and acting in a day.
We acknowledge abuse reports within one working day and investigate promptly. Reports made in bad faith, or as a tactic in a commercial dispute, will be closed without action.
7. Enforcement
Depending on severity we may issue a warning and a deadline to fix, apply a rate limit, suspend the service, or terminate the account.
We will normally warn you first. We will not, where the activity presents an immediate legal or security risk — active phishing, malware distribution, an outbound attack, or CSAM. In those cases the service is suspended immediately and you are told straight afterwards.
Termination for breach does not entitle you to a refund, and does not release you from invoices already due.
8. Appeals
If you believe we acted incorrectly, reply to the suspension notice within 30 days. A member of staff who was not involved in the original decision will review it and respond within five working days.
9. Contact
Apaxon Limited (trading as ApaxonHost) Piccadilly Business Centre, Aldow Enterprise Park, Manchester, M12 6AE Registered in England & Wales, company number 09784429 VAT registration number GB383 9183 59
General enquiries: info@apaxonhost.com Support: support@apaxonhost.com Billing: billing@apaxonhost.com Abuse reports: abuse@apaxonhost.com Data protection: privacy@apaxonhost.com
