Skip to content

Acceptable Use Policy

What you may not run on a ServerQ server, what happens when someone does, and how to report abuse coming from our network.

Last updated:

The principle

You have full root access and we do not inspect what you run. The limit is not our taste: it is whether what you run breaks the law, damages someone else, or threatens the network other customers share. Those three tests are what everything below is an instance of.

Not permitted

  • Sending unsolicited bulk e-mail, running a mailing operation on a list you did not collect yourself with consent, or operating an open relay.
  • Phishing, credential harvesting, or hosting a page that impersonates another organisation, bank or public authority.
  • Distributing malware, ransomware, exploit kits, or command-and-control infrastructure for a botnet.
  • Originating denial-of-service traffic, port scanning or brute-force attempts against hosts you do not own, or running an amplification-capable service left open to the internet.
  • Hosting content that infringes copyright or trade marks you do not hold rights to.
  • Content that is a criminal offence under Turkish law, including child sexual abuse material, incitement to violence, and the offences enumerated in Law 5651.
  • Deliberately concealing who you are in order to do any of the above — false registration details, or reselling to a party you know intends to.

Resource use

The vCPU, memory and disk on your plan are yours to saturate; that is what they are for, and we will not suspend a server for being busy. What is not acceptable is a workload that degrades the host for its neighbours — sustained disk I/O that starves other tenants, or a process that leaks until the host swaps. If that happens we will contact you before we act, unless the host is already failing.

Each VPS plan carries the monthly transfer allowance listed against it on the pricing page. Exceeding it is a conversation about the right plan, not a penalty.

What is yours to secure

A server with root access is an operating system you administer. Patching it, choosing its passwords or keys, configuring its firewall and keeping its applications current are yours. Most abuse reports we receive are not about a customer doing something wrong — they are about a customer whose unpatched application was taken over by someone else. The result on the network is identical, so the response has to be too.

What we do about a breach

The ordinary sequence is: we contact you with what we have received, you have a reasonable window to fix it, and the service continues. We escalate to suspension only where the harm is active and continuing — an attack in progress, a phishing page taking credentials right now, content that must be removed under a legal order. In those cases suspension can come first and the notice follows immediately, because the alternative is letting the harm run while we wait for a reply.

We do not suspend a service because someone complained about its content in the abstract, and we do not act on an informal request from anyone, including a public authority, that is not made in the form the law requires.

Reporting abuse

If traffic from one of our addresses is causing you a problem, write to [email protected] with the IP address, the timestamps with their timezone, and enough log lines to identify what happened. A report with those three things gets acted on the same day. You do not need to be a customer, and you will get a reply from a person.

For a formal notice under Law 5651 or a court order, use the registered office address or the KEP address in the Distance Sales Agreement, which are the channels that constitute valid service.