Acceptable Use Policy
Version 1.0 · Effective 8 August 2026 · AS209990
This is a permanent, unchanging copy of version 1.0. Save or print it and it will still match this page later. See the current version
This policy sets out what may and may not be done with the services we provide, how we handle reports of illegal or abusive use, and what we may do when the policy is broken. It applies to every customer, to everyone they let use a service, and to everything stored, transmitted or delivered through one. Abuse reports go to abuse@karmuz.net; policy questions and appeals go to legal@karmuz.net.
1. About this policy
This Acceptable Use Policy ("AUP") is part of our Terms of Service. Together they are our terms and conditions for the purposes of Article 14 of the Digital Services Act.
Depending on the service concerned, we act in one or more of the capacities recognised by Articles 4 to 6 of the Digital Services Act:
- as a mere conduit, when we carry traffic over AS209990 as transit or peering;
- as a caching provider, when we cache and deliver content through our anycast network;
- as a hosting provider, when we store data on behalf of a customer, including object storage, DNS zone data and edge configuration.
We do not select, originate or modify customer Content. Our liability position under the Digital Services Act depends on the capacity in which we act, and nothing in this policy waives or extends it. We nevertheless operate a single reporting and enforcement process across all services, described in sections 10 to 12.
2. Scope
2.1 Services covered
- IP transit, peering and connectivity over AS209990;
- anycast content delivery and edge caching;
- Karmuz Edge - encrypted tunnels and edge proxying;
- authoritative DNS;
- object storage.
2.2 Who is bound
- Customers - anyone who contracts with us for a service.
- Users - anyone a Customer permits to use a service, including staff, contractors, sub-users, resellers' customers and end users.
- Content - anything stored, hosted, transmitted, cached or delivered through a service, whoever provided it.
A Customer accepts this AUP when it orders or uses a service, and is responsible to us for compliance by every User under its account.
2.3 Peering
Peers are not Customers. Interconnection with AS209990 is governed by our peering policy. The network-integrity requirements in section 7 apply to any party exchanging routes with us, as a condition of interconnection that is accepted by establishing or maintaining a session.
3. Customer identification and verification
We do not provide services anonymously. A Customer must:
- give accurate and complete legal identity, billing, technical and abuse contact details, and keep them current;
- respond to a verification request within a reasonable period. Depending on the service we may ask to see an identity document - from which you may redact your photograph and citizen service number - or a company registration extract, proof that you control a domain, IP range or ASN, and, for services with an elevated abuse profile, details of the natural persons who ultimately own or control the Customer;
- name a contact who can act on abuse reports, and monitor that address.
We may refuse, suspend or terminate a service where identity information is false, incomplete, or cannot be verified, or where a Customer will not disclose who is actually using the service. These checks follow the Dutch hosting sector's code of conduct on abuse (Gedragscode Abusebestrijding), and exist so that abuse can be traced to a responsible party rather than left with the network.
4. Acceptable use
Services may be used for any lawful purpose consistent with this AUP, the Terms of Service, the specification of the plan purchased, and any published fair-use or resource limits.
Customers must:
- secure their own systems, software and credentials, and apply security updates;
- use only IP address space, ASNs and domain names they are authorised to use, and provide a valid Letter of Authorisation where we announce space on their behalf;
- keep RPKI ROAs and IRR objects accurate for any prefix routed through us;
- act on abuse reports we forward - acknowledging within 24 hours and resolving or escalating them within 72 hours, unless a shorter statutory deadline applies;
- cooperate with us on security incidents affecting the services or the network.
5. Prohibited use
The following are prohibited on every service.
5.1 Child sexual abuse material
Any material depicting or facilitating the sexual abuse or exploitation of minors is prohibited absolutely. Confirmed cases result in immediate removal, immediate termination of the account, and a report to the Dutch hotline operated by EOKM (Expertisebureau Online Kindermisbruik) and to the competent authorities. Where a competent authority issues a preservation order, we preserve the account and traffic records it specifies; we do not retain the material itself except as such an order requires.
We act on orders from the Dutch Authority for Online Terrorist and Child Pornographic Material (ATKM) under the Wet bestuursrechtelijke aanpak online kinderpornografisch materiaal (the Dutch act on administrative enforcement against online child sexual abuse material), and on reports from EOKM, without waiting for a further legal determination.
5.2 Terrorist content
Content that incites, solicits, glorifies or provides instruction for terrorist offences, or that solicits participation in a terrorist group, is prohibited. Under Regulation (EU) 2021/784 and its Dutch implementing act, a removal order from the ATKM must be executed within one hour of receipt. We keep a monitored abuse contact and treat such orders as our highest operational priority at any hour. Customers must be reachable so that we can act at the source where possible.
Where we execute a removal order, we preserve the Content removed and the related data for six months under Article 6 of Regulation (EU) 2021/784, and longer where a competent authority or court so orders.
5.3 Other illegal content and activity
- Content that infringes copyright, trade marks, database rights or other intellectual property, and the distribution of counterfeit goods.
- Incitement to violence or hatred, unlawful discrimination, threats, harassment, doxxing, stalking, and non-consensual intimate imagery.
- Defamatory material, and material that unlawfully violates another person's privacy.
- Sale or distribution of controlled substances, weapons, stolen data, stolen credentials or other goods whose sale is unlawful.
5.4 Fraud and financial crime
- Phishing, brand impersonation, spoofed login pages, and any scheme designed to obtain credentials, payment details or personal data by deception.
- Carding, payment fraud, triangulation fraud, money laundering, and the facilitation of any of these.
- Fake webshops, advance-fee fraud, investment and cryptocurrency scams, Ponzi and pyramid schemes.
- Providing regulated financial services, or selling pharmaceuticals, without the licence the law requires.
- Any activity whose purpose is to obscure the identity of a party engaged in the above, including so-called bulletproof hosting.
5.5 Security and network abuse
- Distribution of malware, ransomware, stalkerware or exploit kits, and operation of botnet command-and-control infrastructure.
- Unauthorised access to, or interference with, any system, network or account.
- Originating, coordinating, or assisting denial-of-service attacks, including operating deliberate amplification or reflection infrastructure and selling or advertising "stresser" or "booter" services.
- Source-address spoofing, BGP hijacking, route leaks, or announcing prefixes without documented authorisation.
- Operating open resolvers, open relays, open proxies or misconfigured services exploitable for amplification or laundering of attack traffic.
- Scanning, probing or testing systems the Customer does not own or hold documented written authorisation to test.
5.6 Messaging abuse
- Unsolicited bulk email or messaging, and any sending that does not meet applicable consent, identification and opt-out requirements.
- Phishing by message, and spoofing of sender identities or originating addresses.
- Sending to recipients who have withdrawn consent, or to addresses obtained without a lawful basis.
5.7 Resource abuse
- Activity that materially degrades a service or the network for others.
- Circumvention of plan limits, quotas, trial restrictions or billing controls.
- Cryptocurrency mining, except where approved in writing under section 6.
5.8 Categories we do not carry at all
We do not host, cache or deliver the following, and we do not grant exceptions for them:
- adult, sexual or pornographic content and services, including live webcam and adult chat services;
- gambling, betting and lotteries, whether or not licensed, and services that support them;
- anonymisation services sold or offered to the public, including commercial VPN exit services, open proxy services and cryptocurrency mixers.
We do not carry these even where the operator can identify and act against an abusing user. Tor exit nodes are not covered by the third bullet and are dealt with under section 6.
6. Restricted activities
The following require our prior written approval and may carry additional conditions, verification requirements or pricing. Undeclared use is treated as a breach.
- Tor exit nodes, and VPN infrastructure operated for a Customer's own organisation rather than sold to the public. Tor relays that are not exits need no approval.
- Bulk or transactional email at scale, mailing-list operation, and email service provider businesses.
- Security research, vulnerability scanning and penetration testing. We approve these only where you show us written authorisation from the owner of the target. Testing of our own infrastructure under our published coordinated vulnerability disclosure policy needs no separate approval.
- Reselling, sub-allocating or sub-leasing IP address space, and reselling our services under the Customer's own brand.
- Cryptocurrency mining and comparable high-density compute workloads.
- Services with an elevated abuse profile, including public IRC networks, file-sharing and paste sites, URL shorteners, and free-tier hosting, email or subdomain offerings.
6.1 What our services are not for
Our services are not designed or warranted for safety-critical or life-critical use, and must not be relied on where failure could cause death, personal injury, or severe environmental or property damage.
7. Network integrity
AS209990 is a MANRS participant and follows the MANRS Actions - filtering, anti-spoofing, coordination, and publishing validated routing data - on every session. Customers and peers exchanging routes with us must:
- announce only prefixes they are authorised to originate, covered by valid RPKI ROAs and current IRR objects;
- apply anti-spoofing controls at the network edge, consistent with BCP 38 and BCP 84;
- maintain a working, monitored NOC and abuse contact, and a current PeeringDB record where applicable;
- keep announcements within any agreed max-prefix limit.
We filter on import and on export, drop RPKI-invalid announcements, and reject bogons, martians and unallocated space. We may filter, dampen or withdraw a specific announcement, or suspend a session, where routing behaviour threatens the integrity of the network or of third parties. Where the risk is immediate - an active hijack or leak - we act first and explain afterwards.
8. Legal compliance and sanctions
8.1 General
Customers must comply with all laws applicable to their use of the services, including Dutch and EU law and the law of any jurisdiction in which they or their Users are established or operate. This includes, as relevant:
- Regulation (EU) 2022/2065 (Digital Services Act);
- Regulation (EU) 2021/784 on terrorist content online, and the Dutch implementing act;
- the Wet bestuursrechtelijke aanpak online kinderpornografisch materiaal (the Dutch act on administrative enforcement against online child sexual abuse material);
- Regulation (EU) 2016/679 (GDPR) and the ePrivacy rules;
- the rules on electronic marketing and sender identification in the Telecommunicatiewet;
- consumer protection, e-commerce and distance-selling rules.
The Digital Services Act, Regulation (EU) 2021/784, the Wet bestuursrechtelijke aanpak online kinderpornografisch materiaal apply to us directly, and this policy is written so that we can meet them. Where the Cyberbeveiligingswet (the Dutch cybersecurity act implementing NIS2) applies to us, we meet its requirements too.
8.2 Sanctions
We do not provide services to, and no service may be used to provide anything of value to, any person, entity, vessel or body that is:
- designated under EU restrictive measures, UN sanctions, Dutch national sanctions lists, or any other sanctions regime binding on us; or
- established in, ordinarily resident in, or acting on behalf of a comprehensively sanctioned or embargoed territory.
Specific EU measures also restrict the provision of certain IT and computing services to the Russian and Belarusian governments and to entities established in Russia or Belarus, including access to hosted AI models and high-performance computing capacity. Customers must not use our services to provide, resell or make available anything falling within those restrictions.
Customers represent that neither they, nor their owners or beneficial owners, nor their Users, are sanctioned parties, and must notify us immediately if that changes. We screen against the EU consolidated list before a service is activated and again when circumstances change, and we may suspend services and make any legally required report where a sanctions risk is identified. Deliberate circumvention of sanctions or export controls is a material breach.
9. Resellers, sub-users and third parties
Where a Customer allows third parties to use a service - as sub-users, tenants, resellers' customers, or end users of the Customer's own product:
- the Customer remains fully responsible to us for all activity on its account and for all Content it stores, transmits or delivers, whether or not it created that Content;
- the Customer must bind those third parties to terms at least as strict as this AUP, and must be able to enforce them;
- resellers must operate their own acceptable use policy and abuse-handling process, maintain accurate records identifying their customers, and be able to act against an abusing customer promptly;
- the same 24 and 72 hour deadlines set out in section 4 apply to reports about the Customer's own Users, and the Customer must publish and monitor an abuse contact for them;
- the Customer is the controller for personal data it processes about its own Users and must have a lawful basis for that processing.
We have no contractual relationship with sub-users. We may nonetheless act directly against Content or resources associated with a User where the Customer does not act in time, or where the risk requires immediate intervention.
10. Reporting illegal content and abuse
Anyone may report suspected illegal content or abusive use to abuse@karmuz.net. This is our notice-and-action mechanism for the purposes of Article 16 of the Digital Services Act, and our point of contact for recipients of the service under Article 12.
A useful notice contains:
- an explanation of why the content or activity is believed to be illegal or in breach of this policy;
- the exact location - URL, IP address, hostname or port, with timestamps and time zone;
- the notifier's name and email address. Reports involving child sexual abuse, sexual exploitation of children or solicitation of a child - the offences in Articles 3 to 7 of Directive 2011/93/EU - may be sent anonymously;
- any supporting evidence, such as logs or message headers;
- a statement that the report is made in good faith and is accurate to the best of the notifier's knowledge.
How we handle notices
We acknowledge receipt where contact details are provided. We assess the report in a timely, diligent, objective and non-arbitrary way, and tell the notifier what we decided and how to challenge it. We handle notices in line with the Dutch Gedragscode Notice-and-Take-Down. If someone else is closer to the Content than we are - the Customer, or their reseller - we pass the report to them, and escalate if they do not act.
Priority handling
Orders and notices from the ATKM, law enforcement, the Public Prosecution Service, and other competent authorities are handled with priority and within the statutory deadline - one hour for terrorist content removal orders. Reports concerning child sexual abuse material and active attacks are escalated immediately at any hour. We do not run a staffed 24/7 support desk, but statutory removal orders and reports of this kind reach us out of hours and are acted on at any time.
Orders from authorities
We act on orders issued under Articles 9 and 10 of the Digital Services Act and on other lawful orders, inform the issuing authority of the effect given to them, and notify the affected Customer unless the order or the law prohibits it.
Criminal offences
Where we become aware of information giving rise to a suspicion of a criminal offence involving a threat to the life or safety of a person, we inform the competent authorities without delay, as required by Article 18 of the Digital Services Act.
Abusive notices
We may disregard notices from a source that repeatedly submits manifestly unfounded reports.
11. Monitoring and enforcement
11.1 Monitoring
We are under no general obligation to monitor Content or to seek out illegal activity, and we do not review Content proactively. We do operate automated systems for the security, stability and integrity of the network - including flow analysis, intrusion and abuse detection, route validation and capacity monitoring - and we act on reports from third parties, peers and authorities. Carrying out voluntary investigations of this kind does not deprive us of the liability exemptions in Articles 4 to 6 of the Digital Services Act.
We may inspect logs, traffic metadata and account records where necessary to investigate a suspected breach, secure the services, or comply with a legal obligation. We do not inspect the content of customer traffic except where technically necessary for one of those purposes or where required by law.
11.2 Investigation
We may require a Customer to provide information about activity on its account, including the identity of the User responsible for reported abuse, within a stated and reasonable period.
11.3 Measures
Where this policy is breached, or where we are legally required to act, we may take one or more of the following, proportionate to the severity, recurrence and impact of the breach:
- a warning with a remediation deadline;
- rate-limiting, filtering, null-routing or blocking of specific traffic, addresses or ports, on the grounds Regulation (EU) 2015/2120 permits;
- removal of, or disabling of access to, specific Content, including cache purging;
- suspension of an individual service, instance or resource;
- suspension of the account in whole;
- withdrawal or filtering of prefixes, or shutdown of a BGP session;
- termination of the agreement with immediate effect;
- reporting to the competent authorities, and preservation or disclosure of data where legally required or permitted.
We take the narrowest measure that fixes the problem. If suspending one service, withdrawing one prefix or removing one item of Content will do it, we do not touch the rest of the account.
11.4 Notice and immediacy
We ordinarily give notice and a reasonable opportunity to remediate before suspending a service. We may act immediately and without prior notice where there is a risk of serious harm - including child sexual abuse material, terrorist content, active attack traffic, phishing or malware distribution, or a threat to the security or stability of the network. We may also act immediately and without prior notice where a court or competent authority orders us to. In either case we notify the Customer as soon as practicable afterwards.
11.5 Statement of reasons
Where we restrict Content or a service on the ground that it is illegal or incompatible with this policy, we give a clear and specific statement of reasons, in line with Article 17 of the Digital Services Act. It sets out the measure taken and its territorial and temporal scope, the facts relied on, whether the decision followed a notice or our own investigation, whether automated means were used, the legal or contractual ground, and how the decision can be contested.
We give it to the affected Customer and, where the Content was provided by a User rather than by the Customer, to that User where we are able to reach them - directly or through the Customer, who must pass it on. Where we hold electronic contact details, we provide it at the latest on the date the restriction is imposed, as Article 17 requires, including where we acted immediately under section 11.4. Where Content is removed under a removal order for terrorist content, we make the information required by Article 11 of Regulation (EU) 2021/784 available to the content provider.
11.6 Consequences
Suspension or termination for a serious breach does not entitle the Customer to a refund of prepaid fees; where the breach is not serious we refund the unused part pro rata. The Customer remains liable for fees due and for costs we reasonably and demonstrably incur as a direct result of the breach, including abuse handling, remediation and third-party claims, and for any penalty imposed on us that is attributable to the breach rather than to our own acts or omissions.
12. Complaints and appeals
If you think we got a decision wrong, tell us and we will look at it again.
Write to legal@karmuz.net within 30 days. Give the reference or date of the statement of reasons, and say why you think the decision was wrong.
We look at the complaint afresh on the evidence. A person decides it, not an automated system. We aim to respond within 14 days and in any event without undue delay, and we restore the service or Content promptly where the objection succeeds.
None of this affects your right to go to court, or to complain to the Netherlands Authority for Consumers and Markets, which is the Dutch Digital Services Coordinator.
13. Security incidents
Customers must report to us without undue delay any security incident on their account that affects, or is likely to affect, our services, the network, or other customers - including compromise of a server, credentials or a routing session - and must cooperate with containment. We may act unilaterally to contain an incident where a Customer is unreachable or does not act. Where an incident triggers a statutory reporting duty on us, including under the Cyberbeveiligingswet, Customers must provide the information we need to meet it within the applicable deadline.
14. Data protection
Personal data we process as controller is handled as described in our privacy policy. Where we process personal data on a Customer's behalf, we do so as processor under the data processing terms we agree before processing begins - a copy of which is available on request from legal@karmuz.net. A Customer that hosts or transmits personal data of its own Users is the controller for that data and is responsible for the lawful basis, information duties and data subject rights attaching to it.
15. Changes
We may amend this policy where a change in law, a binding decision, the way a service is provided, or the abuse landscape requires it, or to correct an error. Material changes take effect 30 days after publication and notification to Customers, except where an earlier change is required by law or to address an immediate security or legal risk. If a change is to a Customer's disadvantage, they may terminate the affected service free of charge before it takes effect, and we say so in the notice. Every version has a permanent address of its own - karmuz.net/acceptable-use/v1.0 - and superseded versions stay published there.
16. Contact and governing law
- Abuse and illegal content: abuse@karmuz.net
- Recipients of the service (Digital Services Act Article 12): abuse@karmuz.net
- Member State authorities, the Commission and the Board (Digital Services Act Article 11): legal@karmuz.net
- Policy, legal and appeals: legal@karmuz.net
- Security incidents: security@karmuz.net
Write to us in English or Dutch, by email, at the addresses above - whether you are a customer, someone affected by content we carry, or an authority.
Karmuz Network is a trade name of Karmuz, a sole proprietorship 'eenmanszaak' registered in the Business Register of the Netherlands Chamber of Commerce under KVK number 83633588, VAT number NL003849619B59, established in the Netherlands. Our correspondence address is available on request from legal@karmuz.net.
This policy is governed by Dutch law. Disputes go to the exclusive jurisdiction of the competent court in Rotterdam, the Netherlands.