lbreeze

Acceptable Use Policy

Acceptable Use Policy

Last updated: 16 September 2026

This policy sets the boundaries on what may be done with LBREEZE LIMITED services. It applies to you, to everyone you give access to, and to your own customers where you resell or host on their behalf. It forms part of our Terms of Service, and breaking it is a breach of that agreement.

The policy exists for a practical reason. Our network is shared. Abuse from one customer gets our address ranges blocklisted, degrades performance for everyone, and exposes us to liability we cannot pass on. We would rather write the rules down than improvise them during an incident.

1. Unlawful and harmful content

You must not use our services to store, transmit, publish or link to material that is unlawful in the United Kingdom or in any territory you target. That includes child sexual abuse material, terrorist content, material that incites violence or hatred, threats and harassment, unlawful extreme pornography, content that infringes copyright, trade marks or other intellectual property, defamatory material, and content that breaches a court order.

Child sexual abuse material and terrorist content are treated differently from everything else in this policy. We remove them immediately on discovery or report, without notice and without an opportunity to remedy, we preserve evidence, and we report them to the appropriate authority, including the Internet Watch Foundation or the police. We do not accept explanations first.

2. Security and network abuse

You must not use our services to attack anyone, including us. Specifically, you must not: launch or participate in denial of service or distributed denial of service attacks; operate a botnet, command and control server, or malware distribution point; scan, probe or penetration-test systems you do not own or have written permission to test; attempt to gain unauthorised access to any account, host or network; intercept traffic that is not yours; forge packet headers or spoof addresses; or run software whose purpose is to compromise other systems.

Security research is welcome on systems you own. Testing against a third party without written authorisation is not research, and testing against our infrastructure requires our written permission in advance from security@lbreeze.com.

3. Email, messaging and reputation

You must not send unsolicited bulk email from our network, or use our network to support a mailing sent from elsewhere. Marketing email must comply with PECR and, where relevant, the UK GDPR: consent or a valid soft opt-in, a working unsubscribe link, an identifiable sender, and a suppression list that is actually honoured.

You must not send mail with forged headers or misleading subject lines, harvest addresses, buy lists from brokers, or operate an open relay or open proxy. Where you send at volume you must maintain SPF, DKIM and DMARC records, monitor bounce and complaint rates, and stop sending to an address that has bounced hard or complained.

A high complaint rate, a listing on a major blocklist, or a pattern of hard bounces is grounds for us to rate-limit or block outbound mail from your service, with notice where the situation allows it.

4. Resource use

Your plan states the resources you have bought. You must not attempt to evade those limits, and you must not run workloads that destabilise the host or degrade service for other customers on shared infrastructure.

Cryptocurrency mining, proof-of-work computation and distributed computing projects are not permitted on shared or unmetered plans, because their economics only work by consuming resources someone else has paid for. They are permitted on dedicated resources where the plan expressly allows it and you have told us in advance.

Where a workload is causing measurable harm to other customers, we may throttle it. We will tell you what we have done and why, and we will work with you on a plan or a configuration that fits.

5. Fraud, impersonation and abuse of the platform

You must not use our services for phishing, for fraudulent offers or storefronts, for impersonating another person or organisation, for hosting fake login pages, for distributing stolen credentials or card data, or for money laundering. You must not misrepresent yourself when signing up, use stolen payment details, or open multiple accounts to evade suspension, abuse trials, or defeat resource limits.

6. Prohibited and restricted categories

Some activities are lawful but carry obligations we cannot discharge on your behalf. You must tell us in advance and get written agreement before using our services for: gambling and gaming for money; adult content of any kind; financial services requiring authorisation; the sale of pharmaceuticals, firearms, alcohol, tobacco or age-restricted goods; and anonymising services including Tor exit nodes, open VPN gateways offered to the public, and public proxies.

We are not refusing these outright. We are saying that they require a conversation about jurisdiction, age verification, licensing and abuse handling before the service goes live, rather than after a complaint arrives.

7. Your own customers

If you resell our services or host workloads for others, you must impose terms on them at least as strict as this policy, be able to identify who is responsible for any given workload, and act on abuse reports we forward to you. We will normally send a report to you first and give you a defined window to act. If you do not act within that window, or if the harm is ongoing, we will act directly against the affected service.

8. Reporting abuse

Report anything you believe breaches this policy to abuse@lbreeze.com. Include the domain, IP address or URL, the time and time zone, and any logs or headers you have; a report without those is hard to act on.

We acknowledge reports within one working day. We investigate and, where the report is substantiated, we require the customer to remove the content or stop the activity within the time the situation allows. For material that is unlawful on its face, or where an attack is in progress, we act immediately. We do not disclose customer identities to a reporter, but we will pass a report to the customer so they can respond directly, unless doing so would prejudice an investigation.

9. What we do when this policy is broken

Our response is proportionate to the harm and to whether it is continuing. In escalating order we may: ask you to fix it within a stated time; apply a rate limit, a filter or a null route; suspend the affected service; suspend the account; terminate the service; and report the matter to the police or another authority.

Where the risk is not immediate, you get notice and an opportunity to put it right before suspension. Where it is immediate, including an active attack, an ongoing compromise, or unlawful content of the kind in section 1, we act first and tell you promptly afterwards, keeping the action as narrow as the situation allows.

Suspension for breach does not entitle you to a refund or a service credit, and you remain liable for the fees for the suspended service. Where we incur costs because of your breach, including blocklist delisting, upstream penalties or the cost of handling a large volume of complaints, we may charge them to you.

You may appeal any action by writing to legal@lbreeze.com. An appeal is reviewed by someone who was not involved in the original decision, and we aim to respond within five working days. We will reinstate a service where an appeal succeeds.

10. Cooperation with authorities

We comply with lawful requests from UK law enforcement, courts, regulators, and registries or certificate authorities acting within their published policies. We check that a request is valid and proportionate before acting on it, we disclose only what the request requires, and we tell the affected customer unless the law or the request forbids it.

11. Changes to this policy

We may update this policy as threats, services and the law change. The current version is always at lbreeze.com/legal/acceptable-use with the date it was last updated. Where a change materially restricts what you may do, we will give at least 30 days' notice by email, and you may terminate the affected service before the change takes effect if you do not accept it.