Acceptable Use Policy
Contents
18 sections, 23 numbered clauses
Contents
Last updated 24 September 2026
Version 2, effective September 23, 2026
This version takes effect thirty (30) days after we notify customers by email. That notice has not been sent yet; until this version takes effect, the previous version applies.
About this Policy
This Acceptable Use Policy ("AUP") governs your use of the KapsuleHost Services and forms part of our Terms of Service. By using the Services you agree to this AUP. Capitalised terms used but not defined here have the meanings given in the Terms of Service.
The AUP exists to keep the platform safe, reliable, and lawful for everyone. We enforce it firmly. Where we identify a serious breach, we may suspend or terminate Services with little or no notice. Where the breach is less serious, we will typically contact you first and ask you to remedy the issue.
If you become aware of a breach of this AUP by another customer or by any person using our Services, please report it to abuse@kapsulehost.com. We treat all reports seriously and confidentially.
1. Prohibited content
You must not use the Services to host, store, transmit, distribute, link to, advertise, or facilitate access to any content that:
a. Child safety. Exploits, abuses, endangers, or sexualises children, including any child sexual abuse material (CSAM). We have a zero-tolerance policy. CSAM is reported immediately to the New Zealand Department of Internal Affairs and, where applicable, to the National Center for Missing and Exploited Children (NCMEC).
b. Violent extremism and terrorism. Promotes, glorifies, recruits for, finances, or coordinates terrorism, violent extremism, or genocide, including content prohibited by the New Zealand Films, Videos, and Publications Classification Act 1993 (Objectionable Material) or by the Christchurch Call to Action.
c. Incitement to violence or hatred. Incites violence or hatred against an individual or group on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age, or other protected characteristic.
d. Defamation, harassment, and privacy violations. Is defamatory, libellous, threatening, harassing, stalking, or a serious invasion of privacy, including content prohibited by the Harmful Digital Communications Act 2015 or the Privacy Act 2020.
e. Intellectual property infringement. Infringes any copyright, trademark, patent, trade secret, moral right, publicity right, or other intellectual property right of any person.
f. Misleading or deceptive commercial conduct. Breaches the Fair Trading Act 1986, including false or misleading representations about products, services, or affiliations.
g. Unsolicited electronic messages. Breaches the Unsolicited Electronic Messages Act 2007, including unsolicited commercial email and spam.
h. Malware and exploit content. Contains or distributes viruses, worms, trojans, ransomware, spyware, stalkerware, keyloggers, browser exploit kits, drive-by-download payloads, or any other malicious code.
i. Non-consensual intimate imagery. Including "revenge porn" and any imagery of a sexual or intimate nature shared without the depicted person's consent.
j. Fraud and financial crime. Facilitates fraud, identity theft, money laundering, financing of terrorism, sanctions evasion, or any other financial crime.
k. Weapons and controlled substances. Facilitates the manufacture, distribution, or unlawful sale of weapons (including firearms, explosives, and 3D-printed weapons), controlled drugs, counterfeit goods, or other prohibited items.
l. Adult content. On shared Plans the following are prohibited regardless of legality elsewhere: content depicting minors or persons appearing to be minors, non-consensual content, bestiality, content lacking age verification, and any content that breaches the Films, Videos, and Publications Classification Act 1993. Certain forms of legal adult content may be permitted on dedicated Plans where you have informed us in writing.
m. Other unlawful content. Any content that is unlawful in New Zealand or in any jurisdiction in which the content is or may be accessed.
2.1 Network and system abuse
You must not: (a) conduct, facilitate, or participate in denial-of-service or distributed denial-of-service (DDoS) attacks; (b) scan, probe, or test the vulnerability of any system, network, or application without explicit prior written authorisation from the owner; (c) interfere with, intercept, or expropriate any system, network, data, or communications; (d) circumvent, disable, or attempt to defeat any security, authentication, rate-limiting, monitoring, or access-control mechanism (whether ours or another party's); (e) gain or attempt to gain unauthorised access to any account, computer, network, or data; (f) operate an open relay, open proxy, open recursor, anonymising gateway, or similar service that may be abused by third parties; or (g) attempt to reverse engineer, decompile, or extract the source code of the Services, except as expressly permitted by law.
2.2 Spam and unsolicited communications
You must not: (a) send unsolicited bulk email (UBE), unsolicited commercial email (UCE), or messages of any kind in breach of the Unsolicited Electronic Messages Act 2007 or any equivalent law in the recipient's jurisdiction (including the U.S. CAN-SPAM Act and the Australian Spam Act 2003); (b) forge, falsify, conceal, or remove headers, return paths, source IP addresses, or sender identification; (c) harvest, scrape, or generate email addresses without consent; (d) operate mailing lists where the recipients have not given express or inferred consent to receive your messages; (e) send mail without a clear and functional unsubscribe mechanism where required by law; (f) use the Services as a relay for, or destination for, spam originating elsewhere; or (g) sustain a hard-bounce rate above 5% or a spam-complaint rate above 0.1% over any rolling seven-day period.
2.3 Phishing, fraud, and deception
You must not: (a) host, operate, or facilitate phishing pages, scam pages, or pages impersonating other brands or persons without authorisation; (b) misrepresent the source, identity, or affiliation of any communication or content; (c) distribute malware, drive-by-download payloads, fake software updates, or browser exploit kits; (d) operate "tech support scams", lottery scams, romance scams, fake job scams, advance-fee fraud, or any similar scheme; or (e) operate or facilitate financial scams, including pump-and-dump schemes, fake investment platforms, or fraudulent cryptocurrency token sales.
2.4 Cryptocurrency and abuse of compute
You must not: (a) run cryptocurrency mining workloads on shared hosting Plans (Start, Pro, Scale, Cloud Power), with or without disclosure; (b) operate stratum proxies, mining pools, mining bots, or other persistent high-CPU mining-related processes on shared Plans; (c) operate workloads designed to circumvent or game fair-use limits on shared Plans (for example, multi-tenant Plans masquerading as a single-customer site); (d) operate any workload that consumes shared resources in a manner materially disproportionate to your Plan, including persistent 100% CPU usage, unbounded memory consumption, or unbounded disk-write rates; (e) train, fine-tune, or run inference for machine learning models on shared Plans without our prior written consent; or (f) abuse free Trials by creating multiple Accounts, by using disposable or temporary payment methods, or by other means.
2.5 Email service-specific abuse
You must not: (a) operate any service that constitutes a "snowshoe" sender (low-volume from many domains and IPs designed to evade reputation systems); (b) send messages with deceptive subject lines or bodies; (c) send transactional messages with no relationship to the underlying transaction; (d) operate "email validation as a service" using our infrastructure; (e) operate "warm-up as a service" or any service designed to circumvent sender reputation systems; or (f) send to purchased, scraped, or co-registration lists.
To protect delivery for every customer on our shared mail servers, a mailbox that queues more than 60 outbound messages within any 60-minute period is suspended automatically and must be re-secured before it can send again. This limit applies in addition to the rates in clause 2.2(g) and is not a breach finding on its own; we review every automatic suspension.
2.6 Privacy and surveillance
You must not: (a) collect personal information without a lawful basis and a clear privacy notice to the people whose information is collected; (b) operate, host, or facilitate surveillance, stalkerware, or "spouseware" services; (c) operate unauthorised geolocation, tracking, or behavioural-monitoring services; or (d) host or distribute personal information of any person without their consent in a manner intended to harass or expose them (doxxing).
2.7 Illegal services and prohibited businesses
You must not: (a) operate illegal gambling, illegal pharmacies, illegal weapons sales, illegal pornography, illegal escort services, or any other service unlawful in New Zealand; (b) operate businesses that target sanctioned jurisdictions or sanctioned persons in breach of New Zealand sanctions law; or (c) operate businesses prohibited by our payment processor's restricted-business list (currently Stripe's), in respect of which we may be required to terminate.
2.8 Reseller and third-party services
You must not: (a) resell our Services to third parties without explicit reseller terms with us; (b) provide hosting, email, or other infrastructure to third parties using our shared Plans (a personal staging site for a friend is fine; a hosting business is not); or (c) onboard your customers to our systems without making them aware of, and bound by, our Terms of Service and AUP to the extent applicable.
3. Fair use and resource limits
4. Backups and storage hygiene
5. Domain registration conduct
6. Copyright takedown procedure
7. Investigations, cooperation with law enforcement, and disclosure
8. Consequences of breach
9. Changes
We may update this AUP from time to time. Material changes will be notified by email or KPanel notice at least thirty days before they take effect. Material changes do not retroactively apply to conduct that occurred before they took effect. Non-material changes (typographical corrections, contact updates, clarifications) take effect on posting.
10. Contact
Kapsule Group Limited, New Zealand.
Abuse reports: abuse@kapsulehost.com
Copyright notices: abuse@kapsulehost.com (mark "Copyright")
Security: security@kapsulehost.com
Eleven documents, and none of them is behind a login.
Every one is indexed, searchable by word, and deep linkable by clause. Six of them are not in the footer and this is how you reach them.