Acceptable Use Policy
Revised August 19, 2026
Who it binds
Everyone with a login. That means you, the developer you gave FTP to, the agency managing your site, and every customer of yours if you resell. Traffic leaving an account is the account holder's to answer for, no matter whose hands were on the keyboard.
Clause 4 of the terms is the binding version and stays the binding version. What follows expands it; it never enlarges it.
1. The hard no
A short list, and there is no discussion attached to any of it. Publish any of this and the account ends the same day:
- imagery depicting the sexual abuse of children;
- content promoting terrorism, or urging violence toward anyone;
- fraud infrastructure — fake sign-in pages, cloned bank sites, scam storefronts;
- viruses, ransomware droppers, exploit kits, dumps of stolen credentials or cards;
- botnet controllers, and relays you know are carrying abuse;
- work published without the licence it needed, once a rights holder has shown us so;
- drugs, weapons or betting sold into places that have not licensed you to sell them.
Legal adult content is permitted. Gate it by age, keep it off our outbound mail, and it is no concern of ours.
2. What a shared machine can give you
Speed on a shared plan is a shared resource. Every plan gets a generous slice and no plan gets the whole box, because the moment one account takes the machine the other sites on it slow to a crawl.
Workloads we will ask you to move to a VPS or a dedicated server: encoding audio or video, crawling the web, mining coins, running a public download mirror, backing up machines that live somewhere else, and databases chewing through bulk jobs around the clock. None of that is forbidden — it is simply the wrong product, and you will get a message about it long before anything stops.
Where storage is described as unlimited, it is unlimited for the sites on the plan. Archives unrelated to any website are not what it is for.
3. Patching is yours
We keep the operating system, the web server and the control panel current. Everything you installed on top is yours to maintain, and a plugin three versions behind is how nearly every compromised account here got compromised.
- update your CMS, themes and extensions;
- clear installers, SQL dumps and config files out of public folders;
- give every person their own login, and delete it the day they leave;
- raise a ticket the moment something looks wrong rather than waiting to be sure.
Scanning or stress-testing anything you do not own needs our agreement in writing first. Even against your own site, warn us before you start, or our automated defences will treat it exactly as they treat a real attack.
4. Sending
Mail has its own document, because getting it wrong damages every customer sharing an address range rather than just the sender. Read the anti-spam policy before you send anything to more than a handful of people.
5. How we react
The scale of the response tracks the scale of the harm, and the first step is nearly always a conversation:
- A message. The usual outcome, because the usual cause is a hacked plugin or a job that outgrew its plan.
- Something gets switched off. When the damage is live and spreading — mail pouring out, a phishing page collecting logins, one process starving a node — the offending thing stops while we talk about it.
- The account closes. For section 1, for a pattern of repeat breaches, and for anyone who goes silent while their site causes damage.
Criminal material comes down immediately and is reported where the law says it must be. No warning is owed in that case and none will be given.
6. If we got it wrong
Say so. Reply to the notice you were sent, or open the complaints procedure. Where a suspension turns out to be our mistake, the service goes straight back on and the lost days are credited without you having to ask twice.
7. Telling us about a site
Use report abuse. We put the substance of a report to the account it concerns, and we leave your contact details out of it unless you want them included or a court requires them.
8. The company
HostingFast is a trading name of Vitalcare at Home Ltd, a company registered in England and Wales under Company No. 15098204. Registered office: Office 4648, 221–323 High Road, Chadwell Heath, Romford, England, RM6 6AX. Ask us anything about this policy at info@hostingfastnet.com.