Legal

Acceptable Use Policy

Last updated August 31, 2026

We aim to keep our rules as light as possible while protecting the integrity, reliability and legality of the Services provided by Iron Balkans ("IronBalkans"). This Acceptable Use Policy (the "AUP") applies to every customer and to anyone using a Service under a customer's account. We always review complaints before acting, but ignorance of these rules or of the law is not a defence to a serious violation. Breaching this AUP is a material breach of our Terms of Service.

1.Core rules

In addition to the specific policies below, you must follow the law of Romania (where the Services are physically hosted) and any law that otherwise applies to you. Please research any unfamiliar term or law before relying on the Services. At a minimum, the following are prohibited:

  • Any sexual content involving minors (CSAM), in any form — image, video or audio, AI-generated or not, including fictional depictions of minors. This is a zero-tolerance rule and is reported to the competent authorities.
  • Denial-of-service (DoS/DDoS) attacks originating from our servers, and command-and-control (C2) servers for botnets, as well as stresser or booter panels.
  • Sending mass unsolicited email (spam), hosting phishing pages, mass port or vulnerability scanning, or anything else likely to get a Service's IP address listed on reputation blocklists such as Spamhaus.
  • Any other content or activity that is illegal under Romanian or European Union law.

2.Strictly prohibited content

Beyond the core rules, the following content is prohibited without exception and is treated with zero tolerance:

  • Child sexual abuse material, as described above, which is reported to the competent authorities.
  • Content that promotes, incites or facilitates terrorism or violent extremism.
  • Content that facilitates human trafficking or exploitation.
  • The unlawful sale or distribution of weapons, explosives or controlled substances.

3.Network and security abuse

You may not use the Services to attack, disrupt or gain unauthorised access to any system or network. This includes:

  • Launching, participating in or facilitating denial-of-service (DoS/DDoS) or amplification attacks.
  • Operating botnet command-and-control infrastructure, stresser or booter services.
  • Unauthorised access, mass port scanning or vulnerability scanning of systems you do not own or have written authorisation to test.
  • Distributing malware, ransomware or other malicious code.
  • IP address spoofing, forging network traffic, or running open resolvers, relays or proxies that facilitate abuse.

4.Email, spam and fraud

  • No unsolicited bulk email, purchased or harvested address lists, or any activity that harms the reputation of our IP space or leads to a blocklist listing.
  • No phishing, credential theft, carding, financial fraud or impersonation of any person or organisation.
  • We may require prior review, rate limits or additional safeguards before permitting high-volume outbound mail.

5.User-generated content

If you host user-generated content, you are expected to moderate it so that illegal content is removed before any complaint reaches us. Besides manual monitoring, the most effective approach is to provide a working contact form or email address, linked on every page that displays such content.

Making it clear that you host user-generated content, and providing an easy way to report it, means that law enforcement and child-protection organisations will usually contact you before contacting us.

6.Resource usage and fair use

You may burst to 100% of the CPU, memory and disk space allocated to your Service. Because CPU, disk I/O and network I/O are shared at the node level, sustained usage is subject to fair use. As current guidance, the suggested daily averages are:

  • CPU: up to 50% of your allocated vCPU capacity, averaged over a rolling 24-hour period.
  • Disk: around 20 MB/s (megabytes per second) on average.
  • Network: around 100 Mb/s (megabits per second) on average.

These figures are guidance rather than hard caps. As set out in our Terms of Service, if we find you are consuming CPU, disk I/O or network I/O to a degree that affects other customers on your node for a considerable time, we may apply a hard limit to the affected resource.

7.I2P and Tor

I2P and Tor nodes, including exit nodes, are allowed. For Tor exit nodes we treat abuse reports with more leniency — one notable exception being email spam, since the default Tor exit policy already blocks mail ports.

Running an exit node does not exempt you from these rules; reports involving exit nodes are still reviewed manually. If you run a popular node, keep an eye on your bandwidth usage and set a limit on your side if necessary.

8.Public proxies and VPNs

Unlike Tor exits, there is no accurate public list of open proxies and VPNs that network administrators can use to filter incoming abuse. For that reason, and because our bandwidth fair-use policy makes them a poor fit, running public proxies or VPNs is not allowed.

9.Copyright and intellectual property

You must respect the intellectual property rights of others. Copyright and related complaints are assessed under Romanian and European Union law together with this AUP, rather than under foreign notice-and-takedown regimes such as the US DMCA. Customers who are repeat infringers may have their Services terminated.

10.Security and legal process

Keep the software on your Services patched and secure, and do not probe or test the security of our own systems without prior written permission. If you discover a vulnerability in our infrastructure, report it to us responsibly rather than exploiting or publicising it.

We cooperate with valid legal process issued under Romanian law and assess requests, including foreign requests, under the applicable Romanian and EU framework rather than actioning them automatically. Where legally required, we may preserve or disclose data.

11.Reporting abuse and enforcement

Suspected abuse can be reported to [email protected]. Please include the relevant IP address or hostname, timestamps with a timezone, and any logs or evidence that help us investigate.

  • Depending on severity, actions range from a warning or a request to remediate, up to suspension or immediate termination, following the abuse-handling process described in our Terms of Service.
  • No refunds are provided for Services suspended or terminated due to a violation of this AUP.
  • We may null-route or filter IP addresses that are the target or source of an attack in order to protect the network, and we may preserve and disclose information where legally required.

12.Further references

Because the Services are hosted in Romania, Romanian law is the primary legal framework that applies to what you may host and do. For convenience, the Romanian Penal Code (official English translation) is provided here for reference:

These documents are provided for reference only and may not reflect the most recent amendments. They do not constitute legal advice.

13.Changes to this policy

We may update this AUP from time to time to address new forms of abuse or changes in law. Active customers will receive at least 7 days of notice before any significant change takes effect.

This document is part of the IronBalkans service agreement. By using the Services you agree to it together with our other legal documents.