This Acceptable Use Policy ("AUP") sets out what you may and may not do with the services provided by Xenax Cloud India Private Limited ("Xenax Cloud", "we", "us", "our"). It forms part of our Terms of Service and applies to every customer, reseller, sub-user and end user of our services.
Most of what follows is either required of us by Indian law, or is there because a single bad actor on a shared network damages everyone else on it.
How this policy is organised. Instead of one long banned list, uses fall into three tiers:
This AUP applies to you, to anyone you allow to use your services, and to your own customers if you resell our services. You are responsible to us for everything done on or through your services, as if you had done it yourself. Not knowing what your client was doing does not remove that responsibility, though it will normally place the incident in a lower severity band under Section 12.1 and will affect how much time we give you to fix it.
Section 21 of the Terms of Service applies in full and is repeated here because this is the document your clients will be shown. In summary: you must maintain your own terms of service and acceptable use policy on terms no less strict than ours; you must keep records identifying each of your end clients, the services they use and the IP addresses and periods concerned; and you must furnish those records to us within 24 hours of our request, or sooner where an authority has set a shorter deadline. We deal with you, not with your clients.
Every service you create through our API is subject to this AUP, exactly as if you had ordered it by hand, and you are responsible for making your own clients comply, Section 21.2 of the Terms of Service. Where a complaint concerns a service you have genuinely resold, Section 21.1 of the Terms of Service gives you 48 hours to respond and begin remediation on a Serious-band matter, instead of the deadline in Section 12.1 below, with suspension possible after 72 hours. Severe matters carry no window at all, for either of us, and no window can extend a statutory deadline that binds us: see Section 12.1.
This AUP sits alongside the Terms of Service, the Privacy Policy, the Copyright, DMCA and Abuse Policy, the Service Level Agreement and the Refund Policy. On questions of permitted and prohibited use, this AUP governs. On personal data, the Privacy Policy governs; on uptime and service credits, the SLA; on refunds, the Refund Policy. Terms defined in the Terms of Service have the same meaning here.
We are an intermediary under Section 2(1)(w) of the Information Technology Act, 2000. Our protection from liability for what customers do, "safe harbour" under Section 79, depends on our carrying out due diligence under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended with effect from 20 February 2026. Rule 3(1)(b) requires us to inform you of the categories of information you may not host and to make reasonable efforts to cause you not to host them. We are also bound by the CERT-In Directions dated 28 April 2022, which apply expressly to data centres, virtual private server providers and cloud service providers.
That is why Sections 2 to 5 are written as absolutes. They are not house preferences we can waive for a good customer.
Rule 3(1)(b) of the IT Rules, 2021 requires us to inform you of the following categories and to make reasonable efforts to cause you not to host, display, upload, modify, publish, transmit, store, update or share any information that:
Note on sub-clause (v): the rule also contains a limb relating to information identified as false by a fact check unit of the Central Government. That limb was held unconstitutional by the Bombay High Court in 2024 and the matter is before the Supreme Court. We have not reproduced it, and we do not currently act on that basis. We will update this policy if the position changes.
Zero tolerance. Any material that depicts, describes or sexualises a minor results in immediate termination without notice and without refund, with no warning stage and no reinstatement. This applies whether the material was uploaded by you, by your customer, or by a third party through a system you operate.
We will preserve the material and all associated records without vitiating the evidence, as Rule 3(1)(g) of the IT Rules, 2021 requires, for 180 days or longer if a court or a lawfully authorised agency requires it. We will report the matter to the police or the Special Juvenile Police Unit, and through the National Cyber Crime Reporting Portal.
The relevant law is Section 67B of the Information Technology Act, 2000, which criminalises publishing, transmitting, creating, collecting, seeking, browsing, downloading and facilitating child sexual abuse material, and Sections 19, 20 and 21 of the Protection of Children from Sexual Offences Act, 2012: which impose a duty to report on any person with knowledge of such an offence, a specific duty on operators of studio and photographic facilities, and a punishment for failing to report. We take that duty seriously and we will not exercise discretion about it.
We do not host adult content of any kind, including content that would be lawful elsewhere.
Two provisions apply. First, Sections 67 and 67A of the Information Technology Act, 2000 make it an offence to publish or transmit obscene material, and material containing a sexually explicit act, in electronic form, so the exposure falls squarely on you as the person publishing. Second, Rule 3(1)(b)(ii) requires us to make reasonable efforts to cause our users not to host obscene or pornographic material, and Rule 3(1)(d) requires us to act on a court order or a government notification; failing on either puts our safe harbour under Section 79 at risk.
This covers pornographic sites, adult tube and cam sites, escort and adult dating services, adult affiliate and traffic-broker sites, and infrastructure such as CDNs, proxies, storage and databases serving any of the above. Nudity in a clearly artistic, educational or medical context is assessed on its own facts against those two provisions; if you are unsure, ask us in writing before you deploy and we will give you an answer you can rely on.
You must not offer, host, operate, advertise, or provide computing, storage, network or payment infrastructure for any online money game within the meaning of the Promotion and Regulation of Online Gaming Act, 2025, or for any other unlawful gambling, betting or wagering service.
Section 5 of that Act provides that no person shall offer, aid, abet, induce or otherwise engage in the offering of an online money game or online money gaming service. Section 6 prohibits advertising them. Section 9 provides for imprisonment of up to three years and a fine of up to ₹1 crore for a contravention of Section 5, and up to two years and ₹50 lakh for Section 6, with higher penalties for repeat offences, and Section 11 extends liability to officers of a company. Rule 3(1)(b) separately prohibits information relating to or encouraging gambling, an online game that causes user harm, an unverified online game, and advertising of one.
This includes betting exchanges and bookmakers, casino and card-game platforms played for money or money's worth, fantasy sports played for stakes, "prediction" and colour-trading apps, betting tip and odds sites, and affiliate or landing pages driving traffic to any of them. E-sports and online social games that fall outside the definition of an online money game are dealt with in Section 7.1.
Prohibited, and note that most of these are offences under the Bharatiya Nyaya Sanhita, 2023 (cheating, forgery and related provisions) and under Sections 66C and 66D of the Information Technology Act, 2000 (identity theft, and cheating by personation using a computer resource):
Prohibited, offensive tooling. You must not store, host, distribute or run:
Permitted, defensive and diagnostic tooling. Security and networking software used to protect or diagnose your own systems is permitted: firewalls, intrusion detection, anti-virus and malware scanners, fail2ban and similar, log analysers, TLS and certificate utilities, and the standard networking utilities that ship with every operating system, pingtraceroutedignetstattcpdumpcurlopenssl and their equivalents.
The line is what you point them at. Regardless of which tool you use, or whether it is offensive or defensive in character, you must not scan, probe, test, fingerprint, enumerate or attack any system you do not own and are not authorised in writing to test. Section 3.1 sets out the legal position. If you carry out security testing professionally, we may ask you to produce the client's written authorisation, and we do not offer an environment for unattested testing.
Prohibited. Note Section 66E of the Information Technology Act, 2000 (capturing, publishing or transmitting the image of a private area of any person without consent) and Section 72A (disclosure of information in breach of a lawful contract):
High-yield investment programmes, Ponzi and pyramid schemes, money-circulation and chain schemes, matrix and "gifting" schemes, and multi-level marketing structures whose income derives principally from recruitment rather than the sale of goods or services. Relevant law: the Prize Chits and Money Circulation Schemes (Banning) Act, 1978 and the Banning of Unregulated Deposit Schemes Act, 2019.
These are prohibited outright and cannot be moved to Tier 2 by producing a licence, because no licence exists for them. Legitimate regulated financial services are dealt with in Section 6.4.
You must not operate or host a lending application, website or backend that is not authorised by the Reserve Bank of India or operated by or on behalf of an RBI-regulated entity in accordance with the RBI Digital Lending Guidelines. In particular, we prohibit applications that harvest a borrower's contacts, call logs, photo gallery, location or device identifiers, and any recovery practice involving harassment, threats, impersonation of authorities, or contacting a borrower's contacts. Regulated lending by an authorised entity is dealt with in Section 6.4.
Marketplaces, listings, advertisements and infrastructure for narcotic drugs and psychotropic substances, in contravention of the Narcotic Drugs and Psychotropic Substances Act, 1985. Licensed pharmacy operations are dealt with in Section 6.2.
SIM boxes and GSM gateways, grey-route or unauthorised international VoIP call termination, bypass of licensed telecom operators, and OTP farms, virtual-number farms and bulk-SMS gateways used to circumvent another platform's verification. These contravene the Telecommunications Act, 2023 and are among the most common abuses of Indian VPS infrastructure.
Content that promotes, incites, glorifies or provides material support for terrorism or violent extremism, including recruitment, funding, training and attack-planning material, and content published by or on behalf of an organisation banned under the Unlawful Activities (Prevention) Act, 1967. This overlaps Rule 3(1)(b)(vii) and is treated in the Severe band under Section 12.1.
Content or services relating to human trafficking, forced labour, or prostitution, contrary to the Immoral Traffic (Prevention) Act, 1956, including escort and "companionship" services operating as a front.
Sending unsolicited bulk or commercial messages of any kind, by any channel, from our network or on behalf of any resource hosted on it, including email, SMS, instant messaging, forum posts, blog and comment spam, and referrer spam. This includes hosting a website, landing page, image, script, form, subscriber list or database that is advertised through, or supports, spam sent from anywhere else, even if not one message leaves our network. Section 8 sets out the email rules in full.
These are prohibited because each one, by design, causes other people's traffic to leave our network from our IP addresses, which means the abuse complaints, blacklistings and law-enforcement requests land on us.
You must not operate a VPN, proxy, SOCKS, residential-proxy or anonymisation service for anyone other than yourself or your own organisation, whether paid or free, and whether offered publicly or to a defined group. "Your own organisation" means a single legal entity and its employees, contractors and affiliates; it does not include subscribers, members, community users or customers, however the relationship is described.
Note also that direction (v) of the CERT-In Directions dated 28 April 2022 imposes customer-record obligations on VPN service providers specifically. Running such a service here would place those obligations on you and expose us to the consequences of your not meeting them. CERT-In's clarification of 18 May 2022 confirms that those obligations do not extend to enterprise or corporate VPNs, which is why Section 7.4 permits an internal VPN for your own organisation.
You must not operate any Tor infrastructure on our network, exit nodes, relays, bridges or hidden-service infrastructure. An exit node in particular causes the wider internet's traffic to emerge from an IP address registered to us, and a single one can render an address permanently unusable.
You must secure any service you expose. The following are prohibited because they are used as amplification vectors in attacks against third parties:
We may scan our own address space for these misconfigurations and will require you to remediate. Diagnosing and fixing your own systems is expressly permitted under Section 2.6.
You must not market, advertise or describe Xenax Cloud, or any service you resell from us, in terms that represent or imply that we do not verify customer identity, that we do not act on abuse or infringement complaints, or that unlawful activity will be tolerated or shielded here, including formulations such as "bulletproof", "no-KYC", "anonymous, no questions asked", "DMCA ignored" and their equivalents. Direction (v) of the CERT-In Directions, 2022 places a statutory duty on us to register and maintain validated customer information, and advertising the opposite on our infrastructure is directly inconsistent with it.
For clarity, it is not a breach to state accurately that copyright complaints are handled under Indian law, under the procedure in Section 11.2, rather than under the United States DMCA. What is prohibited is representing that infringement claims are ignored.
You must not sell, transfer, assign or hand over control of your account or of any service to another person without our prior written approval, and the new holder must complete identity verification before the transfer takes effect. Our verified customer records must reflect who is actually operating a service, if they do not, we are not compliant with direction (v), and you have exposed yourself to responsibility for whatever the new operator does.
You must not sell, rent or provide shells, containers, virtual machines, panels, sub-accounts or hosting space on your service to third parties. If you want to resell, buy a reseller product and accept the obligations in Section 1.2, including keeping records of your clients. Informal sub-letting defeats the customer record that Section 5.2 exists to protect, and leaves you personally answerable for people we cannot identify.
You must not scan, probe, penetrate, test or attempt to access our network, our management and hypervisor infrastructure, our control panels, or any other customer's service. This is unauthorised access under Sections 43 and 66 of the Information Technology Act, 2000, and we will treat it accordingly.
You must not deliberately provoke, solicit or invite a denial-of-service or other attack against a service hosted with us, or knowingly host a service for the purpose of drawing such attacks. Section 14 of the Terms of Service separately allows us to act where a service is repeatedly targeted, even where you are blameless.
If we have terminated your services for breach, you must not open a new account or obtain services from us again, whether directly or through another person, without our prior written consent. You must not ask or permit another person to obtain services on your behalf for that purpose, and a person who knowingly does so is themselves in breach of this Section.
We may decline an application, or terminate an account, where we reasonably believe it is being used to return after a termination. We are not obliged to do so, and we will consider a written request to be allowed back, since a breach two years ago is not the same as one last month.
We identify this from the records we already hold, including the verified name and date of birth and the identity document reference retained under direction (v) of the CERT-In Directions, 2022, and from payment and contact details. We do not claim to detect every case.
Approval must be obtained before deployment. Everything in this section is prohibited by default. It becomes permitted only when you have (a) asked us in writing before deploying, (b) produced valid documentation, and (c) received our written approval. Deploying first and producing a licence afterwards is itself a breach, it counts as a strike under Section 12.3, and we may suspend the service even if the licence turns out to be genuine.
Permitted with a valid content licence or distribution agreement covering the material you intend to carry and the territories you intend to serve. You must produce the licence or agreement, and we may ask for the licensor's contact details for verification. Unlicensed IPTV and restreaming remain prohibited under Section 2.7.
Permitted with a valid drug licence issued under the Drugs and Cosmetics Act, 1940 and the Drugs Rules, 1945, together with details of the registered pharmacist supervising the operation. Sale of prescription medicines without a valid prescription remains prohibited regardless of any licence. India has no separate notified e-pharmacy licence; a retail drug licence plus a registered pharmacist is what we will ask for.
Where your activity is one of the notified activities under the Prevention of Money Laundering Act, 2002, exchange between virtual digital assets and fiat currency or between virtual digital assets, transfer of virtual digital assets, safekeeping or administration of virtual digital assets or of instruments enabling control over them, or participation in and provision of financial services relating to an issuer's offer and sale of a virtual digital asset, approval requires valid registration with the Financial Intelligence Unit, India (FIU-IND) as a Reporting Entity, together with evidence of your KYC and AML programme.
Where your activity falls outside those notified activities, for example a purely non-custodial wallet, a block explorer, or open-source development tooling, FIU-IND registration is neither required nor available, and approval will be assessed on the facts. State which category you fall into. Mining remains prohibited on every service under Section 3.3.
Forex dealing, securities broking, investment advisory, lending, payment aggregation and similar activities are permitted with the relevant RBI, SEBI or other regulatory authorisation. Note that dealing in foreign exchange through unauthorised electronic trading platforms is restricted under the Foreign Exchange Management Act, 1999, and the Reserve Bank publishes an Alert List of entities not authorised to deal in forex or to operate such platforms, we check it. Schemes falling within Section 2.9 and lending falling within Section 2.10 cannot be brought within this section by any licence.
Retail or distribution sites for alcohol or tobacco products are permitted with the applicable excise or trade licence for the goods and the territory concerned. Electronic cigarettes and similar products are prohibited outright under Section 2.15 and cannot be approved under this section.
Permitted only for a dealer holding a valid licence under the Arms Act, 1959 or the Explosives Act, 1884, as applicable, and only for lawful trade within the territory the licence covers. Note that a dealer's licence authorises sale from licensed premises; it does not of itself authorise mail-order or e-commerce retail, and ammunition may only be sold against a purchaser's own arms licence. Approval under this section covers an informational or catalogue site for a licensed dealer. It does not authorise online ordering or fulfilment unless you can show that the transaction structure itself is lawful.
Sending bulk or marketing email from our network requires prior written approval. Because there is no licensing authority for email, the approval process for this category is set out separately in Section 8.4 rather than in Section 6.8, and the annual licence-renewal requirement does not apply to it.
| Step | What happens |
|---|---|
| Ask first | Write to abuse@xenaxcloud.com before you order or deploy, describing what you intend to run, on which service, and attaching your licence, registration or authorisation. Where this changes the purpose of use recorded on your account, we will update that record too, Section 3.2 of the Terms of Service requires it to stay accurate. |
| We verify | We check the document against the issuing authority's records where we can, and may ask for further information. We may decline where we are not satisfied that the activity is lawful, that the documentation is valid and sufficient, or that our infrastructure and our other customers can safely carry it, and we will tell you which of those grounds applies. |
| Written approval | Approval is given in writing and identifies the specific service and the specific activity approved. Nothing else is approved by implication. |
| Not transferable | Approval attaches to the named service only. It does not carry over to another server, another product, a renewal on a different service, or another account, including one you also control. |
| Annual renewal | You must produce current proof of your licence or registration every 12 months, and immediately on request. We will remind you, but the obligation is yours. |
| Lapse or cancellation | If your licence expires, is suspended or is cancelled, you must tell us within 48 hours. Approval is revoked automatically and you must remove the affected content or service within the period we specify. This 48-hour duty is specific to a Tier 2 licence and is in addition to the general 7-day duty to keep your account information current under Section 3.2 of the Terms of Service. |
| False documents | Producing a forged, altered, expired or otherwise false licence is a fundamental breach and is treated in the Severe band under Section 12.1: immediate termination without notice. Forgery and the use of a forged document as genuine are offences under the Bharatiya Nyaya Sanhita, 2023, and we may report the matter to the issuing authority and to the police. |
Game servers, e-sports platforms, IRC servers, chat bots and automation bots are permitted for lawful use. What is not permitted is using them for anything unlawful, pirated or cracked game servers, bots used to conduct attacks, bots used for spam or harassment, and bots used to evade another platform's controls.
Automated booking and ticketing. Do not run bots for ticket touting, scalping or bulk automated booking. Carrying on the business of unauthorised procurement and supply of railway tickets is an offence under Section 143 of the Railways Act, 1989. For other ticketing, events, cinema, airlines. There is no equivalent central offence, but such activity breaches the target platform's terms, may amount to unauthorised access depending on how the controls are circumvented, and generates complaints and IP blocks against our address space. We prohibit it here as a matter of contract.
E-sports and online social games. These fall outside the definition of an online money game under the Promotion and Regulation of Online Gaming Act, 2025, and the Act provides for their registration. If you operate a platform of this kind, tell us before you deploy and produce your registration if you hold one. A platform that in substance involves stakes or winnings is an online money game and is prohibited under Section 2.4 whatever it is called.
Be aware that game servers and IRC networks attract denial-of-service attacks. Section 14 of the Terms of Service applies, and a repeatedly targeted service may be null-routed or terminated.
Scraping is permitted subject to all of the following. India has no dedicated scraping statute and the position is developing, so we have set conditions that keep you, and us, on the right side of the provisions that do apply:
robots.txt must permit what you are doing;Because complaints and IP blocks arrive at our address space and not yours, we may require you to stop, to change your approach, or to move to a dedicated IP address, on receiving a credible complaint from a target site.
Running your own Nextcloud, Seafile, media server or video hosting on a VPS or dedicated server is permitted for your own content, and for a closed group of identified users you control: your family, your team, your organisation, or your own customers under a service you operate and are answerable for.
It becomes a public file-sharing service, prohibited under Section 2.7, when uploads are accepted from the general public, when registration is open and anonymous, or when it is used to distribute files to people you cannot identify. If you are not sure which side of the line you are on, ask before you deploy.
Bandwidth is shared. See Section 12.2 of the Terms of Service for allowances and throttling, so heavy media distribution is subject to fair use under Section 9.
Running WireGuard, OpenVPN or similar for your own use, or for your own organisation's internal access, is permitted. You must declare it to us: state it as your purpose of use when you order, or write to abuse@xenaxcloud.com afterwards so that we can record it against your account. Providing VPN or proxy access to anyone outside your own organisation, whether paid or free, remains prohibited under Section 4.1.
Hosting AI models, inference endpoints and image, audio or video generation tools is permitted. We sell GPU capacity for exactly this. But if you make such a tool available to other people, you are the intermediary facilitating the creation of synthetically generated information, and Rule 3(3) of the IT Rules, 2021 as amended with effect from 20 February 2026 applies to you, not to us. You must therefore:
Running a model purely for yourself, with no third-party access, does not engage Rule 3(3) and needs no declaration.
Shared and reseller hosting space is for active websites and their associated email. It must not be used as file storage, a backup destination, a media library, or a general file distribution point, whether or not the files are linked publicly.
Most abuse complaints in this industry originate in email, and a single compromised mailbox can put an entire IP range on a blocklist and stop mail delivery for hundreds of unrelated customers. These rules exist for that reason.
Every service carries limits on outbound mail, messages per hour and per day, concurrent SMTP sessions, and connection rate, enforced automatically at the server. The applicable figures vary by service type, by plan, and by your sending history and reputation, and we adjust them from time to time as delivery conditions change. For that reason we do not publish a single fixed number.
You can always find out what your limit is. The limit configured for your service is visible in your control panel. If you are evaluating a plan and need to know the limit before you buy, write to support@xenaxcloud.com or abuse@xenaxcloud.com and we will confirm it to you in writing. If your workload needs a higher limit, ask us; we will raise it for a legitimate sender.
Where we change the limit applicable to an active service, we will tell you, except where an immediate reduction is necessary to contain abuse or protect deliverability for other customers. Attempting to circumvent a limit: by splitting sending across multiple accounts, relaying through another service to evade it, or scripting around it, is a breach of this AUP, whatever the underlying volume.
Outbound TCP port 25 is blocked by default on VPS, RDP and dedicated servers. To have it opened, raise a ticket describing what you will send, to whom, and at what volume. We open it where we are satisfied the use is legitimate, and we may close it again at any time if we see abuse or a change in sending pattern. On shared and reseller hosting, outbound mail goes through our own mail servers and the limits in Section 8.1 apply instead.
This applies whether the mail leaves through our servers or through an external email service provider, if the list, the application, the landing pages or the sending infrastructure are hosted with us. Before your first campaign, write to abuse@xenaxcloud.com with:
You must retain opt-in records for every address for as long as you mail it, and produce them within 24 hours of our request. If you cannot evidence opt-in for an address, we will treat mail to that address as spam. We may require you to move bulk sending to a dedicated IP address, to a third-party email service provider, or to stop entirely. Approval under this section does not expire annually, but we may review it at any time.
Outbound spam is usually the first visible symptom of a compromise. We will suspend outbound mail immediately on detection, notify you, and expect you to find and fix the cause before we restore it. If your activity places any of our IP addresses on a blocklist, Section 29 of the Terms of Service applies to the cost of remediation.
Resource limits, storage, inodes, CPU, memory, I/O and entry processes, are set per plan and published on that plan's product page. Limits are enforced automatically at the container level: when your account reaches a limit, its performance is throttled until usage falls back within it.
Reaching a limit is not a violation of this policy. Throttling is automatic; it is how the plan is designed to behave, and it does not count as a strike under Section 12.3. Persistent throttling normally just means the account has outgrown its plan, and we will contact you about upgrading or optimising. Only deliberate evasion of limits, or conduct that materially degrades service for others despite throttling, is a breach, and that is dealt with under Section 3.3.
You may use the resources allocated to you. You must not attempt to exceed them, interfere with the hypervisor, or affect other tenants of the same host. Bandwidth allowances and the throttling that follows exhaustion are set out in Section 12 of the Terms of Service.
This section sets out what we monitor and is intended to be complete; Section 10 of the Privacy Policy carries the same information in more detail.
Where automated scanning flags something, a member of our team may review the specific file or message flagged, in order to confirm or dismiss the finding.
We do not read your websites, databases, emails or files as a matter of routine, and we do not use your content for advertising, analytics, profiling or artificial-intelligence training.
When we receive a specific abuse complaint, we access only the reported URL, file, mailbox or resource, and only to the extent needed to confirm or rule out the reported activity. A single complaint is not a licence to review an entire account.
Two situations are wider: where a service is actively compromised and attacking others, and where we must act to keep the platform running: for example migrating a virtual machine off failing hardware. Section 9 of the Privacy Policy and Sections 11 and 19 of the Terms of Service govern access to your content generally.
Send reports to abuse@xenaxcloud.com. To be actionable, a report should include:
Two exceptions, and they matter. We act on reports of child sexual abuse material and of non-consensual intimate imagery, nudity, a sexual act or impersonation including morphed or artificially generated images whether or not the reporter identifies themselves, and whether the report comes from the person depicted or from anyone acting on their behalf. Rule 3(2)(b) of the IT Rules, 2021 gives us 2 hours to act on the second category, and we will not spend that time asking who you are.
Copyright complaints follow the procedure in Section 19.3 of the Terms of Service and our Copyright, DMCA and Abuse Policy, the proviso to Section 52(1)(c) of the Copyright Act, 1957 read with Rule 75 of the Copyright Rules, 2013, under which we disable access to the identified material, we aim to do so within 36 hours of receiving a complying complaint, and keep it disabled for 21 days, restoring it unless an order of a competent court is produced within that period. Rule 75 requires specific declarations from the complainant; a complaint that does not contain them is not a valid complaint under that procedure. Where content also breaches this AUP, we may act under this AUP independently of that procedure.
Three different duties can arise, and it is worth being precise about them:
| Trigger | Our deadline | Authority |
|---|---|---|
| Court order, or notification by an appropriate government agency | 3 hours | Rule 3(1)(d), IT Rules 2021 as amended 20 Feb 2026 |
| Complaint about non-consensual intimate imagery, nudity, a sexual act, or impersonation including morphed or artificially generated images | 2 hours | Rule 3(2)(b), as amended |
| Complaint requesting removal of other Rule 3(1)(b) content | 36 hours | Proviso to Rule 3(2)(a), as amended |
| Any other complaint | Acknowledged in 24 hours, resolved in 7 days | Rule 3(2)(a), as amended |
So we do act on complaints from private parties, within those deadlines. What we do not do is remove content simply because someone asserts a legal right without evidence. A government takedown intimation must come from an officer of the rank the Rules require and must identify the provision relied on; a copyright complaint must satisfy Rule 75; and every other complaint must meet Section 11.1.
We may decline to act on a report that lacks evidence, that appears to be a commercial dispute presented as an abuse report, or that appears to be made in bad faith. Where a person repeatedly submits false, misleading or bad-faith reports, we may decline to accept further reports from them and may block their correspondence. A knowingly false report may also expose the sender to liability towards the customer concerned.
| Severity | What falls here | What we do |
|---|---|---|
| Severe | Child sexual abuse material (Section 2.2); non-consensual intimate imagery (Section 2.8); terrorism and violent extremism (Section 2.13); active phishing or malware distribution; an attack originating from your service; an ongoing compromise threatening our platform or third parties; misrepresenting us under Section 5.1; producing a false licence under Section 6.8 | Immediate suspension or null-routing without prior notice, and termination on the first occurrence without waiting for a third strike. We notify you afterwards, preserve evidence, and report to the appropriate authority where the law requires. For child sexual abuse material, termination is automatic and there is no reinstatement. |
| Serious | Spam; any other prohibited category in Sections 2 to 5; deploying a Tier 2 use without approval; deliberate resource abuse under Section 3.3; failure to secure an open service under Section 4.3 | Written notice with a deadline: normally 24 to 72 hours depending on the issue, to remove the content or correct the problem. Suspension if you do not comply, or if we cannot reach you. Counts as a strike. |
| Minor | Misconfiguration with no third-party impact; an isolated technical problem; a first failure to declare something this policy requires you to declare | Warning and a reasonable opportunity to fix it. No suspension unless it persists or escalates. Does not count as a strike. |
Resellers get longer in the Serious band. Where the complaint concerns a service you have genuinely resold to an unrelated third party, the Serious-band deadline is 48 hours to respond and begin remediation, and 72 hours before we may act, because you have your own client to reach. Section 21.1 of the Terms of Service sets this out. The Severe and Minor bands are unchanged.
No window, reseller or not, can extend a deadline the law puts on us. Where a complaint engages one of the statutory clocks in Section 11.3 of the Copyright, DMCA and Abuse Policy2 hours for non-consensual intimate imagery, 3 hours for a court or government order, 36 hours for a Rule 3(1)(b) removal request or a complying Rule 75 copyright complaint, 6 hours to report a qualifying incident to CERT-In, we act within that period and tell you afterwards, whether or not your response window has run. Note that Rule 3(1)(b) and copyright matters sit in the Serious band, so this is not a theoretical carve-out: it will bite.
Where the facts of a single incident genuinely fall in more than one band, for example a misconfiguration that is actively being exploited to attack third parties, the higher band applies to that incident. We will tell you why. Where we act without notice, we will tell you what we did and why as soon as we reasonably can.
There is no charge for reinstatement. Cleaning up a compromised account is a separate, optional service: if you ask us to do the remediation work for you rather than doing it yourself, we may charge a reasonable fee, and we will quote it before starting. In practice we often do not charge, but we reserve the right to where the work is substantial or repeated.
We operate a three-strike rule on a rolling 12-month window.
Where we suspend for a breach of this AUP, the timeline in Section 8.2 of the Terms of Service applies: the service is terminated and your Customer Content and all backups of it are permanently deleted 3 days after suspension. Use that window to export what you need, raise a ticket and we will help.
Where we terminate immediately without a suspension stage, as the Severe band permits, there is no three-day window and your Customer Content is deleted on termination. On a trial, Section 5 of the Terms of Service applies and content is deleted immediately in every case.
Where we have preserved material as evidence, under Section 19.4 of the Terms of Service, or under Rule 3(1)(g) of the IT Rules, 2021, that copy is retained for as long as the investigation or legal obligation subsists, and we will not provide a copy of it to you where doing so would prejudice an investigation.
No refund is payable where a service is suspended or terminated for breach of this AUP, and prepaid fees for the terminated service are forfeited. This does not affect any right you may have as a consumer under the Consumer Protection Act, 2019, and it does not apply where we terminate a service for a reason that is not your breach, Sections 6.3 and 14 of the Terms of Service provide for a pro-rata refund in those cases.
Beyond suspension and termination, a breach may result in our reporting the matter to law enforcement or a regulator where required or appropriate, in our recovering the cost of investigating and remediating the breach, and in the indemnity in Section 29 of the Terms of Service being engaged, including the cost of getting our IP addresses removed from a blocklist.
If you think we have got an enforcement decision wrong, tell us.
Appealing stops the deletion clock. If you appeal to the Grievance Officer before the deletion in Section 12.4 falls due, that deletion is held until the appeal is decided. We cannot hold it where the law requires removal, or where the matter is in the Severe band under Section 12.1.
We may update this AUP. Material changes are notified at least 15 days before they take effect, by email to your registered address and by announcement in the client area, as set out in Section 30 of the Terms of Service.
As Rule 3(1)(c) of the IT Rules, 2021 as amended requires, we will inform you at least once every three months of this AUP, the Terms of Service and the Privacy Policy and of any change to them; that we have the right to terminate your access or usage rights, or to remove non-compliant information, or both, for non-compliance; and of the legal consequences of non-compliance, including our obligation to report certain offences to the appropriate authorities.
If a change to this AUP would make a use you currently rely on impermissible, tell us before the change takes effect and we will discuss a reasonable transition period, or you may cancel the affected service and receive a pro-rata refund of prepaid fees for the unused period. This refund right applies notwithstanding Section 9.3 of the Terms of Service.
Ask us before you deploy. Write to abuse@xenaxcloud.com describing what you want to run. Asking in advance avoids a suspension that neither party wants.
| Abuse reports and Tier 2 approvals | abuse@xenaxcloud.com |
|---|---|
| Technical support | support@xenaxcloud.com |
| Billing | billing@xenaxcloud.com |
| Grievance Officer and appeals | Mr. Sanket Tripathi, grievance@xenaxcloud.com |
| Postal address | Xenax Cloud India Private Limited, H. No. 17, Jyoti Nagar, Fatehpur Road, Banda - 210001, Uttar Pradesh, India |
We use analytics cookies to understand how the site is used so we can improve it. These load only if you accept. The cookie that keeps your session working is always on and needs no consent. Read our Privacy Policy.