Legal
Acceptable use
The short version is that the server is shared, so what you run on it can affect somebody else's business. Almost everything here follows from that.
What this covers
Anything I supply that runs on infrastructure I own or administer:
- WordPress hosting and care plans
- One page websites and brochure websites
- Business email at your own domain
- Domains registered or managed on your behalf
It does not cover consultancy work on your own infrastructure. There the account is yours, the rules are yours, and I am working inside your environment rather than supplying one.
Why a shared server changes things
WordPress sites on a care plan run on a machine I own and share between clients. That is exactly why the price is what it is. It also means a site that consumes the machine, gets compromised, or gets the server's address blocked for sending spam is not only your problem. It becomes everybody's problem on that machine within minutes.
So the rules below are less about propriety than about the fact that one site can take down several.
What must not be run
None of this is unusual. If you run an ordinary business website you will never come near any of it.
- Anything unlawful, or content that infringes somebody else's rights
- Bulk or unsolicited email, from the server or using the domain
- Malware, phishing pages, or anything designed to deceive a visitor about who they are dealing with
- Attacking, scanning or attempting to gain access to any other system
- Deliberately running the server out of resources, whether your own site or somebody else's
- Using the hosting as general file storage or as a distribution point unrelated to the site
Also not permitted, and these are the ones people ask about:
- Cryptocurrency mining, or anything else whose purpose is to consume processor time rather than to serve your visitors
- Open proxies, VPN endpoints, tunnels, or anything that relays somebody else's traffic through the machine
- Adult content, gambling, and anything requiring a licence or age verification I am not in a position to supervise
- Sharing your hosting with a third party, or reselling it. The account is for your business
- Running software the maintainer has abandoned, where a known unpatched vulnerability exists and no fix is coming
The providers underneath me have their own rules, and those bind you through me. The servers run on GridPane and Vultr, and the mail platform has its own acceptable use terms. Where anything they require is stricter than anything here, theirs is the one that applies, because I cannot grant you permission somebody else has to give. If that ever produces a conflict I will tell you what it is rather than quietly enforce it.
Keeping a site patched
Care plans include updates, and that is a large part of what they are for. Where you have installed something yourself, or asked for a plugin to be kept on an old version, the risk of that choice sits with the choice rather than with the plan.
Where you have asked me to hold something back, and that something turns out to have a known vulnerability, the answer changes. On your own infrastructure the risk is yours to take and I will say so once and respect it. On my shared machine it is not only yours, so it is not only your decision.
What happens is this. I tell you what the vulnerability is, what it allows, and how long I can reasonably leave it. If a fix exists and there is no good reason not to apply it, I will apply it, and you would rather I did. Where you have a real reason to wait, for instance a plugin your order process depends on, we find another way to cover it: a firewall rule, a virtual patch, or taking that one feature offline until the fix lands.
The point at which I stop asking is when it is being actively exploited, or when leaving it puts other sites on the machine at risk. Then I close it and tell you immediately afterwards. That is the bargain of a shared server and it is the same bargain your neighbours have with you.
Resource use
There is no published limit on storage, traffic or database load, and that is deliberate. A number I never enforce is worse than no number, because it tells you something untrue about how this works, and a number I do enforce would have to be low enough to be meaningful and would then catch the wrong people on a busy week.
What actually happens is that I watch the machine, and if your site starts to cost it more than the arrangement supports, I ring you. Usually that is good news: it means the site is working. Sometimes it is a plugin doing something daft, and I can fix it in an afternoon. Occasionally it means the site has outgrown a shared machine, and then we talk about what it should move to.
The one thing that is not a conversation is a site consuming the machine right now and taking other people's sites down with it. That is dealt with first and discussed second, and it is covered below.
A mailbox at your own domain is for your business correspondence. Sending bulk mail through it puts the sending reputation of the domain and the platform at risk, and that reputation is shared.
There is no published number here either, for the same reason, but the shape of it is simple: a mailbox is for messages you write to people who are expecting them. If you find yourself sending the same message to a few hundred addresses at once, that is a newsletter rather than correspondence, whatever it is called.
Newsletters and marketing should go through a service built for them, and there are several good ones that cost very little at the sizes a small business needs. They handle the unsubscribe link and the authentication records that keep your mail out of spam folders, and they keep that traffic away from the reputation your ordinary business email depends on. Ask me and I will point you at one. There is nothing in it for me either way.
This is not me being precious about volume. A shared sending reputation is genuinely fragile, and the business that suffers first when it breaks is the one whose invoices stop arriving.
Domains
Domains are registered in your name and you are the registrant. Nominet's own rules apply to .uk and .co.uk registrations regardless of anything on this page, including the requirement that registrant details are accurate.
Nominet can and does suspend a domain whose registrant details are wrong, and a suspended domain takes your website and your email with it. This is one of the few things on this page that can genuinely cost you a day's trading, and it is entirely avoidable.
So keep me posted when something changes: a company name, a registered address, the person who should be receiving the renewal notices. If Nominet queries the details on a domain of yours, I will pass it straight on and help you answer it. If I cannot reach you and the details are plainly wrong, I have to correct the record rather than leave a false one standing, and I will keep trying to reach you while I do.
If something goes wrong
The realistic case is not a client deciding to misbehave. It is a site getting compromised without anybody noticing, which happens to careful people.
What happens then is that I find it, usually before you do, because those sites are monitored around the clock and server and site level faults are acted on whenever they happen. I will tell you what I found and what I did.
When I act first and ask afterwards
I may suspend or isolate a site without asking you first, and only where it is actively causing harm. In practice that means one of four things: it is compromised and serving malware or a phishing page, it is sending spam, it is consuming the machine to the point that other sites are failing, or a law or a provider above me requires it.
Suspension is the narrowest thing that stops the harm, not a switch for the whole account. Usually that is taking one site offline, or blocking one route into it, while everything else of yours keeps running.
You are told as soon as it is done, by phone if I have your number, with what I found, what I did and what has to happen before it goes back. Your data is not deleted and nothing is held hostage: a suspended site is off, not gone, and you can have a full export of it while it is suspended exactly as you could before.
It goes back on as soon as the cause is dealt with, which for a compromise means cleaned and the way in closed. I will help you do that. There is no reconnection fee.
Ending a service over this
Suspension is meant to be temporary and almost always is. Ending a service is different and is a last resort.
I may end a service where a serious breach is deliberate, or where the same breach keeps happening after we have been through it. That means thirty days' written notice, the reason in plain words, and a full export of everything that is yours. Where the breach is criminal, or where a provider above me requires the service gone sooner, it can be immediate, and you still get the export.
It is written down so that you know where the edge is, not because I expect either of us to go anywhere near it.
Reporting something
If you believe something hosted by me is breaching this policy, email info@dalaric.com with the address and what you have seen. It reaches a person.
There is no separate abuse address, on purpose. A dedicated one on a business this size would be a mailbox nobody watches, which is worse than the one that is read every day.
A report gets acknowledged within one working day and I will tell you what I found, whether or not I agreed with you. If it is urgent, for instance a live phishing page, ring +44 (0) 1935 873985 rather than waiting on email. That reaches me rather than a queue.
Related
The terms of business cover what is sold and what you own. The privacy notice covers information about people.