X
X
X
X

Acceptable Use Policy (AUP)

HomepageAcceptable Use Policy (AUP)

EAK Acceptable Use Policy (AUP)

Last Updated: 9 September 2026

1. Purpose and Scope

This Acceptable Use Policy (“AUP”) establishes the rules governing the lawful, secure and responsible use of services provided by EAK Elektronik Bilgisayar İnternet ve İletişim Hizmetleri Sanayi ve Ticaret Limited Şirketi (“EAK”).

This Policy applies particularly to:

  • web hosting,
  • corporate e-mail services,
  • VPS,
  • VDS,
  • dedicated servers,
  • colocation,
  • network and IP services,
  • domain name services,
  • other related infrastructure services.

This AUP forms an integral part of the General Service Agreement and the Service and Usage Terms.


2. General Acceptable Use Principle

Customers must use EAK services in compliance with:

  • applicable laws and regulations,
  • contractual obligations,
  • this AUP,
  • the rights of third parties.

EAK services must not be used for:

  • unlawful activities,
  • damaging third-party systems,
  • disrupting internet or network security,
  • unauthorised access,
  • spam,
  • fraud,
  • distribution of malicious software.

3. Spam and Unsolicited E-mail

Use of EAK infrastructure for spam or unauthorised bulk messaging is prohibited.

Prohibited activities include, without limitation:

  • sending messages to purchased or unauthorised mailing lists,
  • bulk commercial communications without required permission,
  • spam campaigns,
  • snowshoe spam,
  • using temporary VPS instances or IP addresses for spam,
  • providing relay services to systems engaged in spam,
  • operating services intended to facilitate spam activities.

Customers are responsible for ensuring that bulk messages and commercial electronic communications sent through their services comply with applicable legislation.


4. E-mail Sending Security

Customers are responsible for protecting:

  • e-mail accounts,
  • SMTP credentials,
  • application passwords,
  • API keys.

If spam is sent through a compromised account, application or server, EAK may temporarily restrict or suspend:

  • the affected account,
  • SMTP access,
  • the relevant IP address,
  • specific ports,
  • the affected service.

Such action does not necessarily imply intentional misconduct by the Customer and may also be taken where a system has been compromised by a third party.


5. RBL and IP Reputation

Customers must not engage in activities that cause IP addresses assigned by EAK to develop a negative reputation with:

  • Spamhaus,
  • Barracuda,
  • Microsoft,
  • Google,
  • other RBL or reputation systems.

Where an IP address becomes blacklisted or its reputation is materially damaged as a result of Customer activity, EAK may:

  • suspend outbound e-mail,
  • restrict relevant ports,
  • refuse an IP replacement,
  • require corrective action.

Replacement of an IP address is not an automatic Customer right or a substitute for correcting the underlying cause of abuse.

EAK may refuse to assign a new IP address until the source of the problem has been resolved.


6. Phishing

EAK infrastructure must not be used for:

  • phishing,
  • fraudulent login pages,
  • impersonation of banks or payment services,
  • credential harvesting,
  • theft of cryptocurrency wallet credentials,
  • fraudulent customer panels or similar deceptive systems.

Confirmed phishing content may be disabled immediately where necessary to prevent ongoing harm.


7. Malware

Customers must not knowingly use EAK services to distribute or operate:

  • viruses,
  • trojans,
  • ransomware,
  • worms,
  • backdoors,
  • credential stealers,
  • cryptojacking malware,
  • other malicious software.

Files infected without the Customer's knowledge will not automatically be treated as intentional abuse.

However, EAK may temporarily restrict access to an affected service where necessary to protect other users, third parties or EAK infrastructure.


8. Botnets and Command & Control

EAK infrastructure must not be used as a:

  • botnet command-and-control server,
  • malicious network control panel,
  • malicious proxy node,
  • drop server,
  • malware distribution point.

Systems presenting an immediate security risk may be isolated or disabled without prior notice where necessary.


9. Unauthorised Access

Customers must not access or attempt to access systems for which they do not have authorisation.

Prohibited activities include:

  • account takeover,
  • password cracking,
  • credential stuffing,
  • brute-force attacks,
  • unauthorised SSH or RDP access,
  • exploitation of vulnerabilities without permission,
  • unauthorised acquisition of data.

10. Port Scanning and Security Scanning

Customers may perform security testing on systems they own or systems for which they have explicit authorisation to test.

However, conducting the following activities against third-party systems without authorisation is prohibited:

  • large-scale port scanning,
  • vulnerability scanning,
  • brute-force attempts,
  • exploitation attempts.

EAK may restrict large-scale internet scanning or other scanning activities that cause abuse, complaints or disruption.

This provision is not intended to prohibit legitimate security research. The essential requirement is proper authorisation to test the target system.


11. DDoS and Network Attacks

EAK infrastructure must not be used to initiate or facilitate:

  • DDoS attacks,
  • DoS attacks,
  • SYN floods,
  • UDP floods,
  • amplification attacks,
  • reflection attacks,
  • packet floods,
  • application-layer attacks.

A service originating attack traffic or participating in an attack may be:

  • filtered,
  • null-routed,
  • isolated from the network,
  • temporarily suspended.

12. Compromised Systems

A Customer system may be considered compromised where, without the Customer's knowledge, it:

  • sends spam,
  • participates in attacks,
  • distributes malware,
  • performs brute-force attempts,
  • becomes part of a botnet.

EAK may temporarily restrict the affected service to reduce the security risk.

The Customer may be required to:

  • remove malicious processes or files,
  • change passwords and credentials,
  • update software,
  • remediate vulnerabilities,
  • reinstall the affected system where necessary.

13. Proxy and VPN Services

Operating a proxy or VPN service is not prohibited solely because it is a proxy or VPN.

However, such services must not be used to facilitate:

  • spam,
  • attacks,
  • phishing,
  • fraud,
  • unauthorised access,
  • concealment of abusive activity.

Open proxies or uncontrolled relay services may be restricted where they create a security or abuse risk.


14. Open Relays and Misconfigured Services

Customers are responsible for securely configuring services operating on their systems.

EAK may require remediation of insecure configurations including:

  • open SMTP relays,
  • open DNS resolvers,
  • open proxies,
  • improperly configured NTP services,
  • services vulnerable to amplification attacks.

Where an immediate security risk exists, EAK may temporarily restrict the affected service or port.


15. Cryptocurrency Mining

Cryptocurrency mining is prohibited on shared hosting services.

Mining on VPS or VDS services is prohibited unless expressly permitted by the applicable service package or separately authorised by EAK.

Different conditions may apply to dedicated physical servers and will be determined by the relevant service terms.


16. Resource Usage

Customers must not use shared infrastructure in a manner that materially degrades service quality for other customers.

Resource management may include:

  • CPU usage,
  • RAM usage,
  • disk I/O,
  • inode usage,
  • process counts,
  • concurrent connections,
  • network traffic.

Where technical limits apply, they will be specified in the relevant service package or technical specifications.

This AUP intentionally does not establish fixed technical limits that may become obsolete as EAK infrastructure and service packages evolve.


17. Disk and I/O Abuse

On shared or virtualised infrastructure, EAK may restrict workloads that cause sustained excessive resource consumption and materially affect other customers.

Examples may include:

  • continuous high-volume disk writes,
  • uncontrolled log generation,
  • excessive database workloads,
  • mining-like continuous I/O activity,
  • automated workloads causing persistent storage contention.

Where reasonably possible, EAK may recommend migration to a service more appropriate for the Customer's workload.


18. File Storage and Archive Usage

Web hosting packages are primarily intended for hosting websites, web applications and associated e-mail services.

Unless expressly stated otherwise, hosting packages may not be used intensively as:

  • general-purpose file storage,
  • personal backup storage,
  • large archive repositories,
  • video archives,
  • software or file distribution repositories.

Where EAK provides services specifically designed for storage workloads, Customers should use the appropriate service.


19. Copyright and Intellectual Property

Customers must not use EAK infrastructure to unlawfully infringe:

  • copyright,
  • trademarks,
  • software licences,
  • other intellectual property rights.

EAK may review rights infringement notices that contain sufficient and verifiable information.

Receipt of a complaint alone does not automatically establish that an infringement has occurred.


20. Unlawful Content

EAK services must not be used to host or distribute content that is unlawful under applicable legislation.

EAK is not required to operate a general censorship or continuous monitoring system for Customer content.

However, EAK may take necessary action where there is:

  • a lawful decision or order from a competent authority,
  • a clear and serious security risk,
  • a sufficiently substantiated abuse report,
  • an obligation arising under applicable law.

21. Fraud and Deception

EAK infrastructure must not be used for activities including:

  • credit card fraud,
  • fraudulent payments,
  • fraudulent online stores,
  • identity theft,
  • account takeover,
  • investment fraud,
  • financial scams.

22. IP Spoofing and Network Manipulation

Customers must not engage in:

  • malicious IP spoofing,
  • deceptive manipulation of source addresses,
  • circumvention of network security controls,
  • manipulation intended to deceive EAK network infrastructure.

Legitimate laboratory, testing or private-network scenarios may be evaluated separately where appropriate.


23. Forged Headers and Source Information

The use of misleading or forged information for the purpose of facilitating spam, phishing, abuse or bypassing security controls is prohibited.

This includes:

  • forged e-mail headers,
  • deceptive HELO/EHLO identities,
  • misleading sender addresses,
  • maliciously forged HTTP headers,
  • information intended to misrepresent the source of logged activity.

Legitimate technical header manipulation for software development or authorised testing is not prohibited by this provision.


24. Use of IP Addresses

IP addresses assigned by EAK remain network resources allocated for use during the relevant service period and do not become the property of the Customer.

EAK may change an assigned IP address where reasonably necessary due to:

  • technical requirements,
  • routing changes,
  • security,
  • abuse,
  • IP reputation issues,
  • infrastructure changes.

25. Outbound SMTP

EAK may implement controls on outbound SMTP traffic to protect network reputation and prevent abuse.

Depending on the service and risk profile, EAK may:

  • apply sending limits,
  • restrict TCP port 25,
  • require authenticated SMTP,
  • request verification before enabling outbound SMTP,
  • temporarily suspend SMTP access following abuse.

These measures may vary according to service type and current security requirements.


26. E-mail Deliverability

EAK does not guarantee that an e-mail sent through its infrastructure will always be accepted by Gmail, Microsoft, Yahoo or any other recipient, nor does EAK guarantee delivery to a recipient's inbox.

E-mail deliverability depends on factors outside EAK's exclusive control, including:

  • IP reputation,
  • domain reputation,
  • message content,
  • SPF, DKIM and DMARC configuration,
  • recipient policies,
  • sending patterns and behaviour.

27. Abuse Reports

EAK may investigate abuse reports concerning its network or Customers.

Reports should, where possible, include:

  • affected IP address or domain,
  • date and time of the incident,
  • timezone,
  • logs or other technical evidence,
  • type of alleged abuse,
  • contact information.

Incomplete, automated or unverifiable reports may require additional investigation.


28. Customer Notification Regarding Abuse

Where appropriate to the nature and severity of the risk, EAK may notify the Customer of an abuse report and request remediation.

Customers may be expected within a reasonable period to:

  • investigate the incident,
  • implement necessary security measures,
  • respond to EAK regarding the remediation.

However, EAK may take immediate technical action without prior notice where a serious or ongoing security risk exists.


29. Emergency Intervention

EAK may intervene without prior notice where necessary to stop an immediate or serious threat, including:

  • an ongoing DDoS attack,
  • active phishing,
  • malware distribution,
  • botnet command-and-control activity,
  • high-volume spam,
  • an ongoing attack against third-party systems,
  • traffic presenting a serious risk to EAK infrastructure.

Measures may include:

  • blocking ports,
  • traffic filtering,
  • IP null-routing,
  • network isolation,
  • temporary suspension of the affected service.

The primary purpose of such intervention is to stop ongoing harm or security risk rather than to impose a penalty.


30. Repeated Violations

Where repeated AUP violations occur in connection with the same service or Customer account, EAK may:

  • require additional security measures,
  • restrict particular services,
  • refuse replacement IP addresses,
  • suspend services,
  • terminate the relevant service or contractual relationship.

The nature and frequency of violations and the Customer's corrective actions may be taken into consideration.


31. Security Research

EAK does not treat legitimate, good-faith security research in the same manner as malicious activity.

However, security research must be conducted:

  • on systems owned by the researcher,
  • on targets for which explicit authorisation has been granted,
  • without disrupting EAK services,
  • without harming or unlawfully accessing third-party data.

An unauthorised security test does not become authorised merely because it is described as research.


32. Penetration Testing

Customers may generally perform penetration testing on their own EAK-hosted servers or applications.

However, prior coordination with EAK may be required where testing:

  • generates significant traffic,
  • may affect other EAK customers,
  • may resemble DDoS or other large-scale attack traffic.

33. Monitoring and Logging

EAK may generate technical logs for the operation of its network, services and security systems.

Such logs may be used for:

  • network security,
  • incident response,
  • abuse investigation,
  • troubleshooting,
  • compliance with applicable legal obligations.

EAK does not perform general and continuous monitoring of private Customer communications for the purpose of inspecting their content.


34. Customer Responsibility

Customers are responsible for the security and maintenance of systems under their control.

This includes, where applicable:

  • operating system updates,
  • software updates,
  • password security,
  • firewall configuration,
  • application security,
  • malware prevention,
  • backup management.

The exact division of responsibility between EAK and the Customer depends on whether the service is managed or unmanaged and on the applicable service package.


35. Sub-Users and Customer Users

Where a Customer provides access to EAK services to its own:

  • employees,
  • customers,
  • users,
  • resellers,
  • subcontractors,
  • authorised persons,

the Customer is responsible for ensuring that such users comply with this AUP.

Violations by such users may be treated as activity associated with the relevant Customer service or account.


36. Suspension of Service

EAK may temporarily suspend all or part of a service where necessary due to:

  • an AUP violation,
  • a security risk,
  • ongoing abuse,
  • harm to third parties,
  • a threat to the integrity of EAK infrastructure.

Where reasonably possible, EAK will aim to limit the intervention to the service or component affected by the violation.


37. Termination of Service

In cases of serious or repeated violations, EAK may terminate the affected service or contractual relationship in accordance with the applicable agreements.

Intentional activities involving:

  • spam,
  • phishing,
  • botnets,
  • malware,
  • DDoS attacks,
  • fraud

may be considered serious violations.


38. Data and Backups Following Suspension or Termination

Suspension or termination of a service due to an AUP violation does not automatically guarantee continued access to Customer data or delivery of backup copies in every circumstance.

Where legally permitted and where doing so does not create a security risk, EAK may provide reasonable assistance regarding data transfer or recovery.

EAK is not required to assist in restoring malicious software or unlawful content to an operational state.


39. Fees and Refunds

The financial and refund consequences of suspension or termination resulting from an AUP violation shall be determined in accordance with:

  • the General Service Agreement,
  • the Service and Usage Terms,
  • the Cancellation, Refund and Right of Withdrawal Policy,
  • mandatory consumer protection legislation where applicable.

Nothing in this AUP excludes or restricts mandatory statutory rights of consumers.


40. Changes to This Policy

EAK may update this AUP due to:

  • changes in the threat environment,
  • emergence of new abuse techniques,
  • infrastructure changes,
  • changes in applicable law or regulation.

The current version shall be published through the EAK website.

Where required by applicable law or the contractual relationship, material changes may also be communicated through appropriate channels.


41. Contact and Abuse Reporting

Abuse reports concerning EAK infrastructure should be submitted through EAK's designated abuse communication channel.

General technical support requests should be submitted through EAK's normal customer support system.

Requests relating to personal data and KVKK rights may be submitted separately to:

kvkk@eak.com.tr


42. Relationship with Other Agreements

This AUP shall be read together with:

  • the General Service Agreement,
  • the Service and Usage Terms,
  • the KVKK Privacy Notice,
  • the Privacy Policy,
  • the technical specifications of the relevant service package.

Mandatory provisions of applicable law remain unaffected.


43. Effective Date

This Acceptable Use Policy was last updated on 9 September 2026.

EAK Elektronik Bilgisayar İnternet ve İletişim Hizmetleri Sanayi ve Ticaret Limited Şirketi


Language and Interpretation

This English version is provided for the convenience of international customers.

The official and original version of this Acceptable Use Policy is the Turkish version.

In the event of any discrepancy, inconsistency or difference of interpretation between the Turkish and English versions, the Turkish version shall prevail, to the extent permitted by applicable mandatory law.


Powered by WISECP
Top