Legal

Acceptable Use Policy

A short list of things you may not do with the platform. It exists to keep the service usable and reputable for everyone on it, not to police what you build.

Version 2.2Effective 1 August 2026Updated 1 August 2026
In short
  • No illegal content, phishing, malware distribution, or attacks on other systems.
  • No unsolicited bulk email or SMS. Transactional messaging is fine; cold blasting is not.
  • No crypto mining or proof-of-work on shared capacity.
  • Security research on your own services is welcome. Load-testing another tenant is not.

Prohibited content and activity

  • Content that is unlawful where you or your users are, including CSAM, which we report to authorities without notice.
  • Phishing pages, credential harvesting, fake storefronts, and impersonation of a brand you do not own.
  • Distributing malware, ransomware, botnet controllers, or exploit kits packaged for use against third parties.
  • Attacking or scanning systems you do not own or have written authorisation to test.
  • Unsolicited bulk email or SMS, list rental, or sending to addresses you did not collect yourself.
  • Cryptocurrency mining, hash-rate rental, or proof-of-work on any shared or free capacity.
  • Circumventing plan limits with automation, or creating multiple accounts to multiply free tiers.
  • Publishing another person’s personal data without a lawful basis, including doxxing.

AI-specific rules

Agents you deploy must not impersonate a human where a person would reasonably assume otherwise, must not be used for automated harassment or mass account creation, and must not scrape services in breach of their terms. If an agent takes an action with legal or financial consequence, a human approval step is your responsibility to configure.

Messaging

Transactional messages — receipts, alerts, one-time codes, delivery updates — are expected. Marketing requires consent you can evidence, an unsubscribe path, and a sending domain you control. Complaint rates above 0.1% or bounce rates above 5% pause sending until reviewed.

Resource fairness

Shared and free instances have a fair-use ceiling. Sustained saturation of shared capacity, or use of free resources to serve production traffic at scale, is a breach. Dedicated instances have no fairness constraint beyond their stated size.

How we enforce

SeverityActionNotice
Minor / first timeEmail explaining the issue with time to fix7 days
RepeatedSuspension of the offending service only48 hours
SeriousImmediate suspension of the workloadAt suspension
Illegal / active harmImmediate termination and report to authoritiesNone

We suspend the narrowest thing that stops the harm — a single service before a project, a project before an account. Data is retained for 14 days after suspension so you can export it, unless the law requires otherwise.

Reporting abuse

Report anything hosted by us to abuse@darwa.com with the URL and what you observed. We acknowledge within 24 hours. Copyright complaints follow the DMCA Policy.

Appeals

Reply to the enforcement email and a person reviews it — not an automated system. If we got it wrong we restore the service and say so.

Contact

Darwa Technologies FZ-LLC, Dubai Internet City, Dubai, United Arab Emirates. Written notice may be sent to legal@darwa.com. Security reports go to security@darwa.com. Privacy requests go to privacy@darwa.com.