# ROOT VPN — Acceptable Use Policy **Version 1.0** **Effective: 6 September 2026** This Acceptable Use Policy ("**AUP**") governs your use of the Services provided by **ROOT VPN LTD**, a company registered in England and Wales ("**ROOT VPN**", "**we**", "**us**", "**our**"). This AUP is incorporated into and forms part of our **Terms of Service** and, where applicable, the **Bandwidth Sharing Terms** and any **Business Customer** agreement. Capitalised terms not defined here have the meanings given in the Terms of Service. **Breach of this AUP is a breach of the Terms of Service** and may result in suspension, termination, and reporting to the authorities. This AUP is the abuse-control backbone of our network. It exists to keep the Services lawful, to protect the users whose idle bandwidth funds the Free Tier, and to prevent the Services being used to commit or facilitate offences — including offences under the **Computer Misuse Act 1990**. --- ## 1. Definitions 1.1. "**Services**" means, collectively, the ROOT VPN application (Free Tier and Paid Tier), the Meridian Peer SDK, the Root Proxies Network, and all related software, APIs, and websites. 1.2. "**Root Proxies Network**" means the business-to-business residential and ISP proxy network available to KYC-verified Business Customers. 1.3. "**Business Customer**" means a verified business customer who has completed KYC and entered into a commercial agreement to use the Root Proxies Network. 1.4. "**Shared-Bandwidth Peer**" means a Free Tier user who has opted in to share idle bandwidth and whose IP address and connection may act as a residential exit. 1.5. "**Target Site**" means any website, service, API, or system to which traffic is directed through the Services. 1.6. "**You**" means any user of the Services, whether a Consumer or a Business Customer. --- ## 2. General Principles 2.1. You must use the Services **lawfully, responsibly, and in good faith**. 2.2. You are **responsible for all activity** conducted through your Account, credentials, API keys, or SDK integration, and for all traffic you route through the Services. 2.3. You must not use the Services to do anything that is unlawful, that infringes the rights of others, or that could damage, disable, or impair the Services or the connections, devices, or reputations of Shared-Bandwidth Peers. 2.4. Because the Free Tier is funded by users sharing idle bandwidth, **misuse of the network can cause real harm to ordinary individuals** whose IP addresses act as exits. We treat abuse seriously and enforce this AUP strictly. --- ## 3. Prohibited Conduct You must not use the Services (including any exit provided by a Shared-Bandwidth Peer) to engage in, attempt, enable, or facilitate any of the following: 3.1. **Unauthorised access / hacking.** Accessing, or attempting to access, any computer, account, network, system, or data without authorisation, or exceeding authorised access. This includes conduct that would constitute an offence under the **Computer Misuse Act 1990** (including sections 1, 2, and 3), such as unauthorised access, unauthorised access with intent to commit further offences, and unauthorised acts impairing operation. 3.2. **Credential stuffing and account takeover.** Automated testing of stolen or guessed usernames/passwords, brute-forcing logins, session hijacking, or any attempt to gain unauthorised control of accounts. 3.3. **Fraud.** Payment fraud, carding, identity theft, account-opening fraud, affiliate or ad fraud, click fraud, fake reviews, or any deceptive scheme intended to obtain money, data, or advantage dishonestly. 3.4. **Child sexual abuse material (CSAM) and illegal content.** Accessing, storing, transmitting, producing, or distributing CSAM or any content that is illegal to possess or share. **We report CSAM to the appropriate authorities and cooperate fully with law enforcement.** There is zero tolerance and immediate termination. 3.5. **Malware and command-and-control (C2).** Creating, hosting, distributing, or operating malware, ransomware, spyware, botnets, exploit kits, or any command-and-control infrastructure. 3.6. **DDoS / DoS.** Launching, participating in, or facilitating denial-of-service or distributed denial-of-service attacks, traffic floods, amplification attacks, or any activity designed to overwhelm or degrade a Target Site or network. 3.7. **Spam and phishing.** Sending unsolicited bulk or commercial communications in breach of the **Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)** or other law; operating phishing pages; harvesting contact data for spam; or evading anti-spam controls. 3.8. **Intellectual-property and copyright infringement.** Infringing copyright, trade marks, database rights, or other intellectual-property rights, including unlawful distribution of protected works or circumvention of technical protection measures. 3.9. **Harassment and abuse of persons.** Stalking, harassing, threatening, doxxing, or intimidating any person, or content that incites violence or hatred. 3.10. **Sanctions evasion and export breaches.** Using the Services to evade sanctions, trade restrictions, or export-control laws, or to transact with sanctioned persons, entities, or territories. 3.11. **Illegal goods and services.** Trading in illegal drugs, weapons, stolen data, or other unlawful goods or services. 3.12. **Circumventing security or usage controls.** Bypassing rate limits, CAPTCHAs, bot-detection, access controls, or geo/technical restrictions in a manner that is unlawful or in breach of a Target Site's binding terms, or interfering with our own abuse controls, allow-lists, or destination filtering. 3.13. **Endangering Shared-Bandwidth Peers.** Any use that would expose a Shared-Bandwidth Peer to legal risk, degrade their connection, breach their ISP terms, or route prohibited or illegal traffic through their device. --- ## 4. Ticketing Rule (Digital Economy Act 2017) 4.1. You must **not** use automated software, bots, or any technical means to purchase tickets for events, recreation, or entertainment **in excess of the number permitted per person** by the seller. 4.2. Using such automated means to acquire tickets **above a seller's per-person limit may be a criminal offence under section 106 of the Digital Economy Act 2017**. We prohibit it absolutely on our network. 4.3. When purchasing tickets through the Services you must: (a) stay **within the seller's stated per-person / per-transaction limit**; (b) comply with the **Target Site's terms and conditions** of sale; and (c) not use multiple identities, accounts, or IP addresses (including Shared-Bandwidth Peer exits) to defeat those limits. 4.4. We may block, rate-limit, or terminate any activity we reasonably believe is intended to breach ticketing limits, and we may report suspected offences to the authorities. --- ## 5. Additional Rules for the Root Proxies Network (Business Customers) These rules apply to Business Customers using the residential/ISP proxy product, in addition to all other provisions of this AUP. 5.1. **KYC verification required.** You must be **KYC-verified**. You must provide accurate identity, business, and beneficial-ownership information and keep it current. We may re-verify at any time and may suspend access pending verification. 5.2. **Authorisation for your use.** You must have **lawful authorisation** for the activity you carry out. You must not access systems or data you are not permitted to access, and you warrant that you have all necessary rights and consents for your use case. 5.3. **Compliance with Target Site terms and law.** You must **comply with the terms of service of every Target Site** you access and with all applicable laws (including data-protection, intellectual-property, consumer-protection, sanctions, and computer-misuse laws). 5.4. **No illegal destinations.** You must **not route traffic to illegal destinations** or for illegal purposes. Traffic must remain within **allow-listed commercial destinations** where allow-listing applies, and must never target prohibited destinations. 5.5. **Respect for Shared-Bandwidth Peers.** You acknowledge that exits may be provided by ordinary individuals who opted in to share idle bandwidth on conditions (Wi-Fi, charging, idle, within data-cap) and who can revoke sharing with one tap. You must use exit capacity responsibly and must not do anything that would harm, over-use, or legally endanger a peer or their connection. 5.6. **Purpose limitation.** You must use the Root Proxies Network only for the lawful business purposes declared during onboarding. Undisclosed or prohibited use-cases are a material breach. 5.7. **Data protection.** Where your use involves personal data, you are responsible for your own compliance with the **UK GDPR** and the **Data Protection Act 2018**, including having a lawful basis and honouring data-subject rights. You must not use the Services to build unlawful surveillance or profiling tools. 5.8. **No sub-letting of access.** You must not resell, sub-license, or provide third-party access to the Root Proxies Network except as expressly permitted in your commercial agreement, and any permitted downstream users must be bound by equivalent obligations. --- ## 6. Legal and Regulatory Context 6.1. This AUP is designed to help ensure the Services are not used to commit or facilitate offences, including under the **Computer Misuse Act 1990**, the **Digital Economy Act 2017** (section 106, ticketing), the **Online Safety Act 2023** (illegal content), the **Data Protection Act 2018** and **UK GDPR** (personal data), and **PECR 2003** (electronic marketing). 6.2. We may be subject to lawful requests for information or interception under the **Investigatory Powers Act 2016** and other legal processes. Where legally required, and subject to applicable safeguards, we will comply with valid legal obligations. Our handling of personal data in this context is described in our Privacy Policy. 6.3. Nothing in this AUP requires or authorises you to breach any law, and nothing you do in breach of this AUP is attributable to or endorsed by us. --- ## 7. Enforcement and Monitoring 7.1. **Data-minimised monitoring.** We do not seek to monitor the content of users' lawful activity. However, to protect the network and detect abuse, we operate automated and manual abuse-controls consistent with **data minimisation** and our Privacy Policy. These may include destination allow-listing, anomaly detection, volumetric analysis, and investigation of reports and complaints. 7.2. **Rate limits and technical controls.** We may impose rate limits, throttling, destination filtering, and other technical measures, and may block traffic that appears to breach this AUP. 7.3. **Suspension and removal.** We may **suspend, restrict, or terminate** access — immediately where necessary — where we reasonably believe this AUP has been or is likely to be breached, or where required to protect users, Shared-Bandwidth Peers, third parties, or the Services. 7.4. **Reporting to authorities.** We may **report suspected unlawful activity to law enforcement and other competent authorities** and cooperate with lawful investigations, subject to applicable data-protection law. In cases involving CSAM or imminent risk to a person, we will act promptly. 7.5. **Preservation.** Where we are lawfully required or permitted, we may preserve relevant records for the purposes of investigation, legal compliance, or the defence of legal claims, in line with our retention schedule and Privacy Policy. 7.6. **Cooperation with law enforcement.** We cooperate with valid legal requests. We will assess the validity of requests and act in accordance with applicable law and our internal law-enforcement-request procedures. --- ## 8. Reporting Abuse 8.1. If you become aware of any use of the Services that breaches this AUP, please report it promptly to **abuse@rootproxies.com**. 8.2. Please include, where possible: a description of the activity, relevant dates and times (with time zone), any IP addresses or identifiers, affected Target Sites, and supporting evidence (such as logs or screenshots). 8.3. We aim to acknowledge abuse reports promptly and to investigate and act proportionately. We may not always be able to disclose the outcome of an investigation for legal or privacy reasons. --- ## 9. Consequences of Breach 9.1. Breach of this AUP may result in any one or more of the following, at our discretion and proportionate to the breach: (a) a warning and a requirement to remedy the breach; (b) rate-limiting, throttling, or blocking of specific traffic or destinations; (c) **suspension** of your Account or access; (d) **termination** of your Account, Subscription, or Business Customer agreement; (e) **reporting to law enforcement or regulators**; and/or (f) **legal action**, including claims for damages and injunctive relief, and enforcement of any indemnity in the Terms of Service. 9.2. For serious breaches (including CSAM, fraud, malware/C2, DDoS, sanctions evasion, or activity endangering a Shared-Bandwidth Peer), we may act **immediately and without prior notice**. 9.3. Nothing in this AUP limits any right or remedy available to us at law or under the Terms of Service. --- ## 10. Changes to This AUP 10.1. We may update this AUP from time to time. Where a change is material, we will give reasonable notice by email or in-app. Continued use of the Services after the effective date constitutes acceptance of the updated AUP. 10.2. The "Effective" date at the top reflects the latest version. --- ## 11. Contact - Abuse reports: **abuse@rootproxies.com** - Legal notices: **legal@rootproxies.com** - Privacy enquiries: **privacy@rootproxies.com** - Data Protection Officer: **dpo@rootproxies.com** - General support: **support@rootvpn.com** --- ## Company details **ROOT VPN LTD** Registered in England and Wales Company number: [to be added] Registered office: [to be added] --- *ROOT VPN — Acceptable Use Policy, Version 1.0.*