Legal

Acceptable Use Policy

Last updated: 10 September 2026

1. What this covers

This policy applies to anything we build, host, manage or give you access to — your website, your e-commerce store, an automation, an internal system, our client and staff area, and this website itself.

It forms part of our Terms of Service. If you engage us, you agree to it, and you are responsible for making sure your staff, contractors and end users follow it too.

It exists for three reasons: our hosting providers and payment processors impose these rules on us, some of them are legal obligations under South African law, and the rest is simply what it takes to keep a shared platform working.

2. You may not use our services to

2.1 Break the law

  • Do anything unlawful under South African law, or under the law of any country where the service is accessed or the content is directed.
  • Infringe anyone's copyright, trade mark, patent, trade secret, image or other right.
  • Publish defamatory, fraudulent or deliberately misleading material.
  • Publish child sexual abuse material, or content that promotes or depicts the abuse of a child. We report this to the authorities immediately and without notice to you, as the Films and Publications Act and the Cybercrimes Act 19 of 2020 require.
  • Publish content that incites violence, or that constitutes hate speech under section 10 of the Promotion of Equality and Prevention of Unfair Discrimination Act 4 of 2000.
  • Distribute malware, ransomware or any code designed to damage or gain unauthorised access to a system.
  • Do anything that is an offence under the Cybercrimes Act 19 of 2020, including unlawful access, unlawful interception, or unlawful acts in respect of software or hardware tools.

2.2 Abuse personal information

  • Process personal information in breach of POPIA or the GDPR.
  • Upload a mailing list you did not lawfully obtain, or send direct marketing without the consent or the pre-existing customer relationship that section 69 of the CPA and section 45 of ECTA require.
  • Send unsolicited bulk email. Every marketing message you send from a system we run must identify the sender and carry a working opt-out.
  • Harvest email addresses, telephone numbers or personal information from any source, including scraping this website.

2.3 Abuse the infrastructure

  • Attempt to gain unauthorised access to any account, system, network or data, whether ours or a third party's.
  • Probe, scan or test the vulnerability of a system without our prior written authorisation. If you want a penetration test, ask — we do this for a living and will scope it properly.
  • Circumvent or attempt to circumvent authentication, rate limits, quotas or access controls.
  • Run a denial-of-service attack, or knowingly participate in one.
  • Consume resources so disproportionately that other users are affected — including crypto mining, unthrottled crawling, and running a general-purpose file-sharing or streaming service on a plan not sized for it.
  • Resell, sublicense or provide hosting capacity we provide to you onward to a third party, unless the agreement says you may.
  • Use our infrastructure as an open proxy, an open relay, a VPN exit node, or a tunnel for third-party traffic.

2.4 Abuse payments

  • Take payments for goods or services that your payment processor prohibits. Their published list of restricted businesses applies to you and is not negotiable by us.
  • Process a payment that you know or suspect is fraudulent, or use a card you are not authorised to use.
  • Structure transactions to evade a processor's rules, a sanctions regime, or exchange control.
  • Misrepresent what a customer is being charged for, when they will be charged, or how to cancel.

2.5 Misrepresent

  • Impersonate any person or organisation, or misstate your affiliation with one.
  • Forge headers or otherwise disguise the origin of anything transmitted.
  • Publish an invented review, testimonial, endorsement or statistic. We hold ourselves to this on our own site and we hold you to it on ours.

3. Security is a shared job

You must:

  • Keep your credentials confidential, and never share a login between people. Ask us for another account instead — it costs nothing.
  • Use a strong, unique password, and enable multi-factor authentication where it is offered.
  • Tell us immediately at erik@vdmdigital.io if you suspect a credential has leaked or an account has been compromised.
  • Apply the updates we recommend. If you decline a security update we have recommended in writing, the consequences of that decision are yours.
  • Not disable, weaken or work around a security control we put in place without telling us.

4. Content you are responsible for

You are responsible for everything published through a service we provide to you, whether you wrote it, your staff wrote it, or one of your users submitted it. If your service accepts user-generated content, you need your own moderation process and your own terms with those users.

5. Reporting abuse

If you believe something we host breaches this policy, email erik@vdmdigital.io with the URL, what the problem is, and how to reach you. We acknowledge within 2 business days.

We are not an accredited take-down agency under Chapter XI of ECTA, so a formal section 77 take-down notice must go to the accredited agency for the relevant service provider. We will still act on any credible report we receive, and we will tell you what we did.

6. What we do about a breach

Depending on how serious and how urgent it is, we may:

  1. Contact you and ask you to fix it — the normal first step, and usually the only one;
  2. Suspend the affected content, account or service;
  3. Terminate the engagement under clause 13 of our Terms of Service; or
  4. Report it to law enforcement or the relevant regulator.

We will act proportionately and give you notice and a chance to fix it wherever we reasonably can. We will act immediately and without notice where there is a real risk of harm to a person, a serious security compromise in progress, content of the kind described in clause 2.1 above, or a legal obligation to act at once.

Suspension for a breach of this policy does not entitle you to a refund of a paid period, and does not suspend your obligation to pay.

7. Changes

We may update this policy as our providers' rules and the law change. The current version and its publication date are shown on this page, and every previous published version is retained.

8. Contact

VDM Digital (Pty) Ltd (Reg. No. 2026/179981/07)

13 Jigger Avenue, Somerset West, Western Cape, 7130, South Africa

Email: erik@vdmdigital.io

Last updated: 10 September 2026.

Other policies

  • Terms of Service
  • Refund and Cancellation Policy
  • Privacy Policy
  • Cookie and Local Storage Policy
  • PAIA Manual