Last updated: September 21, 2026
Prohibited Activities on JSBCloud
JSBCloud is a brand of ALTISCORE SAS, a simplified joint stock company (société par actions simplifiée) with a share capital of 105 euros, registered with the Annecy Trade and Companies Register under number 933 804 676, whose registered office is at 4A avenue Auguste Renoir, 74960 Annecy (France). Our services are hosted on our own servers, at the Equinix PA5 datacenter in Paris.
This document lists what may not be hosted on, or done from, our servers, how abuse is reported to us, and the measures we take when abuse is established. It forms an integral part of the General Terms and Conditions: failing to comply with it is a breach of contract.
It is written to be applied as it stands. We announce no monitoring we do not carry out, and no deadline we do not keep: Article 5 states what we measure and the means we devote to the fight against unlawful content.
1. Scope
These rules apply to every offer sold by JSBCloud:
- Web Hosting
- Mail services (Email Pro, AltisMail webmail)
- VPS (Standard, Performance, Extreme) and the associated cloud applications (Nextcloud, Docker)
- Game servers and GameBox pools
- Domain names
- Altis Studio and the artificial intelligence assistants
They bind the Customer, as well as any person to whom the Customer gives access to their service: user, administrator, delegated technician or service provider. The Customer remains liable to JSBCloud for the acts of those persons.
2. Customer responsibility
The Customer is solely responsible for the content they host, the processing they carry out, the software they install and the use made of the IP addresses allocated to them. They are answerable for that content to third parties; any criminal proceedings are brought against the authors of the content under the general law.
In practice, this means that:
- We do not inspect the content of the Customer's machines, databases, files or messages. The only access we carry out, and the grounds that justify it, are set out in Article 5. It is for the Customer to keep their own logs and to be able to account for the activity of their service.
- A compromised server remains their responsibility. An attack, a batch of unsolicited mail or unlawful content sent from their machine is attributable to them, even where they are not the direct author, unless they establish force majeure, the act of a third party unconnected with any failure of theirs to secure the service, or an error in the allocation of the IP address.
- It is for the Customer to keep their system up to date, to protect their credentials and to act without delay on a report we pass on to them.
A report may only be held against the Customer where it relates to a period during which the IP address concerned was allocated to them. Where they establish that this is not the case, the corresponding warning is removed from the count in Article 8.
The processing of personal data is described in the Privacy Policy. This document does not repeat the detail.
3. Prohibited content and activities
3.1 Unlawful content and harm to persons
| Prohibited | What this covers |
|---|---|
| Harm to minors | Child sexual abuse images or representations, solicitation of minors, making content harmful to minors available (Articles 227-23 et seq. of the French Criminal Code). Such content is reported to the authorities immediately |
| Terrorism | Incitement to acts of terrorism and glorification of terrorism, dissemination of terrorist content within the meaning of Regulation (EU) 2021/784 |
| Crimes against humanity | Glorification, denial, minimisation or trivialisation of crimes against humanity, genocide, enslavement and war crimes |
| Hatred and discrimination | Incitement to hatred, violence or discrimination, insult and defamation on grounds of origin, ethnicity, nationality, alleged race, religion, sex, sexual orientation, gender identity or disability |
| Harm to human dignity | Content that undermines human dignity, human trafficking, procuring, exploitation of a person's vulnerability |
| Harm to persons | Harassment, threats, defamation, disclosure of personal data with intent to harm, incitement to suicide, dissemination of images of violence or of harm to physical integrity |
| Non-consensual sexual content | Dissemination of sexual images or words without the consent of the person concerned, including montages and deepfakes produced or altered by automated means |
| Pornographic content | Any pornographic or erotic content, including where it is lawful. Such content is excluded from our offers as a commercial choice and because of the age verification obligations borne by its publishers |
| Illegal goods and services | Sale or promotion of narcotics, weapons, forged documents, medicines outside the legal supply chain, stolen data or misappropriated means of payment |
| Unauthorised gambling | Operating or promoting gambling and games of chance without a licence from the competent authority, in France the Autorité nationale des jeux |
3.2 Counterfeiting and intellectual property
It is prohibited to host, make available or distribute protected works without holding the necessary rights: films, series, music, games, books, software, typefaces, databases. Also prohibited are direct download sites, mirrors of infringing content, directories of links to such content, and the distribution of keys, licences or means of circumventing technical protection measures.
3.3 Fraud, impersonation and deception
- Phishing, pages imitating a service, a bank, a public authority or a brand
- Online scams, pyramid or Ponzi schemes, fake shops, fake investment or crypto-asset services
- Identity or brand impersonation, fake reviews, fake profiles
- IP address spoofing, falsification of email headers or of domain name registration details
- Automated harvesting of personal data in breach of the rights of the data subjects or of the terms of use of the sites targeted
3.4 Computer attacks and harm to third-party systems
- Distribution or hosting of malware, ransomware, trojans, backdoors
- Command and control centres, networks of compromised machines
- Taking part in a denial of service attack, including amplification and reflection attacks
- Port or vulnerability scanning, intrusion or attempted intrusion into a third-party system
- Brute-force attacks against credentials, whatever the protocol and whatever the target
- Penetration testing carried out without the prior written authorisation of the party responsible for the system targeted
Hosting security tools, for study purposes or for use on your own infrastructure, is not prohibited in itself. Using them against a third-party system is.
3.5 Unsolicited mail and messaging
- Sending bulk email without the consent of the recipients
- Sending from lists bought, rented or collected without a legal basis
- Open mail relay, or a sending service made available to third parties so that they can get around their own limits
- Fraudulent messages by email, by SMS or by telephone call
- Commercial communication with no simple and effective means of unsubscribing
We do not apply any automatic sending counter and we do not inspect the content of our customers' messages, apart from the antispam and antivirus filtering of the mail offers, which you configure yourself, and the assistance features you switch on: that processing is described in the Privacy Policy. A breach of this article comes to light through a report: a complaint from a recipient, the listing of the IP address on a blocklist, an alert from a reputation body or from our network provider.
3.6 Crypto-asset mining
Crypto-asset mining is prohibited across all our offers, including on VPS, unless JSBCloud gives its prior written authorisation. Our virtual machines run on shared nodes: sustained processor load of this kind degrades the service of the other customers.
This prohibition covers mining for your own account as well as for the account of third parties, and it extends to mining software installed on a compromised machine without your knowledge.
3.7 Proxies, anonymisation and relays
- Open relays, proxies or VPNs reachable without authentication
- Anonymisation services open to third parties without identification of their users
- Tor exit nodes
A VPN for personal use, or internal to your organisation, whose users you identify, remains allowed. A Tor relay other than an exit node requires our prior written agreement.
3.8 File sharing, seedboxes and large-scale distribution
- Seedbox type services and peer-to-peer file sharing, except to distribute content in which you hold the rights
- Public mirrors of infringing content
- Anonymous, unmoderated file hosting, where it acts as a relay for unlawful content
- High-audience media streaming without prior agreement, where it saturates the shared link
3.9 Resale, sharing and making available to third parties
Resale, subletting or making our services available to third parties, whether free of charge or for payment, is prohibited unless JSBCloud gives its prior written agreement. Sharing one and the same account between several separate companies is prohibited. Delegating technical access to a service provider remains possible on the terms provided for in your client area.
3.10 Resource consumption
Resource use is governed by the Fair Use Policy, which states, offer by offer, the bandwidth, the transfer volumes and the quotas applied.
Only one automatic mechanism exists on the network: where the page of a VPS offer states an included transfer volume, exceeding that volume brings an automatic reduction of bandwidth until the next period opens. That volume is counted over rolling 30-day periods, independent of your billing cycle. No other network cap is applied automatically, and we do not throttle the processor.
The quotas for disk space, websites, mailboxes, databases, backups and assistance credits are, for their part, applied at the moment you create the resource concerned: they are set out in the Fair Use Policy. Consumption that degrades the service of the other customers is established by a member of our team, then handled through an exchange with you before any measure is taken.
3.11 Artificial intelligence assistants
You may not use the assistants offered in your client area to produce, translate or distribute content prohibited by this document, to circumvent a security measure, or to automate requests for the sole purpose of exhausting the credits of a third party or our own.
These assistants are artificial intelligence systems: you are informed of this at the time you use them, and the content they produce is marked as such where Regulation (EU) 2024/1689 requires it. Where you distribute content produced or altered by these assistants, it is for you to comply with your own transparency obligations. The processing of your exchanges is described in the Privacy Policy.
3.12 Non-exhaustive list
This list is not exhaustive. Any activity contrary to applicable law, infringing the rights of third parties or harming the integrity of our infrastructure is prohibited as well. If you are in any doubt about an intended use, write to our support team before putting it into practice.
4. Network ports and securing your server
We do not block any port at network level, port 25 included.
We do not put any firewall in place on your server at delivery. Depending on the system image you choose, the machine may therefore start with an inactive firewall and all its ports reachable. Check and configure your firewall as soon as the server is delivered: securing it is entirely a matter for you.
Two direct consequences:
- Firewall configuration, the choice of the services exposed and their updating are entirely a matter for the Customer. A service exposed without protection and exploited by a third party engages the liability of the Customer.
- Sending mail directly from port 25 exposes the IP address to blocklisting. We recommend going through an external sending relay. Where an address is listed, restoring its reputation is a matter for the bodies concerned and not for JSBCloud.
5. What we measure, and the means we devote to the fight against unlawful content
We are under no general obligation to monitor the content we host, in accordance with Article 8 of Regulation (EU) 2022/2065, and we impose none on ourselves. The breaches listed in Article 3 come to light through a report, through a claim by a rights holder, through an alert from our upstream network or in the course of technical work. They do not come to light through an automated analysis of your servers.
What we measure automatically:
| Measurement | Purpose |
|---|---|
| Network transfer volume | Read every hour on VPS whose offer states an included volume, and compared with that volume |
| Availability of the infrastructure | Operating state of our components, published on our status page |
| Incoming abuse reports | Alerts from our network provider and from reputation bodies, tied to an IP address |
| Access attempts on our interfaces | Logins, two-factor authentication, password resets, sign-ups and requests to our trap pages, the repetition of which brings a temporary block of the IP address across all our sites, from fifteen minutes to seven days depending on the case (detail in Article 12 of the Fair Use Policy) |
The means we devote to the fight against unlawful content:
- a public reporting address, [email protected], monitored by our team;
- the examination of every report by a person, with no automated decision-making;
- priority handling of orders from authorities, carried out within one hour for terrorist content;
- cooperation with our network provider and with reputation bodies;
- immediate reporting to the authorities of the content referred to in Article 7;
- the ability to suspend a service technically across all our hosting platforms.
What we look at, and on what conditions:
- The content of your files, databases, backups, messages and web pages is not inspected. We access it only to carry out a support request of yours, to respond to a security incident or to handle an abuse report.
- No antivirus examination is carried out on the files you host on your servers. The attachments filed in our tickets and the mail flow of the Email Pro offers are, for their part, scanned.
- Our support team has a delivery log that returns the routing metadata of messages (sender, recipient, message identifier, delivery outcome), and not their content. Each search is logged with its author and its criteria.
- Your exchanges with the artificial intelligence assistants are retained and may be read by authorised members of our team, for support purposes and for the fight against abuse.
- Nothing on our side detects prohibited activity on your machines of its own accord.
6. Reporting abuse or unlawful content
Anyone may report to us content or activity they consider unlawful or contrary to this document, at [email protected].
To allow prompt handling, please state:
| Item expected | Detail |
|---|---|
| Identification of the content | Exact address of the page, domain name or IP address concerned and, for a mail sending, the full headers of the message |
| The facts | Description of what is complained of, and date or period of the facts |
| The grounds | The reason why the content or the activity appears to you unlawful or contrary to our rules |
| Your contact details | Name and email address of the notifier, except for a report concerning offences against minors or terrorist content |
| A statement of good faith | Confirmation that the information provided is, to your knowledge, accurate and complete |
These items make the examination easier: they are not a condition of it. An incomplete report is handled as far as possible.
Handling of a report:
- We acknowledge receipt of the report.
- The report is examined by a member of our team. No report gives rise to an automated decision. We are neither judge nor arbitrator of the dispute: we check whether the content or the activity manifestly breaches the law or this document.
- The author of the report is informed of the action taken and of the redress available to them, including bringing the matter before a court.
- Where the measure taken affects a service, the Customer concerned is informed by email and, where the procedure in Article 8 applies, through a ticket opened on their account, setting out the facts complained of, the rule applied, the measure taken and the way to challenge it.
A manifestly abusive or knowingly inaccurate report may engage the liability of its author.
7. Public authorities, legal requests and removal orders
Point of contact for the administrative and judicial authorities: [email protected], or by post to ALTISCORE SAS, 4A avenue Auguste Renoir, 74960 Annecy, France. The languages accepted are French and English.
- Requests and orders from a competent authority are handled as a priority, on the basis of the data we actually hold and nothing else. That data and its retention periods appear in Article 13 and in the Privacy Policy.
- A removal order concerning terrorist content is handled as an absolute emergency: Regulation (EU) 2021/784 requires it to be carried out within one hour of receipt.
- We bring to the attention of the competent authorities, without delay, content falling under harm to minors, terrorism, glorification of crimes against humanity and incitement to hatred or discrimination, and we keep a record of it. For other reported content, we reserve the right to inform the authorities without being bound to do so.
- Where we become aware of matters suggesting that an offence involving a threat to the life or the safety of persons has been committed or is likely to be committed, we inform the authorities immediately.
- We inform the Customer of a measure taken further to an order, except where the issuing authority expressly asks us to defer that information, for the period it states.
8. Procedure applied where abuse is reported
Where a report is tied to a service, we apply the following graduated procedure. The count is kept per service, and not per account.
| Report upheld | Measure |
|---|---|
| 1st | First warning sent to the Customer by email |
| 2nd | Second warning sent to the Customer by email |
| 3rd | Suspension of the service, opening of a ticket on the account of the Customer asking for explanations, and an email informing the Customer of the suspension |
| 4th | Examination by a member of our team, which may lead to termination of the service. No termination is pronounced automatically |
Counting rules, as they are actually applied:
- Several reports received for the same IP address within the same 24-hour period count as a single warning. A service that holds several IP addresses may therefore see several warnings upheld on the same day.
- A report concerning a service already suspended or already terminated is kept as evidence but does not increment the count.
- A warning stops being counted twelve months after it was notified: a service that is not the subject of any new report for twelve months goes back to zero.
- Reactivating a service after suspension does not reset the count to zero: the next report counts as the fourth.
- A report is tied to a service through the IP address allocated to that service. A service with no IP address of its own, in particular shared web hosting, mail or a game server without a dedicated address, cannot be tied automatically: the case is then handled manually, without the procedure above being triggered automatically.
Suspension is a reversible measure: the service is cut off, nothing is destroyed, and it can be restored once the Customer's response has been examined.
9. Immediate measures without prior warning
We reserve the right to suspend or terminate a service immediately, without going through the steps of Article 8, in the following cases:
- Manifestly unlawful content, in particular where it falls under Article 3.1
- Harm to the integrity, the security or the stability of our infrastructure or of that of a third party
- An attack under way originating from the Customer's service, including where it results from a compromise for which they are not responsible
- An order from a competent authority
- An order, a formal notice or an action brought against ALTISCORE SAS by a third party or by an authority, on account of that service
The measure chosen is proportionate to the facts: we suspend rather than terminate whenever suspension is enough to bring the disturbance to an end. In all these cases, the Customer is informed of the measure and of its grounds by email and through a ticket opened on their account, as soon as the measure has been applied.
10. Responding, explaining and challenging
Any measure taken further to a report gives rise to a ticket on your account, stating the IP address concerned, the facts complained of, the evidence passed on where it exists and the rule applied.
- You have 7 days from the opening of the ticket to respond to us and explain the use made of the machine.
- You may attach anything useful: logs, configuration, evidence of compromise, corrective measures undertaken.
- We endeavour to examine your response within 5 business days. Exceeding that period is not penalised in itself, but it does not extend the suspension beyond what the examination requires, and it leaves you every form of redress available under the general law.
- The decision, whether favourable or not, is communicated to you through the same ticket, with its grounds.
- You may also challenge the measure in writing at [email protected], from the email address of the account. JSBCloud replies within 15 days.
- If you do not respond, the suspension is maintained and termination may be initiated. A ticket that closes automatically for want of a response does not end the case and does not lift the suspension.
- Reactivating a service after examination is a reasoned decision, taken in the light of the seriousness of the facts, their repetition, the corrective measures provided and your cooperation.
After our response, a consumer Customer may send a written complaint to [email protected], to which JSBCloud endeavours to reply within 15 days. Where that complaint is not resolved, they have the right to refer the matter free of charge to a consumer mediator, on the terms of Articles L612-1 et seq. of the French Consumer Code and of Article 37 of the General Terms and Conditions. ALTISCORE SAS has joined CM2C, a consumer mediator listed by the French Commission for the Evaluation and Control of Consumer Mediation (CECMC), whose contact details are set out below. The Customer may, in every case, bring the matter before the competent court. None of these routes is subject to the procedure described above being exhausted first.
Consumer mediator. In accordance with the provisions of the French Consumer Code on the consumer dispute mediation process, after having contacted us and failing a reply that satisfies you, you have the possibility of referring the matter free of charge to a consumer mediation procedure with:
- CM2C
- Address: 49 rue de Ponthieu, 75008 PARIS
- Telephone: 01 89 47 00 14
- Website: https://www.cm2c.net/declarer-un-litige.php
- Email: [email protected]
11. Termination for abuse and fate of the data
Termination pronounced for abuse is decided by a member of our team, in the light of the criteria in Article 10.
Before termination. For as long as the service is only suspended, you may ask by ticket for the return of the lawful data it contains. We act on that request within 7 days where recovery is technically possible, excluding data connected with the facts complained of and data we are required by an authority to retain. For the offers where we act as a processor within the meaning of Article 28 of Regulation (EU) 2016/679, that return is exercised on the terms provided for there.
On termination. Termination brings the immediate and definitive destruction of the service and of everything it contains: virtual machine, game server, website, mailboxes, allocated IP addresses and associated records. This operation is irreversible and no copy can be returned afterwards. So ask for your data back during the suspension, and not after it.
Where termination is pronounced immediately under Article 9, there is no suspension phase: destruction takes place at the same time as the measure.
The fate of the sums paid is settled in Article 14.
12. Account ban
Independently of any sanction against a service, an account may be banned in the following cases, and in those cases only:
- Fraud or attempted fraud, in particular the use of a means of payment of which the account holder is not the cardholder, or which is the subject of a payment dispute
- Harm to the security of our systems or of those of a third party, carried out from the account
- Hosting of content falling under Article 3.1
- A further breach after a termination pronounced for abuse, or the opening of an account intended to circumvent such a measure
- Provision of a false identity or false contact details, where this obstructs the handling of abuse
A ban may be pronounced on a temporary or permanent basis. In both cases it brings:
- Immediate termination of all the active services on the account, with destruction of the servers, release of the IP addresses and cancellation of the current subscriptions
- Immediate invalidation of the sessions and loss of access to the client area
Lifting a ban, including on the expiry of a temporary ban, restores access to the account but does not restore the services: the machines and the data destroyed are permanently lost.
The grounds for the ban are communicated to you by email, and they are displayed when you try to log in. To challenge it, write to [email protected] from the email address of the account: the decision taken after re-examination is communicated to you, with its grounds, within 15 days. The routes of redress recalled in Article 10, complaint, consumer mediation and the competent court, are open as well. The fate of the sums paid is settled in Article 14.
13. Retention of evidence and records
| Data | Retention |
|---|---|
| Abuse files, reports received, technical log of their receipt, chronology of the measures and copies of the messages sent | Up to 5 years after the case is closed |
| Log of the IP addresses used to log in to the client area | 12 months from the last appearance of the address |
| Log of the emails we send | 90 days, content and metadata included |
| Log of mailbox access through the AltisMail webmail (date, action, IP address, browser) | Lifetime of the account, deleted with the account |
| Closed tickets | 3 years |
| Invoices and accounting records | 10 years |
Two important points:
- The IP address log covers only logins to your client area and to our interfaces. Logins to the hosted services themselves, in particular SSH, FTP or the game panel, are not logged on our side: if you need traceability over those accesses, it is for you to put it in place. Mailbox access through the webmail is an exception, and that log is available to you in your client area.
- The detail of the processing carried out, together with your rights of access, rectification, erasure and objection, appears in the Privacy Policy.
14. Financial consequences
- Where termination is pronounced for abuse, the unperformed fraction of the price paid in advance is returned to the Customer, the current period and the associated options included, pro rata to the days remaining from the termination. The only exception is a serious breach that has caused harm to JSBCloud or to a third party: the amount withheld is then reasoned and proportionate to the harm suffered. The refund is made on the terms set out in Article 18 of the General Terms and Conditions.
- A suspension pronounced while a report is being examined gives rise to no refund where the breach is established. Where the report turns out to be unfounded, the service is restored and the period of suspension is credited pro rata.
- Service credits granted as a goodwill gesture are cancelled. The prepaid balance, the purchased credits and the credits corresponding to compensation for an incident already acknowledged are returned to the Customer, on the terms set out in Article 18 of the General Terms and Conditions, after deduction of the sums still owed and, where applicable, of the costs of handling abuse set off on the terms provided below.
- A business Customer indemnifies JSBCloud against any third-party claim connected with the content they host or with the activities carried out from their services, excluding claims resulting from a fault of JSBCloud. As regards a consumer Customer, compensation for damage caused by their fault is sought on the terms of the general law.
- The liability of JSBCloud is governed by Article 28 of the General Terms and Conditions. This document adds no exclusion to it and sets aside no right that the law confers on a consumer Customer.
Costs of handling abuse. The costs we incur in handling abuse, in particular the time spent by our team, restoring affected infrastructure, the external costs incurred and answering the claim of a third party, may be charged to the Customer at fault. They are governed by Articles 18 and 23 of the General Terms and Conditions, whose guarantees this paragraph repeats:
- Actual costs and statement. Only the costs actually incurred are claimed. They are the subject of a detailed statement given to the Customer, setting out the time spent and the rate applied, the external costs and the third-party fees, with supporting evidence. The time spent is valued at the published hourly rate of 70 euros excluding tax, that is 84 euros including all taxes at the French rate of 20 percent, the amount applied to a consumer Customer resident in France, the tax of their own country applying if they reside elsewhere in the European Union, and counted in units of fifteen minutes, each unit started being counted in full. No flat amount is set unilaterally.
- Set-off against the sums to be returned. These costs are set off against the sums we have to return to the Customer: the unused fraction of the price paid in advance, the prepaid balance and the purchased credits. The set-off takes place only after that statement has been notified and a period of 15 days has expired, during which the Customer may challenge it in writing at [email protected]. A challenge suspends the set-off until our reasoned reply, sent within 15 days.
- Remaining balance. Where the costs exceed the sums to be returned, the difference is the subject of an ordinary invoice, payable on the usual payment terms of the General Terms and Conditions.
- Cap. For a consumer Customer, these costs are capped at 150 euros including all taxes per abuse case. For a business Customer, the actual costs are due, expressed excluding tax and with no cap.
- Reciprocity. Where JSBCloud is in serious breach of its own obligations towards the Customer, the Customer is entitled to equivalent compensation, established on the same rules of justification and statement, then set off against the sums they owe us or paid by us.
These costs are not cumulative with the amount withheld for harm mentioned above: one and the same expense is claimed only once.
15. Related documents
- General Terms and Conditions, of which this document forms an integral part
- Fair Use Policy, for the volumes, the bandwidth and the quotas of each offer
- Privacy Policy, for the processing of personal data
16. Changes to this document
JSBCloud may change these rules, in particular to follow changes in the law or in its offers. Each change gives rise to a numbered version, which is retained.
- The rules that apply to a current contract are those in force on the date of the order; those that apply to a renewal are the ones in force on the date of that renewal, in accordance with Article 35 of the General Terms and Conditions.
- A substantial change, in particular the addition of a new prohibition, is brought to the attention of customers by email. It applies to current contracts only on the expiry of a period of 30 days from that information. A Customer who does not accept it may terminate the service concerned, free of charge, before it takes effect, and obtains a pro rata refund of the period paid for in advance and not used.
- Changes required by a change in the law apply from the date the law sets.
- A copy of any earlier version is provided on simple request sent to [email protected].
This document exists in French and in English. In the event of divergence, the French version prevails, without depriving a consumer Customer of the protection attached to the language in which the contract was offered to them.
17. Contact
- Reporting abuse or unlawful content: [email protected]
- Complaints, challenging a suspension or a ban, administrative and judicial authorities: [email protected]
- General questions, support and a copy of an earlier version: [email protected] or a ticket from your client area
- Personal data: [email protected]
Version 5 of these rules.
Last updated: 21 September 2026

