1. Purpose
This Acceptable Use Policy (AUP) helps protect Res-Q IT Services, our clients, users, suppliers, networks, systems and the wider community from unlawful, abusive, unsafe or unreasonable use of services.
This AUP applies to all services supplied, managed, supported, resold or made available by Res-Q, including IT support, managed services, remote access, monitoring, cybersecurity tools, cloud services, email, hosting, internet access, NBN, mobile, VoIP, SIP, fixed voice, data, software, hardware and website services.
You are responsible for the conduct of your authorised users, staff, contractors, guests and anyone else who uses the services through your account, systems, equipment or credentials.
2. General rule
You must use the services lawfully, responsibly and reasonably. You must not use the services in a way that:
- breaks the law or encourages unlawful activity;
- harms or threatens any person, system, network, service or property;
- interferes with the operation, security or integrity of the services or any third-party service;
- infringes another person’s rights;
- creates an unreasonable burden on any network, platform, supplier or support resource;
- exposes Res-Q, our suppliers or other clients to legal, regulatory, operational, security or reputational risk; or
- breaches any third-party terms, carrier rules, software licence, acceptable use policy or service schedule that applies to the service.
3. Prohibited activities
You must not use the services to engage in, facilitate or attempt any of the following:
- unlawful, fraudulent, deceptive, misleading or criminal conduct;
- scams, phishing, social engineering, impersonation, credential harvesting or identity theft;
- sending spam, unsolicited commercial electronic messages, bulk messages or marketing messages without required consent, sender identification and unsubscribe facilities;
- nuisance, threatening, abusive, defamatory, harassing, discriminatory or malicious communications;
- malware, ransomware, viruses, worms, trojans, spyware, botnets, unauthorised cryptomining or malicious code;
- hacking, vulnerability scanning, penetration testing, port scanning, password attacks, credential stuffing, denial-of-service attacks or security testing without written authorisation;
- unauthorised access to, monitoring of, interception of, interference with or modification of systems, networks, accounts, data or communications;
- spoofing, manipulating caller ID, sender IDs, headers, routing information or addressing information in a deceptive or unlawful way;
- hosting, storing, transmitting or making available content that is unlawful, harmful, abusive, exploitative, infringing, malicious or otherwise prohibited by law;
- infringing copyright, trade marks, patents, designs, confidential information, privacy rights or other rights;
- bypassing service limits, authentication, licensing, payment controls, content filters, security controls or usage restrictions;
- resupplying, reselling, sharing or making a service available to third parties unless we have approved this in writing;
- using consumer or small business services for bulk termination, call centre operations, mass messaging, automated dialling, high-volume SMS, SIM boxing, callback services or similar use without the correct service plan and written approval; or
- any activity that causes or may cause a carrier, supplier, regulator or law enforcement body to require blocking, suspension, investigation or remediation.
4. Security obligations
You must take reasonable steps to keep your systems, accounts and users secure. This includes:
- using strong passwords and multi-factor authentication where available;
- keeping operating systems, applications, firmware, security tools and devices patched and supported;
- protecting administrative accounts, remote access, APIs, keys and tokens;
- not sharing passwords or credentials with unauthorised people;
- disabling access promptly when users leave or no longer require access;
- maintaining appropriate endpoint protection, backups and logging;
- not running open mail relays, open proxies, unauthorised file-sharing services or exposed systems that create security risk;
- promptly investigating and remediating compromised systems; and
- notifying us promptly of any suspected unauthorised access, malware, data breach, credential compromise, service misuse, spam issue or security incident that may affect the services.
5. Email, SMS, calling and marketing
If you use services for email, SMS, voice, messaging or marketing, you must comply with the Spam Act, Do Not Call Register rules, privacy laws, telecommunications rules and all carrier or supplier requirements.
Marketing messages must only be sent where you have the required consent or other lawful basis. Messages must identify the sender, include accurate contact details and provide a functional unsubscribe method where required.
You must not use the services for nuisance calls, robocalls, scam calls, CLI spoofing, misleading sender IDs, bulk unsolicited messages, unlawful telemarketing, phishing or other abusive communications.
6. Network, bandwidth and fair use
Plans described as unlimited, unmetered or similar are still subject to this AUP, fair use, supplier policies, technical limits, reasonable use and the intended purpose of the service.
Use is unreasonable if it materially affects service performance, creates congestion, disrupts other users, causes supplier complaints, triggers security alerts, generates abnormal costs, or is inconsistent with the service type, plan, quote or customer profile.
We may ask you to reduce, change or stop unreasonable use, move to a more suitable plan, implement controls, or pay additional charges where applicable.
7. Content and hosted services
If we host, manage, support or provide access to systems that store or transmit content, you are responsible for that content and for ensuring that you have all necessary rights, consents and permissions.
We do not routinely review content, but we may investigate, remove, block, suspend or disable content or access if we reasonably believe it breaches this AUP, a supplier policy or the law, or if we are required or requested to do so by a supplier, carrier, regulator, court or law enforcement body.
8. IP addresses, numbers and identifiers
IP addresses, phone numbers, sender IDs, domain names, usernames and other identifiers may be subject to third-party rules and are not owned by you unless expressly stated by law or in writing.
You must not use identifiers in a misleading, deceptive, fraudulent or unlawful way. You must not transfer, port, advertise or publish identifiers in a way that breaches law, supplier rules or our instructions.
9. Monitoring and investigation
We may monitor service performance, security events, traffic patterns, logs, usage, spam reports, abuse reports and supplier notifications to operate and protect the services.
If we investigate a suspected breach, you must reasonably cooperate, provide information, preserve relevant logs or evidence, stop harmful activity and remediate affected systems.
10. Consequences of breach
If we reasonably believe this AUP has been breached, or if a supplier, carrier, regulator or law enforcement body requires action, we may take one or more of the following steps:
- warn you or request remediation;
- block, filter, quarantine or remove traffic, content, messages, calls or access;
- rate-limit, shape, restrict or suspend part or all of a service;
- disable accounts, credentials, numbers, devices or systems;
- notify affected parties, suppliers, carriers, regulators or law enforcement where appropriate;
- charge reasonable remediation, investigation or support costs;
- terminate the affected service or agreement; or
- take any other action reasonably necessary to protect people, systems, networks, services, Res-Q, suppliers or other clients.
We will try to give notice before suspension where reasonable, but we may act without prior notice where necessary to protect security, service integrity, public safety, compliance or other users.
11. Reporting abuse
To report suspected abuse involving Res-Q services, contact [email protected] and include:
- the date and time of the issue;
- the service, IP address, phone number, domain, email header, message ID, log or other identifier involved;
- a description of the issue;
- copies of relevant logs, screenshots or messages; and
- your contact details.
12. Relationship with other terms
This AUP forms part of your agreement with us. It applies in addition to our Website and Service Terms, Privacy Policy, Telecommunications Service Terms, any quote or service schedule, and any third-party acceptable use policy or supplier terms that apply to the services.
13. Changes
We may update this AUP from time to time. The updated version applies from the date it is published on our website or the date we notify you.