Determines the purposes for which our cloud infrastructure services may not be used. It covers prohibited uses, the measures applied in the event of a breach and the channel for objection.
1. Purpose and scope
1.1. This Acceptable Use Policy (hereinafter the “Policy”) determines the purposes for which the cloud infrastructure services provided by TTEN Teknoloji A.Ş. (hereinafter “tten”) may not be used. The Policy contains the minimum rules that everyone using the service must comply with.
1.2. The Policy covers all services provided by tten through the following domain names:
tten.net (promotional site)
store.tten.net (online sales)
core.tten.net (Core Panel)
api.tten.net (Public API)
mcp.tten.net (tten MCP Server)
The scope covers the virtual servers, virtual data centers, storage space and network resources you create through these domain names, together with all software and data you run on them.
1.3. The Policy applies regardless of whether you use the service on your own behalf or on behalf of the organization you represent.
2. Definitions
2.1. Customer / you: the natural or legal person that establishes a service relationship with tten.
2.2. Service: the entirety of the virtual server, virtual data center, storage, network and management interfaces provided by tten.
2.3. Sub-user: the persons who access your account, your virtual data center or your servers with your authorization, together with your end users who use the service through you.
2.4. Breach: the occurrence of an act prohibited under this Policy, or the use of your resources in such an act.
3. Relationship with the Terms of Use
3.1. This Policy is applied together with the tten Terms of Use and is an integral annex thereto. The general matters regulated in the Terms of Use (intellectual property, limits of liability, applicable law, competent court, amendments to the agreement, processing of personal data) are not repeated in this Policy. This Policy regulates only the rules specific to hosting and infrastructure use.
3.2. For information on the processing of your personal data please refer to the Privacy Notice (KVKK), and for the use of cookies to the Cookie Policy.
3.3. In the event of a conflict between this Policy and the Terms of Use, this Policy applies on matters relating to hosting use. The general order of precedence among the documents is set out in section 1 of the Terms of Use.
4. Basic principle and limit of responsibility
4.1. tten is an infrastructure service (IaaS) provider. The operating system of your servers and everything running on it are under your control; root privileges are yours. The details of the distribution of responsibility are defined in the Responsibility Model.
4.2. This control means that you are also responsible for what runs on your servers and for the traffic leaving them. tten does not routinely inspect the content of your servers and does not record your in-server operations (SSH sessions, application logs). The operation records kept by tten cover operations performed through Core Panel and the Public API.
4.3. The fact that tten does not routinely inspect your content does not mean that it will not intervene when it becomes aware of a breach. The powers defined in Article 14 are reserved.
4.4. tten accesses the inside of your server in only two cases: (a) upon your written request and only to the extent required by your request, (b) if there is a legal obligation such as a lawful decision of a competent authority. Apart from these, the inside of your server is your layer and is not accessed by tten.
5. Unlawful content and activity
5.1. You may not use the service for any purpose contrary to the legislation of the Republic of Türkiye, to the international conventions to which it is a party, or to the laws of the countries in which the service is provided or the content is accessible.
5.2. The following are prohibited in all cases:
Any kind of content relating to the sexual abuse of children
Content that propagandizes for terrorist organizations, incites the commission of crimes or praises violence
Content that targets the honor and reputation of persons or violates the privacy of private life
Gambling, unlawful betting and lottery activities not permitted by the legislation
Trafficking in narcotics, arms trafficking and other commercial activities prohibited by the legislation
Structures set up for the purpose of fraud, fake investment and payment systems
Hosting and distribution of stolen data, leaked credentials or credit card information
5.3. If your activity is subject to a permit, licence or notification under the legislation, obtaining the necessary permits and keeping them up to date is your responsibility.
6. Intellectual property and copyright
6.1. You may not host or distribute any work, software, database, film, music, game, visual material or broadcast without the permission of the rights holder.
6.2. Hosting and distribution of unlicensed software and of tools serving to circumvent licence restrictions (crack, keygen, licence server emulation) is prohibited.
6.3. You are prohibited from setting up domain names or content structures that infringe trademark rights or impersonate the identity of another organization.
6.4. When a copyright infringement notice is received, tten operates the general notice process set out in Article 15. No separate procedure is applied for copyright.
7. E-mail and bulk sending
7.1. You may not send unsolicited bulk e-mail (spam) through your servers. In every recipient list to which you send bulk messages, the recipients must have given express consent (opt-in) to the sending and the record of that consent must be capable of being proven.
7.2. If you send commercial electronic messages, complying with Law No. 6563 and with the obligations of the Message Management System (İYS) is your responsibility. Every message must contain a working means of unsubscribing (opt-out).
7.3. Concealing, altering or impersonating the sender identity is prohibited. Fake “From”, “Reply-To” and “Return-Path” headers, sending from a domain name belonging to someone else and operating an unauthorized open relay fall within this scope.
7.4. You may not send messages to purchased or scraped e-mail lists, or to lists of unclear origin.
7.5. The same prohibition also applies to bulk sending through short messages, instant messaging, automated calls and similar electronic channels.
8. Malicious software, phishing and attack infrastructure
8.1. You may not host or distribute malicious software (viruses, worms, trojans, ransomware, spyware, keyloggers), nor act as an intermediary in its spread.
8.2. You may not host phishing pages. Any structure that imitates the login screen of a bank, a public institution, a payment provider, an e-commerce site or another organization and collects credentials from users falls within this scope.
8.3. You may not operate a botnet command-and-control (C2) server, a ransomware key server, a malware distribution point, an exploit kit or a credential harvesting infrastructure.
8.4. If you need to host malicious samples for the purposes of malware analysis, security research or training, it is your responsibility to ensure that the samples are not accessible from the outside and that they are run in isolation. No separate exception application is required.
9. Network abuse
9.1. You may not act as the source of any attack targeting the tten network or third-party networks accessed through tten. The following are prohibited:
Carrying out or participating in denial-of-service attacks (DoS/DDoS), or hosting services used for such attacks (booter, stresser)
Performing port scanning, vulnerability scanning, brute-force password attempts and penetration testing against systems for which you have no authorization
Intercepting or eavesdropping on network traffic without authorization, or spoofing IP or MAC addresses
Leaving services such as DNS, NTP and memcached open to reflection (amplification) attacks
Generating packets with a forged source IP address
9.2. You may have penetration testing carried out against your own servers, provided that you notify tten before the test begins. Notification is made through a Core Panel support request. If you are testing a third-party system, you must have the written permission of the owner of the target system. If the target of the test is the tten infrastructure itself, the prior written permission of tten is required. tten does not otherwise operate a responsible disclosure programme.
9.3. In the Virtual Data Center service your servers are on a single isolated VLAN and communicate directly with each other. In the Cloud Server service the server operates on its own with its own public IP address. In both cases you are responsible for everything you do within this network. You define the ports you open to the internet yourself, from Core Panel or through MCP. Which service is exposed to the outside and the security of that service are your responsibility.
9.4. A server that is not secured, not updated or has been compromised turning into a source of attack is also deemed a breach of this article. The fact that your server has been compromised without your knowledge does not eliminate your responsibility, but tten takes this into account in the order of intervention.
9.5. You may not run a Tor exit node, an open proxy or a publicly available VPN service on your servers. A personal VPN you set up for your own use falls outside the scope of this prohibition.
9.6. If the IP address allocated to you is placed on a blacklist (spam, abuse or reputation lists) because of your use, you may request an IP change. If the blacklisting arises from your use, the allocation of a new IP is subject to a fee. In the event of a repetition of the same behavior, the measures in Article 14 are applied.
10. System and resource use
10.1. The tten infrastructure is a shared infrastructure. You may not make use that exceeds the limits of the package you have purchased and thereby lowers the service quality of other customers.
10.2. Any attempt to break out of the virtualization layer, to access the resources of other customers or to gain unauthorized access to tten management systems is prohibited.
10.3. You may not call the Core Panel, Public API and MCP interfaces with automated tools in a manner that overloads them.
10.4. The limit of resource and traffic use is the limits stated in the definition of the package you have purchased. Limits vary from package to package. Use exceeding the package limit is not stopped; the excess part is reflected in your invoice. Current limit values are set out on the package page and in your order summary.
11. Crypto asset mining
11.1. Crypto asset mining may not be carried out on tten servers. This rule covers the mining software itself, joining a mining pool and similar workloads that generate the same load.
11.2. The rationale for the rule is the shared resource model: a continuous full CPU load lowers the performance of other customers on the same hardware.
11.3. Mining on someone else’s resources without authorization (cryptojacking) and using a compromised system for this purpose are separately prohibited under Article 8.
12. Sub-users and customer responsibility
12.1. If you use the service in order to provide it to your own customers (reselling, hosting resale, application service provision), it is your obligation to ensure that your own users comply with this Policy.
12.2. You must apply to your sub-users rules that are at least as protective as this Policy, reflect these rules in your own agreement, and retain the authority to intervene with your own user in the event of a breach.
12.3. You are directly responsible to tten for the acts of your sub-users. tten identifies the source of the breach through your account and applies the sanction to you.
12.4. In the case of a notice originating from a sub-user, you are expected to be able to identify the user concerned and to respond to tten within a reasonable time.
13. Your data, backup and limit of liability
13.1. You are the owner of the data on your servers. You are responsible for the accuracy of the data, for its compliance with the law and for its retention.
13.2. The scope of backup varies by product: in the Virtual Data Center (VDC) service, your servers are backed up automatically every day and the backups are kept for 7 days. In the Cloud Server service, backup is an optional additional service. When you add it to your package, your backup is taken every day and kept for 3 days. You decide which backup to restore and when. You start the restore yourself through Core Panel.
13.3. A snapshot is not a backup. A snapshot is a rollback point taken before a change and is deleted automatically after 24 hours. If you have a long-term retention need, use the backup channel.
13.4. The fact that tten takes backups does not eliminate your responsibility for your data. Keeping data that is critical for you outside the tten infrastructure as well is your choice and is recommended. A need to roll back to a version older than the retention window is not met by tten’s retention period.
13.5. The limits of the backup service are as follows:
No commitment is given as to the time required to restore from a backup. You start the restore yourself from Core Panel.
tten assumes no liability if the backup copy itself turns out to be corrupt or unusable. It is recommended that you also keep backups of your critical data outside tten (Article 13.4).
You are responsible for data you delete yourself. Restoring from a backup within the retention window as of the moment of deletion is likewise at your disposal.
When the service ends, your backups are deleted. No backup is retained after the end of the service.
14. tten’s powers in the event of a breach
14.1. When tten determines that this Policy has been breached, or when it receives a reasoned notice to that effect, it may apply the following measures. As a rule, the measures are operated in the following order:
Warning and request for correction. The breach is notified to your account and you are given 48 hours to correct it or to respond.
Partial restriction. The resource, service or network access subject to the breach is limited, and the rest of the service continues to operate.
Suspension. Access to the service is closed. Your data is not deleted at this stage.
Termination. The service relationship is brought to an end.
14.2. In the following cases tten may apply suspension directly, without waiting for a warning:
Your being the source of an ongoing attack
Your hosting content relating to the sexual abuse of children
Your operating an active phishing or malware distribution point
The existence of a lawful decision of a competent authority
14.3. In non-urgent breaches the timetable of measures is as follows: 48 hours are granted for a response to the warning and for correction. If no correction or response is received within this period, the service is suspended. A suspended service may be terminated if the breach is not remedied within 14 days. In the urgent cases set out in Article 14.2, no warning is awaited. The service fee continues to accrue during the suspension. When the breach is remedied, your service is reopened and no additional fee is charged for this.
14.4. As a rule, suspension is applied only to the server subject to the breach. If the breach concerns the virtual data center as a whole, or if it is repeated within the same account, the measure may be extended to the entire virtual data center.
14.5. If you believe that the measure has been applied incorrectly, you may object by opening a support request through Core Panel. Suspension only stops your server. Your Core Panel access, your support channel and your data remain available during the suspension.
14.6. Suspension and termination applied on account of a breach do not eliminate tten’s rights to claim in respect of the damage incurred.
15. Abuse notice channel and tten’s response process
15.1. You may report abuse originating from the tten infrastructure to [email protected].
15.2. In order for your notice to be processed, it is expected to contain the following:
The IP address or domain name subject to the breach
The date and time of the incident, with time zone information where possible
The type of breach and a short description of it
Evidence (log record, e-mail header, screenshot, packet sample)
Contact information through which you can be reached
15.3. When tten receives a notice it carries out the following in order: it records the notice, determines which customer the resource concerned belongs to, forwards the notice to the customer, and applies the measures in Article 14 to the extent required.
15.4. Notices are assessed as soon as possible. tten does not commit to a numerical period for acknowledgement, examination and notification of the outcome.
15.5. Notices are received and assessed during business hours.
15.6. Requests coming from competent authorities are assessed separately within the framework of the legislation. Such requests are not subject to the notice process set out in this article.
16. Changes to the Policy and entry into force
16.1. tten may update this Policy. The current text is published on tten.net and enters into force on the date of publication.
16.2. No prior notice is given separately for changes to the Policy. A change enters into force upon publication pursuant to Article 16.1. Price increases are the subject not of this Policy but of the Distance Sales Agreement, and are notified by e-mail at least 15 days before they enter into force. Material changes producing results to your detriment are likewise notified to your registered e-mail address at least 15 days before they enter into force.
16.3. The effective date of each version is shown at the beginning of the document.
17. Contact
TTEN Teknoloji A.Ş. Ziyapaşa Tax Office 8591442515 · Trade Registry No 94489 (Adana) · MERSİS 859144251500001 Cemalpaşa Mah. Gazipaşa Blv. No: 20/11 Seyhan / Adana [email protected] · 0850 307 31 31