Draft for review by legal counsel — not yet in force.
Acceptable Use Policy
This Policy describes what may not be hosted on or done with birden, how shared resources are protected, and what happens when the rules are broken. It is part of the Terms of Service.
- Operator
- WHILETRUE LLP, BIN 250640007871, [Registered address, Republic of Kazakhstan]
- Last updated
- 2026-10-05
- Effective date
- [Effective date]
1.Purpose and scope
1.1birden is shared infrastructure: builds, containers, storage and network capacity are used by many customers at once. This Acceptable Use Policy (the "Policy") protects those customers, the Operator and third parties.
1.2The Policy applies to every account, project, deployment, preview and production hostname, custom domain and document storage database on the Service, and to everyone who uses the Service, including users of the Customer's applications where the Customer permits their actions.
1.3Capitalised terms have the meaning given in the Terms of Service.
2.Prohibited content
2.1Customers must not upload, deploy, store or distribute through the Service any content that:
- is illegal under the law of the Republic of Kazakhstan or infringes the rights of third parties, including copyright, trademark and personal data rights;
- contains child sexual abuse material, or promotes terrorism, extremism, violence or hatred on the grounds of ethnicity, religion, gender or other protected characteristics;
- contains malware, exploits, phishing pages, fake login forms, or any software designed to gain unauthorised access to systems or data;
- impersonates a person, organisation, state body, bank or payment service, or misleads visitors about the origin of a site;
- offers goods or services whose sale is prohibited or requires a licence the Customer does not hold (narcotics, weapons, unlicensed gambling, unlicensed financial services, counterfeit goods);
- is pornographic, or sexually explicit material involving persons who have not given consent;
- is spam, link farms or content whose primary purpose is to manipulate search engines.
3.Prohibited activities
3.1Customers must not use the Service, including build containers and application containers, to:
- mine or stake cryptocurrency, run proof-of-work or similar computational schemes, or rent out computing capacity;
- operate open proxies, VPN exit nodes, Tor relays, BitTorrent clients or other services whose main purpose is to relay traffic that does not belong to the Customer's application;
- send unsolicited bulk email or messages, or run mail servers without the Operator's written permission;
- scan, probe or test the vulnerability of networks or systems that the Customer does not own, or attack them (denial of service, credential stuffing, brute force);
- attempt to access other customers' projects, data, containers or databases, or the Operator's infrastructure, or to escape the build or runtime sandbox;
- circumvent plan limits, metering, rate limits, or create multiple free accounts for one person or organisation;
- resell the Service as a hosting product to third parties without a written agreement with the Operator;
- use the Service for applications whose failure could endanger life, health or safety (medical devices, emergency services, control of hazardous equipment).
4.Resource use
4.1Each plan has limits on projects, build minutes, concurrent builds, build duration, artifact size, document storage, traffic and request rate. Limits are shown in the dashboard and at birden.kz#pricing. When a limit is reached, the corresponding action is refused until the next period or an upgrade.
4.2Builds are intended to compile and bundle the Customer's application. Using build minutes for unrelated computation, long-running tasks, or continuous jobs is not permitted.
4.3Application containers are intended to serve the Customer's web application. Background workers, cron-style jobs that run continuously, or processes that saturate CPU for extended periods may be limited or stopped.
4.4Document storage is intended for the Customer's application data. Using it as a general file store, backup target or cache for third-party datasets is not permitted. Quotas are enforced; when a quota is exceeded the database becomes read-only until usage falls below the quota or the plan is upgraded.
4.5Traffic that is clearly disproportionate to the plan, or that originates from an attack on the Customer's site, may be rate-limited or temporarily blocked to protect other customers. The Operator will inform the Customer where possible.
5.Security
5.1Customers must keep account credentials, GitHub installations and document storage credentials confidential and rotate them if they suspect a leak. Credentials can be rotated in the dashboard.
5.2Customers must keep their application dependencies reasonably up to date and must not deliberately deploy software with known critical vulnerabilities.
5.3Security research against the Service itself is welcome only with prior written agreement. Report vulnerabilities to support@birden.kz; we will acknowledge the report within 3 business days and will not take legal action against researchers acting in good faith within the agreed scope.
6.Enforcement
6.1The Operator may investigate suspected violations and may review deployment metadata, logs and, where necessary, deployed content for that purpose.
6.2Depending on the severity, the Operator may: send a warning and set a deadline for remedy; stop a specific deployment or disable a custom domain; suspend a project or the account; terminate the agreement. Severe cases (malware, phishing, illegal content, attacks on other systems, abuse that threatens the Service) are stopped immediately without prior notice.
6.3The Operator may preserve and, where required by law, disclose evidence of violations to competent state authorities of the Republic of Kazakhstan.
6.4Fees paid for a period in which the account was suspended for a violation of this Policy are not refunded.
6.5A Customer who believes an enforcement action was mistaken may appeal by writing to support@birden.kz. Appeals are considered within 10 business days.
7.Reporting abuse
7.1Anyone may report content or activity that violates this Policy to support@birden.kz. Please include the URL, a description of the problem and, for rights-holder complaints, evidence of the right claimed and contact details.
7.2The Operator reviews reports within 3 business days and informs the reporter of the outcome where possible, without disclosing personal data of the Customer.
8.Changes
8.1The Operator may update this Policy. The current version is published at birden.kz/legal/acceptable-use with the date of the last update. Material changes are announced at least 15 calendar days in advance by email or in the dashboard.