Acceptable Use Policy
Last updated
Effective date
This Acceptable Use Policy ("AUP") applies to all services provided by Duplicati Inc ("Duplicati", "we", "us"), including the Duplicati Console, Duplicati Enterprise, Duplicati-provided backup storage, the managed backup service, and the remote-management relay (collectively, the "Services"). By using any of the Services you agree to this AUP. It forms part of our Terms of Service and, where applicable, your Cloud Service Agreement; capitalized terms not defined here have the meanings given there. This AUP exists to protect the security, integrity, and reliability of the Services for all customers.
Prohibited uses
You must not use the Services, or permit anyone using your Account to use them, to:
Engage in any unlawful activity, or store, transmit, or distribute material that violates applicable law or regulation, including laws on export control and sanctions.
Store, distribute, or transmit material involving the sexual exploitation or abuse of children. We report such material to the relevant authorities.
Upload, store, or distribute viruses, malware, ransomware, spyware, or other harmful code, except as inert samples in a backup set that is not used to distribute them.
Engage in phishing, spoofing, impersonation, or other deceptive practices, including impersonating Duplicati or another customer.
Attempt to gain unauthorized access to any account, organization, system, or network, including another customer's organization or data, or any Duplicati system you are not authorized to use.
Probe, scan, or test the vulnerability of the Services except as permitted by our Vulnerability Disclosure Policy.
Interfere with or disrupt the security, integrity, or performance of the Services or of networks connected to them.
Infringe the intellectual property, privacy, or other rights of any person.
Harass, threaten, or defame any person, or store or distribute content intended to do so.
Resell, sublicense, or provide the Services to third parties except under a reseller or managed-service arrangement agreed with Duplicati in writing.
Regulated and sensitive data
Protected Health Information. You must not store, transmit, or process Protected Health Information or other data subject to HIPAA through the Services unless you have executed a Business Associate Agreement with Duplicati and the relevant Organization has been designated a Confidential Organization, as set out in Section 3.4 of the Terms of Service. Placing such data in any other Organization is a material breach of this AUP.
Other regulated data. If your data is subject to other sector-specific rules (for example payment card data under PCI DSS, or data subject to export controls), you are responsible for determining whether the Services are suitable and for configuring your backups, including encryption, accordingly. Duplicati does not represent that the Services meet any such standard unless stated in writing.
Encryption. You are responsible for choosing and safeguarding your encryption passphrase. For Confidential Organizations and self-hosted backups, Duplicati never holds your key; if you lose it, your backups cannot be recovered by Duplicati or anyone else.
Resource use
The Services are provided for backup, restore, and related management. You must not:
Use the Services for cryptocurrency mining, network scanning, stress testing, or other activity that consumes resources without a backup-related purpose.
Use Duplicati-provided storage as general-purpose file hosting, a content distribution network, or a public download source.
Use automated activity that degrades performance for other customers, including excessive API calls, repeated full backups of unchanged data without reason, or deliberately pathological backup configurations.
Exceed the storage, machine, or user limits of your plan, or circumvent limits by splitting usage across accounts.
Duplicati may apply rate limits or throttling to protect the Services; we will tell you if your usage is the reason.
Your responsibilities
Keep your contact details current so we can reach you about security or policy matters.
Keep your credentials and encryption passphrases secure, and tell us promptly at security@duplicati.com if you believe your Account has been compromised.
Keep the Duplicati client software on your machines reasonably up to date; security fixes are delivered as updates.
Ensure that anyone you authorize to use your Account complies with this AUP. You are responsible for their actions.
Do not send file contents, file listings, paths, or personal information about your users or patients through support channels; we will never ask for them.
Adverse impact on the Services
If your use of the Services is adversely affecting their operation or their availability to other customers, or if immediate action is reasonably necessary to preserve system integrity or prevent network abuse, Duplicati may suspend or restrict the affected Account or Organization without prior notice and without liability to you. We will notify you by email promptly after any such action and work with you to restore service once the issue is resolved.
Enforcement
Violations of this AUP may result in a warning, removal of offending material, suspension or restriction of the affected Organization or Account, termination of the Services, legal action, and cooperation with law enforcement where required. We will normally give notice and an opportunity to remedy before suspending or terminating, except where the violation is unlawful, poses an immediate risk to the Services or to others, or involves the material described under Prohibited uses that we are required to report. Fees are not refunded for Services terminated under this AUP.
Reporting violations
To report a suspected violation of this AUP, or to tell us about a security concern, email security@duplicati.com. We will acknowledge reports within 3 working days.
Changes to this AUP
We may update this AUP by posting a revised version on our website. Material changes take effect for existing customers 30 days after posting, as described in the Terms of Service; your continued use of the Services after that date constitutes acceptance of the revised AUP.
Contact
Duplicati Inc, a Delaware corporation · security@duplicati.com
