Abuse and Content Violation Reporting Policy
LEGAL BASIS
- The Cybersecurity Law 2025 (Law No. 116/2025/QH15, effective 1 July 2026) — on blocking and removing infringing content and coordinating enforcement;
- Digital Technology Industry Law 2025 (Law No. 71/2025/QH15);
- Law on Artificial Intelligence 2025 (Law No. 134/2025/QH15);
- Law on E-Commerce 2025 (Law No. 122/2025/QH15) - on the responsibilities of intermediary service providers;
- Law on Personal Data Protection 2025 (Law No. 91/2025/QH15) and Decree 356/2025/ND-CP;
- Law on Intellectual Property (amended and supplemented 2022);
- Law on Anti-Money Laundering 2022;
- Decree 147/2024/ND-CP on the management, provision, and use of internet services and online information;
- Decree 91/2020/ND-CP on combating spam messages, spam email, and spam calls;
- Decree 174/2026/ND-CP on administrative penalties in the fields of post, telecommunications, radio frequencies, electronic transactions, and information technology;
- the Penal Code 2015 (Bộ luật Hình sự 2015) (Article 326 on distributing depraved cultural products, Article 147 on using persons under 16 for pornographic purposes; Article 174 on fraudulent appropriation of property; Articles 286 and 288 on spreading harmful computer programs and on unlawfully providing or using information on computer networks);
- Decision No. 4567/QD-VBPL dated 01/06/2026 issuing the company's Legal Compliance Framework.
This Policy operationalizes Article 7 (prohibited conduct/AUP) of the Terms of Service and applies together with the Intellectual Property Terms, the PDPD, the Anti-Money Laundering Policy and the Complaint Handling Process.
PART I - SCOPE AND DEFINITIONS
Article 1. Scope of application
1.1. This Policy applies to all Customers, sub-accounts, end users and any party using HiTechCloud services (hosting, cloud, servers, email, domains, SSL, AI/MaaS and related services).
1.2. This Policy sets out prohibited abusive conduct, how to report abuse, the intake and handling process, and the sanctions that may apply.
Article 2. Definition of “abuse”
2.1. “Abuse” means any use of the services that violates the law, breaches the Terms of Service/AUP, infringes the rights of third parties, or harms the infrastructure, systems or other users.
2.2. “Infringing content” means any data, information, file, website or service that the Customer stores, transmits or distributes through HiTechCloud’s systems in violation of the law or of this Policy.
PART II – PROHIBITED ABUSIVE CONDUCT
Article 3. Network and infrastructure abuse
3.1. The following are prohibited: (a) distributing viruses, malware, ransomware, spyware or malicious code in any form; (b) carrying out DDoS/DoS attacks, unauthorized port scanning or network sniffing; (c) operating botnets, C&C servers, or anonymizing proxies and VPNs for unlawful purposes; (d) exploiting security vulnerabilities in HiTechCloud or third-party systems; (e) resource abuse that affects other users; (f) cryptocurrency mining on shared resources without a dedicated service plan.
Article 4. Illegal and harmful content
4.1. The following are strictly prohibited: (a) child sexual abuse material (CSAM) or any child exploitation content; (b) terrorist content, terrorist financing or incitement to violence; (c) content inciting hatred or racial or religious discrimination; (d) fraudulent or phishing sites impersonating financial institutions, state agencies or businesses; (e) content used to defraud people of their property; and (f) any other content that breaches Vietnamese law.
4.2. Sending junk email, junk messages or bulk email without the recipient's consent (spam) is prohibited under Decree 91/2020/ND-CP (Nghị định 91/2020/NĐ-CP), as is spoofing identities, IP addresses or email headers.
4.3. It is strictly prohibited to exploit AI/deepfake technology to create or distribute falsified content, manipulate perception, commit fraud or infringe the rights of third parties, in accordance with the Law on Cybersecurity 2025 (Luật An ninh mạng 2025) and the Law on Artificial Intelligence 2025 (Luật Trí tuệ nhân tạo 2025).
Article 5. Intellectual property infringement
5.1. Storing or distributing unlicensed software, films, music or copyrighted material, and counterfeiting trademarks or trade names, are strictly prohibited. Intellectual property complaints and infringement handling follow the Intellectual Property Terms (including the DMCA/content takedown process).
Article 6. Data abuse and privacy
6.1. Unlawful collection of personal data (scraping, phishing, social engineering), unlawful trading in personal data, and processing of personal data in breach of the Law on Personal Data Protection 2025 (Luật Bảo vệ dữ liệu cá nhân 2025) are strictly prohibited. Incidents involving personal data are handled in accordance with the PDPD.
Article 7. Financial abuse
7.1. Using the services for money laundering, terrorist financing, payment fraud or sanctions evasion is strictly prohibited. Such cases are handled under the Policy on Anti-Money Laundering, Counter-Terrorist Financing, Sanctions Compliance and Asset Freezing.
PART III – ABUSE REPORTING
Article 8. How to submit a report
8.1. Any individual or organization may report abuse or infringing content by email abuse@photuesoftware.com (or report@photuesoftware.com).
8.2. A valid report should include: (a) a description of the violating conduct/content; (b) the URL, IP address, domain, or other identifying information that pinpoints the location of the violation on the HiTechCloud system; (c) supporting evidence (screenshots, logs, email headers, etc.); (d) the reporter's contact information; (e) for IP rights infringement, additional documentation as required under the Intellectual Property Terms.
8.3. HiTechCloud keeps reporter information confidential to an appropriate extent and processes the reporter's personal data in accordance with the PDPD. It does not accept, and may discard, reports that are abusive, harassing or knowingly false.
Article 9. Intake and handling
9.1. Intake process:
| Step | Action | Term |
|---|---|---|
| 1 | Reports received via abuse@photuesoftware.com | Immediate |
| 2 | Acknowledgment of receipt | Within 24 hours |
| 3 | Assess and verify the severity of the violation | 1–3 business days (urgent: immediately) |
| 4 | Apply handling measures (Article 10) | By severity level |
| 5 | Notify the reporter and the account holder of the outcome | After processing |
9.2. For serious, urgent violations (CSAM, terrorism, an ongoing cyberattack, risk of data loss), HiTechCloud acts immediately without following the timeline set out above.
PART IV – ENFORCEMENT AND SANCTIONS
Article 10. Enforcement measures
10.1. Depending on the severity and nature of the breach, HiTechCloud applies one or more of the following measures: (a) a warning with a deadline for remediation; (b) removal, blocking or disabling of the infringing content; (c) partial or full suspension of the service; (d) suspension or termination of the account; (e) withholding of related funds in cases of fraud; and (f) reporting and transferring information to the competent authority.
10.2. For serious violations of Clause 7 of the Terms of Service (in particular CSAM, terrorism, or infrastructure attacks), HiTechCloud has the right to terminate the service immediately without prior notice, in accordance with Clause 26 of the Agreement; services terminated for violations are not eligible for a refund under Article 5 of the Refund Policy.
10.3. The Customer is responsible for the actions of sub-accounts, end users and third parties granted access under its account.
Article 11. Content removal at the request of a competent authority
11.1. On receiving a lawful request from a competent authority, HiTechCloud cooperates to block or remove infringing information under the Cybersecurity Law 2025 (Luật An ninh mạng 2025): within 24 hours for ordinary unlawful information; up to 6 hours for an emergency directly related to national security. Such enforcement does not constitute a breach of the HiTechCloud Agreement and is not counted toward SLA Downtime.
Article 12. Cooperation with competent authorities
12.1. HiTechCloud cooperates with, provides information to, and retains data and logs for the competent state authority upon lawful request; it proactively reports to the police any conduct showing signs of criminal activity (in particular, content involving child exploitation, terrorism, fraud, or cyberattacks).
Article 13. Appeals and responses from the party subject to action
13.1. The account holder subject to a remedial action will be notified of it (except where the law requires otherwise) and has the right to file a complaint under the Complaint and Dispute Resolution Process. If the account holder proves that the content or conduct in question does not violate the rules, HiTechCloud will restore the service or content within a reasonable time, unless the competent authority directs otherwise.
13.2. Accounts that reoffend or commit repeated violations (three or more within 12 months) may be suspended and investigated; serious, large-scale violations may be locked immediately.
PART V – LEGAL SANCTIONS AND EFFECTIVE DATE
Article 14. Legal sanctions
14.1. Abusive conduct may be subject to administrative sanctions (including under Decree 174/2026/NĐ-CP, Decree 91/2020/NĐ-CP, and other sector-specific decrees), criminal prosecution (Articles 174, 286, 288, and 316 of the Penal Code 2015 (Bộ luật Hình sự 2015) and related articles), and compensation for damages under the Civil Code 2015 (Bộ luật Dân sự 2015).
14.2. The Customer in breach is liable to indemnify and hold HiTechCloud harmless against all third-party claims arising from the abuse, in accordance with Article 23 of the Terms of Service.
Article 15. Effect
15.1. This Policy takes effect from 1 July 2026, is an integral part of the Terms of Service and supersedes all previous versions. The Vietnamese version has the highest legal validity.