Skip to content
InfrastructureSolutionsLocationsCompanyLegal & trust
Discuss your project
← Legal & trust

Policy / 1.2

Reseller & Hosting Provider Policy

The responsibilities that follow the infrastructure through every layer of resale.

Effective 2026-09-23

In this document

1. Who this policy covers2. Apply the requirements downstream3. Retain an accountable service relationship4. Apply verification when the risk requires it5. Maintain a working abuse process6. Cooperate with lawful requests7. Protect customer information8. Demonstrate that the controls work9. Correct failures without spreading harm10. Keep the chain clear at exit
Ask a question

1. Who this policy covers

This policy applies to a 3NT customer that resells, rents, allocates or makes a 3NT service available to another person or organisation, including hosting providers, managed service providers and further resellers. It applies when incorporated into the accepted order. “You” means the contracting 3NT customer; a “downstream customer” is a customer or intermediary to whom you supply the relevant service.
A software platform is not automatically a reseller merely because people use its application. Where a platform gives customers control of infrastructure or the ability to deploy workloads, this policy applies to that allocation. The order should identify the operating model and any service-specific requirements.
Read this policy with the Terms & Conditions, Acceptable Use Policy, Customer Verification Policy, AML & Sanctions Statement and Downstream Customer Verification Standard. Mandatory law takes priority; an express, lawful variation must be agreed in writing. Publishing a new website version alone does not amend an existing contract.

2. Apply the requirements downstream

Before granting access, put enforceable terms in place with your downstream customer. Those terms must impose materially equivalent requirements for lawful and acceptable use, proportionate verification, account security, sanctions compliance where applicable, cooperation with substantiated abuse investigations and compliance with valid legal process.
“Materially equivalent” means the same protective outcome for the relevant service. You may use your own wording and processes, but must not create an exception that permits conduct prohibited under your agreement with 3NT. Explain the obligations and the consequences of a breach in a language and format the customer can understand. Keep evidence of the version accepted and when and by whom it was accepted.
If the downstream customer resells again, require that intermediary to apply equivalent obligations at the next level. The requirement must continue through each permitted layer. A contract with your immediate reseller is not sufficient if it allows the next reseller to disregard these requirements.

3. Retain an accountable service relationship

Maintain accurate, current information for your direct customer, a working contact route and a record linking the customer to the resources you allocate. For an intermediary, record its identity, responsible contact and role in the chain, with a lawful route to identify the party controlling an affected resource when a specific issue arises.
Resource attribution should include the service or instance identifier, assigned IP addresses, relevant ports where used for shared addressing, and allocation start and end times with a consistent time zone. Keep enough information to distinguish reassignment and shared resources. These are allocation and account records; this policy does not itself require packet capture, content surveillance or a general record of users’ browsing activity.
You remain the contractual contact for 3NT and must be able to act on the resources supplied to you. Outsourcing support, using your own brand or allowing further resale does not remove the agreed controls or your duty to respond.

4. Apply verification when the risk requires it

Operate the Downstream Customer Verification Standard. Basic account checks apply at onboarding. More extensive verification is required where a documented risk, an applicable legal obligation, a service-specific condition or a specific lawful and proportionate 3NT request calls for it.
You must not bypass a required check by allocating another account, address, service or intermediary to the same unresolved activity. A different verification provider or method is acceptable where it achieves the required level of assurance lawfully. Any unresolved disagreement about scope or feasibility must be escalated to 3NT for a documented decision before the affected restricted function is enabled.
This is a requirement to operate an effective verification process. It is not a universal instruction to collect passports, biometric data or source-of-funds evidence from every end user. The purpose, method and amount of information must fit the risk and applicable law.

5. Maintain a working abuse process

Publish a working abuse contact and nominate an operational contact for 3NT. Monitor the channels at the coverage and escalation levels agreed for your service. Keep the contact details current and maintain a way to reach someone who can isolate an affected resource in an urgent case.
On a sufficiently specific report, investigate the relevant customer and resource, assess the evidence and take proportionate action to stop substantiated misuse. Reply with the case reference, findings, action taken and any remaining work. An unsupported allegation is not conclusive proof, but it cannot be ignored without assessment.
Follow the reasonable, risk-based deadline in the notice and any agreed response schedule. If you cannot meet it, explain the blocker and propose interim containment and a completion time before the deadline where practicable. Urgent threats or binding legal deadlines may require immediate action. Response times reflect the nature and urgency of the incident and the obligations in the accepted order.
Ordinary reports to abuse@3nt.com are automatically forwarded to the customer, including the sender’s address. Use security@3nt.com for confidential security information and legal@3nt.com for authority process. Do not send these matters through the sales form. Follow the Legal & Abuse Guidelines.

6. Cooperate with lawful requests

Maintain a process to assess and route preservation, disclosure and other legal requests. Authenticate the requesting party, identify the legal basis and scope, and distinguish a request to preserve existing material from authority to disclose it. Follow the Law Enforcement Guidelines when the request concerns 3NT.
On a specific, lawful request concerning your allocated resources, provide the relevant attribution or verification evidence that you may lawfully disclose, using an agreed secure channel. Seek clarification promptly if the request is unclear, disproportionate, technically impossible or conflicts with law. A commercial request from 3NT is not, by itself, a court order or a blanket data-protection exemption.
Where a valid non-disclosure restriction applies, do not alert a downstream customer or automatically forward the request. Apply a lawful preservation hold only to the identified records and period. Tell us if relevant material is not held or cannot be located; do not claim that it exists, manufacture historical records or delete material to frustrate an applicable lawful hold.

7. Protect customer information

Identify the actual controller and processor roles for each activity and use the necessary data-processing and transfer arrangements. Your customer-verification work may be your own controller activity; a hosting DPA does not automatically authorise every use or onward disclosure of identity information.
Give customers appropriate privacy information, restrict staff access, protect transmission and storage, and adopt documented retention and deletion periods. Do not send an entire customer database or raw identity files when a narrower record or verification outcome is sufficient. Special-category data, including some uses of biometrics, requires its own applicable legal conditions and safeguards.
Notify the appropriate party of a personal-data breach in accordance with law and the applicable data-processing agreement. A substantiated security issue that may affect 3NT infrastructure must also be escalated promptly through the agreed operational route.

8. Demonstrate that the controls work

Keep an appropriate record of your policy acceptance process, resource assignments, verification decisions, escalations and remediation. On a reasonable, scoped request, demonstrate that the agreed controls operate—for example through a policy extract, process description, redacted case record or verification attestation.
We may ask for a proportionate review where a material risk or a repeated control failure warrants it, subject to the contract, confidentiality and applicable law. The review must be limited to the relevant services and purpose. This policy does not grant unrestricted access to your systems, customer content, source code or identity-document archive.
Tell us about material changes to your service model, resale chain or verification arrangements where they affect the agreed risk assessment. A provider’s promise of checks is not a substitute for monitoring whether your own process works.

9. Correct failures without spreading harm

Where a breach is identified, we may require clarification, a corrective plan, targeted verification or restriction of the affected resources under the contract. Repeated failures, evasion or serious ongoing harm may justify broader restrictions or termination. Measures should account for severity, urgency and whether a narrower action can address the risk.
Where lawful and feasible, we provide notice and an opportunity to remedy. Immediate action may be necessary to protect people or infrastructure or comply with law. A request for review does not automatically lift a restriction. Charges, refunds and liability remain governed by the accepted contract and mandatory law; this policy creates no automatic fine or blanket forfeiture.

10. Keep the chain clear at exit

On termination or reallocation, follow the agreed return and deletion arrangements, resolve access rights and update the resource record. Preserve only information subject to a continuing lawful purpose or hold, with appropriate protection and review. Do not use a customer’s departure to erase evidence that must lawfully be retained.
Contract and policy questions go to legal@3nt.com. Operational reports follow their dedicated channels. The goal is a traceable, accountable service relationship at every level, with verification and enforcement that remain proportionate to the actual risk.

End of document · Version 1.2
3NT Solutions LLP · OC363382

Compute. Connect. Continue.

A foundation for what comes next.

sales@3nt.com

Infrastructure

Bare MetalVirtual MachinesColocationDDoS protectionBackups & recovery

Who we work with

Hosting providersIT & managed service providersSaaS platformsCDN & edge networksTelecom & internet service providersFinTech teamsVPN providers

3NT

LocationsCompanyContactLegal & trustReport abuseLaw enforcementReseller policyCustomer verification
Our missionOur valuesCareers

© 2026 3NT Solutions LLP
Registered in England & Wales · OC363382

TermsPrivacyCookiesKYCAML
Back to top ↑