Acceptable Use Policy

Last updated: September 2, 2026 · Version 1.0

Courtesy translation. The Spanish version published at bimxcloud.com/legal/uso-aceptable is the only binding version. If the two differ, the Spanish text prevails.

This policy forms part of BIMXcloud's Terms and Conditions of Service and applies to everyone who uses the Service: the Customer, its Authorised Users and its External Collaborators. Capitalised terms have the meaning given in section 2 of the Terms.

It is kept as a separate document because it changes more often than the contract. Changes are published on this page with their date, and substantial changes are notified 30 calendar days in advance, as with changes to the Terms.


1. The general idea

In short: your server is yours to work on. Don't use it for anything unlawful, to bother third parties, or for work that isn't your firm's.

Each Customer gets a dedicated instance: it shares no processor, memory or disk with other customers. That gives you freedom of configuration, but the instance is still connected to a shared network and operates under BIMXcloud's name towards third parties. This policy sets the limits of that freedom.

We do not routinely review the content of instances and we do not want to. We act when we receive a report, when an authority requires it of us, or when infrastructure monitoring detects behaviour that affects the network or other customers.


2. Prohibited content and activities

In short: nothing unlawful. No exceptions and no prior warning.

It is prohibited to store, transmit, publish or process from the Instance:

2.1 Material relating to child sexual abuse or any content involving harm to minors. Detection of this material results in immediate suspension, without prior notice, and a report to the competent authority.

2.2 Content that infringes the copyright, trademarks, patents or trade secrets of third parties, including unlicensed software.

2.3 Content that promotes or facilitates crime, violence, terrorism, human trafficking, arms or substance trafficking, or any activity unlawful under Mexican law.

2.4 Content that incites hatred or discrimination, or that constitutes harassment, threats or defamation of an identifiable person.

2.5 Malicious software: viruses, worms, trojans, ransomware, intrusion tools or any program designed to damage third-party systems or data, unless these are isolated samples in a controlled environment and you have informed us in writing in advance.

2.6 Information obtained unlawfully, including personal databases with no legal basis for their processing.

2.7 Identity theft, fraud, phishing or fundraising schemes.


3. Security and integrity of other systems

In short: don't use your server to get into someone else's.

It is prohibited to use the Instance to breach or attempt to breach the security of any network, device, system or application, whether your own or another's. In particular:

3.1 Unauthorised access. Accessing or attempting to access systems, accounts or data without the authorisation of their owner, including BIMXcloud's infrastructure and other customers' instances.

3.2 Interception. Monitoring, capturing or intercepting traffic, data or communications that are not the Customer's own.

3.3 Probing. Scanning ports, enumerating services or carrying out penetration tests against third-party systems. Tests against your own Instance require prior written notice under §4.3.

3.4 Circumvention. Evading authentication controls, usage limits, filters or security measures, whether your own or third parties'.

3.5 Access chains. Using the Instance as an intermediate point to reach other systems: open proxies, exit nodes for anonymity networks, or relaying third-party traffic.


4. Use of resources and of the network

In short: your instance is dedicated, but the network isn't. Don't saturate it and don't use it for anything other than your firm's work.

4.1 Resource abuse. Use that degrades the performance of the shared infrastructure or of other customers' instances is prohibited, including sustained anomalous traffic and processes that saturate the data centre network.

4.2 Use unrelated to the firm's business. The Instance is contracted for the work of the contracting firm. Using it for activities unrelated to that work is prohibited, among them: cryptocurrency mining, render or compute farms for third parties, resale of capacity, hosting public services for third parties, and traffic or gaming bots.

4.3 Load testing. Load, stress or performance testing on your own Instance requires prior written notice to support@bimxcloud.com and agreement on the window in which it will run. Without notice, the resulting traffic is treated as a security incident.

4.4 Ports and services. The services BIMXcloud administers — Revit Server, ERPNext and Nextcloud — do not require any additional outbound ports to be opened. The infrastructure provider restricts certain outbound ports on its servers for security and network reputation reasons. If your firm needs to enable a service requiring a port that is not open, write to us before configuring it: we assess it case by case and tell you whether it is possible.


5. Email and messaging

In short: no unsolicited bulk sending from your server.

5.1 Sending, relaying or facilitating the sending of unsolicited bulk email or messages from the Instance is prohibited.

5.2 Altering or concealing email headers, or assuming another sender's identity without their authorisation, is prohibited.

5.3 Legitimate transactional email and lawful commercial communications — for example, your firm's invoicing or project notices — are permitted, provided you have the recipients' consent and an unsubscribe mechanism.

5.4 Bulk sending from the Instance affects the reputation of the data centre's IP addresses, which is a shared resource. For that reason a breach of this section may lead to suspension even where the content sent is lawful.


6. Access, users and collaborators

In short: access belongs to your firm. If you let someone else in, you answer for them.

6.1 Named access. Credentials are individual. Sharing, publishing or transferring them is prohibited.

6.2 Outside the contracting firm. Giving access to the Instance to people outside the contracting firm is prohibited, save as provided in 6.3.

6.3 External Collaborators. The Customer may grant access to external collaborators — for example, subcontractors connecting to their Revit Server — where the product's scheme allows it. In that case the Customer is responsible for those people's conduct as if it were its own, including compliance with this policy. BIMXcloud has no contractual relationship with them and does not administer them.

6.4 Removals. The Customer must request removal of access for anyone who leaves its organisation or ends their collaboration.

6.5 Compromised credentials. If the Customer suspects a credential has been compromised, it must tell us without delay at support@bimxcloud.com.


7. Reports

Anyone may report use that breaches this policy by writing to support@bimxcloud.com, describing the facts and, where possible, providing evidence. Reports are handled within support hours (08:00 to 22:00, Monterrey time, every day).


8. Consequences of a breach

In short: normally we tell you and give you a chance to fix it. With unlawful content or a security risk, we suspend first.

8.1 Ordinary procedure. Where a possible breach arises we write to you, explain the facts and give you a period to correct it. If it is not corrected, termination for cause under section 19.2 of the Terms applies, with the 10 calendar day cure period.

8.2 Immediate suspension. We suspend the Instance with no cure period where there is: material under §2.1; active malicious software; an ongoing security breach affecting third parties or the infrastructure; or a duly founded and reasoned request from a competent authority.

8.3 Scope of suspension. Suspension may be total or limited to the service or port involved, according to what is sufficient to stop the problem.

8.4 Effect on your information. A suspension under this policy does not delete the Customer's information. The periods in section 7 of the Terms apply.

8.5 Cooperation with authorities. We comply with duly founded and reasoned requests from competent authorities and inform the Customer where the law permits.

8.6 No waiver. Not acting on a breach does not waive the right to act on it later.


9. Contact

support@bimxcloud.com — reports, questions about this policy, and load testing notices.