ENTERPRISE INTERNET SERVICES

Acceptable Use Policy

1. Purpose

NTT DATA, Inc's (“NTT DATA”) Enterprise Internet Services (“EIS”) organization provides enterprise customers (“Customers” or “Subscribers”) and their authorized users with Internet connectivity, managed network services, security and observability Value-Added Services (“VAS”) such as DDoS Shield, and a self-service Customer Portal for monitoring, reporting, and administration of these services (collectively, the “EIS Services”).

NTT DATA respects that the Internet provides a forum for free and open discussion and dissemination of information. However, where competing business, legal, security, or operational concerns arise, NTT DATA reserves the right to take preventative or corrective action. This Acceptable Use Policy (“AUP”) sets out the rules governing use of the EIS Services and supplements, but does not replace, the terms of each Customer's service agreement.

Where this AUP conflicts with the Master Service Agreement (“MSA”) or any Schedule, Statement of Work, or Order Form entered into with the Customer, the terms of the MSA (and its Schedules) shall govern, except that (a) Sections 3, 4, 5, and 6 of this AUP shall apply notwithstanding any conflicting term of the MSA, and (b) NTT DATA’s enforcement rights under Section 8 shall not be limited or waived by the MSA unless the MSA expressly references this AUP by section number and states the specific right being limited. This AUP may be revised from time to time; continued use of the EIS Services after revisions are posted constitutes acceptance of the updated AUP, subject to the notice terms of the MSA. Notwithstanding any notice period required under the MSA, NTT DATA may amend this AUP immediately and without prior notice where, in NTT DATA’s sole judgment, such amendment is necessary to address a security threat, legal or regulatory requirement, or imminent harm to the EIS Services or other Subscribers.

2. Scope

This AUP applies to all use of the EIS Services, including without limitation: Internet access and transit circuits, managed routers and CPE, VAS offerings (e.g., DDoS Shield and other security, observability, or managed service add-ons), the EIS Customer Portal, and any APIs, dashboards, or reporting tools made available as part of the EIS Services. It applies to the Customer and to all of the Customer's users, affiliates, subsidiaries, and any third party the Customer permits to access the EIS Services.

No single party owns or controls the Internet. This openness is central to its value, but it places a high premium on the judgment and responsibility of those who use it. NTT DATA does not monitor, verify, warrant, or vouch for the accuracy, quality, or legality of any content, data, or communications transmitted, accessed, processed, or hosted through the EIS Services, and disclaims all liability for any loss, damage, or claim arising from such content to the maximum extent permitted by applicable law.

The Customer is solely responsible for ensuring that all of its users, affiliates, subsidiaries, and authorized third parties comply with this AUP, and any violation by such persons shall be deemed a violation by the Customer for all purposes under this AUP and the MSA.

3. Prohibited Uses

The Customer and its users may not use the EIS Services, including the Customer Portal and any VAS, to engage in, or attempt to engage in, any of the following:

3.1 Malicious Activity

  • Publishing, transmitting, or distributing defamatory, abusive, harassing, threatening, obscene, or pornographic material, especially child sexual abuse material.
  • Distributing malware, including viruses, worms, Trojan horses, spyware, adware, or key loggers.
  • Hacking, cracking, mail-bombing, crypto-mining on shared infrastructure, port scanning, denial-of-service (DoS/DDoS) attacks, or other malicious or destructive activity.
  • Any activity NTT DATA determines, in its sole discretion, to be harmful to its Subscribers, operations, reputation, goodwill, or customer relationships.

3.2 Disruption of Services

  • Maintaining an open SMTP relay.
  • Disrupting or interfering with the ability of others to use the network, or any connected network, system, service, or equipment.
  • Sending unsolicited bulk or commercial messages (“spamming”).
  • For the avoidance of doubt, NTT DATA shall determine in its sole discretion whether any message or series of messages constitutes “spamming” or unsolicited bulk messaging under this Section.
  • Advertising, transmitting, or making available any software, program, product, or service designed to facilitate a violation of this AUP, including tools for spamming, flooding, mail-bombing, or DoS/DDoS attacks (other than authorized security testing conducted under Section 5).

3.3 Circumventing Security Controls

  • Subverting security, investigative, authentication, or other controls, including spoofing, forging headers, altering or deleting logs, impersonating other users, misrepresenting the originator of a message, or password/encryption cracking.
  • Disabling, bypassing, or rendering ineffective any security software or control — including controls associated with VAS offerings such as DDoS Shield — without NTT DATA's prior written authorization.
  • Installing malware, or software intended to subvert security or authentication controls, on the Customer's, another Subscriber's, or NTT DATA's systems or devices.
  • Sharing, circumventing, or misusing Customer Portal credentials or access controls, including accessing another Customer's data, dashboards, or account.

3.4 Illegal Activities

  • Infringing or misappropriating the intellectual property rights of others, including copyright, patent, trademark, service mark, trade secret, or software piracy.
  • Gaining or attempting to gain unauthorized or illegal access to other computers, accounts, or networks, including any precursor reconnaissance activity (e.g., port scan, stealth scan, vulnerability scan).
  • Engaging in fraud or other unlawful schemes, including Ponzi or pyramid schemes, unauthorized credit card charges, or software piracy.
  • Violating applicable export control laws or regulations, including export of controlled encryption technology.
  • Engaging in any other activity that violates any applicable federal, state, local, or international law, regulation, or order, as determined by NTT DATA in its sole discretion.

3.5 Data Handling

  • Violating the privacy (including data privacy), publicity, or other personal rights of any individual.
  • Transferring Customer Data to NTT DATA (i) without any consents required by applicable law, (ii) in violation of applicable data privacy laws, or (iii) that requires controls not contemplated by the applicable Statement of Work or Order Form.
  • Submitting confidential or sensitive data (e.g., credentials, cardholder data, or regulated personal data) into the Customer Portal, support ticketing system, or VAS reporting tools without the protections required by the MSA.

The Customer is solely responsible for classifying its data and determining whether the EIS Services provide adequate security and compliance controls for such data. NTT DATA makes no representation that the EIS Services are suitable for any particular data category, including without limitation regulated personal data, payment card data, or protected health information, unless expressly agreed in a Statement of Work.

4. Use of the Customer Portal and Value-Added Services

Access to the EIS Customer Portal, dashboards, and VAS reporting tools is provided solely for the Customer's internal use in monitoring, managing, and reporting on its own EIS Services. Without limiting Section 3, Customers and their users must not:

  • Use automated scripts, scraping tools, or API polling that degrades or could reasonably be expected to degrade Portal performance for other users, or that exceeds rate limits established by NTT DATA from time to time in its sole discretion, except through officially supported integrations operating within such limits.
  • Attempt to reverse-engineer, probe, or test the security of the Portal or VAS platforms outside of an authorized penetration-testing engagement agreed in advance with NTT DATA (see Section 5).
  • Provision, modify, or revoke user access in a manner inconsistent with the Customer's designated administrator and access-management controls.
  • Resell, sublicense, or provide third-party access to Portal functionality or VAS capacity beyond what is authorized under the applicable Order Form.

NTT DATA may immediately suspend or restrict a Customer’s access to the Customer Portal, VAS dashboards, or APIs, without prior notice, if NTT DATA determines in its sole discretion that the Customer has violated this Section 4. Such suspension shall not relieve the Customer of its payment obligations under the MSA.

5. Authorized Security Testing

Customers wishing to conduct vulnerability scans, penetration tests, or DDoS-simulation exercises against EIS-managed infrastructure or VAS (including DDoS Shield) must obtain NTT DATA's prior written approval and coordinate scope, timing, and notification with NTT DATA's security or NOC teams. Unauthorized testing will be treated as a violation of Section 3.3 and Section 3.4.

Even where security testing has been authorized, the Customer assumes all risk of service interruption, data loss, or degradation arising from such testing. The Customer shall indemnify and hold harmless NTT DATA from any claims, liabilities, losses, or expenses (including reasonable attorneys’ fees) arising from or related to the Customer’s authorized or unauthorized security testing activities.

6. Monitoring

NTT DATA will not, as an ordinary practice, monitor the content of Subscriber communications to ensure compliance with this AUP or applicable law. Nothing in this AUP shall be construed to impose upon NTT DATA any obligation or duty to monitor, investigate, or police Customer or user activity; NTT DATA’s decision not to monitor shall not constitute negligence, a waiver of its enforcement rights, or an assumption of liability for any Customer or user content or conduct. Where NTT DATA becomes aware of activity that may violate this AUP, it may take any action it deems appropriate to stop the activity, including removing content, suspending or disabling a Portal account, applying additional traffic scrubbing or filtering, taking a device off-line, or restricting access to the EIS Services, without regard to whether such action is expressly permitted under the MSA.

NTT DATA may perform automated monitoring of traffic and Portal activity for security purposes — including malware/virus scanning, DDoS detection and mitigation telemetry, spam filtering, and monitoring for communication with known or suspected malicious infrastructure (e.g., botnets) — as part of the ordinary operation of the EIS Services. NTT DATA will not intentionally monitor the content of private electronic communications except where required by law, requested by the Customer, or necessary to protect public safety.

Where a Customer itself provides Internet or hosting services to its own customers, NTT DATA does not require the Customer to monitor or censor its customers' transmissions, but NTT DATA reserves the right to take direct action against, or request the Customer's cooperation with respect to, activity originating from those downstream customers. Failure to cooperate with a corrective or preventive request within twenty-four (24) hours of notice (or such shorter period as NTT DATA determines is necessary to prevent imminent harm) is itself a material violation of this AUP and the MSA, entitling NTT DATA to suspend or terminate EIS Services immediately without further notice.

7. Legal Requirements and Disclosure

NTT DATA is required by law to remove or disable access to content upon receipt of a valid notice of copyright infringement, and to notify law enforcement if it becomes aware of child sexual abuse material on or transmitted through the EIS Services. It is NTT DATA's policy to terminate the privileges of Customers who commit repeated copyright violations.

NTT DATA may disclose information about a Subscriber, a transmission, or Portal/VAS usage in order to comply with a court order, subpoena, summons, discovery request, warrant, statute, regulation, or governmental request, consistent with the terms of the MSA. NTT DATA may also disclose such information where necessary to protect NTT DATA, its Subscribers, or others from harm, or to ensure the proper operation of the EIS Services. NTT DATA may further disclose information to upstream network providers, peering partners, internet registries, industry threat-sharing organizations (e.g., ISACs), insurers, and professional advisors where NTT DATA determines in its sole discretion that such disclosure is necessary or advisable for security, operational, or risk-management purposes.

8. Enforcement

Violation of this AUP may result in NTT DATA taking any action it deems appropriate in its sole discretion, up to and including: a warning; temporary suspension of Portal, VAS, or network access; rate-limiting or traffic filtering; mandatory remediation before service is restored; or termination of the affected service or the MSA. In the case of violations of Sections 3.1 (Malicious Activity), 3.3 (Circumventing Security Controls), or 3.4 (Illegal Activities), NTT DATA may terminate the affected service or the MSA immediately and without regard to any cure period or termination restriction in the MSA. NTT DATA may, but is not obligated to, notify the Customer of enforcement action before, during, or after taking such action. NTT DATA’s failure to notify shall not affect the validity of any enforcement action taken under this AUP.

9. Complaints

Reports of suspected violations of this AUP relating to the EIS Services should be to ap.eis-abuse@global.ntt

10. Limitation of Liability

IN NO EVENT SHALL NTT DATA BE LIABLE TO CUSTOMER OR ANY THIRD PARTY FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF REVENUE, LOSS OF PROFITS, LOSS OF DATA, OR BUSINESS INTERRUPTION, ARISING FROM OR RELATED TO NTT DATA’S ENFORCEMENT OF THIS AUP, INCLUDING ANY SUSPENSION, TERMINATION, CONTENT REMOVAL, TRAFFIC FILTERING, OR OTHER ACTION UNDERTAKEN IN CONNECTION WITH THIS AUP, REGARDLESS OF THE THEORY OF LIABILITY AND REGARDLESS OF WHETHER NTT DATA HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. NTT DATA’S TOTAL AGGREGATE LIABILITY UNDER OR IN CONNECTION WITH THIS AUP SHALL NOT EXCEED THE FEES PAID BY CUSTOMER FOR THE AFFECTED EIS SERVICES DURING THE ONE (1) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

11. Indemnification

The Customer shall indemnify, defend, and hold harmless NTT DATA, its affiliates, officers, directors, employees, and agents from and against any and all claims, demands, losses, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees and costs of investigation) arising from or related to: (a) the Customer’s or its users’ violation of this AUP; (b) any content transmitted, stored, or processed through the EIS Services by or on behalf of the Customer; (c) any third-party claim arising from the Customer’s use of the EIS Services; (d) the Customer’s failure to comply with applicable laws; or (e) any dispute between the Customer and its downstream customers or end users. This indemnification obligation shall survive termination or expiration of the MSA and this AUP.

12. Reservation of Rights; No Waiver

NTT DATA’s failure to enforce any provision of this AUP at any time shall not constitute a waiver of such provision or of NTT DATA’s right to enforce it at any later time. NTT DATA reserves all rights and remedies available at law or in equity, whether or not expressly set forth in this AUP or the MSA. The rights and remedies provided in this AUP are cumulative and not exclusive of any other rights or remedies provided by law, in equity, or under the MSA.

13. Compliance with Laws

The Customer shall comply with all applicable laws, regulations, and industry standards in connection with its use of the EIS Services, including without limitation the Computer Fraud and Abuse Act (CFAA), the CAN-SPAM Act, the Telephone Consumer Protection Act (TCPA), the Digital Millennium Copyright Act (DMCA), applicable data protection and privacy laws (including GDPR, CCPA, and sector-specific regulations such as HIPAA and PCI-DSS), and applicable export control and sanctions laws. The Customer acknowledges that traffic carried over the EIS Services may traverse international links and that NTT DATA is not responsible for compliance with data localization laws unless expressly agreed in a Statement of Work.