Acceptable Use Policy

Version 1.0, effective 28 August 2026

This Acceptable Use Policy (the AUP) applies to every message sent from Mailboxes provisioned by Meridian Interface Ltd trading as Mailbox Fleet (we, us). It forms part of the Master Service Agreement (the MSA) and expands the Sending Policy, which states the principles in short form. Capitalised terms have the meaning given in the MSA. Where this AUP and the Sending Policy differ, this AUP governs.

The reason for these rules is practical as much as legal. Sending infrastructure only stays deliverable if everyone using it behaves; one abusive Fleet can get a Sending IP throttled, burn Domains and bring complaints to our door. So we enforce these rules at the server where we can, and by pausing, suspending or terminating where we cannot.

1. Permitted use

1.1 The Service is for targeted, relevant, business-to-business outreach: contacting individuals at organisations, at their work addresses, about something plausibly useful to them in their professional capacity.

1.2 Every campaign must have a lawful basis under the UK GDPR that the Customer has identified and documented before sending. For cold B2B outreach this is usually legitimate interests (Article 6(1)(f)), which requires a recorded legitimate interests assessment showing that the outreach is necessary for the Customer's purpose and that the recipient's interests do not override it. Consent is also acceptable where it has genuinely been obtained.

1.3 Under PECR, unsolicited marketing email may be sent without prior consent only to corporate subscribers (companies, LLPs, Scottish partnerships and public bodies) at addresses attributable to that organisation. Email to individual subscribers, including sole traders, non-LLP partnerships and anyone using a personal address, requires prior consent unless the soft opt-in applies. The Customer must classify its recipients accordingly and must not treat a named person's work address at a company as licence to email that person at any other address.

1.4 Recipients outside the UK are protected by their own laws (for example the EU GDPR and ePrivacy rules, CAN-SPAM in the United States and CASL in Canada). The Customer must comply with the law of every jurisdiction in which its recipients are located.

1.5 Permitted uses include: first-contact B2B prospecting to work addresses with messaging relevant to the recipient's role; follow-ups within a sequence, subject to the frequency limits in clause 3.6; replies and continuing conversations; and outreach on behalf of a declared End Client under clause 8 of the MSA.

2. Prohibited use

The Customer must not use the Service to send, or attempt to send:

2.1 Consumer email. Marketing to consumers, to personal addresses (for example gmail.com, outlook.com, icloud.com, yahoo.com), or to anyone in a private capacity.

2.2 Lists without provenance. Email to purchased, rented, scraped or otherwise acquired lists unless the Customer holds records showing where each address came from, when, on what basis, and that the source was lawful. Bulk email to addresses with no plausible business relevance to the offer is prohibited whatever the source.

2.3 Deceptive headers or spoofing. Any message that forges or misrepresents the sender, the From address, the Reply-To address, the sending Domain or the routing information; any use of a third party's name, brand or domain without authority; or any attempt to make a Domain appear to be an organisation it is not.

2.4 Misleading subject lines or content. Subject lines that misrepresent the message's content or purpose (for example "Re:" or "Fwd:" on a first contact, fake invoice or delivery notices, fabricated urgency); false claims of a prior relationship; or content that is otherwise deceptive or that misrepresents who the sender is.

2.5 Suppressed recipients. Any message to an address on the Suppression List, or to anyone who has asked the Customer, by any channel, not to be contacted. The platform blocks the former; the Customer must maintain its own records for the latter and must not try to reach a suppressed person through a different address.

2.6 Harvesting. Collecting addresses by scraping websites, social networks or directories without lawful basis; using Mailboxes or replies to verify or harvest addresses; dictionary or permutation attacks on a domain's address space.

2.7 Malware, phishing and fraud. Malware, links to malware, credential-phishing, business email compromise attempts, advance-fee or investment fraud, or links that redirect to any of these.

2.8 Restricted content. Adult content or services; gambling or betting; promotion of cryptocurrency, tokens or investment schemes (including "pump" or "signal" promotions), unregulated financial products, or unlicensed lending; counterfeit or illegal goods; weapons; controlled substances; anything that is illegal to sell or promote in the recipient's jurisdiction.

2.9 Sanctioned recipients and purposes. Any message to a person or entity on the UK Government consolidated list of financial sanctions targets or an equivalent list, or that would facilitate a transaction prohibited by sanctions law.

2.10 Anything else unlawful in the United Kingdom or in the recipient's jurisdiction, including messages that are defamatory, discriminatory, harassing or threatening, or that infringe intellectual property rights.

2.11 Interference with the platform. Attempts to bypass, probe or defeat the Ramp, the Caps or the Suppression List (including rotating Sending Tools, staggering across Mailboxes to exceed a Cap, or stripping unsubscribe headers); using Mailboxes for anything other than the outreach described in clause 1 (for example bulk transactional email, newsletters, or relaying mail for third parties); or connecting a Mailbox to any tool that does not honour our Caps.

3. Mandatory practices

Every message sent through the Service must comply with the following. These are conditions of the Service, not recommendations.

3.1 Working unsubscribe. Every message must carry a working, clearly visible unsubscribe mechanism. Our one-click unsubscribe headers (List-Unsubscribe and List-Unsubscribe-Post) are required on every message; the Customer's Sending Tool must not remove or override them. An unsubscribe request, whether via the link, a reply or a complaint, must be honoured within 48 hours and permanently. The platform applies it immediately to the Suppression List; the Customer must apply it in its own systems within the same period.

3.2 Identification of the sender. Every message must state the legal name of the business on whose behalf it is sent and either its registered office address or, for a UK company, its company registration number, in a form the recipient can easily read. Messages sent for an End Client must identify the End Client as the sender.

3.3 Accurate sender identity. The From name must be a real person or the sending business; the From address must be a Mailbox on a Domain registered to the Customer or its End Client; and Reply-To must reach a monitored inbox. Signatures must not claim titles, affiliations or endorsements that are untrue.

3.4 Respecting Caps. The Customer must configure its Sending Tool so that scheduled volume does not exceed the Cap shown in the Portal for each Mailbox. Messages submitted above the Cap are refused by the server; repeated over-submission is a breach of this AUP.

3.5 No bypassing the Ramp. New Mailboxes and Domains must be allowed to complete the Ramp. Requests to skip or accelerate it are declined, and attempts to work around it (including sending the same campaign through multiple Fleets to multiply volume) are a breach.

3.6 Frequency and relevance. Sequences must be limited to a reasonable number of touches to the same recipient and must stop at the first request to stop. The Customer must segment so that messaging is relevant to the recipient's role and organisation.

3.7 List hygiene. Addresses must be validated before a campaign, hard bounces removed immediately, and addresses that have not engaged over a prolonged period retired.

3.8 Records. The Customer must keep, and produce to us within 2 business days of request, records sufficient to show for any recipient the source of the address, the lawful basis relied on, and the handling of any opt-out.

4. Monitoring and enforcement

4.1 What we monitor. We do not read message bodies. We monitor delivery outcomes (accepted, bounced, deferred), complaint notifications from mailbox providers, spam-trap hits, unsubscribe and reply-based opt-outs, measured inbox placement, and the presence of every Domain and Sending IP on public blacklists and mailbox-provider reputation feeds. We may also review a sample of message headers, subject lines and the content of messages that are the subject of an abuse report.

4.2 Thresholds. The following rates, measured per Mailbox and per Domain over a rolling window, trigger automated action:

SignalWarningAutomatic pause
Complaint rate (spam reports as a share of delivered mail)0.1%0.3%
Bounce rate (hard bounces as a share of attempted mail)2%5%
Spam-trap hitsanyany confirmed hit
Blacklist listing of a Domain or Sending IPlisting on a minor listlisting on a major list or by a mailbox provider
Measured inbox placement during the Rampbelow 90% on one checkbelow 90% on two consecutive checks

At the warning level the Cap stops rising and the Portal shows an alert. At the pause level the affected Domain or Mailbox is paused automatically, and where a Domain is burned a Swap is provisioned under clause 2.5 of the MSA. We may adjust these thresholds as mailbox-provider requirements change, on notice in the Portal.

4.3 Graduated response. Depending on the seriousness and whether the breach is deliberate, we may: lower a Cap or restart the Ramp; pause a Mailbox or Domain; Swap a burned Domain; suspend the Fleet under clause 6 of the MSA; require corrective action (for example removal of a list, a rewritten template, or evidence of provenance) before resuming; or terminate the MSA under clause 7.3. Deliberate breaches of clause 2 result in termination without refund.

4.4 Repeat and related accounts. A Customer terminated for breach may not open a new account, directly or through a related person or entity. Fleets operated for an End Client that breaches this AUP are treated as the Customer's own breach.

4.5 Cooperation with third parties. We may share Fleet-level telemetry and, where relevant, message headers with mailbox providers, blacklist operators, registrars and law-enforcement or regulatory bodies in order to resolve a listing, respond to an abuse report or comply with a lawful request.

4.6 Our own reporting obligations. Where a breach involves a criminal offence, sanctions law or a serious data-protection breach, we may report it to the relevant authority whether or not the Customer asks us to.

5. Reporting abuse

5.1 Recipients, mailbox providers and third parties can report abuse involving Mailbox Fleet infrastructure to hello@peachdata.co.uk with "abuse" in the subject line, or by post to our registered office. Reports about personal data may also go to privacy@peachdata.co.uk.

5.2 We acknowledge abuse reports within 1 business day, investigate, pause the affected Domain or Mailbox where warranted, and pass the report to the Customer, who must respond to us within 2 business days with what happened and what has been done.

5.3 Recipients never need to contact the Customer or prove who they are to stop receiving mail: following the unsubscribe link, replying with a request to stop, or emailing us is enough, and the opt-out is applied platform-wide.

5.4 Customers who discover a breach of this AUP in their own sending (for example a list loaded by mistake, a compromised Sending Tool or a rogue contractor) must tell us immediately. We treat self-reported breaches more leniently than breaches we find ourselves.

6. Changes to this policy

6.1 We may update this AUP as sending laws, mailbox-provider requirements and blacklist practices evolve. Material changes are notified to the account owner at least 30 days before they take effect, in line with clause 18.2 of the MSA; changes required by law or by a mailbox provider to keep the Service deliverable may take effect sooner, with notice as early as we can give it.

6.2 Continued sending after a change takes effect is acceptance of the updated policy. The version number and effective date at the top of this document identify the current AUP; earlier versions are available on request.

Signature

Meridian Interface Ltd trading as Mailbox Fleet

Signed: ______________________ Name and title: ______________________ Date: [Date]

[Customer legal name] (Company No. [Customer company number])

Signed: ______________________ Name and title: [Signatory name and title] Date: [Date]