GOpenCSR acceptable use policy
What a G Open account, a post in governance and an abuse report may not be used for, how the shared services may not be used, and what follows a breach.
What this covers
This policy applies to every G Open account, every API key and automation key, everything posted in GOpenCSR (public comments, suggestions to a community pool, and motions with their amendments), every abuse report and every message sent through an abuse relay address, and to the services at csr.gplatform.org: sign-in, the consoles, the API front door and the transparency log. You accept it together with the GOpenCSR terms, and every account that moved from GOpenCDR is bound by it from the move. It adds to the acceptable use section of the general terms rather than replacing it.
What you do with names and addresses is covered by each registry's own policy: the GOpenCDR acceptable use policy for names, and the GOpenCNR acceptable use policy for addresses, ASNs, routes and the network. How a case about either is handled, and how a sanction can cover a holder's names and addresses together, is set out in the abuse and sanctions policy.
Your account
- One person, one account. Do not share your account, your password, your passkeys, your recovery codes or a session with anybody. An organisation gives each of its people a role of their own, never a shared sign-in.
- No automation outside API keys and automation keys. Scripts use the API front door with an API key and sign with an automation key registered under a passkey. Do not drive the sign-in pages, the consoles or the signing step with scripts, headless browsers or anything else that acts in place of a person.
- No accounts to get around a restriction: not around a suspension, a closure, a sanctions hold, or a limit such as the number of times you may vouch.
- No accounts to multiply your voice. Support for a community motion counts once per account with standing, and a petition needs 25 such accounts. Do not open or use further accounts, or borrow other people's, to add support or to reach a petition.
- Tell the truth. Sign up only with your own email address and the invitation sent to it, only if you are 16 or over, and, if you are under 18, only with the agreement of a parent or guardian. When you first become a holder, give your true legal name and country.
- Vouch honestly. Invite only people you know and expect to keep these rules. Do not sell, trade or pass on invitations or vouches.
Public comments, suggestions and motions
Governance is public on purpose, and people disagree in it. Criticism of a motion, of a council, of Tier 0 or of us is welcome. What is not allowed in a comment, a suggestion or a motion:
- Unlawful content under the law that applies to you or to us, such as defamation, threats or incitement to hatred. Child sexual abuse material is always reported to the police or the Bundeskriminalamt, with what we hold about it that is not telecommunications traffic data; traffic data is passed on only under a legal order.
- Harassment: attacking, threatening or intimidating a person, including council members, representatives, Tier 0 staff and other commenters, or following them from one motion to the next.
- Doxxing: publishing personal data about somebody without their consent, such as a home address, a phone number, a private email address, a network endpoint or the membership of an audience.
- Spam: advertising, the same text posted again and again, floods of suggestions to a community pool, and posts that have nothing to do with the motion they are on.
- Impersonation: posing as another person, an organisation, a council or Tier 0, or using a display name that misleads about who you are.
- Publishing what is confidential: the content of a confidential motion, a sealed vote, or who sponsored a motion before the council's session reveals it. Council members and Tier 0, who see these, keep them to themselves, and so does anybody who comes by them in another way.
- Links to phishing or malware, and anything else the registries' acceptable use policies forbid a name or an address to be used for.
Abuse reports in good faith
- Report what you believe to be true. Do not make a report you know to be false, and do not report in order to harass a holder, to hurt a competitor or to get a lawful opinion taken down.
- Use the relay for its purpose. A holder's abuse relay address,
abuse+<handle>@relay.csr.gplatform.org, is for reports of abuse about what that holder holds. Do not use it for advertising, for harassment or to find out who is behind a holder. It accepts 20 messages an hour from one sender and evidence up to 20 MB. - Respect the reporter. A holder who receives a report answers it and takes no action against the person who made it. A reporter is contacted through the relay only after agreeing to it, and their identity is not passed to the holder unless they agree or the law requires it.
The services themselves
- No probing, scanning, load-testing or attacks against
csr.gplatform.org, the API front door, the transparency log, the abuse relay or anything behind them, except as the GOpenCSR security and disclosure policy and the Gelhaus Solutions vulnerability disclosure policy allow. - No getting around the controls: not the rate limits, by spreading requests over keys, accounts or addresses; not step-up, the signing step or four-eyes approval; and not the screening at sign-up.
- No harvesting. Do not collect registry data, holder profiles, relay addresses or account data in bulk, from the consoles, the public pages or the API, to build lists, to market to holders or to work out who stands behind them. Bulk registry data is available only where a registry publishes it, under that registry's own terms. Reading and verifying the whole transparency log is welcome: that is what it is for.
- No trying to learn what is withheld: who is in an audience, who sponsored a motion before its session, how a sealed vote was cast, whether a holder is under a sanctions review, or a holder's admin and tech contacts.
What is not our business
We act on breaches of this policy and on binding orders. We do not act on a post because somebody dislikes it, on disagreement, or on criticism of anybody, including of us. A report that a comment is wrong, unfair or unwelcome is answered with exactly that.
How to report a breach
Write to abuse@gplatform.org. Name the account, the post or the resource, say what is happening and include what shows it. For a post you believe to be unlawful, say where it is and why. We acknowledge every report within 24 hours and tell you what we decided. Reports about names and addresses are handled under the abuse and sanctions policy, and reports about names may also go to the address the GOpenCDR acceptable use policy gives.
Consequences
Breaking this policy can lead to a post being removed from public view, to API keys and automation keys being revoked, to sessions being ended, to an account being suspended and, where the breach is serious or repeated, to the account being closed. Measures are proportionate: the lightest one that stops the harm is used, and a restriction is lifted once its cause has been dealt with. Every measure comes with a statement of reasons and can be challenged as the GOpenCSR terms describe. What happens to names and addresses follows the registries' policies and the abuse and sanctions policy.