COMPLAINT AND ABUSE HANDLING PROCEDURE
Abuse Handling Procedure
| Title | Complaint and Abuse Handling Procedure (Abuse Handling Procedure) |
| Company | PROSOX LLC |
| Version | 1.1 — current version |
| Effective Date | August 12, 2026 |
| Review Frequency | At least once a year, or upon any material change in legislation/upstream provider requirements |
| Document Owner | Compliance Officer |
| Classification | Internal document. For internal use only |
This Procedure is an internal governance document of PROSOX LLC and applies together with the Acceptable Use Policy, any applicable risk-based verification procedures (where in effect and to the extent applicable), and the requirements of the agreement with the upstream provider, Infatica Pte. Ltd. To the extent not governed by this Procedure, the foregoing documents, the applicable contractual requirements, and applicable law shall apply.
1. General Provisions
1.1 Purpose
This Procedure establishes a unified internal process for the intake, logging, review, and resolution of complaints and abuse reports relating to the use of PROSOX LLC’s services, as well as the procedure for applying response measures, maintaining an action log (audit trail), and escalating matters to the Legal, Compliance, and Management functions.
1.2 Scope
This Procedure applies to all reports of an alleged violation of the Acceptable Use Policy and applicable law in connection with the use of the proxy infrastructure operated by PROSOX LLC, regardless of the source of the report (third parties, rights holders, law enforcement authorities, the upstream provider, payment systems, or automated monitoring systems).
This Procedure applies to both B2C customers and B2B resellers. A customer is responsible for the actions of its users and end customers; PROSOX may require a reseller to take action against a violator within the reseller’s own customer base.
1.3 Core Principles
- Risk-based approach. The depth of review and the urgency of measures correspond to the category and severity of the violation; not all reports require the same scope of action.
- Timeliness. Compliance with established timeframes for initial response and resolution of a report.
- Documentation. Every report and every action taken is recorded so that the resulting decision can subsequently be justified and verified.
- Proportionality. The measure applied (warning, restriction, suspension, termination) is proportionate to the violation.
- Safety priority. Reports involving child safety, active attacks, and sanctions are handled on a priority basis and without prior notice to the violator.
1.4 Definitions
- Abuse report / complaint — a report of an alleged violation of the rules or of law.
- Complainant — the person or organization submitting the report.
- Customer — a person to whom PROSOX provides access to the service (either a B2C customer or a B2B reseller).
- Upstream provider — the provider of the proxy infrastructure (Infatica), whose contract gives rise to obligations that flow down to PROSOX’s customers.
- Audit trail — the body of records reflecting the chronology of the handling of a report and the measures taken.
- CSAM — child sexual abuse material.
2. Complaint Intake Channels
PROSOX maintains dedicated channels for the intake of abuse reports. Information about the channel is published on the website and, where necessary, communicated to the upstream provider and to payment systems.
- A dedicated email address: abuse@prosox.io — the primary intake channel.
- A “Report Abuse” contact form on the prosox.io website — where available and technically feasible.
- Reports concerning alleged violations of intellectual property rights are accepted via the primary channel, abuse@prosox.io, or via any other channel specifically designated by PROSOX for this purpose, if any (see Section 7.2).
- Reports received from the upstream provider (Infatica), payment systems, hosting and internet providers, and law enforcement authorities.
- Alerts from automated monitoring and anti-fraud systems (where available).
All reports received must be logged and assigned a unique identifier (Case ID), with the date and time of receipt recorded, regardless of channel. Reports received outside the designated channels (for example, through general support channels) are forwarded to the responsible person and logged under the standard procedure.
3. Classification of Reports and Priorities
Upon logging, each report is assigned a category and a priority level. The category determines the applicable protocol and response timeframes (Section 4).
| Category | Examples | Priority |
|---|---|---|
| Child safety (CSAM) | Any material or conduct involving the sexual exploitation of minors | CRITICAL |
| Active attacks | DDoS, distribution of malware, botnet/C2, port scanning, unauthorized access | HIGH |
| Sanctions | Matches against sanctions lists (OFAC SDN, etc.), prohibited jurisdiction | HIGH |
| Fraud and abuse | Fraud, phishing, credential stuffing, payment circumvention, spam | MEDIUM/HIGH |
| IP rights infringement | DMCA notices, infringement of copyrights and trademarks | MEDIUM |
| Platform rules violations | Violation of the terms of use of target platforms, absent indicia of a more serious violation | LOW/MEDIUM |
| Other | Other reports requiring assessment | AS ASSESSED |
4. Response Timeframes (SLA)
Target timeframes are established below. Timeframes run from the time the report is logged. For critical categories, action is taken immediately, ahead of other reports.
| Priority | Acknowledgment of Receipt | Initial Assessment | Target Resolution |
|---|---|---|---|
| Critical (CSAM) | Immediately | Immediately | Immediately + reporting |
| High | Within 4 hours | Within 24 hours | 1–3 business days |
| Medium | Within 24–48 hours | 1–3 business days | 5–10 business days |
| Low | Within 48–72 hours | 3–5 business days | As reviewed |
The above timeframes are internal targets. Where the agreement with the upstream provider or the rules of the payment systems establish shorter response timeframes, the shorter timeframes shall apply.
5. Report Review Procedure
Review is conducted sequentially; the scope of actions corresponds to the category of the report (risk-based approach).
- Logging. Assignment of a Case ID; recording of the source, date/time, category, and priority.
- Initial assessment (triage). Determination of the report’s validity and completeness, categorization, and assignment of the responsible person. For critical categories, immediate proceeding to response measures and escalation.
- Collection and preservation of evidence. Incorporation of the complainant’s materials (logs, IP addresses, timestamps, screenshots, links) and internal technical data enabling the report to be matched to a specific customer/session.
- Identification of the customer/session. Determination of the customer to which the report relates, within the limits of available technical data.
- Request for explanation (where applicable). In cases not requiring immediate suspension, the customer may be sent a request to cease the violation and/or to provide an explanation, with a reasonable deadline set. No notice is sent for critical categories.
- Decision and response measure. Adoption of a reasoned decision and application of a proportionate measure (Section 6); notification of the complainant to the necessary extent; recording in the audit trail.
- Closure of the report. Entry of a final record indicating the outcome and the grounds therefor.
6. Response Measures: Suspension and Termination
PROSOX reserves the right to restrict, suspend, or terminate a customer’s access to the service. The measure applied is determined by the category, severity, and recurrence of the violation.
6.1 Immediate Suspension / Blocking (Without Prior Notice)
Applied, in particular, where any of the following grounds is present:
- material or conduct involving CSAM or other exploitation of minors;
- an active attack or harm to third parties (DDoS, malware, botnet/C2, unauthorized access);
- a match against sanctions lists, or use from or directed at a prohibited jurisdiction;
- a court order or lawful demand of a law enforcement or other authorized authority;
- a substantiated demand by the upstream provider (Infatica) for immediate termination arising from flow-down obligations;
- a clear and immediate threat to safety, and other cases expressly provided for in the Acceptable Use Policy.
6.2 Suspension Following Notice
Applied in cases of less severe or ambiguous violations, where the customer has been given the opportunity to remedy the violation or provide an explanation, but the violation has not been remedied within the established timeframe or the explanation provided is deemed unsatisfactory.
6.3 Termination of Access
Applied, in particular, in the case of: a confirmed serious violation; repeated or systematic violations; use of the service for unlawful purposes; failure to remedy a violation following suspension; or the provision of knowingly false information.
6.4 Restoration of Access
Restoration is possible after the violation has been remedied and/or a satisfactory explanation has been provided, at the decision of the responsible person, and, in cases falling within the competence of Compliance/Legal, in coordination with them. For critical categories, access is, as a general rule, not restored.
7. Special Protocols
7.1 Child Safety (CSAM / NCMEC)
- zero tolerance; the report is handled on a priority basis;
- where sufficient grounds exist, immediate restriction or suspension of access, and preservation of case-related data for a period of not less than one (1) year from the date the report is submitted to the NCMEC CyberTipline, as required by 18 U.S.C. § 2258A(h) (as amended by the REPORT Act of 2024), or for such other period as may be established by applicable law, if longer than the period stated above;
- where an obligation arises under applicable U.S. law, including 18 U.S.C. § 2258A, the corresponding report is submitted to the NCMEC CyberTipline and/or another authorized authority by the Legal function or a person authorized by it;
- the handling, preservation, and transmission of the relevant materials are carried out only to the extent and in the manner permitted by applicable law, with access to such materials restricted;
- immediate escalation to Legal and Management.
7.2 DMCA / Intellectual Property Rights
- intake and logging of reports of alleged infringement of copyright and other intellectual property rights; determination of the applicable procedure having regard to PROSOX’s technical role and the provisions of 17 U.S.C. § 512. PROSOX maintains and keeps current a designated agent for the receipt of copyright infringement notices in the register of the U.S. Copyright Office (publishing the agent’s contact details on the prosox.io website and renewing the registration no less than once every three years), and adopts, reasonably implements, and communicates to customers a policy for terminating access of repeat infringers (repeat infringer policy) — these conditions are mandatory for the application of the limitations on liability under § 512, regardless of the applicable safe harbor category (including for transitory digital network communications under § 512(a));
- acknowledgment of receipt of the report and adoption of proportionate measures within the limits of PROSOX’s technical capability and legal role; notice-and-takedown / counter-notice procedures apply only to the extent applicable to the relevant service and situation;
- tracking of repeated substantiated violations and application of proportionate measures, up to and including restriction or termination of access, where required by applicable law, contractual terms, or the Acceptable Use Policy;
- the handling of intellectual property reports is also conducted with regard to obligations owed to the upstream provider; where the agreement establishes additional mandatory requirements, those requirements shall apply.
7.3 Sanctions (OFAC)
- screening against applicable sanctions lists (including the OFAC SDN List, where applicable) upon identification of relevant indicia or receipt of a report;
- in the event of a potential match, temporary restriction or suspension of service for the duration of the review, together with recording and escalation to Compliance/Legal; in the event of a confirmed match, the measures required by the applicable sanctions regime shall be applied;
- services are not provided in cases where doing so is prohibited by applicable sanctions restrictions; the assessment takes into account the specific sanctions program, the status of the person/jurisdiction, and any applicable licenses or exemptions.
7.4 Obligations to the Upstream Provider (Flow-Down)
The requirements of the Acceptable Use Policy and of the Infatica agreement flow down to PROSOX’s customers. Reports received from the upstream provider are handled on a priority basis and within the timeframes established by the relevant agreement; liaison with the upstream provider is carried out by the Compliance Officer.
7.5 Requests from Law Enforcement and Authorized Authorities
Handled with the involvement of Legal. Data is provided to the extent and in the manner prescribed by applicable law, on the basis of a duly executed request/court order. All communication is conducted exclusively through Legal/Compliance; all such requests are recorded in the audit trail.
8. Recordkeeping and Audit Trail
An action log is maintained for each report, enabling subsequent verification of the decision made.
8.1 Information Recorded
- Case ID; date and time of receipt; channel and source of the report;
- category and priority; brief description; evidence attached;
- customer/session identifier (within the limits of available data);
- actions taken and their chronology; notices sent;
- decision made and its grounds; measure applied; responsible person;
- fact and recipient of escalation; fact and recipient of external reporting (if any); date of closure.
8.2 Retention Periods and Protection
- The retention period for report records is three (3) years from the date of closure of the relevant report, unless a longer period is required by applicable law, contractual obligations, upstream provider requirements, or the need to preserve data in connection with an investigation, dispute, legal hold, or lawful request of an authorized authority. In particular: records and materials relating to CSAM/NCMEC reports are retained for not less than one (1) year from the date the report is submitted to the NCMEC CyberTipline (18 U.S.C. § 2258A(h)); records relating to sanctions screening and other documentation subject to OFAC recordkeeping requirements are retained for not less than ten (10) years.
- records are stored in a secured manner, with access restricted on a need-to-know basis;
- the integrity of records is maintained (protection against unauthorized alteration);
- the processing of personal data contained in records is carried out in accordance with the Privacy Policy and applicable data protection law; records subject to special mandatory retention periods (including applicable sanctions recordkeeping requirements) are retained for the applicable mandatory period.
9. Escalation (Legal / Compliance / Management)
Escalation ensures that a report is brought to the attention of the appropriate level of responsibility.
| Level | Responsible Party | When Engaged |
|---|---|---|
| Level 1 | Abuse desk / Support | Intake, logging, initial assessment, and routine measures for low/medium priority reports |
| Level 2 | Compliance Officer | Potential/unconfirmed sanctions matches (initial screening); repeat violations; ambiguous cases; recordkeeping and reporting matters |
| Level 3 | Legal (SynCo) | CSAM; confirmed sanctions list matches; law enforcement requests; DMCA disputes and counter-notices; liability risk; Infatica demands with legal implications |
| Level 4 | Management / CEO | Material reputational, legal, or commercial risk; termination of a major customer/reseller; crisis situations |
Immediate escalation to Level 3 (with notice to Level 4) is mandatory for the “Child Safety” and “Law Enforcement Requests” categories, and for the “Sanctions” category in the event of a confirmed sanctions list match (potential/unconfirmed matches are handled at Level 2 as set out in the table above), as well as in any case where the report creates a liability risk for PROSOX.
10. Roles and Responsibilities
- Abuse desk / Support — intake and logging of reports, initial assessment, routine measures, and maintenance of the audit trail.
- Compliance Officer — oversight of compliance with this Procedure, sanctions screening, recordkeeping and reporting matters, and liaison with payment systems and the upstream provider.
- Legal (SynCo) — legal assessment, liaison with law enforcement authorities, CSAM/DMCA protocols, and assessment of liability risk.
- Management / CEO — decision-making on material risks and crisis situations.
Specific responsible persons are designated by internal order of the organization and in the Approval Sheet to this Procedure.