This policy sets out the conduct prohibited on the StageVPN service provided by nbase (엔베이스) (trade name: NBASE KOREA Co., Ltd. (엔베이스코리아 주식회사); the “Company”) and the criteria for the measures taken when a violation occurs. This policy contains the detailed standards referred to in Article 23 of the Terms of Service and applies to all individual Members, Business Customers and Team Members of Business Customers.
1. Basic Principles
- StageVPN is a service for lawful purposes, such as protecting communications on public Wi-Fi, connecting securely while traveling or on business trips, and remote work for businesses.
- Using a VPN does not remove users’ legal responsibility for their actions, and the Company retains connection logs in accordance with applicable laws.
- Users must comply with the laws of the Republic of Korea, the laws of the country or region where they use the Service, and the terms of use of the services they access. Some countries restrict or regulate the use of VPNs as such, so users must check before use.
2. Prohibition of Illegal Activities and Criminal Use
Using the Service for conduct prohibited by law, such as the following, or assisting such conduct, is prohibited.
- Producing, distributing, purchasing or possessing information whose distribution or possession is prohibited by law, such as child or adolescent sexual exploitation material and illegally filmed material
- Fraud, telecommunications financial fraud (voice phishing), illegal gambling, trading in illegal goods such as narcotics or weapons, and money laundering
- Unlawfully collecting, trading or misappropriating other people’s personal information or account information
- Planning or committing crimes such as terrorism, violence or threats, and conduct that violates export controls or economic sanctions under applicable laws
- Any other conduct that violates the laws of the Republic of Korea or of the country of use
3. Prohibition of Spam and Deceptive Practices
- Sending advertising information for commercial purposes in bulk by email, text message, messenger, bulletin board or other means without the recipients’ prior consent
- Deceiving others to obtain information or money, such as by operating phishing pages or falsifying sender information
- Operating mail servers for bulk sending, or sending email directly through the Service (the Company may restrict certain ports, such as mail-sending ports, to prevent spam)
- Using automated tools to create or manipulate accounts, reviews, comments, votes, ad clicks and the like in bulk
4. Prohibition of Attacks on Networks and Systems
- Unauthorized access (hacking), password brute-forcing and credential stuffing, and circumventing security measures
- Port scanning, vulnerability scanning and penetration testing without authorization
- Denial-of-service (DoS and DDoS) attacks, traffic amplification attacks, and operating botnets or command-and-control (C2) servers
- Creating or distributing malware, ransomware or spyware, or controlling infected devices
- Attacks on, or interference with, the Company’s servers, other users or the Company’s partners
Even for security research purposes, users must not engage in the above conduct without the explicit permission of the owner of the target system.
5. Prohibition of Infringing the Rights of Others
- Infringing intellectual property rights such as copyrights and trademarks, for example by copying, distributing or sharing videos, music, software or books (including P2P sharing) without the rights holder’s permission
- Defamation, insult, stalking, cyberbullying and invasion of privacy
- Impersonating the Company, its employees, other users or third parties
The Company does not encourage or guarantee the circumvention of region-specific terms of use or license restrictions of any content service. Complying with the terms of use of the services they access is the user’s responsibility.
6. Prohibition of Service Abuse
- Selling, reselling, lending or transferring accounts, subscriptions or VPN configuration information, or sharing them with multiple people, without the Company’s prior written consent
- Re-providing the Service to third parties as a public proxy, shared exit node, VPN for redistribution or the like
- Circumventing usage limits or conditions set by the Company, such as the number of simultaneously connected devices, the period of use, data limits, or payment or verification procedures
- Creating multiple accounts to repeatedly obtain free benefits or promotions, using stolen payment methods, or improperly reversing payments (chargebacks)
- Reverse engineering or modifying the Company’s software beyond the extent permitted by law, or analyzing or circumventing its servers and authentication systems
- Persistently generating abnormally high volumes of traffic or connections to a degree that significantly interferes with other users’ normal use
7. Rules for Using Business Dedicated IPs
- Dedicated IPs are assigned under the Business Contract for business use by the relevant Business Customer and its Team Members.
- Business Customers and Team Members must not engage in any of the following conduct:
- Sharing, reselling or lending a Dedicated IP or Business VPN access rights to individuals or organizations outside the business
- Providing a Dedicated IP to outside parties as a means of improperly passing IP allowlist (whitelist) authentication on third-party systems
- Spam sending, bulk automated scraping, attacks or other conduct that may damage the reputation of the Dedicated IP and cause it to be placed on blocklists
- Use beyond the number of users, countries or purposes permitted in the Business Contract
- Business Customers must remove without delay any Team Member who is no longer authorized due to resignation, transfer or similar reasons, and are responsible for Team Members’ violations as set out in the Business Contract.
- If a Dedicated IP is placed on a blocklist because of a violation, the Company will notify the Business Customer and may, where necessary, temporarily suspend the use of the Dedicated IP or replace it.
8. Identifying Violations and Enforcement Measures
(1) The Company does not view the content of communications. Violations are identified based on third-party reports (such as abuse reports), lawful requests from investigative agencies and other authorities, operational metrics that are not the content of communications (such as connection counts, data transfer volumes and ports), payment records and similar information.
(2) Taking into account the severity of the violation, whether it is repeated and the extent of the harm, the Company may take the following measures:
- Warning and request for correction
- Restriction of the use of specific servers, ports or features
- Temporary suspension of the account or of Business VPN access
- Termination of the service agreement and restriction on re-registration
(3) Before taking a measure, the Company will inform the user of the reason for it, its details and how to file an objection. However, where urgent action is needed to prevent harm from spreading, such as when an attack is in progress or illegal information is being distributed, or where there is a request under applicable law, the Company may take the measure first and inform the user without delay afterwards.
(4) Where there is a legal obligation to report, or a serious crime is suspected, the Company may report the matter to the relevant authorities. If a violation causes damage to the Company or a third party, the Company may claim compensation.
(5) Refunds resulting from measures are governed by the Billing & Refund Policy.
9. Objections and Abuse Reports
- If you disagree with a measure, you may file an objection with the customer center (support@stagevpn.com) within 14 days from the date you received notice of it. The Company will review the objection and inform you of the outcome, and if the objection is justified, it will immediately restore your use.
- If you believe that spam, an attack, an infringement of rights or similar conduct has originated from the IP address of a StageVPN server, please report it to the same email address, stating the date and time (including the time zone), the target IP address and port, and the details. The Company will review the report and take the necessary action.
Revision history
| Version | Published | Effective | Summary of changes |
|---|---|---|---|
| 1.0 | 29 September 2026 | 1 October 2026 | Initial version |
Questions about this document
Send questions about our terms and policies, or requests to exercise your rights, to the contacts below. We respond without undue delay.
- Customer center: [Customer center phone] ([Customer center hours])
- Email: support@stagevpn.com
- Chief Privacy Officer: privacy@stagevpn.com