Skip to content
V.PSV.PS
Deploy a Server

V.PS Terrorist Content Online (TCO) Policy

This page sets out how V.PS meets its obligations as a hosting service provider under Regulation (EU) 2021/784 of the European Parliament and of the Council of 29 April 2021 on addressing the dissemination of terrorist content online (the “TCO Regulation”). In this policy, “V.PS”, “xTom”, “we”, “us” and “our” each refer to xTom OÜ, a private limited company registered in the Republic of Estonia under registry code 14611015, with its registered office at Sepapaja tn 6, Tallinn, 15551, Estonia.

§ 1 Point of contact for removal orders (Art. 15 TCO Regulation)

Competent authorities of EU Member States can send removal orders, and decisions under Articles 4(4), 5 and 9 of the TCO Regulation, to our designated point of contact:

TCO Point of Contact – V.PS (xTom OÜ)
E-mail: [email protected]
Phone (urgent matters): +372 6850188
Postal: xTom OÜ, Sepapaja tn 6, Tallinn, 15551, Estonia

This contact point is primarily intended for competent authorities. Members of the public can also report terrorist or other illegal content to the same address, as described in our Acceptable Use Policy.

§ 2 Our policy on terrorist content (Art. 7(1) TCO Regulation)

2.1 Prohibition. Customers and their users may not use V.PS Services to store, publish or disseminate terrorist content within the meaning of Article 2(7) of the TCO Regulation. This includes material that incites or solicits the commission of terrorist offences, glorifies them, gives instructions for making or using weapons or explosives for terrorist purposes, or threatens to commit a terrorist offence. This prohibition is part of our Terms of Service (§ 11) and Acceptable Use Policy.

2.2 Protecting freedom of expression. Material disseminated for educational, journalistic, artistic or research purposes, or to prevent or counter terrorism, including polemic or controversial views expressed in public debate, is not treated as terrorist content (Article 1(3) of the TCO Regulation). We take account of the fundamental rights of all parties, in particular freedom of expression and information, whenever we act.

2.3 How we act on removal orders. When we receive a removal order from a competent authority, we:

  1. verify that the order comes from a competent authority and contains the information required by Article 3(4);
  2. remove the content, or disable access to it in all Member States, as soon as possible and in any event within one hour of receipt. As Customers have sole administrative control of their VPS and servers, we instruct the Customer to remove the content at once and, if this does not happen in time, disable access to the affected IP address(es), VPS, server or Service ourselves;
  3. confirm the action to the issuing authority;
  4. inform the affected content provider (see § 4) unless the authority has asked us not to for reasons of public security;
  5. preserve the removed content and related data in accordance with Article 6 (see 2.5).

If we cannot comply because of force majeure, de facto impossibility not attributable to us, or because the order contains manifest errors or lacks information, we inform the issuing authority without undue delay in accordance with Article 3(7) and (8).

2.4 Other measures we use. To identify, detect and remove terrorist content, we use the following measures:

2.5 Preservation of content. Content that has been removed, or to which access has been disabled, under the TCO Regulation, together with related data, is preserved for six months from removal. It is used only for administrative or judicial review or complaint handling, or for the prevention, detection, investigation and prosecution of terrorist offences. Preservation is extended where a competent authority or court requests it. Preserved data is protected by appropriate technical and organisational safeguards (Article 6).

2.6 Transparency reports. For any calendar year in which we have taken action against the dissemination of terrorist content or have been required to do so, we publish a transparency report on this page by 1 March of the following year, containing the information listed in Article 7(3) of the TCO Regulation.

§ 3 Complaint mechanism (Art. 10 TCO Regulation)

If content you provided has been removed, or access to it disabled, because of a removal order or a specific measure under the TCO Regulation, you can complain and ask for the content or access to be reinstated.

How to complain

Please include:

How we handle complaints

  1. We acknowledge receipt promptly.
  2. The complaint is reviewed by staff who were not involved in the original decision.
  3. If the removal or disabling was unjustified, we reinstate the content or access without undue delay. Where the removal was based on a removal order, content is reinstated only if the issuing authority has withdrawn the order or a court has annulled it, or the authority confirms that reinstatement is permitted.
  4. We inform you of the outcome within two weeks of receiving your complaint. If we reject the complaint, we give the reasons.

Using this mechanism does not affect your right to seek administrative or judicial redress. Under Article 9 of the TCO Regulation you can challenge a removal order before the courts of the Member State whose competent authority issued it.

§ 4 Information to content providers (Art. 11 TCO Regulation)

If we remove your content, or disable access to it, under the TCO Regulation, we tell you that this has happened, why, and how you can challenge it, including through the complaint mechanism above and the courts. On request, we provide a copy of the removal order. We do not inform you if the issuing authority has decided, for reasons of public security (e.g. to protect an ongoing investigation), that no information should be disclosed, and only for as long as that decision applies.

§ 5 Changes

We may update this page to reflect changes in the law, the guidance of competent authorities, or our Services.

Last updated: Oct 2, 2026