Skip to content
Metroreach homeCheck availability

Acceptable Use Policy

MetroReach Internet Services

Full Fibre Broadband · Open Access FTTH · Retail & Wholesale

Effective Date: 15 August 2025

This Acceptable Use Policy (AUP) sets out the rules and standards that apply to all users of MetroReach network services, including retail full fibre broadband customers, wholesale carrier partners, resellers, and any person who accesses the internet through MetroReach infrastructure. This AUP is incorporated by reference into the MetroReach Terms & Conditions and forms a binding part of the agreement between MetroReach and every customer.

MetroReach is committed to providing a fast, reliable, and secure open-access network for all of its customers. To protect the integrity of its network and to comply with Nigerian law, MetroReach requires that all users act responsibly and in accordance with this Policy. MetroReach reserves the right to take immediate action, including suspension or termination of services, against any user who violates this AUP.

This AUP should be read together with the Terms & Conditions and Privacy Policy. Wholesale customers and resellers are responsible for ensuring that their own end-users comply with this AUP.

1. Scope and Application

This AUP applies to:

  • All retail broadband subscribers using MetroReach full fibre services at residential or business premises
  • All wholesale customers, licensed ISPs, carriers, and resellers taking capacity or managed services from MetroReach
  • All end-users of services delivered over the MetroReach network by wholesale customers or resellers
  • Any person accessing the internet through MetroReach infrastructure, including authorised users on a customer's premises
  • All MetroReach-provided equipment, systems, portals, and APIs

Wholesale customers and resellers must incorporate equivalent acceptable use obligations into their own end-user agreements. MetroReach may hold wholesale customers directly liable for AUP violations committed by their end-users where the wholesale customer has failed to implement adequate controls.

2. General Principles of Responsible Use

All users of the MetroReach network are expected to use the Service in a responsible, ethical, and lawful manner. The following general principles underpin this Policy:

  • Use the network only for lawful purposes that comply with Nigerian federal and state law, including all NCC regulations
  • Respect the privacy, security, and property rights of other users and third parties
  • Do not take any action that interferes with or degrades the operation of the MetroReach network or the experience of other users
  • Do not attempt to circumvent any network security controls, monitoring systems, or traffic management mechanisms
  • Accept responsibility for all activity that occurs through your connection, whether initiated by you directly or by others you have permitted to use your connection
  • Notify MetroReach promptly if you become aware of any activity on your connection that violates this AUP

3. Prohibited Activities

The following activities are strictly prohibited on the MetroReach network. This list is illustrative and not exhaustive. MetroReach reserves the right to determine, in its reasonable discretion, whether any activity not listed below constitutes a violation of the spirit of this Policy.

3.1 Illegal Content and Activities

Users must not use the MetroReach network to transmit, distribute, access, store, or facilitate:

  • Child sexual abuse material (CSAM) or any content that sexually exploits or endangers minors
  • Content that promotes, glorifies, or facilitates terrorism, violent extremism, or incitement to violence under the Terrorism (Prevention and Prohibition) Act 2022
  • Content that constitutes hate speech, incitement to ethnic or religious violence, or that violates the Nigerian Constitution or the Cybercrimes Act
  • Unlicensed or pirated software, films, music, books, or other copyrighted material in breach of the Copyright Act (Cap. C28, LFN 2004) and the Digital Rights Management framework
  • Content that defames, harasses, or threatens individuals, whether private citizens or public officials
  • Material related to illegal gambling, unlicensed financial services, or investment fraud
  • Any content or activity that violates the provisions of the Cybercrimes (Prohibition, Prevention, etc.) Act 2015, the NCC regulations, or any other applicable Nigerian law

3.2 Unauthorised Access and Network Intrusion

Users must not:

  • Attempt to gain unauthorised access to any computer system, network, database, or device - whether owned by MetroReach, another customer, or any third party
  • Conduct, facilitate, or participate in port scanning, network mapping, or vulnerability probing of external systems without explicit written authorisation from the system owner
  • Exploit or attempt to exploit any software vulnerability, configuration weakness, or zero-day vulnerability in systems accessible via the MetroReach network
  • Deploy, execute, or distribute exploit frameworks, rootkits, keyloggers, or remote access tools (RATs) for malicious purposes
  • Conduct man-in-the-middle (MITM) attacks, ARP poisoning, DNS hijacking, or session hijacking against any network or user
  • Attempt to break, brute-force, or bypass any authentication mechanism, password system, or cryptographic control
  • Access, alter, or destroy data belonging to another person or organisation without authorisation

3.3 Malware, Viruses and Malicious Code

Users must not:

  • Introduce, transmit, or distribute viruses, worms, trojans, ransomware, spyware, adware, or any other malicious software onto the MetroReach network or to any connected system
  • Host, operate, or maintain command-and-control (C2) infrastructure for botnets, malware campaigns, or distributed attack networks
  • Use infected or compromised devices knowingly without taking steps to isolate or remediate them
  • Download, install, or execute software from untrusted sources that is reasonably likely to introduce malware into the network

Where MetroReach detects malware activity, botnet traffic, or C2 communications originating from a customer connection, it may immediately quarantine or isolate that connection to protect the wider network, without prior notice to the customer.

3.4 Denial of Service and Network Attacks

Users must not:

  • Launch, facilitate, or participate in Distributed Denial of Service (DDoS) attacks, volumetric floods, SYN floods, UDP amplification attacks, or any other form of network disruption attack against any target
  • Use the MetroReach network as a reflector or amplifier in DDoS attacks, including through open DNS resolvers, open NTP servers, or misconfigured services
  • Engage in packet-level attacks including IP spoofing, ICMP floods, or fragmentation attacks
  • Use the MetroReach network to attack MetroReach's own infrastructure, peering partners, or upstream transit providers
  • Operate any tool, service, or platform that is primarily designed to facilitate DDoS-for-hire (booter or stresser services)

3.5 Spam and Unsolicited Communications

Users must not:

  • Send unsolicited bulk email (spam), SMS messages, or any other form of unsolicited commercial communications in violation of applicable Nigerian law and NCC consumer protection guidelines
  • Operate open mail relays, open proxies, or any service that is routinely used to transmit spam or to conceal the true origin of communications
  • Use the MetroReach network to harvest email addresses, phone numbers, or other contact data without the consent of the individuals concerned
  • Conduct phishing campaigns, spear-phishing attacks, or any other social engineering activity designed to deceive users into disclosing credentials or personal information
  • Use spoofed sender addresses, forged headers, or deceptive routing to misrepresent the origin of electronic communications
  • Operate a snowshoe spamming operation or distribute spam across a large number of IP addresses to evade detection

3.6 Fraud, Identity Theft and Deception

Users must not:

  • Use the MetroReach network to commit fraud, advance-fee fraud (including 419 scams), romance fraud, or any other form of financial deception
  • Engage in identity theft, impersonation, or any activity designed to misrepresent a person's identity online
  • Create, distribute, or use counterfeit websites, fake login pages, or fraudulent online services to deceive users
  • Conduct Business Email Compromise (BEC) scams, invoice fraud, or any other form of corporate fraud
  • Use the MetroReach network to access, obtain, or use another person's financial accounts, payment credentials, or personal identifying information without authorisation
  • Operate any unlicensed financial service, Ponzi scheme, or pyramid selling scheme over the MetroReach network

3.7 Unauthorised Network Services and Infrastructure Misuse

Retail customers must not, without MetroReach's prior written consent:

  • Resell, sublease, or redistribute MetroReach retail broadband services to third parties for commercial gain
  • Operate open proxies, anonymising VPN exit nodes, Tor exit relays, or similar services that provide anonymised internet access to third parties at scale
  • Run public-facing servers (web, email, DNS, FTP, game servers) from a residential or standard business broadband connection in a manner that causes network congestion or violates applicable plan terms
  • Connect more devices or premises than permitted under the applicable service plan without upgrading to an appropriate tier
  • Attempt to exceed or circumvent the bandwidth, data volume, or usage thresholds applicable to the subscribed service plan
  • Use dynamic IP address rotation, MAC address spoofing, or other techniques to circumvent network access controls or identity verification mechanisms

3.8 Harassment, Stalking and Abuse

Users must not use the MetroReach network to:

  • Harass, bully, threaten, intimidate, or stalk any individual, whether online or in a manner that has offline consequences
  • Engage in coordinated harassment campaigns, pile-ons, or targeted abuse of individuals or communities
  • Share intimate images of another person without their consent (non-consensual intimate image abuse), in violation of the Violence Against Persons (Prohibition) Act 2015
  • Dox (publicly disclose private personal information about) individuals without their consent
  • Incite others to engage in harassment or abuse of a specific individual or group

3.9 Interference with MetroReach Infrastructure

Users must not:

  • Tamper with, damage, or interfere with any MetroReach network infrastructure, fibre cabling, optical equipment, or hardware deployed at their premises or in public areas
  • Attempt to access, reconfigure, or reverse-engineer any MetroReach network management system, OSS/BSS platform, or customer portal beyond the permissions granted to them
  • Conduct traffic injection, route hijacking (BGP hijacking), or prefix announcement manipulation on the MetroReach network
  • Exploit any vulnerability in MetroReach's network, systems, or APIs without prior written authorisation under a responsible disclosure programme
  • Attempt to bypass MetroReach's traffic management systems, QoS controls, or lawful interception mechanisms

3.10 Regulatory and Export Control Violations

Users must not:

  • Use the MetroReach network to violate Nigerian export control laws, sanctions regimes, or regulations administered by the CBN, EFCC, or other competent Nigerian authorities
  • Transmit, export, or re-export technology, software, or data in violation of applicable international trade control or sanctions regulations that Nigeria is party to
  • Operate services that circumvent or undermine lawful interception obligations imposed on MetroReach by the NCC or relevant security agencies under Nigerian law

4. Network Management and Fair Use

4.1 Fair Use Principles

MetroReach's full fibre network is a shared infrastructure. While MetroReach invests continuously in network capacity, all customers are expected to use the network in a manner that does not unreasonably impair the experience of other users. The following fair use principles apply:

  • Customers must not deliberately or consistently generate traffic volumes that materially and adversely affect other customers' service quality beyond what is reasonable for their plan tier
  • Business and wholesale customers operating high-volume applications (video streaming platforms, cloud backup services, large-scale content distribution) should contact MetroReach to discuss an appropriate plan or wholesale arrangement
  • Automated or scheduled bulk transfers should, where technically feasible, be configured to run during off-peak hours

4.2 Traffic Management Practices

MetroReach may apply the following traffic management techniques to protect network quality during periods of congestion or in response to AUP violations:

  • Traffic prioritisation: Latency-sensitive traffic (VoIP, interactive video) may be prioritised over bulk-transfer traffic during congestion
  • Rate limiting: Connections generating excessive traffic that affects the network may be temporarily rate-limited
  • Protocol management: Certain protocols associated with high abuse rates (e.g., open proxy protocols) may be rate-limited or blocked on residential plans
  • IP null-routing: IP addresses associated with confirmed DDoS activity or malware C2 may be null-routed to protect the wider network
  • Port filtering: Specific ports commonly exploited for abuse (e.g., SMTP port 25 on residential services) may be filtered by default

MetroReach will publish a summary of its traffic management practices at www.metroreach.ng. These practices are applied on a non-discriminatory basis and are consistent with MetroReach's obligations under NCC net neutrality guidelines.

4.3 Peering and Transit Partners

Wholesale customers and resellers must not conduct or permit activities over MetroReach's peering or transit connections that could result in MetroReach being blacklisted by upstream providers, peering exchanges, or international transit carriers. This includes:

  • Generating traffic that causes MetroReach's IP ranges to be listed on spam blacklists (DNSBLs)
  • Originating DDoS traffic that triggers off-net null-routing or peering de-peering by MetroReach's transit partners
  • Announcing unauthorised BGP prefixes or manipulating routing in a manner that affects MetroReach's peering relationships

5. Customer Security Responsibilities

5.1 Securing Your Connection

Each customer is responsible for the security of all devices connected to the MetroReach network through their subscription. MetroReach strongly recommends the following baseline security practices:

  • Change default passwords on all routers, access points, and connected devices immediately upon installation
  • Keep all operating systems, firmware, and applications up to date with the latest security patches
  • Enable firewall protection on all networked devices and on any router or gateway provided by MetroReach or the customer
  • Use strong, unique passwords and enable multi-factor authentication (MFA) on all accounts accessible from your connection
  • Disable or remove any network services (e.g., remote desktop, UPnP, Telnet) that are not actively required
  • Segment IoT devices on a separate VLAN or guest network where possible
  • Conduct regular malware scans on devices using reputable, up-to-date antivirus or endpoint protection software

5.2 Compromised Connections

If a customer's connection is compromised - for example, if their router is used to participate in a botnet or DDoS attack - MetroReach may take immediate action to protect the network, including rate-limiting, isolating, or suspending the affected connection. MetroReach will notify the customer as soon as practicable where suspension is due to suspected compromise.

The customer is expected to investigate and remediate the compromise promptly. MetroReach may require evidence of remediation before restoring full service. Persistent or repeated compromise events resulting from the customer's failure to maintain reasonable security may be treated as an AUP violation.

5.3 Vulnerability Disclosure

MetroReach encourages responsible disclosure of any security vulnerability discovered in its network, systems, or infrastructure. Any person who identifies a potential vulnerability should report it to security@metroreach.ng without exploiting it, without disclosing it publicly, and without accessing data beyond what is necessary to demonstrate the vulnerability. MetroReach will acknowledge reports within 5 working days and will work to remediate confirmed vulnerabilities promptly.

Unauthorised probing, testing, or exploitation of MetroReach infrastructure - even if motivated by a desire to report a vulnerability - constitutes an AUP violation and may be reported to the NCC and law enforcement authorities.

6. Content Standards

MetroReach is a connectivity provider and does not proactively monitor or moderate the content transmitted over its network. However, MetroReach will act in response to notices of illegal content, court orders, NCC directives, and credible reports of serious harm, as required by law.

6.1 Hosting and Publishing

Customers hosting websites, applications, or services accessible via the MetroReach network must ensure that:

  • All content complies with applicable Nigerian law and does not fall within any category of prohibited content listed in Section 3
  • Third-party content hosted on their platforms (user-generated content) is subject to adequate moderation and take-down processes
  • Hosting services are not used to distribute malware, host phishing pages, or serve as command-and-control infrastructure
  • Any content subject to copyright or intellectual property rights is published only with the appropriate licence or permission

6.2 Peer-to-Peer (P2P) File Sharing

Peer-to-peer file sharing is permitted on the MetroReach network for lawful purposes, including the distribution of open-source software and licensed content. The following restrictions apply:

  • P2P sharing of copyrighted material without a licence or the rights holder's permission is strictly prohibited
  • Customers must not use BitTorrent, eDonkey, or similar protocols to distribute content that infringes on intellectual property rights
  • MetroReach may receive and act upon notices from rights holders or their agents regarding copyright infringement under applicable Nigerian law

6.3 Encrypted Traffic and VPNs

Customers may use VPNs and encrypted tunnels for legitimate privacy, security, and business purposes. However, the use of encryption does not exempt a user from compliance with this AUP. MetroReach reserves the right to take action where it has reasonable grounds to believe that encrypted traffic is being used to mask AUP violations or illegal activity.

Operating public VPN or anonymisation services that provide exit-node access to third parties at scale on a retail broadband subscription is prohibited without MetroReach's prior written consent.

7. Wholesale Customer and Reseller Obligations

Wholesale customers and resellers occupy a position of elevated responsibility under this AUP, as they are accountable both for their own use of the MetroReach network and for the activities of their end-users.

Wholesale customers must incorporate this AUP, or equivalent obligations, into their own end-user terms and conditions

Wholesale customers must maintain and enforce adequate mechanisms to monitor for, detect, and respond to AUP violations by their end-users

Wholesale customers must act promptly on AUP violation notices issued by MetroReach and provide a written response within 24 hours of receipt of an urgent notice

Wholesale customers must maintain up-to-date abuse contact details (abuse@ address) registered with AFRINIC and other applicable RIRs for all IP allocations used on the MetroReach network

Wholesale customers are responsible for ensuring their own routing announcements are accurate, authorised, and comply with RPKI and IRR filtering policies applied by MetroReach

Wholesale customers must not use MetroReach's network to bypass the AUP controls of their own upstream providers

MetroReach may hold wholesale customers directly liable and may suspend wholesale services where a wholesale customer's end-users are responsible for persistent or severe AUP violations and the wholesale customer has failed to take adequate remedial action within the required timeframe.

8. Monitoring, Detection and Enforcement

8.1 Network Monitoring

MetroReach monitors its network for security threats, AUP violations, and abnormal traffic patterns using automated systems, flow analysis, and threat intelligence feeds. This monitoring is conducted in accordance with MetroReach's Privacy Policy and applicable Nigerian law, including the Cybercrimes Act and NCC lawful interception regulations. MetroReach does not conduct deep packet inspection (DPI) of customer content for commercial purposes.

8.2 Abuse Reports

MetroReach maintains an abuse handling team that receives and investigates abuse reports from third parties, NCC, law enforcement, and other network operators. Reports can be submitted to abuse@metroreach.ng. MetroReach will:

  • Acknowledge all abuse reports within 4 business hours.
  • Investigate each report and assess whether an AUP violation has occurred.
  • Take appropriate remedial action, which may include contacting the customer, issuing a warning, or suspending the service.
  • Provide a response to the reporting party within 5 working days, subject to legal constraints on disclosure.

8.3 Enforcement Actions

Where MetroReach determines that a violation of this AUP has occurred or is occurring, it may take one or more of the following actions, proportionate to the severity of the violation:

Violation Category Response / Consequence
Minor / First Offence Written warning issued to the customer. Customer required to cease the activity and confirm compliance in writing.
Repeated Minor Violation Temporary rate-limiting or traffic shaping of the affected connection, plus a final written warning.
Moderate Violation Temporary suspension of the Service for up to 30 days. Service restored on written confirmation of compliance and, where applicable, payment of a reconnection fee.
Serious / Intentional Violation Immediate and permanent termination of the Service without refund. Early Termination Charges may not apply where termination is due to AUP breach.
Illegal Activity Immediate suspension of the Service, preservation of relevant data, and referral to the NCC, Nigeria Police Force, EFCC, DSS, or other competent authorities as required by law.
DDoS / Network Attack Immediate null-routing or quarantine of the affected connection to protect the network, followed by formal investigation and likely termination.
CSAM / Terrorism Content Immediate suspension, mandatory reporting to the NCC, Nigeria Police Force (FCID), and INTERPOL as required. No reinstatement under any circumstances.

MetroReach will use reasonable endeavours to notify the customer of enforcement action and the reason for it, except where immediate action is required to protect the network or where notification would compromise an active law enforcement investigation.

8.4 Law Enforcement Cooperation

MetroReach will comply with all lawful orders, warrants, and directives issued by Nigerian courts, the NCC, the Nigeria Police Force, the DSS, the EFCC, and other competent authorities. This includes providing subscriber information, traffic data, and preserved logs as required under the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 and the Nigerian Communications Act 2003.

MetroReach maintains a statutory data retention period of 2 years for traffic and subscriber data, in accordance with the Cybercrimes Act. All law enforcement requests must be submitted through formal legal channels to legal@metroreach.ng.

9. Reporting Violations

MetroReach encourages any person who becomes aware of an AUP violation originating from the MetroReach network to report it promptly. Reports help MetroReach maintain a clean, secure, and responsible network for all users.

Abuse reports: abuse@metroreach.ng (include originating IP, timestamp in UTC, and a description of the activity)

Security vulnerabilities: security@metroreach.ng (see responsible disclosure process in Section 5.3)

CSAM and child exploitation: MetroReach is legally required to report such content to the NCC and Nigeria Police Force. To report, email abuse@metroreach.ng marked URGENT - CSAM

Law enforcement and legal requests: legal@metroreach.ng

MetroReach will handle all reports confidentially and will not disclose the identity of a reporting party to the subject of the report without the reporter's consent, except where required by law.

10. Customer Rights and Appeal Process

MetroReach is committed to fair and proportionate enforcement of this AUP. Customers who believe that enforcement action has been taken against them in error, or who have remediated a violation and wish to request reinstatement, may appeal through the following process:

Step 1 - Informal Resolution

Within 5 working days of suspension or termination, contact MetroReach Support at support@metroreach.ng or by telephone, explaining the circumstances and providing any evidence of compliance or remediation. MetroReach will review and respond within 3 working days.

Step 2 - Formal Written Appeal

Within 14 days of suspension or termination, if the informal resolution is unsuccessful, submit a formal written appeal to the MetroReach Compliance Team at compliance@metroreach.ng. The appeal must include the customer's name and account reference, a detailed explanation of the circumstances, supporting evidence, and the specific remedy requested. MetroReach will provide a written decision within 10 working days.

Step 3 - Regulatory Escalation

If the formal appeal does not resolve the matter to the customer's satisfaction, retail customers may escalate the complaint to the Nigerian Communications Commission (NCC) through its consumer complaints framework at www.ncc.gov.ng.

Appeals against enforcement actions taken in response to illegal activity, CSAM, terrorism content, or active law enforcement investigations will not be considered for reinstatement under any circumstances.

11. Changes to this Policy

MetroReach may update this AUP at any time to reflect changes in Nigerian law, NCC regulations, network technology, or the evolving threat landscape. Updated versions will be published at www.metroreach.ng with a revised effective date. Where changes are material, MetroReach will notify customers via email or the customer portal with at least 14 days' prior notice.

Continued use of the MetroReach Service after the effective date of any revised AUP constitutes acceptance of the updated Policy. Wholesale customers are responsible for cascading material AUP changes to their own end-users in a timely manner.

12. Key Definitions

AUP: This Acceptable Use Policy, as updated from time to time.

Botnet: A network of internet-connected devices infected with malicious software and controlled remotely by a threat actor.

CSAM: Child Sexual Abuse Material - any image, video, or content that sexually depicts or exploits a person under the age of 18.

C2 / Command-and-Control: Infrastructure used by a threat actor to issue instructions to compromised devices or malware.

DDoS: Distributed Denial of Service - a coordinated attack using multiple systems to overwhelm a target's network or services.

DNSBL: DNS-based Blackhole List - a list of IP addresses known to be associated with spam or abuse.

DPI: Deep Packet Inspection - the inspection of packet content (beyond headers) for traffic management or security purposes.

FTTH: Fibre to the Home - full fibre optical broadband delivered directly to a residential or business premises.

IP Null-routing: A traffic management technique that silently discards all traffic destined for a specified IP address.

NCC: Nigerian Communications Commission - the regulatory authority for the Nigerian telecommunications sector.

Open-Access Network: The shared passive fibre infrastructure over which MetroReach provides retail and wholesale services.

RPKI: Resource Public Key Infrastructure - a cryptographic framework for securing BGP routing announcements.

Service: Any internet connectivity service, wholesale capacity product, or managed service provided by MetroReach.

Wholesale Customer: A licensed ISP, carrier, or operator that takes capacity or services from MetroReach for onward supply.

MetroReach is committed to maintaining a secure, reliable, and responsible network for all of its customers. Thank you for using the network responsibly.

HomePrivacy PolicyTerms & ConditionsAcceptable Use Policy