Purpose and scope
This Acceptable Use Policy (AUP) governs the registration and use of subdomains managed by HMJP Limited (RC1203744), trading as Enterprise IT. It applies to registrants, registrar partners, resellers, and anyone operating a managed domain. It forms part of the Terms of Service and applicable registration agreement.
Enterprise IT operates a private subdomain registry. NiRA operates the upstream .ng registry. A managed registration grants a conditional right to use a label within an Enterprise IT namespace; it does not transfer ownership of that namespace or imply government endorsement.
Definitions and responsibilities
| Term | Meaning |
|---|---|
| Registry | HMJP Limited, trading as Enterprise IT, administering its managed namespaces. |
| Registrar | The approved partner that submits transactions and supports the registrant. |
| Registrant | The person or organisation holding the contractual right to use a registered name. |
| Managed domain | A registered label beneath an Enterprise IT namespace, such as example.biz.ng. |
| Hold | A restriction that may stop DNS resolution while preserving the registration record. |
| Abuse | Conduct that breaches this policy, applicable law, or another incorporated registry policy. |
Registrants remain responsible for their users, delegated administrators, websites, email, and other services using a managed domain. A reseller or hosting provider does not remove that responsibility.
Namespace eligibility
Names must accurately represent their intended use. The table below identifies the intended registrant or use for each namespace. Applicants must meet the applicable eligibility requirements. The registrar or registry may request evidence needed to establish identity, authority, and entitlement to the requested name. Approval of a label is not professional accreditation or verification of every claim made by its operator.
| Namespace | Intended use | Evidence where requested |
|---|---|---|
| biz.ng | Businesses and commercial activity | Business identity and a connection to the name. |
| ltd.ng | Private limited companies | Incorporation evidence showing the relevant legal form. |
| plc.ng | Public limited companies | Incorporation evidence establishing public limited status. |
| ngo.ng | Non-governmental and public-interest organisations | Registration, constitution, or evidence of legitimate organisational activity. |
| col.ng | Collectives, collaboration and collaborative learning | Open to individuals and organisations for commercial and non-commercial collaborative uses. Registrant identity, entitlement to the name, and authority to act for a group may be checked where relevant. College status, accreditation, incorporation and an existing membership list are not blanket prerequisites. Registration does not confer accreditation, recognition of qualifications, or endorsement. |
| gen.ng | General-purpose activity | Applicant identity and lawful intended use. Lawful business, project, community, and personal uses may qualify. |
| one.ng | General-purpose brands, projects, and individuals | Applicant identity and entitlement to the requested label. |
| ind.ng | Individuals and independent activity | Identity and a legitimate connection to the name. |
| ote.ng | Operational Test and Evaluation for development, staging, testing, evaluation and demonstrations | Open commercial registration for individuals and organisations, including prototypes, demonstrations, integration testing, and other lawful development or evaluation uses. Registrar accreditation or a private testing-programme invitation is not a general customer prerequisite. Domain registrations are governed by the applicable commercial terms and are not disposable registry test objects. |
False supporting documents, concealed ownership, or misrepresentation of legal or professional status are grounds for refusal or enforcement. Existing registrants must notify their registrar if they cease to meet eligibility requirements.
The expanded col.ng scope does not cancel an existing registration or require it to move solely because of this revision. Applicable registration terms and any registration-specific commitments continue to govern existing registrations.
Prohibited activity
Managed domains must not be used to organise, facilitate, or conceal:
- Phishing, credential theft, malware delivery, botnet control, pharming, or fraudulent redirection.
- Scams, payment fraud, identity theft, impersonation, or deceptive claims of official authority.
- Child sexual abuse material, exploitation, trafficking, or unlawful threats and incitement to violence.
- Infringement of intellectual property, unlawful disclosure of personal information, or knowingly misleading use of another party’s identity.
- Spam that delivers or enables DNS abuse, or unlawful bulk messaging.
- Attacks on DNS, registry interfaces, networks, or other users; unauthorised access; or evasion of security controls.
- Resale, delegation, or technical configurations designed to bypass namespace restrictions or an existing suspension.
Urgent harm: Active phishing, malware, exploitation, and comparable threats may require a hold before advance notice can be given. Emergency action does not itself determine every disputed fact or third-party right.
Registration data and technical integrity
Provide accurate contact details, keep an email address that can receive policy notices, and respond to verification requests. Your registrar is the first point of contact for corrections and lifecycle transactions.
Secure your account, nameservers, hosting, and email. Do not publish secrets in DNS records or upload passwords and authentication codes as evidence. Follow the Technical and Syntax Policy and Registration Data and RDAP Policy.
Reporting suspected abuse
Use the abuse report form. Identify the full domain, the activity, the relevant URLs or technical indicators, when it occurred, and evidence supporting the report. Explain whether the harm is ongoing. Provide a reachable contact address for clarification.
Submit only evidence you may lawfully share. For suspected child exploitation, provide the URL and a description; do not download or attach illegal imagery. Contact the appropriate emergency or law-enforcement service where there is an immediate threat to life.
Keep the case reference and reporter email address shown after submission. Use Track Abuse Report to view reporter-visible updates. A case reference alone does not disclose private evidence or internal investigation notes.
Assessment and notice
The compliance team assesses jurisdiction, domain control, evidence quality, urgency, and the likely effect of an intervention. It may request more information, contact the registrar or registrant, refer the matter to the hosting provider, or close a report that cannot be substantiated.
A complaint is not automatic proof of a breach. Where practicable, the affected party receives the relevant allegation and an opportunity to respond. Information may be withheld to protect people, an investigation, confidential sources, or legal obligations.
Enforcement and remediation
| Measure | When it may be used | Effect |
|---|---|---|
| Correction notice | Inaccurate data or a remediable policy breach | Requires action within the period stated in the notice. |
| Transaction restriction | A dispute, account compromise, or verification concern | Restricts specified changes or transfer. |
| DNS hold | Active harm or a material unresolved breach | Stops or limits resolution while the registration remains recorded. |
| Suspension or cancellation | Serious, repeated, or unremedied breach, or a binding order | Restricts service or ends the registration, subject to the governing process. |
| Referral | A matter requiring another provider or competent authority | Shares the information necessary for that purpose, subject to privacy rules. |
Measures may be combined or escalated according to the circumstances. A notice should identify the action, required remediation, and any applicable deadline unless disclosure is legally restricted.
Review and reinstatement
Ask the compliance desk to review an action, quoting the domain and case reference. Provide the disputed finding, supporting evidence, and completed remediation. File promptly and within any deadline stated in the notice.
Where practicable, review is handled by someone other than the original decision-maker. The registry may maintain protective restrictions while reviewing ongoing risk. Reinstatement may require corrected data, removal of harmful services, secured credentials, and confirmation from the registrar. A review does not automatically extend the registration term.
Rights disputes and legal orders
Trademark, ownership, eligibility, and competing-rights complaints follow the Dispute Resolution Policy. The registry does not award damages or determine complex ownership disputes through an abuse ticket.
Verified orders and applicable upstream policies may require action. NiRA procedures apply where the disputed registration falls within their scope; ICANN UDRP procedures are not automatically imposed on every private subdomain.
Expiry, reserved names, and commercial treatment
An expired or cancelled domain may remain restricted during recovery, dispute, security, or reservation review. Neither a lookup nor deletion guarantees immediate re-registration. The Reserved Name List and Premium Domain Policy explain allocation controls.
Payments, refunds, and credits follow the applicable registrar agreement and mandatory law. Enforcement does not create an automatic entitlement to a refund.
Policy changes and contact
The version and effective date above identify this publication. Material contractual changes are communicated through the registrar channel before taking effect where practicable; urgent legal or security measures may apply sooner with an explanation. Existing signed agreements and mandatory law determine any notice period.
This policy is governed by Nigerian law, without excluding rights that cannot lawfully be waived. Send policy questions or requests for review to the compliance desk.