On September 8 a LowEndSpirit member posted an email that Dasabo, a VPS and hosting provider incorporated in Palermo, had sent to customers. “In compliance with applicable European regulations regarding security, transparency, and the prevention of illicit activities, our organization is required to perform a customer identity verification process (KYC – Know Your Customer),” it read, with a Stripe verification link and a deadline: “Failure to complete or fully finalize the verification within 10 days of this notification will result in the closure of your account and the termination of all provided services, pursuant to applicable law and contract terms.” The poster’s summary was shorter: “They blocked all accounts and forcing to complete KYC. Some getting 3x price hike.”

Three weeks on, the outline is no longer in dispute, because Dasabo has confirmed most of it in its own words. Posting in the same thread fourteen times between September 8 and 10, the company said the check requires “nothing more than a valid ID document and a live photo,” that accounts which do not complete it are closed, and, asked whether customers who decline get a prorated refund, answered: “No, as stated in article 14.1 of ToS.” It had quoted the clause in full earlier that day. What remains contested is scale. Dasabo said on September 8 that the demand went only to accounts “flagged by system alerts or other compliance triggers” and that “hundreds of legitimate customers completed the KYC check seamlessly within the first 24 hours.” Customers on two forums and on Trustpilot say it reached people who had done nothing but pay, some of them years in advance. For anyone buying low-end VPS capacity from small European providers, the case sets out what a host can do overnight to a paid account, and how little a customer can do about it once the portal is locked.

Key facts

  • The demand: a Stripe Identity check, an ID document and a live photo, within ten days of an email, or the account is closed and services terminated. The email was reproduced on LowEndSpirit on September 8 and quoted again by LowEndBox on September 14.
  • The company’s position: only flagged accounts were asked; “98% of the users who currently refuse to complete KYC clearly used false information during registration”; the legal basis cited is Italy’s E-Commerce Decree, the NIS2 transposition, data retention rules and tax law; no refunds, under clause 14.1 of its terms, which lets Dasabo “terminate the contract while retaining any amounts paid as a penalty” where data is false or incomplete.
  • The customers’ position: accounts locked so that tickets could not be opened; terminations after a name mismatch between account and ID; prepaid multi-year services ended without refund; prices tripled on renewal. All of these are allegations by named forum and Trustpilot users; Dasabo has denied being unreachable, pointing to live chat and a listed email address, has defended the name-mismatch terminations, and has not addressed pricing.
  • The company: DASABO SRL, VAT IT07407380828, Via Imperatore Federico 100, Palermo, per WHTop’s profile; the Estonian DASABO OÜ entered liquidation in April 2026. In May, Dasabo admitted that “an internal collaborator” in support had made unauthorised payment actions affecting 13 customers, five of which went through.
  • Trustpilot: 2.6 out of 5 from 92 reviews as of this week, one-star reviews dated through September, and company replies defending KYC as “a standard and essential operational practice.”

What Dasabo Says the Law Requires, and What It Will Not Say

Dasabo’s account, given across fourteen posts by the user “Dasabo” on LowEndSpirit between the evening of September 8 and the afternoon of September 10, is that the check is a compliance measure a company selling into the Italian public sector cannot avoid. “Since arriving in Italy, we have obtained various certifications that allow us to operate in the public sector and sell to public administration bodies; the associated audits are quite rigorous and very strict,” it wrote. Asked which laws require KYC of a hosting provider, it listed “the E-Commerce Decree (Legislative Decree 70/2003) and the Obligation to Cooperate, the NIS2 Directive (Legislative Decree 138/2024), Data Retention rules (Art. 132 of the Privacy Code – Legislative Decree 196/2003), and tax obligations (Presidential Decree 633/1972), among others.”

It was less specific about why the demand landed when it did. “There are specific security-related reasons why some of our users are currently required to undergo the Enhanced KYC process; I cannot disclose the specific details,” the company wrote. “Similarly, refusing to complete the KYC process when requested raises the risk level for us regarding that client compounded by other concerns I cannot disclose. For this reason, we proceed to close the account and terminate the service.” It added: “We have already factored in the loss of some users due to KYC, but we would rather lose them than face far more serious legal repercussions down the line.”

On the central factual dispute, whether every customer was locked out, Dasabo’s first post on September 8 set the line: “Enhanced KYC (Know Your Customer) verification is not being requested for all accounts. It applies only to specific accounts flagged by system alerts or other compliance triggers.” The same post said that “hundreds of legitimate customers completed the KYC check seamlessly within the first 24 hours without issue,” a figure that, if accurate, is hard to square with a demand sent only to a flagged minority. Pressed on September 9, the company answered that the forum could not know the scale: “The fact that several users on a forum are complaining about receiving a verification email does not mean that all users are affected; claiming ‘everyone’ is involved without even knowing our total customer count is factually incorrect, especially since we have never disclosed how many customers we actually have.” On September 10 it also rejected the claim that locked customers had no way to reach it: “It is also false to claim that we cannot be contacted because the customer area is frozen until the user completes KYC; in fact, our website features live chat, and our email address is listed in the “Consumer Information” section of the terms and conditions.”

Ten Days, Then Nothing Back

The refund position is the part that turned a compliance dispute into a reputational one. On September 10 a LowEndSpirit member, yoursunny, asked whether Dasabo would “provide prorated refunds (including any applicable transaction fees) for customers who choose not to undergo the Enhanced KYC process.” The answer was one line: “No, as stated in article 14.1 of ToS.” Another member, ialexpw, spelled out what that meant: someone on annual billing who has used the service without incident and declines the check, “you’re cancelling it without any type of a refund?” Earlier the same day Dasabo had quoted the clause itself, “in English for informational purposes”: “14.1 The Customer warrants that the personal data provided is truthful, current, and complete. The Customer undertakes to notify Dasabo of any changes within 15 days. In the event of omissions or false data, Dasabo may: refuse transactions, suspend services, reverse changes, or terminate the contract while retaining any amounts paid as a penalty.” The clause conditions forfeiture on false or missing data. Dasabo’s public position is that declining the check, or failing it, is evidence of exactly that.

The reviews that followed describe the consequence. On Trustpilot, miaosir wrote on September 18: “I completed this KYC, but DASABO thought the account name is not the same as the one in my ID card. Hence, DASABO thought I am a risk of money laundering and terrorism, and terminated my account without refunding the advance payments.” Dasabo’s reply defends that outcome: “Discrepancies between the registered account information and official government-issued documentation present compliance risks that we are legally and operationally obligated to address.” Nick wrote the same day of a prepaid two-year VPS terminated “all over a 10-day KYC ultimatum that went straight into my spam folder.” Drietakt, on September 19: “I paid for 4 years of service but received less than 2 years.” Dasabo’s reply to another September 18 review states the policy without softening it: “When verification requests remain unfulfilled after the notice period, we are obligated under our security policies to terminate the associated services.”

The price claim in the opening post has two Trustpilot reviews behind it. Drietakt describes “A small VPS for only €12 for 2 years” and, six months before the end of the contract, “a bizarre price increase to €33.60 per year.” Will writes: “Also, they have raised their prices like x3 times and terminated servers much earlier.” The LowEndSpirit thread itself gives no figures beyond “3x,” and Dasabo has not addressed renewal pricing in any post we could find.

Even the provider’s defenders on the thread drew the line at the money. AnthonySmith, who runs TierHive and argued that most EU businesses must be able to identify customers for their books, wrote: “What I really do NOT agree with is not refunding people; if you are worried enough about the account to force KYC, you should be just as worried about a chargeback. Just move on, remove the customer, remove the burden, remove the money, give it back; everyone is square then.” He advised Dasabo to “backtrack and agree to refund anyone who can be practically refunded when terminating.” Dasabo’s account on LowEndSpirit was banned on September 10 under the forum’s new downvote rule, so it could no longer reply there; Smith wrote on September 12 that “it was a mistake to ban him, it takes away any opportunity to communicate,” and on September 19 that Dasabo’s paid advertising subscription “was cancelled.” The thread then records what happened next. On September 18, poei, who says his payment and address were already linked through Stripe, wrote that “Dasabo still cancelled my account and services I already paid for in full. Vague reasoning and zero refund.” The same day the provider c1vhosting reported that it had “received a formal cease-and-desist letter” from Dasabo “just for commenting in this thread.” On September 22 Smith added that he had “seen screenshots shared privately showing people with genuine details in the system that got hit with this.”

The Second Incident in Four Months

The KYC demand arrived at a company already explaining itself. LowEndBox reported on May 12 that DASABO OÜ, the Estonian entity, had been acquired by DASABO SRL, the Italian one, “purely for administrative reasons” in Dasabo’s words, and that in the same week customers had been charged amounts they had not authorised. Dasabo first said it was “technically impossible for us to access or store your card details in plain text,” then within hours admitted that “an internal collaborator” in customer support had “misused their assigned access privileges by performing unauthorized payment-related actions” between May 5 and 8. Thirteen customers were affected, five charges went through, and all were refunded, per the company’s account as reported by LowEndBox.

That history is why the ID request reads differently to Dasabo’s customers than it would from a provider with a clean year. LowEndBox’s raindog308, writing on September 14 as a former customer who received the email and, on logging in, found a screen reading “account bloccato,” put it this way: “And remember, they already had one employee who started issuing fraudulent charges to people’s payment methods on file…and now they want me to upload government ID.” A customer with data on a Dasabo server has, on the record so far, three options: complete the Stripe check and hope the name on the ID matches the account, use the live chat or the email address in the terms, which Dasabo says remain open, to cancel or export, or lose the service and the prepayment together. Clause 14.1, as Dasabo quotes it, permits the third outcome only where data is false or incomplete. Whether a name that differs from an ID, or a check never completed, meets that test is the question the terminated customers are now asking, and it is one a court rather than a forum would have to answer.

Every statement attributed to Dasabo is quoted from its fourteen posts on the LowEndSpirit thread between September 8 and 10, 2026, read in full on September 28; clause 14.1 is quoted as Dasabo rendered it in English, not from the Italian original. Dasabo’s website and terms of service, and the LowEndTalk threads on the same subject, refused automated requests and are not cited. Trustpilot reviews and company replies are quoted as they appeared on September 28. Allegations by customers are reported as allegations. Dasabo was not contacted for this article.