GPU Bare Metal B2B Service Terms
GPU Server Hub — version 1.1 dated 9 September 2026
English translation revision EN-1
This document is an English translation provided for convenience. The Polish version 1.1 is binding. In the event of any discrepancy, the Polish version prevails, subject to the priority of an individually agreed Order and any mandatory provisions of law.
Public path on the Provider's website: /terms/
These Terms apply to Agreements concluded from the date on which they are made available during the Order process. The Service is intended exclusively for businesses.
1. Provider and contact details
- The Provider is Janusz Ciuruś, conducting business under the business name BESTCONNECT CIURUŚ JANUSZ, Królówka 261, 32-722 Królówka, Poland, Polish Tax Identification Number (NIP) 8681799622, National Business Registry Number (REGON) 120967456, entered in the Central Register and Information on Economic Activity (CEIDG) and in the register of telecommunications undertakings maintained by the Polish Office of Electronic Communications (UKE) under number 8460, operating under the GPU Server Hub brand, hereinafter the “Provider”.
- The common point of contact for sales, technical support, security, reports concerning illegal content and data protection is contact@gpuserverhub.com. This is also the Provider's point of contact for authorities and recipients of the Service within the meaning of Articles 11 and 12 of Regulation (EU) 2022/2065; contact does not rely solely on automated tools.
- Contact is handled in Polish and English.
2. Definitions
- Customer — a business having its registered office or fixed establishment in Poland or another Member State of the European Union.
- User — a person authorised by the Customer to use the Service.
- Service — making a physical GPU server exclusively available to the Customer together with the elements specified in the Order, in particular power, cooling, connectivity and IP addressing. The Service is unmanaged unless the Order expressly states otherwise.
- Order — a document or electronic summary accepted by the Parties which specifies the configuration, price, term, activation date and any special conditions.
- Agreement — the Order, these Terms together with their annexes, and the documents expressly incorporated into the Order.
- Customer Data — any data, files, databases, images, configurations and other content entered or generated by the Customer or Users on the Server.
- Billing Period — one month, unless the Order specifies another period.
- P1 Incident — a complete loss of power at the server port, a complete loss of connectivity to the Provider's network port, or a confirmed hardware failure that prevents use of the Server.
3. B2B scope and order of precedence
- The Provider does not conclude consumer contracts under these Terms.
- The offering is intended for professional purposes. Where an individual conducts business, the professional nature of the Agreement is assessed in accordance with the law, in particular on the basis of its content and the business activity disclosed in CEIDG. Where this is not clear from the Agreement, the Customer may submit a separate declaration, but the Provider does not make conclusion of the Agreement conditional upon its submission.
- These Terms do not exclude or restrict any rights of an individual conducting business that arise from mandatory provisions of law, in particular Article 385⁵ of the Polish Civil Code.
- A person accepting an Order on behalf of the Customer represents that they are authorised to represent the Customer. The Provider may request a document confirming that authority and may verify the Polish Tax Identification Number (NIP) or EU VAT number.
- In the event of a conflict, an individually agreed Order takes precedence over these Terms in technical and commercial matters. The data processing annex takes precedence in data protection matters.
- Marketing descriptions and public information from other entities do not expand the Provider's obligations unless incorporated into the Order or these Terms.
4. Conclusion and activation of the Agreement
- Before submitting an Order, the Customer receives these Terms in a form that enables them to be saved and reproduced.
- The Customer submits an Order using a form, by email or in a signed document and accepts these Terms using a checkbox that has not been preselected or by an equivalent unambiguous declaration.
- Before submitting the form, the Customer may review and correct the summary of the data, configuration and price. After submission, the Customer may report an obvious error to the contact address; correcting it may require renewed acceptance of the Order.
- The system promptly sends an automated acknowledgement of receipt of the Order. Acknowledgement of receipt does not yet constitute acceptance of an offer or conclusion of the Agreement.
- The Agreement is concluded only when the Provider sends a separate confirmation accepting the Order, unless an individual document specifies another time.
- The Provider records both events separately, together with the content of the Order, the versions of the documents, the date and method of acceptance, and sends the concluded Agreement to the Customer on a durable medium.
- The official and binding version of these Terms together with their annexes and of the Register is the Polish version. The English version is a translation made available to facilitate understanding of the documents. In the event of a discrepancy or interpretative doubt, the Polish version prevails, subject to mandatory provisions of law and the priority of an individually agreed Order in accordance with section 3.5. The Provider does not apply any particular code of conduct unless it informs the Customer of that code before the Order.
- Activation takes place after the required payment has been credited and the necessary security verification has been completed. The declared activation date is specified in the Order.
- The Customer should verify the configuration promptly after it is made available. Any deficiencies must be reported to the contact address no later than within 3 business days; this period does not limit liability for latent defects.
5. Nature of the Service and allocation of responsibilities
- The Server is physically dedicated to one Customer. The Provider does not operate a shared virtualisation layer on it unless the Order states otherwise.
- The Provider is responsible for:
- a. making available the configuration specified in the Order;
- b. colocation, power, cooling and physical security of the hardware;
- c. operation of its own network up to the Server port and assignment of the specified addressing;
- d. diagnosis and repair or replacement of a defective hardware component;
- e. protection of its own management systems and restriction of staff access.
- The Customer is responsible for:
- a. installing, configuring, updating and licensing the operating system, drivers, applications and models;
- b. accounts, passwords, keys, firewall, encryption, monitoring and vulnerability management;
- c. the legality of Customer Data and Users' activities;
- d. regular backups outside the Server and testing restoration from those backups;
- e. configuration of public services, domains, DNS and applications;
- f. compliance of its use with the law, sanctions, export controls and third-party rights.
- The Provider does not back up Customer Data unless the Order expressly describes a separate backup service.
- The Customer should encrypt data on the drives and keep the keys outside the Server. The Provider will not recover data or keys lost by the Customer.
- To conclude the Agreement, the Customer needs a device with Internet access, an up-to-date browser that enables documents to be saved, and an active email address. To use the Server, the Customer needs its own compatible system and administration tools, in particular an SSH client or another protocol specified in the Order.
- Typical risks include public exposure of services, intrusion, malware, misconfiguration, software vulnerabilities, component failure, loss of data without a backup, and changes to third-party licence terms.
- The Provider may use factory firmware and BMC, as well as a temporary diagnostic, rescue or provisioning environment, solely for activation, testing, repair and the security of its own layer. Before handing over the Server, the Provider removes temporary images and tools, including the NVIDIA driver, from the Customer's operating system unless, following a separate verification, the Order expressly describes the software left in place, its function and purpose.
6. Hardware, data centre and access
- The Server is located at the 4DataCenter data centre in Katowice, Poland, operated by Quicktel Sp. z o.o. The Provider may, at its own cost, change the particular room within Katowice by giving the Customer at least 7 days' prior notice and specifying the necessary maintenance window. Shorter notice is permitted in the event of a failure or for security reasons. The change must not materially reduce security or the agreed parameters; otherwise, the Customer may terminate the affected Order and receive a refund for the unused period.
- Public statements made by 4DataCenter concerning infrastructure or historical availability do not constitute a separate warranty by the Provider. The binding Service level arises exclusively from the Agreement.
- The hardware remains owned or legally controlled by the Provider. The Agreement does not transfer ownership of the Server, GPU, drives or IP addresses.
- The Customer has exclusive administrative/root control over its operating system; the means of obtaining access follows from the configuration or activation protocol. BMC/IPMI access is provided only if the Order provides for it. The Customer does not obtain physical access to the hardware.
- Without the Provider's written consent, the following are prohibited in particular:
- a. interference with the hardware, cabling, firmware, BIOS or BMC;
- b. permanent modification of power, voltage or clock limits, and overclocking;
- c. disabling thermal, power or security safeguards;
- d. attempts to gain access to the management network or the hardware of other customers.
- A replacement must not materially impair workload compatibility or the agreed parameters. A different GPU model requires the Customer's consent and must have at least the same VRAM capacity, support the agreed functions and be in no worse a compute category. The CPU, RAM, drives and port must not be inferior to those specified in the Order.
- The Provider may use its currently available pool of spare hardware. This does not mean that a particular compatible GPU is reserved for the Customer or that a replacement date is guaranteed, unless the Order provides otherwise.
- During repair, the Provider normally transfers working drives without logically reading them, provided this is technically compatible and secure. The Customer is responsible for encryption keys, TPM, RAID configuration and the ability to boot the system after a motherboard or controller replacement. A defective storage medium is secured and then effectively erased or destroyed; handing it over to a warranty service provider requires prior data removal or equivalent contractual and organisational safeguards.
- A static IP address means an address assigned for the duration of the Service. It does not become the Customer's property and is not transferable upon termination of the Agreement. The Provider may change it only for an important legal, security or technical reason, giving the Customer advance notice whenever possible.
7. NVIDIA and other software
- A standard GPU configuration in the Order may include: 1 × NVIDIA RTX PRO 6000 Blackwell Max-Q Workstation Edition, 96 GB of dedicated GDDR7 GPU memory with error correction (ECC).
- The Provider makes hardware available. Unless the Order expressly states otherwise, the Service does not include the Provider supplying or installing NVIDIA drivers, NVIDIA CUDA Toolkit, NVIDIA AI Enterprise, NVIDIA vGPU or any other NVIDIA software installed in the Customer's operating system, nor does it include the Provider granting a licence or sublicense to such software, collectively “NVIDIA Software”.
- The Customer independently selects and downloads NVIDIA Software directly from NVIDIA or another lawful source and then installs, configures, updates and removes it at its own responsibility. Before downloading, installing or using it, the Customer reviews the current terms of the applicable licence and, where required, accepts them directly with NVIDIA or another relevant licensor.
- The Customer is responsible for obtaining rights appropriate to its manner of use, especially in the case of virtualisation, MIG or another division of the GPU, vGPU, making functionality available to third parties, further distribution or resale of NVIDIA Software, providing commercial hosting services using it, or using products that require a paid licence or subscription.
- The Provider is not a party to a licence agreement concluded between the Customer and NVIDIA and does not warrant that a standard driver licence permits the Customer's particular business model. Upon a justified request, the Customer will confirm that it holds the required licences, subscriptions or other rights without disclosing confidential information.
- The mere technical availability of MIG or another GPU partitioning mechanism does not mean that the Service includes NVIDIA vGPU software or a licence, or that the Customer is entitled to offer NVIDIA Software as a service.
- If the Customer instructs the Provider to install software, this requires a separate Order and prior, documented verification of the licensing rights of both the Provider and the Customer. No implied sublicense arises.
- The absence, expiry, suspension or restriction of the Customer's licence, subscription or account for reasons beyond the Provider's control does not constitute unavailability or a defect of the Service where the hardware and connectivity operate in accordance with the Agreement.
- NVIDIA names and marks are used solely to identify the hardware. NVIDIA is not a party to the Agreement or a sponsor of the Service.
8. Acceptable use rules
- The Customer may use the Service for lawful computing, AI, rendering, data analysis, hosting its own applications and other professional purposes consistent with the Agreement.
- It is prohibited to use the Service for:
- a. unlawful content or activities, including child sexual abuse material;
- b. malware, ransomware, botnets, phishing, credential theft or circumvention of security measures;
- c. DDoS attacks, intrusion, scanning or testing systems without their owner's consent;
- d. unsolicited bulk communications, forged headers or maintaining resources that support spam;
- e. infringement of copyright, trademarks, trade secrets, privacy or other third-party rights;
- f. circumvention of sanctions, export controls or licensing restrictions;
- g. uses whose failure may directly cause death, injury or catastrophic damage, without a separate written agreement;
- h. cryptocurrency mining or resale or further rental of the Service without the Provider's written consent.
- The Customer is responsible for Users and should maintain an up-to-date 24-hour abuse contact.
- The Provider does not generally monitor Customer Data. It may analyse metadata and information necessary for security, billing, performance of the Agreement or handling a specific credible report.
- A report concerning unlawful use must be submitted using the mechanism available at /report-abuse/ on the Provider's website or to the contact address. It should precisely identify the IP address, URL or other location, time, description and reasons for illegality, the reporting person's name or business name and email address, and include a statement of accuracy and good faith. Identification details are not required for a report concerning suspected sexual offences against children to the extent provided for by the DSA. The Provider may request supplementary information.
- The Provider processes reports in a timely, diligent, objective, non-arbitrary and proportionate manner, with due regard to the Customer's rights and the obligations under Regulation (EU) 2022/2065, to the extent that it applies.
- Where electronic contact details have been provided, the Provider acknowledges receipt of the report without undue delay, including where the report requires supplementary information, and following assessment provides information about its decision and available means of redress. The Provider reports a suspected criminal offence involving a threat to life or safety to the competent authorities where required by law.
9. Security and suspension
- The Customer must immediately report account compromise, key leakage, a vulnerability or abuse and cooperate in mitigating its effects.
- The Provider may, to the minimum extent necessary, block a port, apply a filter, disconnect an IP address or suspend the Service where:
- a. required by law, a court or a competent authority;
- b. there is an immediate threat to people, data, hardware, the network or other customers;
- c. an attack, malware, spam or another serious infringement is ongoing;
- d. the Customer has failed to remedy an ordinary breach within a specified reasonable period;
- e. the arrears described in section 10 exist.
- In an urgent situation, suspension may take place without prior notice. No later than when the restriction is imposed, the Provider provides the statement of reasons described in paragraph 6 unless a specific provision of law or binding order prohibits notification or a temporary withholding of information is necessary to protect an investigation or immediate security; in that event, it provides the statement when the impediment ceases.
- The Provider will restore the Service when the cause has ceased and the required actions have been completed. Charges continue to accrue during a suspension caused by the Customer; this rule does not apply to a period of suspension caused exclusively by the Provider.
- Automated signals, such as traffic or IP reputation alerts, may initiate an analysis or urgent isolation, but a human reviews any decision to impose a longer restriction.
- The statement of reasons for a restriction specifies:
- a. the specific facts and circumstances and whether the action resulted from a report, the Provider's own detection or an authority's order;
- b. whether and how automated detection or automated measures were used;
- c. the precise legal basis or specific provision of these Terms;
- d. why the activity or information was considered unlawful or inconsistent with the Agreement;
- e. the type, territorial scope and duration of the restriction;
- f. the ability to request manual reconsideration at the contact address and to apply to the competent court or authority.
10. Prices and payments
- Net prices, currency, activation fee and Billing Period are specified in the Order. VAT is added in accordance with applicable law, including the rules applicable to intra-Community transactions.
- Payment is made by bank transfer to the account indicated on the invoice, normally in advance and within 7 days, unless the Order states otherwise.
- The Provider issues and makes invoices available through the Polish National e-Invoice System (KSeF) where required by law. In other cases, the Customer consents to electronic invoices being sent to the specified email address. The Provider may additionally email a visualisation of, or information about, an invoice available in KSeF.
- In the event of delay, the Provider may charge interest and compensation provided for commercial transactions.
- After the due date, the Provider may grant an additional period of at least 3 business days. If payment is still not made, the Provider may decline to renew or may suspend the Service. Immediate action is permitted in the event of fraud or serious risk.
- Objections to part of an invoice do not release the Customer from timely payment of the undisputed part.
- A Billing Period paid in advance and already commenced is not subject to a pro-rata refund if the Customer simply cancels or commits a material breach that justifies termination of the Agreement. This does not apply to a refund due because of the Provider's fault, under an SLA or under mandatory law.
- Additional work, storage media, shipping, non-standard remote hands and traffic above the agreed limit require prior agreement of the price.
11. Term and termination of the Agreement
- The standard Agreement is concluded for an indefinite term with a monthly Billing Period. Either Party may terminate it on one month's notice effective at the end of a Billing Period. If the Customer chooses to switch provider in accordance with section 12, the Agreement continues during the transitional period and ends in accordance with that section.
- An Order may provide for a fixed term, minimum term or other rules concerning renewal and early termination. Any charge or compensation for early termination must be specified in the Order, either as an amount or under an unambiguous formula, before it is accepted.
- A Party may terminate the Agreement if a material breach has not been remedied within 7 days after notice to remedy it.
- The Provider may terminate the Agreement with immediate effect in the event of serious or repeated unlawful use, an intentional threat to infrastructure, circumvention of sanctions or licences, provision of false information, or arrears despite the additional payment period.
- The Provider may terminate only an Agreement concluded for an indefinite term without cause by giving 30 days' notice and refunding the unused portion of any advance payment. It may terminate a fixed-term Agreement before expiry only under an agreed right of the Customer, for a material breach, force majeure or another express basis in the Agreement or law.
- Termination does not extinguish payments already due or provisions which by their nature should survive, in particular those concerning confidentiality, liability and data protection.
12. Switching provider, data export and deletion
- This section and the current Data Export, Formats and Jurisdiction Register, published at /data-export-register/ on the Provider's website, set out the procedure for switching provider within the meaning of Regulation (EU) 2023/2854 to the extent that the Regulation applies to the Service. The Register forms part of the Agreement in the version made available before the Order.
- The Customer may indicate that after the notice period it wishes to:
- a. transfer Customer Data to another provider;
- b. transfer it to its own infrastructure;
- c. delete Customer Data without transfer.
- The maximum notice period does not exceed 2 months. The standard period is one month in accordance with section 11.
- After the notice period, the agreed transitional period begins and lasts no more than 30 calendar days. During this period, the Agreement remains in force and the Provider:
- a. provides reasonable assistance and does not create artificial obstacles;
- b. maintains the agreed functions and security within the limits of the Agreement;
- c. provides information about any continuity risks of the switching process known to it;
- d. cooperates in good faith with the Customer and the designated new provider.
- If 30 days is technically unfeasible, the Provider will provide reasons within 14 business days and indicate an alternative period not exceeding 7 months. The Customer may extend the transitional period once by a period it considers more appropriate for its purposes, by notifying the Provider before that period expires.
- The detailed categories of input data, output data, metadata and digital assets, their structures, formats, standards, export methods and strictly specified exclusions are contained in the Data Export Register. The Customer controls application data formats because the Provider does not supply a managed application layer.
- The exclusion of the Provider's internal data is permitted only to the extent that disclosure would infringe intellectual property rights, trade secrets, or the security of the Provider or third parties, and may not impede the achievement of functional equivalence.
- During the notice and transitional periods, the standard periodic charge specified in the Order applies. The Provider does not charge a separate fee for the mandatory provider-switching process. The Customer bears only the previously accepted cost of additional storage media, shipping or voluntarily ordered work beyond statutory obligations. From 12 January 2027, no such cost may in substance constitute a switching charge prohibited by law.
- After successful completion of the transitional period, the Customer has at least 30 calendar days to request and carry out retrieval of remaining data. Throughout that period, the Provider protects the original storage media against reuse. Upon request, the Provider makes the data remotely accessible through an isolated connection, with the authentication and bandwidth specified in the Register, within 2 business days and maintains that access until the end of the retrieval period, but for no less than 7 days.
- If the Customer chooses deletion without transfer from the outset, Customer Data is deleted after the end of the notice period on a date agreed with the Customer. If it has commenced switching, deletion takes place only after confirmation of successful migration and expiry of the retrieval period, unless the Customer expressly requests earlier deletion following that confirmation.
- The Provider deletes all copies of Customer Data under its control in a manner appropriate to the technology and confirms completion upon request. It does not delete billing, evidential or security data that it retains in its own capacity as controller on a legal basis.
- The Agreement ends: in the case of deletion without transfer — after the notice period; in the case of switching — upon its successful completion and notification to the Customer; or on a later date specified by the Customer in accordance with a permitted extension. The retrieval period and deletion obligations continue after termination of the Agreement.
- The Service is not a backup. A physical drive failure may prevent export of data that the Customer has not previously copied.
- The location of individual elements of the Service, the applicable jurisdiction, and measures to prevent unlawful international access by public authorities are specified and updated in the Data Export and Jurisdiction Register.
13. Infrastructure SLA and hardware failures
-
The Provider aims for monthly availability of its power and network of 99.9%. This level becomes a guaranteed Standard SLA of 99.9% together with service credits only where the Order expressly specifies this option or a more favourable SLA.
-
The Standard SLA measures separately:
- a. power availability — the presence of the agreed power at the Server's PDU/outlet and cooling that permits normal operation;
- b. network availability — the ability to exchange packets between the Server's network interface card and the Bestconnect network demarcation point specified in the Order.
-
A failure of either component constitutes infrastructure unavailability. Overlapping failures are counted only once, and monthly availability is the lower result for power/cooling or network.
-
Availability is calculated as: (measurement period time minus confirmed downtime) / measurement period time × 100%. Once an event's eligibility is subsequently confirmed, time is counted from the earlier of the Provider's monitoring alert or registration of a valid P1 Incident report. It ends when the faulty component is restored.
-
The SLA does not cover:
- a. the Customer's system, applications, firewall, drivers or configuration;
- b. a hardware failure, to which paragraph 9 applies;
- c. the Internet beyond the Provider's network demarcation point;
- d. planned work notified at least 48 hours in advance together with its scope and anticipated duration;
- e. emergency security maintenance notified without undue delay and only for the objectively necessary duration;
- f. attacks, Customer actions, suspension consistent with the Agreement, force majeure and events beyond the Provider's reasonable control.
-
A failure of the data centre, power or cooling selected by the Provider is not automatically force majeure or an event beyond its control.
-
If the Standard SLA of 99.9% is selected in the Order, service credits are:
Monthly availability Credit against the monthly net fee for the affected Server 99.9% or above 0% below 99.9% but at least 99.0% 5% below 99.0% but at least 95.0% 10% below 95.0% 25% -
The total credit does not exceed 25% of the monthly net fee for the affected Server. The Customer submits a claim within 14 days after the end of the month, stating the Order number and event times. The credit is applied to the next invoice or refunded after termination of the Agreement and constitutes the contractual remedy for the SLA breach itself, without restricting rights that cannot be excluded.
-
The Provider diagnoses and remedies a confirmed hardware failure using reasonable efforts and spare hardware subject to current availability. Unless stated in the Order, no response or replacement time is guaranteed. Diagnosis and replacement of the Provider's defective hardware are included in the price; only additional work ordered by the Customer may be chargeable.
-
If a suitable replacement cannot be made available within 7 calendar days after confirmation of the failure, the Customer may terminate the affected Order and receive a pro-rata refund for the unused period.
-
A guaranteed replacement time specified in the Order runs from completion of diagnosis and confirmation of a hardware failure until a working replacement configuration is made available. It does not include restoration of the operating system or Customer Data.
14. Support and complaints
- Reports may be sent to the contact address at any time. The mere acceptance of email outside service hours does not imply a guaranteed response time unless one is specified in the Order.
- A report should include the Order number, IP address, description, time of occurrence, tests performed and secure return contact details. Passwords and private keys must not be sent by email.
- A complaint should additionally specify the Customer's requested remedy. The Provider normally responds within 14 days and, in a complex matter, provides an anticipated response date.
- Standard support concerns the hardware and network layer. Administration of the Customer's system requires a separate Order.
15. Confidentiality, data and intellectual property rights
- Each Party protects the other Party's non-public technical, commercial and security information with at least the same care as it protects its own information of that kind.
- Confidentiality does not cover information that is public without breach of the Agreement, lawfully known beforehand, independently developed or required by law. To the extent possible, a Party disclosing information at an authority's request will notify the other Party in advance.
- The Customer retains its rights in Customer Data. It grants the Provider only the limited right to perform operations necessary to perform the Agreement, maintain security, assist with export and comply with legal obligations.
- The Provider retains its rights in its own network, automation, documentation, brand and infrastructure configuration. The Agreement does not transfer any licence beyond the right to use the Service during its term.
16. Liability
- Each Party is liable for proven direct loss that is the normal consequence of its breach of the Agreement.
- To the extent permitted by law, the Provider is not liable for loss of profits, revenue, reputation or contracts, indirect downtime, or loss of Customer Data which could have been avoided by a proper backup, unless the loss results from the Provider's wilful misconduct or gross negligence.
- The Provider is not liable for the actions of Users, the content of Customer Data, errors in the Customer's system or software, loss of the Customer's keys, or third-party licensing restrictions.
- The Provider's aggregate liability for all events connected with one Order is limited to the total net fees paid for the affected Service during the 3 months preceding the event. If the Agreement has been in force for a shorter period, the fees paid since its commencement are taken into account.
- The limitations do not apply to loss caused intentionally or through gross negligence, personal injury, or liability that may not be limited by law. Nor do they limit the rights of a business benefiting from the protection of Article 385⁵ of the Polish Civil Code to the extent that a provision would not bind that business under the law. Liability for data protection is also subject to the mandatory provisions of the GDPR.
- The Customer covers reasonable and documented costs of third-party claims arising from unlawful Customer Data or Users' actions to the extent that the Customer is responsible for their cause and had an opportunity to participate in the defence.
17. Force majeure
- A Party is not liable for delay caused by an extraordinary event beyond its reasonable control whose effects it could not prevent, including a disaster, war, widespread failure of external networks or binding action by an authority.
- The affected Party notifies the other Party and mitigates the effects. Force majeure does not release the Customer from payment for Service already performed or release the Parties from data protection and confidentiality obligations to the extent they can be performed.
- If the event prevents a material part of the Service for more than 30 days, either Party may terminate the affected Order without a penalty for a future period.
18. Amendments to the Terms
- The Provider may amend the Terms only for an objective reason:
- a. entry into force of, or a binding interpretation of, law requiring a specific change;
- b. remediation of an identified vulnerability or adaptation to a documented threat;
- c. discontinuation of support for a technology by its manufacturer or subcontractor where retaining the existing solution is not reasonably possible;
- d. addition of an optional feature that does not impair a Service already ordered;
- e. a documented change in a tax or an external energy, colocation or connectivity cost — solely with respect to a proportionate price for future periods of an indefinite-term Agreement.
- The Provider will notify the Customer by email of an amendment affecting an ongoing Agreement at least 30 days in advance, supplying the complete new text on a durable medium and describing its impact. The Customer may terminate the affected Agreement before an adverse amendment takes effect.
- Shorter notice is permitted where required by law or urgent security needs; the Provider will explain the reason.
- An amendment does not have retroactive effect. The price and guaranteed parameters of a fixed-term Agreement do not change during its term unless the Order expressly provides for a lawful adjustment mechanism.
- The Provider archives versions of the Terms and makes them available for download.
19. Governing law and final provisions
- The Agreement is governed by Polish law and directly applicable European Union law.
- The Parties will attempt to settle a dispute amicably for 30 days. Thereafter, jurisdiction lies with the court of general jurisdiction having territorial jurisdiction over the Provider's principal place of business, unless mandatory provisions of law provide otherwise.
- The Customer may not assign the Agreement without the Provider's written consent, which the Provider will not withhold without a justified reason. The Provider may assign the Agreement together with its business or an organised part thereof after prior notice and without diminishing the Customer's rights; if the change materially worsens the Customer's position, it may terminate the affected Service before the assignment.
- The invalidity of an individual provision does not affect the remaining provisions. The Parties will replace it with a solution as close as possible to its lawful purpose.
- Operational and contractual notices are given to the email addresses specified in the Order. The Customer is responsible for keeping them up to date.
- Annex 1 — Data Processing Agreement and Annex 2 — Shared Security Model below form an integral part of these Terms.
Annex 1 — Data Processing Agreement
A. Application and roles
- This Annex applies automatically where, in connection with the Service, the Provider processes personal data on behalf of the Customer.
- The Customer is a controller or processor and the Provider is, respectively, a processor or subprocessor. The Customer ensures that it has the right to issue instructions and — where it acts as a processor — the consent of its controller.
- Documented instructions arise from the Agreement, the Customer's technical settings and requests consistent with the Agreement. An additional instruction requiring non-standard costs is subject to prior agreement unless the law requires it to be performed without charge.
- The Provider acts as a separate controller with respect to data required for the account, conclusion and billing of the Agreement, protection of its own network, prevention of abuse, handling reports, its own telemetry and legal obligations. It acts as a processor with respect to content and application data stored by the Customer and service operations performed on the Customer's instructions. The nature of a particular log is assessed according to its purpose and actual control, rather than its name alone.
B. Subject matter, duration and scope
- The subject matter is the provision of physical infrastructure, storage, transmission, availability, security and limited servicing operations.
- Processing continues for the duration of the Service and the period for data export, retrieval and deletion.
- The nature of the operations includes storage, transmission, organisation, making data available to the Customer, safeguarding, limited diagnosis, export and deletion.
- The purpose is performance of the Service in accordance with the Agreement. The Provider does not use entrusted data for its own marketing or model training.
- The Order or an attached processing schedule specifies, for the relevant Customer, the actual categories of data, data subjects, purpose and any planned special categories of data. If those fields are left blank, the scope may include ordinary identification, contact, network and application data relating to employees, contractors, customers and end users which the Customer enters for its own computing or application hosting purposes.
- Special categories of data, criminal conviction data, professional secrets or high-risk data must be identified in the Order and require a joint assessment of whether both Parties' measures are appropriate. This does not transfer the Provider's own obligation under Article 32 GDPR in the layer it controls.
C. Provider's obligations
- The Provider:
- a. processes data only on the Customer's documented instructions, including with regard to transfers, unless otherwise required by law;
- b. informs the Customer of a legal obligation to process before carrying it out, unless the law prohibits such information;
- c. ensures that authorised persons are subject to confidentiality;
- d. implements the measures set out in Annex 2 and Article 32 GDPR that are appropriate to the risk in the layer controlled by the Provider;
- e. forwards to the Customer without undue delay a data subject request concerning entrusted data and, without instructions, does not provide a substantive response unless required by law;
- f. taking into account the nature of processing, assists the Customer with data subject rights, impact assessments, consultations and obligations under Articles 32–36 GDPR;
- g. notifies the Customer of a personal data breach without undue delay, where possible within 48 hours after becoming aware of it, providing available information in stages;
- h. makes available information necessary to demonstrate compliance and promptly informs the Customer if, in its opinion, an instruction infringes data protection law.
- Assistance does not include administering an application or identifying data within the Customer's encrypted space.
D. Subprocessors
- The Customer grants general authorisation for the engagement of subprocessors necessary for the Service.
- Quicktel Sp. z o.o., KRS 0000297311, Poland, the operator of 4DataCenter, is an infrastructure subcontractor with respect to colocation, power, cooling and physical security. It is a subprocessor only to the extent that, on an individually documented instruction or a previously defined emergency instruction, it performs operations on personal data after being bound by an agreement meeting Article 28(4) GDPR.
- The Provider imposes on a subprocessor the same data protection obligations arising from this Annex to the appropriate extent and remains fully liable to the Customer for the subprocessor's performance of those obligations.
- The Provider will give at least 30 days' advance notice of an intended addition or replacement of a subprocessor. The Customer may raise a reasoned objection concerning data protection. If the Parties cannot find a solution, the Customer may terminate the affected Service before the change without a penalty for a future period.
E. Location and authority requests
- Entrusted Customer Data on the Server is stored in Katowice, Poland. Ancillary Service infrastructure and logs are maintained at the locations specified in the Data Export and Jurisdiction Register. Adding a location in another EEA state is subject to the subprocessor rules, and a transfer outside the EEA requires the Customer's instruction and a legal basis compliant with Chapter V GDPR.
- The Provider verifies authority access requests, discloses the minimum data required, documents its response and — where permitted — informs the Customer and challenges manifestly unlawful requests.
F. Return, deletion and audit
- After termination, the Provider, according to the Customer's choice, returns entrusted data and then deletes it together with all existing copies, or immediately deletes the data and copies, subject to section 12 of the Terms. The only exception is retention required by law; upon request, the Provider confirms deletion.
- The Customer may normally request documents or a remote audit of reasonable scope once per year. The limit does not apply following a personal data breach, where there is a justified suspicion of non-compliance, following a material change in processing or at the request of an authority. An on-site audit requires prior scheduling and protection of other customers and confidentiality.
- The Customer bears the reasonable cost of a non-standard audit unless the audit results from a breach or demonstrates material non-compliance; in that event, the Provider bears the reasonable cost. A charge or organisational conditions may not in practice prevent an audit required under Article 28 GDPR.
Annex 2 — Shared Security Model
| Area | Provider | Customer |
|---|---|---|
| Facility, power, cooling | responsible | — |
| Physical hardware and network port | responsible | reports failures |
| BMC/IPMI and management network | secures infrastructure and initial access | changes access credentials and restricts access to trusted addresses |
| Operating system | — | installs, hardens, updates and monitors |
| GPU driver and licences | not supplied as standard | downloads, accepts the licence and maintains |
| Firewall, accounts, MFA, keys | provides only the mechanisms described in the Order | configures and protects |
| Data encryption | does not manage the Customer's keys | encrypts and keeps keys outside the Server |
| Applications, models and Customer Data | does not administer | responsible for legality, security and retention |
| Backup and restoration | only where separately ordered | creates and tests backups outside the Server |
| Incident response | facility, hardware and own network layer | system, applications, accounts and Users |
The Provider implements at least the following measures in the layer it controls:
- physical access to rooms and hardware is restricted and logged by the data centre, and remote hands are performed on documented instructions;
- staff use individual permissions assigned according to the principle of least privilege, are subject to confidentiality, and their permissions are periodically reviewed;
- BMC and the management network are separated from ordinary traffic, protected by unique access credentials and source restrictions, and MFA is used where supported by the relevant solution;
- administrative channels controlled by the Provider use encrypted protocols such as SSH, TLS or VPN; unsecured remote services are disabled;
- administrative, security and physical intervention events are logged and protected against unauthorised modification; standard retention is up to 12 months unless an incident or law requires a longer period;
- the Provider updates controlled routers, BMC and tools, monitors availability and maintains vulnerability and incident-handling procedures;
- configurations of the Provider's own network and management systems are protected for continuity purposes; this does not constitute a backup of Customer Data;
- before reuse, a storage medium is securely erased using a method appropriate for HDD/SSD/NVMe and, where effective erasure is not possible, is physically destroyed or protected through an equivalent servicing procedure;
- the effectiveness of the measures is periodically reviewed and material deficiencies are documented and remediated.
The scope does not imply possession of a certification not expressly specified in the Order. The Customer remains responsible in parallel for the measures assigned to it in the table.