SAFENIX
Terms of Service
Last updated: September 2026 — v1.3
| Document version | v1.3 |
| Date | 20 September 2026 |
| Supersedes | v1.2 (26 August 2026). v1.3 conditions the continuous database capture promise in Sections 2.1, 2.3, 2.4 and 6.6 on the account being on the Critical plan and the Customer's server having binary logging enabled, and states that where either condition is not met, the database is protected instead with full copies taken periodically — see CHANGES-terms-v1.3.md. v1.2 offered a second product — a plugin for websites on shared hosting, for which Safenix generated and held the encryption key. That product is withdrawn from the offer, so its clauses were removed rather than left in a contract describing something nobody can buy. The key custody guarantee in Section 2.2 is therefore unconditional again. See CHANGES-v1.2.md, which gives the reason for every removal. v1.1 in turn superseded v1.0 (August 2026), which described a product that did not exist; see CHANGES-v1.1.md. |
| Governing law | The law of the Czech Republic |
| Jurisdiction | The courts of Prague, Czech Republic |
| Language | English (authoritative). Translations provided for convenience only. |
| Status | In force |
Relationship to other documents: These Terms govern the commercial relationship between Safenix and the Customer. Data processing obligations are governed separately by the Data Processing Agreement (DPA). Privacy practices are described in the Privacy Policy. In case of conflict between these Terms and the DPA on data protection matters, the DPA prevails.
1. Definitions
| "Agreement" | These Terms of Service, together with any Order Form, the DPA, and the Privacy Policy. |
| "Safenix" | Eurhosting SHPK, a company registered in Albania, NIPT M52305043P, registered office Sallmone, Shijak — Durrës, Albania. Safenix is a commercial brand of that company and not a separate legal entity. The contracting party is Eurhosting SHPK throughout. |
| "Customer" | The business entity or individual that subscribes to the Service. |
| "Service" | The Safenix backup platform: the Agent, the Control Plane, the dashboard, Object Storage and the Compliance Vault. |
| "Agent" | The Safenix software installed on a Customer server to capture data, encrypt it locally and transmit ciphertext to Object Storage. |
| "Protected System" | A server running the Agent. Plan limits are expressed in Protected Systems. |
| "Backup Data" | The Customer's encrypted data stored in Object Storage. |
| "Encryption Key" | The AES-256 key that encrypts Backup Data. It is generated on the Customer's own server and held only there; Safenix never receives it. Section 2.2 sets that out. It is the single most important term in this Agreement. |
| "Metadata" | Operational data processed by the Control Plane: object keys, sizes, timestamps, cryptographic hashes, agent identifiers, agent versions and the name the Customer or their server gives each Protected System. It does not include the content of Backup Data. |
| "Compliance Vault" | The append-only, Merkle-chained record maintained by Safenix of operations performed on a Customer's data. Its properties, including what can and cannot be deleted from it, are described in Section 6.5. |
| "Order Form" | The plan selection and billing details confirmed at subscription, including any Add-ons. |
| "Plan" | The service tier subscribed to, from the table in Section 2.3. |
| "Recovery Point" | The moment to which a Protected System could be restored, being the time of its most recent successfully stored backup. Safenix monitors the age of each Recovery Point and alerts the Customer when it exceeds the threshold configured for their account. It is a monitoring threshold and an alerting commitment. It is not a guarantee of maximum data loss. |
| "Scheduled Maintenance" | Planned downtime announced at least 48 hours in advance by email and dashboard notice. |
2. Service Description
2.1 What Safenix Provides
Safenix provides a backup service for business server infrastructure. The Service consists of:
2.2 Key custody — the Customer holds the key
The Service is built so that Safenix cannot read Customer Backup Data:
Key loss warning. If the Customer loses the Encryption Key, Safenix cannot recover Backup Data. Safenix does not hold the key and there is no mechanism, procedure or escalation by which it can be produced. This is a consequence of the design and is not a service defect. See Sections 7 and 8.
There is no exception to this. Safenix offers one product and one key custody model. There is no Plan, tier or arrangement under which Safenix holds a Customer's Encryption Key or is able to decrypt Backup Data, and Safenix will not describe any subscription as one where it can. Where this guarantee appears elsewhere in these Terms it is stated without qualification, because there is nothing to qualify.
2.3 Plans
These are the Plans Safenix offers. Key custody is per Section 2.2 for every one of them.
Prices are those published at safenix.eu/pricing and are not stated in this Agreement.
| Plan | Servers | Storage | Backup frequency | Retention | Alerts | Support |
|---|---|---|---|---|---|---|
| Starter | 2 | 200 GB | Hourly snapshots | 30 days | Community | |
| Business | 5 | 500 GB | 15-minute snapshots | 90 days | Ticket | |
| Critical | 15 | 1 TB | Continuous database capture where the server's binary logging is enabled; hourly file snapshots | Agreed with the Customer and recorded on the account | Email; SMS when it enters service | Priority |
Add-ons, each per month, added to any Plan: an additional server; an additional 100 GB of storage; an additional 1 TB of storage; extended retention to six months.
All prices are exclusive of VAT and any other applicable tax. Prices are charged monthly in advance and are published at safenix.eu/pricing.
Safenix sells to businesses only. Safenix is established in Albania and supplies customers in the European Union, so every supply is made under the reverse charge: no VAT is added to the price, and the Customer accounts for it in their own member state. That treatment is available only to a taxable person, so a valid VAT registration number is required to open an account and is asked for on the registration form rather than afterwards. An account cannot be opened without one, and the form says so before anything is typed.
Retention on the Critical plan is agreed with the Customer and recorded against the account before it takes effect. Until a figure is agreed and recorded, nothing is deleted by age. This is deliberate: Safenix will not choose a deletion window for a Customer who has not chosen one.
Backup frequency is the frequency the Plan provides for and which the Customer configures on each Protected System. Safenix does not throttle a Customer who configures a shorter interval and does not currently enforce a longer one.
Continuous database capture requires binary logging. It is available on the Critical plan where the Customer's MySQL or MariaDB server has binary logging enabled. Where it is not enabled — which is common on shared and on some managed hosting — the database is instead protected with full copies taken periodically, on every Plan. This is not a fault and Safenix tells the Customer when it applies to one of their servers. See Section 2.4.
2.4 What the Service does not do
Stated because a backup service is bought on what it will do on the worst day of the Customer's year, and a list of capabilities is only useful if its boundary is honest.
2.5 Plan limits: which are enforced, and which are not
The two limits in Section 2.3 behave differently on purpose, and the difference is the one a Customer most needs to understand about this service.
The number of Protected Systems is enforced. Registering a system beyond the Plan's allowance is refused, and the refusal names the Plan, the limit and the ways past it — an Add-on, or a larger Plan. Nothing already protected is affected by it. It is safe to refuse here because the refusal stops something that has not started: an installation fails immediately and visibly, and no backup that was running stops running.
The storage allowance is not enforced, and no backup is ever interrupted because of it. Safenix measures what each account is storing, shows the figure on the Customer's dashboard beside their allowance, and emails the Customer when they go over it. It does not refuse an upload, stop a backup, or close an account for exceeding a storage allowance.
That is a deliberate decision and not an oversight. Refusing an upload would stop backing up a system that is already protected, so a Customer over their allowance would quietly stop having backups and would discover it on the day they needed a restore. Exceeding the storage allowance is a billing matter between Safenix and the Customer, settled by adding storage or moving Plan, and Safenix will raise it rather than act on it silently.
How storage is measured. By listing the objects actually stored and adding up their sizes, rather than by totalling what Customer systems report. The figure carries the time it was taken, and it is a measurement of what is presently stored: objects already deleted are not counted, and a Customer who has just uploaded a large amount will see it at the next measurement rather than immediately.
Backup frequency is not enforced in either direction. The frequency in Section 2.3 is what the Plan provides for and what the Customer configures on each Protected System. Safenix does not throttle a Customer who configures a shorter interval.
3. Account and Access
3.1 Account Registration
To use the Service, the Customer registers an account at app.safenix.eu. The Customer warrants that registration information is accurate, that the person registering has authority to bind the Customer to this Agreement, and that they will keep account credentials secure and notify Safenix immediately of unauthorised access.
At registration the Customer accepts these Terms and the Privacy Policy. Safenix records which version of each document was accepted, a cryptographic hash of the exact text presented, the date, and the person who accepted. That record is kept in the Compliance Vault. Access to the dashboard requires an authenticator application in addition to a password, for every user without exception.
3.2 Trial
A new subscription begins with a fourteen-day trial. No payment method is required to start it and nothing is charged during it. Section 4.5 sets out what happens at the end of it.
3.3 Acceptable Use
The Customer may use the Service only for lawful backup of infrastructure they operate. The Customer must not: back up data they do not have the right to process; reverse-engineer, decompile or modify Safenix software; degrade the Service for other customers; circumvent any security feature; or resell or sublicense the Service without prior written agreement.
3.4 Account Suspension
Safenix may suspend an account where the Customer is in material breach and has not remedied it within 7 days of written notice, or where Safenix reasonably believes the account is being used unlawfully or presents a security risk to others. Suspension for non-payment follows Section 4.5 instead, and never closes the Customer's access to sign in or to the billing page — an account that must be paid for is not one the Customer can be locked out of paying for.
4. Billing and Payment
4.1 Subscription Fees
Fees are charged monthly in advance at the prices published at safenix.eu/pricing, exclusive of VAT and other applicable taxes. Charging is on the Customer's own monthly anniversary, which is the date their trial ends or their first payment is made.
Nothing is prorated, in either direction. A plan change takes effect at the next billing date at the new price; the period already paid for is not adjusted and nothing is charged on the day of the change.
4.1a VAT, and what the Customer warrants
The Customer warrants that they are a taxable person acting as such, that the VAT registration number they supply is theirs and is valid, and that they will tell Safenix if it ceases to be. Safenix verifies the number against the European Commission's VIES register, records the result and the date, and keeps that record as evidence of the check.
No VAT is charged, and the invoice says why. Each invoice carries the reverse charge statement, both parties' identifiers, and the period it covers. Where a registration number cannot be verified, Safenix cannot issue an invoice under the reverse charge — it will say so and ask the Customer to correct it, and backups are not affected while that is resolved.
Where a Customer supplies a registration number that is not theirs or is not valid, any tax consequence of that is the Customer's.
4.2 Payment processing
4.3 Price Changes
Safenix may change Plan pricing with 30 days written notice. The Customer may terminate before the new pricing takes effect without penalty. Continued use after the notice period constitutes acceptance.
Where a Customer's registered card was authorised for a lower amount than a new price or an upgraded Plan, that renewal cannot be taken until the Customer confirms their card at the new amount. Safenix will ask them to, will not attempt the charge, and will not treat the unattempted charge as a failed payment or stop the Service for it.
4.4 Refunds
Safenix does not refund partial months and does not currently operate a refund facility. Where a refund is due, it is applied to the next invoice. No refund or credit arises from the availability of the Service — see Section 5.1, which explains why there is no service level agreement to claim under.
4.5 Non-payment, and what happens to the Customer's data
Stated in full because the last step of it destroys data.
The Customer has thirty days from the day their backups stop. On this path that is thirty-four days from the first declined payment: three attempts over four days, then thirty days of payment hold. The same thirty days apply where a trial ends without a payment method. The Customer is emailed on each attempt, when the hold begins, and again 48 hours before it ends. It is longer where a charge could not be attempted.
Where a charge could not be attempted at all — because Safenix has no registered card, because no price is recorded, because the payment gateway could not be reached, or because of any other fault or limitation on the Safenix side — that is not a failed payment. It does not count towards the three attempts, the Customer is not emailed about a payment problem, and no account is stopped for it.
5. Service Levels
5.1 Availability — what Safenix commits to, and what it does not
Safenix does not measure its own availability, does not publish an uptime figure, and does not offer a service level agreement. There is therefore no availability target in these Terms, no service credit, and no refund calculated from downtime.
This is a decision and not an omission. An availability commitment is only worth what the measurement behind it is worth, and a credit scheme that depends on a number nobody produces is not a scheme — it is a clause that would be argued about after every outage, by two parties neither of whom can prove anything. Safenix would rather say what it does than promise a figure it cannot substantiate.
What the Customer does get, and it is deliberately expressed as behaviour rather than as a percentage:
| Component | What Safenix commits to |
|---|---|
| Control Plane and dashboard | Commercially reasonable efforts to keep them available, and to restore service promptly when they are not. No measured target |
| Object Storage | Hetzner Online GmbH's own service levels, which Safenix passes through and does not add to |
| Agent connectivity | The Agent retries automatically and resumes where it left off. Outages on the Customer's own network or systems are theirs |
A Control Plane outage does not by itself cause data loss. The Agent continues capturing locally and transmits when the Control Plane is reachable again. This is the commitment that matters for a backup service, it is a property of the design rather than of an uptime figure, and it is the reason the absence of an availability target is not the concession it might appear to be.
Safenix does monitor its own service, for its own purposes. Since 26 August 2026 an automated check reaches each of the three service addresses every two minutes and raises an alarm when one does not answer. It exists so that Safenix notices a fault, not so that a Customer can demonstrate one: it is operational monitoring, it is not a contractual measurement, its output is not published, and nothing in these Terms is calculated from it. It is mentioned here because saying "we do not measure availability" while running a monitor would be true in the way that misleads.
Remedies. Where Safenix fails to provide the Service, the Customer's remedies are those in Sections 8 and 9 — including termination — rather than a credit. Nothing in this Section limits a right the Customer has under applicable law that cannot be excluded by agreement.
5.2 Scheduled Maintenance
Announced at least 48 hours in advance by dashboard notice and email; scheduled outside business hours (01:00–05:00 UTC) where reasonably possible; limited to four hours per month without the Customer's consent. There is no availability calculation for it to be excluded from.
5.3 Recovery Point monitoring
Safenix monitors the age of each Protected System's Recovery Point and alerts the Customer when it exceeds the threshold configured for their account.
This is an alerting commitment and not a guarantee of maximum data loss. How recent a Recovery Point is depends on the Customer's configured backup frequency, their system's availability, their network, and the volume of change. Safenix commits to telling the Customer when their Recovery Point falls behind; it does not commit to a maximum quantity of data lost in any particular failure.
6. Data, Security, and Compliance
6.1 Data processing
Processing of personal data is governed by the DPA, which forms part of this Agreement and takes precedence over these Terms on all data protection matters.
6.2 Data residency
Backup Data is stored in Germany, with Hetzner Online GmbH. The Control Plane is hosted in Germany, with KeyWeb AG. Safenix will not move Backup Data outside the EU/EEA without the Customer's prior written consent.
One exception, stated rather than buried: payment processing is carried out by Pago in Albania, outside the EU and EEA. See Section 4.2. Backup Data is not involved. Any statement that all Safenix infrastructure is in the EU should be read as applying to Backup Data and the Control Plane, which is where it is true.
6.3 Security obligations — Safenix
Safenix will:
6.4 What the retention lock does and does not protect against
Stored objects are written with a governance-mode retention lock. Neither the Customer's systems nor anyone who compromises them can delete or overwrite stored backups before the retention period expires. Safenix can override the lock, and does so in exactly one circumstance: to erase an account's data when the Customer asks, or when this Agreement ends. Without that ability Safenix could not honour an erasure request, so it is deliberate.
The honest formulation, which Safenix will use in security questionnaires and everywhere else: a compromised Customer system cannot delete that Customer's backups. Not: backups cannot be deleted by anyone.
Safenix reads this back from storage rather than assuming it. On 26 August 2026 the storage system was asked directly and a stored object was sampled: object locking and versioning enabled, and the sampled object carrying a retention date of 11 November 2026. The check is repeated after any change to the way objects are stored or retained. It confirms that the locks are in force; it does not change the sentence above.
6.5 Compliance Vault and audit
Safenix maintains an append-only, cryptographically chained record of operations on Customer data. Any retroactive alteration breaks the chain and is detectable.
The Customer may download a compliance export from the dashboard at any time. It contains: the Protected Systems registered to the account; the backup history as a table of one row per stored snapshot; the Compliance Vault records for that account; the results of scheduled verifications, including what each one deliberately did not check; and a manifest recording whether the chain verified intact. It does not contain Backup Data — getting data back is a restore, described in Section 9.5.
Customers requiring on-site audit rights may request them at support@safenix.eu, with at least 14 days notice.
6.6 Scheduled verification, and what it establishes
Safenix verifies each Protected System's stored backups monthly. Where a database is protected with continuous capture, the verification confirms that a full copy exists and that the change log runs from it to the present with no missing range. Where a database is protected with periodic full copies instead, there is no change log to check, and the verification confirms that a recent full copy exists. In every case the verification confirms that stored objects match the sizes and counts recorded, and that the Compliance Vault chain is intact.
It does not decrypt anything, and it never confirms that Backup Data will decrypt. Safenix cannot make that check, because it does not hold the key. Every verification result Safenix produces records that decryption was not performed.
Customers can check decryption themselves at any time, with the Agent's
verify-restore command, which performs a real restore into a
temporary location using their own Encryption Key. Safenix recommends doing so
and does not currently record whether a Customer has.
6.7 Security obligations — Customer
The Customer is responsible for: securing each server on which the Agent is installed; maintaining a secure and independently stored backup of the Encryption Key, and verifying that it is accessible; managing access to the dashboard, including the authenticator enrolment of each of their users; and ensuring that data backed up using the Service is data they are lawfully entitled to process.
7. Encryption Key Management and Key Loss
Critical clause. This section determines recoverability of all Backup Data. Legal counsel must review and approve it before publication.
7.1 The Customer holds the key
The Encryption Key is generated on the Customer's server during installation. It is never transmitted to Safenix, is not held or recoverable by Safenix, and is the Customer's sole means of decrypting Backup Data.
The Customer is solely responsible for maintaining a secure, independent backup of the Encryption Key; for verifying that the backup is accessible and functional; and for restricting access to the key on the server.
7.2 Consequences of key loss
If the Customer loses the Encryption Key: all Backup Data becomes permanently unreadable; Safenix cannot and will not be held liable for the resulting loss; and Safenix will not attempt decryption, because it does not have the key.
The Customer acknowledges this separately from, and in addition to, its acceptance of these Terms. The acknowledgement is given at registration as a distinct act, and acceptance of these Terms alone does not constitute it. Each acknowledgement is recorded with the version of the text acknowledged and a hash of that text, in the Compliance Vault.
8. Limitation of Liability
8.1 Exclusions
To the maximum extent permitted by applicable law, Safenix is not liable for:
8.2 Aggregate liability cap
| Scenario | Cap |
|---|---|
| General aggregate | The amount actually paid by the Customer to Safenix in the twelve months preceding the event giving rise to the claim |
| Loss of Backup Data attributable to Safenix | The same cap: the amount actually paid by the Customer in the twelve months preceding the event |
| Encryption Key loss, Customer cause | Zero — see 7.2 |
| Breach of the General Data Protection Regulation attributable to Safenix | Twice the annual subscription fee |
8.3 Mutual exclusions
Neither party is liable to the other for indirect or consequential losses, even if advised of the possibility.
8.4 Force Majeure
Neither party is in breach where performance is prevented or delayed by events outside their reasonable control. The affected party must notify the other within 48 hours and take reasonable steps to resume performance.
9. Term and Termination
9.1 Term
This Agreement begins when the Customer activates an account and continues monthly until terminated.
9.2 Termination by the Customer
The Customer may terminate by contacting Safenix. Termination takes effect at the end of the current billing period and no refund is issued for the remaining days. Self-service cancellation from the dashboard is not currently available; Safenix will act on a request by email without requiring a reason.
9.3 Termination by Safenix
Safenix may terminate with 30 days written notice for any reason; immediately, on material breach not remedied within 7 days of notice; or immediately where the Customer's use presents a security risk to others. On termination by Safenix without Customer cause, fees for the unused portion of the period are refunded.
9.4 Effect of termination
9.5 Getting data out
Backup Data is retrieved by performing a restore, from the dashboard or with the Agent, before termination takes effect. This requires the Customer's Encryption Key.
Safenix does not issue object storage credentials to Customers, and there is no S3-compatible export of Backup Data: the Agent can write to storage and cannot read from it, which is what prevents a compromised Customer system from reading or destroying that Customer's backup history. Safenix will provide reasonable technical assistance with a restore on request.
10. Intellectual Property
10.1 Safenix retains all rights to the Service and its software. The Customer receives a non-exclusive, non-transferable licence to use the Service for the duration of this Agreement.
10.2 The Customer retains all rights to data backed up using the Service and grants Safenix a limited licence to store and transmit it solely to deliver the Service. Safenix cannot access that data.
10.3 Safenix may use feedback about the Service without obligation or compensation.
11. Confidentiality
Each party will keep the other's confidential information in confidence. This does not apply to information that is public, independently developed, or required to be disclosed by law. Safenix's obligations regarding Backup Data are governed by Section 2.2 and the DPA rather than by this clause.
12. Changes to the Service and These Terms
12.1 Safenix may modify, add or remove features with 30 days notice, and will not materially degrade core backup functionality without a migration path or a termination option.
12.2 Safenix may update these Terms with 30 days written notice. Material changes require the Customer's acknowledgement, which is recorded with the version and a hash of the text as at Section 3.1. The Customer may terminate without penalty if they do not accept, provided they notify Safenix before the change takes effect.
13. Governing Law and Dispute Resolution
13.1 Governing law — This Agreement, and any non-contractual obligation arising out of or in connection with it, is governed by the law of the Czech Republic, without regard to its conflict of laws rules.
13.2 Jurisdiction — The courts of Prague, Czech Republic have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement.
13.3 Consumer rights — Nothing in this Agreement limits mandatory statutory rights. Safenix is a B2B service and does not contract with consumers.
14. General
14.1 Entire agreement. This Agreement, with the DPA, the Privacy Policy and any Order Form, is the entire agreement and supersedes prior agreements and representations.
14.2 Severability. An unenforceable provision is modified to the minimum extent necessary; the rest continues in force.
14.3 Waiver. Failure to enforce a right is not a waiver of it.
14.4 Assignment. The Customer may not assign without Safenix's written consent. Safenix may assign to an affiliate or in connection with a merger or sale of substantially all assets, with 30 days notice, and only to an entity established in the European Union.
14.4a Language. The English version of this Agreement is the authoritative one and prevails in the event of any discrepancy. Any translation is provided for convenience only.
14.5 Notices. Notices must be in writing. Safenix writes to the Customer's registered account email. The Customer writes to legal@safenix.eu. Email notices are effective on the day sent; postal notices three days after posting.
14.6 Independent contractors. Nothing here creates a partnership, employment, agency or joint venture.
15. Contact
| Legal entity | Eurhosting SHPK |
| NIPT | M52305043P |
| Registered address | Sallmone, Shijak — Durrës, Albania |
| General enquiries | hello@safenix.eu |
| Technical support | support@safenix.eu |
| Billing | billing@safenix.eu |
| Legal / contract matters | legal@safenix.eu |
| Privacy / data protection | privacy@safenix.eu |
| Data protection contact | dpo@safenix.eu |
End of document — Safenix Terms of Service v1.2