Terms of Service
Version 1.1
Interim terms for the closed beta — a full legal review is pending;
participants will be notified of material changes.
Version 1.1 (21 July 2026) adds data-processing (Article 28) terms
and a clearer statement of how your data is retained and deleted.
1. Who we are
Eighteen Zeros Limited ("Eighteen Zeros", "we", "us") is a company registered in the United Kingdom, founded in January 2026. We operate a managed platform that provisions and runs open-source collaboration software — currently Nextcloud, with related identity, storage, and mail services — on isolated infrastructure for each customer ("the Service").
2. Closed beta status
The Service is currently in closed beta. It is provided "as is" and "as available", without any service level agreement or uptime guarantee. Features, pricing, and functionality may change, be added, or be withdrawn at short notice as the platform develops. We will try to give reasonable notice of anything disruptive, but the beta period should not be relied on for production-critical use without your own backups and contingency plans.
3. Your account and responsibilities
You are responsible for the accuracy of the information you provide during signup, for keeping your account credentials secure, and for the actions taken under your organisation's account by users you invite. You must be authorised to accept these terms on behalf of your organisation.
4. Acceptable use
You agree not to use the Service to store or distribute unlawful content, to attempt to breach the isolation or security of the platform or other customers' environments, or to use the Service in a way that places unreasonable load on shared infrastructure. We may suspend access to protect the platform or other customers if these terms are breached.
5. Data and privacy
We handle two different kinds of data, and our legal role differs between them:
- Your account data — the details you give us to create and run your account (names, contact email, phone, organisation). For this we are the data controller. How we use it, the lawful bases, retention periods, and your rights are set out in full in our Privacy Notice.
- Your content — the files, messages, and other material your organisation stores in the services we run for you. For this your organisation is the controller and we are your processor: we handle that content only on your instructions, under the data-processing terms in clause 6.
UK GDPR and the Data Protection Act 2018 apply throughout. Data is stored on infrastructure located in the EU. We do not sell customer data, and we access your content only to operate, support, or secure the Service.
6. Data processing (our role as your processor)
Where we process your content on your behalf, the following terms apply and form the data-processing agreement between us for the purposes of Article 28 UK GDPR:
- We process your content only on your documented instructions — chiefly, to operate the Service — unless the law requires otherwise.
- We keep your content confidential, and anyone we allow to access it is bound by confidentiality.
- We apply appropriate technical and organisational security measures, including per-customer isolation, encryption in transit, and encrypted off-site backups.
- We engage the subprocessors listed in clause 7 to help deliver the Service. We remain responsible for their compliance and will give notice of any intended change to that list.
- We assist you, so far as reasonably possible, in responding to your users' data-protection requests and in meeting your own security and breach-notification obligations.
- At the end of the Service we return or delete your content as described in clause 8.
Deletion and object storage. When your organisation deletes content, our object storage keeps a hidden copy for a short period before permanently expiring it — up to 35 days. During that window the copy is held beyond use: it is not accessed or restored except as part of disaster recovery, it cannot be retrieved by you or your users, and it ages out automatically. This is the tail on any deletion you carry out, and it is the only respect in which deleted content lingers on our systems.
7. Subprocessors
We rely on the following subprocessors to operate the Service, each acting under contractual data-protection obligations consistent with UK GDPR. All are based in the EU:
- Scaleway SAS (France) — cloud infrastructure and object storage
- QBoxmail S.r.l. (Italy) — email hosting
- Hetzner Online GmbH (Germany) — encrypted off-site backups
- Scaleway Transactional Email (EU) — transactional email delivery
The current list is also published in our Privacy Notice.
8. Termination and data return
You may stop using the Service at any time. We may suspend or terminate access if these terms are breached, if required by law, or — during the beta — if we discontinue the Service or a feature, with reasonable notice where practicable. Before or at termination you can export your data; the stack is built on open standards and we will help you retrieve it. After termination we delete your account data and content from the live Service. Residual copies in our backups and object storage are not individually edited — instead they are held beyond use and age out within our retention window (up to 35 days), after which they are permanently gone. Any restore from backup re-applies deletions already made.
9. Liability
To the extent permitted by law, Eighteen Zeros' liability arising from your use of the Service is limited, and we exclude liability for indirect or consequential losses. Nothing in these terms limits liability that cannot lawfully be excluded, such as liability for death, personal injury, or fraud.
10. Governing law
These terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute.
11. Contact
Questions about these terms can be sent to support@eighteenzeros.com.