Terms of Service
Last updated: 23 September 2026
These Terms of Service ("Terms") govern your use of the website storm-vault.net (the "Site") and the managed backup and business continuity services we provide (the "Services"). The Services are provided by Storm Vault Systems Ltd, a company registered in England and Wales, with its office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("we", "us", "our"). "You" means the business or individual who orders or uses the Services.
The Services are intended for business customers. By ordering or using the Services you confirm that you are acting for business purposes and have authority to bind your organisation.
1. The Services
We provide managed backup, restore, and business continuity services, which may include:
offsite backups of websites (including WordPress and WooCommerce sites, files, and database snapshots) and servers;
backups of cloud accounts such as Microsoft 365 (mailboxes, OneDrive, SharePoint) and Google Workspace (mail, Google Drive);
encrypted storage, automated restore testing, and support.
The specific scope, frequency, retention period, and support arrangements for your plan are set out in your order or plan description ("Service Description"). If the Service Description conflicts with these Terms, the Service Description applies to that plan.
2. Your Responsibilities
You agree to:
give us accurate information and the access, credentials, and permissions needed to run the Services, and keep them current;
make sure you have the legal right to have us back up and process the data you ask us to protect (including personal data of your own customers, staff, and users);
keep your own account credentials secure and tell us promptly of any suspected compromise;
review backup and restore reports we provide and tell us about anything that looks wrong;
not use the Services for unlawful content or to attempt to disrupt or gain unauthorised access to our systems.
3. Your Data
You own your data. We access and process it only to provide the Services, on your instructions, and as described in our Privacy Policy and Data Processing Agreement. You grant us the limited rights needed to copy, encrypt, store, verify, and restore your data. We do not sell your data or use it for advertising.
4. Service Standards and Limits
We use reasonable skill and care, industry-standard encryption (in transit and at rest), and automated verification to protect your backups. However:
no backup system can guarantee that data is never lost, corrupted, or unavailable, and we do not promise uninterrupted or error-free operation;
descriptions such as "ransomware-proof" or "verified restore" on our Site describe our design goals and processes and are not a guarantee against every possible attack or failure;
we can only back up data that the source system, third-party API, or account permissions actually make available to us. Cloud providers (for example Microsoft and Google) may limit, change, or suspend API access, and we are not responsible for those limits;
restore times depend on data size, source-system condition, and third-party availability. Any target restore times are targets, not guarantees, unless expressly stated as a service level with remedies in your Service Description.
5. Fees and Payment
Fees and billing terms are set out in your order or plan description. Fees are exclusive of VAT, which is added where applicable. Invoices are payable by the due date shown on them. Where you pay by card, payment is processed by a third-party payment provider and we do not store full card numbers. We may suspend the Services for non-payment after giving reasonable notice. We may change fees on at least 30 days' written notice, effective from your next renewal.
6. Term, Cancellation, and Data Return
The Services start on the date in your order and continue for the term stated there. Unless your order says otherwise, either party may end the Services by giving at least 30 days' written notice. After termination, we will keep your backups available for 30 days so you can retrieve them, then securely delete them, unless the law requires us to keep them longer.
7. Intellectual Property
We (or our licensors) own the Site, our software, tooling, and documentation. We grant you a non-exclusive, non-transferable right to use them during the term to receive the Services. Your data remains yours.
8. Confidentiality
Each party will keep the other's non-public business information confidential and use it only for the purposes of these Terms, except where disclosure is required by law or a regulator.
9. Warranties and Disclaimer
We warrant that we will provide the Services with reasonable skill and care. Except as stated in these Terms, and to the extent permitted by law, we exclude all other warranties, conditions, and terms, whether express or implied.
10. Limitation of Liability
Nothing in these Terms limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or anything else that cannot be limited or excluded by law.
Subject to that, we are not liable for loss of profit, revenue, business, goodwill, or anticipated savings, or for any indirect or consequential loss, whether in contract, tort (including negligence), or otherwise.
Subject to the above, our total liability to you in each contract year is limited to the fees you paid us for the Services in the 12 months before the claim arose.
We are not liable for loss or damage caused by events outside our reasonable control, by your failure to follow reasonable instructions, or by third-party platforms (including Microsoft, Google, hosting providers, and WordPress plugins).
Because backup failures can be costly, we recommend you also keep your own copies of critical data and maintain appropriate insurance.
11. Data Protection
Where we process personal data on your behalf as part of the Services, we act as your processor, and you act as controller. The terms required by Article 28 UK GDPR are set out in our Data Processing Agreement, available on request at office@storm-vault.net, which forms part of these Terms. Our own use of personal data is described in our Privacy Policy.
12. Suspension and Termination
Either party may terminate on written notice if the other commits a material breach that is not remedied within 14 days of notice, or becomes insolvent. We may suspend the Services immediately if needed to protect the security or integrity of our systems or if required by law.
13. Changes
We may update these Terms from time to time. We will give you at least 30 days' notice of material changes by email or through your account. If you do not agree, you may cancel before the changes take effect.
14. General
These Terms, your order, and the Service Description are the entire agreement between us on the Services. Neither party may assign its rights without the other's consent, except that we may assign to a successor to our business. If any provision is unenforceable, the rest continues. A person who is not a party has no right to enforce these Terms under the Contracts (Rights of Third Parties) Act 1999.
15. Governing Law and Jurisdiction
These Terms and any dispute arising from them are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
16. Contact
Storm Vault Systems Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Email: office@storm-vault.net
Privacy Policy
Last updated: 23 September 2026
This Privacy Policy explains how Storm Vault Systems Ltd ("we", "us") handles personal data. It covers two different roles we have:
As controller, for information about visitors to our Site, prospective customers, and our customers' contacts (Sections 2 to 9).
As processor, for the data in the backups we store for customers (Section 10).
1. Who We Are
Storm Vault Systems Ltd, a company registered in England and Wales, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact for privacy matters: office@storm-vault.net.
2. Data We Collect as Controller
Site visit data: IP address, browser and device type, pages visited, referring page, and timestamps, processed automatically by our servers and hosting provider.
Enquiries and support: name, email address, phone number, company, and the content of your messages when you contact us or use our support channels.
Customer account and billing data: business contact details, billing address, plan details, and transaction status. Where you pay by card, payment is handled by a third-party payment provider and we do not store full card numbers.
Service operations data: metadata such as backup job status, timestamps, error logs, and restore-test results, used to run and support the Services.
Cookies: we do not use advertising cookies. If we use analytics or other non-essential cookies, we will ask for your consent where the law requires it.
3. How and Why We Use It
Purpose Legal basis (UK GDPR)
Providing and supporting the Services Contract
Billing, accounting, and tax records Contract; legal obligation
Securing the Site and preventing abuse Legitimate interests
Responding to enquiries Legitimate interests; steps before a contract
Non-essential cookies or analytics (if used) Consent
4. Sharing
We share personal data only with service providers acting on our instructions (for example hosting, storage, email, support, payment, and accounting providers) and with authorities when the law requires. A list of our sub-processors is available on request at office@storm-vault.net. We do not sell personal data.
5. International Transfers
If personal data is transferred outside the UK, we use appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum, or an adequacy decision.
6. Retention
We keep personal data only as long as necessary for the purposes above. Technical logs are kept for as long as needed for security and troubleshooting, then deleted or anonymised. Enquiries and support records are kept while relevant to our relationship with you. Billing and accounting records are kept for 6 years, as required by UK law.
7. Security
We use encryption in transit and at rest, access controls, monitoring, and regular testing to protect data. No system is completely secure, and we will notify affected customers and regulators of qualifying personal data breaches as the law requires.
8. Your Rights
Under UK GDPR you may request access to, correction of, deletion of, or restriction of your personal data, object to certain processing, request data portability, and withdraw consent where we rely on it. Contact office@storm-vault.net. You can complain to the Information Commissioner's Office (ICO) at ico.org.uk. If your data is in a customer's backup and you wish to exercise rights over it, please contact that customer first, as we act only on their instructions.
9. Children
Our Services are for businesses and not directed to children.
10. Customer Backup Data (We Act as Processor)
When you use our Services, we store and process the data you ask us to back up, which may include personal data of your own customers, employees, and users (for example website orders and customer records, emails, and documents).
Roles: you are the controller; we are your processor. We process this data only on your documented instructions, to provide the Services.
No other use: we do not use backup data for our own purposes, sell it, or use it for advertising.
Access: our staff access backup contents only when needed to provide support or restore data at your request, or to meet legal obligations.
Security: backups are encrypted in transit and at rest and stored offsite.
Sub-processors: we use the sub-processors available on request at office@storm-vault.net and will notify you of changes as set out in our Data Processing Agreement.
Deletion: on termination we delete or return backup data as set out in the Terms (Section 6).
Your obligations: you are responsible for having a lawful basis to back up personal data and for informing the individuals concerned, as required by data protection law.
DPA: the full Article 28 terms are in our Data Processing Agreement, which you can request at office@storm-vault.net.
11. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date shows the latest version, and we will notify customers of material changes.
12. Contact
Storm Vault Systems Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Email: office@storm-vault.net