General Terms and Conditions (T&Cs)
Provider: Moritz Möller Workstations (sole proprietorship), owner Moritz Möller, Böhnhusener Weg 11, 24220 Flintbek, Germany. Brand "ComputeBox", computebox.de.
In case of discrepancies between the German and the English version, the version in the language in which the individual contract was concluded prevails (see clause 13).
Table of Contents
- 1. Scope and Subject Matter
- 2. Contract Formation and Ordering Process
- 3. Scope of Services
- 4. Customer Obligations and Usage Restrictions
- 5. Traffic and Bandwidth Management
- 6. Contract Duration, Renewal and Termination
- 7. Payment and Invoicing
- 8. Wallet System and Balance
- 9. Liability and Warranty
- 10. Data Protection and GDPR Compliance
- 11. Changes to the T&Cs
- 12. Switching Providers and Data Portability (EU Data Act)
- 13. Jurisdiction, Applicable Law and Final Provisions
1. Scope and Subject Matter
These General Terms and Conditions (hereinafter "T&Cs") apply to all contracts between Moritz Möller Workstations, owner Moritz Möller, Böhnhusener Weg 11, 24220 Flintbek (brand "ComputeBox", hereinafter "Provider"), and its customers (hereinafter "Customer") regarding the provision of virtual servers (V-Servers) and dedicated servers as well as related services.
The Provider's offers are directed at both consumers and businesses, including those established or habitually resident in other Member States of the European Union. A consumer within the meaning of these T&Cs is any natural person who enters into a legal transaction for purposes that are predominantly neither commercial nor self-employed professional activity (§ 13 BGB). A business within the meaning of these T&Cs is a natural or legal person or partnership with legal capacity who, when concluding the contract, acts in the exercise of their commercial or independent professional activity (§ 14 BGB).
Conflicting or deviating terms and conditions of the Customer shall not apply unless the Provider expressly agrees to their validity in text form. The conclusion of the contract is only possible with adults with unlimited legal capacity. The Provider provides its services exclusively on the basis of these T&Cs.
2. Contract Formation and Ordering Process
The presentation of services (server packages) on the Provider's website does not constitute a binding offer, but a non-binding invitation to the Customer to submit an offer. In the ordering process, the Customer selects a server package (with CPU or GPU server), determines the desired minimum contract term (1, 3, 6, or 12 months), and the payment method (credit card, SEPA direct debit, or PayPal, processed through the payment service provider Stripe, and, where available, payment from existing Wallet balance or by bank transfer).
Before submitting the order, the Customer receives an overview of all entries and can check them for correctness and make corrections if necessary.
If the Customer is a consumer, they make two separate and independent declarations in the ordering process:
- They confirm that they have taken note of the withdrawal instruction regarding their statutory 14-day right of withdrawal.
- They may, in addition, by activating a separate checkbox, expressly request that the Provider begin performing the service before the withdrawal period expires. In that case the Customer is informed of, and confirms, that their right of withdrawal expires only upon complete performance of the contract by the Provider (§ 356 (4) BGB). If, upon such a request, the Provider begins performance early, the Customer owes, in the event of withdrawal before complete performance, value compensation for the services rendered up to the withdrawal (§ 357a BGB).
The request for early commencement of performance under no. 2 is voluntary and is not a prerequisite for concluding the contract. If the Customer does not make this request, the Provider will begin performing after the withdrawal period has expired, unless otherwise agreed.
Consumers may declare their withdrawal without any particular form; in addition, the online withdrawal function pursuant to § 356a BGB is available at computebox.de/legal/withdrawal/form. The Provider will confirm receipt of any withdrawal without undue delay.
By clicking the order button, the Customer submits a binding offer to conclude a contract. The Provider confirms receipt of the order immediately by email (order-receipt confirmation). This confirmation does not yet constitute acceptance of the contract, unless expressly stated otherwise. The contract is only concluded when the Provider accepts the offer. This is done either by explicit order confirmation by email or by providing the booked server (commencement of service provision). If the Provider does not accept the Customer's offer within 5 working days, the Customer is no longer bound by their order.
In the ordering process, the Customer also confirms that they have taken note of and agreed to these T&Cs and that they have taken note of the Provider's privacy policy.
3. Scope of Services
The Provider provides the Customer with the selected server (virtual or dedicated) with the characteristics specified in the respective service description (e.g., CPU/GPU performance, RAM, hard disk storage, including data transfer volume). The provision and activation of the server typically takes place within 12 hours after contract conclusion and receipt of payment.
The Provider commits to a minimum availability of the server services of 99% per calendar month, unless the service description states a different value. This availability commitment applies as standard to all server services. Where it is undershot, the Provider grants a voluntary service credit under clause 9.6; the Customer's statutory rights, in particular the provisions on contracts for digital products (§§ 327 et seq. BGB) for consumers, remain unaffected. Times of planned maintenance announced in good time, as well as times of force majeure or circumstances beyond the Provider's control (e.g., power failure, network failure outside the sphere of influence, DDoS attack from outside), are not taken into account when calculating availability.
The scope of services includes the provision of the agreed hardware and network infrastructure in the Provider's data center as well as the network connection including an IP address assigned by the Provider. The Customer receives administrator rights (root access) to the server and is responsible for the software installed on it. The Provider is only obliged to ensure the functionality of the hardware and the internet connection. Support by the Provider is exclusively provided for problems with the provided hardware or network connection. Software support (installation, configuration, maintenance, or troubleshooting of operating system, applications, or services on the server) is not part of the contract.
If a hardware or infrastructure error occurs (e.g., defective components in a dedicated server), the Provider will repair it as quickly as possible within the scope of its technical possibilities and replace defective hardware with equivalent components. A guarantee for certain characteristics or an uninterrupted availability of the service is not provided beyond the availability commitments mentioned above, unless expressly assured in the service description or by individual agreement.
The Customer has no claim that the server will be assigned the same IP address throughout the entire contract term.
4. Customer Obligations and Usage Restrictions
4.1 General Behavioral Obligations
The Customer undertakes to use the Provider's services properly and in compliance with the law. They must refrain from all actions that violate the rights of third parties or could endanger the operation of the infrastructure provided by the Provider. In particular, the Customer may not use the servers in a way that impairs the security, integrity, or availability of the Provider's servers and networks.
4.2 Prohibited Uses
The Customer is particularly prohibited from:
- Hardware Manipulations: Changes to the hardware provided by the Provider or interventions in the server infrastructure. In particular, the Customer is prohibited from making changes to the hardware without the Provider's consent, such as overclocking (overclocking of CPU/GPU) or modifications to the cooling system or other hardware components.
- Abusive Use / Attacks: Using the server for illegal purposes or to conduct unauthorized actions. In particular, the Customer may not use the server for attacks on third-party computers, networks, or services (e.g., no execution or support of DDoS attacks, port scans, hacking attempts, or distribution of malware). Any use aimed at gaining unauthorized access to third-party information or impairing the functionality of third-party networks is also prohibited.
- Crypto Mining / Continuous Load: The use of server hardware for cryptocurrency mining (e.g., Bitcoin, Ethereum, etc.) or comparable permanently resource-intensive applications is prohibited. Excessive continuous utilization of the provided resources that exceeds the contractually intended usual use and puts excessive strain on the Provider's infrastructure is also inadmissible.
- Spam and Unwanted Communication: No unwanted mass emails (spam) or comparable unsolicited messages may be sent via the server. In particular, it is prohibited to send emails in bulk to third parties without their consent, or to use false sender data or conceal the identity of the sender when sending emails.
- Mail Port: The mail port 25 is blocked by default. A release can be granted in individual cases at the request of the Customer.
- Inappropriate and Illegal Content: The storage, publication, or distribution of illegal content via the server is prohibited. This includes, in particular, content that violates applicable laws or infringes on the rights of third parties. Inadmissible, among other things, is the offering or distribution of pornographic or youth-endangering material, extremist propaganda, glorification of violence, as well as copyrighted material (software, films, music, etc.), unless the Customer possesses the corresponding usage rights.
- Security Violations: The Customer is prohibited from violating the security of the Provider's network and services or that of another network, system, server, or account of a third party, or from attempting to do so. This includes, without limitation, the following activities: (a) access to data, servers, accounts, databases, etc., for which the Customer does not possess the necessary rights, (b) impersonation as an employee of another company, (c) attempts to research, inquire, or test the weaknesses of a network or system, or to circumvent security and authentication measures without the necessary authorization, (d) attempts to interfere with, interrupt, or disable the provision of services for a user, host, or network, including without limitation, through overloading, "flooding", "mailbombing", "denial of service" attacks, or "crashing", (e) falsifying TCP/IP packet headers or parts of the header information in emails or newsgroup messages, (f) conducting any actions to obtain services that the Customer is not entitled to, or (g) attempts to use the account name or the identity of a person without the latter's consent. The Customer is also prohibited from engaging in activities that aim to circumvent or manipulate the measurement or calculation methods for services. Violations of system or network security are subject to civil or criminal prosecution.
- Fraudulent and Misleading Content: The Customer may not use the service to transmit or distribute content that contains fraudulent offers for goods or services, or advertising or promotional content that contains false, misleading, or deceptive statements, demands, or representations.
4.3 Response to Security Incidents
Should the Customer's server become the target of external attacks (e.g., through a DDoS attack) or should attacks or disruptions towards third parties originate from the Customer's server, the Provider is entitled to temporarily disconnect the server or the corresponding IP address from the network (blocking). This measure serves to protect the Provider's infrastructure and the security of other customers. The Provider will inform the Customer about such a blocking immediately, as far as temporally and technically possible. During the duration of a justified blocking, the Provider is released from the obligation to perform. The Provider is liable for damages of the Customer arising from such a blocking in accordance with clauses 9.1 and 9.2. Where the cause of the blocking is a circumstance for which the Customer is responsible (for example, because attacks or disruptions originate from the Customer's server), the Customer's claims for reduction in connection with the blocking are excluded. Where the Customer is not responsible for the cause of the blocking (for example, because the Customer's server is merely the target of an external attack), the Customer's statutory rights, including the right to reduction, remain unaffected. As soon as the security incident has ended or subsided, the Provider will restore the connection.
4.4 Responsibility for Content and Indemnification
The Customer is solely responsible for all content (data, programs, files, etc.) that they store, provide, or transmit from the rented server. They must ensure that the content stored on the server or their use of the server does not violate any rights of third parties and does not violate any legal provisions (in particular criminal, youth protection, data protection, or copyright regulations).
If the Customer violates the above obligations or if the Provider is held liable by third parties (e.g., by an authority or a rights holder) due to content stored by the Customer or their use of the server, the Customer shall indemnify the Provider from all resulting third-party claims to the extent the Customer is responsible for the claim. This also includes reasonable costs of legal defense of the Provider (e.g., court and attorney fees), to the extent these have been caused by the Customer's behavior. The Provider will inform the Customer of any such claim without undue delay, leave the defense to the Customer as far as possible, and will not acknowledge or settle third-party claims without coordination with the Customer.
4.5 Customer's Data Backup Obligation
The Customer is obliged to regularly and independently back up their data stored on the server. Such data backup should be performed on external storage media and at appropriate intervals to avoid data loss in the event of damage. The Provider does not create backups of customer data without a separate agreement. If the Customer wishes a backup service, this must be explicitly agreed upon as an additional service.
4.6 Abuse Reports, Suspension and Notice-and-Action Procedure (DSA)
The Provider operates a Notice-and-Action mechanism in accordance with Article 16 of Regulation (EU) 2022/2065 on a Single Market For Digital Services ("Digital Services Act" / DSA). Any natural or legal person may report allegedly illegal content hosted on the Customer's server via the reporting form at computebox.de/legal/abuse-report or by email to [email protected]. Sufficiently substantiated notices give the Provider actual knowledge within the meaning of Art. 6 DSA.
Upon receipt of a substantiated abuse report or upon the Provider obtaining knowledge of unlawful conduct by any other means (in particular via law-enforcement requests, automated monitoring, or third-party complaints), the Provider is entitled to take, in its reasonable discretion and depending on the severity of the violation, in particular the following measures:
- request a statement from the Customer or remediation of the violation within a reasonable deadline,
- restrict the accessibility of the content (e.g., firewall blocking, null-routing),
- temporarily suspend the affected VM, IP address, or the entire customer account,
- extraordinary termination of the contract pursuant to clause 6 for good cause with subsequent deletion of the affected server in accordance with clause 7,
- forward the notice and the associated stored data (including the IP-assignment history described in clause 4.7) to law enforcement, other public authorities, or affected rights holders where the Provider is legally obliged or entitled to do so.
In cases of imminent danger to third parties, the Provider's infrastructure, public safety, or where a statutory or regulatory obligation requires immediate action (in particular for content depicting child sexual abuse, terrorist content, malware distribution, large-scale phishing, or attacks on third-party systems), the Provider is entitled to suspend the service immediately and without prior notice.
The Provider communicates every decision taken under this clause 4.6 to the Customer with a statement of reasons, unless this would interfere with an ongoing investigation by a public authority. The communication also contains information on the Customer's available redress. Within six months, the Customer may use the Provider's internal complaint-handling system pursuant to Art. 20 DSA (complaint by reply to the notification or by email to [email protected]). This is without prejudice to the Customer's right to select a certified out-of-court dispute settlement body pursuant to Art. 21 DSA, and to the judicial remedies before the competent courts. The Provider reviews complaints within a reasonable period and communicates the outcome with reasons.
4.7 Logging of Connection Data
For the purposes of abuse prevention, IT security, fulfilling statutory obligations, and responding to lawful information requests by public authorities, the Provider records and stores the assignment of IP addresses to virtual servers and customer accounts on a per-event basis (assignment, release, reassignment), as well as security-relevant events of the customer account (login, signup, password reset, 2FA). The data is stored for a period of 6 months and is processed exclusively for the purposes mentioned above. Storage beyond 6 months takes place only insofar as and for as long as this is necessary to pursue or defend specifically asserted claims or to fulfill statutory obligations; the reasons for such an extension are documented (principle of storage limitation, Art. 5(1)(e) GDPR). Details are set out in the privacy policy.
5. Traffic and Bandwidth Management
The server packages offered by the Provider each include a certain included data volume per billing period (usually per month). The specific amount of traffic volume included in the price results from the service description of the booked package. If the Customer exceeds the included data volume within the current month (or billing period), the Provider is entitled to limit the network bandwidth of the server connection to 10 Mbit/s for the rest of this period (throttling). From the beginning of the next billing period (following month), the Customer will again have the full contractually agreed bandwidth at their disposal.
Regardless of the agreed volume limit, the Customer is not permitted to continuously transfer very large amounts of data in a continuous form (in particular, no continuous streaming of audio or video data or similarly data-intensive continuous transmissions). The server may not serve as a permanent source for live streams, video or audio transmissions, or large file downloads that continuously make high demands on network resources. The Provider reserves the right to take appropriate measures in the event of such inadmissible continuous load on the network, such as further throttling of the bandwidth even before reaching the volume or a temporary blocking of the affected service, to ensure the quality of services for all customers.
6. Contract Duration, Renewal and Termination
6.1 Minimum Term and Advance Payment
The contract term begins with the provision of the server and runs for the fixed minimum term chosen by the Customer (1, 3, 6, or 12 months). The fee for the chosen minimum term is payable in advance. Discounted multi-month rates apply only to the fixed term actively booked in each case.
6.2 End upon Non-Renewal (Default Case without Automatic Payment)
About 7 days before the paid term expires, the Customer receives a payment request for renewal (proforma payment request; this is not an invoice and does not create any payment obligation). If the Customer does not pay this payment request, the contract ends automatically upon expiry of the paid term, without any need for termination. Non-renewal is not a payment default; it triggers neither default consequences nor dunning costs.
6.3 Active Renewal
The Customer may actively renew the contract by paying the payment request under clause 6.2 before the term expires. Each such renewal is a separate, active decision by the Customer and establishes a new fixed term of the length chosen by the Customer (1, 3, 6, or 12 months) at the conditions applicable to it. There is no tacit renewal into fixed term blocks.
6.4 Optional Automatic Payment (Indefinite Continuation)
The Customer may activate automatic payment in their customer account. If automatic payment is activated, the contract continues for an indefinite period after the minimum term and is billed monthly at the regular monthly base price of the booked package. The Customer may terminate this indefinite continuation at any time with a notice period of 7 days. The Provider may ordinarily terminate the indefinite continuation with a notice period of 7 days to the end of the month. Discounted multi-month rates do not apply during the indefinite continuation; they are only available by actively booking a new fixed term under clause 6.3.
6.5 Termination and Statutory Buttons
Termination requires text form (e.g., by email) or can be declared via the online function provided by the Provider in the customer area. Consumers may additionally declare the termination at any time, without logging in, via the cancellation button ("Cancel contracts here") at computebox.de/legal/cancellation (§ 312k BGB). The consumer's statutory right of withdrawal and the online withdrawal function pursuant to § 356a BGB at computebox.de/legal/withdrawal/form remain unaffected (see clause 2). The timely receipt of the declaration by the contractual partner is decisive for compliance with a deadline.
6.6 Extraordinary Termination
The right to extraordinary termination for good cause remains unaffected. For the Provider, good cause exists in particular if the Customer is in default with due and actually owed payments (clause 7) or significantly violates their obligations under this contract despite a warning (in particular against the usage rules in clause 4). Likewise, the Customer can terminate the contract without notice if there is good cause. In the case of a justified extraordinary termination by the Provider for which the Customer is responsible, the Provider retains the claim to remuneration for services already provided; otherwise, the legal consequences are governed by the statutory provisions.
7. Payment and Invoicing
7.1 Fees, Due Date and Payment Methods
Unless otherwise agreed, the agreed fees for the server services are payable in advance for the respective term. The payment methods available for orders and invoices are: credit card, SEPA direct debit, and PayPal (processed through the payment service provider Stripe), as well as Wallet credit (clause 8). Bank transfer (EU/US) and manually confirmed PayPal payments serve exclusively to top up the Wallet (clause 8.3) and are not direct payment methods for orders or invoices. At least one common payment method that is free of charge for the Customer is available (§ 312a (4) BGB). Where automatic payment is activated (clause 6.4), the Customer authorizes the Provider or Stripe to collect the due amounts on the respective due date via the chosen payment method. Invoices are sent to the Customer in electronic form by email to the stored email address, unless another form of invoicing has been agreed. All prices are in euros and, where applicable, include statutory value-added tax.
7.2 Renewal without Automatic Payment Is Not Default
The payment request for renewal under clause 6.2 is a non-binding proforma request. If the Customer does not pay it, the contract ends automatically under clause 6.2. An unpaid renewal does not constitute a payment default and does not trigger any dunning or default consequences. Dunning and default rules (clause 7.3) apply exclusively to fees that the Customer actually owes for a term already bindingly booked or for the indefinite continuation under clause 6.4.
7.3 Payment Default for Amounts Actually Owed
If the Customer is in default, in whole or in part, with a payment that is actually owed and due (e.g., because a direct debit cannot be honored due to lack of funds or a credit card payment fails), the following staged procedure applies:
- Payment reminder: The Provider informs the Customer by email about the outstanding payment and sets a reasonable payment deadline of generally at least 7 days.
- Suspension: If the payment remains outstanding after this deadline expires, the Provider is entitled to temporarily suspend the server, i.e., to prevent further use until payment is received. The stored data is retained at this stage.
- Extraordinary termination: If the payment remains outstanding despite suspension and after a further reasonable grace period of at least 7 days, the Provider is entitled to terminate the contract extraordinarily for good cause (clause 6.6).
- End of contract and data deletion: The uniform procedure under clause 7.5 applies to the end of the contract and to data deletion; it also applies to an ordinary end of contract.
The Customer's obligation to pay the fees actually owed remains unaffected by a suspension or termination due to payment default. The Customer must reimburse the Provider for all owed amounts incurred until the termination of the contract.
7.4 Returned Direct Debits, Chargebacks and Default Interest
If the Provider incurs additional costs (bank fees, processing costs) due to returned direct debits, chargebacks, or other payment failures for which the Customer is responsible, the Provider may demand reimbursement of these costs. The Customer reserves the right to prove that no damage or lesser damage has occurred. In all other respects, the statutory provisions on payment default apply. The Provider is, in particular, entitled to charge default interest at the statutory rate from the onset of default (§ 288 BGB) and to assert further default damages to the extent legally permissible.
7.5 End of Contract, Data Export and Deletion
This procedure applies uniformly to every end of contract, i.e., both to expiry without renewal and to termination due to payment default (clause 7.3).
Upon the end of the contract, the virtual server is stopped. The final deletion of the server and the customer data stored on it takes place at the earliest 7 days after the end of the contract. The Provider announces both steps and the exact deletion date in the contract-end notifications by email and expressly points out that a free data export is available before deletion (clause 12). If, within this window, the Customer makes a data or switching request, the affected data is converted into an archive that is held for 30 days. After the aforementioned periods expire, restoration of the data is no longer possible. Further rights and obligations under clause 12 (Switching Providers and Data Portability) remain unaffected.
8. Wallet System and Balance
8.1 Nature of the Wallet
The Wallet is a euro-denominated credit account of the Customer. It can be used for all charges of the Provider (in particular invoices, renewals, and upgrades). It is not a fantasy currency; no conversion takes place. The Wallet is linked to the Customer's account, is not transferable to other accounts, and does not bear interest.
8.2 Payment with and without the Wallet
Regular invoices can always be paid directly by credit card, SEPA direct debit, or PayPal. Self-service upgrades, by contrast, are paid exclusively from Wallet credit. This exclusive payment from credit and its reason (card fees that are uneconomical for small amounts) are disclosed in the purchase dialog.
8.3 Top-up
The Customer may top up the Wallet. The minimum amount per top-up is EUR 10, the maximum amount EUR 1,500. This aggregation is openly stated: because payments incur card fees, micro-charges are uneconomical. The top-up of the Wallet does not constitute a value-added tax liable service at this time, as no concrete service is received yet; taxation only occurs when services are actually used. The top-up is provided to the Customer as a payment confirmation and does not constitute an invoice within the meaning of § 14 UStG. An invoice with displayed value-added tax is only issued when concrete services are actually used. For consumers, a top-up is subject to a statutory right of withdrawal in accordance with the withdrawal notice (see clause 2 and computebox.de/legal/withdrawal/form); upon withdrawal, credit not yet spent is refunded to the original payment method, while the right of withdrawal expires insofar as the credit has already been spent. No contractual reversal right for individual top-ups is granted beyond this.
8.4 No Expiry of Paid-in Credit
Paid-in Wallet credit does not expire. It remains valid without time limit and is consumed by the use of the Provider's services.
8.5 No Partial Payout during the Ongoing Business Relationship
During the ongoing business relationship, there is no claim to a partial payout of the credit. The credit is consumed by services. The Customer may close their customer account at any time, provided no active services are still running; clause 8.6 applies to the credit.
8.6 Full Payout upon Account Closure
Upon closure of the customer account, the remaining paid-in credit is paid out in full. The payout is made exclusively to the original payment method (refund of a card payment to the same card, of a PayPal payment to the same PayPal account, of a bank transfer to the originating bank account). If the original payment method is no longer available, the payout is made, after an identity check, to a payment account held in the Customer's name. There is no payout to third parties and no cash payout.
8.7 Bonus Credit
Bonus credit (e.g., from referrals or coupons) is tracked separately. It can be used for all services of the Provider and is always consumed before paid-in credit. Bonus credit is not paid out, not even upon account closure, and is not transferable. Bonus credit expires 12 months after it was granted. It is not consideration and does not constitute a taxable service.
8.8 Abuse Reservation
Payouts may be suspended only where there is a concrete suspicion of fraudulent conduct (e.g., chargeback, use of stolen payment credentials), and only until the matter is clarified within a reasonable period of generally no more than 14 days. There is no blanket right to refuse payouts.
8.9 Chargeback Consequence
If a top-up is reversed via the payment service provider (chargeback), the corresponding credit is re-debited; the Wallet balance may thereby become negative. The Provider is entitled to suspend the customer account until the balance is settled.
8.10 No E-Money
The Wallet balance does not constitute e-money within the meaning of the Payment Services Supervision Act (ZAG) and is not subject to the licensing requirement under ZAG, as it is exclusively used to pay for services from the Provider.
9. Liability and Warranty
9.1 Limitation of Liability
The Provider is liable to the Customer in cases of contractual and non-contractual liability for intent and gross negligence without limitation according to the statutory provisions. In the case of simple negligence, the Provider is liable, subject to stricter statutory liability, only for damages resulting from the breach of an essential contractual obligation (cardinal obligation). Essential contractual obligations are those the fulfillment of which enables the proper execution of the contract in the first place and on the compliance with which the Customer may rely. In this case, the Provider's liability is limited in amount to the contractually typical foreseeable damage. Any further liability for simple negligence is excluded.
9.2 Exceptions to the Limitation of Liability
The limitations of liability mentioned in clause 9.1 do not apply to damages resulting from injury to life, body, or health, in case of fraudulent concealment of a defect, in case of assumption of a guarantee or procurement risk, as well as in cases of mandatory statutory liability (such as under the Product Liability Act).
9.3 Data Loss
Subject to clauses 9.1 and 9.2, the Provider's liability for the loss of Customer data is limited to the typical restoration effort that would have arisen if the Customer had properly and regularly backed up their data in accordance with clause 4.5. Under clause 4.5, the Customer is responsible for making their own backup copies of their data at appropriate intervals. This clause does not entail a complete exclusion of liability for simple negligence; liability under clauses 9.1 and 9.2 remains.
9.4 Software and Third-Party Damages
Subject to clauses 9.1 and 9.2, the Provider is not liable for damages caused by software, scripts, or other processes initiated by the Customer on the server, nor for actions of third parties over which the Provider has no influence (e.g., external attacks such as hacking attempts or malware, disruptions of parts of the Internet outside the Provider's network, or other circumstances for which the Provider is not responsible). The Provider does not guarantee that the Customer's software or applications will function without errors on the rented server. Liability under clauses 9.1 and 9.2 remains unaffected in all cases.
9.5 Customer Data Protection Violations
The Customer is obliged to process the data stored on the server in such a way that no data protection violations occur. In particular, the Customer is prohibited from processing personal data of third parties without possessing the legal basis required for this. For this purpose, the Provider makes available a standardized data processing agreement pursuant to Art. 28 GDPR, which the Customer can conclude in the customer area. Where the Customer processes personal data on the server on behalf of others, the Customer must conclude it before the processing begins.
9.6 Availability and Voluntary Service Credit
The Provider guarantees the contractual provision of the services described in clause 3. The Customer must immediately report any defects or disruptions to the Provider (fault report) so that the Provider has the opportunity for subsequent performance (rectification or replacement). If the restoration of the contractual service is not successful within a reasonable period, the Customer may appropriately reduce the compensation or, in case of serious defects, terminate the contract extraordinarily. In all other respects, the statutory provisions apply, in particular §§ 327 et seq. BGB for consumers.
The committed minimum availability is 99% per calendar month, unless the service description states a different value. This availability commitment applies as standard to all server services; a separate designation as "including an SLA" is not required.
Where the committed minimum availability is undershot, the Provider grants, on a voluntary basis, a service credit. The basis of calculation is the pro-rata monthly amount, i.e., the portion of the price paid for the fixed term that is attributable to the affected month. The availability measured in the respective calendar month is decisive. The service credit is:
- for availability below 99.5% in the month: 10% of the monthly share,
- for availability below 99.0% in the month: 25% of the monthly share,
- for availability below 95.0% in the month: 50% of the monthly share,
- for availability below 90.0% in the month: 100% of the monthly share.
Times of planned maintenance announced in good time, as well as times of force majeure or circumstances beyond the Provider's control, are not taken into account when calculating availability. This service credit is a voluntary benefit of the Provider. It does not limit or replace the Customer's statutory claims; in particular, reduction, termination, and claims for damages under clauses 9.1 and 9.2 remain unaffected. A service credit actually granted is set off against any concurrent reduction or damages claim.
10. Data Protection and GDPR Compliance
The Provider processes personal data of the Customer (e.g., name, address, email address, payment data) in compliance with the relevant data protection laws, in particular the EU General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). The processing of the data required for contract initiation and contract performance is based on Art. 6(1)(b) GDPR (performance of a contract), to the extent of statutory obligations on Art. 6(1)(c) GDPR (legal obligation), and within the scope of legitimate interests (e.g., abuse prevention, IT security) on Art. 6(1)(f) GDPR. Consent by the Customer is not required for this processing and is not obtained through these T&Cs.
Data will be transferred to third parties only to the extent necessary for the fulfillment of the contract or due to a legal obligation. For example, it may be necessary to transmit data to the payment service provider Stripe (or to the respective bank, credit card provider, or PayPal) for payment processing.
The Provider may use the email address provided by the Customer upon conclusion of a contract to send direct marketing for its own similar services pursuant to § 7 (3) UWG. The Customer may object to this use at any time, without incurring costs other than the transmission costs at base rates; the Customer is informed of the right to object upon collection and in every marketing email. Any advertising communication beyond this takes place only on the basis of the Customer's express consent, which may be withdrawn at any time (Art. 6(1)(a) GDPR, § 7 (2) UWG).
More detailed information on data processing, including the legal bases, storage periods, and data subject rights, is contained in the privacy policy, which is available on the website. These T&Cs do not replace the privacy policy.
11. Changes to the T&Cs
The Provider may change these T&Cs with effect for the future in accordance with the following paragraphs. The Provider will inform the Customer of planned changes at least 4 weeks before the intended entry into force in text form (e.g., by email), identifying the affected provisions.
11.1 Changes with Deemed Consent
The Customer's consent is deemed to have been given if they do not object to the changes in text form within 4 weeks of receipt of the amendment notification, but exclusively for the following changes:
- changes that are necessary to adapt the T&Cs to an amended legal situation, to supreme-court case law, or to a binding regulatory or judicial order, and
- changes that are exclusively beneficial to the Customer, or that are neutral in substance (e.g., editorial adjustments, changed contact details, process or form descriptions without effect on the Customer's rights and obligations) and affect neither the main performance obligations nor the pricing structure. In case of doubt, a change is not deemed neutral.
The Provider will expressly inform the Customer in the amendment notification about the right of objection, the deadline, and the consequences of not objecting.
11.2 Changes Only with Express Consent
Changes to the main performance obligations (in particular the nature and scope of the service owed) as well as changes to the fees and prices always require the Customer's express consent. A deemed consent under clause 11.1 does not apply to such changes. If no agreement is reached, the previous contract remains in place; the ordinary and extraordinary right of termination remains unaffected.
11.3 Special Right of Termination upon Objection
If the Customer objects to a change under clause 11.1, the change is deemed not agreed and the contract is continued on the previous terms. In this case, both parties are entitled to terminate the contract with a notice period of 7 days to the end of the current paid term or, in the case of an indefinite continuation under clause 6.4, with a notice period of 7 days. The Provider will point out this special right of termination in the amendment notification.
12. Switching Providers and Data Portability (EU Data Act)
The hosting service provided by the Provider is a data processing service within the meaning of Regulation (EU) 2023/2854 (Data Act), which applies since 12 September 2025. This clause 12 implements the requirements of Chapter VI of the Data Act.
12.1 Right to Switch Providers
The Customer has the right to switch to another provider of a data processing service, to port their data and digital assets to their own (on-premises) ICT infrastructure, or to terminate the service. To this end, the Provider removes, within what is technically feasible, commercial, technical, contractual, and organizational obstacles.
12.2 Switching Request and Deadlines
The Customer may initiate the switch at any time. No notice period applies to initiating the switching process; the process starts immediately upon receipt of the switching request. The Provider thereby deliberately waives the maximum notice period of 2 months permitted under Art. 25(2)(d) of Regulation (EU) 2023/2854. The Customer sends the switching request in text form to [email protected].
Upon receipt of the switching request, the transition period within the meaning of Art. 25(2)(a) of Regulation (EU) 2023/2854 begins, during which the Provider supports the switch. The transition period is a maximum of 30 calendar days.
If the switch is not technically feasible within the transition period, the Provider notifies the Customer within 14 working days of the switching request, stating the reasons, and specifies an alternative transition period of at most 7 months (Art. 25(4) of Regulation (EU) 2023/2854). During this alternative transition period, the Provider assures full continuity of the service.
The Customer may extend the transition period once by a period that the Customer considers more appropriate for its own purposes (Art. 25(5) of Regulation (EU) 2023/2854).
The contract is deemed terminated upon successful completion of the switching process; if the Customer requests only the erasure of its data, the contract ends upon completion of the erasure (Art. 25(2)(c) of Regulation (EU) 2023/2854). The switch is deemed successfully completed when the Provider has fully provided the exportable data and the Customer does not object within 14 days.
12.3 Data Export and Formats
The Provider makes available to the Customer their exportable data in a structured, commonly used, and machine-readable format. The export is provided as a complete vzdump image, so that all customer content is included.
Exportable data and digital assets are, exhaustively (Art. 25(2)(e) and (f) of Regulation (EU) 2023/2854):
- the virtual disk images of the server (disk images) in qcow2 or raw format, bundled as a vzdump archive,
- the associated configuration and metadata of the virtual machine (e.g., resource allocation, network and storage configuration), to the extent contained in the vzdump archive,
- all content and data stored by the Customer on the server that forms part of the image.
Exempt from provision are, exhaustively and exclusively:
- provider-internal operational and billing data (e.g., internal logs and the Provider's invoicing and payment-transaction data), and
- the Provider's trade secrets.
This exception does not entitle the Provider to filter or withhold customer content; all content of the Customer within the meaning of Art. 2 No. 38 of Regulation (EU) 2023/2854 is exported with the complete vzdump image. In addition, the Customer has full root access throughout the entire contract term and can copy their data out themselves at any time. Export in OVF/OVA format is not offered; snapshots are not an export format.
12.4 Cooperation and Data Retrieval after End of Contract
The Provider cooperates in good faith with the switch and provides the necessary information. A data or switching request triggers the retrieval and archive period regardless of how the contract ended (expiry without renewal, ordinary or extraordinary termination, termination due to payment default). After expiry of the transition period, the Provider grants free access to retrieve the exportable data for at least 30 calendar days; deletion after the end of the contract is governed by the procedure in clause 7.5, whereby the data is converted for this purpose into an archive that is held for 30 days. Retrieval and handover of the data are not conditional on the settlement of outstanding claims; the Provider has no right of retention over the Customer's data. Any payment claims of the Provider remain unaffected by this and are to be pursued separately.
12.5 Costs of Switching
The switch is free of charge for the Customer. No switching charges of any kind are levied. Regular usage fees for the services actually used until termination remain unaffected by this.
12.6 Pre-contractual Information
Before concluding the contract, the Provider makes available to the Customer the information required under the Data Act on switching providers. This information is additionally available publicly at computebox.de/legal/switching and includes in particular:
- the procedure for switching requests and porting the service,
- the available export format (vzdump archive with virtual disk images in qcow2 or raw) as well as the continuous root access during the contract term,
- the applicable periods (no period for initiation, transition period of a maximum of 30 calendar days, retrieval period of at least 30 calendar days after the end of the contract),
- the fact that switching is free of charge,
- known restrictions (no OVF/OVA; snapshots are not an export format; no provider-internal operational and billing data), and
- the contact point for switching requests ([email protected]).
13. Jurisdiction, Applicable Law and Final Provisions
The law of the Federal Republic of Germany applies to the exclusion of the UN Convention on Contracts for the International Sale of Goods (CISG). If the Customer is a consumer, this choice of law applies only to the extent that it does not undermine any mandatory consumer protection provisions of the country in which the Customer has their habitual residence.
If the Customer is a merchant within the meaning of the Commercial Code, a legal entity under public law, or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from or in connection with this contract is the registered office of the Provider. In all other cases, the statutory provisions apply for the place of jurisdiction.
The place of performance for all services under this contract is, as far as legally permissible, the registered office of the Provider.
Contract language. The contract may be concluded in German or in English. The ordering process and communication may take place in English. These T&Cs are provided in a German and an English version. In case of discrepancies or differences of interpretation between the two versions, the version in the language in which the respective contract was concluded prevails: for a contract concluded in German, the German version; for a contract concluded in English, the English version.
The Customer is entitled to rights of retention or the defense of non-performance of contract only insofar as their counterclaim arises from the same contractual relationship. Offsetting against claims of the Provider is only permissible for the Customer with undisputed or legally established counterclaims. This does not apply to counterclaims that are ready for decision or to counterclaims that are synallagmatically linked to the main claim.
There are no side agreements to this contract. Changes or additions to this contract and these T&Cs require text form (e.g., by email). This also applies to a change of the text form requirement itself.
Should a provision of these T&Cs be or become wholly or partially invalid or unenforceable, this shall not affect the validity of the remaining provisions. In place of the invalid or unenforceable provision, the statutory rule shall apply.
Version: August 3, 2026