WebDisk VM Service Terms
Version: 1.0 · Effective from: 2026-07-25
The Polish version is the legally binding version. This English translation is provided for convenience only.
These terms (hereinafter: "VM Terms") set out the conditions for the provision of the WebDisk VM service (hereinafter: "Service") and constitute a supplement to the WebDisk Cloud Computing IaaS Service Terms (hereinafter: "IaaS Terms"). In matters not governed by the VM Terms, the provisions of the IaaS Terms apply. In the event of a conflict, the VM Terms prevail.
Provider: Mazura sp. z o.o. with its registered office in Ząbki, ul. Baśniowa 1C/2, 05-091 Ząbki, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under number KRS 0000971559, NIP 1251732787, owner of the WebDisk brand (hereinafter: "We" / "WebDisk" / "Provider").
Contact: office@webdisk.io, tel. +48 502 049 866, correspondence address: ul. Baśniowa 1C/2, 05-091 Ząbki.
Customer: a natural person, legal person or organisational unit without legal personality that has purchased a virtual server under the Service (hereinafter: "Customer" / "You").
1. Scope of the service
1.1. WebDisk VM is an infrastructure as a service (IaaS) offering: under the subscription we make available to the Customer a virtual server (VPS) with allocated resources (virtual processor, operating memory, disk space), network connectivity, a public IP address and full administrative (root) access via the SSH protocol.
1.2. Within the Service we provide:
- the virtualisation layer and the allocated resources of the virtual server,
- network connectivity together with at least one public IP address,
- at the Customer's request — a PTR record (reverse DNS) for the allocated address,
- snapshots of the server in accordance with the parameters of the plan (section 4),
- a Customer panel enabling management of the server lifecycle (launch, restart, restore from an image, change of resources, snapshots),
- a choice of operating system template when the server is launched.
1.3. The Provider does not manage the operating system or the software inside the virtual server. Once the server has been launched, full and exclusive control over the operating system, the software, the configuration and the data is exercised by the Customer (section 3). The Provider does not install updates inside the Customer's system and does not obtain access to its content in the course of ongoing operations.
1.4. The parameters of the plan (server resources, disk space, any transfer limits), prices, and the frequency and retention of snapshots are indicated in the Customer panel and on the vm.webdisk.io website. The parameters in force at the time of purchase are binding for the given subscription period.
2. Customer account and access to the server
2.1. The WebDisk account serves to manage the subscription and the lifecycle of the virtual server. The account is created upon purchase of the subscription.
2.2. Administrative (root) access. The access credentials to the server — the SSH key or the password established upon launch — remain at the exclusive disposal of the Customer. The Customer bears full responsibility for their confidentiality, for the secure configuration of access (in particular for the use of SSH keys, the operating system firewall and multi-factor authentication), and also for all actions performed using that access.
2.3. User accounts in the server's operating system are created and managed exclusively by the Customer. The Provider is not a party to any contract with those users.
2.4. Should a breach of the security of the server or of the account be suspected, the Customer shall immediately secure the instance and notify the Provider at security@webdisk.io or via the ticket function in the panel.
3. Allocation of responsibility
3.1. The Provider's scope of responsibility covers: the hardware, the virtualisation layer, the physical network and connectivity, the allocation of resources, the availability of the platform, the taking of snapshots as an infrastructure function, and the physical security of the data centre.
3.2. The Customer's scope of responsibility covers: the server's operating system and its updates, all software and services run on the server, the configuration (including the firewall, accounts and permissions, system hardening), all data stored and processed on the server, backups of that data, and also the compliance of the workloads run with the provisions of law — including with personal data protection provisions in relation to the data of third parties.
3.3. No access to the Customer's data. In the course of ongoing operations the Provider does not log in to the Customer's operating system and does not obtain insight into the data processed inside the server. Activities at the infrastructure layer (disk images, snapshots) are carried out solely to the extent necessary to provide the Service and in order to comply with lawful requests from public authorities (section 7).
3.4. Data encryption. The data carriers of the virtual servers and the snapshots are not currently encrypted at rest on the Provider's side. A Customer processing data requiring encryption at rest should apply encryption on its own, at the operating system or application level.
4. Snapshots
4.1. Rotating snapshots. Within the Service, snapshots of the server are taken with the frequency and retention indicated in the Customer panel, as well as snapshots taken by the Customer independently. A snapshot restores the state of the server as at the moment it was taken.
4.2. A snapshot is not a backup of the data. Snapshots serve to restore the instance after a failure or an erroneous configuration change and do not replace an independent backup of the Customer's data maintained outside the Service infrastructure. In accordance with clause 3.2, the Customer is responsible for backups of the data. A backup service may be introduced as an additional service; until it is made available, only rotating snapshots apply.
4.3. Recommendation of the Customer's own backup. We recommend maintaining your own backup of critical data outside the Service, in accordance with the 3-2-1 rule (three copies, two media, one off the primary site).
5. Network, IP addressing and PTR records
5.1. IP address. We assign at least one public IP address to the server for the duration of the subscription. The address remains under the Provider's administration and, after the Service ends, returns to the address pool; the Customer is not entitled to transfer the address.
5.2. PTR record. At the Customer's request we set a PTR record for the allocated address. The Customer is responsible for ensuring that the content of the record and the manner in which the address is used do not infringe the provisions of law or the rules set out in section 7.
5.3. Address reputation. The Customer is responsible for the reputation of the allocated IP address resulting from the traffic generated by its workloads, including for any entries of the address on blocklists. In the event of abuse affecting other Customers or the reputation of the Provider's network, the measures set out in section 8 apply.
6. Infrastructure, data location and availability
6.1. Data location. Customers' virtual servers, their disks and snapshots are maintained on the Provider's infrastructure located in the territory of the Republic of Poland (European Union). The Provider does not transfer this data outside the European Economic Area. Data transfers carried out by workloads run by the Customer remain outside the Provider's control and the Customer is responsible for them.
6.2. Redundancy. The infrastructure layer maintains hardware redundancy, including redundancy of the power supply, of network connectivity and of the storage layer for the disks of the virtual servers. Redundancy does not replace the Customer's own backup (clause 4.3).
6.3. Availability (SLA). The availability parameters of the Service, the rules for reporting failures, scheduled maintenance and compensation are set out in the SLA Terms document, which forms an integral part of the contract. In particular:
- the guaranteed availability of access to the services via the Internet is 99.95% on an annual basis, and for electrical power and air conditioning — 100% on an annual basis,
- scheduled maintenance is announced at least 12 hours in advance, takes place between 23:00 and 6:00 and does not last longer than 6 hours on any single occasion; in situations of heightened risk of failure the Provider may order scheduled maintenance disregarding these conditions, informing the Customer within the shortest possible time,
- if the availability parameters are not met, the Customer is entitled to compensation in the form of an extension of the subscription period by 1 month after 24 hours of unavailability and for each subsequent commenced 12 hours of interruption, granted following a positive determination of the complaint.
6.4. SLA exclusions. The availability parameters cover solely the infrastructure layer indicated in clause 3.1. They do not cover unavailability resulting from scheduled maintenance, force majeure, failure of equipment not forming part of the Provider's infrastructure, and also from improper use, configuration, software or workloads of the Customer. Detailed exclusions are set out in the SLA Terms document.
7. Acceptable use policy for the Service
7.1. It is prohibited to use the Service for:
a) storing, sharing or processing child sexual abuse material — we report every such case to the competent authorities without prior notification of the Customer;
b) infringing copyright and related rights, including the distribution of warez content;
c) distributing malicious software, software encrypting data for the purpose of extorting a ransom, and exploits; the prohibition does not cover lawful, authorised security testing conducted solely against the Customer's own resources;
d) phishing, fraud and identity theft attempts;
e) distributing content inciting hatred or violence and content of a terrorist nature;
f) publishing the personal data of third parties without a legal basis;
g) processing data subject to special regulatory regimes (in particular medical data subject to United States regulations or full payment card numbers within the meaning of the PCI-DSS standard) without prior written arrangements with the Provider;
h) sending unsolicited commercial communications (spam) and maintaining open mail relays or open proxy servers;
i) conducting network attacks — including port scanning, denial-of-service attacks, brute-force password attacks and attempts to gain unauthorised access to third-party systems — from the Customer's server or through it;
j) excessive use of resources in a manner degrading the operation of other instances on shared hardware, beyond the limits resulting from the plan;
k) cryptocurrency mining, where the description of the plan prohibits it, and running other workloads excluded in the description of the plan;
l) providing services consisting in the deliberate concealment of activity infringing the law.
7.2. Procedure upon suspicion of a violation. Where a violation is identified — on the basis of a report, automatic detection or notification from an authority — the measures set out in section 8 apply. The Customer receives a notification describing the violation and a deadline to respond, which as a rule is 7 days, and in the event of an ongoing attack — immediately after the measure has been applied. In the case of violations indicated in clause 7.1 letter a, the block takes place immediately and without notice, and the matter is referred to the competent authorities.
7.3. Abuse reports. We accept abuse reports concerning the Service at abuse@webdisk.io.
7.4. Requests from authorities. The Provider complies with lawful requests from public authorities. We inform the Customer about a request if the law permits it.
8. Suspension of the Service and termination of the contract
8.1. Suspension and traffic limitation. In the event of an ongoing abuse, an attack originating from the Customer's server, or a threat to the Provider's infrastructure or to other Customers, the Provider may suspend the server or limit its network traffic immediately, informing the Customer within the shortest possible time. The measure is applied proportionately to the threat and is maintained until its cause has been removed. The Customer has the right to appeal against the decision on suspension; where the Customer demonstrates that there were no grounds for applying the measure, or where the cause has been removed, the Provider shall immediately resume the provision of the Service.
8.2. Termination by the Customer. The Customer may at any time:
- cancel the subscription in the panel — the server then operates until the end of the paid subscription period, after which it enters a state of scheduled decommissioning,
- request the immediate decommissioning of the server, without waiting for the end of the subscription period.
8.3. Grace period and deletion. After decommissioning has been chosen, the server and its snapshots are retained for 30 days, during which period the Customer may withdraw the decision. After that period, the server together with all its snapshots is permanently deleted, and the allocated IP address returns to the address pool.
8.4. Downloading the data is the Customer's obligation. The Provider has no access to the data located inside the server and does not export it on the Customer's behalf. Before the server is decommissioned, the Customer downloads its data independently. At the Customer's request, and insofar as this is technically possible, the Provider may make a disk image or a snapshot available for download.
8.5. Retention after decommissioning. Following the permanent deletion of the server we retain solely:
- the infrastructure operations log stripped of data from inside the server (timestamp, type of operation, status) — for 12 months, for security purposes and for complying with requests from authorities,
- accounting documentation (invoices, amounts, tax identification data) — for the period required by accounting and tax regulations, as a rule 5 years counted from the end of the financial year.
8.6. Termination by the Provider. The Provider may terminate the contract:
- with immediate effect — in the event of a violation of section 7, retaining the possibility of downloading the data for 14 days, unless a request from an authority precludes this,
- upon 30 days' notice — in the event of payment arrears exceeding 60 days from the payment due date of the first unpaid invoice,
- upon 90 days' notice — in the event of the Service being withdrawn from the offering.
9. Protection of personal data
9.1. The rules for processing the Customer's personal data (account data, billing data, technical data) are set out in the WebDisk VM Privacy Policy.
9.2. The allocation of roles between the parties in relation to the personal data processed by the Customer inside the virtual server is set out in the document Personal Data Processing Rules for the WebDisk VM Service.
10. Processors
In providing the Service, the Provider uses the following categories of processors — in relation to the data for which the Provider is the controller:
| Entity | Purpose | Location |
|---|---|---|
| The Provider's compute and storage infrastructure | Launching and maintaining virtual servers, storing disks and snapshots | Poland (EU) |
| Stripe Payments Europe Ltd. | Card payment handling | Ireland (EU); a transfer to the USA is possible on the basis of standard contractual clauses |
| Email operator | Sending transactional messages | EU |
We give 30 days' advance notice of changes to the list.
11. Reporting security incidents
11.1. The Customer shall immediately inform the Provider of a breach of the security of its server or account (in particular of a takeover of administrative access or of suspicious network traffic) at security@webdisk.io or via the ticket function in the panel.
11.2. In the event of a personal data breach on the Provider's side, concerning data for which the Provider is the controller, we notify the President of the Personal Data Protection Office (UODO) within 72 hours of becoming aware of the breach (Article 33 GDPR), and the persons affected by the breach — without undue delay, if the breach may result in a high risk to their rights or freedoms (Article 34 GDPR).
11.3. Breaches concerning data processed by the Customer inside the virtual server are detected, assessed and reported by the Customer as the controller of that data. Should it obtain information about such a breach, the Provider shall immediately notify the Customer.
12. Liability
12.1. The Provider provides the Service within the scope indicated in clause 3.1 with due professional diligence and bears liability for damage caused by non-performance or improper performance of the contract.
12.2. The Provider is not liable for:
- the operating system, software, configuration and data remaining within the Customer's scope of responsibility (clause 3.2),
- the consequences of actions performed using the Customer's administrative access, including the disclosure of access credentials to unauthorised persons,
- loss of data resulting from the Customer's failure to maintain its own backup, despite the recommendation in clause 4.3,
- unavailability resulting from the circumstances indicated in clause 6.4,
- the faulty operation of software installed by the Customer and the consequences of its not being updated.
12.3. The Provider's liability in damages covers actual loss, excluding lost profits, and is limited to the amount of the subscription fees paid by the Customer in the 12-month period preceding the event giving rise to the damage.
12.4. The limitations of liability set out in clauses 12.2 and 12.3 do not apply to damage caused intentionally, nor to the extent that mandatory provisions of law, in particular consumer protection provisions, do not permit their application.
13. Provisions concerning consumers
13.1. The provisions of this section apply to a Customer who is a consumer within the meaning of Article 22¹ of the Polish Civil Code, and also — to the extent indicated in Article 7aa of the Polish Act of 30 May 2014 on Consumer Rights — to a natural person concluding a contract directly related to that person's business activity, where it follows from the content of the contract that it is not of a professional nature for that person. In the event of a conflict with the remaining provisions of the Terms, the provisions of this section prevail.
13.2. Right of withdrawal from the contract. A consumer who has concluded a distance contract may withdraw from it within 14 days without giving a reason and without incurring costs, subject to clause 13.4. The period runs from the day on which the contract is concluded. Sending the statement before the deadline expires is sufficient to meet the deadline.
13.3. Manner of withdrawal. The statement of withdrawal may be submitted in any form, in particular by email to office@webdisk.io or in writing to: Mazura sp. z o.o., ul. Baśniowa 1C/2, 05-091 Ząbki. The consumer may use the model withdrawal form constituting Annex 2 to the Act on Consumer Rights, however this is not obligatory. The Provider promptly confirms receipt of the statement.
13.4. Provision of the service before the expiry of the withdrawal period. If the consumer requested that the provision of the Service begin before the expiry of the period for withdrawal from the contract, and subsequently withdrew from the contract, the consumer is obliged to pay for the performance rendered up to the moment of withdrawal — in an amount proportionate to the scope of the performance rendered up to that moment, taking into account the agreed price. The right of withdrawal does not apply if the Provider has fully performed the Service with the express and prior consent of the consumer, who was informed before the performance began of the loss of the right of withdrawal and acknowledged this.
13.5. Refund of payments. In the event of withdrawal, the Provider shall refund to the consumer the payments received — subject to clause 13.4 — promptly, no later than within 14 days of the day on which the statement is received, using the same means of payment, unless the consumer has expressly agreed to another method of refund which does not entail costs for the consumer.
13.6. Conformity of the service with the contract. The Service, being a digital service within the meaning of the Act on Consumer Rights, is subject to the provisions of Chapter 5b of that Act concerning the trader's liability for the lack of conformity of a digital service with the contract, including the right to demand that the service be brought into conformity with the contract and, in the cases specified in the Act — the right to a price reduction or to withdrawal from the contract.
13.7. Out-of-court means of dispute resolution. The consumer may make use of out-of-court means of handling complaints and pursuing claims, and in particular may:
- turn to the district (municipal) consumer ombudsman or to a social organisation whose statutory tasks include consumer protection,
- turn to the voivodeship inspector of the Trade Inspection with a request to initiate out-of-court dispute resolution proceedings or to conduct mediation,
- turn to the permanent arbitration court operating at the voivodeship inspector of the Trade Inspection.
Information on the out-of-court resolution of consumer disputes is available on the website of the Office of Competition and Consumer Protection: uokik.gov.pl. Use of these procedures is voluntary and requires the consent of both parties.
14. Complaints
14.1. In the event of non-performance or improper performance of the Service, the Customer has the right to submit a complaint.
14.2. A complaint may be submitted:
- by email to office@webdisk.io,
- in writing to: Mazura sp. z o.o., ul. Baśniowa 1C/2, 05-091 Ząbki,
- via the ticket function in the Customer panel.
14.3. The complaint should contain data enabling the identification of and contact with the Customer, an indication of the Service complained about, and a description of the circumstances justifying the complaint.
14.4. The Provider examines the complaint and provides a response within 14 days of the day of its receipt, to the address indicated by the Customer. The response contains a statement of reasons.
15. Final provisions
15.1. Amendments to the Terms. The Provider may amend the Terms for important reasons, in particular in the event of a change in the law, a change in the scope or manner of providing the Service, or a change in technical conditions. We inform about amendments by email 30 days in advance. A Customer who does not accept the amendments may terminate the contract before the date on which the amendments enter into force; until the end of the paid subscription period, the existing wording of the Terms applies to that Customer.
15.2. Language versions. In the event of discrepancies between the Polish and the English version of the Terms, the Polish version is binding.
15.3. Governing law. The governing law is Polish law. The choice of Polish law does not deprive the consumer of the protection resulting from mandatory provisions of the law of the country of the consumer's habitual residence.
15.4. Jurisdiction of the court. Disputes arising from the contract are settled by the common court having local jurisdiction over the Provider's registered office. The provision of the preceding sentence does not apply to a Customer who is a consumer — in such a case jurisdiction is determined in accordance with the general provisions.
15.5. Invalidity of provisions. If any provision of the Terms proves to be invalid or ineffective, the remaining provisions remain in force.
15.6. Contact. Questions concerning the Terms: legal@webdisk.io. Personal data protection matters: iod@webdisk.io. Technical reports: support@webdisk.io. Abuse reports: abuse@webdisk.io. Complaints and other matters: office@webdisk.io.
Mazura sp. z o.o. · WebDisk VM · Service Terms · version 1.0 · effective from 2026-07-25
Version 1.0 · EN