GENERAL TERMS AND CONDITIONS OF SERVICE
Version: 1.0 | Effective date: 14.09.2026
TABLE OF CONTENTS
- Definitions and interpretation
- Identification of the Provider and subject matter of the contract
- Conclusion of the distance contract and acceptance of the Terms
- Client Account, identity verification and fraud prevention
- Orders, prices, currency and invoicing
- Payment methods and payment processors
- Non-payment, suspension and termination of services
- Chargebacks and payment disputes
- Refunds and the consumer right of withdrawal
- Term, renewal and cancellation of services
- Acceptable Use Policy (AUP)
- Client obligations and responsibilities
- Provider obligations, service level (SLA) and support
- Backups and responsibility for data
- Upstream providers and subcontractors
- Protection of personal data (GDPR)
- Status as intermediary service provider (DSA) and notice procedure
- Intellectual property
- Confidentiality
- Limitation of liability and warranties
- Indemnification
- Force majeure
- Changes to the Terms and to the services
- Termination of the contract
- Consumer rights, ANPC and alternative dispute resolution
- Governing law and jurisdiction
- Communications, notices and contract language
- Final provisions
Annexes (integral part of this contract):
- Annex A: Specific conditions for Shared and Reseller Web Hosting (cPanel/WHM, CloudLinux)
- Annex B: Specific conditions for Managed WordPress (WP Squared) and Website as a Service (WaaS)
- Annex C: Specific conditions for Virtual Private Servers (VPS, NAT VPS) on Virtualizor and Proxmox
- Annex D: Specific conditions for Game Server Hosting (Pterodactyl / WISP.gg)
- Annex E: Specific conditions for Dedicated Servers (OVHcloud resale)
- Annex F: Domain Names (reference to the Domain Registration Agreement)
- Annex G: Service Level Agreement (SLA) and credits
- Annex H: Data Processing Agreement (DPA) and list of sub-processors
- Annex I: Withdrawal form for consumers
1. DEFINITIONS AND INTERPRETATION
1.1. In this document, the terms below have the following meanings:
- "Provider", "CrockyHost", "we", "us": S.C. CROCKY S.R.L., a Romanian legal entity identified in article 2.1, operating under the trade names "CrockyHost" and "Crocky".
- "Client", "you": any natural person, legal entity, entity without legal personality or public institution that has created an Account and/or ordered a Service.
- "Consumer": any natural person acting for purposes outside their trade, business, craft or profession, within the meaning of art. 2 point 2 of Romanian GEO no. 34/2014 and Law no. 296/2004.
- "Business Client": any Client who is not a Consumer, including legal entities, sole traders, individual enterprises, NGOs, public institutions and authorities.
- "Account": the client account created on the Provider's management platform (WHMCS), through which the Client orders, manages and pays for the Services.
- "Services": all services offered by the Provider, including without limitation: shared web hosting, reseller hosting, managed WordPress, Website as a Service (WaaS), virtual private servers (VPS and NAT VPS), game server hosting, dedicated servers, domain name registration and management, SSL certificates, web design, maintenance, SEO and related services.
- "Dedicated Servers": physical servers made available to the Client on a rental basis, supplied by the Provider through the resale of OVHcloud services, governed by Annex E.
- "Standard Services": all Services other than Dedicated Servers.
- "Platforms": the software systems through which the Services are delivered, including WHMCS, cPanel/WHM, CloudLinux, WP Squared, Pterodactyl, WISP.gg, Virtualizor, Proxmox VE and any successor thereof.
- "Upstream Provider": any third party from which the Provider rents physical infrastructure, network or data centre space, including OVHcloud, Contabo and Scaleway (Online SAS).
- "Client Content": any data, files, databases, programs, text, images, audio-visual material, e-mail addresses, messages and any other information uploaded, stored, transmitted or generated by the Client or by the Client's end users through the Services.
- "Order": the Client's request to purchase one or more Services, submitted through the Account.
- "Invoice": the fiscal document issued by the Provider in accordance with Romanian tax law, including through the national RO e-Factura system.
- "Due Date": the date by which the Invoice must be paid, as stated on the Invoice.
- "Acceptable Use Policy" or "AUP": the separate document published at https://crocky.host/legal/acceptable-use-policy, referred to in Section 11.
- "SLA": the guaranteed service level, as set out in Annex G.
- "Terms": this document, together with all Annexes, the Privacy Policy, the Cookie Policy and any particular conditions accepted at the time of the Order.
1.2. Section headings are for reference only and do not affect interpretation. The singular includes the plural and vice versa. "Including" means "including, without limitation".
1.3. In case of conflict between the provisions of this document, the following order of precedence applies: (a) particular conditions expressly accepted at the time of the Order; (b) the Annex specific to the type of Service; (c) the main body of the Terms; (d) the Privacy Policy. Mandatory provisions of consumer protection law prevail in all cases over any contrary clause.
2. IDENTIFICATION OF THE PROVIDER AND SUBJECT MATTER OF THE CONTRACT
2.1. The Services are provided by S.C. CROCKY S.R.L., a limited liability company registered in Romania, operating under the trade names "CrockyHost" and "Crocky", with the following identification details:
- Tax identification number (CUI): RO50515950
- Trade Register number: J2024020698007
- Registered office: Str. Drăgaica nr. 5, sat Balasan, mun. Băilești, jud. Dolj, postal code 205101, Romania
- Contact e-mail: contact@crocky.host
- Data protection e-mail: gdpr@crocky.host
- Abuse reporting e-mail: abuse@crocky.host
- Telephone: +40 750 265 179
- Website: https://crocky.host
- Main activity: NACE code 6310 - Data processing, hosting and related activities.
2.2. This document governs the legal relationship between the Provider and the Client with respect to all Services, regardless of the channel through which they were ordered (website, Account, e-mail, written offer, separately signed contract or public procurement procedure).
2.3. For Clients that are public institutions or authorities (B2G), this document applies in addition to the public procurement contract, the tender specifications and the accepted technical and financial proposal, which prevail in case of conflict.
2.4. The Provider acts as a hosting service provider within the meaning of art. 6 of Regulation (EU) 2022/2065 (Digital Services Act) and as an information society service provider within the meaning of Romanian Law no. 365/2002 on electronic commerce.
3. CONCLUSION OF THE DISTANCE CONTRACT AND ACCEPTANCE OF THE TERMS
3.1. The contract is concluded at a distance, by electronic means, in accordance with Law no. 365/2002 and GEO no. 34/2014. The technical steps for concluding the contract are: (a) creating the Account; (b) configuring the Order in the shopping cart; (c) reviewing the Order summary and correcting any input errors; (d) express acceptance of these Terms by ticking the dedicated checkbox; (e) confirming the Order; (f) receiving the order confirmation by e-mail.
3.2. The contract is deemed concluded when the Provider sends the confirmation of acceptance of the Order. A mere acknowledgement of receipt of the Order does not constitute acceptance. The Provider reserves the right to refuse any Order, in particular in the cases set out in Section 4.
3.3. By creating an Account or placing an Order, the Client declares that: (a) they have read, understood and fully accept these Terms; (b) they are at least 18 years old and have full legal capacity; (c) in the case of legal entities, they are legally authorised to bind the entity concerned; (d) the information provided is true, complete and up to date.
3.4. These Terms are made available to the Client on a durable medium (a permanently accessible web page and a downloadable version) before the contract is concluded. The Client may save and reproduce the Terms. The Provider archives the version of the Terms accepted at the date of each Order and may provide it to the Client on request.
3.5. The language of the contract is Romanian. Any translations, including this English version, are provided for information purposes; in case of discrepancy, the Romanian version prevails.
4. CLIENT ACCOUNT, IDENTITY VERIFICATION AND FRAUD PREVENTION
4.1. Creating the Account. Each Client must hold their own Account. The Client undertakes to provide accurate identification details (name/company name, address, tax number where applicable, e-mail, telephone) and to update them within 15 days of any change. Inaccurate billing details leading to incorrectly issued Invoices are the sole responsibility of the Client.
4.2. Account security. The Client is solely responsible for keeping confidential the login credentials of the Account, of the control panels (cPanel, WHM, Virtualizor, Proxmox, Pterodactyl/WISP, WP Squared) and of any other credentials. Any action carried out through the Account is presumed to have been carried out by the Client. The Provider recommends enabling two-factor authentication (2FA) and using unique, complex passwords. The Client shall notify the Provider immediately upon becoming aware of any unauthorised access.
4.3. SMS notifications. The Provider may send the Client authentication codes (2FA), security alerts and operational notifications by SMS, using the providers Web2SMS and Vonage. The telephone number provided must be valid and held by the Client. SMS messages are not used for marketing purposes without separate prior consent.
4.4. Fraud screening. All Orders and payments are subject to automated risk analysis through the FraudLabs Pro service, which assesses, among other things: IP address, geolocation, consistency between billing details and payment instrument details, use of anonymising networks (proxy, VPN, Tor), e-mail address, transaction history. This processing is carried out on the basis of the Provider's legitimate interest in preventing fraud (art. 6(1)(f) GDPR) and is described in the Privacy Policy.
4.5. Manual verification. Where an Order is flagged as high risk, the Provider may: (a) hold the Order for manual review; (b) request supporting documents from the Client (copy of identity document with non-essential data masked, proof of address, certificate of incorporation, confirmation of ownership of the payment instrument); (c) request payment by another method; (d) refuse the Order and refund the amount received in full. Verification documents are kept strictly for the time needed for verification and no longer than 30 days after its completion, unless the law requires their retention.
4.6. Automated decisions. An Order is not refused solely on the basis of the automated risk score without prior human review. The Client has the right to contest such a decision and to express their point of view, in accordance with art. 22 GDPR, by contacting the Provider at gdpr@crocky.host.
4.7. Multiple accounts, resale, transfer. The Client may not open multiple Accounts for the purpose of circumventing suspensions, restrictions or promotional offers. Transfer of an Account or a Service to a third party requires the Provider's written consent, after verification of the identity of the new holder.
4.8. Resellers. Reselling the Services or their resources is permitted on Reseller Services, VPS and Dedicated Servers (including through the Client's own virtualisation or containerisation), without prior consent, and is prohibited on other Services without the Provider's written consent, in accordance with the AUP. Clients who resell the Services to their own customers (including through WHMreseller, WHM accounts, virtual machines or containers) remain fully liable to the Provider for compliance with these Terms by their end users, undertake to impose on them conditions at least as restrictive as the AUP and to respond to abuse requests within the deadlines set by the Provider. The Provider has no direct contractual relationship with the reseller's customers.
5. ORDERS, PRICES, CURRENCY AND INVOICING
5.1. Prices. Service prices are those displayed on the website or in the written offer at the time of the Order. Prices are displayed with the express mention "excluding VAT" or "including VAT". For Consumers, the total price, including VAT and all applicable taxes, is displayed before the Order is confirmed.
5.2. VAT. The Provider is VAT registered. The standard VAT rate applicable in Romania is 21%. For Business Clients in other EU member states holding a valid VAT number (verifiable in VIES), the reverse charge mechanism applies. For Clients outside the EU, VAT is not applied, except where required by law. The Provider is not liable for the Client's incorrect declaration of their tax status.
5.3. Currency. When creating the Account, the Client chooses the billing currency from those available (EUR or RON). The chosen currency applies to all Services in the Account and may only be changed subsequently by written request to the Provider, who may require a new Account to be opened. Prices in RON may be updated periodically to reflect the exchange rate; changes apply from the next billing period, in accordance with Section 23.
5.4. Invoicing. Invoices are issued electronically and communicated through the Account and by e-mail. The Provider submits Invoices through the national RO e-Factura system, in accordance with the legal obligations applicable to B2B, B2C and B2G relationships. The Client expressly accepts electronic invoicing. The Provider does not issue pro forma invoices; the order directly generates the Invoice, and activation of the Service is conditional on its payment.
5.5. Advance billing. All Services are billed in advance for the chosen billing period (monthly, quarterly, semi-annually, annually, biennially or triennially, as available). The renewal Invoice is issued 14 days before the renewal date for Standard Services, and in accordance with the OVHcloud policy reflected in Annex E for Dedicated Servers.
5.6. Additional services and fees. Additional services (extra resources, IP addresses, software licences, assisted migrations, paid technical interventions, backup restores, reactivations) are invoiced separately, at the displayed or agreed rates.
5.7. Pricing errors. In case of an obvious price display error (for example a zero price or one manifestly disproportionate to market value), the Provider may cancel the Order and refund the amount paid, informing the Client within 5 business days.
5.8. Promotions. Promotional offers apply only to the first billing period unless otherwise stated, and renewal is at the standard displayed price. Promotional codes cannot be combined and cannot be applied retroactively.
6. PAYMENT METHODS AND PAYMENT PROCESSORS
6.1. Payment may be made by the following methods, depending on availability and Account currency:
- Bank card (Visa, Mastercard and others), processed through Stripe and/or Mollie;
- SEPA Direct Debit, PayPal, Klarna, paysafecard and other local methods, processed through Mollie;
- Bank transfer to the accounts stated on the Invoice (Libra Bank for private Clients; Treasury Băilești for public institutions), with mandatory reference to the Invoice number;
- Account credit, topped up in advance.
6.2. The Provider does not store full bank card details. Payment data are processed directly by PCI-DSS certified payment processors in accordance with their own privacy policies. The Provider stores only tokenised identifiers and the last four digits of the card.
6.3. Recurring payment. By saving a payment method and enabling automatic payment, the Client authorises the Provider to automatically charge renewal Invoices on the due date. The Client may disable automatic payment at any time from the Account, before the next Invoice is issued. For SEPA Direct Debit, the Client benefits from the refund rights provided by the SEPA scheme and Regulation (EU) no. 260/2012.
6.4. Partial or incorrect payments. Payments without an Invoice number or with an incorrect amount may delay activation or renewal of the Service. Bank transfer fees are borne by the Client. Exchange rate differences resulting from cross-border payments are not borne by the Provider.
6.5. Date of payment. Payment is deemed made on the date the payment processor confirms receipt or on the date the Provider's bank account is credited.
6.6. Klarna and other deferred payment methods. Use of "buy now, pay later" methods is subject to the conditions and creditworthiness assessment of the respective provider. Non-payment to the deferred payment provider does not affect the Client's relationship with the Provider, but may result in that method being refused for future Orders.
6.7. paysafecard. paysafecard payments are final and cannot be refunded in cash; any refunds are made exclusively as Account credit, unless the law requires otherwise for Consumers.
7. NON-PAYMENT, SUSPENSION AND TERMINATION OF SERVICES
7.1. Due date. Invoices are due on the date stated on the Invoice. The Service remains active after the due date only during the grace period described below.
7.2. Standard Services (all Services other than Dedicated Servers). If the Invoice is not paid by the Due Date:
- (a) on the 7th day after the Due Date, the Service is automatically suspended. Suspension means public access to the Service is stopped (website, e-mail, server, control panel), with temporary retention of data;
- (b) on the 17th day after the Due Date, the Service is automatically terminated, and all related data are permanently and irreversibly deleted from the Provider's production servers and backups, with no possibility of recovery.
7.3. The Client understands and expressly accepts that the deletion under art. 7.2(b) is final, that the Provider retains no copy of the data after that moment and that any subsequent recovery request cannot technically be honoured. The Provider sends automatic e-mail notifications before the due date, on the due date, upon suspension and before termination; failure to receive them due to an incorrect e-mail address, spam filters or failure to check the mailbox does not release the Client from liability.
7.4. Reactivation after suspension. A suspended Service may be reactivated by paying the outstanding Invoice in full and any reactivation fee displayed in the Account, before the 17th day after the due date. Reactivation is automatic upon payment confirmation.
7.5. Dedicated Servers (OVHcloud resale). Dedicated Servers are subject to the payment, suspension, termination and data deletion terms applied by the Upstream Provider OVHcloud, which the Provider mirrors identically in its relationship with the Client, in accordance with Annex E. The Client understands that the Provider cannot extend the deadlines imposed by OVHcloud and that deletion of data from a Dedicated Server terminated by OVHcloud is final.
7.6. Domain names. Non-payment of a domain name renewal Invoice leads to its expiry on the expiry date set by the registry, with the consequences described in the Domain Registration Agreement (grace period, redemption period with additional costs, release for registration by third parties).
7.7. Recovery costs. The Provider does not charge late payment penalties. Where recovery of outstanding amounts from Business Clients requires enforcement proceedings or legal action, the Provider reserves the right to claim recovery costs and statutory interest, in accordance with Law no. 72/2013 and general law.
7.8. Suspension of the entire Account. The Provider may suspend all Services in the Account where the Account has Invoices overdue by more than 30 days, an unresolved chargeback or repeated AUP violations.
7.9. Client data after termination. Except in the situation under art. 7.2(b), upon termination of a Service for any other reason, the Client may request, before the termination date, export of their data in the Platform's native format (cPanel archive, disk image, game server archive), within reasonable technical limits. The Provider may charge a fee for export assistance.
8. CHARGEBACKS AND PAYMENT DISPUTES
8.1. The Client undertakes to contact the Provider before initiating a payment dispute (chargeback, PayPal dispute, SEPA refund) with their bank or payment processor, to allow amicable resolution of any complaint.
8.2. Initiating a payment dispute for a Service actually provided and conforming, without first contacting the Provider, is considered an unjustified chargeback and has the following consequences:
- (a) immediate suspension of the entire Account and all Services, until the dispute is resolved;
- (b) an administrative fee of [25] EUR (or the RON equivalent) per dispute, representing the costs imposed on the Provider by payment processors and handling costs;
- (c) the obligation to pay the disputed amount, the administrative fee and any bank charges before the Account is reactivated;
- (d) in case of a second unjustified chargeback, the Provider may permanently terminate all Services in the Account and refuse future Orders.
8.3. If the dispute is not resolved in the Provider's favour or the amount is not paid within 17 days of suspension, the suspended Services are terminated in accordance with art. 7.2(b), including permanent deletion of data.
8.4. This section does not affect the rights of Consumers to dispute unauthorised or erroneous payments under Law no. 209/2019 on payment services, nor rights arising from the SEPA scheme. The Provider will present the payment processor with evidence of provision of the Service (access logs, order confirmations, correspondence, acceptance of the Terms).
9. REFUNDS AND THE CONSUMER RIGHT OF WITHDRAWAL
9.1. Consumer right of withdrawal (GEO no. 34/2014)
9.1.1. The Consumer has the right to withdraw from the contract, without giving any reason, within 14 calendar days from the date of conclusion of the contract, by sending an unequivocal statement (e-mail to contact@crocky.host, ticket from the Account or the form in Annex I).
9.1.2. Services started during the withdrawal period. Since hosting Services are usually activated immediately after payment confirmation, the Consumer expressly requests, by ticking the dedicated checkbox at the time of the Order, that provision of the Service begin before the withdrawal period expires. If the right of withdrawal is exercised, the Consumer shall pay the Provider an amount proportionate to the Service provided up to the time of communicating the withdrawal, calculated on the basis of the total price of the billing period, and the difference shall be refunded.
9.1.3. Exceptions to the right of withdrawal. Under art. 16 of GEO no. 34/2014, the right of withdrawal does not apply to:
- (a) domain names: registration of a domain name is a personalised service, fully and immediately executed at the moment of registration in the domain registry, irreversible and non-refundable by the registry. By placing the Order, the Consumer expressly requests immediate registration and confirms that they are aware that they lose the right of withdrawal once the service is fully performed. Amounts paid for the registration, renewal or transfer of domain names are not refundable under any circumstances;
- (b) software licences and SSL certificates issued in the Client's name, which are fully executed at the time of issue;
- (c) Services fully performed before the withdrawal is exercised, with the Consumer's prior express consent;
- (d) web design, development and custom configuration services carried out according to the Client's specifications, after execution has begun with the Client's express consent;
- (e) Dedicated Servers, to the extent the Upstream Provider applies a non-refundable setup fee or a minimum commitment, communicated to the Consumer before the Order.
9.1.4. Refund. Amounts due to the Consumer are refunded within 14 days of receipt of the withdrawal statement, using the same payment method used for the initial transaction, unless the Consumer expressly agrees to another method (for example Account credit) or the initial method does not allow refunds (paysafecard, in which case art. 6.7 applies).
9.2. Refunds for Business Clients
9.2.1. Business Clients do not benefit from a right of withdrawal. Amounts paid for activated Services are not refundable, except for: (a) SLA credits under Annex G; (b) cases where the Provider unilaterally terminates a Service without fault of the Client, in which case the unused period is refunded pro rata; (c) cases where the Provider decides, on a case-by-case basis, to grant Account credit for commercial reasons.
9.2.2. Amounts paid for domain names, software licences, SSL certificates, setup fees and custom services are not refundable under any circumstances.
9.3. Common provisions
9.3.1. No refunds are granted for Services suspended or terminated due to AUP violations or non-payment.
9.3.2. Account credit is non-transferable, does not bear interest and is not converted into cash except where required by law.
10. TERM, RENEWAL AND CANCELLATION OF SERVICES
10.1. Each Service is contracted for the billing period chosen at the time of the Order and renews automatically for successive equal periods, unless the Client requests cancellation in accordance with art. 10.3.
10.2. Renewal notice. The Provider notifies the Client by e-mail at least 14 days before the renewal date of Standard Services and at least 30 days before the expiry of domain names, indicating the renewal price.
10.3. Cancellation by the Client. The Client may request cancellation of any Service at any time, without notice, from the Account, choosing between: (a) immediate cancellation, in which case the Service is terminated and the data deleted within 72 hours, without refund of the remaining period (except for Consumer rights under Section 9); (b) cancellation at the end of the current billing period, in which case the Service remains active until the renewal date and no renewal Invoice is issued. For Dedicated Servers, Annex E applies.
10.4. Mere non-payment of the renewal Invoice does not constitute cancellation and does not release the Client from paying for the grace period during which the Service remained active; however, for Consumers, the Provider will not claim payment for Services not used after the paid period expires, provided the Service was not accessed or used during the grace period.
10.5. Domain names cannot be cancelled before expiry; cancelling automatic renewal leads to expiry of the domain on the date set out in the Domain Registration Agreement.
11. ACCEPTABLE USE POLICY (AUP)
11.1. Use of the Services is subject to the Acceptable Use Policy (AUP), a separate document permanently published at https://crocky.host/legal/acceptable-use-policy, which forms an integral part of these Terms and which the Client accepts together with them. The AUP sets out prohibited content and activities, resource usage limits, e-mail and spam rules, specific rules for IRC, IP addresses and application security, as well as the consequences of violation.
11.2. The Client may use the Services exclusively for lawful purposes, in accordance with the laws of Romania, the European Union, the state where the server is located and the Client's state of residence, as well as the terms of the Upstream Providers. The Client is solely responsible for compliance with the AUP by their end users.
11.3. Depending on the severity of the AUP violation, the Provider may, at its sole discretion: (a) send a warning with a remediation deadline; (b) remove or block access to the content concerned; (c) temporarily suspend the Service or the Account; (d) terminate the Service or the Account without notice and without refund, in case of serious or repeated violations as defined in the AUP; (e) charge the investigation and delisting fees provided in the AUP; (f) notify the competent authorities and provide them with the requested data as required by law; (g) retain the necessary data as evidence.
11.4. Upstream Providers apply their own abuse policies. Suspension of a Service by an Upstream Provider following an abuse report is binding on the Provider, who is not liable for its consequences if the report is founded. Anyone may report abuse to abuse@crocky.host, in accordance with Section 17.
11.5. The AUP may be updated by the Provider with notice to the Client in accordance with Section 23; changes required by law, by Upstream Providers or necessary for security may take effect immediately.
12. CLIENT OBLIGATIONS AND RESPONSIBILITIES
12.1. The Client is solely responsible for the Client Content, for its lawfulness, for obtaining all necessary licences, authorisations and consents and for respecting the rights of third parties.
12.2. The Client is the data controller for the personal data of the end users of their websites, applications and servers and is responsible for: publishing their own privacy and cookie policies, obtaining consent where required, responding to data subject requests and notifying security breaches to the supervisory authority. The Provider acts as processor, in accordance with Annex H.
12.3. The Client undertakes to keep their own backups of the Client Content, independently of the Provider's backups, in accordance with Section 14.
12.4. The Client undertakes to respond within 24 hours at most (or within the deadline stated in the notice, if shorter for reasons of urgency) to the Provider's requests concerning abuse, security incidents or verifications.
12.5. The Client undertakes not to use the Provider's trademark, name or logos without written consent, except for the factual mention "hosted by CrockyHost".
12.6. A Client operating regulated activities (e-commerce, financial services, healthcare, gambling, payment processing) is solely responsible for obtaining the necessary authorisations and for sector compliance (PCI-DSS, ANAF authorisations, ONJN, etc.).
13. PROVIDER OBLIGATIONS, SERVICE LEVEL (SLA) AND SUPPORT
13.1. The Provider undertakes to use all reasonable efforts to ensure the Services operate within the parameters described in the accepted offer and the Annexes, with the availability level set out in Annex G.
13.2. Technical support. Support is provided through the ticket system in the Account and by e-mail, in Romanian and English, for issues relating to the Provider's infrastructure and Platforms. Support does not include: code development, debugging the Client's applications, operating system administration on unmanaged Services (VPS, Dedicated Servers), configuration of third-party plugins or training, unless these services are contracted separately. Indicative response times are set out in Annex G.
13.3. Scheduled maintenance. The Provider may carry out maintenance work involving temporary unavailability of the Services, notifying the Client at least 48 hours in advance, by e-mail or status page. Emergency maintenance (critical security patches, hardware failures) may be carried out without notice. Scheduled maintenance windows are not considered downtime for SLA purposes.
13.4. Migrations. The Provider may migrate Services between servers or Upstream Providers for technical, commercial or security reasons, with prior notice of at least 7 days for Standard Services (except in emergencies) and with minimal disruption. A change of IP address following migration does not constitute non-performance of the contract.
13.5. Security. The Provider implements reasonable technical and organisational measures (firewall, Imunify360, network-level DDoS protection through Upstream Providers, CloudLinux isolation, Platform security updates, monitoring), without however guaranteeing the absolute impossibility of security incidents.
13.6. Changes to Platforms. The Provider may update, replace or discontinue any of the Platforms, provided that functionality equivalent in substance is maintained.
14. BACKUPS AND RESPONSIBILITY FOR DATA
14.1. Shared Hosting, Reseller, WaaS and Managed WordPress. The Provider performs, as a courtesy, through JetBackup: (a) daily backups, retaining the last 7 copies on the Provider's storage infrastructure; (b) a weekly backup, transferred to an external server in another location, retaining the last [4] weekly copies. The Client can restore available backups themselves from cPanel.
14.2. Backups are not guaranteed. The backups under art. 14.1 are provided "as is", without any warranty as to their existence, integrity, completeness or restorability. The Provider is not liable for data loss resulting from the absence, corruption or impossibility of restoring a backup. Backups are excluded for accounts exceeding the size or inode limits set out in Annex A.
14.3. VPS, NAT VPS, Game Servers and Dedicated Servers. These Services do not include backups, unless a backup or snapshot option is contracted separately. Snapshots taken by the Client through Virtualizor, Proxmox or Pterodactyl are stored on the same infrastructure and do not constitute a backup in the proper sense.
14.4. Client responsibility. Regardless of the Service, the Client remains solely responsible for making and keeping their own backups on systems independent of the Provider's infrastructure. The Client accepts that this obligation is essential and that any claim relating to data loss is limited in accordance with Section 20.
14.5. Data deletion. Data are permanently deleted: (a) 17 days after the due date, in accordance with art. 7.2; (b) within 72 hours of immediate cancellation by the Client; (c) on the date of termination of the contract for any other reason, except for backups existing at that date, which are overwritten according to the retention cycle under art. 14.1 (at most 7 days for daily copies and [28] days for weekly copies). Billing and identification data are retained in accordance with the Privacy Policy and tax law.
15. UPSTREAM PROVIDERS AND SUBCONTRACTORS
15.1. The Provider delivers the Services using physical, network and data centre infrastructure rented from Upstream Providers, currently: OVHcloud (OVH SAS, France, with data centres in France, Poland, Germany and other locations), Contabo (Contabo GmbH, Germany) and Scaleway / Online SAS (France). The updated list of Upstream Providers and locations is available in the Privacy Policy.
15.2. The Client accepts that: (a) the Services are subject to the terms of use, abuse policies and technical limitations of the relevant Upstream Provider; (b) the Provider does not control the Upstream Providers' infrastructure and is not liable for their outages, failures or decisions, beyond the credits provided in Annex G; (c) the Provider may change the Upstream Provider in accordance with art. 13.4.
15.3. The Provider also uses third-party providers for payments (Stripe, Mollie), fraud prevention (FraudLabs Pro), SMS communications (Web2SMS, Vonage), domain name registration (NETIM) and software licences (cPanel/WebPros, CloudLinux, JetBackup, LiteSpeed, Softaculous, WHMCS). These providers are listed as sub-processors in Annex H, to the extent they process personal data.
15.4. The Provider may subcontract the provision of certain web design, development or support services to external collaborators, remaining fully liable to the Client.
16. PROTECTION OF PERSONAL DATA (GDPR)
16.1. The processing of the Client's personal data (identification, contact, billing, authentication, access logs, correspondence) is carried out in accordance with Regulation (EU) 2016/679 (GDPR), Law no. 190/2018 and Law no. 506/2004 and is described in detail in the Privacy Policy, available at https://crocky.host/legal/privacy-policy, which forms an integral part of these Terms.
16.2. Roles. For the Client's own data, the Provider is the controller. For Client Content that includes personal data of third parties (visitors, users, customers of the Client), the Provider is a processor and processes the data exclusively on the Client's instructions, in accordance with the Data Processing Agreement in Annex H, which is concluded automatically upon acceptance of these Terms.
16.3. Legal bases. The Client's data are processed on the basis of: performance of the contract (art. 6(1)(b) GDPR); legal obligations, in particular tax and accounting (point (c)); the Provider's legitimate interest in preventing fraud, ensuring network security and defending its rights (point (f)); consent, for marketing communications (point (a)).
16.4. Data location. Client Content is stored exclusively in data centres located in the European Union. Certain providers of auxiliary services (fraud prevention, SMS, payment processing) may process data outside the European Economic Area, in which case the transfer is carried out on the basis of the standard contractual clauses adopted by the European Commission or an adequacy decision, in accordance with Annex H.
16.5. Data subject rights. The Client has the right of access, rectification, erasure, restriction, portability, objection and the right not to be subject to a decision based solely on automated processing, as well as the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP, B-dul G-ral. Gheorghe Magheru nr. 28-30, Bucharest, www.dataprotection.ro). Requests are sent to gdpr@crocky.host and are answered within 30 days.
16.6. Retention period. Billing data are retained in accordance with the statutory archiving periods for financial and accounting documents. Service access logs are retained for no more than 12 months. Account data are retained for the duration of the contractual relationship and for no more than 3 years after its termination, for the defence of legal claims, unless the law requires otherwise.
16.7. Security incidents. The Provider notifies the Client, as controller, without undue delay, of any security breach affecting Client Content, in accordance with Annex H.
16.8. Cookies. The use of cookies on the crocky.host website and in the Account is described in the Cookie Policy.
17. STATUS AS INTERMEDIARY SERVICE PROVIDER (DSA) AND NOTICE PROCEDURE
17.1. The Provider provides hosting services within the meaning of art. 6 of Regulation (EU) 2022/2065 and benefits from the liability exemption provided therein for information stored at the request of Clients, as long as it has no actual knowledge of its illegal nature and acts expeditiously upon obtaining such knowledge.
17.2. The Provider does not proactively monitor Client Content and has no general monitoring obligation.
17.3. Single point of contact. For authorities, natural persons and organisations: abuse@crocky.host (accepted languages: Romanian, English).
17.4. Notice and action. Any person may notify the Provider of content they consider illegal, indicating: (a) the reasons why the content is considered illegal; (b) the exact URL or location of the content; (c) the notifier's name and e-mail address (except for offences against the person, where these may be omitted); (d) a good faith statement regarding the accuracy of the information. The Provider acknowledges receipt, reviews the notice diligently and objectively and informs the notifier and the Client of the decision taken and of the means of redress.
17.5. Appeals. A Client whose content has been restricted may appeal the decision within 6 months, at abuse@crocky.host, presenting their arguments. The Provider re-examines the decision under human supervision.
17.6. Requests from authorities. The Provider complies with orders from competent judicial and administrative authorities to act against illegal content or to provide information, as required by law, and informs the Client to the extent permitted by law.
17.7. Copyright notices. Rights holders may submit notices to abuse@crocky.host, following the procedure in art. 17.4. The Provider may remove or block access to the notified content until the situation is clarified and may forward the notifier's contact details to the Client, as permitted by law.
18. INTELLECTUAL PROPERTY
18.1. All rights in the Platforms, software, documentation, trademarks, logos, the crocky.host website and any materials created by the Provider (except for expressly contracted custom deliverables) belong to the Provider or its licensors. The Client receives only a non-exclusive, non-transferable and revocable right of use for the duration of the contract.
18.2. Client Content remains the property of the Client. The Client grants the Provider a limited, non-exclusive licence to store, copy, transmit and display the Client Content exclusively to the extent necessary to provide the Services (including backups, caching, migrations).
18.3. Third-party software licences included in the Services (cPanel, CloudLinux, LiteSpeed, Softaculous, SitePad, Sitejet, WP Squared, WHMCS, Virtualizor and others) are subject to the licensing conditions of the respective vendors, which the Client accepts by use. Licences are tied to the Service and cannot be transferred or used outside the Provider's infrastructure.
18.4. Web design deliverables. For web design services contracted on a one-off payment basis, the economic rights in the final deliverable are transferred to the Client on the date of full payment of the price, except for open-source components, third-party themes and plugins and the Provider's generic reusable elements. For WaaS, Annex B applies.
18.5. The Provider may mention the Client and the project in its portfolio, unless the Client objects in writing.
19. CONFIDENTIALITY
19.1. Each party undertakes to keep confidential the non-public information of the other party that it becomes aware of in the performance of the contract, including technical, commercial and security data, passwords and configurations, and to use it exclusively for the purpose of performing the contract.
19.2. The following do not constitute breaches of confidentiality: disclosure required by law or by a competent authority; disclosure to Upstream Providers and sub-processors, to the extent necessary to provide the Services; information that has become public without fault of the party.
19.3. The confidentiality obligation survives for 3 years after termination of the contract.
20. LIMITATION OF LIABILITY AND WARRANTIES
20.1. Warranty. The Provider warrants that the Services will be provided with professional diligence, in accordance with the description in the offer and the Annexes. Except for the express warranties in these Terms and the mandatory statutory warranties applicable to Consumers (including conformity of digital content and services under GEO no. 141/2021), the Services are provided "as is" and "as available", and the Provider does not warrant that the Services will be uninterrupted, error-free or fit for any particular purpose of the Client.
20.2. Exclusions. To the extent permitted by law, the Provider is not liable for: (a) indirect damages, loss of profit, revenue, goodwill, opportunity, data (except where caused by the Provider's gross negligence), reputational damage; (b) damages caused by Client Content, applications installed by the Client or the Client's users; (c) damages caused by cyber attacks, DDoS or unauthorised access not attributable to gross negligence of the Provider; (d) outages caused by Upstream Providers, telecommunications networks, domain registries or payment processors; (e) the consequences of suspension or termination of Services under these Terms; (f) data loss resulting from the Client's failure to comply with the obligation under art. 14.4.
20.3. Cap. The Provider's total liability to a Business Client, on any grounds, for all claims aggregated in a contract year, may not exceed the total amount paid by the Client to the Provider for the Service in connection with which the damage arose, in the 12 months preceding the triggering event.
20.4. Consumers. Nothing in this section excludes or limits the Provider's liability for death or personal injury, for fraud or gross negligence, for non-conformity of digital services under GEO no. 141/2021 or for any other liability that cannot be limited by law towards Consumers.
20.5. Any claim by a Business Client must be notified in writing within 30 days of the date on which the Client became aware of the triggering event, failing which the claim is forfeited.
21. INDEMNIFICATION
21.1. The Client undertakes to indemnify and defend the Provider, its shareholders, directors, employees, collaborators and Upstream Providers against any claims, actions, fines, penalties, damages, costs and expenses (including reasonable legal fees) arising from: (a) the Client Content; (b) the Client's or its users' breach of these Terms, the AUP or the law; (c) infringement of third-party rights; (d) the Client's use of the Services; (e) penalties imposed on the Provider by authorities or Upstream Providers due to the Client's conduct.
21.2. For Consumers, the indemnification obligation is limited to damages caused with fault, under general law.
22. FORCE MAJEURE
22.1. Neither party is liable for non-performance of obligations caused by a force majeure event within the meaning of art. 1351 of the Romanian Civil Code, including: natural disasters, fire, floods, war, acts of terrorism, epidemics, general strikes, acts of authorities, major power or telecommunications network outages, large-scale cyber attacks against Upstream Providers, failures of submarine cables or transit networks.
22.2. The affected party notifies the other party within 5 days of the occurrence of the event and uses reasonable efforts to limit its effects. If the event lasts more than 60 days, either party may terminate the contract without compensation, with pro rata refund of amounts paid in advance for the period not provided.
22.3. Force majeure does not release the Client from payment obligations for Services actually provided.
23. CHANGES TO THE TERMS AND TO THE SERVICES
23.1. The Provider may amend these Terms, the Annexes and the prices, notifying the Client by e-mail and by display in the Account at least 30 days before the changes take effect. Changes required by law or necessary for security may take effect immediately.
23.2. If the changes are material and unfavourable to the Client, the Client may terminate the contract without penalty before the effective date, by written notice, with pro rata refund of amounts paid in advance for the period not provided (except for domain names, licences and non-refundable fees). Continued use of the Services after the effective date constitutes acceptance of the changes.
23.3. Price changes apply from the next billing period, never during a period already paid.
23.4. The current version of the Terms is permanently published at https://crocky.host/legal/terms-of-services, with the date of last update indicated and the version history available on request.
24. TERMINATION OF THE CONTRACT
24.1. The contract terminates: (a) by cancellation by the Client, in accordance with art. 10.3; (b) by non-payment, in accordance with Section 7; (c) by termination by the Provider for breach of the AUP or the Terms, in accordance with art. 11.3, without notice in case of serious breaches, or with 7 days' notice and a remediation period in other cases; (d) by unilateral termination by the Provider, with 30 days' notice and pro rata refund, where a type of Service is discontinued or cooperation with an Upstream Provider ends; (e) by mutual agreement; (f) by force majeure, in accordance with art. 22.2; (g) automatically, upon the opening of insolvency proceedings, dissolution or death of the Client, to the extent the Services cannot be transferred.
24.2. Upon termination, the Client loses access to the Services and the data are deleted in accordance with art. 14.5. Payment obligations arising before termination, as well as Sections 18, 19, 20, 21, 25 and 26, survive termination.
25. CONSUMER RIGHTS, ANPC AND ALTERNATIVE DISPUTE RESOLUTION
25.1. These Terms do not limit in any way the rights of Consumers under Romanian and European law, including GEO no. 34/2014 on consumer rights in contracts concluded with traders, Law no. 296/2004 on the Consumer Code, Law no. 193/2000 on unfair terms, Law no. 363/2007 on unfair commercial practices and GEO no. 141/2021 on contracts for the supply of digital content and digital services.
25.2. Complaints. Consumers may submit complaints directly to the Provider at contact@crocky.host or by ticket from the Account. The Provider acknowledges receipt within 2 business days at most and responds within 30 calendar days at most.
25.3. ANPC. Consumers may contact the Romanian National Authority for Consumer Protection (ANPC): - Head office: B-dul Aviatorilor nr. 72, sector 1, Bucharest - Consumer hotline: 021 9551 - Website: https://anpc.ro - Online complaints: https://reclamatii.anpc.ro
25.4. Alternative dispute resolution (ADR / SAL). In accordance with Romanian GO no. 38/2015, Consumers may refer disputes to the Alternative Dispute Resolution Directorate within ANPC: - Website: https://anpc.ro/ce-este-sal/ - Filing ADR requests: https://reclamatiisal.anpc.ro - E-mail: dsal@anpc.ro - Address: B-dul Aviatorilor nr. 72, sector 1, Bucharest
The Provider undertakes to participate in good faith in any ADR procedure initiated by a Consumer.
25.5. European ODR platform. The European Online Dispute Resolution (ODR) platform was discontinued by Regulation (EU) 2024/3228 with effect from 20 July 2025. Consumers in other EU member states may use the European Consumer Centres Network (ECC-Net, https://www.eccnet.eu) for assistance in cross-border disputes, as well as the ADR entities in their state of residence.
25.6. Recourse to the above procedures does not prevent the Consumer from bringing proceedings before the competent courts.
26. GOVERNING LAW AND JURISDICTION
26.1. These Terms are governed by Romanian law. For Consumers resident in another EU member state, the mandatory consumer protection provisions of their state of residence remain applicable, in accordance with art. 6 of Regulation (EC) no. 593/2008 (Rome I).
26.2. The parties shall seek amicable settlement of any dispute within 30 days of written notification thereof.
26.3. Business Clients. Disputes not settled amicably fall under the exclusive jurisdiction of the courts at the Provider's registered office, namely the Băilești Court of First Instance (Judecătoria Băilești) or, as applicable, the Dolj Tribunal.
26.4. Consumers. Disputes with Consumers fall under the jurisdiction of the courts determined in accordance with the Romanian Code of Civil Procedure, the Consumer having the right to also choose the court of their domicile, in accordance with art. 113 point 8 of the Code of Civil Procedure and Regulation (EU) no. 1215/2012.
26.5. Public institutions. Disputes with contracting authorities are subject to the special rules of public procurement law and of the procurement contract.
27. COMMUNICATIONS, NOTICES AND CONTRACT LANGUAGE
27.1. Contractual communications are made by e-mail to the Client's address in the Account and to contact@crocky.host for the Provider, by tickets from the Account and, for notices with major legal effects (termination, formal notice of default), by e-mail with read receipt or by registered letter to the Provider's registered office.
27.2. E-mail communications are deemed received on the date of transmission if sent during business hours (Monday to Friday, 09:00 to 18:00, Romanian time), or on the next business day.
27.3. The Client expressly agrees to receive operational, billing, security and Terms-change notifications by e-mail and SMS. These communications do not constitute commercial communications within the meaning of Law no. 506/2004.
27.4. Commercial communications (newsletter, offers) are sent only with the Client's prior consent, which may be withdrawn at any time via the unsubscribe link or from the Account.
28. FINAL PROVISIONS
28.1. These Terms, together with the Annexes, the Acceptable Use Policy, the Domain Registration Agreement, the Privacy Policy, the Cookie Policy and the particular conditions accepted at the time of the Order, constitute the entire agreement between the parties and supersede any prior understandings on the same subject matter.
28.2. The nullity or ineffectiveness of a clause does not affect the validity of the remaining clauses. The affected clause shall be replaced by a valid clause as close as possible in economic and legal effect.
28.3. Failure by the Provider to exercise a right does not constitute a waiver of that right.
28.4. The Client may not assign the contract without the Provider's written consent. The Provider may assign the contract to a business successor, with notice to the Client, without affecting the Client's rights.
28.5. The Provider may grant the Client, by written agreement, conditions derogating from these Terms; derogations are strictly construed.
28.6. The effective date of this version is the one indicated at the beginning of the document. Previous versions remain applicable to Orders placed under them until the effective date of the new version, in accordance with Section 23.
ANNEX A: SPECIFIC CONDITIONS FOR SHARED AND RESELLER WEB HOSTING (cPanel/WHM, CloudLinux)
A.1. Description. Shared Hosting consists of the allocation of a cPanel account on a server managed by the Provider and shared with other Clients, isolated through CloudLinux (LVE, CageFS). Reseller Hosting consists of the allocation of a WHM account with the ability to create cPanel sub-accounts for the Client's own customers.
A.2. Included components (depending on plan). cPanel/WHM, CloudLinux with PHP selector (versions from PHP 5.2 to PHP 8.5, noting that versions no longer officially supported are provided "as is", without security updates from PHP, and their use is at the Client's risk), Imunify360, Softaculous, SitePad and Sitejet Website Builder, in-house developed AI assistant, JetBackup, LiteSpeed Enterprise, support for Node.js, Python and Ruby applications through CloudLinux, network-level DDoS protection (Upstream Provider) and application-level protection (LiteSpeed WAF), free SSL certificates (Let's Encrypt/AutoSSL).
A.3. Resource limits. Each cPanel account is subject to the LVE limits set per plan and displayed in the accepted offer, including: CPU, physical memory (PMEM), entry processes (EP), number of processes (NPROC), I/O, IOPS, storage space, inode count (files and directories), monthly bandwidth. Current limits are visible in cPanel under "Resource Usage". Repeated exceeding of limits leads to slowdown or temporary interruption of the account's processes (503/508 errors), without liability of the Provider.
A.4. Default limits (unless the plan provides otherwise): - e-mail: maximum [100] messages per hour per cPanel account and [500] per day; maximum [50] recipients per message; - cron: minimum frequency of 5 minutes; cron tasks running longer than 5 minutes or consuming excessive resources may be disabled; - inodes: maximum [250,000] per account; accounts exceeding [100,000] inodes are excluded from backups; - maximum database size: [2 GB] per database; - background processes (daemons), game servers, bots, scanners, streaming services, proxies, chat servers: prohibited on Shared and Reseller Hosting.
A.5. "Unlimited" usage. Where a plan is described as having "unlimited" space or traffic, this means without a preset limit under normal use for hosting websites; it does not mean use as file storage, archive, external backup, distribution of large files (video, ISO, archives) or use disproportionate to the average of Clients on the same server. The Provider may require a reduction in consumption or an upgrade to a higher Service.
A.6. Content and files. Files that are not an integral part of the hosted websites (archives, local backups of other systems, large downloadable files unrelated to the website) may be deleted after 48 hours' notice.
A.7. E-mail. The included e-mail services are intended for the normal correspondence of the hosted websites and businesses, not for bulk e-mail marketing campaigns. For newsletters, the Client shall use a specialised service. The Provider may scan outgoing messages for spam and malware and may block suspicious messages. The Provider does not guarantee deliverability of messages to third-party servers.
A.8. Migration. The Provider offers free assistance with migrating a cPanel account from another provider, once upon activation, up to [10 GB] and only for compatible cPanel accounts. Migration does not include conversion from other control panels, fixing application errors or code changes.
A.9. Resellers. The reseller: (a) is liable for their own customers in accordance with art. 4.8; (b) may not allocate to sub-accounts cumulative resources exceeding those of the Reseller plan; (c) may use WHMreseller and their own branding; (d) may not create accounts with limits more permissive than those set out in art. A.4 without approval; (e) must provide their own customers with their contact details and their own privacy policy.
A.10. AI assistant. The integrated AI assistant is provided on an experimental basis, without warranties as to the accuracy of its output. The Client remains responsible for any change applied to the account on the basis of the assistant's suggestions. Commands executed through the assistant are logged.
A.11. Suspension and termination. Art. 7.2 applies (suspension 7 days, termination and permanent deletion 17 days after the due date).
ANNEX B: SPECIFIC CONDITIONS FOR MANAGED WORDPRESS (WP Squared) AND WEBSITE AS A SERVICE (WaaS)
B.1. Managed WordPress. The Service consists of hosting a WordPress website on the WP Squared platform, with automatic WordPress core updates, staging, caching and optimisations managed by the Provider. The Client retains administrative access to WordPress. Updates to third-party themes and plugins are applied automatically where possible, without any guarantee of compatibility; the Client is responsible for testing the website after updates and for the licences of their own premium plugins.
B.2. Prohibited plugins. The Provider may prohibit or disable plugins that affect performance or security (backup plugins duplicating the JetBackup function, competing cache plugins, plugins with known vulnerabilities, statistics plugins generating excessive database writes). The list is available in the Account.
B.3. WaaS (Website as a Service). WaaS consists of the Provider building a website for the Client and making it available on a monthly subscription basis, including hosting, maintenance, updates and, depending on the plan, a domain. Plans and their contents are those displayed on the website at the date of the Order.
B.4. Ownership under WaaS. During the subscription: (a) the Content provided by the Client (text, images, logo, data) remains the property of the Client; (b) the design, structure, configuration and elements developed by the Provider remain the property of the Provider and are licensed to the Client for the duration of the subscription; (c) the domain name included in the plan is registered in the Client's name, who is its holder.
B.5. Termination of WaaS. Upon termination of the subscription, the Client may request, before the termination date: (a) export of their own content (text, images, WordPress XML export); (b) transfer of the domain name to another registrar, in accordance with the Domain Registration Agreement; (c) [optional] buyout of the complete website, with transfer of rights in the design, at the price displayed in the Account or agreed in writing. In the absence of such a request, the website is deleted in accordance with art. 14.5.
B.6. Included changes. The WaaS subscription includes content changes within the limit provided by the plan (number of requests or hours per month). Structural changes, new pages beyond the plan limit and new functionality are invoiced separately.
B.7. Suspension and termination. Art. 7.2 applies (suspension 7 days, termination and permanent deletion 17 days after the due date).
ANNEX C: SPECIFIC CONDITIONS FOR VIRTUAL PRIVATE SERVERS (VPS, NAT VPS) ON VIRTUALIZOR AND PROXMOX
C.1. Description. A VPS consists of the allocation of a virtual machine or container (KVM, LXC or OpenVZ, as applicable) on a shared physical node, managed through Virtualizor or Proxmox VE, with resources (vCPU, RAM, storage, traffic) defined per plan.
C.2. Unmanaged service. VPS are provided on an unmanaged basis, unless management is expressly contracted. The Client has root/administrator access and is solely responsible for: installing, configuring, updating and securing the operating system and applications; firewall; backups; monitoring; AUP compliance. The Provider is responsible only for the operation of the physical node, the hypervisor, the network and the control panel.
C.3. Shared resources. vCPUs are shared (oversubscribed) with other virtual machines under reasonable use. Sustained CPU usage above [50]% on average over 24 hours, permanent intensive I/O or other patterns affecting the node may lead to throttling, notification and, if persistent, a requirement to upgrade to a higher Service or suspension.
C.4. Traffic. Included monthly traffic is that of the plan. On exceeding it, the port speed may be reduced until the end of the month or additional traffic may be invoiced at the displayed rate.
C.5. NAT VPS. NAT VPS are containers with a shared IPv4 address (NAT), with the following characteristics and limitations: (a) no dedicated IPv4 address; a limited range of forwarded TCP/UDP ports ([20] ports) is allocated and, where available, a dedicated IPv6 address; (b) ports 25, 465 and 587 (SMTP) are blocked for outgoing traffic; (c) reverse DNS is not available for IPv4; (d) resources are reduced and intended for personal use, development, testing or lightweight applications; (e) the following are prohibited: IRC, public game servers, proxies, VPN, torrents, seedboxes, crawlers, scanners.
C.6. Snapshots. Snapshots taken by the Client are stored on the same node, are not backups within the meaning of art. 14 and may be deleted upon reinstallation, migration or exceeding the allocated space.
C.7. Reinstallation. Reinstalling the operating system from the panel permanently deletes all data on the disk. The Client is solely responsible for this action.
C.8. Additional IP addresses. Allocated subject to availability, against payment, on the basis of a usage justification. IP addresses cannot be announced via BGP and cannot be transferred.
C.9. Kernel and virtualisation. For LXC/OpenVZ containers it is not possible to change the kernel, load modules, use Docker without support enabled by the Provider or run nested virtualisation. For KVM, nested virtualisation is not guaranteed.
C.10. Suspension and termination. Art. 7.2 applies (suspension 7 days, termination and permanent deletion 17 days after the due date).
ANNEX D: SPECIFIC CONDITIONS FOR GAME SERVER HOSTING (Pterodactyl / WISP.gg)
D.1. Description. The Service consists of the allocation of a container for a game server (for example Minecraft, Counter-Strike, Rust, ARK, FiveM, Valheim, Terraria and others, as per the offer), managed by the Client through the Pterodactyl or WISP.gg panel, with resources (CPU, RAM, storage, ports) defined per plan.
D.2. Resources. Allocated RAM is the container's hard limit; exceeding it results in automatic termination of the game server process (OOM kill). CPU is shared, with the per-container limit indicated in the plan. Storage includes server files, worlds, mods and plugins. The Provider is not liable for server instability caused by mods, plugins, configurations or an excessive number of players relative to allocated resources.
D.3. Game licences. The Client is responsible for complying with the licensing conditions of the hosted game (for example the Minecraft EULA, Steam terms, the FiveM licence, publishers' monetisation policies). Hosting pirated or illegally modified versions of games is prohibited.
D.4. Mods and third-party software. The Client installs mods and plugins at their own risk. Installing software unrelated to the game server (miners, proxies, bots, IRC servers, unsolicited web applications) is prohibited. Game-related web panels (for example Dynmap, BlueMap, statistics panels) are permitted within resource limits.
D.5. Ports and network. Each server receives the ports allocated in the panel. Additional ports are granted on request, subject to availability. DDoS protection is that of the Upstream Provider, at network level (L3/L4); the Provider does not guarantee protection against game-specific application-level attacks. Persistent attacks affecting the node may lead to temporary suspension of the targeted server, without liability.
D.6. Backups. The panel allows the Client to create backups, within the number and space provided by the plan, stored on the same infrastructure. Art. 14.3 and 14.4 apply.
D.7. Public listings and monetisation. Listing the server on public lists and monetisation (donations, ranks, cosmetics) are permitted in compliance with D.3 and applicable law (including the Client's tax obligations and the prohibition of unauthorised gambling, such as paid loot boxes where prohibited by law).
D.8. Suspension and termination. Art. 7.2 applies (suspension 7 days, termination and permanent deletion 17 days after the due date).
ANNEX E: SPECIFIC CONDITIONS FOR DEDICATED SERVERS (OVHcloud resale)
E.1. Description. Dedicated Servers are physical servers supplied by OVHcloud (OVH SAS and affiliated entities), which the Provider rents and resells to the Client. The Provider acts as a reseller; the Client has no direct contractual relationship with OVHcloud, but the Service is subject to OVHcloud's technical and contractual conditions, available at https://www.ovhcloud.com/en/terms-and-conditions/, which the Client accepts by placing the Order.
E.2. Payment, suspension and termination policy. By derogation from art. 7.2, Dedicated Servers are subject to the billing, suspension, termination and data deletion policy applied by OVHcloud at the relevant date, which the Provider mirrors identically in its relationship with the Client. For guidance, at the date of this version, this includes: monthly billing in advance, with a minimum commitment as per the offer; suspension of the server upon non-payment of the Invoice on the due date, within the period applied by OVHcloud; termination and permanent deletion of data upon expiry of the termination period applied by OVHcloud. The Provider communicates the exact deadlines to the Client in the accepted offer and in the Account and updates them whenever OVHcloud changes them.
E.3. Commitment and setup fees. Dedicated Servers may involve non-refundable setup fees and minimum commitment periods (1, 6, 12 or 24 months), as per the offer. Early termination by the Client does not entitle them to a refund of the remaining commitment period. For Consumers, art. 9.1.3(e) applies.
E.4. Delivery. The delivery time is that communicated by OVHcloud and may vary depending on hardware availability. OVHcloud delays are not attributable to the Provider; where the ordered configuration is unavailable, the Provider proposes an equivalent configuration or refunds the amount paid in full.
E.5. Unmanaged service. Dedicated Servers are provided unmanaged, with root/administrator access, KVM/IPMI and emergency console, subject to OVHcloud availability. Art. C.2 applies accordingly.
E.6. Hardware. Replacement of faulty components is carried out by OVHcloud, within its deadlines and conditions. The Provider does not guarantee retention of data on replaced disks. The Client is responsible for backups in accordance with art. 14.3 and 14.4.
E.7. SLA. The network and hardware availability level is that guaranteed by OVHcloud for the relevant server range; credits are granted to the Client within the limit of the credits actually obtained by the Provider from OVHcloud, in accordance with Annex G.
E.8. IP addresses, vRack, options. Additional IP addresses, vRack, backup storage, Windows/Plesk/cPanel licences and other OVHcloud options are available on request, at the Provider's rates, and are subject to OVHcloud conditions.
E.9. Abuse. Dedicated Servers are subject to the OVHcloud abuse policy. Suspension by OVHcloud following an abuse report (spam, DDoS, phishing, copyright) is binding on the Provider, who will forward to the Client the notice and the remediation deadline imposed by OVHcloud.
E.10. Server transfer. At the Client's request and with OVHcloud's agreement, the server may be transferred to the Client's own OVHcloud account, against an administrative fee and with termination of the relationship with the Provider.
ANNEX F: DOMAIN NAMES
F.1. Registration, renewal, transfer and management of domain names are subject to the Domain Registration Agreement, a separate document permanently published at https://crocky.host/legal/domain-registration-agreement, which forms an integral part of these Terms and which the Client accepts when placing any Order that includes a domain name.
F.2. The Provider acts as a reseller of the accredited registrar NETIM (NETIM SARL, France). Registration is also subject to NETIM's conditions, the policies of the registry of each extension (including ROTLD for .ro) and, for generic domains, ICANN policies.
F.3. Domain name registration, renewal, transfer and redemption fees are non-refundable under any circumstances, in accordance with art. 9.1.3(a) and 9.2.2. The consequences of non-payment of renewal (expiry, grace period, redemption period, release) are described in the Domain Registration Agreement.
ANNEX G: SERVICE LEVEL AGREEMENT (SLA) AND CREDITS
G.1. Guaranteed availability (monthly):
| Service | Network and infrastructure availability |
|---|---|
| Shared Hosting, Reseller, Managed WordPress, WaaS | 99.5% |
| VPS (Virtualizor, Proxmox) | 99.5% |
| NAT VPS | 99.0% (no credits) |
| Game Servers | 99.5% |
| Dedicated Servers | per OVHcloud SLA for the relevant range |
| Domain names (Provider DNS) | 99.9% |
G.2. Availability calculation. Availability is calculated monthly as the percentage of time during which the Service was accessible at the level of the Provider's network and infrastructure (physical node, hypervisor, web server, control panel), according to the Provider's monitoring system, which is the sole reference.
G.3. Exclusions. The following are not considered downtime: scheduled maintenance notified in accordance with art. 13.3; emergency maintenance of up to 4 hours per month; unavailability caused by the Client (applications, configurations, exceeding resources, abuse, suspension for non-payment or AUP); DDoS attacks against the Client or other Clients; force majeure; outages at the level of third-party networks, the Client's ISP, external DNS or registries; Upstream Provider issues not credited by that provider (for Dedicated Servers).
G.4. Credits. If the guaranteed availability is not met in a given month, the Client may request, within 15 days of the end of the month, an Account credit calculated as follows:
| Monthly availability | Credit as a share of the monthly value of the affected Service |
|---|---|
| below 99.5% and at least 99.0% | 10% |
| below 99.0% and at least 95.0% | 25% |
| below 95.0% | 50% |
The credit is the sole remedy for downtime, may not exceed 50% of the monthly value of the affected Service, is not converted into cash (except where required by law for Consumers) and is applied to future Invoices. For Dedicated Servers, the credit is limited to the credit actually obtained by the Provider from OVHcloud.
G.5. Support response times (indicative, not guaranteed):
| Priority | Description | First response |
|---|---|---|
| Critical | Service completely unavailable due to infrastructure | 1 hour (24/7) |
| High | Major functionality affected | 4 hours (24/7) |
| Normal | Questions, configuration requests, minor issues | 24 hours (business days) |
| Low | Commercial requests, suggestions | 48 hours (business days) |
For B2G Clients, the response and resolution times in the public procurement contract apply, if more favourable.
ANNEX H: DATA PROCESSING AGREEMENT (DPA) AND LIST OF SUB-PROCESSORS
This Agreement is concluded between the Client, as Controller, and S.C. CROCKY S.R.L., as Processor, pursuant to art. 28 of Regulation (EU) 2016/679, and forms an integral part of the Terms.
H.1. Subject matter and duration of processing. The Processor processes the personal data contained in the Client Content ("Controller Data") exclusively for the purpose of providing the Services (storage, hosting, transmission, backup, migration), for the duration of the contract and the retention periods under art. 14.5.
H.2. Nature and purpose of processing. Storage, transmission, backup and restore, in an automated manner, without the Processor accessing the content except to the extent strictly necessary for technical support requested by the Controller, for security or for compliance with the law.
H.3. Categories of data subjects and data. Determined by the Controller and may include: visitors, users, customers, employees, collaborators of the Controller; identification, contact and transactional data, logs, user-generated content and any other categories uploaded by the Controller. The Controller undertakes not to use Shared Hosting Services for special categories of data (art. 9 GDPR) without additional application-level encryption measures.
H.4. Processor obligations. The Processor: (a) processes Controller Data only on the Controller's documented instructions, which are these Terms, the configurations made by the Controller in the Platforms and support requests; (b) informs the Controller if, in its opinion, an instruction infringes the GDPR; (c) ensures that authorised personnel are bound by confidentiality; (d) implements the technical and organisational measures under H.7; (e) complies with the conditions on sub-processors under H.5; (f) assists the Controller, to the extent possible and against payment where the effort is disproportionate, in responding to data subject requests and in fulfilling obligations under art. 32 to 36 GDPR; (g) notifies the Controller without undue delay, and in any case within 48 hours of becoming aware, of any security breach affecting Controller Data, providing available information; (h) upon termination of the Service, deletes Controller Data in accordance with art. 14.5, unless the law requires retention; (i) makes available to the Controller the information necessary to demonstrate compliance and allows reasonable audits, with 30 days' prior notice, at most once a year, at the Controller's expense, without access to other Clients' data; the audit may be satisfied by reports or certifications of the Upstream Providers.
H.5. Sub-processors. The Controller gives general authorisation for the use of the sub-processors listed below. The Processor notifies the Controller at least 30 days before adding or replacing a sub-processor, by e-mail or display in the Account; the Controller may object within 15 days, in which case the parties will seek a solution, failing which the Controller may terminate the affected Service with pro rata refund.
| Sub-processor | Location | Role | Data location | Transfer mechanism |
|---|---|---|---|---|
| OVH SAS (OVHcloud) | France | infrastructure, data centres, DDoS protection | EU (FR, PL, DE) | EU |
| Contabo GmbH | Germany | infrastructure, data centres | EU (DE) | EU |
| Scaleway SAS / Online SAS | France | infrastructure, data centres | EU (FR, NL, PL) | EU |
| Stripe Payments Europe Ltd. | Ireland | payment processing (Client data, not Content) | EU / USA | DPF, SCC |
| Mollie B.V. | Netherlands | payment processing (Client data, not Content) | EU | EU |
| Hexasoft Development Sdn. Bhd. (FraudLabs Pro) | Malaysia | fraud prevention (Client data, not Content) | Malaysia | SCC |
| Vonage (Nexmo Inc.) | USA | SMS 2FA and notifications (Client phone number) | USA / EU | DPF, SCC |
| Web2SMS (Web2 SMS SRL) | Romania | SMS notifications (Client phone number) | EU (RO) | EU |
| NETIM SARL | France | domain name registrar (registrant data) | EU (FR) | EU |
| WebPros (cPanel, WHMCS), CloudLinux Inc., JetBackup, LiteSpeed Technologies | USA / various | software licensing; do not normally access Client Content | n/a | DPF, SCC where applicable |
H.6. International transfers. Client Content is not transferred outside the EU/EEA. Sub-processors outside the EU/EEA process exclusively the Client's own data (billing, payment, fraud prevention, SMS), on the basis of the EU-US Data Privacy Framework (DPF), standard contractual clauses (SCC, Decision 2021/914) or other appropriate safeguards under art. 46 GDPR.
H.7. Technical and organisational measures. Account isolation (CloudLinux CageFS/LVE, containers, virtual machines); role-based access control and two-factor authentication for staff; encryption of communications (TLS); firewall and detection systems (Imunify360, WAF); regular security updates; backups in accordance with art. 14; logging of administrative access; physical protection provided by Upstream Providers (ISO 27001 certified data centres); incident response procedures; staff training; confidentiality clauses with collaborators.
H.8. Liability. The Processor's liability under this Agreement is subject to the limitations in Section 20, to the extent permitted by art. 82 GDPR.
ANNEX I: WITHDRAWAL FORM FOR CONSUMERS
(complete and return this form only if you wish to withdraw from the contract)
To: S.C. CROCKY S.R.L., Str. Drăgaica nr. 5, sat Balasan, mun. Băilești, jud. Dolj, 205101, Romania, e-mail: contact@crocky.host
I hereby give notice that I withdraw from my contract for the provision of the following services:
Service / Order no.: ____
Ordered on: ____
Name of consumer: ____
Address of consumer: ____
E-mail address associated with the Account: ____
Signature of consumer (only if this form is submitted on paper): ____
Date: ____
I acknowledge that fees for domain names, software licences and SSL certificates are non-refundable and that, for services started at my express request, I will pay an amount proportionate to the period provided.
