Terms and Conditions for the Use of Services
Effective from July 2026
This is a translation provided for convenience. In case of any discrepancy, the Romanian version prevails.
Any offer accepted directly or through our partners implies acceptance of the terms and conditions detailed below. The general terms and conditions shall apply to all sales of services by SC BRAINCAP S.R.L. to the Client. If you do not accept the terms and conditions set out in this document, do not use the services offered by us. The general terms and conditions are deemed to be accepted by the client directly or by placing an order through our partners. Thus, by entering into legal relations with our partners following confirmation of the order by SC BRAINCAP S.R.L., these shall constitute the services contract governing the contractual relationship between the parties. In accordance with legal provisions, we inform you that you will lose the right of withdrawal after the contract has been fully performed by SC BRAINCAP S.R.L.
Terms
- Client: - A natural/legal person who places an order for services directly or through the Partners;
- Partner: - A legal person who acts as an intermediary for a service of SC BRAINCAP SRL to the client;
- Provider: - SC BRAINCAP SRL, registered with the Trade Register under no. J40/11790/2008, CUI: RO24163684, with registered office in Bucharest Municipality, Bd. Dimitrie Pompeiu no. 5-7, Hermes Campus 1, building B, 2nd floor, room 221, sector 2.
- Services: – any services offered by SC BRAINCAP SRL to the Client directly or through the Partner.
- Order: – the agreement between SC BRAINCAP SRL and the Client/Partner whereby SC BRAINCAP SRL undertakes to deliver the services, and the Client undertakes to pay for them.
- Contract: – an Order confirmed by SC BRAINCAP SRL. Details regarding the characteristics of the services or products may be provided to you by telephone or by e-mail upon request.
Services offered
- VPS (Virtual Private Server) hosting services
- dedicated server rental services
- server colocation services
- IT consultancy and support services
- server administration services
- sale of IT equipment
By SC BRAINCAP SRL’s confirmation of an Order, the Client agrees to the Terms and Conditions of SC BRAINCAP SRL. Acceptance of the order by SC BRAINCAP SRL is considered complete upon confirmation by e-mail. Any order not confirmed by SC BRAINCAP SRL shall not have the value of a Contract.
Rates (prices)
The prices offered and accepted represent the monthly subscription for the client/Partner. Prices are calculated FRANCO BENEFICIAR (free to beneficiary) and are valid for a contractual period of 12 or 24 months from the signing of the contract. The statutory VAT in force at the time of invoicing is added to the prices in the offer. Prices in LEI are calculated by multiplying by the official BNR (National Bank of Romania) exchange rate of the currency in which the offer was made. Any change occurring in Romanian legislation (changes to customs duties, excise duties, taxes, etc.) after the date of the offer will automatically lead to its recalculation.
Method of payment
Payment by bank transfer (payment order) Payment by payment order is made only on the basis of the invoice issued by SC BRAINCAP SRL, sent by e-mail to the Client/Partner. Order processing and service delivery will be carried out after confirmation of payment, into the account below, of the proforma invoice issued. Company name: SC BRAINCAP SRL Bank account: RO50RZBR0000060026249148, opened at Raiffeisen Bank SA Unique registration code: RO24163684 Regardless of the currency you hold in your account, transactions are made in lei, at your bank’s exchange rate. Suspension of services following non-payment SC BRAINCAP SRL has the right to suspend any service provided after 15 days have passed from the due date for payment of the services, if payment has not been made.
Right of withdrawal
Each of the services offered benefits from a 14-day guarantee of full reimbursement of the amount paid, if you exercise your right of withdrawal from the contract, without giving any reason. We inform you that you will lose the right of withdrawal after the contract has been performed by SC BRAINCAP SRL, except for VPS services, for which you may exercise the right of withdrawal even after the services have been performed, within 14 days. The withdrawal period expires after 14 days starting from the day the order is placed or the price is paid. In order to exercise your right of withdrawal, you must inform us of your decision to withdraw from this contract, using an unequivocal statement, for example, a letter sent by post to the registered office address or an e-mail to [email protected]. In order to meet the withdrawal deadline, it is sufficient to send your communication concerning the exercise of the right of withdrawal before the withdrawal period expires. If you withdraw, we will reimburse any amount we have received from you, no later than 14 days from the date on which we are informed of your decision to withdraw from this contract. We will carry out this reimbursement using the same payment method as that used for the initial transaction, unless you have expressly agreed to a different reimbursement method; in any event, you will not incur any fees as a result of such reimbursement. The right of withdrawal cannot be exercised after the services have been performed, except for VPS services, for which you may exercise the right of withdrawal even after the services have been performed, within 14 days. Termination At the client’s request, a services contract concluded with SC BRAINCAP SRL may be terminated with 30 days’ prior notice. Termination requests will not be accepted as long as the account has outstanding payment arrears. Termination requests must be communicated in writing, not by telephone, tickets, live chat, etc. If the client requests termination of the contract (other than under the right of withdrawal) without any fault on the part of SC BRAINCAP SRL, the price calculated annually and paid in advance by the Client for the entire year will not be refunded, the difference being retained by SC BRAINCAP SRL as damages, in consideration of the fact that the Client benefited from a discount for making the advance payment. SC BRAINCAP SRL or the client may terminate the agreement (without prejudice to their other rights) if one of the parties involved significantly breaches the agreement (including, but not limited to, a breach of the Acceptable Use Policy by the client).
Technical data of the services offered
Uptime (service availability) SC BRAINCAP SRL guarantees an uptime of 99.5%. The uptime of our servers is defined by OS reports and by our own monitoring system, and may therefore differ from the uptime reported by other monitoring systems. Data access Data may be accessed at any time and from anywhere by the client through an encrypted virtual private network and through a secure two-step authentication system. Technologies used The website hosting space supports the following technology: Linux Ubuntu, Windows Server, Microsoft SQL Server, IIS, .net core Data replication Data replication to the disaster recovery centre is performed at 15-minute intervals, with the possibility of restoring to the second, for up to 2 days back. Backup The use of the services is strictly the responsibility of clients. SC BRAINCAP SRL may offer backup services in accordance with the agreement concluded. Please also note that backups performed cannot be fully verified to confirm every file or directory. SC BRAINCAP SRL is not liable for the loss of files and/or information. Virtual Machines will perform a daily Backup for all stored information, retention is 14 days, and the backup window is between 1AM-5AM. Fast data access The client’s applications will be hosted on the Virtual Machines, with the server cluster infrastructure providing users with fast access to the client’s website or applications. Access acceleration Website access acceleration is achieved with external resources through Caching, TCP Compression and SSL offload. SSL Certificate The digital SSL certificate for a hosted domain will be valid for 2 years and is free of charge. DDoS Protection DDoS protection will be limited to 1GB. DDoS protection is a system that provides protection against a denial-of-service type cyber-attack. VPS Monitoring The cloud and virtualisation system will be proactively and permanently monitored by BRAINCAP SRL employees. This is an automated system that checks the proper functioning of the servers and their load balancing to avoid overloading. Proactive vulnerability scanning is carried out permanently to prevent cyber-attacks. Patch management Automated weekly patch management is carried out every Friday between 2AM-5AM. Patch management includes remedying security vulnerabilities and other errors, or improving the functionality, usability or performance of a program. Patches are made available periodically by software vendors for operating system and application updates. Updates Permanent updates will be made to the protection systems; the system is periodically taught how to eliminate new vulnerabilities that may arise from the online environment. Resources expressed in GB will be allocated in accordance with the agreement concluded. The VPS services offered include subsequent technical assistance in accordance with the agreement concluded.
Use of SC BRAINCAP SRL services
The services offered by SC BRAINCAP SRL shall be used only for lawful and moral purposes; any activities that may be considered illegal are strictly prohibited. The bulk sending of e-mail messages, sending messages to a large number of e-mail addresses, may be carried out using our servers or other servers to promote any site hosted on our servers, only in accordance with the legislation in force. Any complaint received in this regard will be sent immediately to the client with the aim of resolving the issue between the two parties involved (the client and the person who sent the complaint), however SC BRAINCAP SRL may resort directly to suspending or deleting the service provided depending on the scale and severity of the complaint. All services provided by SC BRAINCAP SRL are used and administered by the client, and the use of these services is entirely the client’s responsibility, SC BRAINCAP SRL having no access or having limited access to the information or activities being carried out, and not being liable for non-compliance with applicable legal provisions. SC BRAINCAP SRL complies with legal provisions and will act on any complaint coming from aggrieved persons or institutions/authorities or organisations, complaints which create at least a reasonable appearance of legitimacy. Use of resources Accounts that cause damage to our servers will receive a notification to resolve the issue within 3 days, as long as the damage is not serious. Otherwise, such accounts may be suspended until the situation is resolved. If the client fails to address the issues notified to them within 3 days of the date of notification, SC BRAINCAP SRL may, at its absolute discretion, terminate the contract. SC BRAINCAP SRL’s liability for loss or damage suffered by you Regardless of whether you are a consumer or a professional:
- We do not exclude or limit our liability in any way if this would not be permitted by law. This includes liability for death or personal injury caused by our negligence or the negligence of our employees, agents or subcontractors, as well as by fraud. If you are a professional: We will not be liable to you for any loss or damage, whether arising from contractual or tortious liability (including negligence), even if these are foreseeable, resulting from or in connection with:
- the use of, or inability to use, our website; or
- the use of, or reliance on, any content displayed on our website. In particular, we will not be liable for:
- loss of profit, sales, business or revenue;
- business interruption;
- loss of anticipated benefits;
- loss of business opportunity or reputation; or
- any indirect or consequential losses or damages. WE ARE NOT RESPONSIBLE FOR VIRUSES AND YOU ARE NOT ENTITLED TO INTRODUCE VIRUSES You are responsible for configuring your information technology, computer programs and platform in order to access our website/our platform. You are advised to use your own virus protection software. You must not misuse our space by knowingly introducing viruses, trojans, worms, logic bombs or other material that is technologically harmful. You must not attempt to gain unauthorised access to our website, the server on which our website is stored, or any server, computer or database connected to our website. You must not attack our website via a DDoS attack. By breaching these provisions, you would commit a criminal offence. We will report any such breach to the competent authorities and will cooperate with those authorities by disclosing your identity to them. In the event of such a breach, your right to use our website will cease immediately. Client responsibilities The client is responsible for updating the contact information and billing details listed in their account; SC BRAINCAP SRL has no responsibility for damages arising as a result of the client’s failure to make the necessary updates. The client is responsible for maintaining the security of the username, passwords and other sensitive information. If there is any doubt in this regard, the client must change or request the change of the authentication data by contacting the support team. SC BRAINCAP SRL will not be responsible for damages caused by the temporary unavailability of our servers, whatever the reason causing this. This provision also includes damages resulting from data corruption or loss. Rules regarding links to our website You may post a link to our home page, provided that you do so in a fair and legal manner and that it does not damage our reputation or image. You must not establish a link in a way that suggests any form of association, without having our approval. You must not post a link to our website on any website that is not owned by you. Our website must not be framed on any other site, nor may you create a link to any part of our website other than the home page. We reserve the right to withdraw your permission to post the link without prior notice. Force majeure Neither party shall be liable for non-performance of its contractual obligations, if such non-performance is due to a force majeure event, in accordance with the legislation in force. Applicable law – jurisdiction The contract is subject to Romanian law. Any disputes arising between SC BRAINCAP SRL and the Client shall be resolved amicably, and if this is not possible, disputes shall be settled by the competent Romanian courts in Bucharest. Intellectual property rights All materials incorporated into this website are the intellectual property of SC BRAINCAP SRL. These materials may not be copied or reproduced. However, complete pages of the website may be printed if intended for strictly personal use. Final provisions In addition to the terms and conditions set out above, SC BRAINCAP SRL, depending on the service purchased by the Client, may also conclude additional services contracts, in which case the conditions thus established shall apply between the parties. Accordingly, the Terms and Conditions represent a general framework contract which may subsequently be amended by agreement of the parties through the signing of additional contracts or annexes. SC BRAINCAP SRL reserves the right to modify its policy and the terms and conditions for the use of the services without prior notice.
Technical and organisational measures
-
- Organisational protection measures — 1.1 Security management — a) Security policies and procedures: The Processor must draft a security policy regarding the processing of personal data.
- b) Roles and responsibilities: i. Roles and responsibilities related to the processing of personal data are clearly established and distributed in accordance with the security policy
- ii. During internal reorganisations or terminations and changes of job position, the revocation of rights and responsibilities through the relevant handover procedures is clearly defined.
- c) Access control policy: Specific access control rights are allocated to each role involved in the processing of personal data, based on the need-to-know principle.
- d) Resource/asset management: The Processor maintains a register of the IT resources used for the processing of personal data (hardware, software and network). A specific person is tasked with maintaining and updating the register (for example, an IT officer).
- e) Change management: The Processor ensures that all changes made to the IT system are recorded and monitored by a specific person (for example, a Security or IT officer). Regular monitoring of this process takes place.
- 1.2 Incident response and business continuity — a) Incident management / personal data security breaches — i. An incident response plan with detailed procedures is established, to ensure an effective and organised response to incidents related to personal data.
- ii. The Processor will report to the Controller without delay any security incident that has resulted in the loss, misuse or unauthorised acquisition of any personal data.
- b) Business continuity: the Processor establishes the main procedures and controls to be followed, in order to ensure the necessary level of continuity and availability of the IT system for processing personal data (in the event of incidents / personal data security breaches).
- 1.3 Human ResourcesStaff confidentiality: The Processor ensures that all employees understand their responsibilities and obligations related to the processing of personal data. Roles and responsibilities are clearly communicated during the hiring and/or induction process.
- Training: The Processor ensures that all employees are duly informed about the IT system security controls relevant to their day-to-day activities. Employees involved in the processing of personal data are also duly informed of the relevant data protection requirements and legal obligations through regular awareness campaigns.
-
- Technical protection measures — 2.1 Access control and authentication — a) An access control system applicable to all users accessing the IT system is implemented. The system allows the creation, approval, review and deletion of user accounts.
- b) The use of shared user accounts is avoided. Where this is necessary, it is ensured that all users of the shared account have the same roles and responsibilities.
- c) When granting access or assigning user roles, the “need-to-know” principle is observed, in order to limit the number of users who have access to personal data only to those who need it for the purposes of the data processing
- d) Where authentication mechanisms are based on passwords, the Processor requires the password to be at least eight characters long and to comply with very strong password control parameters, including length, character complexity and non-repeatability.
- e) Authentication information (such as the user ID and password) will never be transmitted unprotected over the network.
- 2.2 Logging and monitoring: - Logging files are enabled for each system/application used for processing personal data. These include all types of data access (viewing, modification, deletion).
- 2.3 Data-at-rest security — a) Server/database security — i. Database and application servers are configured to run using a separate account, with minimum access privileges, for correct operation.
- ii. Databases and application servers process only the personal data actually necessary for processing, for the purpose of achieving their processing objectives.
- b) Workstation security — i. Users cannot disable or bypass the security settings.
- ii. Antivirus applications and detection signatures are regularly configured/updated.
- iii. Users do not have privileges to install or disable unauthorised software applications.
- iv. The system has a session timeout period when the user has been inactive for a certain period of time.
- v. Critical security updates released by the operating system developer are installed on a regular basis.
- 2.4 Network/communication security — a) Whenever access is carried out via the Internet, communication is encrypted using cryptographic protocols.
- b) Traffic to and from the IT system is monitored and controlled through intrusion prevention and intrusion detection systems.
- 2.5 Backups — a) Data back-up and archiving procedures are defined, documented and clearly linked to roles and responsibilities;
- b) Backups receive an adequate level of physical and environmental protection, which complies with the standards applied to the original data;
- c) The execution of backups is monitored to ensure that they are complete.
- 2.6 Mobile/portable devices — a) Procedures for managing mobile and portable devices are defined and documented, establishing clear rules for their proper use.
- b) Mobile devices that have access to the IT system are registered and authorised in advance.
- 2.7 Application lifecycle security: - throughout the development lifecycle, the best and most advanced security practices and standards, or well-regarded development standards, are observed.
- 2.8 Data erasure/disposal — a) Software-based overwriting will be performed on media before disposal. In cases where this is not possible (CDs, DVDs, etc.), physical destruction will be carried out.
- b) Paper and portable media used for storing personal data are destroyed.
- 2.9 Physical security: - The physical perimeter of the IT system infrastructure is not accessible to unauthorised personnel. Appropriate technical measures (for example, an intrusion detection system, a chip-card turnstile, a single-person-access security system, a locking system) or organisational measures (for example, security guards) will be put in place to protect secure areas and access points against access by unauthorised persons.