Nettipoika Sites — Early Preview service terms Version 2026-09-30-preview-v2 1. Provider and agreement The service is provided by Cloud Rift Oy, trading as Nettipoika Sivusto, Business ID 3246185-6, VAT ID FI32461856. Registered and correspondence address: Jäniksenpolku 11, 90850 Oulu, Finland. Email: timo@nettipoika.fi. Telephone: +358 44 973 4093. These terms cover Nettipoika Sites, a managed website hosting and publishing service for EU individuals and businesses. A business customer must have authority to represent the business. Your order identifies the site, plan, total price, billing interval, trial and first billing date. The order details and the versioned documents presented before your acceptance form the agreement. We retain the accepted version; later website edits do not rewrite it. 2. What the service provides One small, low-traffic website with an HTTPS address, versioned source, publication tools, persistent files and an optional PostgreSQL database. Supported runtimes are static HTML, small Go applications and the supported Django environment. Your own compatible agent uses the documented HTTP API or MCP connection after you approve its scope. An AI assistant subscription, custom development, domain registration and unlisted capabilities are not included. You retain your rights in your content and grant us only the permissions needed to host, copy, back up and deliver it on your instructions. You are responsible for having the required content rights and for reviewing agent-generated changes. 3. Early Preview and service changes You can use Nettipoika Sites today; development continues. Features and interfaces may improve, operations may fail or take time, and explicit Django live editing has a known timeout limitation. Ordinary Django updates use a checked immutable release. See /preview and /for-agents for current limitations and exact tested client workflows. Hard CPU, memory, process, storage, network and time limits protect each customer. Code rollback does not roll back database contents. We do not promise uninterrupted availability or compatibility with every AI application. Early Preview is not a waiver of statutory quality, security, update or consumer rights, and general acceptance of these terms is not separate acceptance of a departure from mandatory conformity requirements. We provide updates needed to keep the contracted service conforming during supply. A material service or price change will be explained in advance on a durable medium; mandatory notice, withdrawal and termination rights apply. A price increase or separately quoted extra work is not authorized by an agent or by these general terms. 4. Price, payment and renewal Payments are in euros (EUR) through Mollie. The annual plan is EUR 100 excluding VAT, billed yearly; the monthly plan is EUR 15 excluding VAT, billed monthly. In Finland the totals are EUR 125.50/year or EUR 18.83/month including 25.5% VAT. The checkout shows the applicable country-specific tax and exact total. Verified qualifying EU business purchases may use reverse charge. Company details are optional for individuals. A card is required; checkout states whether its verification costs EUR 0 or EUR 0.01. The full 14-day trial starts at verified site activation. Any interval between trial end and the displayed first billing date is free of subscription charges. Your subscription renews automatically at the accepted interval until you cancel renewal. No charge is authorized merely by registering or by an agent request. Mollie handles payment-card details; we receive payment references and status, not your full card number or security code. 5. Cancel renewal, withdraw, or report a defect These are different rights. Cancel automatic renewal in your account's site subscription page or contact support before the next charge. Ordinary cancellation leaves service available until the stated trial or paid period ends and does not by itself refund an already supplied period. A consumer may withdraw from this service agreement within 14 days of concluding it, without giving a reason. Use the visible “Withdraw from your contract” function at /withdrawal, email timo@nettipoika.fi, or write to the address above. Sending your notice before the deadline is enough. The model form is: “I hereby withdraw from my Nettipoika Sites service contract. Order/site: __. Ordered on: __. Consumer name: __. Address: __. Date: __. Signature (only if sent on paper): __.” The form is optional; any clear notice is accepted. We acknowledge an online notice on a durable medium and refund amounts due without undue delay, no later than 14 days after receiving the notice, using the original payment method unless you expressly agree otherwise, without a refund fee. Starting hosting during the withdrawal period requires your separate express request. This does not remove the withdrawal right merely because the site was activated. No subscription usage fee accrues during the free trial. These terms do not impose a withdrawal penalty or reduce any statutory refund right. 6. Defects, support and disputes Report a platform defect to support with the affected site and a description. Consumers retain their applicable rights to correction, price reduction, termination and damages for nonconforming or delayed digital services. We do not exclude mandatory liability or make your own backup a condition of those rights. The support policy explains contact hours and the scope of included assistance. Contact us first to resolve a complaint. Consumers can contact Finnish Consumer Advisory Services (kkv.fi/kuluttajaneuvonta) and refer a dispute to the Consumer Disputes Board (kuluttajariita.fi). Finnish law applies without depriving an EU consumer of mandatory protections in their country of habitual residence. Statutory court and dispute-resolution rights are unchanged. 7. Suspension, export and end of service A failed renewal has a seven-calendar-day grace period. After entitlement ends, public serving and site mutations may be suspended; owner status and eligible data export remain available. We may restrict a specific operation immediately to contain an actual security or unlawful-use risk, explaining the reason and how to appeal unless law or security prevents disclosure. We do not delete a site solely because a payment callback is delayed. Primary site data is retained for 30 days after suspension, with notice at suspension and at least seven days before scheduled deletion. Service-managed deletion snapshots expire within 35 additional days. Separate restricted disaster-recovery archives rotate through 7 daily, 4 weekly and 6 monthly restore points, so deleted data can remain there for approximately six months. These archives are used only for recovery, with deletion requests reapplied before restored data returns to ordinary use. Accounting and dispute records have separate legal retention. Request an export while data remains available. Destructive database actions require separate authorization; an agent's ordinary edit permission does not authorize them. 8. Customer-data processing agreement For personal data that you control in your hosted site, you are the controller and Cloud Rift Oy is your processor (or your authorized subprocessor). Processing covers storage, execution, publication, backup, recovery and deletion of the website, files, database, technical logs and access records for the service term and the retention periods above. Data subjects and categories depend on your site: typically visitors, users or customers and their contact details, submitted content and technical identifiers. Special-category data, payment-card data and regulated workloads are not part of the standard service. Your documented instructions are this agreement and authorized service operations. We process these data only on those instructions, including transfers, unless law requires otherwise; we notify you of such a requirement where permitted and flag an instruction we consider unlawful. Authorized personnel are bound to confidentiality. We maintain appropriate technical and organizational safeguards, including tenant separation, least privilege, encryption in transit, access control and protected backups. We assist with individual-rights requests, security incidents, impact assessments and regulator consultation as required by GDPR Articles 28–36, and notify you of a personal-data breach without undue delay after awareness. On termination we return or delete data as instructed, subject to the stated backup cycle and mandatory legal retention. We make compliance information available and permit proportionate audits and inspections required by Article 28; a support process cannot remove those rights. You authorize the disclosed hosting subprocessor Hetzner and Cloud Rift-operated Finnish backup infrastructure. We notify you before adding or replacing a subprocessor so you can raise a substantiated data-protection objection; equivalent obligations bind every subprocessor and we remain responsible for its performance. The privacy notice lists other providers handling account, email and payment data, and explains their distinct roles and international transfers.