Cloud Terms of Service global | v0.1.0 | 2026-10-05 | draft Draft — not yet effective These Cloud Terms govern online subscriptions to Shpyrd Cloud, our proprietary platform as a service for deploying and running applications on infrastructure operated by Shpyrd. The provider is FLUXYR LTDA, a Brazilian company registered under CNPJ 47.640.746/0001-23, at Avenida Engenheiro Luiz Carlos Berrini, 1376, 17th floor, São Paulo, Brazil ("Shpyrd", "we", "us"). "Customer" means the person or entity identified in the subscription. Contact legal@shpyrd.io for contractual notices and privacy@shpyrd.io for privacy requests. 1 Agreement and acceptance 1.1 The agreement is formed when Customer affirmatively accepts these Terms in the registration or checkout process and the subscription is confirmed. A person acting for an entity represents that they have authority to bind it. Before acceptance, we will make these Terms and the commercial summary available to read, download, and retain, and record the accepted version, account, time, and evidence of acceptance. 1.2 The agreement consists of the confirmed commercial summary, these Terms, and any expressly identified, versioned schedules. The summary specifies the plan, prices, metering units, cycle, currency, limits, cancellation rules, region, and support. The Privacy Policy describes our own processing of account and website information; it does not replace a data processing agreement for Customer-controlled application data. 1.3 Expressly negotiated provisions override the provisions they specifically identify. A data processing agreement governs its subject matter; an agreed service level schedule governs its subject matter. These Terms otherwise govern the Cloud subscription and take priority over the general Terms of Service for that subscription. Mandatory rights and expressly accepted offers remain unaffected. 2 Service and access rights 2.1 During the subscription, Customer has a non-exclusive right to access the PaaS and make its applications available to end users within the plan. Cloud is a proprietary, closed-source service. A subscription does not deliver its source code, transfer intellectual property, or authorize resale of the platform itself unless separately agreed. 2.2 Customer retains its code, applications, and data and grants us only the rights needed to store, run, transmit, and protect them to provide the service. Any components separately supplied under third-party licenses remain subject to those licenses. 2.3 We operate the infrastructure components included in the plan. Customer manages its applications, dependencies, permissions, secrets, and configurations, maintains rights to its content, and supports its end users. Application development, business operations, and migration services are excluded unless expressly included. 3 Accounts and acceptable use 3.1 Customer must keep account and contact information accurate, protect credentials, and report suspected compromise. Customer is responsible for its authorized users, without relieving us of responsibility for failures attributable to us. 3.2 Unlawful use, infringement of third-party rights, malware distribution, attacks, unauthorized access, interference with other customers, and metering or payment fraud are prohibited. Security tests that could affect shared infrastructure require prior coordination. Workload-specific restrictions must be disclosed in the plan before purchase. 3.3 Customer may host applications used by its own customers. An agency may consolidate billing for third-party workspaces only after those workspaces and their owners' authorization are identified. Billing consolidation does not itself transfer data ownership or administrative rights; the agency's payment obligations must be specified in the commercial summary or an amendment. 4 Pricing and metered usage 4.1 For plans with a monthly minimum convertible into usage credit, the minimum is billed in advance and provides an equal credit for eligible resources in the same cycle. Unused credit expires at the end of the cycle, does not roll over, and is not redeemable for cash, subject to refunds required by this agreement or law. Separately billed add-ons must be disclosed before acceptance. 4.2 For a full cycle without plan changes, the charge for eligible resources is the greater of the monthly minimum and metered usage. Illustrative example: a minimum of 100 and usage of 160 produces a total of 160 in the agreed currency, before taxes and add-ons. We do not add the minimum a second time to usage already covered by its credit. 4.3 CPU core-hours, memory GiB-hours, storage GiB-months, and outbound GiB are charged only if included in the plan's pricing schedule, at the accepted rates. The summary and metering documentation must define allocated versus consumed resources, time basis, month conversion, rounding, and included services. Dashboard figures may be estimates subject to reconciliation; Customer will have access to billing details. 4.4 Usage exceeding credits is billed in arrears, at cycle end or an identified invoicing threshold. Interim invoices are deducted from the same cycle's reconciliation. Usage credits, an unbilled-balance limit, and a spending cap are different: a credit limit or alert is not a guarantee of immediate shutdown or a maximum bill. 4.5 An automatic spending stop is included only when its operation, coverage, and metering delay are disclosed. Suspension may interrupt applications and does not mean immediate data deletion. Previously incurred usage and expressly priced retained resources remain billable; no undisclosed new charges are introduced. 4.6 An upgrade, downgrade, or negotiated change must show its effective date and any prorated calculation before confirmation. New rates do not retroactively reprice past usage. Without an accepted transition rule, changes take effect in the next cycle. Time-limited negotiated pricing must identify the rates and date that will apply after it ends. 5 Payment and international customers 5.1 The commercial summary identifies currency, payment method, due date, taxes, and fees. Customer authorizes recurring charges for agreed fixed and variable amounts. We may use payment processors and will issue legally required tax documents; a processor receipt does not replace a required tax invoice. 5.2 Nonresident customers may agree to a foreign currency. Any conversion must identify its source, date, and charges in advance. Domestic transactions between Brazilian residents will be priced and settled in BRL unless a specific lawful exception has been validated and expressly agreed. Currency is not determined merely by the language selected in this portal. 5.3 Each party bears taxes allocated to it by law. Mandatory withholding must be documented and recognized in payments. A gross-up for withholding on an international transaction requires an express, lawful provision in the commercial summary; no general gross-up is implied. 5.4 Customer may dispute charges through legal@shpyrd.io, identifying the disputed items. The proposed operational period is 30 days after receipt, without extinguishing statutory rights afterward. Undisputed amounts remain due. We will investigate within a reasonable time, correct demonstrated errors, and will not suspend solely for a portion disputed in good faith while it is under review. 6 Availability and support 6.1 Support channels, hours, language, and scope are specified in the plan. Guaranteed availability, response times, and service credits apply only under an accepted schedule defining covered components, measurement, exclusions, and claims. Around-the-clock support is not implied. 6.2 We will exercise reasonable professional care and give reasonable advance notice of scheduled maintenance. We do not guarantee an error-free or uninterrupted service. Customer's responsibility for its applications does not remove our obligations for infrastructure we operate. 6.3 Backup, restoration, and retention commitments are those expressly included in the plan. Customer should maintain a continuity strategy appropriate to its business; this does not relieve us of contracted backup and security obligations. Experimental features must be identified, voluntarily enabled, and accompanied by their limitations. 7 Personal data and confidentiality 7.1 Each party must comply with applicable data protection law. For personal data in applications, Customer determines purposes and instructions and we act as processor or subprocessor according to the actual contractual chain. For account administration, billing, and our own legal obligations, our role and processing are described in the Privacy Policy. 7.2 Hosting may require storage, processing, transmission, support access, and deletion during the service and agreed retention periods. Before production processing of personal data, the commercial summary and data processing schedule must identify data and data-subject categories, regions, subprocessors, instructions, security measures, and applicable international transfer mechanisms. 7.3 We will process application data only on documented instructions or as required by law, restrict access to authorized persons subject to confidentiality, and apply risk-appropriate technical and organizational measures. We will not use that data for advertising or model training without specific authorization and an applicable legal basis. 7.4 Within our role and available information, we will assist Customer with individual requests, risk assessments, and incidents. We will notify Customer without undue delay of incidents affecting data for which we are responsible, providing available information and updates. Operational deadlines and contacts must be agreed in the data processing schedule and support Customer's legal deadlines. 7.5 Subprocessors must have compatible obligations. Their list, countries, change notices, and a reasoned objection procedure must be specified in the data processing schedule. A valid mechanism is required for restricted international transfers; accepting these Terms is not itself such a mechanism. Workloads with special sector requirements require prior assessment of the offering. 7.6 Confidential information may be used only to perform the agreement and disclosed only to recipients with a need to know and a confidentiality obligation. Exceptions cover information lawfully public, previously known, independently developed, or lawfully received without restriction. Compelled disclosure must be limited and notified where permitted. Confidentiality lasts five years after termination, and longer for protected trade secrets or personal data as required by law. 8 Term suspension and termination 8.1 Subscriptions renew monthly. Customer may cancel in the dashboard, or through legal@shpyrd.io if the dashboard is unavailable, before the current cycle ends, effective at its end. Cancellation prevents the next renewal but does not waive incurred usage or other amounts due. An annual commitment exists only if expressly and prominently agreed. 8.2 Undisputed nonpayment may result in suspension after notice and ten calendar days to cure. A concrete security risk, fraud, unlawful use, legal order, or an expressly accepted risk limit may justify immediate, proportionate restriction. We will communicate the reason and restoration steps as soon as possible and restore access after resolution. 8.3 Either party may terminate for material breach not cured within 30 days after notice. We may discontinue an offering or decline renewal without cause on 30 days' notice, allowing transition and refunding prepaid, unprovided periods proportionately. Wrongful suspension or failures attributable to us do not eliminate Customer's remedies. 8.4 Customer may export data during the subscription through available functions. After termination, we will make retained data recoverable on request for 30 days, without continuing to run applications. Active data will then be deleted within 30 days; backup deletion follows the period identified in the plan, subject to identified legal retention. These periods must also be disclosed for a downgrade to a free plan. 8.5 Underuse of the minimum during an already-started cycle does not itself entitle Customer to a refund. Statutory rights, billing errors, more favorable agreed terms, and termination for our breach are preserved. Accrued payment, confidentiality, data protection, intellectual property, and liability obligations survive as their nature requires. 9 Warranties and responsibility 9.1 We have the rights needed to provide the service and will deliver it substantially in accordance with the documentation and plan. We will seek to correct notified material nonconformity within a reasonable time. If it remains unresolved for 30 days and prevents essential contracted use, Customer may terminate the affected service and receive unused prepaid amounts, without prejudice to statutory rights. 9.2 To the extent permitted by law, each party's aggregate liability for direct loss is capped at amounts paid or payable for the affected service in the 12 months before the event. Accrued payment obligations are not capped. The proposed cap for confidentiality, data protection, and intellectual-property indemnity is twice that amount. Fraud, intentional misconduct, and liability that cannot legally be limited are excluded from the caps. 9.3 To the same lawful extent, indirect loss and lost profits are excluded, subject to fraud, intentional misconduct, and mandatory law. These limits govern the parties' relationship and do not restrict rights of individuals, authorities, or third parties. Mandatory consumer protections, including cancellation and refund rights, prevail where applicable. 9.4 Each party is responsible for third-party claims arising from infringement by materials it supplies or acts attributable to it. We are responsible for intellectual-property claims concerning authorized use of the platform; Customer is responsible for its content and applications. The indemnified party must give timely notice, cooperate, and allow reasonable control of the defense. No settlement may impose obligations on it without consent. Our obligation excludes infringement caused by unauthorized modifications or combinations to the extent of their causal contribution. 10 Changes language and general provisions 10.1 Material changes to prices or these Terms require at least 30 days' notice and take effect only for a future renewal. Customer may cancel before they take effect. Specific consent will be obtained where required. Agreed fixed-term commitments will not be changed during that term without agreement, except as required by law. 10.2 Neither party may assign the agreement in a way that reduces the other's protections without consent. A change of corporate name with the same legal entity and CNPJ will be notified and does not itself substitute the provider. Public use of Customer's name or marks requires authorization. 10.3 Brazilian law and, where permitted, the courts of São Paulo, Brazil apply, subject to mandatory law and jurisdiction. Different law or forum for an international transaction must be expressly agreed. This Global edition is drafted in English and controls over convenience translations unless mandatory law or the accepted Order provides otherwise. A transaction expressly accepting the Brasil edition is governed by that Portuguese edition and its local provisions. 10.4 Electronic records of assent, identity, and document integrity may serve as evidence as permitted by law. Notices will be sent to registered contacts and retained for access. If a provision is unenforceable, the remaining provisions continue to apply.