WebDisk Next Service Terms
Version: 1.0 · Effective from: 2026-07-25
The Polish version is the legally binding version. This English translation is provided for convenience only.
These terms (hereinafter: "Next Terms") set out the conditions for the provision of the WebDisk Next service (hereinafter: "Service") and constitute a supplement to the WebDisk SaaS Service Terms (hereinafter: "SaaS Terms"). In matters not governed by the Next Terms, the provisions of the SaaS Terms apply. In the event of a conflict, the Next Terms prevail.
Provider: Mazura sp. z o.o. with its registered office in Ząbki, ul. Baśniowa 1C/2, 05-091 Ząbki, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under number KRS 0000971559, NIP 1251732787, owner of the WebDisk brand (hereinafter: "We" / "WebDisk" / "Provider").
Contact: office@webdisk.io, tel. +48 502 049 866, correspondence address: ul. Baśniowa 1C/2, 05-091 Ząbki.
Customer: a natural person, legal person or organisational unit without legal personality that has purchased a subscription to the Service and for whom a Nextcloud instance has been launched (hereinafter: "Customer" / "You").
1. Scope of the service
1.1. WebDisk Next is a managed Nextcloud instance hosting service: under the subscription we launch and maintain for the Customer a dedicated virtual machine (VM) with the Nextcloud software installed and configured, available under an individual subdomain within the next.webdisk.io domain.
1.2. Within the Service we provide:
- the launch and maintenance of a dedicated virtual machine (compute resources, memory, disk, network connectivity),
- an installed and configured Nextcloud instance together with a TLS certificate for the subdomain,
- managed updates of the Nextcloud software and of the virtual machine's operating system (section 3),
- snapshots of the instance in accordance with the parameters of the plan (section 4),
- a Customer panel enabling management of the instance lifecycle,
- optional monitoring of the availability and performance of the instance, enabled by the Customer.
1.3. Nextcloud is third-party software. The Provider supplies a managed hosting service and is not the author of the Nextcloud software. The functionality of the application itself (browser access, Nextcloud client applications, sharing, calendar, contacts, applications from the Nextcloud App Store) is delivered by the manufacturer's software — the rules of liability are set out in section 3.
1.4. The parameters of the plan (virtual machine resources, disk capacity, any limits), prices, and the frequency and retention of snapshots are indicated in the Customer panel and on the next.webdisk.io website. The parameters in force at the time of purchase are binding for the given subscription period.
2. Customer account and Nextcloud users
2.1. The WebDisk account serves to manage the subscription and the instance lifecycle: purchasing and changing the plan, launching and stopping the instance, accessing the Customer panel and handling billing. The account is created upon purchase of the subscription.
2.2. Users inside the Nextcloud instance. End-user accounts within the instance (e.g. the Customer's employees) are created, configured and deleted by the Customer independently, using the Nextcloud administration panel. The Provider is not a party to any contract with those users and does not manage their permissions; in relation to them, the Customer acts as the controller of personal data.
2.3. The Customer is responsible for the confidentiality of the access credentials to the WebDisk account and to the administration panel of its Nextcloud instance, for the proper use of multi-factor authentication where it is made available, and also for creating accounts and granting permissions inside Nextcloud.
2.4. The Customer shall not disclose access credentials to unauthorised persons. Should a breach of the security of the account or of the instance be suspected, the Customer shall immediately change the passwords and notify the Provider at security@webdisk.io or via the ticket function in the panel.
3. Nextcloud software, updates and applications
3.1. Manufacturer's software. The instance is based on the Nextcloud software, made available under the AGPLv3 licence. The Provider installs and maintains it, exercising due diligence so that versions supported by the manufacturer and security updates are used. The Provider is not liable for defects, security vulnerabilities or functional changes introduced by the manufacturer of the software.
3.2. Managed updates. The Provider applies updates to the operating system of the virtual machine and to the Nextcloud software, including automatic updates performed by package update mechanisms without the involvement of the Provider's personnel. An update may involve a short-term unavailability of the instance or Nextcloud entering maintenance mode.
3.3. Major version updates. Major version updates of Nextcloud may change the interface, disable or alter the operation of incompatible applications and require data migration. We give advance notice of planned major version updates. The Provider does not guarantee that third-party applications will continue to operate following such an update.
3.4. Applications installed by the Customer. If the plan enables the installation of additional applications from the Nextcloud App Store, the Customer installs them at its own risk. The Provider is not liable for the operation, security or licence compliance of such applications and may disable them if they threaten the stability or security of the instance or of the infrastructure.
4. Instance lifecycle and snapshots
4.1. Launch. Once the payment has been credited, we launch a dedicated virtual machine and install the Nextcloud instance. The launch status is visible in the Customer panel.
4.2. Change of resources. The Customer may change the plan or the resources of the instance in the panel. A change of resources may require the virtual machine to be restarted and a short-term unavailability of the instance.
4.3. Migration. The Provider may move the Customer's virtual machine between infrastructure hosts for maintenance purposes or for load balancing, without changing the scope of the Service. We communicate planned migrations on the terms applicable to scheduled maintenance (section 6).
4.4. Snapshots. Within the Service, rotating snapshots of the instance are taken — with the frequency and retention indicated in the Customer panel. A snapshot restores the state of the instance as at the moment it was taken. Snapshots serve to restore the instance after a failure and do not constitute a backup of the Customer's data within the meaning of a separate archiving service. A service of making backups outside the Service infrastructure may be introduced as an additional service; until it is made available, only rotating snapshots apply.
4.5. Recommendation of the Customer's own backup. We recommend that the Customer maintain its own backup of critical data outside the Service, in accordance with the 3-2-1 rule (three copies, two media, one off the primary site). Nextcloud client applications enable data synchronisation to the Customer's devices and may serve as one of the media of such a copy.
4.6. Subdomain. The subdomain assigned to the instance applies for the duration of the subscription and, after it ends, returns to the Provider's pool.
5. Data sharing and liability for content
5.1. Sharing is carried out inside Nextcloud. The sharing functions (public links, sharing between users of the instance, password protection, expiry dates) are functions of the Nextcloud software and are configured by the Customer within its instance. The Provider does not create these shares and does not act as an intermediary in them.
5.2. The Customer's liability for content. The Customer bears liability for the content stored and shared through its instance and undertakes not to share content infringing the law or the rights of third parties (section 7). The Provider does not proactively monitor content in Customers' instances.
5.3. Blocking unlawful content. Upon obtaining credible information about the unlawful nature of data stored by the Customer, the Provider may prevent access to that data, having first notified the Customer of the intended blocking. Where an official notification of the unlawful nature of the data is received, the obligation to notify the Customer in advance does not apply. Action in accordance with this clause releases the Provider from liability towards the Customer.
6. Infrastructure, data location and availability
6.1. Data location. Customers' virtual machines, their disks and snapshots are maintained on the Provider's infrastructure located in the territory of the Republic of Poland (European Union). The Provider does not transfer this data outside the European Economic Area.
6.2. Redundancy. The infrastructure layer maintains hardware redundancy, including redundancy of the power supply, of network connectivity and of the storage layer for the disks of the virtual machines. Redundancy does not replace the Customer's own backup (clause 4.5).
6.3. Availability (SLA). The availability parameters of the Service, the rules for reporting failures, scheduled maintenance and compensation are set out in the SLA Terms document, which forms an integral part of the contract. In particular:
- the guaranteed availability of access to the services via the Internet is 99.95% on an annual basis,
- scheduled maintenance is announced at least 12 hours in advance, takes place between 23:00 and 6:00 and does not last longer than 6 hours on any single occasion; in situations of heightened risk of failure the Provider may order scheduled maintenance disregarding these conditions, informing the Customer within the shortest possible time,
- if the availability parameters are not met, the Customer is entitled to compensation in the form of an extension of the subscription period by 1 month after 24 hours of unavailability and for each subsequent commenced 12 hours of interruption, granted following a positive determination of the complaint.
6.4. SLA exclusions. The availability parameters do not cover unavailability resulting from scheduled maintenance, force majeure, failure of equipment not forming part of the Provider's infrastructure, and also from the Customer's configuration, software or actions, including applications installed by the Customer in the Nextcloud instance. Detailed exclusions are set out in the SLA Terms document.
7. Acceptable use policy for the Service
7.1. It is prohibited to use the Service, including the Customer's Nextcloud instance, for:
a) storing, sharing or processing child sexual abuse material — we report every such case to the competent authorities without prior notification of the Customer;
b) infringing copyright and related rights, including the distribution of illegally copied works, software and other warez content;
c) distributing malicious software, software encrypting data for the purpose of extorting a ransom, exploits and tools serving unauthorised access;
d) phishing, fraud, sending unsolicited commercial communications and identity theft attempts;
e) distributing content inciting hatred or violence, content of a terrorist nature;
f) publishing the personal data of third parties without a legal basis;
g) processing data subject to special regulatory regimes (in particular medical data subject to United States regulations or full payment card numbers within the meaning of the PCI-DSS standard) without prior written arrangements with the Provider;
h) using resources in an excessive manner or in a manner inconsistent with the purpose of the Service, hindering the use of the infrastructure by other Customers.
7.2. Procedure upon suspicion of a violation. Where a violation is identified — on the basis of a report, automatic detection or notification from an authority — the Provider may prevent access to specific content or suspend the instance. The Customer receives a notification describing the violation and a deadline to respond, which as a rule is 7 days. In the case of violations indicated in clause 7.1 letter a, the block takes place immediately and without notice, and the matter is referred to the competent authorities.
7.3. Requests from authorities. The Provider complies with lawful requests from public authorities. We inform the Customer about a request if the law permits it.
8. Termination of the contract and deletion of data
8.1. Termination by the Customer. The Customer may at any time:
- cancel the subscription in the panel — the instance then operates until the end of the paid subscription period, after which it enters a state of scheduled decommissioning,
- request the immediate decommissioning of the instance, without waiting for the end of the subscription period.
8.2. Grace period. After decommissioning has been chosen, the instance and its snapshots are retained for 30 days, during which period the Customer may withdraw the decision. After that period, the virtual machine together with all its snapshots is permanently deleted.
8.3. Downloading data before decommissioning. The Customer may at any time download its data directly from the Nextcloud instance, in particular using the client applications or the export functions available in Nextcloud. We recommend downloading the data before the grace period expires.
8.4. Retention after decommissioning. Following the permanent deletion of the instance we retain solely:
- the infrastructure operations log stripped of data from inside the instance (timestamp, type of operation, status) — for 12 months, for security purposes and for complying with requests from authorities,
- accounting documentation (invoices, amounts, tax identification data) — for the period required by accounting and tax regulations, as a rule 5 years counted from the end of the financial year.
8.5. Termination by the Provider. The Provider may terminate the contract:
- with immediate effect — in the event of a violation of section 7, retaining the possibility of downloading the data for 14 days, unless a request from an authority precludes this,
- upon 30 days' notice — in the event of payment arrears exceeding 60 days from the payment due date of the first unpaid invoice,
- upon 90 days' notice — in the event of the Service being withdrawn from the offering.
9. Protection of personal data
9.1. The rules for processing the Customer's personal data (account data, billing data, technical data) are set out in the WebDisk Next Privacy Policy.
9.2. The rules for entrusting to the Provider the processing of personal data contained in the Customer's Nextcloud instance are set out in the Data Processing Agreement, accepted by the Customer upon purchase of the Service.
10. Processors
In providing the Service, the Provider uses the following categories of processors:
| Entity | Purpose | Location |
|---|---|---|
| The Provider's compute and storage infrastructure | Launching and maintaining virtual machines, storing disks and snapshots | Poland (EU) |
| Stripe Payments Europe Ltd. | Card payment handling | Ireland (EU); a transfer to the USA is possible on the basis of standard contractual clauses |
| Email operator | Sending transactional messages | EU |
We give 30 days' advance notice of changes to the list of processors. The Customer has the right to raise a reasoned objection on the terms set out in the Data Processing Agreement.
11. Reporting security incidents
11.1. The Customer shall immediately inform the Provider of a breach of the security of its account or instance (in particular of a takeover of access credentials or of the Nextcloud administration panel) at security@webdisk.io or via the ticket function in the panel. We accept abuse reports concerning the Service at abuse@webdisk.io.
11.2. In the event of a personal data breach on the Provider's side, we notify the President of the Personal Data Protection Office (UODO) within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR, and the Customers affected by the breach — without undue delay, if the breach may result in a high risk to their rights or freedoms (Article 34 GDPR).
12. Liability
12.1. The Provider provides the Service with due professional diligence and bears liability for damage caused by non-performance or improper performance of the contract.
12.2. The Provider is not liable for:
- defects and security vulnerabilities of the Nextcloud software and of applications installed by the Customer (section 3),
- content and configuration introduced by the Customer in the instance,
- the consequences of the Customer disclosing access credentials to unauthorised persons,
- loss of data resulting from the Customer's failure to maintain its own backup, despite the recommendation in clause 4.5,
- unavailability resulting from the circumstances indicated in clause 6.4.
12.3. The Provider's liability in damages covers actual loss, excluding lost profits, and is limited to the amount of the subscription fees paid by the Customer in the 12-month period preceding the event giving rise to the damage.
12.4. The limitations of liability set out in clauses 12.2 and 12.3 do not apply to damage caused intentionally, nor to the extent that mandatory provisions of law, in particular consumer protection provisions, do not permit their application.
13. Provisions concerning consumers
13.1. The provisions of this section apply to a Customer who is a consumer within the meaning of Article 22¹ of the Polish Civil Code, and also — to the extent indicated in Article 7aa of the Polish Act of 30 May 2014 on Consumer Rights — to a natural person concluding a contract directly related to that person's business activity, where it follows from the content of the contract that it is not of a professional nature for that person. In the event of a conflict with the remaining provisions of the Terms, the provisions of this section prevail.
13.2. Right of withdrawal from the contract. A consumer who has concluded a distance contract may withdraw from it within 14 days without giving a reason and without incurring costs, subject to clause 13.4. The period runs from the day on which the contract is concluded. Sending the statement before the deadline expires is sufficient to meet the deadline.
13.3. Manner of withdrawal. The statement of withdrawal may be submitted in any form, in particular by email to office@webdisk.io or in writing to: Mazura sp. z o.o., ul. Baśniowa 1C/2, 05-091 Ząbki. The consumer may use the model withdrawal form constituting Annex 2 to the Act on Consumer Rights, however this is not obligatory. The Provider promptly confirms receipt of the statement.
13.4. Provision of the service before the expiry of the withdrawal period. If the consumer requested that the provision of the Service begin before the expiry of the period for withdrawal from the contract, and subsequently withdrew from the contract, the consumer is obliged to pay for the performance rendered up to the moment of withdrawal — in an amount proportionate to the scope of the performance rendered up to that moment, taking into account the agreed price. The right of withdrawal does not apply if the Provider has fully performed the Service with the express and prior consent of the consumer, who was informed before the performance began of the loss of the right of withdrawal and acknowledged this.
13.5. Refund of payments. In the event of withdrawal, the Provider shall refund to the consumer the payments received — subject to clause 13.4 — promptly, no later than within 14 days of the day on which the statement is received, using the same means of payment, unless the consumer has expressly agreed to another method of refund which does not entail costs for the consumer.
13.6. Conformity of the service with the contract. The Service, being a digital service within the meaning of the Act on Consumer Rights, is subject to the provisions of Chapter 5b of that Act concerning the trader's liability for the lack of conformity of a digital service with the contract, including the right to demand that the service be brought into conformity with the contract and, in the cases specified in the Act — the right to a price reduction or to withdrawal from the contract.
13.7. Out-of-court means of dispute resolution. The consumer may make use of out-of-court means of handling complaints and pursuing claims, and in particular may:
- turn to the district (municipal) consumer ombudsman or to a social organisation whose statutory tasks include consumer protection,
- turn to the voivodeship inspector of the Trade Inspection with a request to initiate out-of-court dispute resolution proceedings or to conduct mediation,
- turn to the permanent arbitration court operating at the voivodeship inspector of the Trade Inspection.
Information on the out-of-court resolution of consumer disputes is available on the website of the Office of Competition and Consumer Protection: uokik.gov.pl. Use of these procedures is voluntary and requires the consent of both parties.
14. Complaints
14.1. In the event of non-performance or improper performance of the Service, the Customer has the right to submit a complaint.
14.2. A complaint may be submitted:
- by email to office@webdisk.io,
- in writing to: Mazura sp. z o.o., ul. Baśniowa 1C/2, 05-091 Ząbki,
- via the ticket function in the Customer panel.
14.3. The complaint should contain data enabling the identification of and contact with the Customer, an indication of the Service complained about, and a description of the circumstances justifying the complaint.
14.4. The Provider examines the complaint and provides a response within 14 days of the day of its receipt, to the address indicated by the Customer. The response contains a statement of reasons.
15. Final provisions
15.1. Amendments to the Terms. The Provider may amend the Terms for important reasons, in particular in the event of a change in the law, a change in the scope or manner of providing the Service, or a change in technical conditions. We inform about amendments by email 30 days in advance. A Customer who does not accept the amendments may terminate the contract before the date on which the amendments enter into force; until the end of the paid subscription period, the existing wording of the Terms applies to that Customer.
15.2. Language versions. In the event of discrepancies between the Polish and the English version of the Terms, the Polish version is binding.
15.3. Governing law. The governing law is Polish law. The choice of Polish law does not deprive the consumer of the protection resulting from mandatory provisions of the law of the country of the consumer's habitual residence.
15.4. Jurisdiction of the court. Disputes arising from the contract are settled by the common court having local jurisdiction over the Provider's registered office. The provision of the preceding sentence does not apply to a Customer who is a consumer — in such a case jurisdiction is determined in accordance with the general provisions.
15.5. Invalidity of provisions. If any provision of the Terms proves to be invalid or ineffective, the remaining provisions remain in force.
15.6. Contact. Questions concerning the Terms: legal@webdisk.io. Personal data protection matters: iod@webdisk.io. Technical reports: support@webdisk.io. Complaints and other matters: office@webdisk.io.
Mazura sp. z o.o. · WebDisk Next · Service Terms · version 1.0 · effective from 2026-07-25