ULOX Business Terms of Service
- Purpose and parties
- Commercial nature of the agreement
- Definitions
- Zero-knowledge architecture: scope and consequences
- Workspace creation and domain verification
- Custody of credentials and recovery phrase
- Authorised Users and administration
- Seats, capacity and billing
- Customer Data and roles of the parties
- Backups, continuity and export
- Loss of information: express allocation of risk
- Customer obligations
- Acceptable use
- Availability, maintenance and support
- Security and incidents
- Intellectual property
- Confidentiality
- Warranties and disclaimers
- Limitation of liability
- Claim period and duty to mitigate
- Indemnity
- Force majeure
- Suspension of the Service
- Term, termination and return of data
- Subprocessors and assignment
- Changes
- Entire agreement, severability and language
- Governing law and jurisdiction
- Contact
1. Purpose and parties
These Terms govern the contractual relationship between EUROPEAN DIGITAL STORES, S.L., registered office at Calle José Echegaray, 8, Edificio Alvia 3, offices 7 and 8, 28232 Las Rozas (Madrid), Spain, tax ID B-70983770 ("EDS", the "Provider" or "we"), and the legal entity or sole trader that contracts or uses ULOX Business (the "Customer").
ULOX Business is a corporate workspace with end-to-end encryption and a blind server architecture, in which the Provider has no technical ability to access Customer content. Its operation — and in particular its consequences for information recovery — is described in clause 4 and must be read carefully before contracting.
These Terms are supplemented by the Data Processing Addendum (DPA), the Business Privacy Policy, the Acceptable Use Policy and the Service Level Agreement, all of which form an integral part of the agreement (together, the "Legal Documents").
2. Commercial nature of the agreement
ULOX Business is offered exclusively to businesses, professionals, public bodies and entities acting within their trade or profession. The Customer declares that it is not contracting as a consumer and, accordingly, consumer protection legislation — including any right of withdrawal — does not apply.
The Customer represents that the individual accepting these Terms has sufficient authority to bind the entity they represent.
3. Definitions
| Workspace | The Customer's corporate environment in ULOX Business, tied to a verified domain and governed by its Administrator. |
|---|---|
| Administrator | The individual appointed by the Customer who creates the Workspace and manages onboarding, offboarding, roles and permissions. |
| Authorised User | An employee, contractor or third party granted access to the Workspace by the Customer. |
| Corporate Credential | An Authorised User's access identity (corporate email and password), independent of any personal ULOX account. |
| Recovery Phrase | A 24-word sequence (BIP-39 standard) generated on the Authorised User's device; the only way to recover access if the password is forgotten. |
| Customer Data | Any content the Customer or its Authorised Users create, transmit or store in the Service: messages, files, vault credentials, notes, documents and associated metadata. |
| Blind Server | An architecture in which the server stores only encrypted material it cannot interpret, holding no decryption keys. |
| Seat | A unit of contracted capacity enabling access for one (1) Authorised User. |
4. Zero-knowledge architecture: scope and consequences
ULOX Business encrypts Customer Data on the Authorised User's device, before it leaves it. Encryption keys are derived from credentials known only to the Customer and its Authorised Users, and are never transmitted to or held by the Provider. The Provider stores opaque encrypted material only.
The Customer expressly acknowledges and accepts that, as a direct and necessary consequence of this design:
- The Provider cannot read, decrypt, index, moderate, reconstruct or deliver Customer Data, not even at the request of the Customer, its Administrators or a public authority.
- The Provider cannot reset passwords for Corporate Credentials or restore access by any alternative means.
- Loss of a password together with its Recovery Phrase results in the permanent and irreversible loss of access to the Customer Data associated with that credential, with no technical mechanism — present or future — capable of reversing it.
- There is no back door, master copy, third-party key escrow or emergency recovery service. Their absence is deliberate and constitutes an essential feature of the Service, without which it could not be provided as offered.
The Customer declares that it assessed this feature before contracting and considered it essential and decisive in its decision, accepting the allocation of risk set out in clause 11.
5. Workspace creation and domain verification
Creating a Workspace requires (i) verification of ownership or control of the domain by publishing a DNS record, or the assignment of a subdomain operated by the Provider, and (ii) verification of the Administrator's email address.
The Customer warrants that it holds sufficient title over the domain it verifies and shall be liable to the Provider and to third parties for any claim arising from improper verification. The Provider may suspend or revoke a Workspace where there are reasonable grounds to suspect fraudulent verification.
6. Custody of credentials and recovery phrase
Custody of passwords and Recovery Phrases is the sole responsibility of the Customer and its Authorised Users. In particular, the Customer undertakes to:
- Establish and maintain a written internal policy for the custody and deposit of its Authorised Users' passwords and Recovery Phrases, covering onboarding, offboarding, extended absence, incapacity and termination.
- Instruct each Authorised User to keep their Recovery Phrase offline and secure at the moment the Service displays it.
- Ensure continued access to corporate information in the event any Authorised User becomes unavailable, without relying on Provider intervention, which is impossible.
- Notify the Provider immediately of any suspected credential compromise, without prejudice to taking the revocation measures available in the administration panel.
Failure to comply with these obligations gives rise to no liability for the Provider and excludes any claim based on the resulting loss of access.
7. Authorised Users and administration
The Customer is responsible for selecting its Authorised Users, for the roles and permissions it assigns them, for their use of the Service and for the timely revocation of their access. Actions performed by an Authorised User are attributed to the Customer for all contractual purposes.
The Customer undertakes to revoke without delay the access of Authorised Users who cease their relationship with it, and acknowledges that information an Authorised User legitimately accessed may have been copied locally, without the Provider having any means to prevent or reverse it.
8. Seats, capacity and billing
The Service is billed per contracted Seat, in accordance with the commercial terms in force at the time of contracting and accepted by the Customer during onboarding or in the applicable order. Specific commercial terms — amounts, tiers, frequency and taxes — are set out in the contracting process and applicable commercial documentation, and do not form part of this document.
Non-payment entitles the Provider to suspend the Service under clause 23, upon notice to the Customer.
9. Customer Data and roles of the parties
Customer Data is and remains the exclusive property of the Customer. The Provider acquires no rights over it beyond those strictly necessary to provide the Service.
For personal data protection purposes, the Customer acts as controller and the Provider as processor, on the terms of the Data Processing Addendum (DPA), which is deemed executed upon acceptance of these Terms.
10. Backups, continuity and export
The Service is not an archiving, records-custody or customer backup service.
The Provider maintains redundancy and infrastructure copy mechanisms for platform operational continuity. Such mechanisms:
- Are intended to restore the Service after an infrastructure failure, not to recover specific information on the Customer's request.
- Necessarily operate on opaque encrypted material: restoring them grants neither the Provider nor the Customer access to content whose keys have been lost.
- Do not constitute a warranty of recoverability of any specific data, nor a recovery point (RPO) or recovery time (RTO) commitment towards the Customer, save where expressly agreed in writing.
The Customer undertakes to maintain its own backups of information it deems critical, using the export and download features available in the Service or any other means at its disposal, at the frequency its risk assessment determines. The absence of such backups is attributable solely to the Customer.
11. Loss of information: express allocation of risk
This clause has been specifically negotiated and accepted by the parties, who acknowledge that the price of the Service has been set taking into account the allocation of risk established here.
The Customer assumes the risk of loss, inaccessibility, alteration or destruction of Customer Data in all of the following cases:
- Loss, forgetting or disclosure of passwords, Corporate Credentials or Recovery Phrases.
- Departure, absence, incapacity, death or lack of cooperation of any Authorised User holding credentials.
- Deletion, overwriting, access revocation or key rotation performed by the Customer or its Authorised Users, even in error.
- Failure, loss, theft, damage or compromise of the Customer's devices, networks or systems.
- Acts of third parties who obtained credentials for reasons not attributable to the Provider, including phishing directed at the Customer.
- Absence or inadequacy of the Customer's own backups under clause 10.
In such cases the Provider accepts no liability whatsoever, without prejudice to clause 19 regarding cases in which mandatory law does not permit exclusion.
The Customer acknowledges that, given the nature of the Service, taking out its own insurance or implementing additional business continuity measures are decisions exclusively for it, and that the Provider has expressly warned it of this through this clause.
12. Customer obligations
- Use the Service in accordance with the law, these Terms and the Acceptable Use Policy.
- Provide accurate information and keep it up to date.
- Inform its Authorised Users of how the Service works and of its consequences, in particular those described in clauses 4, 6 and 11.
- Comply with the legislation applicable to it regarding the information it stores, including employment law and data protection towards its own employees.
- Refrain from circumventing, altering or reverse engineering the Service's security mechanisms, save with the Provider's written authorisation.
13. Acceptable use
The Acceptable Use Policy applies. Material breach entitles the Provider to suspend or terminate the Service under clauses 23 and 24.
Given the Blind Server model, the Provider does not and cannot monitor stored content. Any Provider action in response to a breach will necessarily rest on external information available to it.
14. Availability, maintenance and support
The Provider will deliver the Service with the diligence of a professional provider, in accordance with the Service Level Agreement, which establishes a best-efforts obligation and not an obligation of result.
The Provider may carry out maintenance involving interruptions, endeavouring to schedule it in low-impact windows and giving reasonable notice where possible. Scheduled or emergency maintenance is not counted as unavailability.
15. Security and incidents
The Provider applies the technical and organisational measures described in the DPA. End-to-end encryption means that unauthorised access to the Provider's infrastructure does not, of itself, grant access to the content of Customer Data.
The Provider will notify the Customer without undue delay of security incidents affecting it of which it becomes aware, on the terms of the DPA. The Customer undertakes to notify the Provider of incidents it detects in its own environment that may affect the Service.
16. Intellectual property
The Service, its software, trade marks, interfaces and documentation belong to the Provider or its licensors. The Provider grants the Customer a non-exclusive, non-transferable, revocable licence, limited to the term of the agreement, to use the Service in accordance with these Terms.
Nothing in this agreement transfers to the Provider any right over the Customer's trade marks, content or data.
17. Confidentiality
Each party undertakes to keep confidential the other party's information accessed in connection with the agreement, during its term and for three (3) years thereafter, unless the information is public without breach, must be disclosed by law, or was lawfully obtained from a third party.
18. Warranties and disclaimers
The Service is provided "as is" and "as available". To the maximum extent permitted by applicable law, and without prejudice to clause 19, the Provider does not warrant that:
- The Service will meet the Customer's specific needs or purposes.
- It will operate uninterrupted, timely, secure or free from errors, defects or vulnerabilities.
- Customer Data will always be delivered, retained, recoverable or accessible.
- The Service will be compatible with third-party systems, devices or software not expressly supported.
All implied warranties of merchantability, fitness for a particular purpose and non-infringement are excluded to the maximum extent permitted by law.
19. Limitation of liability
To the maximum extent permitted by applicable law:
- Excluded damages. The Provider shall in no event be liable for indirect, consequential, special, incidental or punitive damages, nor for loss of profit, revenue, goodwill, business opportunity, reputation, anticipated savings, nor for loss, corruption or inaccessibility of data, keys, credentials or communications, even if advised of their possibility.
- Financial cap. The Provider's aggregate liability for any claims arising out of or relating to the agreement, on any basis, shall be limited to the amounts actually paid by the Customer to the Provider for the Service during the twelve (12) months immediately preceding the event giving rise to liability.
- Non-attributable events. The Provider shall not be liable for damages arising from the events listed in clause 11, from use of the Service by Authorised Users, from content stored by the Customer, or from failures of networks, devices or third-party services beyond its control.
- Mandatory limits. Nothing in these Terms excludes or limits the Provider's liability for wilful misconduct, gross negligence, death or personal injury, or in any case where mandatory law does not permit exclusion or limitation. In such cases, liability shall be limited to the greatest extent the law permits.
The above limitations also apply for the benefit of the Provider's directors, employees, contractors and suppliers.
20. Claim period and duty to mitigate
The Customer must notify the Provider in writing of any incident that may give rise to a claim within thirty (30) calendar days of the date on which it became aware, or could reasonably have become aware, of it, detailing the facts and the alleged loss. Failure to notify within that period, where it prevents the Provider from investigating or mitigating the incident, will be taken into account in determining recoverable loss.
Any action arising from the agreement shall lapse, to the maximum extent permitted by applicable law, one (1) year after it could have been brought.
The Customer undertakes to take reasonable steps available to it to mitigate loss, including the use of its own backups.
21. Indemnity
The Customer shall indemnify and hold harmless the Provider, its directors, employees, contractors and suppliers against any claim, demand, proceeding, penalty, loss, damage or expense (including reasonable legal fees) arising from: (i) content stored or transmitted through the Workspace; (ii) use of the Service by its Authorised Users; (iii) the Customer's breach of these Terms or of applicable law; and (iv) claims by its own employees, customers or third parties relating to the information hosted.
22. Force majeure
Neither party shall be liable for failure to perform due to causes beyond its reasonable control, including natural disasters, armed conflict, acts of authority, power or telecommunications outages, infrastructure provider failures, large-scale cyber attacks or pandemics. The affected party shall give prompt notice and both shall cooperate to minimise the effects.
23. Suspension of the Service
The Provider may suspend the Service in whole or in part, upon notice where circumstances permit, in the event of: (i) non-payment; (ii) material breach of the Acceptable Use Policy; (iii) demonstrated risk to the security or integrity of the platform or third parties; or (iv) a requirement from a competent authority.
Suspension does not release the Customer from accrued payment obligations and gives rise to no right to compensation where it results from a cause attributable to the Customer.
24. Term, termination and return of data
The agreement remains in force for the contracted period and its renewals, unless terminated under this clause. Either party may terminate for material breach by the other that is not remedied within fifteen (15) calendar days of written notice.
Upon termination, the Customer shall have thirty (30) calendar days to export its Customer Data using the Service's export features. After that period, the Provider shall delete the encrypted material in accordance with the DPA.
Given the Blind Server model, only the Customer can perform the export, using its own credentials. The Provider cannot extract, decrypt or deliver Customer Data in any readable format. Loss of credentials before export results in permanent loss of the information.
25. Subprocessors and assignment
The Provider may engage infrastructure and ancillary service providers, listed and kept up to date in the DPA, remaining liable for their performance on the terms set out there.
The Customer may not assign its contractual position without the Provider's written consent. The Provider may assign it in the context of a corporate transaction, giving notice to the Customer.
26. Changes
The Provider may amend these Terms for legal, technical or operational reasons, giving the Customer at least thirty (30) calendar days notice before they take effect. If the amendment materially prejudices the Customer, it may terminate the agreement without penalty before that date by written notice.
27. Entire agreement, severability and language
These Terms and the other Legal Documents constitute the entire agreement between the parties on their subject matter and supersede any prior agreement. The invalidity of one clause shall not affect the validity of the remainder, which shall be construed so as best to preserve the economic purpose of the agreement.
The Spanish version prevails over any translation in the event of discrepancy.
28. Governing law and jurisdiction
This agreement is governed by Spanish law. For the resolution of any dispute, the parties, expressly waiving any other jurisdiction to which they may be entitled, submit to the Courts of the city of Madrid (Spain).
29. Contact
- Email:
legal@ulox.org - Post: Calle José Echegaray, 8, Edificio Alvia 3, offices 7 and 8, 28232 Las Rozas (Madrid), Spain. Attn.: "Legal Department — ULOX Business".
