Hacked or down? We step in within 5 hours
Let's talk

General Terms and Conditions

Effective: 26 September 2026

This English version is a translation for information. In case of any discrepancy, the Hungarian version prevails.

1. Scope

1.1. These General Terms and Conditions (Terms) apply to the IT services of upTools Kft. (the Provider) and to every individual contract between the Provider and the Client.

1.2. The Provider serves only businesses, public institutions and other organisations acting within their business or professional activity, in Hungary and abroad. It does not provide services to consumers (Hungarian Civil Code, Ptk. 8:1. § (1) point 3).

1.3. Every order is based on an individual offer. These Terms do not by themselves create a contract. Where the individual contract differs from these Terms, the individual contract prevails.

1.4. These Terms are available at uptools.io/terms/, and the Hungarian original at uptools.io/hu/terms/.

2. Provider details

  • Name: upTools Kft.
  • Registered office: 8220 Balatonalmádi, Árpád utca 17., Hungary
  • Registry court: Veszprémi Törvényszék Cégbírósága (Court of Registration of the Veszprém Regional Court)
  • Company registration number: 19-09-524059
  • Tax number: 32380356-2-19
  • Email: [email protected]
  • Website: uptools.io
  • Hosting provider of the website: upTools Kft. (own servers), 8220 Balatonalmádi, Árpád utca 17., [email protected]

3. Definitions

Client: a business, public institution or other organisation contracting with the Provider.

Parties: the Provider and the Client.

Individual contract: the individual offer accepted by the Client, or a separate contract signed by the Parties, together with its annexes.

Service: the system takeover, development, operations, scaling, emergency intervention or audit defined in the individual contract, or any combination of these.

SLA: a service level committed to in writing in the individual contract (for example availability, response time, method of measurement, exceptions).

Response time: the time from receipt of a report within which the Provider substantively contacts the Client or starts handling the matter. The response time is not a resolution deadline.

Business day: Monday to Friday, except public holidays in Hungary.

Business hours: 9:00 to 17:00 on business days, Hungarian time.

Intermediary: a third party acting on behalf of the Client, for example an agency.

In writing: on paper or by email.

4. Services

4.1. Within the scope defined in the individual contract, the Provider offers the following services:

  1. System takeover: auditing, taking over, stabilising and modernising existing, neglected or inherited systems, one at a time or several systems at once (a fleet).
  2. Development: designing, building and changing webshops, CRMs, internal systems, AI integrations and websites.
  3. Operations: managed operations, infrastructure and DevOps tasks, security updates, backups and monitoring, on the Provider’s servers or in the Client’s own environment.
  4. Scaling: performance optimisation, campaign readiness, conversion and analytics work, automation.
  5. Rescue and audits: emergency handling of hacked, broken or abandoned systems, as well as Rescue Audit, Revenue Leak Audit and Tech Due Diligence.
  6. PANIC mode: a priority emergency service with a surcharge, as described in section 7.

4.2. The specific tasks, systems, deadlines and deliverables are defined in the individual contract.

4.3. The Provider commits to availability, response times or other SLA targets (for example 99.9% availability) only if the individual contract sets them out in writing.

4.4. The Provider works during business hours. Round-the-clock on-call service, seven days a week, is part of the service only under a separate, paid written commitment.

5. Offers and conclusion of contract

5.1. The Client can request an offer through the contact form on the website or at [email protected]. The Provider replies to the request within one business day. A request for an offer is not an order and binds neither Party.

5.2. After assessing the task, the Provider makes an individual offer. The offer states the task, the fee, the deadlines, how long the offer is valid and how it can be accepted.

5.3. The contract is concluded when the Client accepts the offer in writing, or when the Parties sign a separate contract.

5.4. Where an Intermediary acts on behalf of the Client, the Intermediary warrants that it is authorised to do so. In white-label cooperation, the individual contract sets out how tasks and responsibilities are shared between the Intermediary, the end client and the Provider.

5.5. An accepted task can be changed (a new task, a wider scope) by written agreement of the Parties, with a new fee and deadline where needed.

6. Fees, invoicing and payment

6.1. The fee and its currency are set out in the individual contract. Value added tax is charged on the fees as required by law. The Provider does not publish prices on its website.

6.2. Unless the individual contract provides otherwise, the Provider invoices as follows:

  • operations and other recurring services: monthly, in advance;
  • project work: per milestone, after acceptance of that milestone (Ptk. 6:42. §);
  • ad hoc work (Rescue, PANIC mode, hourly tasks): after completion, at least monthly.

6.3. The Provider sends invoices electronically, by email. The Client pays by bank transfer within 8 days of receiving the invoice.

6.4. In case of late payment, the Client pays default interest under Ptk. 6:155. §: the central bank base rate valid on the first day of the calendar half-year affected by the delay, plus 8 percentage points. The Provider is also entitled to a flat-rate recovery cost of EUR 40 under Hungarian Act IX of 2016 on the flat-rate recovery cost.

6.5. In case of late payment, the Provider sends the Client a written reminder with a grace period of at least 8 days, starting from receipt of the reminder. If the grace period passes without payment, the Provider may suspend development work and new tasks until the fee is paid. The suspension does not affect the operation of the systems the Provider runs or the Client’s data: the Provider does not shut down the system and does not delete data. Termination is covered in section 16.

6.6. The fee in an accepted offer can only change by written agreement of the Parties.

7. Rescue and PANIC mode

7.1. Rescue. For an emergency request about a hacked, broken or abandoned system (marked as urgent on the contact form, or reported as an emergency at [email protected]), the Provider takes the first step within 5 hours of receipt, at any hour of the day, including weekends and public holidays. The first step is contacting the Client, a preliminary assessment of the situation, or starting the intervention. The 5 hours are not a deadline for fixing the problem.

7.2. PANIC mode. In PANIC mode, the Provider responds to the request within 1 hour, every day between 7:00 and 22:00, Hungarian time. For requests received between 22:00 and 7:00, the hour starts at 7:00 in the morning. A response is not the same as fixing the problem.

7.3. PANIC mode carries a surcharge, which the Client expressly accepts on the contact form. The amount and settlement of the surcharge are set out in the individual offer; work at the surcharge rate starts after the offer is accepted.

7.4. In an emergency, the Provider works to stabilise the system. It commits to recovering data only where this is technically possible from the available backups or from the state of the system.

8. Performance, delivery and acceptance

8.1. The Provider performs the task by the deadlines and milestones set out in the individual contract.

8.2. If a circumstance that was not known in advance comes to light during the work (for example a new fault, missing documentation, a hidden problem in a system taken over), the Provider informs the Client without delay. The Parties agree on any necessary change to the task, the fee or the deadline.

8.3. The Client examines the delivered result within 5 business days and reports any faults found in writing. If the Client reports no fault within this period, or puts the result into live use, the delivery is deemed accepted and the fee becomes due under section 6. Acceptance does not waive any claims for defective performance, in particular for faults that only become apparent later (section 10).

8.4. Acceptance cannot be refused because of a fault that does not prevent normal use (Ptk. 6:247. §). The Provider fixes such faults under section 10.

9. Client cooperation

9.1. The Client provides the access, permissions, information, decisions and approvals needed for performance on time (Ptk. 6:62. § (1)).

9.2. The Client warrants that it is entitled to give the Provider access to the systems, hosting, domains and accounts concerned.

9.3. If the Client’s cooperation is delayed, the Provider notifies the Client, and the deadline is extended by the time actually lost through the delay.

9.4. Where backups are not part of the Service, the Client is responsible for backing up its data.

9.5. The Client is responsible for the content stored in its systems and for its lawfulness.

10. Defective performance

10.1. The Client reports a fault in writing without delay after discovering it, together with the information needed to investigate it.

10.2. In case of defective performance, the Provider’s first remedy is to fix the fault within a reasonable time, with due regard to the Client’s interests. If the Provider does not undertake the repair, cannot complete it within a reasonable time with due regard to the Client’s interests, or the Client no longer has an interest in the repair, the Client may exercise its further rights under Ptk. 6:159. § (price reduction, withdrawal).

10.3. Warranty claims become time-barred one year after performance (Ptk. 6:163. § (1)).

10.4. It is not defective performance if the fault is caused by:

  • changes made by the Client or a third party after delivery;
  • use contrary to the documentation;
  • third-party software, services or environments outside the Provider’s responsibility;
  • in a system taken over, a fault that existed before the takeover, unless the Provider expressly undertook to fix it.

10.5. The Provider gives a guarantee only where the individual contract expressly says so.

11. Liability

11.1. The Provider’s liability for damage caused by breach of contract is limited, per incident and in total, to the fees actually paid under the individual contract concerned in the 12 months before the incident.

11.2. The Provider is not liable for lost profits or indirect damage.

11.3. The Provider is liable for data loss if backups were its task under the contract and it did not make the agreed backups. In that case its liability extends to restoring the last backup made in line with the contract.

11.4. The Provider is not liable for:

  • in a system taken over, faults, security holes and data leaks that arose before the takeover, and their consequences, unless it undertook to fix them;
  • outages of third-party services outside the Provider’s control (for example a payment provider, an external API, or a cloud provider chosen by the Client);
  • damage caused by the Client’s failure to cooperate.

11.5. Sections 11.3 and 11.4 do not release the Provider from the consequences of breaching its own obligations (for example agreed backups, checks or fault reporting).

11.6. None of the limitations in section 11 apply to breaches of contract committed intentionally, or causing harm to human life, physical integrity or health (Ptk. 6:152. §), or where the law provides otherwise.

12. Intellectual property and source code

12.1. Custom development. The economic rights in the source code, documentation and other results made specifically for the Client pass to the Client on full payment of the fee (Hungarian Copyright Act, Act LXXVI of 1999, Szjt. 58. § (3)), without territorial or time limits, covering reproduction, adaptation, distribution and communication to the public, and the right to license any of these to third parties. The author’s moral rights cannot be transferred (Szjt. 9. § (2)).

12.2. Until the fee is paid in full, the Client may use the result only for testing and acceptance.

12.3. Existing components. Libraries, tools and templates that the Provider developed earlier or for general use remain the Provider’s. In connection with the delivered system, the Client receives a non-exclusive licence to them, without territorial limits, for the full term of copyright protection. It covers the reproduction and adaptation needed to run, develop and fix the system. The Client may transfer this licence to a third party (for example a new provider, an affiliate or its own client) or sublicense it to them (Szjt. 46. § (1)).

12.4. Open-source and third-party components may be used under their own licence terms. On request, the Provider informs the Client about the relevant licence terms.

12.5. The Provider warrants that it has obtained from its staff and subcontractors the rights needed to fulfil sections 12.1 and 12.3.

12.6. In a system taken over, the rights in existing code and content do not change, and the Provider gives no warranty for them.

12.7. The Provider remains free to use the general know-how and methods gained during its work, without the Client’s confidential information.

13. Confidentiality and references

13.1. The Parties keep the other Party’s business, technical and financial information, access credentials and system security details confidential. They use them only to perform the contract, and pass them to third parties only to the extent needed for performance, under the same confidentiality obligation.

13.2. Confidentiality lasts for 5 years after the contract ends.

13.3. Information is not confidential if it is public, if the Party already knew it lawfully, or if the law or an authority requires its disclosure.

13.4. The Provider names the Client as a reference only with the Client’s prior written consent. It may publish anonymous case studies, which do not identify the Client and use rounded figures, without consent.

14. Personal data and data processing

14.1. Where the Provider processes personal data on behalf of the Client while providing the Service, the Parties conclude a data processing agreement under Article 28(3) of the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR). It forms an inseparable part of the individual contract.

14.2. The Client gives general prior authorisation to engage further processors (GDPR Article 28(2)). The Provider notifies the Client in advance and in writing of any new or replaced processor, and the Client may object.

14.3. The Provider explains how it handles personal data on its website in its privacy notice.

15. Subcontractors

15.1. The Provider may use subcontractors to perform the contract (Ptk. 6:129. §). It is liable for their conduct as if it had acted itself (Ptk. 6:148. § (1)).

16. Termination and handover

16.1. A contract concluded for a fixed term or a defined task ends on completion.

16.2. Either Party may terminate an indefinite contract (for example operations) in writing, without giving reasons, with 30 days’ notice (Ptk. 6:213. § (3)). This does not limit the right of termination under Ptk. 6:278. §; compensation for damage caused by such termination is governed by that section.

16.3. Either Party may terminate the contract in writing with immediate effect if the other Party:

  • commits a serious breach of contract;
  • seriously or repeatedly breaches the agreed SLA;
  • seriously breaches its confidentiality or security obligations;
  • is still late with payment after the grace period under section 6.5 has passed without payment (Ptk. 6:140. §).

16.4. Handover at termination. The Provider hands over to the Client the source code and documentation of the paid work and the access credentials to the systems, and cooperates with the new provider or the Client’s team as agreed by the Parties. Work beyond a normal handover is agreed separately, for a fee.

16.5. Within 30 days of termination, the Client decides whether the data stored on the Provider’s servers is to be returned or deleted (GDPR Article 28(3)(g)). If the Client does not decide, the Provider deletes the data after the 30 days. The data is deleted from backups within 90 days of termination at the latest. If deleted data would reappear through restoring a backup, the Provider deletes it again. None of this applies to data the law requires to be kept for longer.

16.6. The Parties settle accounts for the work done up to termination.

17. Force majeure

17.1. Neither Party is liable for a breach of contract caused by a circumstance outside its control that could not be foreseen when the contract was concluded, and which it could not reasonably have been expected to avoid or whose damage it could not have averted (Ptk. 6:142. §). Examples include natural disasters, war, epidemics, measures by authorities, or large-scale utility or network outages.

17.2. The affected Party notifies the other without delay. Performance of the affected obligations is suspended for as long as the obstacle lasts.

17.3. If the obstacle lasts longer than 30 days, either Party may terminate the contract with immediate effect.

18. Communication and complaints

18.1. The Parties communicate primarily by email: the Provider at [email protected], the Client at the address given in the individual contract.

18.2. Complaints can be sent to [email protected], or by post to the Provider’s registered office, stating the contract or system concerned and the substance of the complaint.

18.3. The Provider replies to complaints in writing, on the merits, within 15 days.

19. Governing law and disputes

19.1. The contract is governed by Hungarian law, in particular the Hungarian Civil Code (Act V of 2013, Ptk.).

19.2. The Parties first try to settle any dispute by negotiation.

19.3. If negotiation fails, the Parties submit to the exclusive jurisdiction of the Hungarian court competent for the Provider’s registered office. This also applies to Clients based outside Hungary.

20. Changes to these Terms

20.1. The Provider may change these Terms unilaterally only for the following reasons, and only to the extent the reason requires (Ptk. 6:191. § (4)):

  • a change in law or in a requirement of an authority;
  • the introduction of a new service, limited to the provisions on that service;
  • a change in the terms of a third party used by the Provider (for example an email sending or network provider);
  • a reason affecting the security of the systems or the data.

20.2. The Provider publishes any change on its website at least 30 days before it takes effect, and notifies existing Clients by email.

20.3. If the Client does not accept the change, it may terminate the contract with immediate effect before the change takes effect, settling accounts for work already done. If it does not terminate, the change applies to it from its effective date.

20.4. Changes do not affect the fees and deadlines in individual contracts already accepted.

21. Final provisions

21.1. Express acceptance. The following provisions of these Terms differ from the law or from usual practice (Ptk. 6:78. §): 6.5 (suspension), 8.3 (acceptance), 10.2 (repair first), 11 (limitation of liability), 13.4 (anonymous case studies) and 20 (unilateral changes). The individual offer highlights them separately, and the Client expressly accepts them with a separate statement when accepting the offer.

21.2. If any provision of these Terms is invalid, the other provisions remain unaffected.

21.3. If a Party does not exercise a right, this does not mean that it has waived it.

21.4. The English translation of these Terms is for information only; in case of any discrepancy, the Hungarian version prevails.