VPS SPECIAL TERMS
Specific terms applicable to our virtual private server offers.
This document is an English translation of the French original.
It is provided so that our English-speaking customers can read our terms in their own language.
Only the French version has legal value. If a sentence here differs from the French text, the French text applies. The French original is available at winheberg.com/autres/legal/cp-vps.
These VPS Specific Terms ("VPS ST") supplement Winheberg's General Terms of Use and Sale (GTSU) and set out the conditions of use of the Virtual Private Server (VPS) service. In the event of a contradiction between these VPS ST and the GTSU, the provisions of the VPS ST shall prevail for VPS use.
Article 1 – Purpose
The purpose of these VPS ST is to define the specific conditions applicable to the provision, administration and use of the Virtual Private Servers offered by Winheberg.
Article 2 – Orders
Orders are placed online through the Winheberg client area (billing.winheberg.com). An order is validated once payment has been received and confirmed. Winheberg reserves the right to refuse or cancel any order where abuse, fraud or non-payment is suspected.
Article 3 – Winheberg's obligations and liability
Winheberg undertakes to deliver VPS orders within an indicative time of 120 seconds after payment is received. Delays may occur, in particular where stock is unavailable, where payment requires manual validation, or during anti-fraud checks. Winheberg will inform the Client of any significant delay.
If delivery has not taken place within 24 hours, the Client may request a refund, either through the original payment method or as a credit in the client area, according to the terms agreed.
Winheberg cannot be held liable for delays caused by external factors (malfunctions at third-party suppliers, connectivity problems on the Client's side and so on).
Article 4 – Client obligations and liability
The Client is solely responsible for administering, configuring and securing its VPS, which includes in particular:
- Installing and updating software and operating systems.
- Managing access (user accounts, passwords, SSH keys).
- Applying security patches.
The Client must ensure that its VPS is configured in a secure environment, following network and system security best practice. The Client is also responsible for putting regular backups in place to protect its data.
4.1 Lawful use
Any use of a VPS for unlawful purposes — such as DDoS, port scanning, spam, IP hijacking, unlawful torrents, hosting illegal content or use as a malicious proxy — is strictly prohibited. Where this policy is breached, Winheberg reserves the right to suspend the service immediately and without notice. Prior notice may nonetheless be sent to the Client where the breach is minor, in which case the Client may remedy the situation within a reasonable period.
The Client remains liable for all legal consequences arising from the unlawful use of its VPS.
4.2 Analysis and security technologies
Winheberg deploys advanced analysis technologies to detect any potentially malicious or fraudulent activity. These tools may in particular analyse:
- Network traffic (protocols, logs) to identify suspicious behaviour (phishing, spam, DDoS, intrusion and so on).
- The IPv4 addresses in our blocks, analysed using specialised tools that monitor their use and detect any suspicious activity.
The Client accepts that these analyses are necessary to maintain the overall security of the infrastructure. In the event of suspicious or manifestly unlawful activity, Winheberg may suspend or terminate the service without notice, in accordance with Article 7.
4.3 Hosted content and activities
The Client is solely responsible for the data, websites, applications and content it hosts or distributes through its VPS. Winheberg cannot be held liable for unlawful content, or content contrary to public decency, hosted by the Client.
4.4 QEMU agent
Winheberg installs and configures the QEMU Guest Agent by default on VPS delivered with a predefined system image. This agent is essential to the proper operation of certain services, such as automated backups, fine-grained resource management and clean system shutdown.
Where the Client installs the operating system manually (for example from an ISO image), it is strongly recommended to install and configure this agent correctly. Failing that, Winheberg accepts no liability regarding backups, data consistency or system stability.
4.5 Technical logs
In addition to the logs common to all services defined in Article 6 of the GTSU, Winheberg collects the following technical logs specific to VPS services:
- Access logs for the VPS management panel: connecting IP address, timestamp, action performed;
- Hypervisor logs: virtual machine start, stop and migration events.
The legal basis, the purposes and the arrangements for disclosure to the authorities are those set out in Article 6 of the GTSU. The applicable retention periods are specified in Winheberg's Privacy Policy.
4.6 Automatic backups
Winheberg takes daily automatic snapshots of all VPS. These snapshots are kept on a rolling 7-day basis and are accessible directly from the client area, which allows the Client to launch a restore independently.
This feature is included in all VPS plans at no extra cost.
Winheberg does not, however, guarantee the integrity, completeness or availability of these snapshots, which constitute technical assistance and not an obligation of result. The Client remains solely responsible for putting independent backups in place to protect its critical data, in accordance with Article 13 of the GTSU.
4.7 Portability and data export
At any time during the term of the contract, the Client may retrieve the data hosted on its VPS by the following means:
- Direct access: SSH connection to the VPS, allowing the Client to transfer its data by its own means;
- Disk image export: on request through a support ticket, Winheberg may provide a disk image of the VPS in RAW or IMG format, depending on the technical capabilities available at the time of the request.
Where the service is suspended for non-payment, Winheberg may temporarily start the VPS so that the Client can retrieve its data, upon a request submitted through a support ticket.
Winheberg does not guarantee the compatibility of exported images with third-party infrastructures.
4.8 Prohibition on hosting sensitive data
The Client expressly undertakes not to host, transmit or process through its VPS the following categories of personal data:
- Health data (Art. L. 1111-2 of the French Public Health Code);
- Biometric data (Art. 9(1) GDPR);
- Genetic data (Art. 4(13) GDPR);
- Data relating to criminal convictions and offences (Art. 10 GDPR);
- Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerning sex life and sexual orientation (Art. 9(1) GDPR).
Where a breach is detected, Winheberg will proceed with:
- Immediate suspension without prior notice;
- Automatic termination of the contract 48 hours after notification, with no refund;
- Permanent deletion of the hosted data;
- Reporting to the authorities (CNIL, law enforcement) where appropriate.
Winheberg cannot be held liable for any damage resulting from the unauthorised hosting of such data or from its deletion under this clause.
For sensitive data hosting needs, consult the official list of HDS-certified hosting providers: https://esante.gouv.fr/offres-services/hds/liste-des-hebergeurs-certifies
Article 5 – Protocol restrictions
5.1 Initial blocking of certain protocols
To prevent abusive use (spam, phishing and so on), Winheberg applies an initial block on certain protocols for newly delivered VPS, such as:
- SMTP / SMTPS
- SQUID
- BitTorrent
5.2 Unblocking SMTP/SMTPS
The Client may request, through a ticket, that these ports be unblocked in order to send or receive legitimate email. Winheberg reserves the right to refuse or delay such unblocking where there is doubt about the intended use.
5.3 Client responsibility
The Client is responsible for the use of the unblocked protocols, in compliance with applicable law. In the event of abuse or non-compliance, Winheberg may suspend the service or reinstate the block on the protocols concerned.
Article 6 – Fair use policy
6.1 Fair use principle
The resources allocated to the VPS (CPU, RAM, disk, bandwidth) are subject to a fair use policy intended to guarantee an equitable quality of service for all Clients using the shared infrastructure.
6.2 Bandwidth limits
Bandwidth is unlimited in volume but subject to the following limits:
- Maximum throughput: limited according to the plan taken out (1 Gbit/s, 2 Gbit/s, 3 Gbit/s and so on)
- Excessive use: continuous saturation of the maximum allocated throughput for more than 12 consecutive hours will trigger automatic measures
Measures applied in the event of prolonged saturation:
- Notification: the Client is alerted by email as soon as continuous saturation is detected
- Proportionate throttling: if the saturation persists, throughput will be temporarily limited to 20% of the plan's initial throughput (e.g. a 1G plan → throttled to 200 Mbit/s)
- Support: Winheberg will contact the Client to propose a suitable solution (optimisation or migration to a higher plan)
- Lifting the throttle: the initial throughput will be restored as soon as the situation is regularised or the Client migrates to a suitable plan
- Suspension: in the event of established abuse (mass unlawful downloads, unauthorised proxy, unlawful activities), the service may be suspended
6.3 CPU limits
The allocated CPU resources must be used reasonably:
- Normal use: usage peaks are accepted as part of normal use
- Prolonged intensive use: continuous use of 100% of the CPU for more than 24 consecutive hours may be considered abusive
Overruns: in the event of prolonged excessive CPU use liable to affect the performance of other VPS:
- Winheberg will contact the Client to identify the cause
- The Client will be invited to optimise its applications or to migrate to a higher plan
- In the event of established abuse (cryptocurrency mining, unauthorised intensive computation), the service may be suspended
6.4 Disk limits
The allocated disk space corresponds to the capacity of the plan taken out:
- Storage space: limited according to the plan (e.g. 50 GB, 100 GB and so on)
- IOPS (input/output operations): intensive and prolonged read/write operations may be limited to preserve the overall performance of the shared storage
Overruns:
- Exceeding the allocated disk space will cause system errors
- In the event of excessive input/output operations affecting performance, Winheberg may contact the Client for optimisation or migration
6.5 Notification and regularisation
Where fair use limits are exceeded, Winheberg undertakes to:
- Prior notification: inform the Client by email of the overruns observed
- Regularisation period: allow a reasonable period of 48 hours for the Client to regularise the situation
- Support: propose suitable solutions (optimisation, migration to a higher plan)
Exception: in the event of serious abuse endangering the infrastructure or the services of other clients, Winheberg may act immediately without prior notice.
6.6 Monitoring and transparency
Winheberg provides the Client with monitoring tools through the client area, allowing it to track:
- CPU and RAM usage
- Bandwidth consumption
- Disk space used
The Client is encouraged to monitor its consumption regularly to avoid any overrun.
Article 7 – Abuse policy and suspension
The general rules on the abuse policy, suspension measures and applicable consequences are set out in Articles 17.1 and 17.2 of the GTSU. Those provisions apply as of right to VPS services.
Winheberg may nonetheless apply, in addition and where necessary, specific operational measures suited to the VPS service (temporary protocol blocks, filtering, resource limits, temporary preservation of evidence). Such measures will be notified to the Client through the client area when implemented.
Article 8 – Technical support
8.1 Access to support
The Client may contact Winheberg's technical support through the client area, by email or by telephone. Requests may be sent at any time through a ticket.
8.2 Support hours
Support is available 24/7 through the ticket system. Response times may vary depending on urgency.
8.3 Support coverage
Support covers issues relating to the availability of the VPS (outages, malfunctions). Internal configuration and application management are the Client's responsibility, unless a specific support offering has been taken out.
8.4 Response time
Winheberg endeavours to respond within an indicative time of 48 hours, Monday to Sunday. This time is indicative and may vary with request volumes and periods of heavy activity. Critical emergencies (complete service interruption) are handled as a priority as soon as they are received.
8.5 Nature of the support commitments
Support is available 24/7 for opening and receiving tickets. The contractual handling and first-response times remain those set out in these VPS ST.
Article 9 – Changes and developments
9.1 Changes to the terms
Winheberg may amend the VPS ST. Changes will be notified by email or through the client area within the periods set out below.
For business clients: Changes take effect after a 15-day notice period following their notification.
For consumers: Changes take effect 30 days after their notification. The Client has 30 days to accept the new terms or terminate the service without penalty. Failure to terminate within that period constitutes acceptance of the new terms.
9.2 Service developments
Winheberg may make technical changes or updates to the VPS services. The Client will be informed of significant changes through the client area.
9.3 Scheduled maintenance
Routine or urgent maintenance may be carried out on the infrastructure. The Client will be informed of possible interruptions.
Article 10 – Service level (SLA)
The service level (SLA) applicable to VPS is defined in Article 4 of the GTSU and, as regards DDoS incidents, by the DDoS Technical Annex. The availability commitments, the pro rata compensation arrangements and the reporting procedure are set out there.
Article 11 – Governing law
11.1 Governing law
These VPS ST are governed by French law. Any dispute shall be submitted to the courts having jurisdiction over Winheberg's registered office.
11.2 Dispute resolution
For business clients: Any dispute relating to these VPS ST shall be submitted to the courts having jurisdiction over Winheberg's registered office.
For consumers: The protective provisions of the French Consumer Code apply. Territorial jurisdiction remains that provided for by the law applicable to consumers.
Consumer mediation: In accordance with Articles L612-1 et seq. of the French Consumer Code, a Consumer Client has the right to use a consumer mediator free of charge to settle a dispute amicably, after having unsuccessfully attempted to resolve it directly with Winheberg. The contact details of the competent consumer mediator will be provided by Winheberg once appointed, in accordance with Article L616-1 of the French Consumer Code. For cross-border disputes, the Consumer may contact the European Consumer Centre France (ECC France): https://www.europe-consommateurs.eu/fr/
The Client undertakes to contact Winheberg's customer service to resolve any disagreement amicably before taking legal action.