Legal
Terms & Conditions
These terms govern your use of the platform at zopit.cloud. Vault Content is encrypted on your device before it reaches our servers — we store it in encrypted form and cannot decrypt or read it. The following documents form part of your agreement with us.
Document 01
Zopit Cloud Terms
By creating an account or using the platform at zopit.cloud to store, manage, request, or share information, you accept these Zopit Cloud Terms. If you are acting on behalf of a business, organization, school, institution, professional practice, or other commercial entity, you confirm that you have authority to accept these Zopit Cloud Terms on its behalf.
These Zopit Cloud Terms govern your use of the platform. Information and files you choose to keep in your vault are referred to as "Vault Content".
Vault Content is encrypted on users' devices before it reaches our servers. We store it in encrypted form and cannot decrypt or read it. This protection of Vault Content is distinct from the processing of account, support, technical, and payment information described in the Privacy Policy.
1. Your Vault and Your Responsibility
You decide what to store in your vault and what to share, and you are responsible for those choices and your use of the platform.
Zopit Cloud does not impose rules about the subject matter of Vault Content. We do not review, approve, classify, or monitor what you put in your vault. We cannot decrypt or read it.
2. Encrypted Storage
The platform stores, transmits, and backs up encrypted data as necessary to provide the vault services and the sharing you authorize.
We do not receive your master password or the keys needed to decrypt your vault. We do not read or analyze the underlying Vault Content or use it for advertising or product improvement.
3. Payments
The platform uses Stripe Connect for payment processing. Stripe handles payment-card data and processes payment transactions for the Services. Stripe manages the security of card-data collection and payment processing within its systems.
We do not store the payment-card details used to pay for the Services, including card numbers and card security codes, in our systems. We retain account and transaction records as described in the Privacy Policy, separately from payment-card details handled by Stripe.
This describes payments for the Services. Any financial information you choose to keep inside your encrypted vault remains Vault Content; it is not provided to Stripe for payment processing merely because you store it in the vault.
Subscriptions to the platform services are subject to the Refund & Cancellation Policy included in these Zopit Cloud Terms.
4. Service Access
We may restrict or suspend access to the platform where necessary to address non-payment, payment fraud, unauthorized account access, interference with platform security, or a technical incident, or to comply with a binding legal requirement.
These measures concern operation of the service and do not involve decryption or inspection of Vault Content. Nothing in these Zopit Cloud Terms changes obligations that apply under mandatory law.
We may act without prior notice where immediate action is necessary or appropriate.
5. Account Misuse
Attempting to access another user's account without authorization, bypassing platform security, disrupting the platform's infrastructure, or committing payment fraud may result in restriction, suspension, or cancellation of your account.
Where an account is cancelled for such misuse, we may cancel active subscriptions, restrict future access, and preserve available account, payment, and security records for compliance, dispute, or enforcement purposes. This does not give us access to decrypted Vault Content.
6. Indemnity
You agree to indemnify, defend, and hold harmless the platform provider, its directors, officers, employees, contractors, affiliates, suppliers, hosting providers, payment providers, and partners from and against any claims, demands, damages, liabilities, losses, costs, expenses, legal fees, penalties, or proceedings arising from or related to:
- your use of the platform;
- your breach of these Zopit Cloud Terms;
- your violation of applicable law.
7. Data Protection and Privacy
The Privacy Policy describes the processing of personal data in connection with the platform.
Where applicable, you agree to comply with data protection laws, confidentiality obligations, internal policies, and any data processing agreement entered into with the platform provider.
8. Master Password, Vault Access, and Security
You are responsible for managing access to your account and vault and for deciding which recipients may receive which items or fields. Sharing your Zopit Cloud code permits requests for access; it does not by itself authorize access to Vault Content.
IMPORTANT — IF YOU FORGET YOUR MASTER PASSWORD, YOU LOSE ACCESS TO YOUR VAULT.
Your master password is the secret used to derive the keys that encrypt and decrypt your vault on your device. We do not know, receive, or store your master password, and we do not hold the keys needed to decrypt your vault. Keeping that secret is your responsibility.
If you forget or lose your master password, you will lose access to your vault and its contents. We cannot retrieve or reset the master password, decrypt the vault, or restore access for you. Account or billing support cannot recover it.
You may change your master password only if you know your current master password. A password change is not a recovery or reset method for a forgotten master password.
To the extent permitted by applicable law, we are not responsible for loss of access resulting from your forgetting or losing your master password. This does not limit any liability that cannot lawfully be excluded.
You may revoke a share or set an expiry through the platform. Revocation or expiry ends access through the platform; it does not erase information a recipient has already copied or retained outside it.
You must not share your Zopit Cloud account credentials, bypass access controls, attempt to access restricted areas, interfere with the platform's technical protections, or enable unauthorized access to content.
You must promptly notify us if you become aware of unauthorized access, account compromise, security incidents, or misuse of your account.
9. Platform Security
You must not attempt to circumvent, disable, interfere with, reverse engineer, or bypass any access control, encryption, sharing permission, security feature, or technical restriction used by the platform.
10. Confidentiality
In the course of using the platform, each party (the "Receiving Party") may gain access to non-public information belonging to the other party (the "Disclosing Party"). "Confidential Information" means any non-public information disclosed by or on behalf of the Disclosing Party that is identified as confidential or that a reasonable person would understand to be confidential given its nature or the circumstances of disclosure.
Confidential Information may include, but is not limited to:
- for the user: encrypted Vault Content and non-public account information, business plans, and internal materials;
- for the platform provider: non-public pricing arrangements, unreleased features, technical architecture, security measures, and other proprietary business or operational information.
The Receiving Party agrees to (a) use the Disclosing Party's Confidential Information only as necessary to use or provide the platform; (b) protect it using at least the same degree of care it uses for its own confidential information, and no less than a reasonable degree of care; and (c) not disclose it to any third party except to employees, contractors, or service providers who need to know it and who are bound by confidentiality obligations at least as protective as those set out here.
These obligations do not apply to information that is or becomes publicly available through no fault of the Receiving Party, was already lawfully known to the Receiving Party without a duty of confidentiality, is independently developed without use of the Confidential Information, or is rightfully received from a third party without restriction.
The Receiving Party may disclose Confidential Information where required by law, regulation, court order, or a competent authority, provided that, where legally permitted, it gives the Disclosing Party reasonable prior notice so that party may seek protective measures. These confidentiality obligations survive termination of these Zopit Cloud Terms. Nothing in this section grants access to, or requires disclosure of, your master password, decryption keys, or decrypted Vault Content to us or our service providers.
11. Availability and Platform Control
The platform may modify, suspend, limit, or discontinue any service, feature, storage capacity, vault functionality, sharing feature, access method, or technical capability where necessary for security, maintenance, legal compliance, provider requirements, operational stability, or business reasons.
We do not guarantee uninterrupted availability of the platform or continuous availability of any specific encrypted stored data or feature.
12. Account Records
You agree that the platform may retain available technical, transactional, operational, and compliance records relating to your account and use of the platform, including access logs, payment records, account and payment dispute records, legally required records, and security events. These records do not include Vault Content in decrypted form.
Such records may be used for platform operation, customer support, legal compliance, account security, payment fraud prevention, dispute resolution, and protection of the platform and its users.
13. Acceptance
By creating an account or using the platform, you confirm that you have read, understood, and accepted these Zopit Cloud Terms.
If you are acting on behalf of another person or entity, you confirm that you are authorized to act on behalf of the account holder.
14. Addendums
The following addendums form part of these Zopit Cloud Terms and are acknowledged when you accept them:
- Data Processing Addendum (GDPR)
- Privacy Policy
- Refund & Cancellation Policy
Document 02
Data Processing Addendum (GDPR)
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Orione OÜ (“Processor”, “we”, “our”, or “us”) and the customer identified in the applicable service agreement (“Controller”, “you”, or “Customer”).
This DPA applies whenever the Processor processes Personal Data on behalf of the Controller in connection with the Services.
Vault Content is encrypted on users' devices before transmission to the Processor. The Processor stores and transmits it in encrypted form and cannot decrypt or read it. This DPA does not authorize the Processor or its subprocessors to decrypt Vault Content or obtain users' master passwords or decryption keys.
Personal Data processed by the Company as a controller for its own account administration, billing, security, and support purposes is addressed in the Privacy Policy and is outside the scope of this DPA.
1. Definitions
Unless otherwise defined herein, capitalized terms have the meanings assigned to them in the Agreement.
For purposes of this DPA:
- Applicable Data Protection Law means Regulation (EU) 2016/679 (General Data Protection Regulation or “GDPR”), the UK GDPR where applicable, and any applicable national implementing legislation, together with any amendments or successor legislation.
- Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given in the GDPR.
- Customer Data means any information, including Personal Data, submitted, uploaded, transmitted, stored, or otherwise processed through the Services on behalf of the Controller.
2. Scope
This DPA applies solely to the Processing of Personal Data carried out by the Processor on behalf of the Controller in connection with the Services.
The Controller determines the purposes and means of Processing.
The Processor processes Personal Data solely on behalf of the Controller.
3. Roles of the Parties
For Personal Data processed under this DPA:
- the Customer acts as the Data Controller, except where it acts as a Processor for another controller; and
- the Company acts as the Data Processor.
Where the Customer itself acts as a Processor, it warrants that it has appropriate authorization from the relevant Controller to appoint the Company as a subprocessor.
4. Subject Matter and Duration
The Processor shall process Personal Data only for the purpose of providing, maintaining, securing, supporting, and improving the Services in accordance with the Agreement.
Processing continues for the duration of the Agreement unless otherwise required by law.
5. Categories of Personal Data
Depending upon the Services used, Personal Data may include:
- names;
- email addresses;
- usernames;
- account identifiers;
- IP addresses;
- device identifiers;
- authentication data;
- billing information;
- communication records;
- usage and diagnostic data;
- encrypted Vault Content, including files and documents;
- metadata generated during use of the Services; and
- any other Personal Data submitted by the Controller.
The Controller determines the categories of Personal Data submitted to the Services. Vault Content may include identity documents, financial information, credentials, and other private information selected by the Controller; the Processor cannot inspect those contents.
6. Categories of Data Subjects
Data Subjects may include:
- customers;
- employees;
- contractors;
- suppliers;
- business partners;
- website visitors;
- authorized users;
- end users; and
- any other individuals whose Personal Data is submitted by the Controller.
7. Processor Obligations
The Processor shall:
- process Personal Data only on documented instructions from the Controller unless required otherwise by applicable law;
- ensure personnel authorized to process Personal Data are subject to confidentiality obligations;
- implement appropriate technical and organizational measures;
- assist the Controller in fulfilling its obligations under Applicable Data Protection Law;
- notify the Controller of Personal Data Breaches as required by this DPA; and
- not sell Customer Personal Data or process it for unrelated commercial purposes.
The Processor shall not determine the purposes for which Customer Personal Data is processed.
8. Customer Responsibilities
The Controller is responsible for:
- ensuring a lawful basis for Processing;
- providing required privacy notices;
- obtaining required consents where applicable;
- responding to Data Subject requests;
- ensuring uploaded Personal Data complies with applicable law;
- determining retention periods; and
- ensuring that instructions given to the Processor comply with Applicable Data Protection Law.
9. Confidentiality
The Processor shall ensure that all personnel with access to Personal Data:
- receive appropriate privacy and security training;
- are subject to confidentiality obligations; and
- access Personal Data only where necessary for their duties.
This does not permit access to decrypted Vault Content, master passwords, or decryption keys.
10. Security Measures
The Processor shall implement appropriate technical and organizational measures appropriate to the risks involved.
Security measures may include:
- encryption in transit using industry-standard protocols;
- encryption at rest where appropriate;
- logical access controls;
- role-based permissions;
- authentication controls;
- multi-factor authentication for administrative access where appropriate;
- infrastructure monitoring;
- audit logging;
- vulnerability management;
- malware protection;
- network security controls;
- regular backups;
- disaster recovery procedures;
- change management processes; and
- periodic review of security controls.
Security measures may be updated over time provided that the overall level of protection is not materially reduced.
11. Subprocessors
The Controller authorizes the Processor to engage subprocessors necessary for providing the Services.
The Processor shall:
- conduct reasonable diligence before appointing subprocessors;
- enter into written agreements imposing data protection obligations substantially equivalent to those contained in this DPA; and
- remain responsible for the performance of its subprocessors to the extent required by law.
A current list of subprocessors shall be made available upon request or published on the Company’s website.
12. International Transfers
Where Personal Data is transferred outside the European Economic Area, the United Kingdom, or another jurisdiction requiring appropriate safeguards, the Processor shall implement a lawful transfer mechanism, including where appropriate:
- an adequacy decision;
- the European Commission’s Standard Contractual Clauses;
- the UK International Data Transfer Addendum; or
- another lawful transfer mechanism recognized by Applicable Data Protection Law.
13. Data Subject Requests
Taking into account the nature of Processing, the Processor shall provide reasonable assistance to enable the Controller to respond to requests concerning:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection; and
- other applicable rights.
If the Processor receives a request directly from a Data Subject, it shall promptly notify the Controller unless prohibited by law.
14. Security Incidents
The Processor shall notify the Controller without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available, the notification shall include:
- the nature of the breach;
- affected categories of Personal Data;
- likely consequences;
- measures taken or proposed to address the breach; and
a contact point for further information.
The Processor shall cooperate with the Controller in investigating and mitigating the breach.
15. Government Requests
Unless legally prohibited, the Processor shall promptly notify the Controller of any legally binding request from a public authority seeking disclosure of Customer Personal Data.
Where appropriate, the Processor may challenge requests that appear unlawful or disproportionate.
16. Audits
The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.
Where required by Applicable Data Protection Law, the Controller may conduct an audit or appoint an independent auditor, provided that:
- reasonable advance notice is given;
- audits occur during normal business hours;
- confidentiality is maintained; and
audits do not unreasonably interfere with the Processor’s operations.
The Processor may satisfy audit obligations by providing current independent security certifications, audit reports, or similar documentation where appropriate.
17. Return and Deletion of Data
Upon termination of the Services, and subject to applicable law and documented backup procedures, the Processor shall, at the Controller’s choice:
return Customer Personal Data; or
securely delete Customer Personal Data.
The Processor may retain Personal Data where required by applicable law or necessary for legitimate backup, security, legal compliance, or dispute resolution purposes, provided that such retained data remains protected under this DPA.
Return of Vault Content means return in its encrypted form. The Processor cannot provide decrypted Vault Content or retrieve or reset a user's master password. A user who forgets or loses the master password loses access to the vault; the Processor cannot restore that access. A user may change the master password only if they know the current master password. Any retained Vault Content remains encrypted. These technical limitations do not remove the Processor's applicable assistance or deletion obligations.
18. Liability
Each party remains liable for its own compliance with Applicable Data Protection Law.
Nothing in this DPA limits liability where such limitation is prohibited by law.
Except as otherwise required by law, liability under this DPA shall be governed by the liability provisions of the Agreement.
19. Changes in Law
Where Applicable Data Protection Law changes, the parties shall cooperate in good faith to amend this DPA as reasonably necessary to maintain compliance.
20. Order of Precedence
In the event of any conflict between this DPA and the Agreement concerning the Processing of Personal Data, this DPA shall prevail to the extent of that conflict.
Annex A – Description of Processing
Subject Matter
Provision of the Company’s encrypted vault storage and sharing services and related support services.
Purpose of Processing
- user authentication;
- account administration;
- encrypted storage and transmission of Vault Content;
- customer support;
- security monitoring;
- service delivery;
- billing;
- analytics;
- system maintenance; and
other documented instructions from the Controller.
These purposes apply only to Processing on behalf of the Controller and do not include decryption, reading, or analysis of Vault Content.
Categories of Personal Data
As described in Section 5.
Categories of Data Subjects
As described in Section 6.
Duration
For the duration of the Agreement, together with any lawful retention period.
Annex B – Technical and Organizational Measures
The Processor maintains a security program that includes measures appropriate to the risks associated with the Processing of Personal Data, including:
- documented security policies;
- employee confidentiality obligations;
- secure development practices;
- encrypted communications;
- access management;
- logging and monitoring;
- vulnerability scanning and remediation;
- incident response procedures;
- business continuity and disaster recovery planning;
- regular backups;
- periodic security reviews; and
ongoing evaluation and improvement of security controls.
The Processor may update these measures over time, provided that the level of protection is not materially diminished. Vault Content remains encrypted before it reaches the Processor, and the Processor does not receive the master password or keys needed to decrypt it.
Document 03
Privacy Policy
1. Introduction
Welcome to Orione OÜ (“Company,” “we,” “our,” or “us”). We own this service and we respect your privacy and are committed to protecting your personal information.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use our website, applications, services, and related products (collectively, the “Services”).
By using our Services, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for processing personal data is:
- Company: Orione OÜ
- Email: support@zopit.cloud
3. Information We Collect
Depending on how you use the Services, we may collect the following categories of information.
Account Information
- Full name
- Email address
- Username
- Password (stored only in encrypted or hashed form)
- Organization or company name
- Profile information
Contact Information
When you communicate with us, we may collect:
- Name
- Email address
- Telephone number
- Correspondence
- Support requests
Usage Information
We automatically collect technical information, including:
- IP address
- Browser type
- Operating system
- Device identifiers
- Language preferences
- Time zone
- Pages visited
- Features used
- Date and time of access
- Error logs
- Performance metrics
Vault Content
You may store private information and files in your vault, including passwords, card and bank details, identity documents, notes, images, documents, and other files. Vault Content is encrypted on your device before it reaches our servers. We receive and store it in encrypted form and cannot decrypt or read it.
Other Information You Provide
Account information, support correspondence, and service configuration information are separate from Vault Content. Information you send directly to support is available to us; please do not send your master password, decryption keys, or decrypted Vault Content.
Payment Information
We use Stripe Connect for payment processing. Stripe handles payment-card data, processes payment transactions for the Services, and manages the security of card-data collection and payment processing within its systems. Stripe processes personal data under its own privacy policy, available at https://stripe.com/privacy.
We do not store payment-card details used to pay for the Services, including card numbers and card security codes, in our systems. Account, invoice, and transaction records are separate from those payment-card details and may be processed for billing, support, and the other purposes described in this Policy.
Card or bank details you choose to keep in your encrypted vault remain Vault Content. Storing them in the vault does not submit them to Stripe or use them to make a payment.
4. How We Use Personal Data
We process personal data to:
- Provide the Services
- Create and manage user accounts
- Authenticate users
- Deliver requested functionality
- Process transactions
- Respond to customer support requests
- Improve products and services
- Maintain system security
- Detect fraud, abuse, and unauthorized activity
- Monitor service performance
- Comply with legal obligations
- Communicate important service notices
- Send marketing communications where permitted by law
These purposes do not authorize us to decrypt or read Vault Content. We use encrypted Vault Content only for the technical operations necessary to provide the vault services, including storage, transmission, backups, and security.
5. Legal Basis for Processing
Where the General Data Protection Regulation (GDPR) applies, we process personal data based on one or more of the following legal grounds:
- Performance of a contract
- Compliance with legal obligations
- Legitimate interests
- Your consent
- Protection of vital interests where applicable
6. Cookies and Similar Technologies
We use cookies and similar technologies to:
- Keep users signed in
- Remember preferences
- Improve website functionality
- Measure performance
- Analyze usage
- Maintain security
You may control cookies through your browser settings. Some Services may not function correctly if cookies are disabled.
7. Analytics
We may use analytics providers to understand how users interact with our Services.
Analytics information may include:
- Device information
- Session duration
- Pages viewed
- Navigation paths
- Referring websites
- Approximate location derived from IP address
Analytics data is generally aggregated and used to improve the Services. It does not include decrypted Vault Content, your master password, or decryption keys.
8. Encrypted Vault Content and Sharing
Vault Content is encrypted on your device before it reaches our servers. Your master password is used to derive encryption keys on your device. We do not know, receive, or store it, and we do not hold the keys needed to decrypt your vault.
If you forget or lose your master password, you lose access to your vault and its contents. We cannot retrieve or reset the master password, decrypt your vault, or restore access for you. You may change the master password only if you know your current master password.
Sharing your Zopit Cloud code allows others to request access; it does not itself give them access to Vault Content. You choose whether to approve a request and which items or fields to share. Shared information is encrypted for the recipient you select.
You may set an expiry or revoke a share through the platform. This ends access through the platform but does not erase information a recipient has already copied or retained outside it.
These protections concern Vault Content. Account, support, technical, and payment information is processed separately as described in this Policy.
9. Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, destruction, or accidental loss.
Security measures may include:
- Encryption during transmission
- Encryption at rest where appropriate
- Access controls
- Authentication mechanisms
- Security monitoring
- Logging
- Regular software updates
- Vulnerability management
- Backup procedures
Although we strive to protect personal information, no method of transmission or storage is completely secure.
10. Sharing of Personal Data
We may share personal data with:
- Service providers
- Cloud infrastructure providers
- Payment processors
- Analytics providers
- Identity verification providers
- Professional advisers
- Auditors
- Regulatory authorities
- Law enforcement agencies when legally required
Service providers are permitted to process personal data only for authorized purposes and under contractual confidentiality obligations.
Vault Content provided to storage or infrastructure providers remains encrypted and cannot be decrypted by us or those providers. The sharing described in this section does not authorize disclosure of your master password, decryption keys, or Vault Content in decrypted form.
We do not sell personal information.
11. International Data Transfers
Your information may be processed in countries other than your country of residence.
Where required by applicable law, we implement appropriate safeguards for international transfers, including:
- Standard Contractual Clauses
- Adequacy decisions
- Other legally recognized transfer mechanisms
12. Data Retention
We retain personal data only for as long as necessary to:
- Provide the Services
- Fulfill contractual obligations
- Resolve disputes
- Maintain security
- Comply with legal obligations
- Enforce our agreements
When information is no longer required, we securely delete, anonymize, or otherwise dispose of it in accordance with applicable law. Any Vault Content retained in storage or backups remains encrypted. Ending a share is distinct from deleting stored data or backups.
13. Your Privacy Rights
Depending on applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate information
- Delete personal data
- Restrict processing
- Object to processing
- Withdraw consent
- Receive a portable copy of your information
- Lodge a complaint with a supervisory authority
Requests may be submitted using the contact details provided below.
14. Account Management
Users are responsible for maintaining the confidentiality of their account credentials.
If you believe your account has been compromised, please notify us immediately.
15. Third-Party Services
The Services may integrate with third-party products or services.
Your use of third-party services is governed by their own privacy policies and terms. We are not responsible for the privacy practices of independent third parties.
16. Children’s Privacy
The Services are not directed to children under the age required by applicable law.
We do not knowingly collect personal information from children without appropriate legal authorization.
If we become aware that such information has been collected unlawfully, we will take reasonable steps to delete it.
17. Business Transfers
If our business is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to applicable law.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Material changes will become effective when the updated version is published or as otherwise required by applicable law.
The “Last Updated” date indicates the most recent revision.
19. Contact Us
If you have questions regarding this Privacy Policy or wish to exercise your privacy rights, please contact us:
Email: support@zopit.cloud
Where required by law, you may also contact your local data protection authority.
Document 04
Refund & Cancellation Policy
1. Purpose
This Refund & Cancellation Policy explains the terms governing subscription cancellations, refunds, billing adjustments, and payment disputes for the services provided by Orione OÜ (“Company,” “we,” “our,” or “us”).
By purchasing or subscribing to our Services, you agree to this Policy.
2. Subscription Services
Our Services are provided on a subscription basis unless otherwise stated.
Subscription plans may be billed:
- Monthly
- Annually
- Per-user
- Usage-based
- Under a custom B2B agreement
Subscription fees are charged in advance for each billing period.
3. Free Trials
If we offer a free trial:
No payment may be required until the trial ends unless otherwise specified.
The trial automatically expires at the end of the stated period.
If payment details are collected during registration, your subscription may automatically renew unless cancelled before the trial expires.
Trial eligibility is limited to new customers unless expressly stated otherwise.
4. Cancellation
You may cancel your subscription at any time through your account settings or by contacting our support team.
Cancellation:
Stops future automatic renewals.
Does not affect charges already incurred.
Remains effective at the end of the current billing period unless otherwise specified.
After cancellation, you may continue using the Services until the end of your paid subscription term.
5. Refund Policy
Unless required by applicable law or expressly stated in a separate agreement, subscription fees are generally non-refundable once a billing period has begun.
Refunds may be considered under the following circumstances:
Eligible Refund Requests
We may approve a full or partial refund where:
- duplicate payments were processed;
- an incorrect amount was charged due to a billing error;
the Service could not be provided because of a verified technical failure attributable to us;
a refund is required by applicable consumer protection laws; or
we determine, at our sole discretion, that exceptional circumstances justify a refund.
Refund approvals remain at our sole discretion except where prohibited by law.
6. Situations Not Eligible for Refund
Refunds are generally not available for:
- unused subscription time;
- partial billing periods;
- failure to cancel before renewal;
- dissatisfaction after substantial use of the Service;
- user error or accidental purchases;
- changes in business requirements;
- incompatibility caused by unsupported hardware or software;
- suspension or termination resulting from violations of our Terms of Service;
third-party service interruptions outside our reasonable control.
7. Consumer Rights
Nothing in this Policy limits any mandatory statutory rights available under applicable consumer protection laws.
Where legislation grants consumers a right of withdrawal or refund, those statutory rights prevail over this Policy.
If digital services have begun immediately at your express request and you acknowledged that your withdrawal rights may be affected, any applicable statutory exceptions may apply in accordance with local law.
8. B2B Agreements
Customers operating under separate enterprise, reseller, partner, or negotiated agreements are governed by the refund provisions contained in those agreements.
Where those agreements conflict with this Policy, the negotiated agreement prevails.
9. Billing Errors
If you believe you have been charged incorrectly, please contact us promptly.
To help us investigate, include:
- account email;
- invoice number;
- transaction reference;
- payment date;
description of the issue.
We may request additional information before processing a refund.
10. Refund Request Procedure
Refund requests should be submitted within 14 days of the relevant payment unless a different period is required by applicable law.
Requests should include:
- customer name;
- registered email address;
- payment confirmation;
- invoice or receipt;
explanation of the request.
We may request further information to verify the transaction.
11. Refund Processing
If a refund is approved:
refunds will generally be issued using the original payment method whenever practicable;
processing typically begins within 10 business days after approval; and
the time required for funds to appear in your account depends on your bank, card issuer, or payment provider.
We are not responsible for delays caused by financial institutions.
12. Chargebacks
Before initiating a chargeback with your payment provider, we encourage you to contact us so we can attempt to resolve the issue.
Fraudulent or abusive chargebacks may result in:
- temporary account suspension;
- permanent account termination;
recovery of unpaid fees where permitted by law.
13. Taxes
Refunds generally include applicable taxes where legally required.
If taxes have already been remitted to governmental authorities, refunds will be handled in accordance with applicable tax laws.
14. Promotional Credits
Promotional credits, discounts, coupons, trial extensions, and bonus balances:
- have no cash value;
- are non-transferable unless expressly permitted;
- are not refundable; and
may expire in accordance with their stated terms.
15. Service Suspension
If your account is suspended because of:
- non-payment;
- fraud;
- unlawful activity;
- security risks; or
- violations of our Terms,
you will generally not be entitled to a refund for the affected subscription period.
16. Changes to This Policy
We may update this Refund & Cancellation Policy periodically.
Material changes become effective upon publication or as otherwise required by applicable law.
The latest version will always be available on our website.
17. Contact
Questions regarding this Policy or refund requests may be directed to:
Email: support@zopit.cloud