1 Parties
These Terms (“Agreement”) are between Codebite Oy (Business ID 3135024-9), “Provider”, and the entity or individual accepting them (“Customer”, “Tenant”, “you”).
1.1 Definitions
- Service. The Apply.Build Platform and related APIs and dashboards.
- Resource Package. A predefined and limited amount of resources (1 virtual CPU, 1 GiB memory and 10 GB storage) purchased per §3.
- Team. A Customer account space, shared by its members, in which Applications and Databases run.
- Application. A runnable container image deployed by Customer.
- Database. A managed PostgreSQL database provided through the Service.
- Free Tier. The resources Provider makes available at no charge, described in §3.
- Billing Period. One calendar month starting on the date of first charge (unless otherwise agreed).
2 Service description
Apply.Build is a managed application-hosting platform that lets you deploy containerised web services and managed PostgreSQL databases without operating your own infrastructure. Applications are built and deployed from Customer's GitHub repositories or Dockerfiles. Each customer application runs in its own isolated virtual environment with predefined CPU and memory allocations. All data and processing remain within the European Economic Area.
- Public access. Every application is reachable over HTTPS on a default sub-domain of
{app}.apps.apply.build. You may also attach custom domains; the platform automatically provisions and renews trusted TLS certificates. Applications may initiate outbound connections to the Internet unless explicitly blocked by a prevailing policy. - Resource packages. You purchase CPU, memory and storage packages in advance and can distribute those resources across your applications and databases at any time during the billing period.
- Security & isolation. Applications are strictly separated from one another, and traffic between customer environments is blocked by default. Only external traffic routed through a controlled ingress will be able to reach your service by default.
- Threat-detection. All inbound HTTP requests are inspected by an automated intrusion detection/prevention system. Suspicious requests may be blocked before they reach your Application.
- Monitoring & logs. Basic performance graphs and recent application logs are available in the dashboard for the last seven (7) days.
- Data location. Compute, database, backup and observability data are stored on servers located in Finland; data will not be moved outside the EEA without notice.
- Back-ups. Databases include point-in-time recovery for the previous seven (7) days. Application disks are ephemeral and are not backed up; you are responsible for keeping copies of any other critical data.
3 Resource Packages, billing & payment
- Each Resource Package (“Package”) provides 1 vCPU, 1 GiB RAM and 10 GB storage for one billing period (1 month).
- Free Tier: 0.5 vCPU, 512 MiB RAM and 5 GB storage at no charge. It can be used alongside purchased Packages and remains available after paid Packages are cancelled. Provider may change the Free Tier under §14.
- Packages are billed in advance; unused Packages expire at month-end.
- Cooling-off period: for new subscriptions (first purchase), unused Packages may be cancelled within 14 days of purchase for a full refund. After that, all sales are final.
- Billed currency is Euro (EUR), unless otherwise and separately agreed.
- Payments are processed by our payment processor (see Sub-processors); card data may be processed outside the EEA under that processor's terms.
- Grace period: 30 days to cure failed payment before suspension.
- Over-provisioning: If Customer schedules workloads exceeding purchased Packages, deployment will be refused until additional Packages are purchased.
4 Service level & maintenance
- Service levels: no uptime commitment or service credits apply unless agreed in a separate service-level agreement. Current and historical availability is published at status.codebite.fi.
- Maintenance: may happen at any time; Provider tries to announce planned work in advance.
- Availability: Customer application reachable from public endpoint.
5 Support
- Support by e-mail at contact@codebite.fi.
6 Customer responsibilities
-
Legal compliance. You must follow all applicable Finnish, EU, and international laws.
-
Prohibited content & activities.
- No illegal, defamatory, extremist, obscene, or pornographic content.
- No unsolicited bulk e-mail (“spam”), falsified headers or open mail relays.
- No cryptocurrency mining, farming, plotting.
- No phishing pages, malware, or command-and-control servers.
- No VPNs, forward proxies, tunnels, Tor nodes or any other service used to route internet traffic through the platform, whether your own or anyone else's. Reverse proxies that serve your own application are allowed.
- No BitTorrent or other peer-to-peer file sharing, and no services whose main purpose is hosting or distributing files for the public.
- No attacking, scanning or flooding any system, whether the platform, other tenants or anyone else.
- No credential stuffing, mass scraping or other automated abuse of third-party services.
- One free tier per person or organisation; no creating multiple accounts to get around limits.
Provider may remove or disable any application, without notice, that in Provider's sole judgment violates these rules or otherwise negatively impacts the platform or its reputation.
-
Security telemetry. You acknowledge that security telemetry (including source IP address and request path) may be analysed by the Provider's threat-detection engine to protect the Service. Provider may retain security-telemetry related to confirmed malicious activity (including source IP address and request details) indefinitely in order to enforce permanent blocks and protect the Service.
-
Security configuration. You manage your own secrets, images, and must not deploy privileged workloads (including but not limited to privileged, hostNetwork, hostIPC, hostPID, hostPath volumes, or CAP_NET_RAW).
-
Custom domains. You must keep required CNAME records. If a certificate cannot be issued or renewed within 72 h, Provider may disable the hostname.
-
Fair-use bandwidth. Traffic that materially exceeds normal web-application usage may be rate-limited or suspended, solely determined at Provider's reasonable discretion. Provider may notify Customer and require purchase of additional Resource Packages.
-
Sanctions and export control. You must comply with applicable EU sanctions and export-control laws when using the Service.
-
Service region. The Service is only available to customers based in Europe. Signing up or using the Service from elsewhere, or getting around our region restrictions (for example with a VPN), is not allowed, and Provider may suspend or delete the account and all its applications without notice. This applies to account holders; visitors to your applications can be anywhere.
-
Connected services. GitHub and any notification destinations Customer connects are governed by their own terms. Customer is responsible for data it chooses to send to them.
7 Data location, privacy & backups
- All data remains within the European Economic Area.
- Databases include point-in-time recovery for the previous seven (7) days. Application disks are ephemeral and are not backed up; you must maintain your own copies of any other data.
8 Data protection (GDPR)
- Provider = Processor; Customer = Controller.
- Data Processing Agreement available on request by emailing contact@codebite.fi.
- Provider will notify Customer of any personal-data breach without undue delay and within GDPR timeframes.
- Provider publishes its list of authorised sub-processors on the Sub-processors page, and maintains the technical-and-organisational measures (TOMs) and the record of processing activities as required by GDPR Art. 28, which it will provide to Customer on request. Provider will inform Customer before adding or replacing a sub-processor.
9 Confidentiality
Each party keeps the other's non-public information confidential and uses it only to perform this Agreement, during the Agreement and for five (5) years after it ends.
10 Intellectual property
- You retain ownership of your code, images, data.
- Provider retains ownership of platform software, documentation & trademarks.
- Customer grants Provider a non-exclusive, worldwide, royalty-free licence for the term of this Agreement to copy, store, execute and transmit Customer's images and data solely for the purpose of providing the Service.
- Customer grants Provider a perpetual, irrevocable, royalty-free licence to use any feedback or suggestions regarding the Service.
11 Suspension & termination
- Provider may suspend or delete workloads that breach §6 or remain unpaid for more than 30 days. No refunds are given when an account or application is suspended or deleted for breaching these Terms.
- You may cancel at any time; service continues until period-end. Unused Packages are non-refundable except during the initial 14-day cooling-off period.
- Provider will delete all Customer data and logs 30 days after effective termination. Customer is responsible for retrieving any data it needs before termination. Administrative records required for tax, accounting, or otherwise legal purposes may be retained per statutory law.
12 Limited warranty & liability
- Except as expressly stated in these Terms, the Service is provided “as is” without warranties.
- Exclusion of consequential damages.
- Liability cap: Provider's aggregate liability in any twelve-month period shall not exceed the fees actually paid by Customer in the three (3) months immediately preceding the event giving rise to the claim.
- In no event shall Provider be liable for lost profits, business interruption, lost data or any indirect, special or consequential damages, including but not limited to any loss of data resulting from Customer's failure to maintain backups of data not covered by database point-in-time recovery.
- Nothing limits liability for gross negligence or liabilities that cannot be limited under Finnish law.
13 Governing law
This Agreement is governed by Finnish law. Jurisdiction: courts of Helsinki, Finland.
14 Changes to these Terms
Provider may amend these Terms with 30 days' notice by e-mail or dashboard banner. Continuing to use the Service after the effective date constitutes acceptance. If Customer does not agree to the revised Terms, Customer may terminate the Service within the 30-day notice period by e-mailing contact@codebite.fi; no further use of the Service will be allowed after the effective date.
15 Force-majeure
Neither party is liable for failure to perform due to events beyond its reasonable control, including natural disasters, war, strikes, power or network outages, or governmental action. Either party may terminate the Agreement with written notice if the force-majeure event continues beyond 30 days.
16 Survival clause
Clauses on Intellectual Property, Confidentiality, Limitation of Liability, Governing Law, and Survival shall survive termination.
17 Order of precedence
If a conflict exists between these Terms and a separately executed Master Service Agreement (MSA) or Data Processing Agreement (DPA), the MSA/DPA shall prevail for the conflicting subject matter.
18 Severability
If any provision of these Terms is deemed invalid, illegal, void or unenforceable, then that provision will be deemed severed from these Terms and will not affect the validity or enforceability of the remaining provisions of these Terms.