1. Scope and Conclusion of Contract#
1.1 These General Terms and Conditions (the «GTC») apply to all services and products that Xerio GmbH («Xerio») offers or provides to its customers (the «Customer»). They form an integral part of every contract between Xerio and the Customer.
1.2 The following documents apply in addition and are incorporated into these GTC by reference:
- Annex 1: Acceptable Use Policy
- Annex 2: Data Processing Agreement (DPA)
- Annex 3: Special Provisions for Colocation
- the Xerio privacy policy
- the applicable service and price description on the website or in the customer portal
In the event of conflict, individually agreed written terms prevail over these GTC, and these GTC prevail over the annexes and the published service descriptions. Clause 1.3 of Annex 2 remains reserved.
1.3 The contract is concluded as soon as Xerio confirms an order, provisions the ordered service, or the Customer signs or electronically confirms a customer-specific quotation. For orders placed through the customer portal, Xerio may require the Customer to accept these GTC by ticking a corresponding checkbox.
1.4 Xerio contracts with natural persons who have legal capacity and have reached the age of 18, and with legal entities. If the Customer acts on behalf of a third party or a company, it warrants that it is authorised to represent that party.
1.5 Terms and conditions of the Customer that deviate from these GTC apply only if Xerio has accepted them in writing. Providing services without objection does not constitute acceptance.
2. Services Provided by Xerio#
2.1 General#
Xerio provides both paid and free services. The scope, conditions and prices are governed by the service description published at the time of ordering or by the customer-specific quotation. Xerio may develop its portfolio further and may restrict or discontinue individual services; clause 16 remains reserved.
2.2 Hosting Services#
2.2.1 Xerio provides the Customer with storage space, computing capacity and server services on an internet-connected infrastructure, in the scope selected.
2.2.2 Prices for shared and reseller hosting are calculated on the basis of average usage («fair use»). The allocated resources — in particular storage space, traffic, CPU time, memory, concurrent processes, database connections and inodes — may be used solely for the ordinary operation of the Customer's websites and mailboxes.
2.2.3 It is not permitted to use shared or reseller storage space as an archive, backup target, file repository or distribution platform for content unrelated to a website operated on the infrastructure. Details are set out in Annex 1.
2.2.4 Xerio may set resource limits for individual customers or groups of customers and restrict service delivery accordingly where usage impairs the operation of the shared infrastructure or the service quality of other customers. Xerio will inform the Customer in advance or — where this is not operationally possible — immediately thereafter.
2.2.5 Xerio may temporarily block access to a customer website where its operating behaviour or the behaviour of its users endangers the infrastructure, in particular in the event of DDoS attacks, compromised applications or exceptional load.
2.3 Virtual Servers (VPS)#
2.3.1 For virtual servers, the scope of service is determined by the resources committed in the product ordered. The Customer is responsible for the administration, updating, hardening and backup of the operating system and of the software running on it, unless a managed service has been expressly agreed.
2.3.2 Xerio does not create backups unless a corresponding backup product has been ordered.
2.3.3 Xerio may reset credentials where this is necessary for security reasons or where the details on file are not current. The Customer keeps a valid contact address on file in the customer portal at all times.
2.3.4 Xerio may migrate virtual machines to another host node for maintenance purposes. This may involve a brief interruption and does not give rise to a claim under clause 2.9.2.
2.4 Dedicated Servers#
2.4.1 Xerio provides the Customer with hardware for its exclusive use. Title to the hardware remains with Xerio or its suppliers; there is no entitlement to acquire it, nor to any particular brand or component generation.
2.4.2 The scope of service includes — where stated in the product — rack space, power, cooling, network connectivity at the port speed and data volume ordered, and out-of-band access (IPMI/KVM).
2.4.3 Administration, operating system, updates, hardening, monitoring and backups are the responsibility of the Customer, unless a managed service has been expressly agreed. Xerio owes no support for software installed by the Customer.
2.4.4 In the event of hardware failure, Xerio will replace the affected components within a reasonable period after the fault has been confirmed; the target is remediation within four hours, around the clock. Replacement may be made with equivalent or higher-performing components. Restoring data and configuration is the Customer's responsibility (clause 5).
2.4.5 Simple on-site actions (e.g. reboot, visual inspection, media change) are performed by Xerio free of charge on request. Work beyond this («remote hands») is charged on a time-and-materials basis at the published rates.
2.4.6 Where the data volume or port speed ordered is exceeded, Xerio may charge for the excess at the published rates or throttle the connection. Xerio will inform the Customer in advance where operationally possible.
2.4.7 In the event of attacks on or originating from a dedicated server, of misuse, or of a threat to the platform, Xerio may temporarily filter, throttle or interrupt network access (null-routing).
2.4.8 Clause 6.4 applies in the event of late payment. After prior reminder, Xerio may decommission a dedicated server, wipe the storage media and reassign the hardware. Xerio is not liable for the resulting loss of data.
2.5 Colocation#
2.5.1 Under a colocation agreement, Xerio provides the Customer with floor space in a data centre (rack units, rack or cage) for housing the Customer's own hardware, including power up to the agreed connected load, cooling and physical security. Network connectivity is included only where expressly ordered.
2.5.2 Annex 3 (Special Provisions for Colocation) applies in addition, together with the house rules and security regulations of the respective data centre. Xerio will make these available to the Customer on request.
2.5.3 Hardware installed by the Customer remains its property. Xerio owes no maintenance, configuration or monitoring of customer hardware unless expressly agreed.
2.6 Domain Names#
2.6.1 Xerio registers, manages and transfers domain names in the name and for the account of the Customer. The rules of the competent registry, of ICANN and of the registrar used apply in addition. The Customer acknowledges that Xerio has no influence over their decisions.
2.6.2 There is no entitlement to the allocation of a particular domain name. The Customer warrants that the registration does not infringe any third-party rights.
2.6.3 The Customer acknowledges that registration data is, depending on the extension, publicly accessible in whole or in part (WHOIS/RDAP) and must be passed on to the registry and to third parties.
2.6.4 Renewals are generally invoiced at least 30 days before the expiry date. Renewal notices are provided as a courtesy and confer no legal entitlement. It is the Customer's own responsibility to notify Xerio in good time — at the latest 30 days before expiry — if a domain is not to be renewed. Registrations and renewals are non-refundable once executed.
2.7 IP Addresses and Routing#
2.7.1 IP addresses, address blocks and AS numbers are provided to the Customer for use only, for the term of the contract. They remain allocated to Xerio or to the competent registry; the Customer acquires no ownership, assignment or transfer rights in them.
2.7.2 Additional IP addresses are allocated subject to justification of need and in accordance with the policies of the competent registry (RIPE NCC or ARIN). Xerio may request supporting evidence and may decline requests that lack sufficient justification.
2.7.3 Xerio may change IP addresses assigned to the Customer for operational, security-related or regulatory reasons. Xerio will give reasonable notice where possible.
2.7.4 All assigned addresses revert to Xerio at the end of the contract. There is no entitlement to a transfer to the Customer or to a third party. Reverse DNS entries are removed upon return.
2.7.5 Where the Customer brings its own address resources and has them announced via the Xerio network, the following applies: the Customer evidences its right of disposal by means of a Letter of Authorization, maintains accurate IRR objects and valid ROAs, and announces only prefixes it is entitled to announce. Xerio filters announcements in accordance with relevant industry standards and may withdraw announcements without prior notice where there are indications of unauthorised use. The Customer is liable for damage arising from unauthorised announcements and indemnifies Xerio accordingly.
2.7.6 Where the Customer's conduct causes Xerio addresses to be entered on blocklists, Xerio may charge for the effort involved in delisting.
2.8 Applications, Additional Services and Third-Party Products#
2.8.1 Xerio may make available applications (e.g. content management systems) and additional services (e.g. TLS certificates, backup, website builder) supplied by Xerio or by third parties. By using them, the Customer additionally accepts the applicable licence and usage terms of the respective provider.
2.8.2 Installation, configuration and operation of such applications are at the Customer's responsibility and risk. There is no entitlement to support for applications unless expressly agreed.
2.8.3 Xerio is not liable for the availability, quality or functionality of third-party products and assumes neither an agency nor a fiduciary role in relation to them.
2.9 Availability and Maintenance#
2.9.1 Xerio endeavours to provide the services around the clock and targets an annual availability of 99.9 % for shared and reseller hosting. The following do not count as downtime: scheduled maintenance windows, disruptions outside the control of Xerio (in particular in the transit, peering or upstream domain), disruptions caused by the Customer's applications or configurations, and measures taken to defend against attacks.
2.9.2 Where the committed availability is demonstrably not met in a calendar month, the Customer may request a credit to its customer account within 30 days. The credit is calculated pro rata on the monthly fee for the affected service and is capped at one monthly fee. For dedicated servers, VPS and colocation, no availability guarantee applies to customer systems; instead, a network and power availability guarantee applies, with the credit calculated pro rata on the duration of the interruption. Xerio's monitoring is authoritative; measurements by third parties are not admissible as evidence. Cash payment is excluded; no further claims arise.
2.9.3 Maintenance work, fault remediation and security measures may require temporary interruptions. Xerio will, where possible, give advance notice of planned work.
2.10 Locations and Migration#
2.10.1 Xerio operates infrastructure at several locations. Where the product provides for a choice of location, the Customer selects the location when ordering. If the Customer selects a location outside Switzerland, it acknowledges that its data will be processed and stored there and may be subject to foreign law.
2.10.2 Xerio may migrate services to different infrastructure within the same legal jurisdiction for operational, security-related or legal reasons. A change of location to a different jurisdiction will be made only after prior notice to the Customer.
2.10.3 Assistance with taking over existing data from a previous provider is rendered by Xerio as a courtesy, without warranty as to feasibility, completeness or time required. The Customer remains responsible for backing up its data in all cases.
3. Customer Obligations and Responsibility#
3.1 Information and Contact Details#
3.1.1 The Customer provides truthful, complete and current information when ordering and throughout the term of the contract, in particular for the billing, administrative and technical contacts. It registers an e-mail address that does not run via a domain hosted with Xerio.
3.1.2 Xerio may at any time request evidence to verify the information provided (e.g. commercial register extract, copy of identity document, proof of payment). If such evidence is not provided within the period set, Xerio may decline the order, suspend service delivery or terminate the contract for cause.
3.1.3 Contractually relevant communications are sent to the contact address stored in the customer portal. Xerio is not obliged to take account of details other than those stored there, nor to make its own enquiries. Xerio is not liable for disadvantages arising from out-of-date details, in particular for the lapse of domain names.
3.2 Credentials and Account Security#
3.2.1 The Customer chooses secure passwords, keeps all credentials safe and protects them against third-party access. It is responsible for all actions carried out via its access.
3.2.2 Xerio may check password strength and require the Customer to make changes. Where such a request is not complied with, Xerio may block the affected access until the matter is resolved.
3.2.3 If the Customer establishes or suspects a compromise, it notifies Xerio without delay. Xerio may block compromised access or services until the cause has been remedied. Clean-up by Xerio is carried out only on request and against reimbursement of effort.
3.3 Responsibility for Content#
3.3.1 The Customer is solely responsible for all data, content, applications, references and communications that it or third parties store, transmit, distribute or make available for retrieval via the services of Xerio. This also applies to content of users of its websites and to persons acting under its supervision.
3.3.2 Content is not permitted where it infringes Swiss law or the law applicable at the Customer's location, impairs third-party rights (in particular intellectual property, personality or data protection rights), breaches the Unfair Competition Act — including the Customer's imprint obligation under Art. 3 para. 1 lit. s UCA — or constitutes a criminal offence. Annex 1 applies in addition.
3.3.3 Xerio is under no obligation to monitor customer content. Xerio is, however, entitled to review content where a substantiated third-party notice has been received, where an authority or court so orders, or where there are concrete indications of a breach of these GTC.
3.3.4 Xerio forwards third-party notices concerning allegedly unlawful content to the Customer for comment. The Customer undertakes to respond within the period stated in the notice, as a rule 48 hours. If no response is received, Xerio may block the affected content or services.
3.3.5 Disputes between the Customer and third parties, or between joint account holders, concerning content or account use are exclusively a matter for the parties involved. Xerio's obligation to provide information on the order of a court or authority remains reserved.
3.4 Operation and Cooperation#
3.4.1 The Customer keeps the software it uses at a current and security-supported level, applies updates promptly and removes applications it no longer needs from the infrastructure.
3.4.2 The Customer reports disruptions without delay and supports Xerio in isolating them. Where the cause of a disruption investigated at the Customer's request lies within its sphere of responsibility, Xerio may charge for the effort on a time-and-materials basis.
3.4.3 Procuring and operating the Customer's own devices, software and internet connection is its own responsibility. Xerio is not responsible for delays attributable to outstanding cooperation on the part of the Customer.
3.5 Provision to Third Parties#
3.5.1 Without a reseller agreement, the Customer is not entitled to make the services obtained available to third parties, in whole or in part, whether for consideration or free of charge. If Xerio establishes such use, it may suspend service delivery until the matter is resolved; the payment obligation remains in force.
3.5.2 Clause 14 applies in addition to resellers.
4. Acceptable Use#
The Customer undertakes to comply with the Acceptable Use Policy set out in Annex 1. It governs, in particular, prohibited uses, resource limits, the sending of e-mail and the handling of abuse reports. Xerio may amend the Acceptable Use Policy in accordance with clause 16.
5. Data Backup#
5.1 The Customer is solely responsible for taking suitable measures to enable it to restore its data in the event of loss or unauthorised or inadvertent alteration. Xerio recommends creating regular backups and keeping them outside the Xerio infrastructure.
5.2 Where Xerio creates backups, this is done within the scope of the product ordered. Scope, frequency and retention period follow from the service description. Without a backup product, any backup is provided as a free courtesy, without legal entitlement and without warranty.
5.3 Volatile data, cache and temporary files as well as messages classified as spam are excluded from restoration. For technical reasons — for instance during maintenance, disruptions or the replacement of infrastructure components — individual backup cycles may be omitted. Data loss in an individual case can therefore not be ruled out.
5.4 Xerio does not provide backups for suspended or terminated services unless otherwise agreed in writing.
6. Prices, Invoicing and Payment#
6.1 The prices published at the time of ordering or the customer-specific quotation are authoritative. Unless stated otherwise, prices are in Swiss francs and exclusive of value added tax and any further duties.
6.2 The payment obligation begins upon conclusion of the contract or upon provisioning of the service. Xerio generally invoices in advance for the contract period selected.
6.3 Invoices are payable without deduction by the due date stated. Incoming payments are first applied to the oldest outstanding receivable.
6.4 In the event of late payment, Xerio is entitled to charge default interest of 5 % p.a. and, from the second reminder, cost-covering reminder fees. Where an invoice remains outstanding more than 10 days after the due date, Xerio may suspend the affected services; after an unsuccessful reminder, it may terminate the contract for cause. Reinstatement takes place only after payment has been received in full and, for dedicated servers and VPS, is not automatic — the Customer must contact support for this purpose.
6.5 Xerio may refuse to activate new services for customers with outstanding receivables. Costs of legal enforcement and debt collection are borne by the defaulting Customer.
6.6 Set-off of Customer claims against claims of Xerio is excluded.
6.7 Objections to an invoice must be raised in writing within 90 days of the invoice date. Thereafter the invoice is deemed approved.
6.8 Abusive or fraudulent use of means of payment constitutes a material breach of contract. Xerio reserves the right to report such matters to the competent authorities, financial institutions and card organisations.
6.9 Xerio may adjust prices and conditions. Price increases to the Customer's detriment are announced by e-mail at least 30 days before they take effect; clause 16.2 applies mutatis mutandis.
7. Term, Renewal and Termination#
7.1 The contract is concluded for the term selected when ordering (e.g. 1, 12, 24 or 36 months). It renews automatically for the same period unless terminated in good time.
7.2 Either party may terminate the contract with 30 days' notice effective at the end of the current contract period. The Customer gives notice via the cancellation form in the customer portal; Xerio may give notice by e-mail to the contact address on file.
7.3 Xerio confirms every termination in writing, stating a ticket number. If the Customer does not receive an automatic acknowledgement within a few minutes, it should contact support without delay. The form-based procedure serves to verify identity and to document the deletion.
7.4 Withdrawal and refund. For newly ordered shared and reseller hosting products, Xerio grants first-time customers a right of return of 7 days from the start of the contract. The following are excluded:
- domain registrations and renewals
- setup, migration and administration fees as well as customer-specific work
- third-party licences and certificates
- dedicated servers, VPS and colocation services
- contracts based on a customer-specific quotation
Only the basic fees for the affected service are refunded. Where payment was made by bank transfer, cheque or money order, the refund is issued as a credit to the customer account. Refunds are processed in Swiss francs at the exchange rate on the day of the refund; exchange rate fluctuations are not to the detriment of Xerio.
7.5 After the end of the contract, Xerio is entitled to delete all of the Customer's data. The Customer backs up its data itself in good time before the end of the contract.
8. Suspension and Termination for Cause#
8.1 Xerio may suspend services in whole or in part and/or terminate the contract with immediate effect where:
a) the Customer breaches these GTC, the Acceptable Use Policy or statutory provisions;
b) impermissible content is made available;
c) a court or authority so orders;
d) Xerio would otherwise incur legal responsibility or suffer significant reputational damage;
e) the Customer remains in default of payment despite reminder;
f) bankruptcy or composition proceedings are opened against the Customer, or its inability to pay becomes otherwise evident;
g) Xerio employees are insulted, threatened or otherwise materially impaired.
8.2 Where there is imminent danger — in particular in the event of acute security incidents, attacks or a threat of IP addresses being blocklisted — Xerio may act without prior notice and will inform the Customer immediately thereafter.
8.3 Upon termination under clause 8.1, the Customer owes the fees payable up to the ordinary end of the contract as well as reimbursement of the additional costs incurred. Fees already paid are not refunded.
8.4 Xerio may invoice the effort involved in measures under this clause and under clause 3.3 and may require security for its provisional coverage.
9. Warranty#
9.1 Xerio provides the services with due care and skill in accordance with the current state of the art. Xerio does not, however, warrant that the services will be uninterrupted, error-free or free of security risks, that data will always be transmitted without delay, or that the Customer will achieve any particular commercial purpose with the services.
9.2 Defects must be notified to Xerio in writing with a comprehensible description. The Customer sets Xerio a reasonable grace period of at least 30 days for remediation. If remediation does not occur, the Customer may terminate the contract with immediate effect; in that case Xerio refunds the pro rata fees paid in advance for the service no longer received. Any further claims are governed exclusively by clause 10.
9.3 Xerio gives no warranty for applications and third-party products under clause 2.8, in particular not as to completeness, accuracy, availability, security, fitness for a particular purpose or freedom from defects.
10. Liability of Xerio#
10.1 Xerio is liable without limitation for direct, proven damage caused by unlawful intent or gross negligence.
10.2 Liability for medium and slight negligence is limited to CHF 20,000.00 per calendar year. This limit applies in the aggregate; the existence of more than one claim does not increase it.
10.3 Liability for indirect damage and consequential damage is excluded. This includes, in particular, lost profit, loss of revenue, business interruption, reputational damage, third-party claims and damage arising from data loss.
10.4 Any liability is further excluded for damage arising from third parties misusing or gaining unauthorised access to the infrastructure of Xerio or to the Customer's services — in particular through malware, DDoS attacks, unauthorised access or abusive e-mail sending. The exclusion extends to damage resulting from measures taken by Xerio to defend against such interference, including precautionary suspensions.
10.5 Liability for injury to life, limb and health, and in cases of mandatory law including the Product Liability Act, remains reserved.
11. Liability and Indemnification by the Customer#
11.1 The Customer is liable to Xerio without limitation for damage caused by unlawful intent or gross negligence.
11.2 The Customer indemnifies Xerio, its officers, employees, auxiliary persons and partners against all third-party claims raised in connection with the use of the services by the Customer, its customers or persons under its supervision. The indemnity also covers the costs of an appropriate legal defence. The Customer supports Xerio in any proceedings.
12. Confidentiality and Data Protection#
12.1 Xerio and the Customer treat as confidential all information that is not generally known and that becomes accessible to them in the course of initiating and performing the contract. This obligation continues beyond the end of the contract for as long as there is a legitimate interest in it.
12.2 Xerio processes personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation. Details are set out in the Xerio privacy policy.
12.3 Where Xerio processes personal data on behalf of the Customer in the course of providing the services, the Data Processing Agreement in Annex 2 applies.
12.4 Xerio is entitled to monitor its systems in order to ensure proper operation, to defend against unauthorised access and to verify operational security. The Customer acknowledges this.
12.5 Xerio provides information to law enforcement and other authorities to the extent that it is legally obliged to do so or that this appears necessary to avert a significant danger.
12.6 Xerio may inform the Customer about its own services and developments. The Customer may unsubscribe at any time via the unsubscribe link or in the customer portal; system and billing notices necessary for operations are excluded from this.
13. Intellectual Property#
13.1 For the term of the contract, the Customer receives a non-exclusive, non-transferable right to use the services for their intended purpose.
13.2 All rights to existing intellectual property of Xerio and to intellectual property created in the performance of the contract — in particular in software, configurations, templates, documentation, trade marks and the customer portal — remain with Xerio or with the third parties engaged by it. Reproduction, modification, transfer or reverse engineering is not permitted without written consent.
13.3 Rights to the content and data contributed by the Customer remain with the Customer. The Customer grants Xerio the rights of use necessary to perform the contract (in particular storage, reproduction for backup purposes, transmission).
14. Resellers#
14.1 Resellers ensure that each of their own customers complies with these GTC and the Acceptable Use Policy.
14.2 Support for a reseller's customers is the exclusive responsibility of that reseller. Xerio provides no support to end customers of resellers; enquiries are referred to the reseller.
14.3 The reseller is responsible for all content stored and transmitted under its account and for the conduct of its customers, and indemnifies Xerio accordingly.
14.4 In the event of a breach by an end customer, Xerio will suspend the affected service and inform the reseller. Repeated breaches may lead to termination of the reseller agreement.
14.5 Xerio may amend the terms of the reseller programme with effect from publication or from a later date.
15. Force Majeure#
Neither party is liable for the non-performance or delayed performance of its obligations — with the exception of payment obligations — to the extent that this is attributable to circumstances outside its reasonable control. These include, in particular, natural events, fire, epidemics, war, terrorism, official orders, labour disputes, power and network outages, large-scale attacks on internet infrastructure, and the failure of third-party deliveries.
16. Amendments to these GTC#
16.1 Xerio may amend these GTC including their annexes. Amendments are published on the website and take effect upon publication.
16.2 Xerio notifies the Customer by e-mail of material amendments to its detriment and of price increases at least 30 days before they take effect. The Customer may terminate the contract within 30 days of receiving the notice, effective as at the date the amendment takes effect. If no termination is given in good time, the amendments are deemed approved.
16.3 Xerio reserves the right to develop, adapt or discontinue individual aspects of the services at any time; clause 16.2 remains reserved.
17. Assignment of the Contract#
Rights and obligations under the contractual relationship may be transferred to third parties only with the written consent of the other party. This does not apply to a transfer by Xerio to a legal successor or an affiliated company, nor to the engagement of auxiliary persons and subcontractors.
18. Final Provisions#
18.1 Should individual provisions of these GTC be invalid or unenforceable in whole or in part, the validity of the remaining provisions is unaffected. The parties will replace the affected provision with a valid arrangement that comes closest to its commercial purpose.
18.2 Failure to exercise a right does not constitute a waiver of its later assertion.
18.3 Xerio and the Customer are independent contracting parties. No employment, partnership, agency or joint venture relationship is created.
18.4 These GTC together with their annexes constitute the entire agreement between the parties on the subject matter governed and supersede prior arrangements. Titles and headings serve orientation only.
18.5 The contractual relationship is governed exclusively by Swiss law, to the exclusion of its conflict-of-law rules and of the United Nations Convention on Contracts for the International Sale of Goods (CISG).
18.6 The exclusive place of jurisdiction is Zurich, Switzerland. Xerio is alternatively entitled to bring proceedings at the Customer's registered office or domicile. Mandatory places of jurisdiction remain reserved.
18.7 These GTC are provided in German and English. In the event of discrepancies or questions of interpretation, the German version prevails.
Zurich, 1 August 2026
---
---
Part of this agreement
Annex 1: Acceptable Use Policy#
This Acceptable Use Policy applies to all services of Xerio and forms an integral part of the GTC. In the event of conflict, the GTC prevail unless expressly provided otherwise here.
A1.1 Principle#
The services may be used only for lawful purposes and in compliance with applicable law. Xerio may remove or disable content that in its assessment breaches this policy, with or without prior notice.
A1.2 Prohibited Uses#
The following are prohibited in particular:
- committing or participating in criminal offences, and making the services available to supervised persons for that purpose;
- distributing content that is unlawful under criminal or civil law, in particular depictions of violence, racial discrimination, incitement to criminal offences, defamation, calumny and violations of personality rights;
- depictions of sexual acts involving minors. Such content leads to immediate suspension without prior notice and is reported to the competent authorities;
- unauthorised reproduction or distribution of copyright-protected works (software, films, music, books, images) and the sale of counterfeit goods;
- fraud, pyramid and Ponzi schemes, unlicensed financial, credit and investment offerings, and unauthorised gambling and lottery offerings;
- the sale of controlled substances without evidence of the required authorisations;
- phishing sites, attack and abuse tools, and instructions for their use.
A1.3 Prohibited Applications on Shared and Reseller Hosting#
The following applications, among others, are not permitted on shared and reseller hosting:
- peer-to-peer software, BitTorrent clients and trackers
- public proxies and anonymisation services
- IRC servers, IRC bots and clients
- network and port scanners, brute-force tools
- mail bomb and spam scripts, bulk SMS gateways
- game servers and terminal emulations
- crypto mining software
- file storage and mirror services as well as image and video hosting platforms without a substantive connection to the Customer's own website
- commercial audio and video streaming and the transmission of live events
- banner and e-mail exchange schemes as well as autosurf, PTC and PTS offerings
This list is not exhaustive. In case of doubt, the Customer clarifies admissibility with Xerio in advance.
A1.4 Resource Usage#
A1.4.1 On shared and reseller hosting, a single account may not permanently exceed the resources allocated to it. The following serve as guide values:
- no occupation of 25 % or more of system resources for more than 90 seconds
- no unattended server processes or daemons
- cron jobs at intervals of at least 15 minutes
- database queries with a runtime of no more than 15 seconds; tables must be appropriately indexed
- no continuous operation of web spiders and indexers
A1.4.2 Inodes: accounts with more than 250,000 inodes may be warned and, if no clean-up follows, suspended. Accounts above 100,000 inodes are automatically excluded from backups. The most common cause is unread catch-all mailboxes; the Customer disables these or empties them regularly.
A1.4.3 For VPS the following applies in addition: the 15-minute load average may not exceed twice the number of allocated CPU cores; I/O-intensive applications must not impair normal platform operation. The default inode limit is 1,000,000 and may be raised upon substantiated request.
A1.5 E-mail#
A1.5.1 The Customer is responsible for the content of all messages sent via the Xerio infrastructure.
A1.5.2 For shared and reseller hosting, a limit of 200 outbound messages per domain and hour applies. Where this is exceeded, further messages are rejected.
A1.5.3 Distribution lists with more than 2,000 recipients require a VPS or dedicated server. Splitting a list to circumvent this limit is not permitted. Mailings to more than 500 recipients are sent outside peak hours (all day Saturday and Sunday, and Monday to Friday 22:00–08:00 CET).
A1.5.4 Newsletters must be throttled, as a rule to no more than one message every 20 seconds. Software that does not support throttling may not be used.
A1.5.5 Address lists must be collected using a double opt-in procedure. Purchased, rented or supplied lists may not be used. Scripts used must log the time of subscription and confirmation together with the IP address, process unsubscribes without delay and automatically remove bounces.
A1.5.6 Every mailing must correctly identify the sender and include a simple, free means of unsubscribing. The Telecommunications Act (TCA), the Unfair Competition Act (UCA) and the Federal Act on Data Protection (FADP) are authoritative in particular.
A1.5.7 Xerio operates a zero-tolerance policy towards unsolicited bulk messages. Using third-party mail servers as a relay and promoting offerings operated on the infrastructure by means of spam (spamvertising) are prohibited. Where an account causes Xerio IP addresses to be entered on blocklists, Xerio may invoice the effort involved in delisting.
A1.5.8 Connection limits per source IP address apply to POP3/IMAP. Automatic polling intervals must be configured accordingly (guide value: no more often than every 10 minutes).
A1.6 System and Network Security#
The following constitute material breaches of contract in particular:
- unauthorised access to third-party data, systems or network elements
- vulnerability scans without the prior written consent of the party concerned
- intercepting third-party traffic (sniffing)
- attempts to overload systems of Xerio or of third parties (flooding, mail bombs)
- manipulation of control information in TCP/IP packets, in particular of sender addresses
On request, the Customer evidences that its access to third-party systems is authorised.
A1.7 Handling of Breaches#
A1.7.1 Abuse reports are to be sent to abuse@xerio.ch. Xerio generally handles reports within 48 hours.
A1.7.2 If the Customer does not respond within the period set by Xerio in a notice — as a rule 48 hours — Xerio may suspend or terminate the affected services.
A1.7.3 In the case of alleged violations of personality rights, Xerio generally removes content only on the basis of a judicial or official decision. As a hosting provider, Xerio is not the publisher of customer content and is not in a position to assess the merits of individual allegations. Manifest infringements and cases under clause A1.2 remain reserved.
A1.7.4 Infringements of intellectual property rights are to be reported to abuse@xerio.ch.
---
---
Part of this agreement
Annex 2: Data Processing Agreement (DPA)#
A2.1 Subject Matter#
A2.1.1 This agreement governs the processing of personal data that Xerio carries out on behalf of and for the purposes of the Customer in the course of providing the services.
A2.1.2 It supplements the main contract and does not restrict the rights and obligations of the parties under it. As regards its subject matter, it prevails over the main contract.
A2.1.3 It does not apply to processing in which Xerio determines the purposes and means itself (e.g. invoicing, customer communication, domain services, operational and security logs). The Xerio privacy policy is authoritative for such processing.
A2.2 Roles#
A2.2.1 The Customer is the controller within the meaning of the FADP or the GDPR; Xerio is the processor.
A2.2.2 Where the Customer is itself a processor — in particular as a reseller or agency — it confirms that it has been authorised by its own principal to engage sub-processors and to issue instructions to Xerio.
A2.3 Scope of Processing#
A2.3.1 The purpose is the provision of the agreed services. The processing comprises storing, making available, transmitting and deleting personal data.
A2.3.2 The processing concerns data that the Customer stores on the infrastructure as well as data of persons to whom it grants access to its websites, applications or mailboxes. This typically includes log data (IP address, time of access, user agent), data entered by users, and usage data collected by the Customer.
A2.3.3 The processing continues for the term of the main contract.
A2.4 Obligations of Xerio#
A2.4.1 Xerio processes personal data solely for the performance of the main contract and within the scope of this agreement.
A2.4.2 Xerio implements further documented instructions of the Customer on request and against reasonable remuneration, to the extent that this is operationally reasonable and technically possible. Xerio informs the Customer where, in its view, an instruction infringes data protection law, and may suspend its execution pending confirmation.
A2.4.3 Xerio binds the persons entrusted with the processing to confidentiality, including beyond the duration of their engagement.
A2.4.4 Xerio takes appropriate technical and organisational measures in accordance with Addendum A.
A2.4.5 Xerio informs the Customer without delay of any breach of data security affecting its personal data and provides the information required for the Customer to meet its notification and documentation obligations.
A2.4.6 Xerio supports the Customer, on written request and against reasonable remuneration, in fulfilling data subject rights and in carrying out data protection impact assessments and consultations with supervisory authorities.
A2.4.7 Where a data subject approaches Xerio directly, Xerio refers that person to the Customer and informs the Customer, provided attribution is possible.
A2.4.8 After the end of the contract, Xerio returns or deletes the personal data in accordance with the main contract.
A2.5 Sub-processors#
A2.5.1 Xerio is entitled to engage sub-processors. Xerio makes a current list of the sub-processors engaged available to the Customer on written request within an existing contractual relationship. It is not published.
A2.5.2 Xerio gives notice in text form of the engagement or replacement of a sub-processor at least 30 days in advance. The Customer may object in writing within 15 days on data protection grounds. If no solution is found within 15 days, the Customer may terminate the affected service for cause.
A2.5.3 Xerio binds sub-processors to a level of protection corresponding to this agreement.
A2.6 Disclosure Abroad#
Xerio discloses personal data abroad only:
a) to the Customer, its affiliated companies or, on its instruction, to third parties;
b) to recipients in countries with an adequate level of data protection;
c) to other recipients, provided the safeguards required under the FADP and, where applicable, the GDPR are in place (in particular standard contractual clauses);
d) to the extent agreed with the Customer or required by law.
Where the Customer selects an infrastructure location outside Switzerland, this constitutes a corresponding instruction under lit. a.
A2.7 Obligations of the Customer#
A2.7.1 The Customer is responsible for the lawfulness of the processing, including the admissibility of processing and sub-processing on its behalf.
A2.7.2 The Customer takes appropriate technical and organisational measures within its own sphere of responsibility.
A2.7.3 The Customer informs Xerio without delay if it identifies any infringement of data protection law in Xerio's provision of the services.
A2.8 Information and Audit Rights#
A2.8.1 On written request, Xerio provides the Customer with the information it requires to demonstrate compliance with this agreement.
A2.8.2 The Customer, or an auditor appointed by it and bound to confidentiality, may verify compliance. The audit rights are subject to proportionality and to safeguarding the security and confidentiality interests of Xerio and of other customers. The Customer bears all costs, including documented internal costs of Xerio.
A2.9 Definitions#
Data protection terms have the meaning assigned to them in the FADP or, depending on the context, the GDPR.
Part of this agreement
Addendum A: Technical and Organisational Measures (TOM)#
Taking into account the nature, scope, circumstances and purpose of the processing as well as the risks to data subjects, Xerio takes the following measures in particular:
A. Confidentiality and access
- role-based, restrictive authorisation concept following the need-to-know principle
- administration by a minimal number of administrators
- multi-factor authentication for administrative access where technically possible
- all employees bound to confidentiality and data secrecy
- internal policies on passwords, mobile devices, clean desk and data destruction
B. Integrity and transmission
- remote access exclusively over encrypted connections
- encryption of data transmission using industry-standard methods; TLS for e-mail transport where supported by the remote end
- encryption of endpoints and mobile storage media
- secure storage of key material, access limited to a narrow group of persons
C. Availability and resilience
- redundant design of business-critical components
- documented backup strategy; backup systems subject to the same protective measures as production systems
- separate storage locations for operating systems and payload data where required
- trained personnel for restoration procedures
D. Physical security
- operation in data centres with access control, video surveillance and intrusion detection
- entry restricted to authorised persons; external visitors accompanied
- contractual obligation of data centre operators to corresponding measures
E. Logging and traceability
- logging of administrative access and security-relevant events
- formalised procedure for handling security incidents
- documentation of data protection breaches including nature, scope, period, consequences and measures taken
F. IT security management
- prompt installation of security updates
- ongoing monitoring and assessment of security advisories and vulnerabilities
- monitoring of remote access by third parties
G. Data minimisation and retention
- collection of personal data only to the extent necessary
- privacy-friendly default settings
- defined retention periods and regular deletion of data no longer required
- procedures for the return and deletion of data at the end of the contract
Zurich, 1 August 2026
---
---
Part of this agreement
Annex 3: Special Provisions for Colocation#
These provisions apply in addition to the GTC for all colocation services. In the event of conflict, they prevail over the GTC as regards their subject matter.
A3.1 Subject Matter#
A3.1.1 Xerio provides the Customer with the floor space designated in the contract (rack units, rack or cage) in the agreed data centre for housing the Customer's own hardware.
A3.1.2 There is no entitlement to a particular position within the data centre. Xerio may relocate the allocated space for operational reasons with 30 days' notice and at its own cost. In urgent cases, relocation may take place at short notice.
A3.2 Installation of Hardware#
A3.2.1 Only operationally safe equipment suitable for data centre operation in 19-inch form factor and compliant with the applicable standards and conformity requirements is admitted.
A3.2.2 The Customer registers the hardware to be installed in advance, stating type, number of rack units, serial numbers, power consumption and connection type. Xerio may refuse the installation of equipment that has not been registered, that exceeds the connected load or that could endanger operations.
A3.2.3 Not admitted are, in particular, devices with open lead-acid batteries, devices with impermissible interference emissions, devices without suitable mounting, and combustible packaging and storage material of any kind.
A3.2.4 Installation and removal are carried out by Xerio, or by the Customer under supervision or by prior arrangement.
A3.3 Power#
A3.3.1 The connected load agreed in the contract per rack or feed is authoritative. Consumption is metered.
A3.3.2 Where the agreed load is exceeded, Xerio may charge for the excess at the published rates, require an adjustment of the contract or — after an unsuccessful request — disconnect individual devices.
A3.3.3 Where power is fed redundantly (paths A and B), the Customer distributes its load such that, on failure of one path, the load on the remaining path does not exceed the agreed connected load. Devices with only one power supply unit must be connected via a suitable transfer switch.
A3.4 Cooling and Airflow#
A3.4.1 The Customer orients its equipment in accordance with the hot-aisle/cold-aisle principle, closes unoccupied rack units with blanking panels and keeps the airflow clear.
A3.4.2 Cables and objects must not impair the airflow, doors, escape routes, or fire detection and suppression systems.
A3.5 Access#
A3.5.1 Access is granted exclusively to persons designated by the Customer in writing. The Customer keeps this list current at all times and reports the lapse of any authorisation without delay.
A3.5.2 Authorised persons identify themselves with an official identity document. Access is logged. Xerio may require accompaniment and may make access conditional on prior notification.
A3.5.3 The following are prohibited in particular: bringing in unauthorised persons; interfering with third-party racks, cabling or infrastructure installations; taking photographs or recordings without consent; smoking; and consuming food and drink in the operating areas.
A3.5.4 Instructions of Xerio personnel and of the data centre operator must be followed. In the event of breaches, Xerio may permanently refuse access to individual persons.
A3.6 Cabling and Cross-connects#
A3.6.1 Connections outside the allocated rack, in particular cross-connects to third parties or into the meet-me room, are established exclusively by Xerio or with its prior written consent, and are charged at the published rates.
A3.6.2 All cables must be clearly labelled at both ends and routed properly. Xerio may, after a request, rectify non-compliant cabling at the Customer's expense.
A3.7 Remote Hands#
Simple on-site actions (reboot, visual inspection, media change) are performed by Xerio free of charge on request. Work beyond this is charged on a time-and-materials basis. Instructions must be given in writing and unambiguously; Xerio carries them out to the best of its knowledge and is liable for the outcome only within the scope of clause 10 of the GTC.
A3.8 Title and Insurance#
A3.8.1 Hardware installed by the Customer remains its property. The Customer evidences its title on request. Where the hardware is owned by a third party (e.g. a lessor), the Customer notifies Xerio in advance.
A3.8.2 The Customer insures its hardware and the data on it at its own expense and to an appropriate extent. Xerio does not take out insurance for the Customer's benefit.
A3.8.3 Xerio is liable for damage to, loss of or destruction of customer hardware exclusively within the scope of clause 10 of the GTC.
A3.9 Right of Retention#
Xerio holds a right of retention over the installed hardware under Art. 895 et seq. of the Swiss Civil Code for receivables due under the contractual relationship, insofar as the hardware is owned by the Customer. Xerio may refuse access and release until receivables due have been settled in full.
A3.10 End of Contract and Vacation of Space#
A3.10.1 The Customer vacates the floor space in full by the end of the contract and restores it to its original condition.
A3.10.2 Where the space is not vacated in good time, Xerio may invoice the fee for the continued occupancy pro rata temporis. Following a written request and a grace period of 30 days, Xerio is entitled to remove and store the hardware at the Customer's expense or — after a further period of 30 days has expired unused — to realise or properly dispose of it. Any proceeds of realisation are set off against outstanding receivables after deduction of costs.
A3.10.3 The Customer is responsible for deleting its data before the equipment is returned.
A3.11 Emergencies and Operational Safety#
A3.11.1 Xerio may switch off or disconnect individual devices without prior notice where they present a danger to persons, to the facility or to other customers — in particular in the event of overload, overheating, fire risk, interference emissions, escaping substances or abusive use. Xerio informs the Customer without delay.
A3.11.2 Xerio may carry out planned interruptions of the power or network supply for maintenance and testing. Such windows are announced at least 14 days in advance and do not count as downtime within the meaning of clause 2.9.
Zurich, 1 August 2026
