SaveState organization agreement
Version 2026-08-30-v1 · Effective 30 August 2026
This business-to-business master agreement is between SaveState, operated personally by Gustav Fyhn Larsen with guardian approval, Dalagervej 12, 6623 Vorbasse, Denmark (“SaveState”), and the organization accepting it (“Organization”). It covers the organization portal, management API, customer entitlements, installations, and related encrypted backup services across savestate.dk and its subdomains.
Contract formation and orders
The person accepting confirms that they are at least 18, are authorized to bind the Organization, and accept this agreement and the Data Processing Addendum. Acceptance is recorded electronically. Each invitation, purchase link, order, or pilot schedule accepted by the parties is an “Order” and states the applicable capacity, price, billing interval, pilot scope, or special term. This master agreement controls unless an Order expressly identifies the clause it changes. Consumer use and unauthorized acceptance are not permitted through the organization portal.
Service and customer relationship
SaveState provides the Organization with scoped management functions for creating and administering customer entitlements, lifecycle actions, installations, API keys, and operational metadata. The Organization, not SaveState, selects its end customers, manages its commercial relationship with them, bills them, handles first-line support, gives required notices, obtains lawful instructions, and remains responsible for promises it makes. The Organization may not represent that it can bind SaveState or offer terms, warranties, credits, or service levels on SaveState’s behalf.
End customers may need a separate SaveState account to control authentication, recovery credentials, encryption material, and restores. Granting or changing an entitlement through the API changes the assigned quota without a separate customer acceptance step, but it does not authorize the Organization to access plaintext backup contents or customer credentials.
Capacity, quota, and billing
The Order states the Organization’s purchased storage allowance and price. Customer entitlements allocate capacity within that allowance. Unless an Order expressly says otherwise, usage is the actual encrypted Kopia repository footprint after compression and deduplication, including repository packs, indexes, metadata, and stored object versions. Source bytes and estimated optimization savings are informational and do not determine quota.
Reducing an entitlement below retained usage blocks new writes but does not delete retained data or immediately return capacity. Kopia maintenance may need time and temporary headroom to reclaim unreferenced packs. No overage right is implied. SaveState may reject new allocations or writes that exceed purchased or safety capacity.
Prices and intervals are those in the Order. SaveState is not VAT registered and does not currently add VAT. If a future registration or tax obligation requires a charge, it applies only as required and will be disclosed for future invoices or renewals. The Organization is responsible for its own resale taxes, invoices, and customer charges.
API use and security
API keys are secret server credentials. The Organization must keep them out of browsers, client software, public repositories, and logs; grant only required scopes; rotate exposed credentials; validate webhook signatures; use TLS; and promptly report suspected compromise. Keys, sessions, roles, and resources are organization-scoped. The Organization may not bypass limits, enumerate other tenants, resell raw API access, interfere with security controls, or use the service unlawfully.
External customer identifiers must be unique, stable, non-secret identifiers from the Organization’s own system. The Organization must use idempotency controls where documented and reconcile API responses and webhook deliveries. SaveState may rate-limit, revoke, or suspend credentials to prevent abuse, protect customers, or contain an incident.
Customer lifecycle and deletion
Lifecycle operations are distinct. Suspension blocks new protection while retaining data. Resume re-enables an eligible service. Termination begins the documented three-day restore-only grace. Permanent purge is a separate privileged deletion instruction available only after the grace and cannot be undone. A quota reduction is never a deletion instruction. The Organization must authenticate and authorize customer requests before issuing lifecycle or purge commands and is responsible for erroneous, premature, duplicated, or unauthorized instructions.
Data protection and confidentiality
The Data Processing Addendum is incorporated. Where the Organization determines purposes and means, it is controller and SaveState is processor. Where the Organization acts for an end customer, the Organization is processor and appoints SaveState as subprocessor. The Organization warrants that it has authority to do so and will pass through lawful controller instructions. Each party must protect the other party’s non-public technical, security, customer, and commercial information and use it only to perform this agreement.
Encryption and recovery responsibility
Backup contents are encrypted before upload. SaveState is not given the repository password or plaintext vault master key. The Organization and end customer are responsible for correct backup selection, working encryption and recovery material, suitable independent copies, and periodic restore tests. Lost customer-controlled keys may make backups permanently unrecoverable. The management API does not provide plaintext backup access.
Availability, support, and changes
SaveState’s current operational targets are 99.9% service availability and an initial support response within 24 hours. These are planning targets, not warranties, service-level commitments, or credit entitlements. No backup system eliminates every risk, and Cloudflare, Backblaze, Stripe, internet, or customer-system failures may affect service. A binding SLA exists only if an Order expressly states its measurement, exclusions, remedy, and service credits.
SaveState may make reasonable security, provider, API, and feature changes. For a breaking API change, SaveState will give reasonable advance notice where practicable. Emergency security and legal changes may take effect sooner. Preview and pilot features may be changed or withdrawn and have no production SLA unless the Order expressly says otherwise.
Acceptable use and suspension
The Organization must not store unlawful content, infringe rights, distribute malware, probe other accounts, bypass capacity or security controls, use the service for regulated processing requiring unagreed controls, or expose SaveState or its providers to legal or operational harm. SaveState may immediately suspend affected access where reasonably necessary for security, non-payment, abuse, unlawful use, capacity protection, or provider/legal compliance and will restore access when the grounds are resolved where reasonably possible.
Term and termination
This agreement begins on recorded acceptance and continues while any Order or organization service is active. Either party may terminate on the notice in the Order, or for material breach not cured within 14 days after notice. Immediate termination is permitted for fraud, unlawful use, serious security risk, insolvency, or breach that cannot be cured. Termination stops new API activity and allocations; retained customer data follows the documented lifecycle and DPA rather than being silently deleted.
Warranties and liability
Each party warrants that it has authority to enter this agreement. Except for express terms and mandatory law, the service is provided as available without implied guarantees of uninterrupted operation, a particular recovery outcome, merchantability, or fitness for a specific purpose. The Organization indemnifies SaveState, to the fullest extent permitted by law, against third-party claims, regulatory costs, and reasonable legal expenses caused by the Organization’s customer relationship, unlawful instructions, promises, content, security failure, misuse, or breach.
Neither party is liable for indirect or consequential loss, lost profit, lost revenue, lost goodwill, loss of anticipated savings, or loss avoidable through a reasonable recovery strategy. SaveState’s aggregate liability arising from the organization service, whether in contract, tort, indemnity, or otherwise, is limited to fees the Organization paid under the affected Order during the 12 months before the event. The exclusions and cap yield only to liability that applicable law does not permit the parties to exclude or limit, including fraud, wilful misconduct, gross negligence, or mandatory data-protection liability.
Events beyond reasonable control
Neither party is liable for delay or failure caused by an event beyond its reasonable control, including widespread internet or cloud-provider failure, war, civil disorder, government action, labour disruption, natural disaster, epidemic, power or telecommunications failure, or attack that could not reasonably have been prevented. Payment obligations already due are not excused. The affected party must use reasonable efforts to limit the effect and resume performance.
Law, notices, and entire agreement
Danish law governs this agreement. Disputes are subject to the competent Danish courts. Notices may be sent to the organization owner email and to SaveState at [email protected]. The accepted agreement, DPA, and Orders are the entire agreement for the organization service and replace earlier statements about that subject. A failure to enforce once is not a waiver. Invalid provisions are limited only as necessary, and the rest remains effective.
