# KapsuleHost: full text > KapsuleHost sells web and WordPress hosting, business email, domain names, cloud and dedicated servers, and managed services. It is run by Kapsule Group Limited, a New Zealand company. > Every page below is also published as Markdown at its own address plus ".md". Prices on those pages are read from our live catalogue, may be up to a few minutes old, and are shown in every currency we sell in. --- # KapsuleHost: Your Business, Online In Minutes Web hosting, WordPress, domains, business email and servers on one panel and one bill. Start with what you need and add the rest later. See the plans. Canonical page: https://kapsulehost.com/en-us ## On this page - Your business, online in minutes. - One account. Every tool your business runs on. - A control panel you'll actually enjoy using. - Your price is your price. Forever. - Switching hosts? We'll carry the boxes. - Meet your new favourite coworker. - Your AI, plugged straight into your hosting. - Fast. Secure. Backed up every night. - Hosted in Europe. Not in big tech's back pocket. - Your current host is hoping you don't read this. - Good questions. Straight answers. - Your business deserves a better host. Let's go. ## Products - [Web hosting](https://kapsulehost.com/hosting/web.md) - [WordPress hosting](https://kapsulehost.com/hosting/wordpress.md) - [WooCommerce hosting](https://kapsulehost.com/hosting/woocommerce.md) - [Managed hosting](https://kapsulehost.com/hosting/managed.md) - [Business email](https://kapsulehost.com/email.md) - [Domains](https://kapsulehost.com/domains.md) - [Cloud servers](https://kapsulehost.com/servers/cloud.md) - [Dedicated servers](https://kapsulehost.com/servers/dedicated.md) - [GPU servers](https://kapsulehost.com/servers/gpu.md) - [Storage servers](https://kapsulehost.com/servers/storage.md) - [Container hosting](https://kapsulehost.com/hosting/containers.md) - [Reseller hosting](https://kapsulehost.com/hosting/reseller.md) - [Protect](https://kapsulehost.com/protect.md) - [Kora](https://kapsulehost.com/kora.md) - [Kapsule Agents](https://kapsulehost.com/agents.md) - [Kapsule Bench](https://kapsulehost.com/bench.md) - [KPanel control panel](https://kapsulehost.com/kpanel.md) Full pricing, every product, every currency we sell in: https://kapsulehost.com/pricing.md An index of every page in Markdown: https://kapsulehost.com/llms.txt --- Summary of KapsuleHost: Your Business, Online In Minutes (https://kapsulehost.com/en-us), published for AI readers and agents. It is built from the page's title, description and links (and any live prices), not its full text: for everything on the page, visit the canonical URL above. --- # Web Hosting Cost: Every Plan We Sell, One Page | KapsuleHost Every plan we sell on one page, in your own currency: web hosting, WordPress, email, servers and more. Tax shows on its own line at checkout. See every plan. Canonical page: https://kapsulehost.com/en-us/pricing Every price below is read from the live KapsuleHost catalogue and may be up to a few minutes old, and is shown in every currency KapsuleHost sells in (10 currencies: USD, NZD, AED, AUD, CAD, CNY, EUR, GBP, JPY, SGD). ## Web hosting Product page: https://kapsulehost.com/en-us/hosting/web (Markdown: https://kapsulehost.com/hosting/web.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Start | per month | 10 GB storage, 1 site, 5 mailboxes | On sale | US$3 | NZ$5 | ⃃ 11 | AU$5 | CA$5 | CN¥21 | €3 | £2.50 | ¥450 | S$4 | | Pro | per month | 50 GB storage, 10 sites, 25 mailboxes | On sale | US$9 | NZ$15 | ⃃ 33 | AU$16 | CA$13 | CN¥63 | €9 | £7.50 | ¥1,350 | S$12 | | Scale | per month | 200 GB storage, 25 sites, 100 mailboxes | On sale | US$21 | NZ$35 | ⃃ 77 | AU$38 | CA$30 | CN¥147 | €21 | £18 | ¥3,150 | S$28 | | Cloud Power | per month | - | On sale | US$45 | NZ$75 | ⃃ 165 | AU$82 | CA$64 | CN¥315 | €45 | £36 | ¥6,750 | S$60 | ## WordPress hosting Product page: https://kapsulehost.com/en-us/hosting/wordpress (Markdown: https://kapsulehost.com/hosting/wordpress.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | WordPress Start | per month | 20 GB storage, 1 site, 5 mailboxes | On sale | US$5 | NZ$8 | ⃃ 18 | AU$9 | CA$7 | CN¥34 | €5 | £4 | ¥720 | S$7 | | WordPress Pro | per month | 100 GB storage, 5 sites, 25 mailboxes | On sale | US$14 | NZ$25 | ⃃ 55 | AU$27 | CA$22 | CN¥105 | €14 | £12 | ¥2,250 | S$20 | | Managed WP Start | per month | 20 GB storage, 1 site, 5 mailboxes | On sale | US$12 | NZ$19 | ⃃ 42 | AU$21 | CA$17 | CN¥80 | €12 | £9.50 | ¥1,710 | S$16 | | Managed WP Pro | per month | 100 GB storage, 5 sites, 10 mailboxes | On sale | US$30 | NZ$49 | ⃃ 108 | AU$53 | CA$42 | CN¥206 | €30 | £25 | ¥4,410 | S$40 | ## WooCommerce hosting Product page: https://kapsulehost.com/en-us/hosting/woocommerce (Markdown: https://kapsulehost.com/hosting/woocommerce.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Managed WC Start | per month | 30 GB storage, 1 site, 10 mailboxes | On sale | US$24 | NZ$39 | ⃃ 86 | AU$43 | CA$34 | CN¥164 | €24 | £20 | ¥3,510 | S$32 | | Managed WC Pro | per month | 100 GB storage, 1 site, 25 mailboxes | On sale | US$48 | NZ$79 | ⃃ 174 | AU$86 | CA$68 | CN¥332 | €48 | £40 | ¥7,110 | S$64 | ## Business email Product page: https://kapsulehost.com/en-us/email (Markdown: https://kapsulehost.com/email.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Email Solo | per month | 10 GB quota, 1 mailboxes | On sale | US$2 | NZ$3 | ⃃ 7 | AU$4 | CA$3 | CN¥13 | €2 | £1.50 | ¥270 | S$3 | | Email Team | per month | 10 GB quota, 5 mailboxes | On sale | US$8 | NZ$12 | ⃃ 27 | AU$13 | CA$11 | CN¥51 | €8 | £6 | ¥1,080 | S$10 | | Email Business | per month | 10 GB quota, 25 mailboxes | On sale | US$18 | NZ$30 | ⃃ 66 | AU$33 | CA$26 | CN¥126 | €18 | £15 | ¥2,700 | S$24 | | Email Premium | per month | - | On sale | US$15 | NZ$25 | ⃃ 56 | AU$27 | CA$22 | CN¥105 | €15 | £13 | ¥2,250 | S$20 | ## Bench Product page: https://kapsulehost.com/en-us/bench (Markdown: https://kapsulehost.com/bench.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Bench Starter | per month | 2 vCPU, 4 GB RAM, 400 credits | On sale | US$9 | NZ$15 | ⃃ 33 | AU$14 | CA$12 | CN¥63 | €8 | £7 | ¥1,340 | S$12 | | Bench Pro | per month | 4 vCPU, 8 GB RAM, 1200 credits | On sale | US$19 | NZ$32 | ⃃ 70 | AU$29 | CA$26 | CN¥133 | €17 | £15 | ¥2,830 | S$25 | | Bench Power | per month | 8 vCPU, 16 GB RAM, 2800 credits | On sale | US$35 | NZ$60 | ⃃ 130 | AU$53 | CA$47 | CN¥245 | €32 | £28 | ¥5,220 | S$46 | ## AI agents Product page: https://kapsulehost.com/en-us/agents (Markdown: https://kapsulehost.com/agents.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Agents Credit Pack | per month | 1200 credits | On sale | US$9.99 | NZ$16.99 | ⃃ 36.99 | AU$14.99 | CA$13.49 | CN¥69.99 | €8.99 | £7.99 | ¥1,490 | S$12.99 | | Agents Top-Up: 150 Credits | one time | 150 credits | On sale | US$2.99 | NZ$4.99 | ⃃ 10.99 | AU$4.49 | CA$3.99 | CN¥19.99 | €2.49 | £2.49 | ¥449 | S$3.99 | | Agents Top-Up: 500 Credits | one time | 500 credits | On sale | US$7.99 | NZ$13.49 | ⃃ 28.99 | AU$11.99 | CA$10.49 | CN¥54.99 | €6.99 | £6.49 | ¥1,190 | S$10.49 | ## Container hosting Product page: https://kapsulehost.com/en-us/hosting/containers (Markdown: https://kapsulehost.com/hosting/containers.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Pod | per month | - | On sale | US$18 | NZ$29 | ⃃ 64 | AU$32 | CA$25 | CN¥122 | €18 | £15 | ¥2,610 | S$24 | | Cluster | per month | - | On sale | US$54 | NZ$89 | ⃃ 196 | AU$97 | CA$76 | CN¥374 | €54 | £45 | ¥8,010 | S$72 | | Fleet | per month | - | On sale | US$150 | NZ$249 | ⃃ 548 | AU$269 | CA$212 | CN¥1,046 | €150 | £125 | ¥22,410 | S$200 | ## Cloud VPS Product page: https://kapsulehost.com/en-us/servers/cloud (Markdown: https://kapsulehost.com/servers/cloud.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Photon | per month | 2 vCPU, 4 GB RAM, 40 GB disk | On sale | US$16 | NZ$29 | ⃃ 59 | AU$23 | CA$23 | CN¥110 | €14 | £12 | ¥2,590 | S$21 | | Quark | per month | 4 vCPU, 8 GB RAM, 80 GB disk | On sale | US$28 | NZ$49 | ⃃ 105 | AU$41 | CA$40 | CN¥190 | €25 | £21 | ¥4,530 | S$36 | | Lepton | per month | 8 vCPU, 16 GB RAM, 160 GB disk | On sale | US$55 | NZ$98 | ⃃ 200 | AU$80 | CA$78 | CN¥375 | €48 | £42 | ¥8,900 | S$71 | | Muon | per month | 16 vCPU, 32 GB RAM, 320 GB disk | On sale | US$107 | NZ$189 | ⃃ 395 | AU$155 | CA$150 | CN¥730 | €94 | £81 | ¥17,320 | S$140 | | Meteor | per month | 1 vCPU, 2 GB RAM, 40 GB disk | On sale | US$20 | NZ$35 | ⃃ 73 | AU$29 | CA$28 | CN¥135 | €18 | £15 | ¥3,240 | S$26 | | Comet | per month | 2 vCPU, 4 GB RAM, 80 GB disk | On sale | US$35 | NZ$62 | ⃃ 130 | AU$51 | CA$50 | CN¥240 | €31 | £26 | ¥5,670 | S$45 | | Atlas | per month | 4 vCPU, 8 GB RAM, 160 GB disk | On sale | US$65 | NZ$115 | ⃃ 240 | AU$94 | CA$92 | CN¥440 | €57 | £49 | ¥10,520 | S$84 | | Apollo | per month | 8 vCPU, 16 GB RAM, 320 GB disk | On sale | US$120 | NZ$213 | ⃃ 440 | AU$175 | CA$170 | CN¥815 | €105 | £91 | ¥19,430 | S$155 | | Vega | per month | 12 vCPU, 24 GB RAM, 480 GB disk | On sale | US$174 | NZ$308 | ⃃ 640 | AU$255 | CA$245 | CN¥1,185 | €150 | £130 | ¥28,170 | S$225 | | Pulsar | per month | 16 vCPU, 32 GB RAM, 640 GB disk | On sale | US$220 | NZ$389 | ⃃ 810 | AU$320 | CA$310 | CN¥1,495 | €195 | £165 | ¥35,620 | S$285 | | Quasar | per month | 2 vCPU, 8 GB RAM, 80 GB disk | On sale | US$70 | NZ$124 | ⃃ 255 | AU$100 | CA$99 | CN¥475 | €61 | £53 | ¥11,330 | S$91 | | Orion | per month | 4 vCPU, 16 GB RAM, 160 GB disk | On sale | US$140 | NZ$248 | ⃃ 515 | AU$205 | CA$200 | CN¥955 | €125 | £105 | ¥22,660 | S$180 | | Nebula | per month | 8 vCPU, 32 GB RAM, 240 GB disk | On sale | US$230 | NZ$407 | ⃃ 845 | AU$335 | CA$325 | CN¥1,565 | €200 | £175 | ¥37,230 | S$295 | | Nova | per month | 16 vCPU, 64 GB RAM, 360 GB disk | On sale | US$440 | NZ$779 | ⃃ 1,615 | AU$640 | CA$625 | CN¥2,995 | €385 | £330 | ¥71,230 | S$570 | | Sirius | per month | 32 vCPU, 128 GB RAM, 600 GB disk | On sale | US$839 | NZ$1,485 | ⃃ 3,080 | AU$1,220 | CA$1,190 | CN¥5,710 | €735 | £635 | ¥135,830 | S$1,085 | | Andromeda | per month | 48 vCPU, 192 GB RAM, 960 GB disk | On sale | US$1,339 | NZ$2,370 | ⃃ 4,915 | AU$1,945 | CA$1,900 | CN¥9,110 | €1,175 | £1,010 | ¥216,770 | S$1,730 | ## Managed cloud servers Product page: https://kapsulehost.com/en-us/servers/cloud (Markdown: https://kapsulehost.com/servers/cloud.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Photon Managed | per month | 2 vCPU, 4 GB RAM, 40 GB disk | On sale | US$20 | NZ$36 | ⃃ 73 | AU$29 | CA$28 | CN¥135 | €18 | £15 | ¥3,240 | S$26 | | Quark Managed | per month | 4 vCPU, 8 GB RAM, 80 GB disk | On sale | US$35 | NZ$62 | ⃃ 130 | AU$51 | CA$50 | CN¥240 | €31 | £26 | ¥5,670 | S$45 | | Lepton Managed | per month | 8 vCPU, 16 GB RAM, 160 GB disk | On sale | US$69 | NZ$122 | ⃃ 255 | AU$100 | CA$98 | CN¥470 | €60 | £52 | ¥11,170 | S$89 | | Muon Managed | per month | 16 vCPU, 32 GB RAM, 320 GB disk | On sale | US$134 | NZ$237 | ⃃ 490 | AU$195 | CA$190 | CN¥910 | €115 | £100 | ¥21,690 | S$175 | | Meteor Managed | per month | 1 vCPU, 2 GB RAM, 40 GB disk | On sale | US$36 | NZ$63 | ⃃ 130 | AU$52 | CA$51 | CN¥245 | €32 | £27 | ¥5,830 | S$47 | | Comet Managed | per month | 2 vCPU, 4 GB RAM, 80 GB disk | On sale | US$63 | NZ$112 | ⃃ 230 | AU$91 | CA$89 | CN¥430 | €55 | £48 | ¥10,200 | S$81 | | Atlas Managed | per month | 4 vCPU, 8 GB RAM, 160 GB disk | On sale | US$115 | NZ$204 | ⃃ 420 | AU$165 | CA$165 | CN¥785 | €100 | £87 | ¥18,620 | S$150 | | Apollo Managed | per month | 8 vCPU, 16 GB RAM, 320 GB disk | On sale | US$225 | NZ$398 | ⃃ 825 | AU$325 | CA$320 | CN¥1,530 | €195 | £170 | ¥36,430 | S$290 | | Vega Managed | per month | 12 vCPU, 24 GB RAM, 480 GB disk | On sale | US$327 | NZ$579 | ⃃ 1,200 | AU$475 | CA$465 | CN¥2,225 | €285 | £245 | ¥52,940 | S$425 | | Pulsar Managed | per month | 16 vCPU, 32 GB RAM, 640 GB disk | On sale | US$420 | NZ$743 | ⃃ 1,540 | AU$610 | CA$595 | CN¥2,860 | €370 | £315 | ¥67,990 | S$545 | | Quasar Managed | per month | 2 vCPU, 8 GB RAM, 80 GB disk | On sale | US$139 | NZ$246 | ⃃ 510 | AU$200 | CA$195 | CN¥945 | €120 | £105 | ¥22,500 | S$180 | | Orion Managed | per month | 4 vCPU, 16 GB RAM, 160 GB disk | On sale | US$279 | NZ$494 | ⃃ 1,025 | AU$405 | CA$395 | CN¥1,900 | €245 | £210 | ¥45,170 | S$360 | | Nebula Managed | per month | 8 vCPU, 32 GB RAM, 240 GB disk | On sale | US$449 | NZ$795 | ⃃ 1,650 | AU$650 | CA$640 | CN¥3,055 | €395 | £340 | ¥72,690 | S$580 | | Nova Managed | per month | 16 vCPU, 64 GB RAM, 360 GB disk | On sale | US$895 | NZ$1,584 | ⃃ 3,285 | AU$1,300 | CA$1,270 | CN¥6,090 | €785 | £675 | ¥144,890 | S$1,155 | | Sirius Managed | per month | 32 vCPU, 128 GB RAM, 600 GB disk | On sale | US$1,730 | NZ$3,062 | ⃃ 6,355 | AU$2,510 | CA$2,455 | CN¥11,770 | €1,515 | £1,305 | ¥280,070 | S$2,235 | | Andromeda Managed | per month | 48 vCPU, 192 GB RAM, 960 GB disk | On sale | US$2,769 | NZ$4,901 | ⃃ 10,170 | AU$4,020 | CA$3,935 | CN¥18,840 | €2,425 | £2,090 | ¥448,270 | S$3,580 | ## Dedicated servers Product page: https://kapsulehost.com/en-us/servers/dedicated (Markdown: https://kapsulehost.com/servers/dedicated.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Bedrock | per month | 8 cores, 64 GB RAM, 2×512GB NVMe | On sale | US$145 | NZ$260 | ⃃ 535 | AU$285 | CA$205 | CN¥985 | €158 | £132 | ¥23,470 | S$185 | | Slate | per month | 16 cores, 128 GB RAM, 2×1.92TB NVMe | On sale | US$370 | NZ$660 | ⃃ 1,360 | AU$535 | CA$525 | CN¥2,520 | €325 | £280 | ¥59,900 | S$480 | | Basalt | per month | 32 cores, 128 GB RAM, NVMe | On sale | US$810 | NZ$1,440 | ⃃ 2,975 | AU$1,175 | CA$1,150 | CN¥5,510 | €710 | £610 | ¥131,130 | S$1,045 | | Granite | per month | 48 cores, 128 GB RAM, 2×3.84TB NVMe | On sale | US$870 | NZ$1,540 | ⃃ 3,195 | AU$1,265 | CA$1,235 | CN¥5,920 | €760 | £655 | ¥140,840 | S$1,125 | | Titan | per month | 86 cores, 256 GB RAM, NVMe | On sale | US$1,320 | NZ$2,340 | ⃃ 4,850 | AU$2,412 | CA$1,875 | CN¥8,980 | €1,340 | £995 | ¥213,700 | S$1,705 | | Bedrock Managed | per month | 8 cores, 64 GB RAM, 2×512GB NVMe | On sale | US$330 | NZ$590 | ⃃ 1,210 | AU$480 | CA$470 | CN¥2,245 | €290 | £250 | ¥53,420 | S$425 | | Slate Managed | per month | 16 cores, 128 GB RAM, 2×1.92TB NVMe | On sale | US$840 | NZ$1,490 | ⃃ 3,085 | AU$1,220 | CA$1,195 | CN¥5,715 | €735 | £635 | ¥135,990 | S$1,085 | | Basalt Managed | per month | 32 cores, 128 GB RAM, NVMe | On sale | US$1,840 | NZ$3,260 | ⃃ 6,755 | AU$2,670 | CA$2,615 | CN¥12,520 | €1,610 | £1,390 | ¥297,880 | S$2,380 | | Granite Managed | per month | 48 cores, 128 GB RAM, 2×3.84TB NVMe | On sale | US$1,990 | NZ$3,530 | ⃃ 7,310 | AU$2,890 | CA$2,825 | CN¥13,540 | €1,745 | £1,505 | ¥322,160 | S$2,575 | | Titan Managed | per month | 86 cores, 256 GB RAM, NVMe | On sale | US$3,020 | NZ$5,350 | ⃃ 11,090 | AU$4,385 | CA$4,290 | CN¥20,550 | €2,645 | £2,280 | ¥488,910 | S$3,905 | ## Storage servers Product page: https://kapsulehost.com/en-us/servers/storage (Markdown: https://kapsulehost.com/servers/storage.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Shelf | per month | 64 GB RAM, 64 TB storage | On sale | US$115 | NZ$210 | ⃃ 420 | AU$165 | CA$165 | CN¥785 | €100 | £87 | ¥18,620 | S$150 | | Trench | per month | 128 GB RAM, 176 TB storage | On sale | US$640 | NZ$1,140 | ⃃ 2,350 | AU$930 | CA$910 | CN¥4,355 | €560 | £485 | ¥103,610 | S$830 | | Abyss | per month | 256 GB RAM, 308 TB storage | On sale | US$1,200 | NZ$2,130 | ⃃ 4,405 | AU$1,740 | CA$1,705 | CN¥8,165 | €1,050 | £905 | ¥194,270 | S$1,550 | | Shelf Managed | per month | 64 GB RAM, 64 TB storage | On sale | US$260 | NZ$470 | ⃃ 955 | AU$375 | CA$370 | CN¥1,770 | €230 | £195 | ¥42,090 | S$335 | | Trench Managed | per month | 128 GB RAM, 176 TB storage | On sale | US$1,450 | NZ$2,570 | ⃃ 5,325 | AU$2,105 | CA$2,060 | CN¥9,865 | €1,270 | £1,095 | ¥234,740 | S$1,875 | | Abyss Managed | per month | 256 GB RAM, 308 TB storage | On sale | US$2,750 | NZ$4,870 | ⃃ 10,100 | AU$3,995 | CA$3,905 | CN¥18,710 | €2,410 | £2,075 | ¥445,200 | S$3,555 | ## GPU servers Product page: https://kapsulehost.com/en-us/servers/gpu (Markdown: https://kapsulehost.com/servers/gpu.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Spark | per month | 20 GB GPU RAM | On sale | US$330 | NZ$590 | ⃃ 1,210 | AU$480 | CA$470 | CN¥2,245 | €290 | £250 | ¥53,420 | S$425 | | Forge | per month | 256 GB RAM, 96 GB GPU RAM | On sale | US$1,680 | NZ$2,980 | ⃃ 6,170 | AU$2,440 | CA$2,385 | CN¥11,430 | €1,470 | £1,270 | ¥271,980 | S$2,170 | | Foundry | per month | 512 GB RAM, 96 GB GPU RAM | On sale | US$2,520 | NZ$4,470 | ⃃ 9,255 | AU$3,660 | CA$3,580 | CN¥17,145 | €2,205 | £1,905 | ¥407,960 | S$3,260 | | Reactor | per month | 768 GB RAM, 96 GB GPU RAM | On sale | US$3,240 | NZ$5,740 | ⃃ 11,900 | AU$4,705 | CA$4,600 | CN¥22,045 | €2,840 | £2,445 | ¥524,530 | S$4,190 | | Spark Managed | per month | 20 GB GPU RAM | On sale | US$750 | NZ$1,330 | ⃃ 2,755 | AU$1,090 | CA$1,065 | CN¥5,105 | €655 | £565 | ¥121,420 | S$970 | | Forge Managed | per month | 256 GB RAM, 96 GB GPU RAM | On sale | US$3,850 | NZ$6,820 | ⃃ 14,140 | AU$5,590 | CA$5,470 | CN¥26,195 | €3,375 | £2,905 | ¥623,280 | S$4,980 | | Foundry Managed | per month | 512 GB RAM, 96 GB GPU RAM | On sale | US$5,770 | NZ$10,220 | ⃃ 21,190 | AU$8,375 | CA$8,195 | CN¥39,260 | €5,055 | £4,355 | ¥934,110 | S$7,460 | | Reactor Managed | per month | 768 GB RAM, 96 GB GPU RAM | On sale | US$7,420 | NZ$13,140 | ⃃ 27,250 | AU$10,775 | CA$10,540 | CN¥50,490 | €6,500 | £5,605 | ¥1,201,230 | S$9,595 | ## Backup Product page: https://kapsulehost.com/en-us/protect/backup (Markdown: https://kapsulehost.com/protect/backup.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Backup 90 | per month | 90 day retention | On sale | US$3 | NZ$5 | ⃃ 11 | AU$5 | CA$5 | CN¥21 | €3 | £2.50 | ¥450 | S$4 | | Backup 1-Year | per month | 365 day retention | On sale | US$9 | NZ$15 | ⃃ 33 | AU$16 | CA$13 | CN¥63 | €9 | £7.50 | ¥1,350 | S$12 | | Backup 7-Year | per month | 2555 day retention | On sale | US$29 | NZ$49 | ⃃ 109 | AU$55 | CA$42 | CN¥206 | €29 | £25 | ¥4,500 | S$40 | ## SSL certificates Product page: https://kapsulehost.com/en-us/protect/ssl (Markdown: https://kapsulehost.com/protect/ssl.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | SSL DV Branded | per year | - | On sale | US$15 | NZ$25 | ⃃ 56 | AU$27 | CA$22 | CN¥105 | €15 | £13 | ¥2,250 | S$20 | | SSL Wildcard DV | per year | - | On sale | US$114 | NZ$189 | ⃃ 416 | AU$205 | CA$161 | CN¥794 | €114 | £95 | ¥17,010 | S$152 | | SSL OV (Organisation Validated) | per year | - | On sale | US$90 | NZ$149 | ⃃ 328 | AU$161 | CA$127 | CN¥626 | €90 | £75 | ¥13,410 | S$120 | | SSL Wildcard OV | per year | - | On sale | US$198 | NZ$329 | ⃃ 724 | AU$356 | CA$280 | CN¥1,382 | €198 | £165 | ¥29,610 | S$264 | | Multi-Domain (SAN) SSL | per year | - | On sale | US$150 | NZ$249 | ⃃ 548 | AU$269 | CA$212 | CN¥1,046 | €150 | £125 | ¥22,410 | S$200 | | SSL EV (Extended Validation) | per year | - | On sale | US$210 | NZ$349 | ⃃ 768 | AU$377 | CA$297 | CN¥1,466 | €210 | £175 | ¥31,410 | S$280 | ## Network and DNS Product page: https://kapsulehost.com/en-us/domains/dns (Markdown: https://kapsulehost.com/domains/dns.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Premium DNS | per month | - | On sale | US$11 | NZ$19 | ⃃ 42 | AU$21 | CA$17 | CN¥80 | €11 | £9.50 | ¥1,710 | S$16 | | Additional IPv4 Address | per month | - | On sale | US$4 | NZ$6 | ⃃ 13 | AU$6 | CA$5 | CN¥25 | €4 | £3 | ¥540 | S$5 | ## WordPress care Product page: https://kapsulehost.com/en-us/protect/wordpress-care (Markdown: https://kapsulehost.com/protect/wordpress-care.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Kapsule Care Basic | per month | - | On sale | US$48 | NZ$79 | ⃃ 175 | AU$85 | CA$68 | CN¥332 | €48 | £39 | ¥7,200 | S$64 | | Kapsule Care Pro | per month | - | On sale | US$109 | NZ$179 | ⃃ 399 | AU$195 | CA$153 | CN¥752 | €109 | £89 | ¥16,200 | S$144 | | WooCommerce Care | per month | - | On sale | US$90 | NZ$149 | ⃃ 328 | AU$161 | CA$127 | CN¥626 | €90 | £75 | ¥13,410 | S$120 | | Care Starter Hour | one time | - | On sale | US$59 | NZ$99 | ⃃ 220 | AU$105 | CA$84 | CN¥415 | €59 | £50 | ¥8,910 | S$79 | | Care Pro Hour | one time | - | On sale | US$47 | NZ$79 | ⃃ 175 | AU$85 | CA$67 | CN¥330 | €47 | £40 | ¥7,110 | S$63 | ## Managed hosting Product page: https://kapsulehost.com/en-us/hosting/managed (Markdown: https://kapsulehost.com/hosting/managed.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Concierge Start | per month | 3 sites | On sale | US$357 | NZ$595 | ⃃ 1,309 | AU$643 | CA$506 | CN¥2,499 | €357 | £298 | ¥53,550 | S$476 | | Concierge Pro | per month | 10 sites | On sale | US$897 | NZ$1,495 | ⃃ 3,290 | AU$1,615 | CA$1,271 | CN¥6,279 | €897 | £748 | ¥134,550 | S$1,196 | | Concierge Scale | per month | 25 sites | On sale | US$2,097 | NZ$3,495 | ⃃ 7,690 | AU$3,775 | CA$2,971 | CN¥14,679 | €2,097 | £1,748 | ¥314,550 | S$2,796 | | Engineering Hour | one time | - | On sale | US$132 | NZ$220 | ⃃ 485 | AU$238 | CA$187 | CN¥924 | €132 | £110 | ¥19,800 | S$176 | ## Professional services Product page: https://kapsulehost.com/en-us/protect/pro-services (Markdown: https://kapsulehost.com/protect/pro-services.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Website Migration | one time | - | On sale | US$150 | NZ$249 | ⃃ 548 | AU$269 | CA$212 | CN¥1,046 | €150 | £125 | ¥22,410 | S$200 | | Email Migration | one time | - | On sale | US$120 | NZ$199 | ⃃ 438 | AU$215 | CA$170 | CN¥836 | €120 | £100 | ¥17,910 | S$160 | | DNS Migration Assistance | one time | - | On sale | US$60 | NZ$99 | ⃃ 218 | AU$107 | CA$85 | CN¥416 | €60 | £50 | ¥8,910 | S$80 | | Custom DNS Configuration | one time | - | On sale | US$48 | NZ$79 | ⃃ 174 | AU$86 | CA$68 | CN¥332 | €48 | £40 | ¥7,110 | S$64 | | WordPress Speed Optimisation | one time | - | On sale | US$240 | NZ$399 | ⃃ 878 | AU$430 | CA$340 | CN¥1,676 | €240 | £200 | ¥35,910 | S$320 | | Site Security Audit | one time | - | On sale | US$240 | NZ$399 | ⃃ 878 | AU$430 | CA$340 | CN¥1,676 | €240 | £200 | ¥35,910 | S$320 | | SEO Audit | one time | - | On sale | US$180 | NZ$299 | ⃃ 658 | AU$323 | CA$255 | CN¥1,256 | €180 | £150 | ¥26,910 | S$240 | | Monthly SEO Retainer | per month | - | On sale | US$180 | NZ$299 | ⃃ 658 | AU$323 | CA$255 | CN¥1,256 | €180 | £150 | ¥26,910 | S$240 | | WooCommerce Setup | one time | - | On sale | US$300 | NZ$499 | ⃃ 1,098 | AU$540 | CA$425 | CN¥2,096 | €300 | £250 | ¥44,910 | S$400 | | WordPress Plugin Development | one time | - | On sale | US$480 | NZ$799 | ⃃ 1,758 | AU$863 | CA$680 | CN¥3,356 | €480 | £400 | ¥71,910 | S$642 | | Copywriting (per page) | one time | - | On sale | US$90 | NZ$149 | ⃃ 328 | AU$161 | CA$127 | CN¥626 | €90 | £75 | ¥13,410 | S$120 | | Custom Site Care | per month | - | On sale | US$120 | NZ$199 | ⃃ 438 | AU$215 | CA$170 | CN¥836 | €120 | £100 | ¥17,910 | S$160 | | WHOIS Lock & Transfer Lock Review | one time | - | On sale | US$18 | NZ$29 | ⃃ 64 | AU$32 | CA$25 | CN¥122 | €18 | £15 | ¥2,610 | S$24 | ## Reseller hosting Product page: https://kapsulehost.com/en-us/hosting/reseller (Markdown: https://kapsulehost.com/hosting/reseller.md) | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Starter | per month | - | By application | US$59 | NZ$99 | ⃃ 220 | AU$105 | CA$84 | CN¥415 | €59 | £50 | ¥8,910 | S$79 | | Professional | per month | - | By application | US$150 | NZ$249 | ⃃ 550 | AU$270 | CA$210 | CN¥1,045 | €150 | £125 | ¥22,410 | S$200 | | Agency | per month | - | By application | US$360 | NZ$599 | ⃃ 1,320 | AU$645 | CA$510 | CN¥2,515 | €360 | £300 | ¥53,910 | S$480 | Every price on this page is the price you pay, exactly as listed for your currency. If a tax applies to your account, it is shown on its own line at checkout. --- This is the Markdown rendition of https://kapsulehost.com/en-us/pricing, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Web Hosting with Email, Backups and SSL | KapsuleHost Web hosting with mailboxes on your own domain, nightly backups, SSL and a CDN on every Web Hosting plan, plus free tools to move in. See the plans. Canonical page: https://kapsulehost.com/en-us/hosting/web Every price below is read from the live KapsuleHost catalogue and may be up to a few minutes old, and is shown in every currency KapsuleHost sells in (10 currencies: USD, NZD, AED, AUD, CAD, CNY, EUR, GBP, JPY, SGD). ## Plans | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Start | per month | 10 GB storage, 1 site, 5 mailboxes | On sale | US$3 | NZ$5 | ⃃ 11 | AU$5 | CA$5 | CN¥21 | €3 | £2.50 | ¥450 | S$4 | | Pro | per month | 50 GB storage, 10 sites, 25 mailboxes | On sale | US$9 | NZ$15 | ⃃ 33 | AU$16 | CA$13 | CN¥63 | €9 | £7.50 | ¥1,350 | S$12 | | Scale | per month | 200 GB storage, 25 sites, 100 mailboxes | On sale | US$21 | NZ$35 | ⃃ 77 | AU$38 | CA$30 | CN¥147 | €21 | £18 | ¥3,150 | S$28 | | Cloud Power | per month | - | On sale | US$45 | NZ$75 | ⃃ 165 | AU$82 | CA$64 | CN¥315 | €45 | £36 | ¥6,750 | S$60 | Every price on this page is the price you pay, exactly as listed for your currency. If a tax applies to your account, it is shown on its own line at checkout. Pricing for every KapsuleHost product, in every currency we sell in: https://kapsulehost.com/pricing.md --- Summary of Web Hosting with Email, Backups and SSL | KapsuleHost (https://kapsulehost.com/en-us/hosting/web), published for AI readers and agents. It is built from the page's title, description and links (and any live prices), not its full text: for everything on the page, visit the canonical URL above. --- # WordPress Hosting with Staging and Backups | KapsuleHost WordPress hosting that installs in one click, with staging, nightly backups, SSL, mailboxes and a CDN on every WordPress plan. Compare the four plans. Canonical page: https://kapsulehost.com/en-us/hosting/wordpress Every price below is read from the live KapsuleHost catalogue and may be up to a few minutes old, and is shown in every currency KapsuleHost sells in (10 currencies: USD, NZD, AED, AUD, CAD, CNY, EUR, GBP, JPY, SGD). ## Plans | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | WordPress Start | per month | 20 GB storage, 1 site, 5 mailboxes | On sale | US$5 | NZ$8 | ⃃ 18 | AU$9 | CA$7 | CN¥34 | €5 | £4 | ¥720 | S$7 | | WordPress Pro | per month | 100 GB storage, 5 sites, 25 mailboxes | On sale | US$14 | NZ$25 | ⃃ 55 | AU$27 | CA$22 | CN¥105 | €14 | £12 | ¥2,250 | S$20 | | Managed WP Start | per month | 20 GB storage, 1 site, 5 mailboxes | On sale | US$12 | NZ$19 | ⃃ 42 | AU$21 | CA$17 | CN¥80 | €12 | £9.50 | ¥1,710 | S$16 | | Managed WP Pro | per month | 100 GB storage, 5 sites, 10 mailboxes | On sale | US$30 | NZ$49 | ⃃ 108 | AU$53 | CA$42 | CN¥206 | €30 | £25 | ¥4,410 | S$40 | Every price on this page is the price you pay, exactly as listed for your currency. If a tax applies to your account, it is shown on its own line at checkout. Pricing for every KapsuleHost product, in every currency we sell in: https://kapsulehost.com/pricing.md --- Summary of WordPress Hosting with Staging and Backups | KapsuleHost (https://kapsulehost.com/en-us/hosting/wordpress), published for AI readers and agents. It is built from the page's title, description and links (and any live prices), not its full text: for everything on the page, visit the canonical URL above. --- # Business Email Hosting with Your Own Domain | KapsuleHost Business email at your own domain, with a calendar, contacts and to-do lists in every mailbox. Works in Outlook, Apple Mail and on your phone. See the plans. Canonical page: https://kapsulehost.com/en-us/email Every price below is read from the live KapsuleHost catalogue and may be up to a few minutes old, and is shown in every currency KapsuleHost sells in (10 currencies: USD, NZD, AED, AUD, CAD, CNY, EUR, GBP, JPY, SGD). ## Plans | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Email Solo | per month | 10 GB quota, 1 mailboxes | On sale | US$2 | NZ$3 | ⃃ 7 | AU$4 | CA$3 | CN¥13 | €2 | £1.50 | ¥270 | S$3 | | Email Team | per month | 10 GB quota, 5 mailboxes | On sale | US$8 | NZ$12 | ⃃ 27 | AU$13 | CA$11 | CN¥51 | €8 | £6 | ¥1,080 | S$10 | | Email Business | per month | 10 GB quota, 25 mailboxes | On sale | US$18 | NZ$30 | ⃃ 66 | AU$33 | CA$26 | CN¥126 | €18 | £15 | ¥2,700 | S$24 | | Email Premium | per month | - | On sale | US$15 | NZ$25 | ⃃ 56 | AU$27 | CA$22 | CN¥105 | €15 | £13 | ¥2,250 | S$20 | Every price on this page is the price you pay, exactly as listed for your currency. If a tax applies to your account, it is shown on its own line at checkout. Pricing for every KapsuleHost product, in every currency we sell in: https://kapsulehost.com/pricing.md --- Summary of Business Email Hosting with Your Own Domain | KapsuleHost (https://kapsulehost.com/en-us/email), published for AI readers and agents. It is built from the page's title, description and links (and any live prices), not its full text: for everything on the page, visit the canonical URL above. --- # Domain Names: Search, Register and Transfer | KapsuleHost See the first-year and renewal price of every domain extension we carry side by side, with DNS and DNSSEC free where the extension allows. Search your name. Canonical page: https://kapsulehost.com/en-us/domains Pricing for every KapsuleHost product, in every currency we sell in: https://kapsulehost.com/pricing.md. An index of every page in Markdown: https://kapsulehost.com/llms.txt --- Summary of Domain Names: Search, Register and Transfer | KapsuleHost (https://kapsulehost.com/en-us/domains), published for AI readers and agents. It is built from the page's title, description and links (and any live prices), not its full text: for everything on the page, visit the canonical URL above. --- # Cloud Servers with Full Root Access, on NVMe | KapsuleHost Cloud servers on NVMe in the EU, the US and Asia-Pacific, with root access, your own SSH keys, nightly backups, a firewall and security patching. See sizes. Canonical page: https://kapsulehost.com/en-us/servers/cloud Every price below is read from the live KapsuleHost catalogue and may be up to a few minutes old, and is shown in every currency KapsuleHost sells in (10 currencies: USD, NZD, AED, AUD, CAD, CNY, EUR, GBP, JPY, SGD). ## Cloud VPS | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Photon | per month | 2 vCPU, 4 GB RAM, 40 GB disk | On sale | US$16 | NZ$29 | ⃃ 59 | AU$23 | CA$23 | CN¥110 | €14 | £12 | ¥2,590 | S$21 | | Quark | per month | 4 vCPU, 8 GB RAM, 80 GB disk | On sale | US$28 | NZ$49 | ⃃ 105 | AU$41 | CA$40 | CN¥190 | €25 | £21 | ¥4,530 | S$36 | | Lepton | per month | 8 vCPU, 16 GB RAM, 160 GB disk | On sale | US$55 | NZ$98 | ⃃ 200 | AU$80 | CA$78 | CN¥375 | €48 | £42 | ¥8,900 | S$71 | | Muon | per month | 16 vCPU, 32 GB RAM, 320 GB disk | On sale | US$107 | NZ$189 | ⃃ 395 | AU$155 | CA$150 | CN¥730 | €94 | £81 | ¥17,320 | S$140 | | Meteor | per month | 1 vCPU, 2 GB RAM, 40 GB disk | On sale | US$20 | NZ$35 | ⃃ 73 | AU$29 | CA$28 | CN¥135 | €18 | £15 | ¥3,240 | S$26 | | Comet | per month | 2 vCPU, 4 GB RAM, 80 GB disk | On sale | US$35 | NZ$62 | ⃃ 130 | AU$51 | CA$50 | CN¥240 | €31 | £26 | ¥5,670 | S$45 | | Atlas | per month | 4 vCPU, 8 GB RAM, 160 GB disk | On sale | US$65 | NZ$115 | ⃃ 240 | AU$94 | CA$92 | CN¥440 | €57 | £49 | ¥10,520 | S$84 | | Apollo | per month | 8 vCPU, 16 GB RAM, 320 GB disk | On sale | US$120 | NZ$213 | ⃃ 440 | AU$175 | CA$170 | CN¥815 | €105 | £91 | ¥19,430 | S$155 | | Vega | per month | 12 vCPU, 24 GB RAM, 480 GB disk | On sale | US$174 | NZ$308 | ⃃ 640 | AU$255 | CA$245 | CN¥1,185 | €150 | £130 | ¥28,170 | S$225 | | Pulsar | per month | 16 vCPU, 32 GB RAM, 640 GB disk | On sale | US$220 | NZ$389 | ⃃ 810 | AU$320 | CA$310 | CN¥1,495 | €195 | £165 | ¥35,620 | S$285 | | Quasar | per month | 2 vCPU, 8 GB RAM, 80 GB disk | On sale | US$70 | NZ$124 | ⃃ 255 | AU$100 | CA$99 | CN¥475 | €61 | £53 | ¥11,330 | S$91 | | Orion | per month | 4 vCPU, 16 GB RAM, 160 GB disk | On sale | US$140 | NZ$248 | ⃃ 515 | AU$205 | CA$200 | CN¥955 | €125 | £105 | ¥22,660 | S$180 | | Nebula | per month | 8 vCPU, 32 GB RAM, 240 GB disk | On sale | US$230 | NZ$407 | ⃃ 845 | AU$335 | CA$325 | CN¥1,565 | €200 | £175 | ¥37,230 | S$295 | | Nova | per month | 16 vCPU, 64 GB RAM, 360 GB disk | On sale | US$440 | NZ$779 | ⃃ 1,615 | AU$640 | CA$625 | CN¥2,995 | €385 | £330 | ¥71,230 | S$570 | | Sirius | per month | 32 vCPU, 128 GB RAM, 600 GB disk | On sale | US$839 | NZ$1,485 | ⃃ 3,080 | AU$1,220 | CA$1,190 | CN¥5,710 | €735 | £635 | ¥135,830 | S$1,085 | | Andromeda | per month | 48 vCPU, 192 GB RAM, 960 GB disk | On sale | US$1,339 | NZ$2,370 | ⃃ 4,915 | AU$1,945 | CA$1,900 | CN¥9,110 | €1,175 | £1,010 | ¥216,770 | S$1,730 | ## Managed cloud servers | Plan | Billing | Specs | Availability | USD | NZD | AED | AUD | CAD | CNY | EUR | GBP | JPY | SGD | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Photon Managed | per month | 2 vCPU, 4 GB RAM, 40 GB disk | On sale | US$20 | NZ$36 | ⃃ 73 | AU$29 | CA$28 | CN¥135 | €18 | £15 | ¥3,240 | S$26 | | Quark Managed | per month | 4 vCPU, 8 GB RAM, 80 GB disk | On sale | US$35 | NZ$62 | ⃃ 130 | AU$51 | CA$50 | CN¥240 | €31 | £26 | ¥5,670 | S$45 | | Lepton Managed | per month | 8 vCPU, 16 GB RAM, 160 GB disk | On sale | US$69 | NZ$122 | ⃃ 255 | AU$100 | CA$98 | CN¥470 | €60 | £52 | ¥11,170 | S$89 | | Muon Managed | per month | 16 vCPU, 32 GB RAM, 320 GB disk | On sale | US$134 | NZ$237 | ⃃ 490 | AU$195 | CA$190 | CN¥910 | €115 | £100 | ¥21,690 | S$175 | | Meteor Managed | per month | 1 vCPU, 2 GB RAM, 40 GB disk | On sale | US$36 | NZ$63 | ⃃ 130 | AU$52 | CA$51 | CN¥245 | €32 | £27 | ¥5,830 | S$47 | | Comet Managed | per month | 2 vCPU, 4 GB RAM, 80 GB disk | On sale | US$63 | NZ$112 | ⃃ 230 | AU$91 | CA$89 | CN¥430 | €55 | £48 | ¥10,200 | S$81 | | Atlas Managed | per month | 4 vCPU, 8 GB RAM, 160 GB disk | On sale | US$115 | NZ$204 | ⃃ 420 | AU$165 | CA$165 | CN¥785 | €100 | £87 | ¥18,620 | S$150 | | Apollo Managed | per month | 8 vCPU, 16 GB RAM, 320 GB disk | On sale | US$225 | NZ$398 | ⃃ 825 | AU$325 | CA$320 | CN¥1,530 | €195 | £170 | ¥36,430 | S$290 | | Vega Managed | per month | 12 vCPU, 24 GB RAM, 480 GB disk | On sale | US$327 | NZ$579 | ⃃ 1,200 | AU$475 | CA$465 | CN¥2,225 | €285 | £245 | ¥52,940 | S$425 | | Pulsar Managed | per month | 16 vCPU, 32 GB RAM, 640 GB disk | On sale | US$420 | NZ$743 | ⃃ 1,540 | AU$610 | CA$595 | CN¥2,860 | €370 | £315 | ¥67,990 | S$545 | | Quasar Managed | per month | 2 vCPU, 8 GB RAM, 80 GB disk | On sale | US$139 | NZ$246 | ⃃ 510 | AU$200 | CA$195 | CN¥945 | €120 | £105 | ¥22,500 | S$180 | | Orion Managed | per month | 4 vCPU, 16 GB RAM, 160 GB disk | On sale | US$279 | NZ$494 | ⃃ 1,025 | AU$405 | CA$395 | CN¥1,900 | €245 | £210 | ¥45,170 | S$360 | | Nebula Managed | per month | 8 vCPU, 32 GB RAM, 240 GB disk | On sale | US$449 | NZ$795 | ⃃ 1,650 | AU$650 | CA$640 | CN¥3,055 | €395 | £340 | ¥72,690 | S$580 | | Nova Managed | per month | 16 vCPU, 64 GB RAM, 360 GB disk | On sale | US$895 | NZ$1,584 | ⃃ 3,285 | AU$1,300 | CA$1,270 | CN¥6,090 | €785 | £675 | ¥144,890 | S$1,155 | | Sirius Managed | per month | 32 vCPU, 128 GB RAM, 600 GB disk | On sale | US$1,730 | NZ$3,062 | ⃃ 6,355 | AU$2,510 | CA$2,455 | CN¥11,770 | €1,515 | £1,305 | ¥280,070 | S$2,235 | | Andromeda Managed | per month | 48 vCPU, 192 GB RAM, 960 GB disk | On sale | US$2,769 | NZ$4,901 | ⃃ 10,170 | AU$4,020 | CA$3,935 | CN¥18,840 | €2,425 | £2,090 | ¥448,270 | S$3,580 | Every price on this page is the price you pay, exactly as listed for your currency. If a tax applies to your account, it is shown on its own line at checkout. Pricing for every KapsuleHost product, in every currency we sell in: https://kapsulehost.com/pricing.md --- Summary of Cloud Servers with Full Root Access, on NVMe | KapsuleHost (https://kapsulehost.com/en-us/servers/cloud), published for AI readers and agents. It is built from the page's title, description and links (and any live prices), not its full text: for everything on the page, visit the canonical URL above. --- # Terms of Service KapsuleHost Terms of Service, the agreement governing your use of KapsuleHost hosting, domain registration, email, KPanel, and related services. Canonical page: https://kapsulehost.com/en-us/legal/terms Last updated: 9 October 2026 Version 19, effective October 9, 2026 ## About this Agreement These Terms of Service (the "Agreement") set out the terms on which Kapsule Group Limited, a New Zealand company ("KapsuleHost", "we", "us", "our"), provides cloud hosting, domain registration, email hosting, and related products and services (the "Services") to you ("you", "Customer", "your"). The Agreement incorporates by reference: the Acceptable Use Policy ("AUP"), Privacy Policy, Cookie Policy, Refund Policy, Service Level Agreement ("SLA"), Data Processing Agreement ("DPA"), the Sub-processors List, the Security Statement, and any product-specific or promotional terms presented to you at the point of purchase or in your customer panel at kpanel.kapsulehost.com ("KPanel"). Each of these forms part of this Agreement. Your electronic acceptance of this Agreement, your creation of an Account, or your use of any Service, whichever occurs first, signifies that you have read, understood, and agree to be bound by this Agreement. If you do not agree, do not access or use the Services. The English language version of this Agreement is the only legally binding version. Any translation is provided for convenience only. ## 1. Definitions "Account" means your registered KapsuleHost account. "Affiliate" means, in relation to a party, any entity that controls, is controlled by, or is under common control with that party. "Kora" means our artificial intelligence customer support and platform assistant, built on third-party large language models. "Customer Content" means any data, code, files, websites, databases, emails, images, audio, video, configuration, or other material that you (or any person using the Account) upload to, store on, transmit through, or process using the Services. "Fees" means the amounts payable for the Services, as set out on your order, in KPanel, or in any promotional terms accepted by you. "Force Majeure Event" has the meaning given in clause 18.1. "KPanel" means the customer control panel at kpanel.kapsulehost.com. "Personal Information" has the meaning given in the Privacy Act 2020. "Plan" means the subscription tier or product you select, including Start, Pro, Scale, Cloud Power, domain registration, email hosting, and any future Plan or add-on. "Registry" means the operator of a top-level domain ("TLD") for which you register a domain name through us. "Sub-processor" means a third party we engage to process Personal Information on your behalf, as listed at kapsulehost.com/legal/sub-processors. "Switching Credit" has the meaning given in clause 7.13. "Trial" means any free, discounted, or promotional offer of the Services granted by us, including the 30-day free trial on the Start Plan. Words importing the singular include the plural and vice versa. Headings are for convenience only and do not affect interpretation. References to a statute include any amendment to or replacement of it. ## 2. Eligibility 2.1 You may only use the Services if you are at least 18 years old and have full legal capacity to enter a binding contract under the laws of New Zealand. 2.2 If you are accepting this Agreement on behalf of an entity, you represent and warrant that you have the authority to bind that entity. References to "you" include both you personally and the entity, jointly and severally. 2.3 You must not use the Services if you are prohibited from doing so by any applicable law or sanctions regime, or if you are located in, organised under the laws of, or ordinarily resident in any jurisdiction subject to comprehensive trade sanctions imposed by New Zealand, the United Nations, the United States, the United Kingdom, the European Union, or Australia. 2.4 We reserve the right, in our sole discretion, to refuse, limit, suspend, or terminate the Services to any person at any time, including where we have a reasonable suspicion of fraud, abuse, money laundering, sanctions breach, or breach of this Agreement. ## 3. The Account 3.1 You must provide accurate, current, and complete information when creating the Account and must keep that information up to date at all times. We may suspend or terminate the Account if we discover that information you have provided is materially false, misleading, or out of date. 3.2 You are responsible for all activity that occurs under the Account, whether or not authorised by you, except to the extent caused by our breach of this Agreement. 3.3 You must keep your credentials secure and confidential. KPanel supports password-based sign-in, third-party OAuth (Google, GitHub, Apple, Discord), passkeys, and TOTP or SMS two-factor authentication ("2FA"). We may require 2FA for higher-risk actions (for example, billing changes, mass deletions, account transfers, domain transfers, email address changes, and account deletion). You are responsible for maintaining access to your enrolled authentication methods; if you lose access to all of them, contact support@kapsulehost.com to initiate a manual identity verification process. 3.4 You must notify us immediately at security@kapsulehost.com if you suspect or become aware of any unauthorised access to the Account or any compromise of your credentials. You remain liable for activity occurring under the Account prior to such notification. 3.5 You may not transfer the Account to any other person without our prior written consent. We may permit account transfers subject to verification of identity, settlement of outstanding Fees, and acceptance of this Agreement by the new account holder. 3.6 Where you grant access to the Account to any other person (such as a contractor, employee, or co-administrator), you remain fully responsible for that person's acts and omissions as if they were your own. ## 4. The Services and resource allocation 4.1 We will use commercially reasonable efforts to provide the Services in accordance with this Agreement, the SLA, and the Plan-specific limits set out at kapsulehost.com/pricing or in your KPanel. 4.2 Resource categories. Each Plan includes the following non-exhaustive resource categories, each subject to fair use and the AUP: Storage (solid-state disk storage per Plan, measured by total bytes stored including databases, mailboxes, files, and configuration; does not include our off-site disaster-recovery backups); Bandwidth (outbound and inbound network transfer per calendar month; "unmetered" means no hard byte cap but subject to fair use and AUP); CPU and memory (shared compute resources; we may throttle processes exceeding per-Plan limits to preserve quality of service); Inodes and file count (files and directories per Plan; excessive inode usage may be limited even where total storage is within allowance); Email sending (outbound mail volume, mailboxes, message size, and recipients per Plan); Databases (number of databases, size, query rate, and concurrent connections per Plan); Sites and domains (number of distinct websites, applications, and domains per Plan). 4.3 If your usage materially exceeds your Plan limits, we may: (a) contact you to discuss upgrading; (b) automatically scale you to a higher Plan on reasonable notice where necessary to preserve service quality; (c) apply temporary technical limits, throttling, or queuing; (d) charge usage-based overage Fees if stated in your order or KPanel; or (e) where the excess is sustained, severe, or in breach of the AUP, suspend or terminate the Services under clause 13. 4.4 Service modifications. We may add, change, deprecate, or remove features of the Services. Material adverse changes will be notified to you at least 30 days before they take effect, except where shorter notice is required by law, an upstream provider, or to address a security, legal, or operational risk. 4.5 GPU, dedicated, and storage servers. GPU servers, dedicated servers, and storage servers are provided "AS IS". We do not guarantee uninterrupted or continuous availability of a GPU server, dedicated server, or storage server, or the continued availability of any particular GPU, compute, or storage resource. We do not guarantee any particular level of performance, throughput, latency, or workload completion time. GPU servers, dedicated servers, and storage servers are not subject to the SLA. 4.6 Third party software. Where the Services rely on third-party software or services (for example, the third-party control panel software underlying our hosting platform, WordPress, our email platform, or open-source applications you install), your use of that software is subject to the relevant provider's licence terms, and we are not responsible for any limitations, defects, or vulnerabilities introduced by that software. 4.7 Fair Use Policy. Plans marketed as offering "unlimited" resources (such as Cloud Power) are subject to the Fair Use Policy at https://kapsulehost.com/legal/fair-use, which sets out explicit thresholds (currently: 20 TB bandwidth, 500 GB storage, 500 active mailboxes per account) and a notification-first enforcement process. We will email you the day you cross a threshold; we do not throttle silently, bill retroactively, or suspend without notice. The Fair Use Policy is incorporated into this Agreement by reference. 4.8 KapsuleHost keeps a management key (named kapsulehost-management) on every server we build, for backups, monitoring and security updates. Removing it stops those features. ## 5. Domain name registration services 5.1 Reseller role. We provide domain name registration as reseller of a third-party domain registrar (the "Registrar"), whose identity is disclosed in the Sub-processors List at kapsulehost.com/legal/sub-processors. Your registration is also subject to the Registrar's customer terms, ICANN policies where applicable, and the policies of the Registry for the relevant TLD ("Registry Policies"). Where there is a conflict between this Agreement and ICANN policy or a Registry Policy, the ICANN policy or Registry Policy prevails to the extent of the conflict. 5.2 WHOIS accuracy. You must provide and maintain true, accurate, complete, and current contact information for each domain ("WHOIS Data"). It is a material breach of this Agreement to: (a) provide inaccurate or unreliable WHOIS Data; (b) fail to update WHOIS Data within seven days of any change; or (c) fail to respond within fifteen days to any inquiry from us, the Registrar, or the Registry regarding the accuracy of WHOIS Data. 5.3 WHOIS privacy. Where you enable WHOIS privacy (free with all Plans), public WHOIS displays a privacy proxy contact instead of your personal contact information. Privacy services do not absolve you of the obligation to maintain accurate underlying WHOIS Data. We may disclose underlying WHOIS Data to law enforcement, courts, registries, or other parties with a legitimate legal interest. 5.4 Registrant agreement and UDRP. By registering a domain you agree to be bound by: (a) the UDRP for generic TLDs; (b) any country-code dispute resolution policy applicable to the relevant ccTLD (for example, the Domain Name Commission's Dispute Resolution Service Policy for .nz domains); and (c) all Registry Policies for the relevant TLD. 5.5 Domain lifecycle. Domain names have specific lifecycle stages including registration period, expiry, auto-renew grace period, redemption grace period (typically 30 days, with restoration fees), and pending delete. You are solely responsible for renewing the domain in time and for managing auto-renew settings in KPanel. We are not liable for any loss of a domain due to non-renewal, failed payment, expired payment method, or your failure to act within Registry-mandated periods. 5.6 Automatic renewal. Domain names registered through us are set to automatic renewal by default. You may disable automatic renewal in KPanel. If renewal fails, we will email you and attempt to retry as set out in clause 7. 5.7 Domain transfers. Transfer out: you may request a transfer to another registrar at any time, subject to ICANN and Registry rules; we will provide an authorisation code through KPanel. Transfer lock: we apply registrar transfer-lock by default on new registrations; you may unlock the domain in KPanel. Transfer in: you may transfer a domain into our service subject to the relevant Registry's transfer-in policies, an authorisation code from the losing registrar, and payment of the applicable transfer Fee. 5.8 Refusal, cancellation, or lock by us. We, the Registrar, or the Registry may deny, cancel, transfer, modify, or place on registry-lock any domain name to comply with industry specifications, correct mistakes, recover non-payment, protect Registry integrity, comply with a court order or government request, comply with ICANN rules or Registry Policies, or where we have a reasonable suspicion of breach of this Agreement. 5.9 Domain Fees non-refundable. Domain registration, renewal, transfer, and restoration Fees are non-refundable once the registration or other action has been submitted to the Registry, except where the action fails through no fault of yours. 5.10 .nz domains. .nz domains are administered by the Domain Name Commission Limited. By registering a .nz domain you agree to the Domain Name Commission's policies, including the Dispute Resolution Service Policy and the New Zealand Open Source .nz Policies. ## 6. Email hosting 6.1 Service description. We offer email hosting on platforms operated by us and through third-party sub-processors. Mailbox quotas, mail send quotas, and message size limits are set per Plan and shown in KPanel. 6.2 Sender reputation. You must: (a) configure SPF, DKIM, and DMARC records for any sending domain; (b) only send mail to recipients who have consented under the Unsolicited Electronic Messages Act 2007 or any other applicable law; (c) maintain a hard-bounce rate below 5% and a spam-complaint rate below 0.1% across any rolling seven-day period; (d) include a clear and functional unsubscribe mechanism in marketing email; and (e) not engage in any practice prohibited by the AUP. 6.3 Suspension of email service. We may rate-limit, quarantine, suspend, or terminate email Services where we reasonably believe you have breached this clause or where your activity is harming the reputation of our shared IP space, with or without prior notice depending on severity. 6.4 No archival guarantee. Unless your Plan explicitly includes mail archival, you are responsible for retaining and archiving your own email. Our retention of mail data is governed by the Privacy Policy and the SLA. ## 7. Fees, billing, taxes, and renewal 7.1 Currency and taxes. Fees are stated and payable in New Zealand dollars (NZD) unless otherwise shown. Fees are exclusive of GST unless stated; GST will be added at the prevailing rate (currently 15%) where applicable. You are responsible for any other taxes, duties, or levies imposed in your jurisdiction. 7.2 Payment method. You authorise us, and our payment processor, to charge your nominated payment method for all Fees that are charged automatically, including renewals of Plans that renew automatically, overages, taxes, and any other amounts due under this Agreement. A valid card is required, and must be kept on file, only while you hold a Plan that renews automatically (for example, a monthly Plan). A Plan that renews by invoice (clause 7.12, for example a yearly Plan) does not require a card on file: you may pay its invoice by card or, where the invoice offers it, by bank transfer to the account shown on the invoice, in the invoice currency, quoting the payment reference shown on it. An invoice is paid when we receive the full amount in that currency with that reference; a payment in another amount, currency or reference is applied by us once we have matched it, which may take longer. You bear any fees your bank charges to send the transfer. 7.3 Automatic renewal. Subject to clause 7.5, Plans automatically renew at the end of each billing cycle at the then-current Plan price, unless cancelled in KPanel before the renewal date. We will email you a renewal reminder at least seven days before an annual renewal. 7.4 Price changes. Subject to clause 7.5, we may change Fees on at least thirty days' notice. New Fees apply from your next renewal. Where you have prepaid annually, the existing Fee applies for the remainder of the prepaid term. 7.5 Price lock. The Fee applicable to your Plan at the time you subscribe is locked for the lifetime of your continuous subscription. Provided your subscription remains active and you do not change to a different Plan, we will not increase the Fee you pay, even if we increase Fees for new subscribers. The price lock is personal to your Account and does not transfer. 7.6 Failed payment. If a charge fails, we will retry for up to fourteen days. After fourteen days of non-payment, we may suspend the Services. After thirty days of non-payment, we may terminate the Services and delete Customer Content as set out in clause 13.5. 7.7 Disputes about charges. You must notify us of any disputed charge within sixty days of the invoice date. Charges not disputed within that period are deemed accepted. 7.8 Chargebacks. If you have a billing concern, contact billing@kapsulehost.com before initiating a chargeback. Chargebacks for amounts properly owed, where there is no underlying billing error, may be treated as a material breach of this Agreement. 7.9 Set-off. We may set off any amount you owe us against any credit or refund payable to you. 7.10 Promotional pricing and free trials. Promotional or trial pricing is offered subject to the terms displayed at the point of purchase and may be limited to first-time customers, one per household or business, and subject to verification. We may refuse, withdraw, or claw back any promotional benefit obtained by fraud, multiple-account abuse, or breach of the promotion's terms. 7.11 Reserved servers. A reserved cloud, GPU, or dedicated server is charged automatically when stock becomes available, which may be days or weeks after you reserved it, on the payment method on file. You may cancel it for a full refund and removal within forty-eight (48) hours of the fulfilment email, once per Customer, as set out in the Refund Policy. After that window it is billed monthly and may be cancelled at the end of the current billing cycle. A server that is switched off is still charged at its full price until you delete it. We do not stop charging or delete a switched-off server automatically. 7.12 Manual annual renewal. Some annual Plans are renewed by invoice rather than by automatic charge. Where your Plan renews this way, we will email you an invoice at least thirty days before the end of your current term, and no payment method on file will be charged automatically. If the invoice is unpaid at the end of your term, your Services enter a grace period. We may suspend the Services seven days after the term ends, and we may terminate them twenty-one days after the term ends. On termination, clause 13.5 applies to your Customer Content, including the thirty-day Grace Period during which you may reinstate the Service by purchasing it again and paying any outstanding Fees. Clause 7.6 does not apply to a Plan renewed under this clause, because no charge is attempted. 7.13 Switching credit. 7.13(a) The offer. If you move a website to us from another hosting provider while you still have paid time left on your hosting plan with that provider, you can claim account credit for the paid time you will no longer use ("Switching Credit"). You can claim only while we show this offer as open on our website or in KPanel. This clause sets out the whole offer. 7.13(b) Who can claim. You can claim if all of these are true: (i) you are a new customer, meaning neither you nor any business you act for has held a paid Plan with us in the 12 months before your order; (ii) you have ordered, and paid the first year of, one of these Plans billed yearly: Start, Pro, Scale, Cloud Power, WordPress Start, WordPress Pro, Managed WordPress Start, Managed WordPress Pro, Managed WooCommerce Start or Managed WooCommerce Pro (an "Eligible Plan"). Monthly billing, email plans, domain names, servers, add-ons, one-off services and accounts managed by a reseller are not included; (iii) the website for the domain you claim for was hosted with the other provider on a paid hosting plan, not a free plan, a free tier or a trial; (iv) that website now serves from your Eligible Plan with us. The day it first does is your "Go-Live Date"; (v) at least 30 days of paid time are left on the other provider's plan after your Go-Live Date; and (vi) you paid the other provider for that paid time more than 90 days before you claim. 7.13(c) One claim. Each domain can be claimed once, ever. Each customer can make one claim, counting every Account held by the same person or business or paid for with the same payment method. If you move several websites, you choose which one to claim for. 7.13(d) How to claim. Claim in KPanel within 60 days after your Go-Live Date, using the claim form on your migration or billing page. Upload the other provider's invoice, statement or renewal notice. It must show: (i) the provider's name; (ii) the name of the person or business it was billed to; (iii) the hosting plan; (iv) the domain; (v) the amount paid for the hosting plan, and its currency; (vi) the period paid for, with its start date and the date it is paid up to; and (vii) that it was paid. If the document does not show the domain, also upload a screenshot of the provider's control panel showing that plan with the domain on it. You may hide card numbers and items that have nothing to do with the hosting plan, but not the details listed above. The name billed must match the Account holder or the business named on your Account. If it does not, tell us why on the form (for example, your web designer paid for it), and we may ask for evidence that you are entitled to claim. When you claim, you confirm that you have not received, and will not ask for, a refund from the other provider for the paid time you claim. 7.13(e) How we work out the credit. (i) "Unused days" means the days from your Go-Live Date up to the date the other provider's plan is paid up to. (ii) The value at the other provider's price is the amount you paid for the hosting plan, leaving out tax, domain names, add-ons and setup fees, divided by the number of days in the period it paid for, multiplied by your unused days. (iii) The value at our price is the first-year Fee you paid us for your Eligible Plan, leaving out tax and after any discount, divided by 365, multiplied by your unused days. (iv) Your Switching Credit is the lower of (ii) and (iii), and never more than half of the first-year Fee you paid us for your Eligible Plan. (v) If the other provider billed you in a different currency from your Account, we convert (ii) into your Account's currency at the exchange rate we record for the day we approve your claim. If we hold no rate for that currency on that day, we use a published central bank reference rate for that day. (vi) We round the result down to the smallest unit of your Account's currency. We show you each of these figures when we decide your claim. 7.13(f) Monthly limit. Each calendar month we approve Switching Credit for up to 50 claims and up to a total of US$6,000, or the same value in other currencies at the rate in (e)(v). When either limit is reached, we say so where the offer is shown, and valid claims already received are approved the next month in the order we received them. A claim received after we say the month is full can still be made, and waits in the same order. 7.13(g) Checking your claim. We check every claim and aim to decide within 5 business days of receiving everything we need. We may ask you for more evidence, and the 60-day claim period in (d) is paused while we wait for it. We will approve your claim, approve it at a lower amount with the working shown, or decline it with the reason. We tell you our decision in KPanel and by email. 7.13(h) What Switching Credit is. Switching Credit is account credit in your Account's currency. It is not cash and has no cash value. It cannot be withdrawn, refunded, transferred to another person or Account, exchanged or converted to another currency, and it earns no interest. It is applied automatically to the next invoices for our Services on your Account, including your renewal, until it is used up. Clause 7.9 (set-off) applies to it. 7.13(i) When you can use it. If we approve your claim before the 30-day money-back Guarantee Period for your Eligible Plan (Refund Policy clause 1) ends, we add the credit to your Account the day after that period ends. Otherwise we add it the day we approve your claim. 7.13(j) Expiry. Switching Credit you have not used expires 24 months after we add it. We email you at least 30 days before any of it expires. 7.13(k) When unused credit is removed. We remove Switching Credit you have not yet used if: (i) you receive a refund of any payment for your Eligible Plan, including under the money-back guarantee; (ii) any payment for your Eligible Plan is charged back or reversed; (iii) your Eligible Plan or your Account ends for any reason, unless you move to another Eligible Plan on the same Account; or (iv) you receive a refund from the other provider for any of the paid time you claimed. Credit already applied to an invoice stays applied. Removing unused credit never creates a charge, except under (l). 7.13(l) False claims. If a claim relied on a document that was false, altered or misleading, repeats a claim already made, or otherwise breaks this clause, we may decline it, remove any unused Switching Credit, and reverse Switching Credit already applied, so that the part of any invoice it paid becomes payable again. Clause 7.10 also applies, and a deliberately false claim may be treated as a material breach of this Agreement. 7.13(m) Other offers. Switching Credit replaces the earlier switching offer that added months to the end of your first year; you cannot have both. You can combine Switching Credit with the Start Plan free trial (you claim once your first yearly payment is taken), with a promotional price (clause (e)(iii) uses the price you actually paid), and with extra free days you receive as a referred customer under the Affiliate Programme Agreement (those days do not change your credit). It is separate from, and does not reduce, any service credit under the SLA. You cannot combine it with any other credit or discount given for moving from another provider. 7.13(n) Changes to the offer. We may change or end this offer at any time by updating what we show on our website and in KPanel. A change or ending does not affect a claim for an order you placed while the offer was shown as open, provided you claim within the period in (d), or Switching Credit already added to your Account. ## 8. Trials 8.1 Start Plan free trial. We offer a thirty-day free trial on the Start Plan to new eligible customers. 8.2 Eligibility. The trial is limited to one per person, one per household, and one per business entity. We may refuse the trial to anyone we reasonably believe has previously held an Account, has created multiple Accounts, or is otherwise abusing the trial offer. 8.3 Trial conversion. At the end of the trial period, the Services will continue at the then-current Start price unless you cancel or upgrade. We will email you a reminder at least seven days before the trial ends. 8.4 Trial limitations. Trials are subject to the same fair use limits, AUP, and other terms as paid Plans, except that Plan-specific premium features may not be available during the trial. 8.5 Modification or withdrawal. We may modify or withdraw any trial offer at any time. Modifications do not affect trials already in progress. ## 9. Acceptable use 9.1 Your use of the Services is governed by the AUP. The AUP forms part of this Agreement. 9.2 We may suspend, limit, or terminate the Services without notice if we reasonably believe you have breached the AUP, particularly where there is a risk to the platform, other customers, third parties, our reputation, or our ability to provide the Services. 9.3 You acknowledge that we operate automated systems that monitor for behaviour consistent with abuse, fraud, or breach of the AUP, and that we may take automated proportionate action (including throttling, captcha challenges, mailbox holds, and account holds) on the basis of those systems' outputs, subject to human review on request. ## 10. Customer Content and intellectual property 10.1 Ownership of Customer Content. As between you and us, you retain all ownership and intellectual property rights in your Customer Content. We claim no ownership of it. 10.2 Licence to us. You grant us a worldwide, non-exclusive, royalty-free, sub-licensable licence to host, store, copy, transmit, cache, display, perform, modify (only as necessary for format conversion or technical compatibility), and process Customer Content solely to provide and improve the Services for you, to back up Customer Content, to comply with law, and to enforce this Agreement. 10.3 Customer warranties. You represent, warrant, and undertake that: (a) you own or have sufficient rights to all Customer Content; (b) the Customer Content does not and will not infringe any intellectual property, privacy, publicity, or other rights of any third party; (c) the Customer Content and your use of the Services comply with the AUP and all applicable laws; and (d) you have all consents required to allow us to process Personal Information you upload, in accordance with the Privacy Act 2020 and any other applicable privacy law. 10.4 Our intellectual property. We and our licensors own all rights, title, and interest in the KapsuleHost platform, KPanel, our software, APIs, trademarks (including "KapsuleHost", "Kapsule Group", "KPanel", and our logos), documentation, and any modifications or derivative works of any of these. Nothing in this Agreement grants you any rights in our intellectual property except the limited right to use the Services. 10.5 Feedback. If you provide us with suggestions, ideas, feedback, or recommendations about the Services, you grant us a perpetual, irrevocable, worldwide, royalty-free licence to use, modify, and incorporate the Feedback into the Services or other products without obligation to you. 10.6 Use of aggregated data. We may collect, use, and disclose anonymised and aggregated data derived from your use of the Services for any lawful purpose, including capacity planning, security, abuse prevention, marketing, benchmarking, and product development, provided that we do not identify you or your customers in any such use. ## 11. Backups and data preservation 11.1 Our backups. We perform daily encrypted backups of customer site data and email data to off-site locations (currently a third-party object storage provider in Finland; site backups are also kept on the hosting server in Germany, so every site backup is stored in Europe). Online shops are not site data for this clause: their data runs with our control panel in the Asia-Pacific region, and their off-site backups are stored in Finland. Retention is thirty days minimum for all paid Plans, with extended retention for higher-tier Plans as set out at kapsulehost.com/pricing. Backups are intended for disaster-recovery and continuity-of-service purposes. 11.2 Your responsibility. Notwithstanding clause 11.1, you remain solely responsible for maintaining your own independent backups of any Customer Content that is important to you. You must not rely on our backups as your sole or primary backup. We are not liable for any loss, corruption, or inaccessibility of Customer Content, except to the limited extent set out in the SLA. 11.3 Backup access. Restore requests are processed in accordance with the support response times stated in the SLA. We may charge a reasonable fee for restore requests caused by your error (for example, accidental deletion), as set out in KPanel. 11.4 Termination and deletion. On termination, Customer Content is retained for thirty days after the Services stop, as set out in clause 13.5, after which it is permanently deleted from live systems. Backup copies become unrecoverable within thirty-one days after that, except where retention is required by law or to defend a legal claim. ## 12. Kora and AI-powered features 12.1 What Kora is. Kora is our AI assistant, built on third-party large language models. Kora may read your support messages, ticket history, Account metadata, and information you specifically provide to it in order to respond to your enquiries. Kora is offered as a customer-support tool and as a feature within KPanel. 12.2 AI outputs are advisory. Kora outputs are generated by a probabilistic model and may be incorrect, incomplete, out of date, biased, or inappropriate to your circumstances. Kora outputs are advisory only and are not professional advice (legal, financial, medical, security, or otherwise). You must independently verify any Kora output before relying on it. 12.3 No training on Customer Content. We do not authorise our AI sub-processors to use Customer Content to train their general models. Kora interactions are processed for the purpose of providing the Service only and are retained for the periods stated in the Privacy Policy. 12.4 Inputs. You must not submit to Kora any Customer Content or other information you are not authorised to disclose to us, or that is subject to enhanced confidentiality or regulatory protections (for example, payment card numbers, full credit card data, government identification, or sensitive health information). 12.5 Ownership. As between you and us, you own the inputs you submit to Kora and the outputs Kora generates for you. We make no warranty that Kora outputs are unique to you; identical or similar outputs may be generated for other customers. 12.6 Human review. You may request a human-only support interaction at any time by emailing support@kapsulehost.com. 12.7 AI changes. We may change the underlying AI model, model provider, model capabilities, or the features Kora can access at any time without notice. ## 13. Suspension and termination 13.1 Termination by you. You may cancel any Service at any time via KPanel. Termination takes effect at the end of the current billing cycle (for monthly Plans) or as set out in the Refund Policy (for annual Plans). Domain registrations and one-off services that have already been delivered are not refundable. 13.2 Termination by us for convenience. We may terminate this Agreement, or any Service, on thirty days' written notice to you, for any reason. If we terminate for convenience, we will refund any prepaid Fees for the unused portion of the relevant billing cycle on a pro rata basis. 13.3 Suspension or termination for cause. We may suspend or terminate the Services immediately and without prior notice if: (a) you materially breach this Agreement (and where the breach is capable of remedy, fail to remedy it within ten days of our notice); (b) you fail to pay Fees when due, and the failure continues for fourteen days after our reminder; (c) we reasonably believe your use creates a security, legal, regulatory, reputational, or operational risk; (d) we receive a credible complaint, court order, or government request requiring suspension or termination; (e) you become insolvent, are placed in administration, liquidation, or receivership, or cease to carry on business; (f) you provide false or misleading information in connection with the Account; or (g) any payment to us is reversed, charged back, or disputed without proper basis. 13.4 Effect of suspension. During any suspension, you remain liable for Fees. The Services may be reactivated on your remedy of the breach (where remediable) and payment of any reactivation Fee. 13.5 Effect of termination. On termination: (a) your right to use the Services ends immediately; (b) you must export Customer Content within thirty days using the export tools in KPanel; (c) we will retain Customer Content for thirty days after the Services stop following termination ("Grace Period"), we will email you the date it will be deleted when the Services stop and again seven days before that date, and during the Grace Period you may reinstate the Service by purchasing it again and paying any outstanding Fees; (d) after the Grace Period, we will permanently delete Customer Content from our live systems, and backup copies become unrecoverable as set out in clause 11.4; (e) prepaid Fees are non-refundable except as set out in this Agreement or the Refund Policy; and (f) provisions that by their nature should survive termination survive, including clauses 1, 7, 9, 10, 13.5, 15, 16, 17, 18, 19, and 20. 13.6 Reactivation. Where the Account has been suspended or terminated for cause, reactivation is at our sole discretion and may be conditional on remedy of the breach, payment of outstanding Fees, payment of a reactivation Fee, and acceptance of additional terms. ## 14. Service levels 14.1 The availability targets we commit to and the service credits available where we fail to meet them are set out in the SLA. 14.2 SLA service credits are your sole and exclusive remedy for downtime, except where another remedy is required by law (for example, under the Consumer Guarantees Act 1993 where you are a consumer). ## 15. Disclaimers 15.1 Except as expressly stated in this Agreement or the SLA, and subject to clauses 15.2 and 16.1, the Services are provided "AS IS" and "AS AVAILABLE". We make no warranty of any kind, whether express, implied, statutory, or otherwise, including any warranty of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, reliability, uninterrupted availability, error-free operation, security, or freedom from viruses or harmful components. 15.2 Consumer Guarantees Act. If you are a "consumer" within the meaning of the Consumer Guarantees Act 1993, that Act gives you statutory guarantees that cannot be excluded. Nothing in this Agreement limits any such guarantee. Where you acquire the Services for the purposes of a business, you agree that the Consumer Guarantees Act 1993 does not apply, to the maximum extent permitted by section 43 of that Act, and you acknowledge that this exclusion is fair and reasonable. 15.3 We do not warrant or endorse any third-party content, products, software, or services that may be accessible through, integrated with, or installed on the Services. ## 16. Limitation of liability 16.1 Nothing in this Agreement excludes or limits liability that cannot lawfully be limited, including liability for fraud, fraudulent misrepresentation, wilful misconduct, death or personal injury caused by negligence, or any statutory consumer right that cannot be excluded under New Zealand law. 16.2 Subject to clause 16.1, our total aggregate liability to you for all claims arising out of or in connection with this Agreement and the Services in any rolling 12-month period, whether in contract, tort (including negligence), under statute, or otherwise, is limited to the greater of: (a) the Fees actually paid by you to us in the 12 months immediately preceding the event giving rise to the claim; or (b) NZ$200, converted into the currency in which your Fees are charged at the exchange rate on the date the claim arises. 16.3 Subject to clause 16.1, neither party is liable to the other for any indirect, consequential, special, incidental, exemplary, or punitive loss, or for any loss of profits, revenue, business opportunity, anticipated savings, goodwill, reputation, data (except as expressly addressed in clauses 11 and the SLA), or business interruption, in each case howsoever arising and whether or not the party was advised of the possibility of such loss. 16.4 You acknowledge that the limitations and exclusions in this clause 16 reflect a fair allocation of risk between the parties, are essential to the basis of this Agreement, and would not be agreed to by us without them. ## 17. Indemnity 17.1 You will indemnify, defend, and hold harmless KapsuleHost, its Affiliates, and their respective officers, employees, contractors, and Sub-processors (each an "Indemnified Party") from and against any third-party claim, demand, action, loss, damage, liability, fine, penalty, cost, or expense (including reasonable legal fees) arising out of or in connection with: (a) your Customer Content; (b) your use of the Services in breach of this Agreement, the AUP, or any law; (c) your infringement or violation of the rights of any third party; (d) your handling of Personal Information in breach of the Privacy Act 2020 or any other privacy law; (e) any dispute between you and a third party (including any end-user, other customer, or registry); or (f) your breach of any representation or warranty in this Agreement. 17.2 We will give you prompt written notice of any indemnified claim, allow you to assume control of the defence (subject to our reasonable approval of counsel), and provide reasonable cooperation at your expense. You may not settle any indemnified claim in a manner that imposes an obligation or admission on us without our prior written consent. ## 18. Force majeure 18.1 Neither party is liable for any failure or delay in performing its obligations under this Agreement (other than payment obligations) caused by a Force Majeure Event, defined as any event beyond the affected party's reasonable control, including acts of God, natural disaster, fire, flood, earthquake, pandemic, war, civil unrest, terrorism, riot, sabotage, governmental action, change of law, embargo, labour dispute, internet backbone failure, denial-of-service attack, upstream provider failure, undersea cable failure, telecommunications outage, or interruption to electrical power. 18.2 The affected party must promptly notify the other and take reasonable steps to mitigate the effect and resume performance as soon as practicable. 18.3 If a Force Majeure Event continues for more than sixty consecutive days, either party may terminate the affected Service on written notice without further liability, subject to any pro rata refund under the Refund Policy. ## 19. Governing law and dispute resolution 19.1 This Agreement is governed by the laws of New Zealand without regard to conflict-of-laws principles. 19.2 The courts of New Zealand have exclusive jurisdiction, save that we may bring proceedings to enforce or protect our intellectual property rights in any jurisdiction. 19.3 Before commencing any court proceeding, the parties will attempt in good faith to resolve any dispute by negotiation. If the dispute is not resolved within thirty days, the parties will refer it to mediation administered by the Resolution Institute (resolution.institute), with each party bearing its own costs and the mediator's fees shared equally. 19.4 Clause 19.3 does not prevent either party from seeking urgent injunctive or equitable relief in any court of competent jurisdiction. 19.5 Any claim arising out of or in connection with this Agreement must be brought within two years of the event giving rise to the claim, except where a longer period is required by law. ## 20. Changes to this Agreement 20.1 We may update this Agreement from time to time. Material changes will be notified to you by email or KPanel notice at least thirty days before they take effect. Non-material changes (such as typographical corrections, contact updates, formatting, or clarifications) take effect on posting and the "Last updated" date will be revised accordingly. 20.2 Your continued use of the Services after a change takes effect constitutes acceptance of the updated Agreement. 20.3 If you do not agree to a material change, you may terminate the affected Service before the change takes effect and receive a pro rata refund of any prepaid Fees for the unused portion of the relevant billing cycle. ## 21. General 21.1 Assignment. You may not assign, transfer, or sub-licence any of your rights or obligations under this Agreement without our prior written consent. We may assign or novate this Agreement to an Affiliate or in connection with a merger, acquisition, restructuring, or sale of substantially all our assets, on notice to you. 21.2 Entire agreement. This Agreement (including the documents incorporated by reference) constitutes the entire agreement between the parties in relation to its subject matter and supersedes all prior or contemporaneous oral or written communications, proposals, and representations. 21.3 No reliance. You acknowledge that you have not relied on any statement, promise, or representation made by us that is not expressly set out in this Agreement. 21.4 Severability. If any provision of this Agreement is held to be unenforceable, that provision is severed, and the remaining provisions continue in effect. Where reasonably possible, the unenforceable provision will be replaced by an enforceable provision of similar effect. 21.5 No waiver. A failure or delay in exercising any right is not a waiver of that right. A single or partial exercise of a right does not preclude further exercise. 21.6 Notices. Notices to us must be sent to legal@kapsulehost.com. Notices to you will be sent to the email address on your Account or posted in KPanel. Notices are deemed received on the next business day after sending. 21.7 Independent contractors. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, fiduciary, or employment relationship. 21.8 No third-party beneficiaries. Except where expressly stated (for example, the Indemnified Parties in clause 17), nothing in this Agreement is intended to confer any benefit or right on any person other than the parties. 21.9 Electronic acceptance. This Agreement may be accepted electronically. Electronic acceptance is binding and has the same force and effect as a wet-ink signature under the Contract and Commercial Law Act 2017 (Part 4). 21.10 Survival. Clauses 1, 7, 9, 10, 13.5, 15, 16, 17, 18, 19, 20, and 21, together with any other provisions that by their nature should survive, will survive termination of this Agreement. ## 22. Contact Kapsule Group Limited, New Zealand. General enquiries: support@kapsulehost.com Billing: billing@kapsulehost.com Legal and notices: legal@kapsulehost.com Privacy: privacy@kapsulehost.com Abuse: abuse@kapsulehost.com Security: security@kapsulehost.com --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/terms, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Privacy Policy KapsuleHost Privacy Policy: how we collect, use, hold, and protect your personal information under the New Zealand Privacy Act 2020. Canonical page: https://kapsulehost.com/en-us/legal/privacy Last updated: 8 October 2026 Version 22, effective October 8, 2026 ## About this Privacy Policy This Privacy Policy explains how Kapsule Group Limited ("KapsuleHost", "we", "us", "our") collects, uses, holds, stores, discloses, and protects personal information when you use our cloud hosting, domain registration, email hosting, and related products and services (together, the "Services"). It is written to comply with the New Zealand Privacy Act 2020 and the twelve Information Privacy Principles ("IPPs") set out in that Act. This Privacy Policy applies to our customers, our customers' personnel, visitors to kapsulehost.com and kpanel.kapsulehost.com, applicants, and any other individual whose personal information we hold. It does not apply to information you choose to store on the Services about other people; that processing is governed by the Data Processing Agreement ("DPA"). We are committed to handling your personal information openly and lawfully. If you have a concern, please contact us first at privacy@kapsulehost.com. We will work with you to resolve it. You can also complain to the Office of the Privacy Commissioner (details in clause 12). ## 1. Who we are Kapsule Group Limited is a company incorporated in New Zealand. We are the agency for the purposes of the Privacy Act 2020 in respect of personal information we hold about you. Contact for privacy matters: privacy@kapsulehost.com | Privacy Officer, Kapsule Group Limited, New Zealand. ## 2. What we collect We only collect personal information that we need for one or more of the purposes set out in clause 3. Account information: name, business name, email address, a mobile phone number (which we require and verify when you open an Account), billing address, country, and the username and hashed password you set. Verification information: where required to prevent fraud or comply with law, government identification, proof of address, or other identity documents. Payment information: payment method, billing history, transaction identifiers, and partial card details (last four digits and card type). Full card numbers are tokenised by Stripe and are not stored on our systems. When you pay by bank transfer, we receive from our bank-account provider the sender's name, the sender's account details and the payment reference your bank sends with the payment; and when we refund a bank transfer, we collect the account holder's name and the bank account details needed to pay it. We store these encrypted and use them only to match and refund payments. Authentication information: hashed passwords, two-factor authentication secrets and recovery codes, session tokens, authentication logs, and password-reset audit trails. Customer Content metadata: filenames, sizes, content types, dates of upload, access logs, and other metadata about content you store on the Services. We do not routinely inspect the substance of Customer Content. Usage data: server resource usage (CPU, memory, storage, bandwidth, requests, queries, mail volumes), feature usage in KPanel, API call records, error logs, and aggregated metrics used for capacity planning, abuse prevention, and product improvement. Device and connection information: IP address, browser type and version, operating system, device type, screen resolution, language, time zone, approximate geographic location derived from IP, referrer URLs, and unique device identifiers. Communications: records of your communications with us, including support tickets, KPanel messages, conversations with Kora (our AI customer support assistant), emails, phone or video call recordings (where you consent), survey responses, feedback, and messages and comments you send to our Facebook Page or Instagram account (clause 4B). Domain registrant information: where you register a domain through us, the registrant, administrative, technical, and billing contact information required by the relevant Registry, including name, organisation, address, email, and phone. Where you enable WHOIS privacy, public WHOIS displays a privacy proxy contact instead of your personal contact information, but we still hold the underlying information. Mail metadata: for email Services, message headers (including sender, recipient, subject, message ID, timestamps), routing data, and reputation indicators. We do not routinely read the content of your messages, except where strictly necessary for security, abuse-prevention, or to comply with law. Cookies and similar technologies: see our Cookie Policy at kapsulehost.com/legal/cookies. Job applicant information: where you apply for a role with us, your CV, cover letter, references, and the information you provide during the recruitment process. Other information: any other personal information you choose to provide to us. ## 3. Why we collect it (purposes) We collect, use, and disclose personal information for the following purposes: To provide the Services: including creating, operating, supporting, and maintaining your Account, provisioning resources, delivering content, hosting websites, sending and receiving email on your behalf, and registering domain names. To bill and collect payment: including processing transactions, issuing invoices, calculating taxes, retrying failed payments, processing refunds, and managing disputes and chargebacks. To authenticate and secure the Services: including verifying your identity, enforcing two-factor authentication, detecting and preventing fraud, abuse, and unauthorised access, and protecting the integrity of the platform. To verify your mobile number and prevent abuse: when you open an Account, or at your next sign-in for an existing Account, we send a one-time code to your mobile number by SMS or WhatsApp. Before sending it we may check the number's line type (for example mobile, landline or internet (VoIP) number) with our verification provider, and we do not accept landline, internet or other non-mobile numbers for verification. We keep a one-way hash of your verified number so we can limit how many Accounts one number can be verified on. We use your number for verification, account security and fraud and abuse prevention, not for marketing. To communicate with you: including responding to support enquiries, providing service-related notices (billing, security, outages, policy changes), and (where you opt in) sending marketing communications. To improve our Services: including analysing aggregated and de-identified usage data, conducting research, developing new features, and benchmarking performance. To comply with law: including responding to lawful requests from regulators, law enforcement, or courts; meeting tax and corporate record-keeping obligations; and complying with the Privacy Act 2020, Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (to the extent applicable), and other applicable laws. To enforce our agreements: including investigating breaches of our Terms of Service or Acceptable Use Policy, exercising our rights under those agreements, and defending legal claims. To operate automated abuse detection: we operate automated systems that analyse patterns in account activity, traffic, payments, and content to identify potential abuse or breach of our policies. Where the system flags activity as likely abusive, proportionate automated measures may be applied (such as challenge tests, rate limiting, account holds, or service suspension), subject to human review on request. For recruitment purposes: where you apply for a role with us, to assess your suitability and to communicate with you about the application. We do not use your personal information for any purpose other than those listed in this clause or for purposes you authorise. Lawful basis under the EU GDPR (for EU/EEA residents). Where the EU General Data Protection Regulation applies to our processing of your personal information, we rely on the following lawful bases: (a) Contract (Article 6(1)(b)): providing the Services, billing, and Account management; (b) Legitimate interests (Article 6(1)(f)): security, fraud prevention, abuse detection, enforcing our agreements, and improving our Services - these interests do not override your rights given the technical and organisational safeguards we maintain; (c) Consent (Article 6(1)(a)): marketing communications - you may withdraw consent at any time; (d) Legal obligation (Article 6(1)(c)): tax, accounting, and regulatory requirements. Launch Check (1 to 7 October 2026). If you ask us to check a domain, we keep the domain name, one way to reach you (an email address, or a social media or Discord handle) and the channel you asked on, only to run the check and send you its report. The check uses public information about the domain: its DNS records, its certificate and registration expiry dates, and a mobile speed test we run ourselves. Kora, our AI assistant, drafts the report from those results and never sees your contact details. A person on our support team reviews it and sends it to you. We do not use your details for marketing, and we delete them 30 days after your request. If you reply to your report, your reply reaches our support team and is kept as ordinary support correspondence. Measuring which of our own posts, ads and links bring sign-ups. When a link carrying campaign tags brings you to kapsulehost.com, we set one first-party cookie, kh_ft, there (Cookie Policy clause 3.6); when the link brings you straight to KPanel instead, with no cookie already set, we read the same tags from the link itself. Either way, if you go on to open an Account, we read those details once, at that moment. It holds only the four campaign tags on that link (utm_source, utm_medium, utm_campaign and utm_content: the labels we add to our own posts, ads, messages and emails, or that whoever shared the link added, to say where it was published and which post or ad it belongs to), the path of the page you landed on without its query string, and the date and time of that visit. It holds no advertising click identifier, IP address, browser or device details, or referring page. A visit without campaign tags sets nothing, a later tagged visit never replaces the first, and the cookie is not set if your browser sends a Global Privacy Control (GPC) signal on that visit. If you open an Account while the cookie is held, we store those same details with your Account. We use them only to count the sign-ups, paying customers and revenue that each of our posts, ads, campaigns, networks and markets brings, and our reports show those counts only, never a name, email address or Account. We do not send these campaign details to any advertising network or other third party; the Account-opening and purchase events described under Advertising with Meta and Google below are separate, and follow the advertising choices described there. Lawful basis under the EU GDPR: legitimate interests (Article 6(1)(f)). Our interest is putting our own marketing effort and money where it brings customers. We have balanced it against your interests and consider that it does not override your rights, because the details are limited to campaign labels, a page path and a time, only we read them, we use them only as counts, nothing follows you on other websites, and a GPC signal stops the cookie being set. The cookie lasts 30 days. The details stored with your Account are Account information: they are kept while the Account is open and deleted 12 months after it closes (clause 9). You can object at any time by writing to privacy@kapsulehost.com (clause 11). Your choices about campaign measurement, advertising and analytics. Campaign measurement (the kh_ft cookie in the paragraph above), advertising (the next paragraph) and analytics (the paragraph after it) are used only once we switch them on, and then only as your choice and where you are allow. If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, or we cannot tell your country, each stays off until you choose Accept all in our cookie banner or switch it on in Cookie settings (Cookie Policy clause 3.7), and for campaign measurement the lawful basis under the EU and UK GDPR is then your consent (Article 6(1)(a)) rather than legitimate interests. Everywhere else each is on by default, which means we measure ad clicks and sign-ups for advertising unless you turn it off. You can turn it off at any time with Reject all, by switching Advertising off in Cookie settings, or by having your browser send a Global Privacy Control signal. Cookie settings is always available from the link at the bottom of every page of kapsulehost.com, and a Global Privacy Control signal always overrides any choice made there. The advertising and analytics tags load only after the page has shown. Switching campaign measurement off deletes the kh_ft cookie. On kapsulehost.com, while campaign measurement is allowed, the four campaign tags from the link that brought you are kept in your browser session storage (kh_utm) for that browser session only, so that the sign-up and sign-in links on that site can pass them on to KPanel. We record your choices in one strictly necessary cookie, kh_consent, which lasts 12 months (Cookie Policy clause 3.1). The campaign details stored with an Account are deleted 12 months after the Account closes, like all Account information (clause 9). Advertising with Meta and Google: measurement, remarketing and audiences. If advertising is switched on and you allow it, we load the Meta Pixel and the Google tag for Google Ads on kapsulehost.com only; KPanel loads neither. From those tags, Meta (Facebook and Instagram) and Google receive the address of the page and the page you came from, your IP address, your browser's user agent, screen size and language, their own cookie identifiers (_fbp and _fbc for Meta, _gcl_au, _gcl_aw and _gcl_gb for Google, and any cookies of their own that your browser already holds, such as Meta's fr cookie if you are signed in to Facebook or Instagram), and the click identifier when you arrived from one of their ads (fbclid for Meta; gclid, gbraid or wbraid for Google). These tags send page visits only. When you open an Account, or a payment is captured, we send that event only from our servers, under the same rules as the tags, set out at the end of this paragraph; it is never sent when your browser sends a Global Privacy Control signal. To Meta (Conversions API) we send the kind of event, its time and identifier, the address of the page without its query string, your email address hashed with SHA-256 after being lower-cased and trimmed (Meta cannot read it back, but can match it to a Meta account that holds the same address), Meta's two cookie values (_fbp and _fbc) if your browser holds them, and your browser's user agent, and for a purchase its value and currency; we never send Meta your IP address from our servers. To Google Ads we send, only if you arrived from a Google ad, the Google click identifier (gclid, gbraid or wbraid), the conversion, its time and identifier, and for a purchase its value and currency; we never send Google your email address. Event identifiers are derived from our own records in a way that cannot be reversed. We never send your name, postal address, phone number, payment details or anything about the services you host, and we upload no customer list to either. Meta and Google use these visits and conversions to measure our ads, to show you our ads on their services and on other sites and apps that carry their ads (remarketing), and to build advertising audiences for us: people who visited our site, people who viewed our pricing, people who started to sign up but did not buy, and our customers, whom we use to stop showing ads for services they already have. Each visitor stays in an audience for 180 days after their last matching visit (30 days for the sign-up audience). Meta also finds people it judges similar to our customers (a lookalike audience), and Google may also use audiences built in Google Analytics for visitors who allowed analytics as well. Nobody at KapsuleHost can see who is in an audience: Meta and Google show us only its approximate size. We keep a record of each event we send: its kind, identifier, Account and order, value and currency, the campaign, ad set and ad it came from, why it was allowed, and whether each network accepted it. The Meta cookie values, the Google click identifier and the user agent are kept in it only until the event is sent or given up, and at most 7 days; your email address, its hash and your IP address are never stored. Each record is deleted 12 months after the event, all of them are deleted when your Account is erased, and a record for a purchase that is never paid is deleted after 30 days. Meta and Google are recipients who use what they receive under their own terms as independent controllers, including to measure and improve their advertising services, and keep it for the periods those terms set. In the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, this happens only after you choose Accept all or switch Advertising on in Cookie settings, and the lawful basis under the EU and UK GDPR is your consent (Article 6(1)(a)). Elsewhere we measure ad clicks and sign-ups for advertising unless you turn it off: it happens unless you choose Reject all, switch Advertising off in Cookie settings, or your browser sends a Global Privacy Control signal, and we rely on our legitimate interest in advertising our services. You can withdraw your consent or opt out at any time in Cookie settings (the link at the bottom of every page of kapsulehost.com); this stops the tags and any further server events and deletes the Meta and Google cookies on kapsulehost.com, but does not undo what was sent before. Where a law treats this as sharing personal information for targeted advertising, that opt-out is your right to opt out of it. Analytics with Google Analytics. If analytics is switched on and you allow it, we load Google Analytics on kapsulehost.com and on the KPanel sign-up, welcome, onboarding and checkout pages, to understand how visitors use them. It sends Google each page view with the page address (its query string removed, except for our campaign tags), the page title and the page you came from, your screen size and language, a random identifier for your browser and for your session, how long you engaged, whether you scrolled to the end of the page, clicks on links that leave our site, and when you open an Account or complete a purchase, with our event identifier and, for a purchase, its value and currency. Google derives an approximate country and city from your IP address and does not store the IP address in Google Analytics. We send no email address, user identifier, form contents or keystrokes, and form, site search, video and file-download tracking are off. Its cookies, _ga and _ga_ followed by our property identifier, last 13 months, and the event data is kept for 14 months. Google signals and advertising personalisation are used only if you have also allowed advertising, and only then can audiences built in Google Analytics be used for our Google ads. Google is a recipient under its own terms, as for advertising above. In the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, it runs only after you choose Accept all or switch Analytics on in Cookie settings, and the lawful basis under the EU and UK GDPR is your consent (Article 6(1)(a)). Elsewhere it runs unless you choose Reject all, switch Analytics off, or your browser sends a Global Privacy Control signal, and we rely on our legitimate interest in understanding how our sites are used. Switching it off stops Google Analytics and deletes its cookies on kapsulehost.com. Plausible, our own cookieless analytics on kapsulehost.com, is separate and is described in clause 3.3 of our Cookie Policy. Heatmaps with PostHog. If analytics is switched on and you allow it, PostHog, which processes this for us in the EU, records heatmaps of the public pages of kapsulehost.com; it never runs in KPanel or on sign-up, sign-in, checkout, cart, order, account, password or billing pages. It receives where on the page you click and move the pointer, repeated clicks, how far you scroll, the size of your window and screen, the page address (its query string removed, except for our campaign tags), the website you came from (not the page), your browser, operating system and type of device, and a random identifier that is kept in memory for that page load only. It records nothing you type, no form contents, no page text and no recording of your visit. It sets no cookie and stores nothing on your device, and the IP address is discarded before processing; PostHog counts visitors with a hash on its own servers. PostHog keeps these heatmap points for up to 7 years. They contain no cookie, no IP address and no identifier for you, and nothing you type. The regional rule, the lawful basis and how to switch it off are the same as for Google Analytics in the paragraph above; switching Analytics off stops it at once, and there is nothing to delete on your device. ## 4. Sources Most personal information we hold about you is collected directly from you when you sign up, log in, contact support, or use the Services. We also collect personal information from our Sub-processors and other service providers (for example, Stripe provides payment status); fraud prevention databases and third-party verification services; public sources (including WHOIS records and government registers); referrals (for example, where another customer refers you and you accept the referral); Meta, when you send a message to, or comment on, our Facebook Page or Instagram account (clause 4B); and your interactions with our website (including via cookies; see Cookie Policy). ## 4A. Contacts you bring from Google or Microsoft This clause applies when, as part of moving your email to KapsuleHost, you choose to have us copy your contacts from a Google account (Gmail or Google Workspace) or a Microsoft account (Outlook.com or Microsoft 365). You start this yourself in KPanel, and you sign in at Google or Microsoft to give us permission. We ask only for read-only access to your contacts, and for your account's email address so that we can check you signed in to the account you are moving: from Google, the People API scope contacts.readonly, with openid and email; from Microsoft, the Microsoft Graph permissions Contacts.Read, User.Read and offline_access. How we use it: we read your contacts (names and nicknames, email addresses, phone numbers, postal addresses, organisation, department and job title, birthdays, notes and photos, and, from Microsoft, categories) and write them into the address book of your own KapsuleHost mailbox. From Google we copy your saved contacts, not the "other contacts" Gmail collects automatically; from Microsoft we copy your Contacts folder and the folders inside it. Making that copy, and showing you its progress, is the only thing we use this data for, and we use your account's email address only for the check described above. We never change or delete your contacts or anything else in your Google or Microsoft account, other than asking Google to end our own access as described below. How we store it and when we delete it: the access tokens Google or Microsoft give us are stored encrypted and used only by that migration. We delete them as soon as the copy of your contacts finishes, whether or not every contact could be copied, and in any case when the migration completes, fails or is cancelled; at that point we also ask Google to revoke its token. You can withdraw our access yourself at any time in your Google or Microsoft account's security settings (for Google, at myaccount.google.com/permissions). The copied contacts are held in your KapsuleHost address book, which you control, and follow that mailbox's retention and deletion, including its backups (see clause 9). How we share it: we do not sell, rent or share this data, we do not transfer it to anyone except where needed to make the copy you asked for or where the law requires, we do not use it for advertising, and we do not use it to develop, improve or train artificial intelligence or machine learning models. No KapsuleHost staff member reads it unless you ask us to for a support request, for security reasons, or where the law requires. KapsuleHost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. If you choose Sign in with Microsoft for a Microsoft 365 or Outlook.com mailbox you are moving, we ask Microsoft for the delegated permissions IMAP.AccessAsUser.All and offline_access, and User.Read to confirm that the account you sign in with is the mailbox being moved. Microsoft describes IMAP.AccessAsUser.All as read and write access to your mailbox over IMAP; we use it only to read. We open each folder read-only and copy each message, with its flags and date, into your KapsuleHost mailbox, and we never change, move, delete or mark as read anything in your Microsoft mailbox. Messages pass through our migration service in memory on their way to your new mailbox and are not written anywhere else. The token Microsoft gives us is stored encrypted, used only by that migration, and deleted when the migration completes (for a migration that switches your mail over, at the end of the 24 hours after the switch in which we collect late mail), fails or is cancelled, and as soon as that mailbox can no longer be copied. Microsoft offers no way for us to revoke it ourselves; you can remove KapsuleHost's access in your Microsoft account settings at any time. ## 4B. Messages and comments on our social accounts This clause applies when you send a message to, or comment on a post of, the KapsuleHost Facebook Page or Instagram account. We receive this information through Meta, which runs Facebook and Instagram. What we receive: your name or username, the identifier Meta gives your account for our Page or Instagram account, the text of your message or comment, a link to your comment, and when you sent it. How we use it: only to read and answer you. Kora, our AI assistant, reads each message or comment to sort it (for example, a question, thanks or a complaint) and to draft a reply; this is AI processing under clause 5, and clause 5.3 applies to it. A person on our team reviews and sends replies, and simple routine answers (a thank-you, or a link to our help centre or to our Launch Check) may be sent automatically only where we have switched that on, after an automatic check of their facts. Messages about billing, account access, security or legal matters, and complaints, always go to a person. Who receives it: our reply goes back to you through Meta, and a reply to a comment is public on that post, as your comment is. Meta handles these messages and comments under its own terms and privacy policy, as an independent controller. How long we keep them: 12 months after the conversation ends, and then we delete them, with our replies. If our team escalates a message internally, the note in our audit log may quote it and is kept as part of that log. To have them deleted: write to privacy@kapsulehost.com with your name or username on Facebook or Instagram, and we delete them within 30 days (clause 11). This deletes them from our systems; to remove a comment or message from Facebook or Instagram itself, use Meta's own tools. ## 4C. Our own social media accounts. Our internal staff tool, KApex, connects to KapsuleHost's own accounts on LinkedIn, YouTube, TikTok, Threads, Facebook, Instagram and X, so that one authorised member of our team can schedule and publish our own marketing posts. The access tokens these platforms give us are stored encrypted, used only to publish to our own account and to confirm a post we made is still there, and are never used to read, follow, message or act on any other account. We delete a token when the connection is disconnected, or when it expires and nobody renews it. Where a platform is Google (our YouTube channel), KapsuleHost's use and transfer of information received from the YouTube API Services will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements, and to the YouTube API Services Terms of Service (https://www.youtube.com/t/terms). ## 5. How we use AI to provide the Services 5.1 Kora. Kora is our AI customer-support assistant, built on Anthropic Claude. Kora may read your support messages, recent ticket history, basic Account context, and any information you specifically include in a support chat (for example, log excerpts) in order to respond to your enquiries. 5.2 Memory. Kora keeps a memory of your earlier support conversations, as short summaries and the facts you have told it, so that it can answer follow-up questions in context. This memory is stored in our own database with the rest of your account data, and no third-party memory service receives it. 5.3 Limitations on AI processing. We do not authorise our AI sub-processors to use Customer Content or your support communications to train their general models. AI processing is for the purpose of providing the Services only. 5.4 No automated decision-making with legal effect. Kora does not make decisions with legal or similarly significant effects on you. Decisions about suspension, termination, refunds, or account changes are made by humans, or by automated systems that are reviewed by humans on request. 5.5 Human review. You may request that your support interaction be handled by a human at any time by emailing privacy@kapsulehost.com or support@kapsulehost.com. ## 6. Disclosure to Sub-processors and other recipients 6.1 We disclose personal information only: (a) to our Sub-processors (clause 7), who are bound by contractual confidentiality and security obligations and permitted to use the information only to provide services to us; (b) to integration partners and other third parties where you have directed or authorised us to do so; (c) to professional advisers (lawyers, accountants, auditors, insurers) under duties of confidentiality; (d) to law enforcement, regulators, courts, registries, or other authorities where required by New Zealand law or by foreign law applicable to a Sub-processor; (e) to acquirers in connection with a merger, acquisition, or sale of all or substantially all of our assets (we will notify you of any such change); (f) where reasonably necessary to enforce our agreements, protect our rights or those of others, or prevent harm; (g) with your express consent; and (h) to Meta, when we reply to a message or comment you sent to our Facebook Page or Instagram account (clause 4B). 6.2 We do not sell, rent, or trade personal information. ## 7. Sub-processors We rely on Sub-processors to provide the Services. Each is subject to a written contract and to security and confidentiality obligations no less protective than those in this Privacy Policy. Our current Sub-processors, with their purpose and location, are listed in the Sub-processors List at kapsulehost.com/legal/sub-processors, which forms part of this Privacy Policy. A current and dated list is maintained at kapsulehost.com/legal/sub-processors. We will notify you of any new Sub-processor that will process personal information, and of any material change to an existing one, at least thirty days before it takes effect, so you can object on reasonable grounds. If you object and we cannot resolve your concern, you may terminate the affected Service and receive a pro rata refund of any prepaid Fees. ## 8. International transfers 8.1 Some Sub-processors are located outside New Zealand. Where personal information is transferred overseas, we ensure that the recipient is required (by contract or operation of law) to apply protections comparable to those in the Privacy Act 2020. This includes ensuring that the recipient is bound by privacy laws that, in our view, provide comparable safeguards (for example, the EU General Data Protection Regulation), or by contractual safeguards we put in place. 8.2 By using the Services, you authorise the transfer of your personal information to the jurisdictions in which our Sub-processors operate, as listed in clause 7 and at kapsulehost.com/legal/sub-processors. 8.3 You may withdraw this authorisation by terminating the Services. Withdrawal of authorisation may make it impossible for us to continue to provide the Services. ## 9. Retention We retain personal information only for as long as we need it for the purposes set out in clause 3, or as required by law. Account information: retained for the life of the Account plus 12 months after closure. Your verified mobile number, its hash and its line-type result are account information and follow the rule above. If you remove your number from your Account, we delete the number, its hash and its line-type result. Billing and tax records: 7 years from the date of the transaction (Tax Administration Act 1994). Customer Content: retained for the duration of the subscription and until its Services stop, plus a 30-day Grace Period, after which it is deleted. Off-site backups (Customer Content): 30-day rolling retention minimum (longer for higher Plans). Backups become unrecoverable within 31 days of deletion from live systems. Support communications: 3 years after the ticket is closed. Kora chat logs: 12 months from the date of the conversation, then aggregated and de-identified. Authentication and security logs: 12 months (longer where needed for an active investigation). Marketing consent records: life of the consent plus 7 years after withdrawal (to evidence the consent). Recruitment information: 12 months after the recruitment decision (unless you ask us to retain it longer for future opportunities). WHOIS Data: for the duration of the domain registration plus any period required by ICANN or the relevant Registry. We may extend retention where required to comply with law, to defend a legal claim, or to investigate or remedy a security incident. ## 10. Storage and security 10.1 We protect personal information using a layered approach, including: TLS encryption for all data in transit; encryption at rest for backups and sensitive databases; encrypted backups: backups of hosted websites and their databases are stored in Europe, on the hosting server in Germany and off-site in Finland; backups of managed servers, of our own account and billing databases, of online shop databases, of our object storage service and of email are stored off-site in Finland; and whole-server backups of our control panel, which also runs online shops, are kept with it in the Asia-Pacific region; strict role-based access controls and least-privilege principles; mandatory two-factor authentication for all personnel with access to production systems; regular security patching, vulnerability scanning, and periodic penetration testing; segregation of customer data; logging of authentication events and configuration changes to a centralised audit trail, with system-level logs retained locally on each server; documented incident response and breach notification procedures; and personnel confidentiality undertakings and ongoing privacy and security training. 10.2 A more detailed description of our technical and organisational measures is available at kapsulehost.com/legal/security. 10.3 No system is perfectly secure. If a notifiable privacy breach occurs, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, and in any event within seventy-two hours of becoming aware of the breach, as required by sections 112 and 114 of the Privacy Act 2020. 10.4 KPanel, our control panel, runs on servers in the Asia-Pacific region. So do the database that holds your account information, including your billing and support records, and the online shops you run with us, with their data. Off-site backups of this data are stored in Finland, as clause 10.1 sets out. The Sub-processors List at kapsulehost.com/legal/sub-processors sets out where each Sub-processor processes personal information. ## 11. Your rights Under the Privacy Act 2020 you have the following rights in relation to personal information we hold about you. Right of access (IPP 6): you may request a copy of the personal information we hold about you. Right to correct (IPP 7): you may request that we correct personal information that is inaccurate, incomplete, out of date, irrelevant, or misleading. Where we do not agree to make a correction, we will attach a statement of the correction sought, if you request. Right to request deletion: you may ask us to delete personal information we hold about you by writing to privacy@kapsulehost.com. We will delete it, except what the law requires us to keep (see clause 9), and reply within the time set out at the end of this clause. Messages and comments you sent to our Facebook Page or Instagram account (clause 4B) are deleted within 30 days of your request; tell us your name or username there so we can find them. We also delete personal information when we no longer need it. Right to receive a portable copy: where reasonably practicable, we will provide your data in a structured, commonly used, machine-readable format (such as CSV or JSON). Right to withdraw consent: where we rely on your consent (for example, for marketing communications), you may withdraw consent at any time without affecting the lawfulness of earlier processing. Right to complain: you may complain to us at privacy@kapsulehost.com. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (see clause 12). Additional rights under the EU GDPR (for EU/EEA residents). If the EU GDPR applies to our processing of your personal information, you also have: (a) Right to restriction of processing (Article 18): request that we pause processing of your information while a dispute is resolved; (b) Right to object (Article 21): object to processing based on legitimate interests or for direct marketing (we will stop unless we have compelling legitimate grounds); (c) Right to lodge a complaint with a supervisory authority: in addition to the Office of the Privacy Commissioner, you may complain to the EU data protection supervisory authority in your country of residence or in the EU member state where the alleged breach occurred. A list of EU supervisory authorities is available at edpb.europa.eu. To exercise any of these rights, contact privacy@kapsulehost.com. We may need to verify your identity before responding. We will respond within twenty working days or thirty calendar days of receiving your request, whichever is sooner. We do not charge for these requests, except where a request is manifestly unfounded, excessive, or repetitive. ## 12. Office of the Privacy Commissioner If you are not satisfied with our response to a privacy concern, you may contact: Office of the Privacy Commissioner, PO Box 10094, Wellington 6143, New Zealand. Phone: 0800 803 909. Website: privacy.org.nz. ## 13. International customers We do not specifically target the Services to residents of any particular jurisdiction outside New Zealand. We endeavour to respect rights granted to you under your local law (including, where applicable, the EU General Data Protection Regulation, UK General Data Protection Regulation, and Australian Privacy Act 1988). Where you believe a specific local right applies to you and is not addressed by this Privacy Policy, please contact privacy@kapsulehost.com. We will respond to your specific request to the extent it is applicable to our processing. ## 14. Children The Services are not directed at children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe we have collected personal information from a person under 18, contact privacy@kapsulehost.com so we can promptly delete it. ## 15. Cookies and similar technologies Our use of cookies, pixels, local storage, and similar technologies is described in our Cookie Policy at kapsulehost.com/legal/cookies. ## 16. Marketing communications 16.1 We may send you service-related communications (for example, billing notices, security alerts, outage notifications, policy updates). These are not marketing communications and you cannot opt out of them while you have an active Account. 16.2 Where you have opted in, we may send you marketing communications (such as product updates, offers, and event invitations). You may opt out at any time by clicking the unsubscribe link in any marketing email, by updating your preferences in KPanel, or by emailing privacy@kapsulehost.com. 16.3 Our marketing complies with the Unsolicited Electronic Messages Act 2007. We will identify ourselves clearly, include a functional unsubscribe mechanism, and only send marketing where we have your express, inferred, or deemed consent under that Act. ## 17. Links to third parties The Services may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. You should review their privacy policies before providing personal information to them. ## 18. Changes to this Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. Material changes will be notified by email or KPanel notice at least thirty days before they take effect. Non-material changes (such as typographical corrections or contact updates) take effect on posting. The "Last updated" date at the top of this Policy indicates the most recent change. ## 19. Contact Privacy Officer, Kapsule Group Limited, New Zealand. Email: privacy@kapsulehost.com --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/privacy, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Acceptable Use Policy Canonical page: https://kapsulehost.com/en-us/legal/acceptable-use Last updated: 27 September 2026 Version 4, effective September 27, 2026 ## About this Policy This Acceptable Use Policy ("AUP") governs your use of the KapsuleHost Services and forms part of our Terms of Service. By using the Services you agree to this AUP. Capitalised terms used but not defined here have the meanings given in the Terms of Service. The AUP exists to keep the platform safe, reliable, and lawful for everyone. We enforce it firmly. Where we identify a serious breach, we may suspend or terminate Services with little or no notice. Where the breach is less serious, we will typically contact you first and ask you to remedy the issue. If you become aware of a breach of this AUP by another customer or by any person using our Services, please report it to abuse@kapsulehost.com. We treat all reports seriously and confidentially. ## 1. Prohibited content You must not use the Services to host, store, transmit, distribute, link to, advertise, or facilitate access to any content that: a. Child safety. Exploits, abuses, endangers, or sexualises children, including any child sexual abuse material (CSAM). We have a zero-tolerance policy. CSAM is reported immediately to the New Zealand Department of Internal Affairs and, where applicable, to the National Center for Missing and Exploited Children (NCMEC). b. Violent extremism and terrorism. Promotes, glorifies, recruits for, finances, or coordinates terrorism, violent extremism, or genocide, including content prohibited by the New Zealand Films, Videos, and Publications Classification Act 1993 (Objectionable Material) or by the Christchurch Call to Action. c. Incitement to violence or hatred. Incites violence or hatred against an individual or group on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age, or other protected characteristic. d. Defamation, harassment, and privacy violations. Is defamatory, libellous, threatening, harassing, stalking, or a serious invasion of privacy, including content prohibited by the Harmful Digital Communications Act 2015 or the Privacy Act 2020. e. Intellectual property infringement. Infringes any copyright, trademark, patent, trade secret, moral right, publicity right, or other intellectual property right of any person. f. Misleading or deceptive commercial conduct. Breaches the Fair Trading Act 1986, including false or misleading representations about products, services, or affiliations. g. Unsolicited electronic messages. Breaches the Unsolicited Electronic Messages Act 2007, including unsolicited commercial email and spam. h. Malware and exploit content. Contains or distributes viruses, worms, trojans, ransomware, spyware, stalkerware, keyloggers, browser exploit kits, drive-by-download payloads, or any other malicious code. i. Non-consensual intimate imagery. Including "revenge porn" and any imagery of a sexual or intimate nature shared without the depicted person's consent. j. Fraud and financial crime. Facilitates fraud, identity theft, money laundering, financing of terrorism, sanctions evasion, or any other financial crime. k. Weapons and controlled substances. Facilitates the manufacture, distribution, or unlawful sale of weapons (including firearms, explosives, and 3D-printed weapons), controlled drugs, counterfeit goods, or other prohibited items. l. Adult content. On shared Plans the following are prohibited regardless of legality elsewhere: content depicting minors or persons appearing to be minors, non-consensual content, bestiality, content lacking age verification, and any content that breaches the Films, Videos, and Publications Classification Act 1993. Certain forms of legal adult content may be permitted on dedicated Plans where you have informed us in writing. m. Other unlawful content. Any content that is unlawful in New Zealand or in any jurisdiction in which the content is or may be accessed. ## 2.1 Network and system abuse You must not: (a) conduct, facilitate, or participate in denial-of-service or distributed denial-of-service (DDoS) attacks; (b) scan, probe, or test the vulnerability of any system, network, or application without explicit prior written authorisation from the owner; (c) interfere with, intercept, or expropriate any system, network, data, or communications; (d) circumvent, disable, or attempt to defeat any security, authentication, rate-limiting, monitoring, or access-control mechanism (whether ours or another party's); (e) gain or attempt to gain unauthorised access to any account, computer, network, or data; (f) operate an open relay, open proxy, open recursor, anonymising gateway, or similar service that may be abused by third parties; or (g) attempt to reverse engineer, decompile, or extract the source code of the Services, except as expressly permitted by law. ## 2.2 Spam and unsolicited communications You must not: (a) send unsolicited bulk email (UBE), unsolicited commercial email (UCE), or messages of any kind in breach of the Unsolicited Electronic Messages Act 2007 or any equivalent law in the recipient's jurisdiction (including the U.S. CAN-SPAM Act and the Australian Spam Act 2003); (b) forge, falsify, conceal, or remove headers, return paths, source IP addresses, or sender identification; (c) harvest, scrape, or generate email addresses without consent; (d) operate mailing lists where the recipients have not given express or inferred consent to receive your messages; (e) send mail without a clear and functional unsubscribe mechanism where required by law; (f) use the Services as a relay for, or destination for, spam originating elsewhere; or (g) sustain a hard-bounce rate above 5% or a spam-complaint rate above 0.1% over any rolling seven-day period. ## 2.3 Phishing, fraud, and deception You must not: (a) host, operate, or facilitate phishing pages, scam pages, or pages impersonating other brands or persons without authorisation; (b) misrepresent the source, identity, or affiliation of any communication or content; (c) distribute malware, drive-by-download payloads, fake software updates, or browser exploit kits; (d) operate "tech support scams", lottery scams, romance scams, fake job scams, advance-fee fraud, or any similar scheme; or (e) operate or facilitate financial scams, including pump-and-dump schemes, fake investment platforms, or fraudulent cryptocurrency token sales. ## 2.4 Cryptocurrency and abuse of compute You must not: (a) run cryptocurrency mining workloads on shared hosting Plans (Start, Pro, Scale, Cloud Power), with or without disclosure; (b) operate stratum proxies, mining pools, mining bots, or other persistent high-CPU mining-related processes on shared Plans; (c) operate workloads designed to circumvent or game fair-use limits on shared Plans (for example, multi-tenant Plans masquerading as a single-customer site); (d) operate any workload that consumes shared resources in a manner materially disproportionate to your Plan, including persistent 100% CPU usage, unbounded memory consumption, or unbounded disk-write rates; (e) train, fine-tune, or run inference for machine learning models on shared Plans without our prior written consent; or (f) abuse free Trials by creating multiple Accounts, by using disposable or temporary payment methods, or by other means. ## 2.5 Email service-specific abuse You must not: (a) operate any service that constitutes a "snowshoe" sender (low-volume from many domains and IPs designed to evade reputation systems); (b) send messages with deceptive subject lines or bodies; (c) send transactional messages with no relationship to the underlying transaction; (d) operate "email validation as a service" using our infrastructure; (e) operate "warm-up as a service" or any service designed to circumvent sender reputation systems; or (f) send to purchased, scraped, or co-registration lists. To protect delivery for every customer on our shared mail servers, a mailbox that queues more than 60 outbound messages within any 60-minute period is suspended automatically and must be re-secured before it can send again. This limit applies in addition to the rates in clause 2.2(g) and is not a breach finding on its own; we review every automatic suspension. ## 2.6 Privacy and surveillance You must not: (a) collect personal information without a lawful basis and a clear privacy notice to the people whose information is collected; (b) operate, host, or facilitate surveillance, stalkerware, or "spouseware" services; (c) operate unauthorised geolocation, tracking, or behavioural-monitoring services; or (d) host or distribute personal information of any person without their consent in a manner intended to harass or expose them (doxxing). ## 2.7 Illegal services and prohibited businesses You must not: (a) operate illegal gambling, illegal pharmacies, illegal weapons sales, illegal pornography, illegal escort services, or any other service unlawful in New Zealand; (b) operate businesses that target sanctioned jurisdictions or sanctioned persons in breach of New Zealand sanctions law; or (c) operate businesses prohibited by our payment processor's restricted-business list, in respect of which we may be required to terminate. ## 2.8 Reseller and third-party services You must not: (a) resell our Services to third parties without explicit reseller terms with us; (b) provide hosting, email, or other infrastructure to third parties using our shared Plans (a personal staging site for a friend is fine; a hosting business is not); or (c) onboard your customers to our systems without making them aware of, and bound by, our Terms of Service and AUP to the extent applicable. ## 3. Fair use and resource limits 3.1 Shared hosting Plans (Start, Pro, Scale, Cloud Power) are subject to fair use. Fair use means that no single Plan may consume sustained resources that materially degrade service for other customers, regardless of whether the Plan documentation states a hard limit. 3.2 Examples of conduct that is not fair use include: (a) sustained CPU usage above the Plan's allocated share for more than a continuous 30-minute period; (b) sustained memory consumption above the Plan's allocated share; (c) sustained outbound bandwidth that materially exceeds typical use for the relevant Plan; (d) sustained inbound bandwidth that floods the network or affects other tenants; (e) excessive process count, fork rate, or thread count; (f) excessive number of files (inodes) that affects backup or filesystem operations; (g) high-frequency cron jobs running more often than every five minutes that materially consume shared resources; or (h) running long-lived persistent connections (such as websockets, IRC bots, or game servers) at scale on shared Plans. 3.3 Where your usage exceeds fair use, we may apply remedies in the order of severity: (i) automated throttling, (ii) contact and a request to upgrade or remediate, (iii) automatic upgrade to a Plan that fits your usage, (iv) suspension, and (v) termination. We will use commercially reasonable judgment about which remedy is appropriate. 3.4 Cloud Power and any future dedicated Plans have higher allowances set out on the relevant order page. ## 4. Backups and storage hygiene 4.1 You must not use the Services as primary off-site backup storage for unrelated systems, or as bulk file storage for content that is not part of your hosted website, application, or email. 4.2 You must not store on the Services any content that has not been accessed by a website visitor or application in the preceding six months, except where you have a documented business reason and the storage is reasonable in the context of your Plan. 4.3 The off-site backups we maintain are for disaster recovery only. They are not a substitute for your own backups. You must maintain your own independent backups of any content that is material to you. ## 5. Domain registration conduct 5.1 You must comply with all ICANN, Registry, and dispute-resolution policies applicable to your domain (including the UDRP and, for .nz domains, the Domain Name Commission's policies). 5.2 You must not engage in domain name cybersquatting, typosquatting, name reservation in bad faith, hoarding, or warehousing. 5.3 You must respond promptly to Registry, Registrar, or our enquiries regarding WHOIS Data accuracy or domain use. ## 6. Copyright takedown procedure 6.1 We respect intellectual property rights. We respond to credible reports of copyright infringement on the Services in accordance with the Copyright Act 1994 (New Zealand) and equivalent laws where applicable. 6.2 Notice. If you believe Customer Content hosted on the Services infringes your copyright, send a written notice to abuse@kapsulehost.com with: (a) your full name, address, telephone number, and email address; (b) identification of the copyright work (including title, author, date, and where published); (c) identification of the material on the Services that is claimed to be infringing, with the specific URL or sufficient detail to allow us to locate it; (d) a statement of good-faith belief that the use is not authorised by the copyright owner, its agent, or the law; (e) a statement, under penalty of perjury, that the information is accurate and that you are the copyright owner or authorised to act on the owner's behalf; and (f) your physical or electronic signature. 6.3 Action by us. On receipt of a valid notice, we will investigate and, where the claim appears substantiated, remove or disable access to the material and notify the affected customer. 6.4 Counter-notice. If you are a customer whose content has been removed and you believe the removal was a mistake or misidentification, submit a counter-notice to abuse@kapsulehost.com with: (a) your full name, address, telephone number, and email address; (b) identification of the material that was removed and the URL where it appeared; (c) a statement, under penalty of perjury, of good-faith belief that the material was removed by mistake or misidentification; (d) a statement that you consent to the jurisdiction of the courts of New Zealand; and (e) your physical or electronic signature. 6.5 Reinstatement. On receipt of a valid counter-notice, we will forward it to the original complainant and may restore the material unless the complainant notifies us within ten business days that they have commenced legal action against you. 6.6 Repeat infringers. We will terminate the Accounts of customers who are determined, in our reasonable judgment, to be repeat infringers. 6.7 False notices. Sending a notice or counter-notice that materially misrepresents the position may make you liable for damages and costs under the Copyright Act 1994 and other law. We may refer false notices to relevant authorities. ## 7. Investigations, cooperation with law enforcement, and disclosure 7.1 We may investigate suspected breaches of this AUP and may, in our reasonable discretion, remove or disable any content, suspend Services, or terminate Accounts. 7.2 We will cooperate with lawful requests from New Zealand law enforcement, regulators, and courts, and with requests from foreign law enforcement where authorised by New Zealand law or by mutual legal assistance treaty. 7.3 We may disclose Customer Content or Account information to law enforcement or other authorities (i) where required by law, (ii) where we receive a credible request with valid legal authority, or (iii) where we believe in good faith that disclosure is necessary to prevent imminent harm to any person. ## 8. Consequences of breach 8.1 Depending on the nature and severity of the breach, we may: (a) contact you and ask you to remedy the breach; (b) issue a written warning; (c) remove or disable specific content; (d) throttle, rate-limit, quarantine, or otherwise restrict your usage; (e) suspend the Services in whole or in part; (f) terminate the Account; (g) report the matter to law enforcement, regulators, anti-abuse networks (such as Spamhaus, NCSC-NZ, NCMEC, and CERT NZ), and to our Sub-processors; and (h) preserve evidence of the breach for our own use or for disclosure to authorities. 8.2 No refund is payable for Fees forfeited because of an AUP breach, except where a refund is required by the Consumer Guarantees Act 1993 or other law that cannot be excluded. 8.3 You will indemnify us for any cost, loss, or damage we suffer as a result of your breach of this AUP, in accordance with clause 17 of the Terms of Service. ## 9. Changes We may update this AUP from time to time. Material changes will be notified by email or KPanel notice at least thirty days before they take effect. Material changes do not retroactively apply to conduct that occurred before they took effect. Non-material changes (typographical corrections, contact updates, clarifications) take effect on posting. ## 10. Contact Kapsule Group Limited, New Zealand. Abuse reports: abuse@kapsulehost.com Copyright notices: abuse@kapsulehost.com (mark "Copyright") Security: security@kapsulehost.com --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/acceptable-use, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Refund Policy Canonical page: https://kapsulehost.com/en-us/legal/refunds Last updated: 1 October 2026 ## About this Policy This Refund Policy explains when refunds are available for KapsuleHost Services. It forms part of our Terms of Service. Capitalised terms used but not defined here have the meanings given in the Terms of Service. Nothing in this Refund Policy limits or excludes any right you may have under the Consumer Guarantees Act 1993, the Fair Trading Act 1986, or any other law that cannot be contracted out of. ## Reserved servers: a 48-hour full-refund window Reserved cloud, GPU, and dedicated servers are charged automatically the moment stock becomes available, which can be days or weeks after you reserve them, on the card you have on file. Because that charge lands on a day you did not choose, you have forty-eight (48) hours from the fulfilment email (the email telling you the server is live and your card has been charged) to cancel that server for a full refund. We refund the charge in full and remove the server. This applies once per Customer. After the 48-hour window, a reserved server is an ordinary monthly server: you may cancel it at any time from KPanel, with billing stopping at the end of the current monthly cycle, as set out in clause 2. Cloud, GPU, dedicated, and storage servers are otherwise outside the 30-day money-back guarantee in clause 1, which covers hosting Plans (Start, Pro, Scale, and Cloud Power); provisioned compute is refunded on review of work done and usage. This 48-hour window is more generous than most cloud providers, who refund nothing on provisioned compute at all. ## 1. 30-day money-back guarantee on hosting Plans 1.1 If you are a new customer and not satisfied with the Services, you may request a full refund of your first hosting Plan payment by cancelling and submitting a refund request within thirty (30) days of the date of your first paid invoice for that Plan ("Guarantee Period"). 1.2 The guarantee applies to monthly and annual subscriptions to: (a) Start; (b) Pro; (c) Scale; and (d) Cloud Power. 1.3 The guarantee does not apply to: (a) renewal payments (only the first payment for a new Plan is covered); (b) Customers who have previously had a KapsuleHost Account or have previously received a refund under this Policy; (c) domain registration, renewal, transfer, or restoration Fees (see clause 4); (d) SSL certificates that have been issued (where charged separately); (e) one-off setup, migration, professional services, or consulting Fees that have been substantively delivered; (f) usage-based add-on Fees that have already been consumed; (g) Accounts terminated by us for breach of the Terms of Service or AUP (see clause 5); (h) third-party fees passed through by us (for example, Registry fees, payment processor fees, or government taxes we cannot recover); (i) free Trials, which incur no charge in the first place; or (j) any refund request submitted after the Guarantee Period has expired. 1.4 To request a refund under this clause, contact billing@kapsulehost.com or open a billing ticket in KPanel within the Guarantee Period. 1.5 We may, in our discretion, refuse the guarantee where we reasonably believe the Account has been used in breach of the Terms of Service or AUP, or where the guarantee is being claimed in bad faith (for example, repeated sign-ups by the same person to obtain repeated refunds). ## 2. Cancelling after the Guarantee Period 2.1 You may cancel any Service at any time via KPanel. 2.2 Monthly subscriptions. Cancellation takes effect at the end of the current monthly billing cycle. No refund is payable for the unused portion of the current month. 2.3 Annual subscriptions. Where you cancel an annual subscription after the Guarantee Period, you may request a pro rata refund calculated as: Refund = (Annual Fee × Full unused months ÷ 12) − Annual discount applied − Non-refundable items. Where: (a) "Full unused months" means the number of complete months remaining in the annual billing cycle at the date the cancellation takes effect, rounded down; (b) "Annual discount applied" means the value of any discount applied because you chose annual billing, calculated as the difference between the equivalent monthly rate × months used and the amount you actually paid prorated across the months used; and (c) "Non-refundable items" means any domain Fee, SSL Fee, setup Fee, or other item identified as non-refundable in clauses 1.3 and 4. 2.4 Where the calculation in clause 2.3 yields a negative amount (because you have effectively used the Service at a higher rate than the annual rate you paid), no refund is payable and no further amount is owed. ## 3. 30-day Start Plan free Trial 3.1 The Start free Trial incurs no Fee. 3.2 If you upgrade or convert to a paid Plan during the Trial, the Guarantee Period in clause 1 begins on the date of your first paid invoice on the upgraded or converted Plan. 3.3 If you do not upgrade and do not cancel before the Trial ends, the Service will continue at the then-current Start price. The Guarantee Period in clause 1 then begins on the date of your first paid invoice. ## 4. Domain names 4.1 Domain registration, renewal, transfer, and restoration Fees are paid by us to the relevant Registry on your behalf. These Fees are non-refundable once the registration or other action has been submitted to the Registry, regardless of whether you continue to use other KapsuleHost Services and regardless of whether you cancel within the Guarantee Period. 4.2 The non-refundability in clause 4.1 reflects the fact that we incur an irrecoverable cost to the Registry on your behalf at the time of registration or renewal. 4.3 If a domain registration fails through no fault of yours (for example, the domain becomes unavailable, is rejected by the Registry through no act or omission of yours, or there is a system error on our side), we will refund the relevant Fee in full. We will tell you when a registration fails. To arrange the refund, open a billing ticket in KPanel or reply to that notification, and we will process it. The refund is not issued automatically, so please contact us rather than waiting for it to appear. 4.4 Where a domain is transferred away from us at your request, we will not refund any portion of the registration term. ## 5. Termination for breach 5.1 Where we suspend or terminate the Services because you have breached the Terms of Service, AUP, or any other policy forming part of the Terms of Service: (a) you are not entitled to a refund of any Fees, including prepaid annual Fees and prepaid add-on Fees; (b) Customer Content may be retained, deleted, or preserved as set out in the Terms of Service; and (c) we may set off any amount owed to you against any amount you owe to us, including legal costs and any third-party claims. 5.2 Clause 5.1 does not apply where a refund is required by law (for example, where a consumer guarantee under the Consumer Guarantees Act 1993 has not been met). ## 6. How refunds are paid 6.1 Approved refunds are returned to the original payment method used for the transaction. A payment you made by bank transfer is refunded by bank transfer, in the currency you paid, to a bank account you give us for that purpose in KPanel; for your protection we send it no sooner than 24 hours after you give the account, and we email your billing contact when it is given. Where the original payment method is no longer available, we may arrange an alternative method (for example, bank transfer to a verified bank account in your name) on a case-by-case basis. 6.2 We will use commercially reasonable efforts to process approved refunds within five (5) business days of approval or, for a refund by bank transfer, of the later of approval and the end of the 24-hour period in clause 6.1. Your bank or card issuer may take additional time to credit the funds to your account; this is outside our control. 6.3 GST included in your original payment is refunded proportionately. We will issue a credit note where required by the Goods and Services Tax Act 1985. ## 7. Chargebacks 7.1 Before initiating a chargeback, please contact us at billing@kapsulehost.com. We will work with you in good faith to resolve any genuine billing concern. 7.2 A chargeback initiated for an amount that is genuinely owed and not the subject of a legitimate billing error may be treated as a material breach of the Terms of Service. We may: (a) recover the disputed amount, together with any bank or card-scheme fees we incur in defending the chargeback; (b) suspend or terminate the Account immediately; (c) refuse to provide further Services to you, including refusing future Accounts; and (d) report the chargeback to fraud-prevention services and payment processors. 7.3 Clause 7.2 does not apply where the chargeback is a result of unauthorised use of your payment method by another person (and you have notified us promptly), or where it relates to a genuine billing error that we have not resolved within a reasonable time. ## 8. Service Level Agreement credits 8.1 Where we fail to meet the availability targets in the Service Level Agreement, your remedy is the service credit set out in the SLA. 8.2 SLA service credits are applied to your next invoice. They are not paid as cash and are not transferable, except where a cash refund is required by law. 8.3 Switching Credit under Terms of Service clause 7.13 is applied to your invoices and is never paid as cash. Unused Switching Credit is removed when a refund, a chargeback or the end of your Plan brings it within clause 7.13(k). ## 9. Refunds required by law 9.1 Nothing in this Refund Policy excludes, restricts, or modifies any consumer guarantee, right, or remedy that you have under the Consumer Guarantees Act 1993, the Fair Trading Act 1986, or any other law that cannot be excluded. 9.2 If you are a consumer (within the meaning of the Consumer Guarantees Act 1993) and you consider that a Service has failed to meet a consumer guarantee, contact us at billing@kapsulehost.com. We will work with you to resolve the issue, which may include remedying the failure, providing a refund, or providing a credit, depending on the nature of the failure. ## 10. Disputed refunds 10.1 If you disagree with our refund decision, you may escalate the matter to legal@kapsulehost.com for review by a senior member of our team. 10.2 If the matter is not resolved by escalation, the dispute resolution process in clause 19 of the Terms of Service applies. ## 11. Changes to this Refund Policy We may update this Refund Policy from time to time. Material changes apply only to Plans purchased or renewed on or after the effective date of the change. Existing Plans purchased before the change remain subject to the version of this Refund Policy in effect at the time of purchase, until the next renewal. ## 12. Contact Kapsule Group Limited, New Zealand. Billing: billing@kapsulehost.com Escalation: legal@kapsulehost.com --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/refunds, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Cookie Policy Canonical page: https://kapsulehost.com/en-us/legal/cookies Last updated: 8 October 2026 ## About this Policy This Cookie Policy explains how KapsuleHost (Kapsule Group Limited) uses cookies and similar tracking technologies on kapsulehost.com, kpanel.kapsulehost.com, our marketing sites, and any other site, application, or property that links to this Policy ("Sites"). It should be read together with our Privacy Policy. We use several strictly necessary cookies automatically to sign you in, keep your session secure, and protect our forms against forgery; these are required for the Sites to function securely and cannot be disabled. Our own analytics sets no cookies, and we set no advertising cookies of our own; if you allow analytics or advertising, Google and Meta set their cookies (clauses 3.3 and 3.8). We also set functional cookies for your language, location, currency and appearance preference when you actively make that choice, a chat-continuity marker when you message the Kora AI widget, one attribution cookie that is set only if you arrive through a partner's referral link, and one campaign attribution cookie that is set only if a link carrying our campaign tags brings you to kapsulehost.com. Clause 3 below names every one of these cookies individually, with what it does and how long it lasts, so you can check this Policy against your own browser. On your first visit to kapsulehost.com, a cookie banner at the bottom of the page offers Accept all, Reject all and Cookie settings, and you can change your choice at any time from the Cookie settings link at the bottom of every page of kapsulehost.com. The banner decides whether the campaign attribution cookie (clause 3.6), the Google Analytics cookies (clause 3.3) and the advertising cookies of Meta and Google (clause 3.8) are set; clause 3.7 describes how it works where you are. KPanel (kpanel.kapsulehost.com) is different: it sets only strictly necessary cookies, reads the cookies above rather than setting them, and has no banner of its own. KPanel's cookies, in plain words. KPanel sets only cookies that are strictly necessary: session and sign-in cookies keep you signed in and your session secure, including social sign-in while you are completing it, and are cleared when you sign out or your session ends; a short-lived security check confirms that a request really comes from you (anti-forgery), and, if you tick "Trust this browser for 90 days" when you sign in, a device-trust token lasts 90 days; your language, location, currency and light or dark theme choice, set only after you make it, is shared across kapsulehost.com and KPanel so that a choice on one carries to the other, and lasts 1 year; your cart remembers the plan and add-ons you chose before you have an Account, for 30 days; and a Kora chat-continuity marker lets a conversation you started with our assistant before you had an Account carry into your Account once you sign up. KPanel sets no advertising, analytics, campaign-measurement or affiliate-referral cookie of its own, and no third party (Meta, Google or anyone else) sets a cookie through KPanel. The campaign attribution cookie (kh_ft, clause 3.6) is set on kapsulehost.com, and KPanel never sets the affiliate referral cookie (kc_affiliate, clause 3.5); KPanel only reads them when you open an Account, and reads the same details from your sign-up link when neither cookie exists yet. There is no cookie banner and no Cookie settings control on KPanel, because nothing there needs your choice. ## 1. What cookies are Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, to remember preferences, to authenticate users, to measure usage, and to deliver advertising. In this Policy, "cookies" includes traditional cookies as well as similar technologies that store or read data on your device, including: (a) HTML5 local storage and session storage (small data stores in your browser); (b) IndexedDB (a structured browser data store); (c) web beacons and pixels (tiny invisible images used to track that a page or email has loaded); (d) server-side and first-party fingerprinting signals (information about your browser and device used to identify you across sessions); (e) tags placed by us or by integration partners on the Sites; and (f) SDK identifiers in applications. ## 2. First-party and third-party cookies We use first-party cookies set by us under the kapsulehost.com domain. We also rely on third-party services that may set their own cookies (see clauses 3 and 4). ## 3.1 Strictly necessary cookies These are essential for the Sites to function. You cannot disable them without breaking core functionality. We do not require consent for strictly necessary cookies because they are required for the Sites to operate. Several distinct cookies fall in this category; each is named below with its real cookie name, where it is set, and how long it lasts. Authentication and session (authjs.session-token, or __Secure-authjs.session-token on kapsulehost.com): set on kpanel.kapsulehost.com only, when you sign in. Up to 30 days from your last activity. Form security / CSRF protection (authjs.csrf-token, or __Host-authjs.csrf-token on kapsulehost.com): set automatically on kpanel.kapsulehost.com whenever you visit, so that our forms can tell a genuine request on the Sites from one forged elsewhere. Session only. Post-sign-in redirect (authjs.callback-url, or __Secure-authjs.callback-url on kapsulehost.com): set automatically alongside the two cookies above, to remember which page to return you to once you have signed in. Session only. Two-factor authentication, trusted device (kap-device, or __Secure-kap-device on kapsulehost.com): set only when you choose "remember this device" after completing two-factor authentication. Up to 90 days; removing the device from your account security settings ends its trust immediately, whatever time is left on the cookie. Sign-in flow security (kap-google-state, kap-apple-state, kap-gh-state, kap-dc-state, kap-passkey-challenge, kap-passkey-auth-challenge, kap-signin-bind, kap-google-return): short-lived markers used only for the few minutes it takes to complete sign-in with Google, Apple, GitHub, Discord, or a passkey, so the sign-in cannot be forged and you are returned to the right page afterwards. Cleared automatically once sign-in completes; any left over expire within 10 minutes. Linking an extra sign-in method (kap-oauth-link-google, kap-oauth-link-apple, kap-oauth-link-github, kap-oauth-link-discord): set only when you are already signed in and choose, from your account settings, to add Google, Apple, GitHub or Discord as an additional way to sign in. Up to 10 minutes. Reseller and affiliate partner sign-in (kap-reseller-sid, kap-aff-sid): set on kpanel.kapsulehost.com only, when a reseller or affiliate partner signs in to their partner account. Up to 30 days, refreshed while the partner stays active; a short-lived version (1 hour) is used for a one-time email sign-in link before the full session begins. Active account selector (kc_account): where your sign-in has access to more than one account, remembers which one you are currently viewing. Session only. Signed-in language marker (kc_locale_sid): a technical companion to the language cookie in clause 3.2, used only to stop your language being reset while you are signed in. Not readable by page scripts. 12 months, or until you change your language. Browser integrity check (kap-bc): where this check is enabled, set on kpanel.kapsulehost.com after your browser passes an automated bot-detection check during sign-up or checkout, so you are not re-challenged partway through. Up to 2 hours. Cookie choice (kh_consent): set when you make a choice in our cookie banner or in Cookie settings (clause 3.7), on kapsulehost.com or KPanel, so that your choice is respected across the Sites. It stores only whether Campaign measurement, Advertising and Analytics are on or off, and when you chose. It is set cross-subdomain (.kapsulehost.com), page scripts can read it so that the banner and the Sites know your choice, and it lasts 12 months. ## 3.2 Functional cookies These remember choices you make. One of them, kc_locale, is also set on your first visit, to choose a language for you; apart from that, they are set only when you use a specific feature, not automatically on page load. Language, location and currency preference (NEXT_LOCALE, kc_locale, kc_country, kc_currency): set when you use the language, location or currency switcher in the site header. kc_locale is also set on your first visit to kapsulehost.com without a language in the address, when we choose a language for you; your browser records it for 365 days. Stored as cookies for 12 months. These are set cross-subdomain (.kapsulehost.com) so your preference carries across KPanel, webmail, our Help Centre, our status page and the marketing site. Light or dark appearance (kc_theme): set when you choose Light, Dark or System using the appearance control. It stores that one word and nothing else. It is set cross-subdomain (.kapsulehost.com), the same scope as above, so your choice carries across every one of those Sites. Stored for 12 months. Kora AI chat widget (browser localStorage: kora-sales-conv, kora-sales-locale): your conversation history and last-used locale are stored in your browser's local storage when you open the Kora chat widget. Cleared when you reset the conversation or clear your browser storage. Kora AI chat continuity (kc_kora_anon): set when you send your first message to the Kora chat widget. It is a random identifier for your browser and nothing else: it is not derived from your IP address, your device, or anything you tell Kora. It is set cross-subdomain (.kapsulehost.com) so that if you go on to open an account, the conversation you were already having comes with you instead of you having to explain it again. Kept for 30 days, after which the conversation is deleted; if you create an account the conversation becomes part of your account history, where you can see it and remove it like any other, and this cookie is retired. ## 3.3 Analytics cookies We use Plausible, a privacy-focused analytics tool, on our marketing pages (kapsulehost.com) to understand aggregate traffic patterns. It is self-hosted on our own infrastructure (analytics.kapsulehost.com): no third party receives your visit data. It sets no cookies and stores no persistent identifier that could recognise your device on a return visit; it counts a unique visit using a value derived from your IP address and browser that is rotated daily and never stored. It is not used on kpanel.kapsulehost.com. We also analyse server-side logs (such as nginx access logs) in aggregate to understand traffic patterns and improve performance; this does not involve setting any cookies on your device. Plausible does not load at all if your browser sends a Global Privacy Control (GPC) signal (see clause 6). Apart from Google Analytics, described in the next paragraph, we do not use any analytics tool that sets a cookie, builds a cross-site profile of you, or shares your visit data with a third party. Google Analytics is used only once we switch it on, and then only if you allow Analytics (clause 3.7): in the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, only after you choose Accept all or switch Analytics on in Cookie settings; elsewhere unless you choose Reject all, switch it off, or your browser sends a Global Privacy Control signal. It then loads on kapsulehost.com and on the KPanel sign-up, welcome, onboarding and checkout pages, after the page has shown, and sets two first-party cookies on .kapsulehost.com: _ga (a random identifier for your browser) and _ga_ followed by our property identifier (your session), each for 13 months. What it sends to Google is set out in clause 3 of our Privacy Policy. Switching Analytics off stops it and deletes both cookies. PostHog heatmaps, also under Analytics, run only on the public pages of kapsulehost.com, set no cookie and store nothing in your browser; clause 3 of our Privacy Policy describes what they record. ## 3.4 Marketing cookies Apart from what this clause describes, we do not run advertising or marketing cookies that track you across other websites or build an advertising profile of you. There are three exceptions. Two are first-party cookies that are never shared with an advertising network: the cookie described in clause 3.5, which credits a referring partner, and the cookie described in clause 3.6, which records which of our own posts, ads or links brought you to us. The third is advertising with Meta (Facebook and Instagram) and Google (clause 3.8): if it is switched on and you allow it, their tags load and set cookies, and Meta and Google use your visits and sign-ups to measure our ads, to show you our ads elsewhere (remarketing) and to build advertising audiences, including audiences of people similar to our customers. Nobody at KapsuleHost can see who is in an audience. ## 3.5 Affiliate attribution cookie If you arrive at the Sites through a link shared by one of our reseller or affiliate partners, we set one first-party cookie (kc_affiliate) so that, if you go on to become a customer, the partner who referred you is credited. It is not set on an ordinary visit with no referral link. It is set, and your arrival through the referral link is recorded for the partner, whether or not your browser sends a Global Privacy Control (GPC) signal (see clause 6). It does not track your browsing on any other website, does not build an advertising profile of you, and is never shared with or read by a third party: only we read it, to attribute a sale to the partner who sent you here. It lasts 30 days for most partners, or 60 days for a smaller number of senior partners; we may adjust this period from time to time. KPanel (kpanel.kapsulehost.com) does not set kc_affiliate. Once our referral hand-off is live, it is set on kapsulehost.com and KPanel reads it when you open an Account; until then, the referral travels in the sign-up link itself and is read once, when you open an Account, with no cookie involved. ## 3.6 Campaign attribution cookie If a link carrying our campaign tags brings you to kapsulehost.com, we set one first-party cookie (kh_ft) there, under the choice you make in our cookie banner (clause 3.7), so that, if you go on to open an Account on KPanel, we can count which of our own posts, ads and links brought you. KPanel itself never sets this cookie: it is set on kapsulehost.com, carried to KPanel because the cookie is shared across our subdomains, and read once, at the moment you open an Account. If a sign-up link brings you to KPanel directly, with no earlier visit to set the cookie, the same campaign tags travel as part of that link instead, and are read the same way, once, at sign-up. It holds only the four campaign tags on the link (utm_source, utm_medium, utm_campaign and utm_content), the path of the page you landed on without its query string, and the date and time of that visit. It holds no advertising click identifier, IP address, browser or device details, or referring page. It is not set on a visit without campaign tags, a later tagged visit never replaces it, and it is not set if your browser sends a Global Privacy Control (GPC) signal (see clause 6). It is set cross-subdomain (.kapsulehost.com), page scripts cannot read it, and it lasts 30 days. It does not track your browsing on any other website, does not build an advertising profile of you, and is never shared with or read by a third party: only we read it, to keep the first tagged visit and, when you open an Account, to store those details with your Account, and we report on them only as counts. Clause 3 of our Privacy Policy describes how we use and keep them. Campaign measurement is used only once we switch it on. Whether kh_ft is then set also depends on where you are and on your choice in our cookie banner (clause 3.7): in the European Union, the European Economic Area, the United Kingdom or Switzerland, or where we cannot tell your country, only after you choose Accept all or switch Campaign measurement on in Cookie settings; everywhere else by default, until you choose Reject all or switch it off. Choosing Reject all, or switching Campaign measurement off, deletes it, and a Global Privacy Control signal always overrides any choice made in the banner. ## 3.7 Your cookie choices Our cookie banner appears at the bottom of the page and does not block it. It offers three choices of equal weight: Accept all, Reject all and Cookie settings. Cookie settings lists Strictly necessary cookies (clause 3.1), which are always on; Campaign measurement (the kh_ft cookie, clause 3.6); Advertising (Meta and Google, clause 3.8); and Analytics (Google Analytics, clause 3.3). You can switch the last three on or off separately. Your choice is stored in the kh_consent cookie (clause 3.1) for 12 months and applies on kapsulehost.com and KPanel alike, because the cookie is shared across every kapsulehost.com subdomain: KPanel reads your choice, it never asks you again. You can change it at any time from the Cookie settings link at the bottom of every page of kapsulehost.com; KPanel has no separate Cookie settings link, because that shared cookie already reaches it. If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, or we cannot tell your country, the banner is shown until you make a choice, and Campaign measurement, Advertising and Analytics stay off until you choose Accept all or switch them on. Everywhere else the banner is shown once, as a notice: all three are on by default, closing the notice keeps them on, and Reject all and Cookie settings stay available from the link at the bottom of every page. We tell where you are from the country that our content delivery network reports for your connection, and we do not store it. If your browser sends a Global Privacy Control signal, the banner says so and all three stay off whatever you choose. The banner also uses your browser storage, only for itself. kh_consent_notice (local storage) records that you closed the notice, so that it is not shown again, and holds nothing else. kh_utm (session storage) holds the four campaign tags from the link that brought you to kapsulehost.com, only while Campaign measurement is allowed and only for that browser session, so that our sign-up and sign-in links can pass them on to KPanel (clause 3.6). Choosing Reject all, or switching Campaign measurement off, deletes kh_utm. ## 3.8 Advertising cookies (Meta and Google) Advertising is used only once we switch it on, and then only if you allow it (clause 3.7): in the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, only after you choose Accept all or switch Advertising on in Cookie settings; elsewhere unless you choose Reject all, switch it off in Cookie settings, or your browser sends a Global Privacy Control signal. When it is allowed, the Meta Pixel and the Google tag for Google Ads load on kapsulehost.com and on the KPanel sign-up, welcome, onboarding and checkout pages, after the page has shown, and these cookies are set on .kapsulehost.com: _fbp (Meta, identifies your browser to Meta, 90 days), _fbc (Meta, holds the Facebook click identifier, fbclid, when you arrive from a Meta ad, 90 days), _gcl_au (Google, 90 days), _gcl_aw (Google, holds the Google click identifier, gclid, when you arrive from a Google ad, 90 days) and _gcl_gb (Google, holds the Google click identifiers gbraid or wbraid when you arrive from a Google ad, 90 days). Where Advertising is allowed, _fbc, _gcl_aw and _gcl_gb are kept from the first page you land on; where it stays off until you choose, nothing is kept in your browser before you accept. Meta and Google also read and set cookies on their own domains, including Meta's fr cookie (.facebook.com, 90 days) if you are signed in to Facebook or Instagram in that browser, and Google's IDE (.doubleclick.net, about 13 months) and test_cookie (15 minutes). Meta's automatic advanced matching and form scanning are switched off. Meta and Google use these visits and conversions to measure our ads, to show you our ads (remarketing) and to build audiences for us; clause 3 of our Privacy Policy describes this, what they receive and what we keep. If you choose Reject all or switch Advertising off, the tags are no longer loaded, we delete _fbp, _fbc, _gcl_au, _gcl_aw and _gcl_gb from kapsulehost.com, and we send no further sign-up or purchase events to Meta or Google. Cookies that Meta or Google set on their own domains can be deleted in your browser settings. ## 4. Third-party services Some pages of the Sites load third-party services that may set their own cookies and process data through your browser. We do not control those cookies; the third-party's own privacy and cookie policies apply. Stripe, Inc: Payment processing and fraud prevention on checkout and billing pages only (stripe.com/privacy). Sentry: Error monitoring on all pages, only when an error occurs (sentry.io/privacy/). We do not permit third parties to use cookies on the Sites for their own marketing purposes. ## 5. Cookies set by content you load Where you embed content into a page hosted on our Services (for example, YouTube videos, Google Maps, third-party fonts, or social-media share buttons), that content may set its own cookies on your visitors' devices. You are responsible, as the operator of the website, for disclosing those cookies in your own cookie policy and (where required) obtaining consent. ## 6. Managing cookies We set strictly necessary cookies (clause 3.1), functional cookies and browser storage that remember your preferences and your Kora conversation (clause 3.2), one attribution cookie, kc_affiliate, when you arrive through a partner's referral link (clause 3.5), and one campaign attribution cookie, kh_ft, when a link carrying our campaign tags brings you to kapsulehost.com (clause 3.6). We set no advertising or cross-site tracking cookies of our own, and Plausible, our own analytics (clause 3.3), sets no cookies; if you allow them, Google Analytics (clause 3.3) and the Meta and Google advertising tags (clause 3.8) set their own. A Global Privacy Control signal stops our analytics loading and stops the campaign attribution cookie being set; it does not stop the affiliate attribution cookie being set (see below). You can manage cookies in the following ways. Your browser settings: all major browsers allow you to block, delete, or limit cookies. Check your browser's help documentation. Note that blocking strictly necessary cookies will break the Sites. Kora widget storage: to clear Kora conversation history, use the reset button in the widget or clear your browser's local storage for kapsulehost.com. Global Privacy Control (GPC): where your browser sends a Global Privacy Control signal, we honour it as a request to minimise any data collection beyond what is strictly necessary. In practice, our analytics (clause 3.3) does not load; the affiliate attribution cookie (clause 3.5) is still set if you arrive through a partner's referral link. The campaign attribution cookie (clause 3.6) is not set. Do Not Track (DNT): there is no widely agreed standard for DNT, and we do not respond to DNT signals. Our own analytics tool is Plausible, on our marketing pages (clause 3.3): it is self-hosted, sets no cookies, and reports visits only in aggregate. Google Analytics and the advertising tags (clauses 3.3 and 3.8) follow your choice in our cookie banner and a Global Privacy Control signal, not a DNT signal. Plausible does not read a DNT signal, so it loads whether or not your browser sends one; a Global Privacy Control signal does stop it loading (see above). Our cookie banner (clause 3.7): choose Accept all, Reject all or Cookie settings when it appears, or use the Cookie settings link at the bottom of every page at any time. Reject all, or switching a category off, stops its tags and deletes its cookies on kapsulehost.com: the campaign attribution cookie (clause 3.6), the Google Analytics cookies (clause 3.3) or the Meta and Google advertising cookies (clause 3.8). A Global Privacy Control signal does the same whatever you choose. Strictly necessary cookies stay on because the Sites need them to work. ## 7. Children The Sites are not directed at children under 18. We do not knowingly use cookies to collect personal information from children under 18. ## 8. Changes to this Cookie Policy We may update this Cookie Policy from time to time to reflect changes in our use of cookies, our service providers, or the law. Material changes (such as adding analytics cookies) will be notified by email and posted here at least 30 days before taking effect. Adding or changing advertising cookies is not notified by email in advance: this Policy is updated before any such cookie is set. The "Last updated" date at the top of this Policy shows the most recent change. ## 9. Contact Kapsule Group Limited, New Zealand. Email: privacy@kapsulehost.com --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/cookies, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Service Level Agreement Canonical page: https://kapsulehost.com/en-us/legal/sla Last updated: 28 September 2026 Version 5, effective September 28, 2026 ## About this SLA This Service Level Agreement ("SLA") forms part of the Terms of Service between Kapsule Group Limited ("KapsuleHost", "we", "us", "our") and you ("Customer", "you"). It sets out the availability, performance, and support standards we commit to in providing the Services, and the service credits available where we do not meet them. Capitalised terms used but not defined in this SLA have the meanings given in the Terms of Service. ## 1. Scope 1.1 This SLA applies to the production Services on each paid Plan. It does not apply to: (a) GPU servers, dedicated servers, or storage servers (see clause 4.5 of the Terms of Service); (b) free Trials, including the Start free Trial (although we use commercially reasonable efforts to provide availability during Trials); (c) the marketing site at kapsulehost.com, our blog, our status page, or any other non-production website; (d) APIs, integrations, and features explicitly labelled "not covered by the SLA"; or (e) any aspect of the Services where the unavailability is caused by factors set out in clause 4. ## 2. Availability targets and how we measure them 2.1 "Uptime" is the percentage of total minutes in a calendar month during which the core hosting Service for the relevant Plan is available to receive requests from the public internet, calculated by our monitoring systems. "Downtime" is defined in clause 2.5, and clause 2.4 sets out which monitoring results we count as available and which we count as Downtime. 2.2 Monthly Uptime target: 99.9% for every paid Plan. 2.3 99.9% Uptime in a month with 30 days means up to approximately 43.2 minutes of allowed Downtime. 2.4 What counts as available, and what degraded means. Our monitoring records each check against a Service as operational, degraded, partial outage, major outage, or under maintenance, and records a check it could not complete at all as ungraded. A Service that is still reachable and still serving requests, but is slower than normal or offering reduced functionality, is recorded as degraded. Operational, degraded, and under maintenance all count as available for the purposes of this SLA. Only partial outage and major outage count as Downtime. Because degraded time is not Downtime, degraded performance does not on its own give rise to a service credit under clause 5. Ungraded checks are excluded from the calculation in both directions under clause 4.1(k): time we could not measure neither raises nor lowers your Uptime. 2.5 "Downtime" means any period, or part of a period, that our monitoring records under clause 2.4 as partial outage or major outage for the relevant Service. It does not include any period recorded as operational, degraded, or under maintenance, all of which count as available and not as Downtime under clause 2.4. It also does not include any period excluded from this SLA under clause 4, including a period where our monitoring could not determine a Service's status (clause 4.1(k)) or a spell of Downtime under two consecutive minutes (clause 4.1(l)). Uptime and Downtime are complementary within the results our monitoring could grade: a result that counts as available under clause 2.4 is never also Downtime, and a result that counts as Downtime is never also available. 2.6 The Monthly Uptime target in clause 2.2, and the service credits in clause 5, apply only to Downtime occurring on or after 1 October 2026; no period before that date is measured, counted, or eligible for a service credit under this SLA. ## 3. Email and domain Services 3.1 Email availability. For paid email hosting included with a Plan, we target the same Uptime as the underlying Plan in clause 2.2. Service credits for email-specific Downtime are calculated as a proportion of the email-attributable portion of your monthly Fee. 3.2 Domain DNS resolution. Where we operate authoritative DNS for your domain, we target 99.99% monthly DNS resolution. DNS Downtime is measured separately from hosting Downtime and is subject to a separate service credit calculation if you request one. 3.3 Domain registration and management. The act of registering, renewing, transferring, or modifying a domain is dependent on the Registry and is not covered by this SLA. ## 4. Exclusions 4.1 The following do not count as Downtime and are excluded from this SLA: (a) scheduled maintenance announced at least 48 hours in advance; (b) emergency maintenance required to address a security, stability, or legal issue, where we use commercially reasonable efforts to give notice; (c) Downtime caused by your code, configuration, content, or third-party software you have installed; (d) Downtime caused by you exceeding the resource limits of your Plan, fair use, or the AUP; (e) Downtime caused by your domain registrar, DNS configured outside our authoritative DNS, content delivery network configured outside our infrastructure, or any other component outside our control; (f) Downtime affecting GPU servers, dedicated servers, or storage servers, or any other feature explicitly marked as not covered by the SLA; (g) Downtime caused by a Force Majeure Event; (h) Downtime that occurs while your Account is suspended for breach of the Terms of Service, AUP, or for non-payment; (i) intermittent unreachability caused by your visitor's local network, ISP, or device; (j) Downtime caused by upstream provider outages where we use commercially reasonable efforts to mitigate; (k) periods during which our monitoring was itself impaired and Downtime cannot be substantiated; (l) Downtime of less than two consecutive minutes (excluded by way of de minimis); or (m) Downtime claimed without sufficient evidence, where our own monitoring records show no corresponding incident. ## 5. Service credits 5.1 If Uptime in a calendar month falls below the target in clause 2.2, you are entitled to the following service credit on your next invoice for the affected Service: below the target but at or above 99.0%, 10% of the monthly Fee; below 99.0% but at or above 95.0%, 25% of the monthly Fee; below 95.0% but at or above 90.0%, 50% of the monthly Fee; below 90.0%, 100% of the monthly Fee. 5.2 Maximum credit. Total service credits in any calendar month are capped at one hundred percent (100%) of the monthly Fee for the affected Service. 5.3 Sole remedy. Service credits are your sole and exclusive remedy for failure to meet the SLA, except where another remedy is required by law (including under the Consumer Guarantees Act 1993 where you are a consumer). 5.4 Application of credits. Service credits are applied to your next invoice for the affected Service. They are not paid as cash, are not transferable between Accounts or Services, and do not roll over more than three consecutive months. Where your Account is terminated before the credit is applied, the credit is forfeited unless cash payment is required by law. 5.5 Migration guarantee. When you move a site to KapsuleHost with our migration tools or our team, your existing site keeps serving until you press Switch. If a migration causes your site to be unavailable (measured by our monitoring of the site's public address), that time counts as Downtime under this SLA, and in addition we credit one full month of the hosting plan the site moved to. This does not apply to DNS changes you make yourself outside KapsuleHost, or to your previous host going offline before or during the migration. Claim within 30 days through a KPanel ticket. ## 6. How to claim 6.1 To claim a service credit, you must: (a) open a billing ticket in KPanel within thirty (30) days of the end of the calendar month in which the Downtime occurred; (b) include the dates, times (in UTC or your local time), and approximate duration of the Downtime you observed; and (c) provide reasonable evidence of the Downtime where you can (for example, third-party monitoring logs, error messages, or URLs affected). 6.2 We will review your claim against our internal monitoring records and respond within ten (10) business days. If approved, the credit will be applied to your next invoice. 6.3 We may decline a claim where: (a) it is submitted after the 30-day window; (b) the Downtime is excluded under clause 4; (c) our records show no corresponding incident; (d) the Account is in breach of the Terms of Service or AUP at the time of the Downtime; or (e) the Account has Fees outstanding for more than fourteen days. ## 7. Support response targets 7.1 We provide customer support through KPanel tickets and at support@kapsulehost.com. Response targets are based on issue severity and your Plan. S1 (Critical), Service is wholly unavailable for production use: Cloud Power 1 hour, 24x7. All other Plans: 4 hours, business hours. S2 (High), Material loss of functionality for production use: Cloud Power 4 hours, 24x7. All other Plans: 1 business day. S3 (Normal), General issue or question affecting use: Cloud Power 1 business day. All other Plans: 2 business days. S4 (Low), Feature request, "how do I" question, or cosmetic issue: best effort within 5 business days. First reply from a person. On every Plan, the first-response target for any Ticket that needs a person is 4 business hours, or the target above for its severity and Plan where that is sooner. For this target the first response is the first reply from a person; clause 7.3 applies. This target is subject to clause 7.4 like every other target in this clause. Concierge plans. While a Concierge Start, Concierge Pro or Concierge Scale subscription is active on your Account, the first-response target for any Ticket you raise is 4 business hours, or the target above for its severity where that is sooner. For this target the first response is the first reply from a person; clause 7.3 applies. This target is subject to clause 7.4 like every other target in this clause. 7.2 "Business hours" means 09:00 to 18:00 New Zealand Time, Monday to Friday, excluding New Zealand public holidays. 7.3 Kora (our AI assistant) is available 24x7 in KPanel and at support@kapsulehost.com to handle initial triage and to answer routine questions. Kora responses are not "first response" for the purpose of the targets above unless they resolve your issue. 7.4 Response targets are aspirational and do not give rise to service credits, except where required by law. ## 8. Backup and restore service standards 8.1 We perform daily encrypted off-site backups of customer site data and email data as set out in clause 11 of the Terms of Service and the Security Statement. 8.2 Restore requests will be triaged in accordance with the support response targets in clause 7. Time-to-restore depends on the size of the data, the complexity of the request, and the load on the backup system at the time. We do not commit to a fixed time-to-restore. 8.3 We may charge a reasonable fee for restore requests caused by your error (for example, accidental file deletion outside the 30-day retention window). Restore requests required because of our error are at no additional charge. ## 9. Status page and incident communication 9.1 Our public status page is at status.kapsulehost.com. It shows current incidents, historic uptime, and scheduled maintenance. Where it shows a Service as degraded, that Service is reachable and serving but slower or reduced, and under clause 2.4 that time counts as available rather than as Downtime. 9.2 You can subscribe to status page alerts to receive notification of incidents, maintenance, and resolution by email or RSS. 9.3 We will publish an incident on the status page as soon as practicable after it is confirmed by our on-call team. Updates are posted at reasonable intervals (typically every 30 to 60 minutes for active incidents) until resolution. 9.4 For major incidents (those resulting in Downtime materially affecting many customers), we will publish a post-incident review within ten business days of resolution, including root-cause analysis and remediation steps. ## 10. Scheduled maintenance windows 10.1 Routine maintenance is performed during low-traffic windows, typically Sunday 02:00 to 06:00 UTC. Maintenance is announced on the status page in advance and, where reasonably practicable, by email. 10.2 We may perform emergency maintenance with little or no notice where required to address a security, stability, or legal issue. Such maintenance is excluded from Downtime under clause 4. ## 11. Changes 11.1 We may update this SLA from time to time. Material changes will be notified by email or KPanel notice at least thirty days before they take effect. 11.2 Material changes that reduce the availability targets do not apply to active annual prepaid subscriptions until the next renewal. ## 12. Contact Kapsule Group Limited, New Zealand. Support: support@kapsulehost.com Billing and SLA claims: billing@kapsulehost.com Status page: status.kapsulehost.com --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/sla, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Data Processing Agreement KapsuleHost Data Processing Agreement, roles, security measures, sub-processors, breach notification, and Data Subject rights under the NZ Privacy Act 2020 and EU GDPR. Canonical page: https://kapsulehost.com/en-us/legal/dpa Last updated: 30 September 2026 Version 8, effective September 30, 2026 ## About this DPA This Data Processing Agreement ("DPA") applies where you ("Customer", "Controller") use the KapsuleHost Services to process personal information about other individuals ("Data Subjects"). It forms part of the Terms of Service between you and Kapsule Group Limited ("KapsuleHost", "we", "us", "Processor"). This DPA reflects the requirements of the New Zealand Privacy Act 2020. Where you are subject to other applicable privacy laws (for example, the EU General Data Protection Regulation, UK GDPR, or Australian Privacy Act 1988), the relevant provisions of this DPA, read together with our Privacy Policy and Sub-processors List, are intended to provide protection comparable to those laws. Where additional contractual measures are required to support your compliance with a foreign law, we will consider these on request. If you are using the Services solely to process your own personal information (and not personal information about other individuals), this DPA does not apply; the Privacy Policy alone applies. ## 1. Definitions In this DPA: "Applicable Privacy Laws" means the Privacy Act 2020 and any other privacy or data protection law applicable to the Customer's processing of personal information using the Services. "Controller" means the natural or legal person who determines the purposes and means of processing personal information. "Customer Personal Information" means personal information processed by us on your behalf using the Services in respect of Data Subjects. "Data Subject" means an identified or identifiable natural person to whom Customer Personal Information relates. "Notifiable Privacy Breach" has the meaning given in section 112 of the Privacy Act 2020 (a privacy breach that has caused, or is likely to cause, serious harm). "Personal Information" has the meaning given in the Privacy Act 2020. "Processor" means a person who processes personal information on behalf of the Controller. "Processing" means any operation or set of operations performed on personal information, whether or not by automated means. "Sub-processor" means a third party we engage to process Customer Personal Information on our behalf. "Standard Contractual Clauses" means the standard data protection clauses adopted by a recognised data protection authority (for example, the European Commission's EU Standard Contractual Clauses) for transfers of personal data from a jurisdiction with restrictive cross-border data transfer rules. Other capitalised terms have the meanings given in the Terms of Service. ## 2. Roles, scope, and instructions 2.1 Roles. In relation to Customer Personal Information, you are the Controller and we are the Processor. You are responsible for the lawfulness of your collection and processing of Customer Personal Information, including for providing all required privacy notices, obtaining all required consents, and complying with all Applicable Privacy Laws in your dealings with Data Subjects. 2.2 Documented instructions. We will process Customer Personal Information only: (a) as needed to provide the Services in accordance with the Terms of Service; (b) in accordance with your reasonable, documented instructions (the Terms of Service, the configuration choices you make in KPanel, and any further written instructions you give us are deemed to be your documented instructions); and (c) as required by law applicable to us, in which case we will inform you of the legal requirement before processing, unless prohibited by that law on important grounds of public interest. 2.3 Inconsistent instructions. We will inform you if, in our reasonable opinion, an instruction from you infringes an Applicable Privacy Law. We may decline to process Customer Personal Information where doing so would put us in breach of an Applicable Privacy Law. ## 3. Confidentiality 3.1 We will ensure that any person authorised to process Customer Personal Information on our behalf is bound by confidentiality obligations, whether through contract or law, and is informed of the confidential nature of the information. 3.2 Access to Customer Personal Information is limited on a need-to-know basis and is protected by access controls, mandatory two-factor authentication, and audit logging. ## 4. Security 4.1 We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Information against unauthorised or unlawful processing, accidental loss, destruction, or damage. Current measures are summarised in Annex B to this DPA and at kapsulehost.com/legal/security. 4.2 We will regularly review and update our security measures to account for the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk to the rights and freedoms of Data Subjects. 4.3 We will not materially reduce overall protection without notice to you. ## 5. Sub-processors 5.1 Authorisation. You authorise us to engage the Sub-processors listed at kapsulehost.com/legal/sub-processors to process Customer Personal Information. 5.2 Sub-processor terms. We will enter into a written contract with each Sub-processor that imposes data protection obligations no less protective than those in this DPA, including obligations of confidentiality, security, and limited processing. 5.3 Notification of Sub-processor changes. We will notify you of any new Sub-processor, and of any material change to the processing an existing Sub-processor performs or the location where it performs it, at least thirty (30) days before the change takes effect. Notification will be by email to your account address and by posting to the Sub-processors page, and you do not need to request it. 5.4 Objection. You may object on reasonable grounds (for example, a documented concern about the proposed Sub-processor's security, compliance, or jurisdiction) by emailing privacy@kapsulehost.com within the 30-day window. If we cannot reasonably accommodate your objection (for example, by switching Sub-processors or modifying the configuration), you may terminate the affected Service and receive a pro rata refund of any prepaid Fees for the unused portion of the relevant billing cycle. 5.5 Liability for Sub-processors. We remain liable to you for the acts and omissions of our Sub-processors in respect of Customer Personal Information as if they were our own. ## 6. Data Subject rights 6.1 We will, taking into account the nature of the processing, provide reasonable assistance to help you respond to requests from Data Subjects to exercise their rights under Applicable Privacy Laws, including rights of access, correction, deletion, restriction, and portability. 6.2 If we receive a request from a Data Subject that relates to your use of the Services, we will: (a) refer the Data Subject to you (the Controller); and (b) unless legally prohibited, notify you of the request without undue delay. 6.3 Assistance is provided through the access, export, and deletion features of KPanel where these are sufficient, and through manual support where the technical features cannot meet the request. 6.4 We may charge a reasonable fee for manual assistance that is materially in excess of routine support, where the request is manifestly unfounded or excessive. ## 7. Personal information breaches 7.1 Notification. We will notify you of any confirmed Notifiable Privacy Breach affecting Customer Personal Information without undue delay, and in any event within seventy-two (72) hours of becoming aware of it. 7.2 Content of notification. The notification will include, to the extent known and reasonably available at the time: (a) the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and records affected; (b) the likely consequences of the breach; (c) the measures we have taken or propose to take to address the breach and mitigate its possible adverse effects; and (d) the contact point for further information. 7.3 Subsequent updates. Where some of the information is not available at the time of the initial notification, we will provide it in further updates as soon as practicable. 7.4 Cooperation. We will cooperate reasonably with you in any required investigation, notification to authorities, notification to affected Data Subjects, and remediation. 7.5 Customer's responsibility. You remain responsible for assessing whether a breach is a Notifiable Privacy Breach under your applicable law and for making the necessary notifications to the Office of the Privacy Commissioner, affected Data Subjects, or other regulators. We will provide the information you reasonably need to do so. ## 8. Audits 8.1 Information. We will make available to you the information necessary to demonstrate compliance with this DPA, including the Security Statement at kapsulehost.com/legal/security, the Sub-processors list, and any third-party audit reports or certifications we hold (if any). 8.2 On-site audit. Where the information in clause 8.1 is not sufficient to demonstrate compliance with respect to a particular issue you have raised in writing, you may conduct an audit of our compliance with this DPA on the following conditions: (a) audits are conducted at your cost (including our reasonable costs of assisting); (b) you give us at least thirty (30) days' written notice; (c) audits take place during our normal business hours; (d) audits are conducted no more than once in any twelve (12) month period, except after a confirmed Notifiable Privacy Breach affecting you, in which case an additional audit may be conducted on reasonable notice; (e) the audit does not unreasonably interfere with our operations or compromise the confidentiality of other customers' information; (f) the auditor must be qualified, independent of our competitors, and bound by confidentiality obligations on terms acceptable to us; (g) we may, at our option, satisfy our audit obligations by providing copies of third-party audit reports or certifications (where available) or by responding to a security questionnaire. 8.3 You will provide us with a copy of any audit report and any findings, and we will use reasonable efforts to address material findings within an agreed period. ## 9. International transfers 9.1 You acknowledge that some of our Sub-processors are located outside New Zealand. The current locations are set out at kapsulehost.com/legal/sub-processors. 9.2 Where Customer Personal Information is transferred outside New Zealand, we will ensure that comparable safeguards apply, including: (a) ensuring the Sub-processor is subject to a privacy law that, in our view, provides comparable protections to the Privacy Act 2020; or (b) entering into contractual safeguards with the Sub-processor that require comparable protections (for example, by reference to Standard Contractual Clauses where appropriate); or (c) obtaining your express authorisation for the transfer. 9.3 By entering this DPA, you authorise the transfers described in clause 8 of the Privacy Policy and clause 5 of this DPA, on the basis of the safeguards in clause 9.2. ## 10. Return and deletion of Customer Personal Information 10.1 During the term of the Services, you can export Customer Personal Information via KPanel using our standard export tools (CSV, JSON, archive download, or database dump, depending on the data type). 10.2 On termination of the Services and at your option, we will: (a) make Customer Personal Information available for export for thirty (30) days after termination (the "Grace Period"); and (b) thereafter, permanently delete Customer Personal Information from live systems. 10.3 Backup copies become unrecoverable within thirty-one (31) days of deletion from live systems. 10.4 We may retain Customer Personal Information after termination where required by law (for example, billing and tax records under the Tax Administration Act 1994, or to defend a legal claim). Any such retention will be limited to the minimum necessary, and the information will remain subject to the confidentiality and security obligations in this DPA. ## 11. Liability 11.1 The liability provisions in the Terms of Service (including the limitation of liability in clause 16) apply to this DPA. 11.2 Without prejudice to clause 11.1, nothing in this DPA limits a party's liability for fraud, fraudulent misrepresentation, wilful misconduct, or any liability that cannot lawfully be limited under Applicable Privacy Laws. 11.3 Where we incur a regulatory penalty as a result of, or in connection with, your failure to comply with your obligations under this DPA or Applicable Privacy Laws, the amount of that penalty will be treated as a loss recoverable from you, subject to the limits in the Terms of Service. 11.4 The service credits under the SLA are not credits under this DPA. ## 12. Term and amendments 12.1 This DPA takes effect when you first use the Services (or 15 May 2026, whichever is later) and continues until the Services are terminated and our deletion obligations under clause 10 are complete. 12.2 We may update this DPA from time to time to reflect changes in law or in our operations. Material changes will be notified at least thirty (30) days in advance. ## 13. Order of precedence 13.1 If there is a conflict between this DPA and the Terms of Service or Privacy Policy in respect of the processing of Customer Personal Information, this DPA prevails. 13.2 If there is a conflict between this DPA and an applicable mandatory provision of an Applicable Privacy Law, the mandatory provision prevails to the extent of the conflict. ## 14. Contact Privacy Officer Kapsule Group Limited, New Zealand. Email: privacy@kapsulehost.com ## Annex A: Description of processing A.1 Subject matter. Provision of cloud hosting, domain registration, email hosting, and related services as described in the Terms of Service. A.2 Duration. For the term of the Services, plus the Grace Period and any retention required by law as set out in clause 10. A.3 Nature and purpose. Storage, transmission, backup, security, replication, indexing, format conversion (for technical compatibility), abuse prevention, billing, and other processing necessary to operate the Services. A.4 Categories of Customer Personal Information. As determined and uploaded by you. May include: names, contact details (email, phone, address), account credentials, identity verification information, payment information, transactional data, IP addresses, device identifiers, photos and other images, content of websites and applications, content of email, message metadata, customer relationship management records, support communications, and any other personal information you choose to process via the Services. A.5 Categories of Data Subjects. As determined by you. May include: your employees, contractors, agents, customers, prospective customers, suppliers, members, end-users, donors, and other individuals whose personal information you choose to process via the Services. A.6 Special categories. You must not upload to the Services any special-category or sensitive personal information (such as health information, biometric information, criminal records, religious beliefs, sexual orientation, or trade union membership) without our prior written agreement about appropriate additional safeguards. If you upload such information without our agreement, you are responsible for the lawfulness of doing so and indemnify us in respect of any related claims. A.7 Frequency and duration of processing. Continuous, for the duration of the Services. ## Annex B: Technical and organisational measures We implement the following technical and organisational measures, which we may update from time to time to maintain or improve overall protection: B.1 Information security policies and governance. Documented information security and privacy policies, reviewed at least annually. Designated Privacy Officer responsible for compliance. Personnel privacy and security training on induction and annually thereafter. Background checks on personnel with access to production systems, where lawful. B.2 Access controls. Strict role-based access controls based on least-privilege principles. Mandatory two-factor authentication for all personnel with access to production systems. Periodic access reviews and prompt revocation on role change or departure. Separation of production and non-production environments. Privileged access logging. B.3 Encryption and data protection. TLS encryption (at least TLS 1.2) for all data in transit. Encryption at rest for off-site backups and for sensitive data stores. Encrypted backups: customer sites and their databases stored in Europe, on the hosting server in Germany and off-site in Finland; managed servers, our own account and billing databases, online shop databases, our object storage service and email stored off-site in Finland; and whole-server backups of our control panel, which also runs online shops, kept with it in the Asia-Pacific region. Secure key management with off-line copies of master recovery keys. B.4 Network and system security. Kernel-level firewall rules isolating each customer site from the shared database and from every other site's application-server ports, keyed to the process's own system account rather than application logic, verified from within a live site's own execution context (the platform's shared caching service is authentication-scoped only; extending the same network-layer blocking to it is planned). Web application firewall (ModSecurity with the OWASP Core Rule Set) on our own infrastructure, covering every production surface. For Services delivered through our CDN edge network, the CDN provider additionally applies always-on network-layer DDoS mitigation across its anycast network; the CDN is included with some Plans and available as an add-on for others, and we do not offer a service level in respect of a third-party network. Regular security patching of operating systems, runtimes, and applications. Vulnerability scanning of internet-facing infrastructure. Periodic penetration testing. B.5 Logging, monitoring, and incident response. Authentication attempts, account and configuration changes, and administrative actions are logged to a centralised, append-only audit trail. Infrastructure and system-level logs (web server, firewall, and operating system) are retained locally on each production server; centralising these into the same audit trail is a planned enhancement. 24x7 monitoring of platform health and security signals. Documented incident response plan with defined severities and escalation paths. Notifiable Privacy Breach notification procedure aligned with the Privacy Act 2020 and clause 7 of this DPA. B.6 Backup, business continuity, and disaster recovery. Daily encrypted off-site backups of customer site data and email data. Off-site backup retention of at least thirty (30) days, with longer retention on higher Plans. Documented disaster-recovery procedures and runbooks. Regular restore testing. B.7 Personnel and sub-processors. Confidentiality undertakings for all personnel. Written contracts with all Sub-processors imposing protections no less protective than this DPA. Annual review of Sub-processors for continued suitability. B.8 Physical security. Production servers are operated in third-party data centres. We do not own or operate a data centre, so physical security, environmental controls, power redundancy and fire suppression are the facility operator's responsibility, and our agreements with infrastructure sub-processors require protections no less protective than those in this DPA. B.9 Application security. Secure software development lifecycle, including code review, dependency scanning, and pre-release testing. Application secrets stored in restricted-permission files, never committed to source code; infrastructure and backup secrets additionally protected with SOPS age encryption. Direct changes to the production branch are refused by our source control host itself and must pass through an automated verification chain before reaching production; a documented, logged emergency override exists for the rare case where the pipeline itself is blocked. B.10 Data segregation and deletion. Logical segregation of customer data. Documented data deletion procedures aligned with clause 10 of this DPA. Documented procedures for handling Data Subject access, correction, and deletion requests. A more detailed version of these measures is published at kapsulehost.com/legal/security and is updated from time to time. --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/dpa, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Security Statement Canonical page: https://kapsulehost.com/en-us/legal/security Last updated: 3 October 2026 ## About this statement This Security Statement describes the technical and organisational measures Kapsule Group Limited ("KapsuleHost") implements to protect the data hosted on our platform. It is referenced by the Data Processing Agreement and is updated from time to time to reflect improvements to our security posture. Our core principle is defence in depth: we layer multiple independent controls so that no single failure exposes customer data. ## 1. Information security governance We maintain documented information security and privacy policies, reviewed at least annually and updated when material changes to the platform or threat landscape require it. A designated Privacy Officer holds responsibility for data protection compliance. Security responsibilities are assigned to a named individual, our Security Owner, who also holds the Privacy Officer role; as the infrastructure team grows, each new member is given named security responsibilities when they join. All personnel receive privacy and security training on induction and annually thereafter. Personnel with access to production systems are subject to background checks where permitted by law. Security incidents and near-misses are recorded, reviewed, and used to improve controls on an ongoing basis. ## 2. Access controls Access to production systems and customer data is governed by strict role-based access controls built on least-privilege principles: personnel are granted only the access they need to perform their specific role. Mandatory two-factor authentication (2FA) is enforced for all personnel with access to production infrastructure, the hosting control panel, source code, and cloud provider consoles. Access rights are reviewed periodically and revoked promptly on role change or departure. Access events and privilege escalations are logged. Production and non-production environments are strictly separated. Customer environments are logically isolated from each other within the hosting platform. All administrative access to production servers is authenticated via SSH key pairs; password-based SSH authentication is disabled. ## 3. Encryption and data protection All data in transit between customers and our platform is encrypted using TLS 1.2 or higher. TLS certificates are issued automatically and renewed before expiry. Every backup we make is encrypted on our own server before it leaves it. Site files, site databases, managed servers and our own servers are backed up with restic, using AES-256. Our account and billing databases are encrypted with GPG, using 4096-bit RSA keys, or with age, using X25519 and ChaCha20-Poly1305. The site backups you make in KPanel are encrypted with age. Email backups are encrypted object by object with AES-256-GCM. The keys are held apart from the backups they protect, on our own servers with a second escrowed or offline copy, and never in the storage that holds the backups. Losing a key would make its backups unrecoverable, which is why every key has that second copy. Encrypted off-site backups are held in object storage in a different location from the servers they protect: customer sites and their databases, managed servers, our own platform databases, online shop databases, our object storage service and email, all in Finland. Customer sites also keep a copy on the hosting server in Germany, and whole-server backups of our control panel, which also runs online shops, are kept with it in the Asia-Pacific region. Application secrets, API keys, and credentials are stored in restricted-permission files on the servers that use them, accessible only to the service account that requires them, and are never embedded in source code or committed to version control. Infrastructure and backup secrets are additionally protected using SOPS with age encryption. ## 4. Network and system security Every production surface, including our marketing website, the customer control panel, our API, and customer-hosted sites, is protected by a web application firewall (ModSecurity with the OWASP Core Rule Set) running on our own infrastructure. Our marketing website is additionally protected by a web application firewall at our CDN edge, running in blocking mode. Edge-layer protection covers customer-hosted sites served through our CDN. It does not extend to the customer control panel or our API. Customer sites are isolated from each other and from shared platform services at the network layer, not merely by separate filesystem accounts and processes. Kernel-level firewall rules (nftables), keyed to each process's own system account rather than to any application logic, block every non-administrative process, including every customer site's own application code, from reaching the shared database port or any other site's own application-server port. This has been verified by driving real connection attempts from inside a live site's own execution context, in both directions: blocked for an ordinary site process, permitted for system administration. The same mechanism also blocks non-administrative access to internal cloud-infrastructure service endpoints that a site process should never be able to reach. It does not yet extend to every shared service: the platform's shared caching service is protected by per-site credentials scoped to that site's own data, but is not yet additionally blocked at the network layer the way the database and application-server ports are; extending the same firewall protection to it is a planned enhancement to our security programme. Operating systems, platform software, and application dependencies are patched on a regular cadence. Security updates are applied automatically via unattended-upgrades, usually within a day of release. For critical security patches, including any that require manual intervention such as a reboot or that are not yet available through automated updates, our committed ceiling is 7 days from release. Internet-facing infrastructure is scanned for known vulnerabilities on a regular basis. Firewall rules restrict inbound access to the minimum necessary ports and services. Unnecessary services are disabled by default. Periodic penetration testing is conducted by independent qualified testers. Material findings are remediated and retested. ## 5. Logging, monitoring, and incident response Authentication attempts, account and configuration changes, and actions taken by our own personnel on customer accounts are logged to a centralised, append-only database audit trail, retained for a minimum of 90 days. Infrastructure and system-level logs (web server, firewall, and operating system logs) are retained locally on each production server, accessible only to authorised personnel, and are additionally shipped hourly to an independent, write-once off-site store with a 90-day retention lock: once written, a log archive cannot be deleted or overwritten by anyone, including us, for that period, so a compromised server cannot erase evidence of what happened on it. Platform health and security signals are monitored 24x7. Alerts are routed to on-call personnel for immediate investigation. We maintain a documented incident response plan with defined severity levels, escalation paths, and communication procedures. The plan is reviewed and tested at least annually. In the event of a confirmed Notifiable Privacy Breach affecting Customer Personal Information, we will notify affected customers within 72 hours of becoming aware, as required by the Privacy Act 2020 and the Data Processing Agreement. We use real-time error tracking on our control panel and our website, with default personal data switched off in every error report. We do not run performance tracing in visitors' or customers' browsers. ## 6. Backup and disaster recovery Customer site files and databases, and email data, are backed up daily to off-site object storage in Finland. Every backup is encrypted before upload, as described in section 3. Backup retention is a minimum of 30 days on all paid plans. Higher plans retain backups for longer: 90 days, 1 year, or 7 years, depending on the tier purchased. See the Service Level Agreement for plan-specific retention details. Restore procedures are documented in our internal runbooks and tested periodically. The platform team conducts restore drills to validate backup integrity. The KapsuleHost platform codebase (including configuration and provisioning scripts) is backed up daily to private source-code repositories held separately from our servers, providing an independent recovery path for the platform itself. Disaster recovery procedures for each infrastructure component are documented with target recovery times specific to that component: up to 8 hours for the hosting server, scaled to the volume of customer data being restored; 2 to 4 hours for the mail platform; and 4 hours for the customer portal. ## 7. Personnel and sub-processors All personnel with access to customer data are bound by confidentiality obligations, either by contract or by law. We maintain written data processing agreements with all sub-processors. These agreements require sub-processors to implement protections no less protective than those in our Data Processing Agreement, including confidentiality, security, and limited-purpose processing obligations. Our sub-processor list is reviewed at least annually for continued suitability. Sub-processors are assessed against our minimum security requirements before engagement. The current list of sub-processors is published at kapsulehost.com/legal/sub-processors. ## 8. Physical security Production servers are operated in third-party data centres. We do not own or operate a data centre, so physical security, environmental controls, power redundancy and fire suppression are the facility operator's responsibility, and our agreements with infrastructure sub-processors require protections no less protective than those in our Data Processing Agreement. We do not publish the country of individual production servers: our capacity moves as we add regions, and a location published once is wrong the day it changes without anybody editing it. The sub-processors we engage are listed at kapsulehost.com/legal/sub-processors. Physical access to server hardware is restricted to authorised data centre personnel. KapsuleHost personnel do not have routine physical access to production hardware; all administrative access is performed remotely over encrypted channels. Decommissioned storage media is securely wiped or destroyed in accordance with the data centre operator's procedures before reuse or disposal. ## 9. Application security 9.1 Automated release gate. Every production code change passes through an automated verification chain (over 190 checks spanning correctness, security, money handling, and translation completeness at the time of writing, a number that grows as the platform does) before it can reach production. Direct changes to the production branch are refused by our source control host itself; the only credential permitted to update it belongs to the release pipeline, not to any individual, including the platform's own owner. A documented, logged emergency override exists for the rare case where the pipeline itself is blocked; every use is recorded and alerts the on-call owner. Application secrets, API keys, and sensitive configuration values are stored in restricted-permission files on the servers that use them and are never committed to source code repositories. Infrastructure and backup secrets are managed separately using SOPS with age encryption. Pre-release testing includes functional, regression, and security-focused test runs. Changes to authentication, payment, or data-handling flows receive additional scrutiny. Customer-facing input is validated and sanitised at all application boundaries. We apply standard defences against OWASP Top 10 risks including SQL injection, cross-site scripting, and cross-site request forgery. KPanel authentication: passwords are hashed with Argon2id (memory-hard, resistant to GPU cracking). New passwords are checked against the Have I Been Pwned database via k-anonymity prefix lookup before acceptance. Sign-in supports TOTP-based two-factor authentication, SMS one-time codes, and hardware passkeys (WebAuthn/FIDO2). OAuth sign-in is supported through the third-party sign-in providers offered on the sign-in page. Providers that publish a JWKS endpoint are verified against it; for providers that do not, the sign-in is verified by calling the provider's own account API directly with the access token it issues. Sign-in attempts are rate limited per IP address, and repeated failed attempts against a single account are locked out for a period. Session tokens are cryptographically random and cryptographically signed, and expire after 30 days of inactivity. ## 10. Data segregation and deletion Customer data is logically segregated at the hosting, database, and application layers. Each customer's files and databases are isolated under separate system accounts, with no cross-customer access. Email is isolated and protected on its own terms. Every mailbox is a separate account, isolated by our mail server's access controls, and signs in with its own credentials. Our mail servers accept only TLS 1.2 and TLS 1.3: TLS 1.0 and 1.1 are refused on every mail port, over both IPv4 and IPv6. We do not offer unencrypted IMAP or POP3 at all, and no sign-in method of any kind is offered before a connection is encrypted. The server-to-server mail port does not offer sign-in at all. Five failed sign-ins within five minutes block the connecting IP address for an hour, and the mail server independently blocks IP addresses behind repeated abusive connections. Mailbox data is stored on encrypted volumes (AES-256-XTS), and mail backups are encrypted. Every domain we host mail for gets its own DKIM signing keys, in both RSA and Ed25519, together with an SPF record. Our own domain, kapsulehost.com, publishes a DMARC policy of reject and an SPF policy that ends in -all, so receiving servers that check DMARC refuse mail that forges it. It also publishes an enforced MTA-STS policy with TLS reporting, which tells sending servers to deliver mail to us only over an encrypted connection to a verified certificate. When a customer terminates their service, Customer Personal Information is made available for export for 30 days, then permanently deleted from live systems. Encrypted backup copies are purged on the next scheduled rotation cycle, within 31 days of deletion from live systems. Documented data deletion procedures ensure that data is removed from all relevant systems, including live databases, caches, and application storage, not just the primary datastore. Procedures for handling Data Subject requests (access, correction, deletion) are documented and tested. KPanel export tools allow customers to retrieve their data at any time during the service term. ## Questions and reporting If you have questions about our security practices, or wish to report a suspected vulnerability, please contact us at privacy@kapsulehost.com. Kapsule Group Limited, New Zealand. --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/security, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Fair Use Policy Canonical page: https://kapsulehost.com/en-us/legal/fair-use Last updated: 24 September 2026 Version 2, effective September 24, 2026 ## About this Policy This Fair Use Policy ("FUP") applies to Plans marketed as offering "unlimited" resources (such as Cloud Power and any future "unlimited" tier). It is part of the Agreement at /legal/terms and is incorporated into the Service. Our promise: "unlimited" resources are designed for the way real customers use them. The thresholds below describe where we will reach out to talk to you, not where we silently bill or throttle. The competitor pattern we object to is FUPs that activate without warning and bill retroactively. Ours is the opposite: explicit numbers, advance notification, and a conversation before any enforcement. ## 1. Bandwidth (Cloud Power) 1.1 Fair-use threshold: 20 TB of outbound network transfer per calendar month per account. This is enough for a typical busy site running media galleries, customer downloads, or e-commerce traffic without exhausting cache. 1.2 If you exceed 20 TB in a month, we email you on the day you cross the threshold with your usage to date and projected month-end usage, and we offer to help you configure a free CDN cache layer to reduce it. 1.3 Bandwidth is not billed. There is no metered bandwidth plan and no bandwidth overage rate: the threshold in 1.1 is the point at which we contact you, not a point at which any charge begins. 1.4 We do not throttle or suspend while we wait for your response, and bandwidth above the threshold is never billed. ## 2. Storage (Cloud Power) 2.1 Fair-use threshold: 500 GB total storage used across all sites, databases, mailboxes, and uploads on your account. 2.2 Above 500 GB we email with a breakdown of where the storage is concentrated and offer either: consolidation help (we identify redundant data, old backups, oversized media) or migration to a dedicated metered storage plan. 2.3 No silent throttling. Customer backups remain available regardless of overage status. ## 3. Mailboxes (Cloud Power) 3.1 Fair-use threshold: 500 active mailboxes per account. "Active" means received or sent mail in the last 6 months. 3.2 Above 500 active mailboxes we will reach out to discuss moving your account to a dedicated mail instance with explicit per-mailbox pricing (typically $1.50/mailbox/mo for the upper tier). 3.3 Inactive mailboxes do not count toward the threshold. ## 4. Websites (Cloud Power) 4.1 There is no fixed count cap on the number of websites you can host on Cloud Power. Instead, per-site resource consumption is monitored. 4.2 If a single site is consistently consuming more than 25% of its node's CPU or memory over a 7-day window, we will contact you with the metrics and offer migration to a dedicated VPS plan (Cloud Servers), where pricing matches the actual resources consumed. 4.3 The check is at the site level, not the account level. A handful of low-traffic sites adding up to high aggregate usage will not trigger this rule; one site consistently consuming a disproportionate share will. ## 5. Enforcement principles 5.1 No surprise. We email you the same day a threshold is crossed, with a copy to the billing contact. 5.2 No silent throttling. Service quality is not degraded while we wait for your response, up to a reasonable conversation window (typically 14 days). 5.3 No retroactive billing. Overage above a threshold is not charged unless you opt in to a metered option. Bandwidth has no metered option and is never charged (clause 1.3). 5.4 No suspension without notice. If a customer does not respond within 30 days of repeated notifications and continues to materially exceed thresholds in a way that affects other customers, we may suspend the account after a final 7-day notice. Service credits under the SLA accrue from the suspension date onward. ## 6. Changes to this Policy 6.1 We may update the thresholds above. Any reduction in threshold (less generous) requires 30 days' advance notice to all customers on affected Plans. Threshold increases (more generous) take effect immediately. 6.2 Thresholds reflect our infrastructure costs. If those costs change materially, thresholds will move to maintain Plan viability. ## Contact Questions about this Policy or about your usage: help@kapsulehost.com. If you receive a fair-use notification and want to discuss your options, reply directly to the notification email. It routes to our support team. --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/fair-use, published for AI readers and agents. For the full interactive page, visit the canonical URL above. --- # Reseller Agreement Canonical page: https://kapsulehost.com/en-us/legal/reseller-agreement Last updated: 30 September 2026 Version 8, effective September 30, 2026 ## About this Agreement This Reseller Agreement ("Agreement") is the contract between Kapsule Group Limited and a business that resells KapsuleHost Services to its own clients. This is the version in force. The copy a Reseller accepts at sign-up is this document. The parties are: Kapsule Group Limited, a New Zealand company, having its registered office at Suite 13063, Level 1, 6 Johnsonville Road, Johnsonville, Wellington 6037, New Zealand ("KapsuleHost", "we", "us"); and the business named in the approved application ("Reseller", "you"). Together they are referred to as "the parties". The Agreement takes effect on the Effective Date, which is the date KapsuleHost approves the Reseller's application and activates the Reseller's account. The Reseller's own details, Tier and rates are recorded in the approved application and are summarised in Schedule 1. ## 1. Definitions "Acceptable Use Policy" or "AUP" means the KapsuleHost Acceptable Use Policy as published at kapsulehost.com/legal/acceptable-use, as updated from time to time. "Clients" means the end customers of the Reseller who receive Services through the reseller panel. "Commission" means the margin earned by the Reseller under the Retail White-Label billing model. "Effective Date" means the date on which KapsuleHost approves the Reseller's application and activates the Reseller's account. "KPanel" means KapsuleHost's customer-facing hosting control panel. "Reseller Panel" means the white-labelled version of KPanel provided to the Reseller under this Agreement. "Services" means web hosting, email hosting, domain registration, and related services provided by KapsuleHost. "Tier" means the reseller plan selected by the Reseller (Starter, Professional, Agency, or Enterprise). "Wholesale Rate" means the discounted price at which KapsuleHost charges the Reseller for Services. ## 2. Appointment and Scope 2.1 Non-exclusive appointment: KapsuleHost appoints the Reseller as a non-exclusive, non-transferable reseller of the Services in the territory stated in Schedule 1. KapsuleHost may appoint other resellers in the same territory at any time. 2.2 Independent contractor: The Reseller is an independent contractor. Nothing in this Agreement creates a partnership, joint venture, employment, or agency relationship. The Reseller has no authority to bind KapsuleHost or make representations on KapsuleHost's behalf. 2.3 Reseller as principal: For the purposes of the Reseller's relationship with Clients, the Reseller acts as a principal. The Reseller is responsible for all commitments, representations, and service levels offered to Clients that go beyond what KapsuleHost explicitly provides under this Agreement. ## 3. Services and Reseller Panel 3.1 Provision of Services: KapsuleHost will provision Services on behalf of the Reseller for Clients in accordance with this Agreement and KapsuleHost's standard technical specifications. 3.2 Reseller Panel: KapsuleHost will provide the Reseller with access to a white-labelled Reseller Panel at the Reseller's chosen domain. The Reseller Panel allows the Reseller to: provision, manage, and terminate Client accounts; configure branding (subject to clause 8); set pricing for Clients (subject to minimums); access billing statements and margin reports; and raise support tickets with KapsuleHost. 3.3 Client Panel: KapsuleHost will provide Clients with access to a white-labelled version of KPanel, branded with the Reseller's brand configuration. Clients will see the Reseller's branding, not KapsuleHost's, except where the Reseller's Tier requires a "Powered by KapsuleHost" attribution (Starter tier). 3.4 Platform availability: KapsuleHost maintains the Services to the monthly Uptime commitment published in the Service Level Agreement at kapsulehost.com/legal/sla. That commitment is the same for every paid Plan and does not vary by Tier. Where Uptime in a calendar month falls below it, the service credit schedule in that SLA applies to the Fees for the affected Service. This clause does not apply to downtime caused by: (a) the Reseller's actions or configurations; (b) Client actions; (c) force majeure; (d) scheduled maintenance notified at least 24 hours in advance. ## 4. Reseller Obligations 4.1 AUP compliance: The Reseller must comply with the AUP and must include the AUP (or its own acceptable use policy that is no less restrictive than the AUP) in the Reseller's agreement with each Client. The Reseller is responsible for enforcing AUP compliance by Clients. 4.2 Client agreements: The Reseller must maintain written agreements with each Client that: incorporate the AUP or equivalent; authorise the Reseller to provision Services on the Client's behalf; include terms compliant with the Privacy Act 2020 (NZ) or applicable data protection law; and do not make representations about Service levels that exceed what KapsuleHost provides under this Agreement. 4.3 Payment: The Reseller must pay the monthly Tier fee as stated in Schedule 1 and the Wholesale Rates for all Services provisioned for Clients during the billing period, within the payment terms stated in Schedule 1. 4.4 Payment method: The Reseller must maintain a valid payment method on file with KapsuleHost's payment processor at all times. Failure to maintain a valid payment method is a material breach. 4.5 Notification obligations: The Reseller must notify KapsuleHost within 5 business days of: any change in the Reseller's legal name, company structure, or ownership; any insolvency event (receivership, liquidation, administration, moratorium); any legal proceeding involving the Reseller that could affect this Agreement; any security incident involving Client data. 4.6 Compliance with law: The Reseller must comply with all applicable laws, including (without limitation) the Privacy Act 2020 (NZ), the Fair Trading Act 1986 (NZ), consumer protection laws applicable in the Reseller's jurisdiction, and anti-money-laundering laws. For resellers operating outside New Zealand, the Reseller is responsible for compliance with all applicable local laws. 4.7 Support first tier: The Reseller must provide first-line support to Clients. KapsuleHost is not obligated to communicate with Clients directly except in the circumstances described in clause 5.3. The Reseller must respond to Clients within the timeframes the Reseller commits to in their own service terms. 4.8 Accurate information: The Reseller must not make any false or misleading representations to Clients about the Services, pricing, or capabilities. ## 5. KapsuleHost's Obligations 5.1 Services delivery: KapsuleHost will provide the Services and infrastructure necessary to operate the Reseller Panel and Client-facing services. 5.2 Support: KapsuleHost will provide second-line support to the Reseller (not directly to Clients) via the Reseller Panel ticketing system, at the SLA for the Reseller's Tier. 5.3 Direct Client contact: KapsuleHost will not contact Clients directly except: where the Client has a separate direct account with KapsuleHost; in cases of AUP violation or abuse where the Reseller has failed to act within 2 hours of notification; where required by law, court order, or regulatory authority; in case of a critical infrastructure emergency where the Reseller cannot be reached; or with the Reseller's written consent. 5.4 Pricing changes: KapsuleHost will give the Reseller at least 30 days' written notice of any increase in Wholesale Rates. Price decreases take effect immediately. If the Reseller does not accept a price increase, the Reseller may terminate this Agreement on written notice within the 30-day notice period. 5.5 Service changes: KapsuleHost will give the Reseller at least 60 days' written notice of any material change to the Services that would adversely affect Clients. 5.6 Confidentiality: KapsuleHost will keep the Reseller's Wholesale Rates confidential and will not disclose them to Clients or other resellers. ## 6. Billing Models ### 6.1 Wholesale Model 6.1.1 How it works: KapsuleHost charges the Reseller the Wholesale Rate for each Service provisioned for Clients during the billing period. The Reseller bills Clients independently on whatever terms and pricing the Reseller chooses, provided the Reseller pays KapsuleHost the Wholesale Rate. 6.1.2 Monthly invoice: KapsuleHost will issue a monthly invoice to the Reseller no later than 3 business days after the end of the billing period, itemising Services by Client and service type. 6.1.3 Payment terms: Invoices are due within 14 days of issue. Late payment incurs interest at 2% per month on the outstanding amount. 6.1.4 Reseller's billing to Clients: The Reseller is solely responsible for billing Clients, collecting payment, and handling Client disputes. KapsuleHost has no obligation and no liability in respect of the Reseller's billing relationship with Clients. ### 6.2 Retail White-Label Model (Professional tier and above) 6.2.1 How it works: KapsuleHost collects payment from Clients on behalf of the Reseller's branded panel. KapsuleHost retains the Wholesale Rate and pays the Reseller the margin via monthly payout. 6.2.2 Payout onboarding: The Reseller must complete our payment processor's payout onboarding, started from KPanel, to receive payouts. KapsuleHost is not responsible for delays caused by the payment processor's onboarding process. 6.2.3 Commission calculation: Commission is calculated at the end of each calendar month as the sum of all margin earned on Client payments received during that period. Refunds are deducted. 6.2.4 Payout: Commission payouts are made in your account currency within 10 business days after the end of the month. A payout below the minimum payout for your account currency, shown in the Reseller Panel, is rolled over to the following month. 6.2.5 Tax: Commission is income for the Reseller. The Reseller is responsible for all tax obligations on Commission received. 6.2.6 Client refunds: If a Client requests a refund, KapsuleHost may process the refund at its discretion. The refund amount is deducted from the Reseller's Commission for that period. The Reseller's Wholesale Rate is not refunded unless the refund arises from a KapsuleHost service failure. ### 6.3 Referrals 6.3.1 Referral code: Each Reseller has a referral code, and a referral link that carries it, in the Reseller Panel. A business that applies to become a Reseller with your code or link, and that we approve, is a "Referred Reseller". You are its "Referring Reseller". 6.3.2 What the Referred Reseller receives: We waive the Tier Fee on the Referred Reseller's first two monthly invoices. These are the invoice for the calendar month in which we approve its application and the invoice for the following month. For an Enterprise Reseller, the Tier Fee is the platform fee agreed for its account. Wholesale Rates for Services provisioned in those months are still invoiced. GST is charged only on the amount invoiced, so a waived Tier Fee attracts no GST. Each waived invoice shows the Tier Fee and the waiver as separate lines. 6.3.3 What the Referring Reseller earns: You earn a referral commission of 10% of the Tier Fee, excluding GST, that the Referred Reseller actually pays on each monthly invoice. You earn it for the 12 calendar months starting with the first month for which the Referred Reseller pays a Tier Fee. You earn nothing for a month whose Tier Fee was waived under 6.3.2, or whose invoice is unpaid, voided, refunded or credited in whole or in part. If commission has already been credited for an invoice that is later voided, refunded or credited, we reverse it, and deduct it from your next payout if it has already been paid. 6.3.4 Payment: Referral commission is paid in your account currency, through the same monthly payout as Commission under 6.2.4. That payout is made by our payment processor to the account you connect in KPanel under 6.2.2, and you may connect one on any Tier to receive referral commission. A payout balance below the minimum payout under 6.2.4 carries forward to a later month until it reaches that minimum. 6.2.5 (Tax) applies to referral commission. 6.3.5 When it ends: No further referral commission is earned once either your account or the Referred Reseller's account is closed or terminated. Referral commission already paid is not affected. Unpaid referral commission already earned is settled under 9.2.3(d). 6.3.6 Limits: A business can be a Referred Reseller only once. The following do not qualify: a referral of yourself or your own business (including an application from your contact email or from anyone on your Reseller team), and a referral of a business with the same NZBN or company registration number as yours. A referral code must be active, unexpired, and within any use limit you set for it when the application is approved. We may withdraw a referral, and any waiver or commission arising from it, if we reasonably believe it was obtained by fraud or misrepresentation. 6.6 Currency: Your Tier Fee, Wholesale Rates, invoices, Commission and referral commission are in the currency of your KapsuleHost account, at the prices published for that currency. GST is charged only on accounts billed in New Zealand dollars. ## 7. Data Protection 7.1 Privacy Act 2020 (NZ): Both parties must comply with the Privacy Act 2020 (NZ) in respect of personal information processed under this Agreement. 7.2 Wholesale model, data controller relationship: Under the Wholesale model, the Reseller is the primary data controller for Client personal information. KapsuleHost acts as a data processor on the Reseller's behalf. KapsuleHost will: process personal data only as instructed by the Reseller; implement appropriate technical and organisational security measures; notify the Reseller within 48 hours of becoming aware of a personal data breach affecting Client data; and delete or return Client data on termination of this Agreement. 7.3 Retail model, data controller relationship: Under the Retail model, KapsuleHost is the data controller for Client personal information (because KapsuleHost holds the billing relationship and processes Client payment data). The Reseller acts as an agent of KapsuleHost for the purpose of onboarding and managing Clients. The Reseller must obtain Clients' consent to KapsuleHost's privacy policy at sign-up. 7.4 Data access: The Reseller may access Client data only to the extent necessary to manage the Reseller's account and provide support to Clients. The Reseller must not access, download, or use Client data for any purpose other than managing their KapsuleHost reseller account. 7.5 Cross-border transfers: If the Reseller is based outside New Zealand, the Reseller acknowledges that Client websites and mail are hosted in Europe, and that Client account and billing data, and the data of any online shops, are held with our control panel in the Asia-Pacific region, and the Reseller must ensure any cross-border data transfer complies with applicable law. 7.6 Data processing agreement (DPA): The terms in clause 7 constitute a data processing agreement between the parties. For resellers subject to GDPR, a separate GDPR-compliant DPA is available on request. ## 8. Intellectual Property and Branding 8.1 KapsuleHost IP: KapsuleHost retains all intellectual property rights in the Services, KPanel, the Reseller Panel software, and all associated materials. The Reseller receives a limited, non-exclusive, non-transferable licence to use these materials solely for the purpose of reselling Services under this Agreement. 8.2 Reseller branding: The Reseller may display its own brand, logo, and colours in the Reseller Panel and Client-facing surfaces as configured through the brand settings. The Reseller's Tier determines the extent of white-labelling available (see Schedule 1). 8.3 KapsuleHost name and logo: The Reseller must not: use the name "KapsuleHost" as part of the Reseller's own trading name or product name without KapsuleHost's prior written consent; imply that the Reseller is KapsuleHost or a KapsuleHost affiliate; use KapsuleHost's logo or brand assets in the Reseller's own marketing without prior written approval for each use; or register any domain name containing "KapsuleHost" without prior written consent. 8.4 "Powered by KapsuleHost" (Starter tier): Starter tier Resellers must display a "Powered by KapsuleHost" attribution in the footer of the Client-facing panel as configured by KapsuleHost. This attribution may not be modified, hidden, or obscured. 8.5 Co-marketing (Agency tier and above): Agency tier Resellers may participate in co-marketing activities. Any co-branded materials must be approved by KapsuleHost in writing before publication. 8.6 Reseller's IP: The Reseller retains all intellectual property rights in the Reseller's own brand, content, and materials. KapsuleHost receives a limited licence to use the Reseller's brand assets to provide the white-labelled panel. ## 9. Suspension and Termination ### 9.1 Suspension 9.1.1 By KapsuleHost for non-payment: If the Reseller fails to pay an invoice within 30 days of the due date, KapsuleHost may suspend the Reseller's panel access. Client sites will continue to operate. KapsuleHost will notify the Reseller 5 days before suspension. 9.1.2 By KapsuleHost for AUP breach: If a Client or the Reseller materially breaches the AUP, KapsuleHost may suspend specific services without notice where immediate action is required to prevent harm. In other cases, KapsuleHost will give the Reseller 2 hours to remediate. 9.1.3 By KapsuleHost for cause: If the Reseller breaches any material term of this Agreement and fails to remedy the breach within 14 days of written notice, KapsuleHost may suspend the Reseller's account. 9.1.4 Client impact during suspension: During a Reseller account suspension: (a) existing Client sites, email, and domains remain operational; (b) new provisioning is blocked; (c) Clients receive a generic notice without specifying the reason relates to the Reseller. ### 9.2 Termination 9.2.1 By either party without cause: Either party may terminate this Agreement on 60 days' written notice. 9.2.2 By KapsuleHost for cause: KapsuleHost may terminate immediately if: the Reseller becomes insolvent; the Reseller commits fraud or material misrepresentation; the Reseller's Clients repeatedly or seriously breach the AUP; or the Reseller uses the Services for any illegal purpose. 9.2.3 Effect of termination: On termination: (a) the Reseller's panel access terminates on the effective date; (b) existing Client accounts enter a 60-day transition period during which Clients are offered direct-to-KapsuleHost migration or data export; (c) outstanding invoices become immediately due; (d) KapsuleHost will pay any outstanding Commission owed to the Reseller after deducting amounts owed by the Reseller. 9.2.4 Client transition: During the 60-day transition period, KapsuleHost will notify Clients that the reseller's services are being discontinued, offer Clients direct-to-KapsuleHost accounts at KapsuleHost's standard rates, provide data export tools for Clients who wish to move elsewhere, and continue hosting Client sites at KapsuleHost's cost for the transition period. After the 60-day period, Client sites that have not migrated will be suspended and then deleted (30-day suspension before deletion). 9.2.5 Data deletion: After termination and completion of the transition period, KapsuleHost will delete the Reseller's account data within 90 days, subject to retention requirements under applicable law. ## 10. Liability 10.1 KapsuleHost's liability to Reseller: KapsuleHost's total liability to the Reseller under this Agreement (whether in contract, tort, or otherwise) is limited to the amount of Tier fees paid by the Reseller in the 3 months preceding the event giving rise to the claim. 10.2 Exclusion of consequential loss: Neither party is liable for indirect, special, or consequential loss (including loss of profits, loss of business, or loss of goodwill) arising under this Agreement, even if advised of the possibility of such loss. 10.3 Reseller's liability to KapsuleHost: The Reseller indemnifies KapsuleHost against any loss, damage, or expense (including reasonable legal costs) arising from: (a) the Reseller's breach of this Agreement; (b) Client actions that are the Reseller's responsibility; (c) the Reseller's false or misleading representations to Clients; (d) the Reseller's failure to comply with applicable law. 10.4 No liability for Reseller's client relationships: KapsuleHost is not liable for any obligations or commitments the Reseller makes to Clients that exceed what KapsuleHost provides under this Agreement. 10.5 Consumer guarantees: Nothing in this Agreement limits any rights that cannot be excluded under the Consumer Guarantees Act 1993 (NZ) or other applicable consumer protection law. ## 11. Confidentiality 11.1 Each party must keep confidential all information received from the other party that is marked as confidential or that a reasonable person would understand to be confidential, including (without limitation) Wholesale Rates, the Reseller's client list, and KapsuleHost's technical infrastructure details. 11.2 Confidentiality obligations do not apply to information that: (a) is or becomes publicly available through no breach by the receiving party; (b) was independently developed by the receiving party; (c) is required to be disclosed by law, court order, or regulatory authority. 11.3 Confidentiality obligations survive termination for 3 years. ## 12. General 12.1 Governing law: This Agreement is governed by the laws of New Zealand. The parties submit to the non-exclusive jurisdiction of the New Zealand courts. 12.2 Dispute resolution: Before commencing litigation, the parties must attempt to resolve any dispute by mediation under the AMINZ Mediation Rules, with a mediator agreed between the parties or, failing agreement, appointed by AMINZ. 12.3 Amendments: KapsuleHost may amend this Agreement with 30 days' written notice. The Reseller's continued use of the Services after the notice period constitutes acceptance of the amended terms. 12.4 Entire agreement: This Agreement (including Schedules and any Order Form) is the entire agreement between the parties relating to its subject matter and supersedes all prior agreements or representations. 12.5 Waiver: A failure to enforce any term is not a waiver of that term. 12.6 Severability: If any term is unenforceable, it is severed and the remainder of the Agreement continues in force. 12.7 Assignment: The Reseller may not assign this Agreement without KapsuleHost's prior written consent. KapsuleHost may assign this Agreement to an affiliate or in connection with a sale of all or substantially all of its assets. 12.8 Notices: Written notices may be given by email to the addresses in Schedule 1. Email notices are deemed received when sent (unless the sender receives a delivery failure notification). ## Schedule 1: Tier Details The values in this Schedule are set from the Reseller's approved application. Reseller details: Legal name, registration number, country, contact email, and reseller panel domain are recorded in the approved application. KapsuleHost details: Contact for notices: legal@kapsulehost.com Tier: As selected in the application (Starter / Professional / Agency / Enterprise) Tier fee: As published at kapsulehost.com/hosting/reseller in your account currency at the time of application, billed monthly in arrears. Referral programme: As set out in clause 6.3 (2 months' Tier Fee waived for the Referred Reseller; 10% of the Tier Fee it pays, for 12 months, to the Referring Reseller). Wholesale rates: Exclusive of GST; rates vary by Tier and are published in the Reseller Panel after approval. Client limit: 25 (Starter) / 100 (Professional) / Unlimited (Agency and Enterprise) Billing model(s) enabled: As available for the selected Tier. SLA uptime target: 99.9% monthly Uptime, as published in the Service Level Agreement at kapsulehost.com/legal/sla. It is the same for every Tier, and the service credit schedule in that SLA is the remedy if a month falls below it. Support SLA: Email response within 24h (Starter) or 4h (Professional and above). White-label level: Custom domain and removal of "Powered by KapsuleHost" attribution available on Professional tier and above. Agreement version: 1.0. Effective date: date of account approval. ## Schedule 2: Acceptable Use Policy The current AUP is incorporated by reference from kapsulehost.com/legal/acceptable-use. As at the Effective Date, the AUP prohibits (among other things): hosting of spam sending infrastructure; distribution of malware or illegal content; cryptocurrency mining without explicit permission; CSAM or other illegal sexual content; DDoS-for-hire or similar attack services; and sites that facilitate illegal activity in New Zealand or the Reseller's jurisdiction. --- This is the Markdown rendition of https://kapsulehost.com/en-us/legal/reseller-agreement, published for AI readers and agents. For the full interactive page, visit the canonical URL above.