These terms govern the PatientZero website and security services provided by [Company name]. They are written to be read, so please do. If anything is unclear, ask us before you sign up.
About us and these terms
PatientZero is a trading name of [Company name], registered in England and Wales under company number [Company number], with its registered office at [Registered address] ("we", "us"). You can contact us at repair@patientzerosolutions.co.uk or on 01932 593642.
These terms apply to anyone who uses our website ("you") and, when you buy a plan, to the business buying it ("the customer"). Our services are provided to businesses and are not intended for consumers. By using the website or our services you accept these terms.
Our services
PatientZero provides malware detection, removal, hardening and monitoring for websites and the servers they run on. Depending on your plan, the services include:
- a security audit and setup when you join
- forensic scans and malware sweeps of your websites and servers
- removal of malware, backdoors and malicious accounts
- hardening of websites and servers
- 24/7 monitoring and alerts
- incident reports and an activity log of changes we make
The exact scope of your plan, including which websites and servers are covered, is confirmed when you sign up.
Plans, pricing and payment
| Plan | Price |
|---|---|
| Single Site | £99 per month, plus a one-off £129.99 security audit and setup |
| Server / Multi-site | Price on application, based on the server and sites covered |
| Agency (white-label) | From £299 per month |
New accounts start with a one-off £129.99 security audit and setup, so we understand your websites and servers before the first removal. This fee is payable once, at the start, and is not refundable once the audit has begun.
Plans are billed monthly in advance. Prices are shown [inclusive / exclusive] of VAT. We may change our prices by giving you at least 30 days' notice by email; if you do not agree, you can cancel before the change takes effect.
No contract: cancel any time
There is no minimum term. You can cancel your plan at any time by emailing repair@patientzerosolutions.co.uk. Cancellation takes effect at the end of the monthly billing period you have already paid for, and services continue until then. We do not refund part months.
When your plan ends, we will remove our scan engine and any access we were given, and you should revoke any keys, passwords or user accounts you created for us.
Unlimited malware removal and fair use
Every plan includes unlimited malware removal for the websites and servers covered by your plan. If a covered site or server is re-infected while your plan is active, we will clean it at no extra cost, and there is no cap on the number of clean-ups.
Fair use applies to full server rebuilds. Where we recommend rebuilding a server or migrating sites to a new one, for example after a deep root-level compromise, we will agree the scope with you first and may charge for the rebuild or migration if it goes beyond reasonable use of your plan. We will always tell you before any additional charge applies.
Unlimited removal does not cover websites or servers outside your plan, development of new features, or recovery of data that has been permanently destroyed and is not available in any backup.
Your responsibilities
To provide the services, we need your help. You agree to:
- give us the access we reasonably need, such as SSH, hosting control panel, CMS administrator and Google Search Console access
- confirm that you own the websites and servers covered, or have the authority of the owner to grant us access and instruct us
- keep your own backups, and tell us about any backups you have
- give us accurate information and tell us promptly about changes, incidents or anything that may affect the services
- follow our reasonable security recommendations, such as updating software and changing compromised passwords
- pay our invoices on time
If we cannot get the access or information we need, we may not be able to complete a clean-up, and we are not responsible for delays caused by that.
How we use the access you give us
We use access to your systems only to provide the services. Our platform connects to your server over SSH and deploys a scan engine to /opt/patient-zero/scan-engine. We record the actions we take in an activity log that you can review. We may quarantine malicious files rather than delete them, so evidence is preserved.
You can withdraw our access at any time. If you do, we will not be able to provide services that depend on it.
What we can and cannot promise
We use skill and care to detect and remove malware, fix the causes we find and reduce the risk of future attacks. However, no service can guarantee that a website or server will never be attacked or compromised again. New vulnerabilities, stolen credentials and threats outside our control mean some risk always remains.
In particular, we do not guarantee:
- that all future attacks will be prevented
- any particular response or clean-up time, unless agreed in writing
- decisions made by third parties, such as Google lifting a blacklist warning, or a host reinstating a suspended account
- the recovery of data that was destroyed or encrypted before we were engaged and is not in any backup
If a covered site is re-infected while your plan is active, our remedy is to clean it again at no extra cost.
The free malware check
The free malware check uses only publicly available information about a website. It is provided free and as is, for information only. A clean result does not mean a website is free of malware, because much malware hides on the server where a public check cannot see it. You must only check websites you own or are authorised to check, and must not use the tool to overload or attack any website.
Our liability
Nothing in these terms limits our liability for death or personal injury caused by our negligence, fraud, or anything else that cannot be limited by law.
Subject to that, we are not liable for loss of profits, revenue, business, goodwill or data, or for any indirect or consequential loss. Our total liability to a customer in any 12-month period is limited to the fees paid by that customer for the services in that period.
We are not responsible for loss caused by an attack or compromise that happened before we were engaged, by third-party software, hosting or services, or by the customer not following our recommendations.
Data protection
While providing the services we may process personal data held on your websites and servers. For that data, you are the controller and we are your processor. We will process it only on your documented instructions to provide the services, keep it confidential and secure, use sub-processors only under equivalent obligations, help you respond to data subject requests and personal data breaches, and delete or return it at the end of the services, in line with UK GDPR Article 28.
How we handle personal data as a controller, for example your contact details, is explained in our privacy policy.
Confidentiality and intellectual property
We keep confidential all non-public information about your business, systems and security, and use it only to provide the services. You own your websites, content and data. We own the PatientZero platform, scan engine, playbooks and our know-how. You may use the reports we provide for your own business purposes, including sharing them with your clients, insurers, hosts and regulators. Agency plans include the right to share white-label reports with your clients.
Suspension and termination
We may suspend or end the services if invoices remain unpaid after we have reminded you, if you seriously breach these terms, or if continuing would be unlawful or put our systems or other customers at risk. We will give you notice where we reasonably can.
Using our website
The information on our website, including our guides, is general information, not advice for your specific situation. You must not misuse the website, including by attempting to gain unauthorised access, introducing malicious code or submitting false information through our forms. If you find a security issue with our website, please report it responsibly as described on our security page.
General
We may update these terms from time to time. The date at the top shows when they were last changed, and we will tell customers about significant changes by email in advance. If any part of these terms is found to be unenforceable, the rest remains in force.
These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.