Terms and Conditions
Effective from 29 July 2026
This English version is provided to help non-Hungarian clients understand the principal terms governing WebShield services. The detailed Hungarian Terms and Conditions are authoritative. If the two versions differ, the Hungarian version prevails, subject to mandatory law.
1. Service provider
Company: WebShield IT Security Kft.
Registered office and postal address: 2080 Pilisjászfalu, Dombhát u. 14., Hungary
Company registration number: 13-09-219848
Tax number: 27830374-2-13
Registering court: Company Court of the Budapest Environs Regional Court
Email: info@webshield.hu
Telephone: +36 30 251 80 70
Website: https://webshield.hu
2. Scope
These terms apply to contracts between WebShield IT Security Kft. (Provider) and the person or organisation ordering a service (Client). An accepted individual quotation, order confirmation or separately signed agreement forms part of the contract and prevails over these general terms where it expressly differs.
A Consumer is an individual acting outside their trade, business or profession. Consumer-specific provisions apply only to Clients who qualify as Consumers.
3. Services
Depending on the selected plan and technical environment, managed WordPress security may include:
- AI-assisted and rule-based detection and firewall protection;
- monitoring of files, components, administrator accounts and relevant events;
- comparison of WordPress core, plugin and theme files with official or other verified copies;
- analysis of newly installed or changed components;
- managed updates of WordPress core, plugins and themes, including verification of the result and restoration of the previous working version where necessary;
- correlation of file changes with incoming HTTP requests;
- a shared attacker blocklist based on events across protected websites;
- incremental backups every two hours;
- malware removal, incident investigation and recovery;
- Hungarian-language support and priority handling under Agency plans.
Current plans and fees are shown on the Pricing page. Bespoke terms apply above 50 websites and to requirements outside the standard plans.
The SOS service covers urgent incident response and recovery. In addition to the selected plan, an emergency fee of HUF 10,000 plus VAT applies. The confirmed scope and start time are stated in the Provider’s confirmation.
Penetration testing, security reviews, consultancy and security awareness training are delivered only within an agreed scope, schedule and quotation. Testing may be carried out only with verifiable authorisation from the system owner or another duly authorised person.
4. Ordering and contract formation
For managed WebShield protection, the Client selects a plan and billing period, enters the requested details, accepts the Terms and submits the order. The Client is then redirected to Stripe’s payment interface.
The contract, subscription period and billing period begin when payment is successfully completed through Stripe. If payment fails or is abandoned, no contract or subscription is created.
After payment, the Client must install and connect the WebShield plugin on the website to be protected. If the Client cannot do so, the Client must provide the hosting, FTP/SFTP or other agreed access required for installation or initial recovery. Monitoring, backups, managed updates and other technical protection can start only after the plugin is connected or the required access has been provided. A delay by the Client does not automatically postpone the paid subscription period.
The Provider sends or makes available an electronic confirmation of successful payment and creation of the subscription. Stripe processes payment under its own contractual and privacy terms.
The Client may correct form data before submission and must promptly report any later-discovered error. The Client is responsible for providing accurate information and for having the authority to order the service and grant the required access.
The contract may be concluded in Hungarian or English. Order and confirmation records are retained as required by accounting, tax and civil law and can be made available to the Client on request.
The Provider may reject an order or refund a successful payment where performance would be unlawful, authorisation cannot be verified, the scope creates unacceptable risk or technical conditions prevent activation.
The contract is concluded electronically. The Provider has not submitted to a separate code of conduct. The technical ordering steps are selecting a plan and billing period, entering Client and billing details, checking the summary, accepting the Terms and expressly requesting performance before the 14-day withdrawal period expires, submitting the order with an obligation to pay and completing payment through Stripe.
5. Fees, invoicing and payment
Prices shown as “plus VAT” are net prices. Applicable VAT is added. A Consumer must be shown the total gross amount before making a declaration that creates a payment obligation.
Monthly billing covers one month and annual billing covers twelve months. Payment method, due date and any advance payment are specified during ordering, on the invoice or in the accepted quotation. Electronic invoices may be sent to the email address supplied by the Client.
The Provider may change fees for future subscription periods by giving at least 30 days’ notice. The Client may terminate the subscription for the next period before the change takes effect.
6. Performance and Client cooperation
The Client must provide the information, authority and technical cooperation reasonably required for performance. If the Client can access WordPress administration and install the WebShield plugin, no additional access is normally needed. FTP/SFTP, hosting or other access may be required where the administration interface is unavailable or damaged.
Where reasonably necessary for a contracted maintenance, update, investigation or recovery task, the system or the Provider may create a WordPress administrator account using the username webshield. The account may be used only to perform the service, its credentials must be protected, and it is disabled or removed when no longer needed unless continued access is required for the managed service.
For SOS orders, the Provider aims to start as soon as practicable, generally within one hour. This is a target for starting work, not a guaranteed full-recovery deadline. Timing depends on access, infection scope, website condition and whether manual recovery is required before the plugin can be installed.
The Client must use lawful and appropriately licensed software, protect credentials, maintain accurate contact details, act on material security recommendations and immediately report suspected incidents or significant system changes.
7. Backups and security
The managed service creates incremental file backups every two hours for technically accessible files within the selected service. Backups are retained on a rolling basis for two weeks, after which older backups may be overwritten or deleted automatically.
Database backup is not included automatically with file backup. The Client must request it separately. Because a WordPress database may contain personal data, the Client generally remains the data controller and the Provider acts as a processor on the Client’s behalf. Database backup may start only after the parties have entered into an Article 28 GDPR data-processing agreement. The Client must identify the Provider as a processor in its data-protection records and, where required, its privacy notice.
No security service can guarantee that every attack, zero-day vulnerability, third-party outage or data-loss event will be prevented. Clients should retain a separate business-continuity backup where required by law, contract or their own risk assessment.
During recovery, the Provider may remove, quarantine or replace infected files, revoke compromised access and apply necessary security settings. Where urgency permits, material functional changes are agreed with the Client first.
8. Subscription term and termination
Unless otherwise agreed, subscriptions continue for an indefinite term in monthly or annual billing periods and renew for the next period until terminated.
The Client may terminate by email. Termination takes effect at the end of the current paid period. Fees for a period already started are generally non-refundable, without affecting mandatory Consumer rights or a specific money-back undertaking.
The Provider may terminate with 30 days’ notice. Material breach, unlawful use, conduct that endangers security or an unpaid debt remaining after notice may lead to immediate suspension or termination.
When the service ends, monitoring, firewall protection, backups and expert intervention end. The Client should request any export available under the service before termination.
9. Consumer withdrawal and termination rights
A Consumer entering into a distance contract may withdraw within 14 days from conclusion. For a service contract where performance has begun, the Consumer may terminate within that period without giving a reason.
If the Consumer asks performance to begin before the 14-day period expires, the request must be express. Upon termination, the Consumer must pay the proportionate price for performance completed before notice.
Once a service has been fully performed, the Consumer loses the withdrawal or termination right only where performance began with the Consumer’s express prior consent and acknowledgement of this consequence. This is particularly relevant to an immediately started and completed SOS recovery.
A withdrawal or termination statement may be sent to info@webshield.hu or the Provider’s postal address. It should identify the Client, service, contract date and the decision to withdraw or terminate.
10. Warranty and money-back undertaking
Statutory warranty rights under Hungarian law remain applicable. A defect should be reported without undue delay, together with information reasonably required for investigation.
The 100% money-back guarantee published on the website is an additional voluntary undertaking. If the Client did not receive the service expressly agreed, the Client may notify the Provider at info@webshield.hu. After reviewing the performance, the Provider refunds the affected service fee where the claim is substantiated. This does not limit mandatory statutory rights.
11. Liability
The Provider performs with professional care but cannot guarantee that a website will never be attacked, that all unknown vulnerabilities will be detected immediately, or that third-party infrastructure will always remain available.
To the extent permitted by law, the Provider is not liable for failures outside its control, unsupported or unlawfully sourced components, inaccurate Client information, delayed Client cooperation, ignored security recommendations, force majeure, or indirect and consequential loss.
For business Clients, total liability is limited to the net fees actually paid for the affected service in the 12 months preceding the event, except for deliberate breach and harm to life, physical integrity or health. This limitation does not restrict rights that cannot lawfully be limited.
12. Confidentiality, privacy and data processing
Both parties must protect credentials, vulnerability details, personal data, trade secrets and non-public technical information learned during performance.
The Provider’s own processing is described in the Privacy notice. Where the Provider processes personal data held on the Client’s website on the Client’s behalf, the Client may be the controller and the Provider a processor. The parties must then put in place Article 28 GDPR data-processing terms in a separate agreement or contractual schedule.
Anonymised incident and vulnerability information that does not identify the Client may be used to improve detection rules, defensive methods and shared blocklists.
13. Intellectual property
WebShield software, rules, documentation, methodology, report templates, branding and website content remain the intellectual property of the Provider or its licensors. The Client receives a non-exclusive, non-transferable right to use the necessary service elements for the contracted purpose and duration.
Penetration-test reports and training materials may be used internally and shared confidentially with the Client’s advisers, authorities or insurer. Public publication or commercial reuse requires prior written permission unless the individual agreement states otherwise.
14. Complaints and disputes
Complaints may be sent to info@webshield.hu or the Provider’s postal address. Written Consumer complaints are answered in writing within 30 days.
Hungarian Consumers may contact the competent government office or a conciliation body. Current conciliation-body details are available from the Hungarian consumer protection authority. The body competent at the Provider’s registered office is the Pest County Conciliation Board.
The parties first seek an amicable resolution. Hungarian law applies, without depriving Consumers of mandatory protection applicable under the law of their habitual residence. Statutory rules determine jurisdiction for Consumer disputes.
15. Changes and final provisions
The Provider may amend these terms because of legal, service, security, pricing or operational changes. Material changes adversely affecting an existing subscription are notified at least 30 days in advance. The Client may terminate for the next billing period before the change takes effect.
If any provision is invalid or unenforceable, the remaining provisions remain effective.
These terms take effect on 29 July 2026 and apply to contracts concluded afterwards and to the next renewal period of existing subscriptions.