01 Legal

Terms of Service

Last updated: August 14, 2026

These Terms of Service ("Terms") govern the relationship between Etherlabz IT Solutions Private Limited ("Etherlabz", "we"), a company registered in India, and any individual or entity ("Client", "you") who engages us for services or uses this website. Project-specific terms are documented in a separate written agreement; in case of conflict, the project agreement controls.

1. Scope of services

Etherlabz provides custom software engineering services, including ecom builds (WooCommerce, headless storefronts), product configurators, third-party connectors and scrapers, plugins and integrations, custom development on Next.js, NestJS, and WordPress, audits, and ongoing care plans. Our SaaS product LocalLeads (under the PostOrbit brand) is governed by separate terms at leads.postorbit.io/terms.

The exact scope, deliverables, milestones, and price for any engagement are set out in a written project agreement signed by both parties. These Terms apply to that engagement unless explicitly overridden in writing.

2. Engagement formation

A binding engagement is formed only when (a) a written proposal is signed by both parties, or (b) a deposit invoice is paid, whichever happens first. Initial scoping calls, ballpark estimates, and emailed quotes are not binding on either side.

3. Payment terms

  • Fees, milestones, and payment schedule are defined per engagement.
  • We invoice in EUR for European clients (typically without VAT under reverse-charge), USD for US/global clients, and INR for clients invoiced in India. Other currencies on request.
  • Standard net-15 unless otherwise agreed in writing. Late payments may attract interest at the rate permitted under India's MSME Act and the EU Late Payment Directive (Directive 2011/7/EU) where applicable.
  • Payment is processed via bank transfer, Razorpay, or PayPal. Payment processor fees are borne by the Client unless agreed otherwise.
  • Estimates and fixed-price quotes are valid for 30 days from the date of issue.

4. Intellectual property

On full payment for a phase, all deliverables developed specifically and exclusively for the Client under the engagement become the Client's property, including source code, designs, documentation, and integrations.

Etherlabz retains ownership of any pre-existing tools, libraries, and general-purpose components, as well as the technical know-how and patterns acquired during engagements. We may reuse general technical knowledge in future projects, provided we do not reproduce specific Client logic, algorithms, or organisational structures developed for that Client.

Open-source plugins and components we publish under our own GitHub organisation (github.com/EtherLabZ) remain our property and are licensed under their stated open-source licenses (typically MIT). Use of an open-source plugin in a Client project does not transfer ownership of that plugin.

5. Confidentiality

We treat Client information (source code, credentials, business documents, customer lists, financial data) as confidential. Unless explicit written permission is granted, we do not display, reference, or use Client work in our portfolio, marketing materials, or case studies. Confidentiality obligations survive termination of any engagement indefinitely.

6. Non-competition

Where a Client requests an exclusivity arrangement (e.g., "we will not take a competing client in the same geography"), it is agreed in the project agreement and we honour it strictly. Without such an arrangement, no implicit non-compete is in force.

7. Warranty & defect correction

We warrant that deliverables substantially conform to the specifications in the project agreement. We provide a four-week warranty after final delivery during which we correct defects at no additional cost: up to two weeks for major bugs, up to four weeks for minor adjustments. Clients on a Care Plan retainer (six months or more) receive an extended one-year design-effort warranty.

8. Acceptance criteria

Clients have 30 days from final delivery to review and report defects. Acceptance is deemed confirmed if no issues are reported within that period. Pre-delivery testing covers functional, performance, and basic security checks.

9. Hosting and infrastructure responsibilities

Unless we are explicitly contracted to host, the Client is responsible for providing infrastructure (domain, server, cloud accounts) and securing it. We are responsible for application-level code we deliver but not for breaches arising from insecure hosting environments, leaked credentials, or unauthorised client-side access. Care Plan retainers may include managed hosting where agreed.

10. Limitation of liability

To the maximum extent permitted by applicable law, our total aggregate liability, whether in contract, tort (including negligence), or otherwise, arising out of or in connection with an engagement, shall not exceed the total amount paid by the Client to Etherlabz under the specific phase or service giving rise to the claim. We shall not be liable for indirect, incidental, special, punitive, or consequential damages, including loss of profits, revenue, business opportunities, or data, even if advised of their possibility.

11. Indemnification

The Client agrees to indemnify and hold harmless Etherlabz and its personnel from claims, demands, and liabilities arising from (a) the Client's use or misuse of deliverables after handover, (b) unauthorised modification or distribution of our work, or (c) actions or inactions following project delivery, except to the extent caused by our gross negligence or wilful misconduct.

12. Termination

Either party may terminate an engagement with fourteen (14) days' written notice. Upon termination, Etherlabz is entitled to retain payments for work completed up to that point. Unused revision rounds or undelivered phases are forfeited unless otherwise agreed in writing.

13. Force majeure

Neither party is liable for delays or failures due to causes beyond its reasonable control, including natural disasters, war, terrorism, strikes, pandemics, government restrictions, or major internet outages. The affected party will notify the other promptly. If the event continues for more than 21 days, either party may terminate without penalty.

14. Governing law

These Terms are governed by the laws of India, including the Indian Contract Act, 1872 and the Information Technology Act, 2000. Where the Client is established in the European Union, the mandatory provisions of EU law also apply, including the General Data Protection Regulation (GDPR), the Consumer Rights Directive (2011/83/EU), the Digital Services Act, and the Late Payment Directive.

15. Dispute resolution

The parties will first attempt to resolve any dispute amicably through good-faith negotiation within fifteen (15) days of written notice. If unresolved, the parties will mediate with a mutually agreed mediator; failing agreement, either party may request appointment by the London Court of International Arbitration (LCIA).

If mediation fails, the dispute will be finally resolved by binding arbitration under the LCIA Rules. If no agreement on the institution is reached within ten (10) days, arbitration will be conducted under the UNCITRAL Arbitration Rules. The seat of arbitration will be New Delhi, India and the language English, unless agreed otherwise.

Subject to the arbitration clause above, the courts at Jhansi, Uttar Pradesh shall have exclusive jurisdiction for any matters not capable of arbitration, with appellate jurisdiction at the High Court of Delhi and ultimately the Supreme Court of India.

16. Fixed-price audits and reviews

This section applies to our fixed-price review products: the security & launch audit (currently €299) and the UI/UX audit (currently €490). Where this section conflicts with the general terms above, this section controls for those products.

Nature of the service. An audit is an expert, time-boxed review of your application against a defined checklist (for the security & launch audit: auth and access control, payment flows, secrets handling, error handling, and monitoring). The deliverable is a written, severity-ranked report. An audit is not a penetration test, not an exhaustive vulnerability assessment, and not a compliance certification of any kind (including SOC 2, ISO 27001, PCI DSS, or GDPR). We apply professional skill and care, but the absence of a finding in the report is not a warranty that no issue exists, and a report with no critical findings is a valid, complete deliverable.

Scope. One audit covers one application. For the security & launch audit that means one repository, one auth provider, and one payment integration; monorepos, multiple services or projects, or materially larger codebases need a separate written quote before payment. For the UI/UX audit it means one application's core journey set as listed on the audit page; a second product, a two-sided marketplace, or a full design-system review needs a separate written quote before payment. If you pay the standard fee for something outside this scope, we will tell you before starting and either agree a quote for the difference or refund you in full.

Turnaround and refund. The clock starts at our written confirmation that we have received payment and working access. For the security & launch audit, the delivery target is 48 hours; during periods of high demand delivery may take up to 5 calendar days (we say so at confirmation), and if we do not deliver within 5 calendar days you receive a full refund of the fee. For the UI/UX audit, the delivery target is 1 week, and if we do not deliver within 10 calendar days you receive a full refund of the fee. These refunds are the sole remedy for late delivery. Delays caused by missing or broken access on your side pause the clock until access works.

Change of mind. If you paid but have not yet sent access, you can request a full refund at any time and we issue it; nothing has started. Once we confirm working access and the clock starts, the fee is no longer refundable for change of mind (the late-delivery refund above still applies).

Rush delivery. Guaranteed 48-hour delivery regardless of the current queue is available as a paid rush option, priced case by case and agreed in writing before payment.

Emergency triage. Where you report an active leak or exposed credential, our stated reply time (within 4 hours on working days) is a service target, not a contractual guarantee. Containment or remediation work beyond the audit checklist is quoted separately.

Fee credit. The security & launch audit fee is credited in full toward a fix engagement with us for the same application, as described on the pricing page at the time of purchase. The UI/UX audit fee does not credit toward follow-on engagements; the report itself is the deliverable.

Liability. Consistent with Section 10, our total aggregate liability arising out of an audit engagement shall not exceed the audit fee paid.

17. Fixed-price rescue services

This section applies to our fixed-price rescue products: the Speed Rescue and the Store Rescue (currently $699 each). Where this section conflicts with the general terms above, this section controls for those products.

Nature and scope. A rescue is one week of diagnosis and implemented fixes on one WordPress site (Speed Rescue) or one WooCommerce store (Store Rescue) on one domain, on the key templates agreed at booking. The deliverable is the implemented fixes plus a written handover listing every change and the benchmark numbers. A rescue is not a redesign, a rebuild, a hosting migration, or ongoing maintenance. Where free triage shows the right first step is something else (for example a host move), we say so before you pay and the fee stays with you.

Benchmark guarantee. Before we change anything we record Core Web Vitals from PageSpeed Insights (mobile) on the agreed key templates, and we record them again at handover from the same tool on the same templates. If the after numbers do not show a measurable improvement over the before numbers, you say so at handover and we refund the fee in full. This refund is the sole remedy under the guarantee. The comparison assumes the site is not materially changed by you or third parties during the rescue week (new plugins, theme swaps, host changes, large content imports); where such changes affect the numbers, we will show you the effect and agree a fair reading before either side relies on the benchmark.

How we work. We take a full backup (files and database) before any change. Work happens on staging where your host provides it; otherwise changes go in one at a time in an agreed window, each reversible, with the backup as the floor. Anything visible to visitors is agreed with you in advance.

Scheduling and access. The rescue week is scheduled at our written confirmation that payment and working access (wp-admin and hosting or staging access) have both arrived. Delays caused by missing or broken access pause the schedule until access works. If you paid but have not yet sent access, you can request a full refund at any time.

Liability. Consistent with Section 10, our total aggregate liability arising out of a rescue engagement shall not exceed the rescue fee paid.

18. Emergency malware cleanup and reinfection cover

This section applies to the emergency malware cleanup (currently from $499, priced after free triage).

Nature and scope. The cleanup covers one WordPress site on one domain: removal of malware and backdoors we find, removal of rogue administrator accounts, identification and closure of the entry point where it can be determined, and a blocklist review. The scope and fixed price are confirmed in writing after the free triage and before payment. A cleanup is not a guarantee that a site can never be compromised again; the handover lists the hardening steps we recommend.

30-day reinfection cover. If the same site is reinfected within 30 calendar days of our written handover, we clean it again at no charge. The repeat cleanup needs the same access as the original. The cover applies to the site as we handed it over; it does not extend to compromises introduced by changes made after handover that reverse our work or reintroduce the vulnerability we identified in writing (for example reinstalling software we removed as infected, or restoring a backup from before the cleanup). The cover is another cleanup, not a refund.

Liability. Consistent with Section 10, our total aggregate liability arising out of a cleanup engagement shall not exceed the cleanup fee paid.

19. Care Plans

This section applies to the monthly Care Plans (Care, Care+, Commerce Care, and Custom Care) at the prices published on the pricing page at the time of purchase.

Term and cancellation. Plans are billed monthly in advance and run month to month. You can cancel at any time, effective at the end of the paid period; there is no minimum term, no cancellation fee, and no refund for the remainder of a started period. Annual prepay buys 12 months for the price of 10; an annual term that is cancelled early is refunded for whole unused months beyond the 10 paid.

Included hours. Development hours included in a tier apply within the plan month and do not roll over. Work beyond the included hours is quoted before it is done.

Service windows. Monitoring runs continuously. Human response happens inside business hours (IST); alerts that arrive overnight are handled at the start of the next working day. Stated response times are service targets, not contractual guarantees; guaranteed off-hours response is available only where agreed in writing under Custom Care.

Compromise during a plan. If a site that has our hardening baseline in place is compromised while its plan is active, we clean it up at no extra charge. Sites that join a plan in unknown condition may be required to start with the security audit so the baseline is established first.

Liability. Consistent with Section 10, our total aggregate liability arising out of a Care Plan shall not exceed the plan fees paid in the three months preceding the event giving rise to the claim.

20. Changes to these Terms

We may update these Terms from time to time. Existing engagements continue under the version of the Terms in force at the date of the project agreement; new engagements use the version published at signing.

21. Contact

Etherlabz IT Solutions Private Limited
Registered in India · Operating with EU and global clients
Legal contact: hello+legal@etherlabz.com
General contact: hello@etherlabz.com