These Terms of Service (the “Terms”) are an agreement between Rouhee Group Ltd, Business ID 2684686-4, a company registered in Finland (“BehindGate”, “we”, “us”), and the organisation that creates a BehindGate account (the “Customer”, “you”). They govern your use of the BehindGate service at behindgate.com and its subdomains, the dashboard, the API, the command line tools, and any related software and documentation (together, the “Service”).
By creating an account, clicking to accept, or using the Service, you accept these Terms and the documents they incorporate. If you accept on behalf of an organisation, you confirm that you have the authority to bind it. If you do not have that authority or do not agree, do not use the Service.
These Terms are standard and are not negotiable, except that Enterprise customers may have a separate written agreement that takes precedence where it conflicts with these Terms.
1. Documents that form the agreement
The following documents are part of these Terms and are incorporated by reference:
- the Acceptable Use and Fair Use Policy (the “AUP”);
- the Data Processing Agreement (the “DPA”);
- the Service Level Agreement (the “SLA”);
- the Privacy Policy, which describes how we handle personal data of account holders and website visitors;
- the pricing and plan descriptions published on behindgate.com at the time of purchase.
If these documents conflict, the order of precedence is: the DPA for personal data we process on your behalf, the Privacy Policy for personal data we process as controller, the published pricing and plan descriptions for fees and plan entitlements, then these Terms, then the SLA, then the AUP.
2. Business customers only
The Service is offered to businesses, public bodies, and other organisations for use in their trade or profession. It is not offered to consumers. You confirm that you are not acting as a consumer and that consumer protection legislation does not apply to this agreement.
3. Accounts
3.1 You must provide accurate account details and keep them current. You are responsible for all activity under your account, including activity by the members you invite and by any deploy tokens, API keys, or agents you authorise.
3.2 You must keep credentials, deploy tokens, and keys confidential and notify us without undue delay at security@behindgate.com if you suspect unauthorised use.
3.3 Each account must have at least one administrator with a working email address. Notices under these Terms are sent to the administrator email addresses on the account.
4. The Service
4.1 BehindGate hosts static sites and applications (“Apps”) and makes them available only to people who authenticate through the viewer authentication method you choose (“Viewers”). The available methods are a customer-managed identity provider (Microsoft Entra ID, Google Workspace, or another OIDC provider you control), which is the expected method for production use, and email one-time codes (“email OTP”), which exist primarily to make trials and evaluation easy. We do not run server side code for your Apps.
4.2 We may change, improve, or discontinue features of the Service. We will give at least 30 days’ notice by email before removing a feature that materially reduces the functionality of your plan, except where the change is required by law, by a security concern, or by a third party provider.
4.3 We may use third party providers, including cloud infrastructure and payment processors, to deliver the Service. Providers that process personal data on your behalf are listed in the Sub-processor List.
5. Plans, trial, and payment
5.1 Fees are based on the plan you select and the pricing published on behindgate.com, or an order form where one applies, at the time you subscribe or change plan. Fees exclude VAT and other taxes, which are added where applicable.
5.2 A free trial starts when you first deploy an App and runs for the period stated on behindgate.com. No payment card is required for the trial. When the trial ends without a paid plan, Viewers see a trial-ended page on your domain until you subscribe. Your content is not published elsewhere or made public.
5.3 Subscriptions are billed in advance, monthly or annually, through our payment processor. Any usage based charges under your plan are billed monthly in arrears. By subscribing you authorise recurring charges to the payment method on file.
5.4 Subscriptions renew automatically for the same period unless cancelled before the renewal date. Cancellation takes effect at the end of the current billing period.
5.5 Plan changes take effect immediately. On an upgrade, the difference for the remainder of the current period is charged at once. On a downgrade, the lower price applies from the next billing period and no proration or credit is given for the current period.
5.6 Fees are non-refundable, except as expressly stated in Sections 13.4, 14.4, and 16.2, in the DPA, and in the SLA. Nothing in these Terms limits refunds required by mandatory law.
5.7 If a payment fails, we will notify you and retry. If the fees remain unpaid 14 days after the due date, we may suspend the Service under Section 13 until payment is received. Overdue amounts bear interest under the Finnish Interest Act.
5.8 Price changes follow the procedure in Section 15 and apply from your next billing period after the notice period.
6. Your content
6.1 You retain all rights to the content you publish through the Service (“Customer Content”). You grant us a non-exclusive, worldwide, royalty-free licence to host, store, copy, transmit, and display Customer Content solely to provide, secure, and support the Service and as instructed by you.
6.2 You are responsible for Customer Content, for the domains you connect, and for your viewer authentication configuration, including the access rules in your identity provider and any allowed domains or allowed addresses for email OTP. You confirm that you have the rights needed to publish Customer Content and that it complies with the AUP and applicable law.
6.3 We do not review Customer Content and have no obligation to do so. We may remove or disable access to Customer Content that violates the AUP or the law, or in response to a valid legal request, and will notify you where the law allows.
6.4 Customer Content is confidential to you. We access it only to provide, secure, and support the Service, to comply with law, or with your permission. Our staff do not view Customer Content in the ordinary course of operating the Service.
7. Viewers and viewer authentication
7.1 You decide who counts as a Viewer through your viewer authentication configuration. With a customer-managed identity provider, your provider decides who can sign in, and we rely on its assertions. We are not responsible for its configuration, availability, or the accuracy of its data.
7.2 With email OTP, you decide who can sign in by configuring allowed email domains, individual allowed email addresses, or both. You do not need to provide or maintain a viewer directory. When a Viewer signs in with email OTP, we process the email address that Viewer provides to authenticate them and establish their session, as described in the DPA.
7.3 You are responsible for informing Viewers about the processing of their personal data in connection with the Apps you publish, as described in the DPA.
7.4 Viewers do not need a BehindGate account and are not parties to these Terms. You are responsible for their compliance with the AUP when they use your Apps.
8. Acceptable use and fair use
8.1 You must comply with the AUP. The AUP includes fair use limits on traffic, storage, and request volume that keep the Service reliable for all customers.
8.2 If your use exceeds fair use, we will normally contact you first to agree a solution, which may include moving to a plan that fits your usage. Where excessive use threatens the security or stability of the Service, we may throttle or suspend the affected Apps immediately and notify you afterwards.
9. Our software and intellectual property
9.1 We and our licensors own the Service, including its software, design, documentation, and trademarks. These Terms grant you a limited, non-exclusive, non-transferable right to use the Service during the term for your internal business purposes.
9.2 You must not copy, modify, reverse engineer, resell, or sublicense the Service, or use it to build a competing product, except where the law expressly permits.
9.3 If you give us feedback about the Service, we may use it without restriction and without owing you anything.
10. Security and data protection
10.1 We maintain technical and organisational measures appropriate to the risk of the Service, as described in the DPA. We keep the Service in a fail-closed design: if a Viewer cannot be verified, the request is denied.
10.2 The DPA governs personal data that we process on your behalf. The Privacy Policy governs personal data of account holders and website visitors that we process as controller.
10.3 We will notify you without undue delay of a personal data breach affecting data we process for you, as set out in the DPA.
11. Confidentiality
Each party will keep the other party’s non-public information confidential, use it only to perform this agreement, and protect it with at least reasonable care. This does not apply to information that is public through no fault of the receiving party, was already known to it, is independently developed, or must be disclosed by law, in which case the receiving party will notify the other where permitted. These obligations survive for three years after the agreement ends, and indefinitely for Customer Content and trade secrets.
12. Warranties and disclaimers
12.1 We warrant that the Service will perform materially in accordance with its documentation and that we will provide it with reasonable skill and care.
12.2 Except as stated in Section 12.1 and the SLA, the Service is provided “as is”. We do not warrant that the Service will be uninterrupted or error free, that it will meet your specific requirements, or that any third party service, including your identity provider or domain registrar, will be available.
12.3 You are responsible for keeping a copy of your Customer Content. The Service is not a backup or archival service.
13. Suspension
13.1 We may suspend all or part of the Service for your account if: (a) your use violates the AUP; (b) fees are more than 14 days overdue; (c) your account or an App is used in a way that threatens the security, integrity, or availability of the Service or of others; (d) we are required to do so by law or by a court or authority; or (e) your identity provider or a connected domain is compromised.
13.2 Where practical, we will notify you before suspending and give you a reasonable opportunity to fix the issue. We will limit the suspension to what is necessary and lift it once the cause is resolved.
13.3 Suspension does not relieve you of the obligation to pay fees for the suspended period, except where the suspension was caused by our error.
13.4 If we suspend under Section 13.1(c) and it turns out that your account was not the cause, we will credit the fees for the period of suspension.
14. Term and termination
14.1 This agreement starts when you create an account and continues until terminated.
14.2 You may terminate at any time by cancelling your subscription and deleting your account in the dashboard. Termination takes effect at the end of the current billing period, and fees already paid are not refunded.
14.3 Either party may terminate with immediate effect by written notice if the other party materially breaches this agreement and does not cure the breach within 14 days of notice, or if the other party becomes insolvent, enters liquidation, or ceases business.
14.4 We may terminate this agreement for convenience with 30 days’ written notice. In that case we refund prepaid fees for the period after termination.
14.5 We may delete an account that has had no paid plan and no activity for 90 days after the trial ended, after sending a notice to the administrator email addresses at least 14 days in advance.
14.6 On termination: (a) your right to use the Service ends; (b) published Apps stop being served; (c) we delete Customer Content and account data within 30 days, and from backups within 90 days, except where retention is required by law; and (d) Sections 6.4, 9, 11, 12, 16, 17, 20, and 21 survive.
14.7 You may export your Customer Content from the dashboard at any time before termination. We do not provide an export after deletion.
15. Changes to these Terms
15.1 We may change these Terms, the AUP, the DPA, the SLA, and the Sub-processor List. Each document carries a version number and an effective date.
15.2 Changes to prices, plans, and other commercial terms take effect at the start of your next billing period, provided we have sent notice to the administrator email addresses at least 30 days before that date. If you do not accept such a change, cancel your subscription before the renewal date and it will not renew under the changed terms.
15.3 Changes required by law, by a court or supervisory authority, or to address a security risk, and changes to the DPA, take effect 30 days after notice by email, or sooner where the law or the risk requires. Changes to the Sub-processor List follow the notice and objection procedure in the DPA.
15.4 Non-material changes, such as clarifications and corrections, take effect when published on behindgate.com.
15.5 Continued use of the Service after the effective date is acceptance of the change. Administrators may be asked to accept the current version of the Terms when signing in after a change takes effect.
16. Indemnities
16.1 You will defend and indemnify us against third party claims, and the resulting damages, costs, and reasonable legal fees, arising from Customer Content, from your breach of the AUP, or from your use of the Service in violation of law.
16.2 We will defend and indemnify you against third party claims that the Service, as provided by us and used in accordance with these Terms, infringes a patent, copyright, or trademark in the European Union. This does not apply to claims arising from Customer Content, from your combination of the Service with other products, or from use after we have offered a non-infringing alternative. If such a claim arises, we may modify the Service, obtain a licence, or terminate the affected Service and refund prepaid fees for the unused period.
16.3 The indemnified party must notify the other party promptly, let it control the defence and settlement, and give reasonable assistance at the indemnifying party’s expense. No settlement may impose obligations on the indemnified party without its consent.
17. Limitation of liability
17.1 Neither party is liable to the other for indirect or consequential loss, or for loss of profit, revenue, business, goodwill, or data, however arising.
17.2 Each party’s total aggregate liability arising out of or in connection with this agreement, whether in contract, tort, or otherwise, is limited to the fees paid by you to us in the 12 months immediately before the event giving rise to the claim.
17.3 The exclusions and limitations in this Section do not apply to: (a) liability for death or personal injury; (b) liability caused by gross negligence or wilful misconduct; (c) your payment obligations; (d) your indemnity under Section 16.1; or (e) any liability that cannot be limited under applicable law.
17.4 Service credits under the SLA are your sole remedy for the availability shortfalls they cover.
18. Force majeure
Neither party is liable for a delay or failure caused by events beyond its reasonable control, including natural disasters, war, terrorism, labour disputes, government action, failure of the internet or of a third party provider, or a denial of service attack. Payment obligations are not excused. If the event continues for more than 30 days, either party may terminate the affected Service by written notice.
19. Publicity
We may name you as a customer and use your logo in a list of customers on behindgate.com and in marketing material, unless you ask us not to by email to legal@behindgate.com. We will not describe your use of the Service without your consent.
20. Notices
Notices from us to you are sent by email to the administrator email addresses on the account and are effective when sent. Notices from you to us must be sent to legal@behindgate.com and are effective when received. Either party may update its notice details by notifying the other.
21. Governing law and disputes
21.1 This agreement is governed by the laws of Finland, excluding its conflict of law rules and the United Nations Convention on Contracts for the International Sale of Goods.
21.2 The parties will first try to resolve a dispute by negotiation. A dispute that cannot be resolved within 30 days will be settled exclusively by the District Court of Helsinki, Finland. We may seek injunctive relief in any court of competent jurisdiction to protect our intellectual property or the security of the Service.
22. General
22.1 This agreement is the entire agreement between the parties on its subject matter and replaces all earlier agreements and representations.
22.2 You may not assign this agreement without our written consent. We may assign it to an affiliate or to a successor of our business on notice to you.
22.3 If a provision is found unenforceable, it will be enforced to the maximum extent permitted and the remaining provisions remain in force.
22.4 A failure to enforce a right is not a waiver of it.
22.5 The parties are independent contractors. Nothing in this agreement creates a partnership, joint venture, or agency.
22.6 This agreement is written in English. A translation is provided for convenience only and the English version prevails.
Contact
Rouhee Group Ltd, Business ID 2684686-4, Finland. Legal and contract matters: legal@behindgate.com. Security and vulnerability reports: security@behindgate.com.