Effective Date: 01 February 2026
Applicable To: All clients, partners, licensees, resellers and authorised shared-service operators using Fludnox hosting, backup or infrastructure services.
This Backup and Data Recovery Policy (“Policy”) governs the creation, storage, availability, restoration and deletion of backups connected with hosting and infrastructure services supplied by The Xdemór Group Limited under the Fludnox brand.
In this Policy, “You” and “Your” refer to the business, organisation or professional using the Services and any person authorised to act on its behalf. “Fludnox”, “We”, “Us” and “Our” refer to The Xdemór Group Limited acting under the Fludnox brand. “Services” means the applicable Fludnox hosting, infrastructure, backup and restoration services. “Content” means all websites, applications, databases, files, email, configurations, credentials, logs, media and other information stored or processed through the Services.
1. Application of this Policy #
1.1 Contractual Status #
This Policy forms part of the contractual framework governing the Services and applies together with the Shared Services Terms of Service, the Shared Services Data Processing Agreement, the Fludnox Hosting and Infrastructure Policy, the applicable Service Description, Order Form or Individual Agreement and any other policy incorporated into the Services.
Where an Individual Agreement or Order Form expressly provides different backup or recovery terms, that document shall prevail to the extent of the inconsistency. The Shared Services Data Processing Agreement shall prevail in relation to the deletion, return, restriction or lawful retention of personal data.
1.2 Acceptance #
You accept this Policy when You order, activate, renew, access or use a Service that includes or may involve backup, restoration, snapshot, replication or disaster-recovery functionality.
1.3 No Implied Backup Service #
The existence of technical backup, replication, snapshot or recovery functionality within a hosting environment does not mean that You have purchased a backup service or acquired a contractual right to access any copy created for Fludnox’s internal operational purposes.
A backup service is included only where it is expressly identified in the applicable Service Description, Order Form or Individual Agreement.
2. Types of Backup #
2.1 Operational Backups #
Fludnox or its authorised infrastructure providers may create operational backups, snapshots, replicas or recovery copies for business continuity, infrastructure maintenance, incident response, disaster recovery or service resilience.
Operational backups are maintained primarily for Fludnox’s internal recovery purposes. Unless expressly stated otherwise, You have no direct access to them and no right to require that a particular operational backup be retained, supplied, exported or restored.
The creation of an operational backup does not relieve You of Your obligation to maintain independent copies of Your Content.
2.2 Managed Backup Services #
Where Your purchased Service expressly includes managed backups, Fludnox will create backups in accordance with the frequency, retention, storage allocation and scope stated in the applicable Service Description or Order Form.
A managed backup service provides a mechanism for requesting or initiating restoration from an available restore point. It does not constitute a guarantee that every backup will be complete, free from corruption or capable of restoring every application, integration or item of Content.
2.3 Snapshots and Replicas #
A snapshot or replicated environment may be designed for rapid infrastructure recovery and may not constitute an independent or historically retained backup.
Replicas may reproduce corruption, deletion, malware, configuration errors or other defects from the source environment. They must not be treated as a substitute for separate retained backups.
2.4 Archives #
A backup is not an archive unless the applicable Service expressly includes archival storage.
Standard hosting and operational backup Services must not be used as long-term record storage, general file storage, email archiving, regulatory archiving or a records-management system.
3. Backup Scope and Schedule #
3.1 Applicable Schedule #
The applicable Service Description or Order Form will identify, where included, the scheduled backup frequency, retention period, available restore points, storage allocation and any included restoration allowance.
Where no schedule is expressly stated, no specific backup frequency, retention period, recovery point or restoration time is guaranteed.
3.2 Rolling Retention #
Backups may be maintained on a rolling basis. When the applicable retention period or storage allocation is reached, the oldest restore points may be overwritten or deleted automatically without further notice.
A backup may cease to be available before the end of the nominal retention period where it is corrupted, incomplete, infected, technically incompatible, subject to lawful removal or excluded under this Policy.
3.3 Timing #
Backup times may vary according to system load, data volume, maintenance, security incidents, infrastructure availability and the operation of the relevant backup platform.
A scheduled backup time is an operational target and does not guarantee that a valid restore point will be created at precisely that time.
3.4 Changes to Backup Configuration #
Fludnox may change the technical system, storage platform, backup window, encryption method or operational process used to create backups, provided that the overall protection expressly included in Your Service is not materially reduced without appropriate notice.
Urgent changes may be implemented without prior notice where reasonably necessary for security, legal compliance, service continuity or the protection of backup integrity.
4. Backup Content and Exclusions #
4.1 Included Content #
A backup may include website files, databases, email, account configurations and other Content associated with the applicable Service, but only to the extent supported by the selected plan and backup system.
The fact that Content is stored within a Service does not guarantee that it is included in every backup.
4.2 Excluded Content #
Fludnox may exclude temporary files, cache files, generated files, session data, logs, mail queues, spam folders, local backup archives, redundant copies, system files, files exceeding applicable limits and Content not reasonably required to restore the principal operation of the hosted Service.
Backups created by You and stored inside the hosting account may be excluded from Fludnox backups. Nested backups may also be removed where they create excessive storage use, instability or operational risk.
4.3 External Systems #
Unless expressly included, Fludnox does not back up third-party platforms, external software-as-a-service accounts, external DNS providers, external email accounts, payment platforms, advertising accounts, social-media accounts, source-code repositories or systems located outside the applicable Fludnox Service Environment.
4.4 Client-Managed Encryption #
Where Content is encrypted using a key, password or mechanism controlled exclusively by You, You are responsible for securely retaining the information required to decrypt and restore that Content.
Fludnox is not required to recover encrypted Content where the relevant key, password or recovery material is unavailable, incorrect or damaged.
5. Storage Allocation and Backup Eligibility #
5.1 Storage Limits #
Managed backup Services may be subject to a maximum protected data volume, storage allocation, file count, database size or account size.
Where Your Content exceeds the applicable limit, backup creation may fail, become incomplete, be suspended or exclude the affected Content.
5.2 Exceeded Quotas #
You are responsible for monitoring the storage and backup limits applicable to Your Service.
Fludnox may notify You where a backup quota has been exceeded, but failure to send or receive a notification does not extend the applicable storage allocation or create liability for a missed backup.
Backup protection may resume only after the Content is reduced, the Service is upgraded or additional capacity is purchased. Backups missed while a quota was exceeded may not be created retrospectively.
5.3 Unsupported Accounts #
Accounts or datasets exceeding the technical maximum supported by the applicable backup system may be excluded from that system.
Fludnox may require migration to another Service, a customised backup arrangement or an external archival solution before backup protection can continue.
6. Client Backup Responsibilities #
6.1 Independent Copies #
You must maintain independent and current copies of all Content that is critical to Your operations, legal obligations, regulatory responsibilities or business continuity.
Your independent copies must be stored separately from the affected Fludnox hosting account and should not depend on the same credentials, infrastructure or failure domain.
6.2 Backup Verification #
You are responsible for verifying that Your required Content is being backed up and that Your independent copies can be accessed and restored.
Dashboard indicators, automated notices and successful backup messages do not replace appropriate verification and testing.
6.3 Business Continuity #
You remain responsible for Your own business-continuity, disaster-recovery, records-retention and regulatory-archiving requirements.
Unless expressly agreed otherwise, Fludnox does not determine Your required recovery point objective, recovery time objective, statutory retention period or acceptable level of data loss.
6.4 Material Changes #
Before performing significant updates, migrations, imports, deletions, software changes, database operations or configuration changes, You must create and verify an appropriate independent backup.
You must not assume that an immediate Fludnox restore point exists unless the relevant backup has been confirmed as available.
7. Backup Integrity and Limitations #
7.1 Reasonable-Efforts Basis #
Unless an Individual Agreement expressly states otherwise, backups are created and retained on a reasonable-efforts basis.
Fludnox does not warrant that every backup will be created successfully, contain every item of Content, remain available for the full nominal retention period or restore every component without error.
7.2 Source Defects #
A backup may contain or reproduce defects already present in the source environment, including corrupted files, deleted data, application errors, unauthorised changes, malware, compromised credentials and incompatible software.
Fludnox is not responsible for verifying the legal, operational or substantive accuracy of the Content contained in each backup.
7.3 Backup Failure #
Backups may fail or become unavailable because of hardware failure, software failure, corruption, excessive data volume, storage exhaustion, unsupported files, encryption issues, network interruption, upstream failure, Client configuration, malware, force majeure or circumstances outside Fludnox’s reasonable control.
Fludnox will take reasonable measures to maintain backup systems included in the Services, but no backup system eliminates all risk of data loss.
7.4 No Sole-Reliance Warranty #
The Services are not supplied as the sole mechanism for protecting Your Content.
Your failure to maintain independent backups may be taken into account when determining responsibility for loss, recovery costs or the availability of contractual remedies, subject to applicable law and the Shared Services Terms of Service.
8. Restoration Requests #
8.1 Request Procedure #
A restoration request must be submitted through the authorised Fludnox support channel and must identify the affected Service, requested restore point and Content to be restored.
Fludnox may require identity, authority or account verification before performing a restoration.
8.2 Availability #
A restoration can be performed only from an available and technically usable restore point.
The display of a date, snapshot or backup record does not guarantee that the corresponding restore point is complete or recoverable.
8.3 Restoration Scope #
Unless otherwise agreed, Fludnox may restore the entire account, website, database, mailbox or other technical unit supported by the backup system.
Granular restoration of individual files, messages, tables, records or configuration items may be unavailable or subject to additional charges.
8.4 Effect of Restoration #
A restoration may overwrite or remove Content created or modified after the selected restore point. It may also change databases, credentials, application states, email, configurations or permissions.
You must ensure that any current Content requiring preservation has been independently copied before restoration begins.
8.5 Client Authorisation #
By approving a restoration, You authorise Fludnox to replace or modify the affected Content to the extent reasonably necessary to perform the requested operation.
Fludnox may require written confirmation of the restoration scope and acknowledgment of the overwrite risk.
8.6 Testing After Restoration #
You must promptly test the restored website, application, database, email and connected services.
Fludnox does not guarantee that third-party software, external integrations, payment systems, APIs, licences or DNS configurations will operate correctly following restoration.
Any post-restoration correction outside the included Service scope may require separate work and payment.
9. Restoration Times and Priority #
9.1 No Implied Recovery Time #
No particular restoration or recovery time is guaranteed unless it is expressly stated in an applicable Service Level Agreement or Individual Agreement.
Estimated restoration times are not binding and may vary according to data volume, backup condition, incident severity, system demand and infrastructure availability.
9.2 Incident Priority #
Fludnox may prioritise restoration work according to the severity and scope of an incident, the number of affected clients, security requirements and the need to protect shared infrastructure.
Infrastructure-wide recovery may take priority over an individual restoration request.
9.3 Emergency Restorations #
Emergency, expedited, out-of-hours, repeated or complex restoration work may be subject to additional charges where it is not included in the applicable Service.
Fludnox will disclose the applicable charge before beginning chargeable work where reasonably practicable.
10. Malware, Abuse and Unlawful Content #
10.1 Infected Backups #
Fludnox may refuse to restore, quarantine or delete a backup that contains malware, malicious code, compromised files, phishing content or other material prohibited under the Fludnox Hosting Acceptable Use Policy.
Where technically practicable, Fludnox may offer a partial, cleaned or isolated restoration as separate chargeable work.
10.2 Reintroduction of Risk #
You must not require Fludnox to restore Content where You know or reasonably suspect that doing so would reintroduce malware, compromise, unlawful material or a material security vulnerability.
Fludnox may require evidence of remediation before restoring an affected environment to public access.
10.3 Investigations and Preservation #
Where a backup is relevant to a security incident, abuse complaint, legal claim or competent-authority request, Fludnox may preserve or restrict the affected backup where required or permitted by law.
Preservation for investigation does not create a right for You to access the preserved copy.
11. Suspension and Non-Payment #
11.1 Backup Creation During Suspension #
Backup creation may stop when a Service is suspended, expired, disabled or materially restricted.
Fludnox does not guarantee that new backups will be created during a suspension period.
11.2 Existing Backups #
Existing backups may continue to expire or be overwritten during suspension in accordance with the normal retention cycle.
Suspension does not freeze, extend or restart a backup-retention period unless Fludnox confirms otherwise in writing.
11.3 Restoration During Suspension #
Fludnox may refuse restoration or non-mandatory export work while valid charges remain unpaid, subject always to mandatory obligations concerning personal data under the Shared Services Data Processing Agreement and applicable law.
Payment after a backup has expired does not require Fludnox to recreate or recover the expired copy.
12. Expiry and Termination #
12.1 Client Responsibility Before Termination #
Before a Service expires or terminates, You must download or otherwise obtain any Content that You wish to retain and verify that the exported copy is usable.
You must not rely on Fludnox backups remaining available after the Service ends.
12.2 End of Backup Service #
When the underlying hosting Service or backup add-on expires or terminates, backup creation and Client-accessible backup management may stop immediately.
Associated restore points may enter automatic deletion or overwrite cycles and may become unavailable without further notice.
12.3 No Post-Termination Guarantee #
Fludnox does not guarantee any post-termination period during which backups will remain available, unless such a period is expressly stated in the applicable Order Form, Service Description or Shared Services Data Processing Agreement.
Any discretionary assistance provided after termination does not create an ongoing obligation or modify the original retention cycle.
12.4 Reactivation #
Reactivation or repurchase of a Service does not guarantee that any backup from the previous Service period remains available.
Where a previous restore point still exists, Fludnox may make access or restoration conditional on technical feasibility, account verification and payment of the applicable restoration or reactivation charges.
13. Personal Data in Backups #
13.1 Data-Protection Roles #
Where backups contain personal data processed by Fludnox on Your behalf, You ordinarily act as Controller and The Xdemór Group Limited ordinarily acts as Processor.
The Shared Services Data Processing Agreement and the Fludnox Hosting Data Processing Schedule govern that processing.
13.2 Return and Deletion #
At the end of the applicable processing service, personal data will be returned or deleted in accordance with the Shared Services Data Processing Agreement, Your documented choice and applicable data-protection law.
Nothing in this Policy permits Fludnox to disregard a mandatory obligation concerning the return, deletion, restriction, security or lawful preservation of personal data.
13.3 Rotational Backup Deletion #
Where immediate deletion of an individual item from a rotational backup is not technically practicable, the affected data may remain within a protected backup until that backup is overwritten or securely destroyed under the applicable retention cycle.
During that period, the data will not be restored to active use except where necessary for legitimate recovery, legal compliance or an authorised investigation. Where a full backup is restored, relevant deletion or restriction instructions must be reapplied where technically and legally required.
13.4 Data Subject Requests #
You remain responsible for determining and responding to requests from data subjects.
Fludnox will provide the assistance required under the Shared Services Data Processing Agreement, taking into account the nature of the processing and the technical characteristics of the relevant backup system.
13.5 Storage Locations #
Backup processing locations, authorised subprocessors and applicable international-transfer safeguards are identified in the Fludnox Subprocessor and Data Location Register and the Shared Services Data Processing Agreement.
14. Security of Backups #
14.1 Appropriate Measures #
Fludnox will apply appropriate technical and organisational measures to backups containing personal data or confidential Client Content, having regard to the risks, available technology and nature of the applicable Service.
The detailed security obligations governing personal data are contained in the Shared Services Data Processing Agreement and the Fludnox Hosting Data Processing Schedule.
14.2 Access Control #
Access to operational backup systems will be limited to authorised personnel and service providers requiring access for administration, restoration, security, incident response or lawful compliance.
14.3 Encryption #
Backups may be encrypted in transit and at rest according to the technical controls applicable to the selected Service and storage environment.
No representation concerning a particular encryption standard, key-management model or storage architecture applies unless expressly stated in the applicable Service Description, security schedule or Individual Agreement.
14.4 Security Incidents #
A confirmed personal-data breach affecting Client personal data contained in backups will be handled under the Shared Services Data Processing Agreement and the applicable incident-response procedure.
15. Legal Holds and Required Retention #
Fludnox may suspend deletion or preserve an affected backup where retention is required by applicable law, court order, regulatory direction, legal claim, fraud investigation, security investigation or another legally recognised preservation obligation.
Data retained under this section will be restricted to the relevant purpose and retained only for as long as the applicable obligation or legitimate requirement continues.
Where legally permitted and operationally appropriate, Fludnox will notify You of a material preservation requirement affecting Your Content.
16. Charges and Additional Work #
Restoration, export, forensic recovery, data extraction, granular recovery, recovery from damaged media, malware remediation, post-termination assistance and work outside the normal backup tooling may be chargeable.
No fee will be charged where the applicable Service expressly includes the requested operation within a stated allowance.
Where work is chargeable, Fludnox may require advance payment before allocating resources or beginning the operation.
Payment for recovery work does not guarantee that the requested Content is recoverable.
17. Liability #
Liability arising from backups, restoration or data recovery is governed by the Shared Services Terms of Service and any applicable Individual Agreement.
To the fullest extent permitted by applicable law, Fludnox is not responsible for loss arising from Your failure to maintain independent backups, Your selection of an unsuitable retention period, excluded Content, exceeded quotas, source corruption, malware, Client-managed encryption, unsupported software, expired restore points or Your failure to verify a restored environment.
Nothing in this Policy excludes or limits liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence or any other liability that cannot lawfully be excluded or limited.
18. Support and Notices #
Backup and restoration requests must be submitted to support-fludnox@shared-services.co or through the authenticated Fludnox support channel.
Formal contractual or legal notices must be sent to legal@xdemor.com.
Privacy or personal-data matters must be submitted through the applicable Shared Services privacy request procedure or to privacy@xdemor.com. Matters requiring the attention of the Data Protection Officer may be submitted to dpo@xdemor.com.
A support request does not constitute a formal legal notice unless Fludnox expressly confirms otherwise.
19. Changes to this Policy #
Fludnox may amend this Policy to reflect changes in law, technology, backup systems, security requirements, Service design, storage architecture or operational arrangements.
Except where an urgent exception applies, Fludnox will provide reasonable notice before a material amendment takes effect.
A shorter period or immediate amendment may apply where required by law, security, incident response, an urgent infrastructure requirement, abuse prevention or protection of service continuity.
Continued use of the affected Service after the effective date of a properly notified amendment constitutes acceptance of the amended Policy.
20. Governing Law and Related Documents #
This Policy and any non-contractual obligations arising from it are governed by the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction, subject to any mandatory rule that cannot lawfully be excluded.
This Policy operates together with the contractual documents published through the Shared Services Policy Portal at https://policies.shared-services.co/, including the Shared Services Terms of Service, the Shared Services Data Processing Agreement, the Fludnox Hosting and Infrastructure Policy, the Fludnox Hosting Acceptable Use Policy, the Fludnox Service Level Agreement and the Fludnox Migration, Suspension and Termination Procedure.