BurroHost Services Agreement
Version 1.2, effective 8 October 2026. Changed from version 1.1 (8 October 2026): added the early-exit refund rule for yearly plans (clause 3).
Parties
Supplier: Gary O'Donoghue, trading as BurroHost ("BurroHost", "we"), hello@burrohost.com.
Client: the business named on the invoice ("the Client", "you"). You confirm you act for a business and not as a consumer.
1. The Order
"The Order" is your BurroHost invoice together with any order details we send you (for example a quote, order form or email) that name the services, the fees, the start date and anything specific to your business. This agreement sets the rules for every Order. If the Order and this agreement conflict, the Order wins for the services, fees and specifics it states; this agreement wins on everything else. Extra work (paid ads, new pages, extra locations) is quoted and agreed in a new Order before it starts.
2. Services
BurroHost provides the services listed in the Order. These can include: (a) a website, on your own domain name, which BurroHost registers in your name (clause 6); (b) hosting and upkeep; (c) an online booking system (self-hosted cal.diy); (d) management of your Google Business Profile (clause 9); (e) social media management, with posts approved by you first (clause 10); (f) a web chat AI assistant and a WhatsApp AI assistant (clauses 12 and 13); (g) booking alerts and reminders. Only the services in the Order apply to you; clauses about a service you did not order do not apply.
3. Fees and payment
- Fees. The fees are those in the Order. Recurring fees are charged in advance for each month. If the Order splits a fee into parts, each part is due on the date the Order gives. No tax is added by BurroHost unless the invoice says so; you handle any tax you owe.
- Card authorisation. When you accept this agreement and save your payment card with Stripe, you authorise BurroHost to charge it automatically for the amounts in the Order, including recurring monthly fees, until this agreement ends. Card details go to Stripe, never to BurroHost. Invoices and receipts are emailed from billing.burrohost.top.
- How to stop. Give 30 days' notice (clause 5) and automatic charging stops at the end of the notice period. You may also remove your card in the billing portal or by email; if you do so without giving notice, fees still fall due and BurroHost may invoice them by PayPal or other means.
- Fallback. If the card fails, BurroHost emails a payment link. You may pay manually by PayPal at the invoice amount plus PayPal's fee.
- Founding rate. If the Order states a founding rate, it is fixed for the period the Order states (12 months unless it says otherwise). After that, BurroHost may change the fee on 30 days' written notice; if you do not agree, you may end the agreement under clause 5. A change to your fees needs your agreement (clause 4).
- Yearly plans: early exit. If you pay for a yearly plan up front and leave before the year ends, we refund what you paid, minus the months used at the monthly price, minus the $149 setup fee.
- Non-payment. Nothing is paused or suspended automatically. If an amount is more than 14 days overdue, BurroHost may suspend the services until it is paid, but only as a personal decision by Gary O'Donoghue, after telling you. Your data is not deleted for non-payment while the clause 5 and clause 7 periods run.
4. Acceptance and changes to this agreement
- Acceptance. You accept this agreement by clicking to accept (for example "Next" or "I accept") and signing when you open or pay your first BurroHost invoice. The date, your name, your signature and your IP address are recorded as evidence. The agreement starts on that date. Services already running before then are covered by it.
- Updates. BurroHost can update this agreement by giving you 30 days' notice by email. If you keep using the services after the 30 days, you accept the update. If you do not agree, you may end the agreement under clause 5 before the update takes effect.
- Fees. A material change to your fees (other than a change under the founding-rate clause) needs your agreement; continued use alone is not enough.
- Other changes to the Order must be in writing (email or WhatsApp from each side's known contact is enough).
5. Term and exit
Month to month. Either side may end it with 30 days' written notice (email is enough). Services run to the end of the notice period.
6. Ownership, domain, and exit
- You own: your domain name, your business name and brand, your content (texts, photos, prices), your customer and booking data, your Google Business Profile and your Facebook, Instagram and WhatsApp accounts.
- BurroHost keeps: the website, its template and code, and the booking platform and automations. You may use them for as long as the agreement runs.
- Your domain. Your domain is registered in your name. You are the registrant and the owner. BurroHost manages the registrar account and the DNS for you while this agreement runs, and holds the logins. Registration and renewal fees are paid at cost, as shown in the Order.
- Moving your domain. You can ask for your domain to be moved to another registrar at any time, during the agreement or after it. On request BurroHost gives you the transfer (auth) code and unlocks the domain, within 5 business days, subject to registry rules (for example a 60-day lock on new registrations). This is free, and it is never held back for an unpaid invoice or any other reason. If you want BurroHost to do the transfer work for you, that is an optional service for a small admin fee (currently US$49, shown in the Order). You do not have to use it.
- Website files. On ending, you may buy a copy of the website files for a fixed fee equal to one month's fee (as shown in the Order), payable before delivery. BurroHost completes it within 14 days of payment and notice.
- Always free, never held back: an export of your content and your customer and booking data (standard file such as CSV/ZIP) within 30 days of you asking, and the domain transfer code described above.
- After the notice period your domain stays yours. BurroHost stops managing it and tells you where it is registered, and renewal is then your responsibility. BurroHost may let the website lapse and will not use your brand on a replacement.
7. After exit
BurroHost switches off the services at the end of the notice period, hands back access to everything you own, and deletes your customers' data within 30 days after the export is delivered (backups age out within 14 days), unless the law requires it to keep something.
8. Your responsibilities
You give accurate prices, hours, offers and descriptions and keep them current; you have the right to use every photo, logo and text you supply and supply nothing infringing or unlawful; you reply to approvals in reasonable time; and you run your own staff, services and health and safety. BurroHost is not responsible for errors that come from information you provided.
9. Google Business Profile
(Applies if the Order includes it.) You are and stay the Primary Owner. BurroHost is added as a Manager only. BurroHost will never hold ownership of, or remove you from, the profile. You can remove BurroHost's access at any time, and this clause continues after exit. BurroHost does not guarantee rankings or review numbers.
10. Social media and content approval
(Applies if the Order includes it.) BurroHost drafts posts for Facebook and Instagram (published via Postiz and Meta). Nothing is published until you approve it by WhatsApp or email. Once approved, the content is your responsibility. You let BurroHost hold the access tokens needed to post and can revoke them at any time.
11. Data protection
For your customers' data (bookings, chat, WhatsApp) you are the controller and BurroHost is the processor, acting on your instructions, under Annex A. Where it applies this follows the data protection law of your country and, for EU/UK visitors' data, GDPR. The sub-processors in Annex B are approved. For its own billing and contact data BurroHost is a controller (see the Privacy notice). You also authorise BurroHost to create anonymised statistics from the services under Annex A13.
12. AI assistants
The web chat and WhatsApp assistants are automated software using third-party language models (Annex B). They can be wrong or misunderstand, and give no medical, legal or clinical advice. The booking record is the official record, not the chat. You keep a human contact available and do not rely on the assistant for health matters. BurroHost will tell every customer at the start of a conversation that they are talking to an AI assistant, with a link to the privacy notice and a way to reach a person; you agree to leave that disclosure in place.
13. WhatsApp risk acknowledgement
(Applies if the Order includes the WhatsApp assistant.) The WhatsApp assistant uses an UNOFFICIAL automation layer (WAHA), not Meta's official WhatsApp Business API. This is against WhatsApp's terms. Meta can restrict or permanently ban the connected phone number at any time, without notice. If that happens the number, its contacts and chat history could be lost. BurroHost recommends a dedicated number, not your main line, and will move to the official API if you ask and pay any extra fees. BurroHost is not liable for a ban or interruption caused by Meta, beyond reasonable efforts to restore or migrate the service. By accepting this agreement you confirm you have read and accept this risk.
14. Availability and third parties
Services depend on Hetzner, Google, Meta, Stripe, PayPal and others. BurroHost does not guarantee uptime, bookings, rankings or revenue, and is not liable for outages outside its control.
15. Liability
BurroHost's total liability under this agreement is capped at the fees you paid in the previous 12 months. Neither side is liable for indirect losses (lost bookings, lost profit). Nothing limits liability that cannot lawfully be limited.
16. Notices
Notices to BurroHost go to hello@burrohost.com. Notices to you go to the email address on your invoice or account. Keep it current.
17. Governing law and disputes
This agreement is governed by the laws of Ireland. Both sides will first try to settle any dispute by talking, in good faith, for at least 30 days. If that fails, either side may use online mediation, or go to the courts of Ireland. Those courts have non-exclusive jurisdiction, so either side may also bring a claim in the courts of the client's own country. Nothing here stops either side from seeking urgent relief anywhere.
18. Whole agreement
This agreement and the Order are the entire agreement on these services and replace any earlier draft, message or agreement. If a part is unenforceable, the rest stays in force.
Annex A: Data processing terms (BurroHost as processor)
A1. Scope. BurroHost processes your customers' personal data (name, phone/WhatsApp number, email, treatment or service and booking time, promo code, chat/WhatsApp messages, session identifiers) only to provide the services and on your documented instructions, which include this agreement and the Order.
A2. Controller duties. You decide purposes, give your customers a privacy notice, hold any lawful basis or registration you need, and handle customer requests with BurroHost's help.
A3. Confidentiality. Anyone at BurroHost with access is bound to confidentiality. Operator access to raw customer data is limited to what a task needs and logged where the system allows.
A4. Security. Hetzner Germany hosting; TLS in transit; access controls and least privilege; credentials in a password vault; nightly backups kept up to 14 days. No payment card data is held.
A5. Sub-processors. You approve those in Annex B (also published on the Sub-processors page). BurroHost gives 30 days' notice of any addition or replacement; you may object on reasonable data-protection grounds and, if unresolved, end the agreement. BurroHost remains responsible for its sub-processors.
A6. Transfers. Data is processed in Germany (hosting) and sent to language-model providers outside the EU and outside your country (Annex B). You authorise these.
A7. Assistance. BurroHost helps you answer access, correction and deletion requests within statutory deadlines.
A8. Breach. BurroHost tells you without undue delay, within 48 hours of confirming a personal data breach affecting your data.
A9. Retention. Bookings 24 months after last visit; chat and message transcripts 90 days; then deleted.
A10. Return/deletion. On exit, free export and deletion as in clause 7.
A11. Audit. BurroHost provides reasonable information to show compliance, once a year on reasonable notice.
A12. Health data. The assistant is for bookings only and must not be used for health information. If customers volunteer it, BurroHost will not use it for anything else. This cannot be guaranteed technically.
A13. Anonymised statistics. You instruct and authorise BurroHost to produce anonymised, aggregated statistics from the services (WhatsApp/WAHA, web chat, bookings and billing), for example enquiry and booking counts, conversion rates, response times, service mix, prices, average spend, busy days and hours, and channel performance. BurroHost uses them to report to you, to improve its services and to benchmark and plan BurroHost's own and other projects. Rules: (a) statistics contain no names, phone numbers, emails, message text or anything that identifies a customer, and small groups that could single someone out are not reported; (b) BurroHost works on the raw data only inside its own systems to make the statistics, and the A9 retention periods still apply to the raw data; (c) the statistics may be kept after the agreement ends; (d) BurroHost never sells customer data, never contacts your customers for its own purposes, and never names you or shows your identifiable figures to anyone else without your written permission.
Annex B: Approved sub-processors
Full public list: Sub-processors. Those that apply to you depend on the services in the Order. At version 1.0: Hetzner (hosting, Germany); DeepSeek (hosted AI model, China) and OpenAI (AI model, United States) for the web chat and WhatsApp assistant; Meta/WhatsApp (messaging, global); Meta Facebook/Instagram (social posting); Stripe and PayPal (BurroHost's own billing of you, not customer data); Google (Business Profile, in your own account).