TurnKey

Legal

The four documents every TurnKey product runs under. They describe the systems we actually operate, so they change when the systems do.

Read this first. These documents were drafted in-house, from our own architecture, for a company at launch. They are templates pending review by counsel. Have a lawyer licensed in your jurisdiction review them before relying on them, and before signing a customer to them. Nothing on this page is legal advice.

entityNOVA CLOUD LLC, doing business as TurnKey
place of businessDawsonville, Georgia, United States
contactjimmy@turnkey.tech
version1.0
effective
statustemplate — counsel review pending

In all four documents, "TurnKey", "we", "us" means NOVA CLOUD LLC, a limited liability company doing business as TurnKey. "you" and "Customer" mean the business that buys a TurnKey service and the people it authorises. "Services" means anything we host, build or run for you, including Mercury, Atrium, Sisyphus, Speedrun, BlueLine and any open-source tool we host on your behalf.

1Terms of Service

↑ top · version 1.0 · effective 19 September 2026

1.1 The agreement

These Terms, the order you place (in our billing system at pay.turnkey.tech or in a written quote we both sign), the Acceptable Use Policy and, where we process personal data for you, the Data Processing Addendum, together form the whole agreement between us. A purchase order, a vendor portal's click-through or your own standard terms add nothing unless we sign them.

You accept these Terms when you place an order, sign in to a Service, or let us start work, whichever happens first.

1.2 What we provide

We build, host and maintain open-source business tools, and software we write ourselves, as a managed service. Each Service is described on its own page and in the order you place. Unless the order says otherwise:

1.3 Fees, onboarding fees and usage

  1. Subscription fees are billed in advance for each billing period, monthly or annually as your order states, and renew automatically for the same period until cancelled.
  2. Onboarding (setup) fees are one-time, due before work begins, and are earned when the onboarding work is performed. They are not refundable except under a written guarantee that says so. An annual plan may waive the onboarding fee; if you cancel an annual plan early, the waived fee becomes payable.
  3. Usage fees, where a Service meters them (for example language-model usage), are billed in arrears, itemised on your invoice, and capped at the limit on your plan. We do not bill above a cap you have set without your written agreement.
  4. Invoices are due on receipt unless the invoice states a term. Amounts unpaid 10 days after the due date may carry interest at 1.5% per month, or the maximum the law allows, whichever is lower, and we may suspend the Service after written notice.
  5. Prices are in United States dollars and exclude taxes. You are responsible for sales, use and similar taxes; we are responsible for taxes on our own income.
  6. We may change prices for a renewal term with at least 30 days' written notice before that term begins.

1.4 Guarantees

Some Services carry a written guarantee. The guarantee that applies to you is the one printed on that Service's page and in your order on the day you bought, together with its conditions; we keep a copy. Most guarantees are service guarantees: if we miss the stated outcome, we keep working at no further charge until we meet it. Where a guarantee offers a refund, it says so in those words. A guarantee does not apply if the conditions printed with it were not met.

1.5 Term, cancellation and suspension

  1. Monthly plans continue until either of us cancels. You may cancel at any time in your billing account or by writing to us; cancellation takes effect at the end of the paid period, and we do not pro-rate a partial month.
  2. Annual plans run for the term stated and renew unless cancelled at least 30 days before renewal.
  3. We may suspend a Service immediately if the Acceptable Use Policy is breached, if an account is compromised, if continued operation would break the law, or if an invoice is more than 30 days overdue. We restore it when the cause is fixed.
  4. Either of us may terminate for a material breach the other has not cured within 30 days of written notice.
  5. On termination, your right to use the Service ends, unpaid fees fall due, and section 1.6 governs your data.

1.6 Your data

Your content is yours. Everything you or your users put into a Service, and everything a Service produces for you, belongs to you. We claim no ownership of it and we do not sell it. We use it only to run and support the Service for you, and as the Privacy Policy and the DPA describe.

You can export your data from any Service at any time while your account is active. After termination, we keep your data for 30 days so you can export it, then delete it from live systems; encrypted backups age out on their own schedule, at most 90 days after termination. Ask us in writing and we will delete it sooner, unless the law requires us to keep it.

We do not train, fine-tune or evaluate models on your content. See the Privacy Policy for what happens when a Service calls a language model on your behalf.

1.7 Intellectual property and open source

We keep ownership of our software, configuration, designs and documentation, including anything we reuse across customers. You get a non-exclusive, non-transferable right to use it for your own business while your subscription is paid.

Most of what we host is open-source software under its own licence, which governs your use of that software; nothing here limits a right an open-source licence gives you. Where we build something for you that your order calls a custom deliverable, that deliverable is yours on payment in full, and any open-source components in it stay under their own licences.

You may give us feedback. We may use it without obligation.

1.8 Your responsibilities

1.9 Availability and support

We aim for the Service to be available at all times other than announced maintenance, and we publish live status at status.turnkey.tech. Unless your order contains a signed service-level agreement with credits, availability is a target, not a contractual commitment, and your remedy for an outage is the guarantee on your plan, if any.

Support is by email to jimmy@turnkey.tech during United States business hours, and we aim to answer within one business day.

1.10 Warranties and disclaimer

We warrant that we will provide the Services with reasonable skill and care, by qualified people, in line with this agreement. Except for that warranty, the Services are provided "as is". We disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement.

Language models produce text that can be wrong, and search and enrichment tools return data that can be out of date. We do not warrant that any model output, lead, takeoff, score or report is accurate, complete or fit for a decision you make. It is your work product once you use it.

We are not a law firm, an accounting firm, a licensed contractor, an estimator of record, or a provider of investment, medical or educational-placement advice. Nothing a Service produces is professional advice.

1.11 Limitation of liability

Neither of us is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data or business interruption, even if told such damages were possible.

Each party's total liability arising out of this agreement is capped at the fees you paid us for the affected Service in the 12 months before the event giving rise to the claim.

These limits do not apply to your obligation to pay fees, to either party's indemnity obligations, to a breach of the Acceptable Use Policy, or to liability that cannot be limited by law (including fraud, wilful misconduct, and death or personal injury caused by negligence).

1.12 Indemnities

We will defend you against a third-party claim that the software we wrote and host for you infringes that party's intellectual property, and pay damages finally awarded, provided you tell us promptly, let us control the defence and cooperate. We may modify or replace the affected part, or terminate it and refund fees paid for the unused period. This does not cover open-source components under their own licences, your content, or use of the Service contrary to this agreement.

You will defend us against a third-party claim arising from your content, from your use of a Service in breach of the Acceptable Use Policy, or from messages you send using our tools, and pay damages finally awarded.

1.13 Confidentiality

Each of us will protect the other's non-public information with at least the care we use for our own, use it only to perform this agreement, and disclose it only to people who need it and are bound to keep it confidential. This does not cover information that is public through no fault of the recipient, was already known, is independently developed, or must be disclosed by law — and if the law compels disclosure, the recipient will give notice where it lawfully can.

1.14 Publicity

We will not name you, use your logo or describe your results publicly without your written permission. Where we publish results without permission, we publish them without identifying you, in a form from which you cannot reasonably be identified. You may withdraw a permission you have given, and we will remove the material within 30 days.

1.15 Subcontractors

We may use subcontractors and third-party providers to deliver the Services, including the sub-processors listed in Annex III of the DPA. We stay responsible for their performance.

1.16 Changes to these Terms

We may change these Terms. For a material change we will give at least 30 days' notice by email to your account address and post the new version here with its effective date. If you object to a material change, you may cancel before it takes effect and we will refund any prepaid, unused subscription fees. The version that applies to a dispute is the one in force when the event happened; we keep the old versions.

1.17 General

This agreement is governed by the laws of the State of Georgia, United States, without regard to conflict-of-laws rules, and the state and federal courts sitting in Georgia have exclusive jurisdiction. Neither of us may assign this agreement without the other's consent, except to a successor of the whole business on notice. If a provision is unenforceable, the rest survives. A failure to enforce a right is not a waiver of it. Neither of us is liable for a delay caused by events outside our reasonable control. Sections on fees, data, intellectual property, disclaimers, liability, indemnities, confidentiality and general terms survive termination. Notices go to jimmy@turnkey.tech and to the email address on your account.

2Privacy Policy

↑ top · version 1.0 · effective 19 September 2026

This policy covers personal data TurnKey handles as a controller: data about our own customers, the people who use our Services, and the people who contact us. Where we handle personal data on a customer's behalf — the contents of their mailbox, their CRM records, their leads — we are a processor and the Data Processing Addendum governs it, not this policy.

2.1 What we collect

CategoryWhat it isWhy we have it
AccountYour email address, your organisation's name, the roles and organisations you belong to, sign-in timesTo let you sign in and to give your account only the Services it pays for. Sign-in is by one-time email code; we never hold a password for you.
BillingBilling name and email, invoices, the products and plans on your account, payment statusTo take payment and keep records the tax authorities require. We never see or store card or bank numbers — our payment provider does.
Service dataWhatever you put into a Service, and what it produces for youTo run the Service for you. Governed by the DPA; see section 2.6.
Usage and meteringWhich model a request used, how many tokens, what it cost, which account it belonged to, timestampsTo bill usage, cap it, and catch abuse. Prompt and response text is deliberately not stored in these records.
Operational logsRequest paths, status codes, latency, IP addresses, user agents, error tracesTo keep the platform up and secure. Some of it is stored as a salted hash rather than in the clear.
Sales and contactWhat you send us by email or a form: name, business, email, phone, what you asked for; notes from callsTo answer you and to run our own business. Held in our self-hosted CRM.
Business contact dataPublic business contact details (company, business address, business phone, published email) about businesses we may sell to, and about businesses our lead product researches for customersBusiness-to-business outreach. See section 2.7.

We do not ask for, and ask you not to send us, special-category data (health, biometric, political, religious), government identifiers, or payment card numbers.

2.2 Cookies and tracking

We run no advertising trackers, no analytics pixels and no third-party tracking cookies on any TurnKey site. We set a session cookie when you sign in, because sign-in needs one. Our pitch pages send one anonymous view beacon per visit so we can tell how many people saw a page; it stores a day, a product and a salted hash of your IP address, never a cookie or an identifier that follows you.

2.3 Why we may lawfully use it

Where the GDPR or UK GDPR applies, our bases are: performance of a contract (running the Service you bought, billing you); legitimate interests (keeping the platform secure, preventing abuse, business-to-business outreach, improving our own operations); legal obligation (tax and accounting records); and consent where we ask for it, which you can withdraw at any time.

2.4 Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only with:

2.5 Where it lives, and for how long

Customer data lives on servers TurnKey leases and operates, and backups live on storage TurnKey operates. We do not use a public cloud provider's managed database, file store or email service for customer data.

DataKept for
Account and sign-in recordsWhile the account exists, then 30 days
Invoices and payment records7 years (tax and accounting)
Model usage and spend records90 days, then deleted automatically
Operational logs30 days or less
Service dataWhile the account exists; 30 days after termination in live systems; backups age out within 90 days
Sales and CRM notesUntil you ask us to delete them, or 3 years after the last contact

2.6 Language models

Several Services call a language model on your behalf. When that happens:

  1. The call goes through our own gateway, which we operate. The gateway records who made the call, which model, how many tokens and what it cost. It is configured not to store the prompt or the response.
  2. The gateway sends the request to OpenRouter, which routes it to a model provider. OpenRouter and the provider it selects handle the request under their own published data policies, which we do not control.
  3. TurnKey does not train, fine-tune or evaluate any model on your data, and we do not give your data to anyone to train on. We cannot, however, promise on behalf of a downstream provider; if zero-retention routing matters to your business, tell us before you sign and we will agree it in writing.
  4. Model usage is billed per account so that one customer's usage is never mixed with another's.

2.7 Outbound business contact

We contact businesses about our services using business contact details that are published or lawfully obtained. Every message we send names us, gives our postal address and carries a working opt-out; reply "stop" and we stop, permanently. We do not cold-contact consumers, we do not send automated calls or texts, and we do not buy consumer lists. If a business tells us not to contact it, we record that and honour it across every TurnKey product.

2.8 Your rights

Wherever you live, you may ask us to show you the personal data we hold about you, correct it, delete it, export it in a portable format, restrict or object to a use, or withdraw a consent. We will answer within 30 days and we will not charge you or treat you worse for asking. Write to jimmy@turnkey.tech. If you are not satisfied, you may complain to your data protection authority; in the United States, to your state's attorney general.

If you reached us as a user of one of our customers' systems, ask that customer — we will forward your request to them and help them answer it.

2.9 Security

What we actually do is listed in Annex II of the DPA. In short: everything is encrypted in transit, secrets are encrypted at rest and never stored in plain text in our code repository, each customer is isolated, access is least-privilege and reviewed, backups are taken daily and test-restored, and automated assistants have no access to the infrastructure that runs them.

2.10 Children

Our Services are sold to businesses and are not directed at children under 13. One Service, Speedrun, is used by secondary-school students: it is bought by a parent, guardian or school, who provides the account, and we collect from the student only the work they do in the product. We do not show advertising to any user and we do not sell student data. A parent, guardian or school may ask us to delete a student's data at any time and we will do so within 30 days.

2.11 Changes

We post changes here with a new effective date, and email account holders before a material change takes effect.

3Data Processing Addendum

↑ top · version 1.0 · effective 19 September 2026

This Addendum forms part of the Terms of Service between TurnKey and the Customer and applies whenever TurnKey processes personal data on the Customer's behalf. Where this Addendum and the Terms conflict, this Addendum wins for data protection. It is offered pre-signed: accepting the Terms accepts this Addendum. A customer who needs a signed counterpart, or a different form, should ask.

3.1 Roles

The Customer is the controller (or a processor acting for its own controller) of the personal data it puts into the Services. TurnKey is the processor. Each of us complies with the data protection law that applies to it. The Customer is responsible for having a lawful basis, for giving the notices its own people and contacts are owed, and for the accuracy of what it sends us.

3.2 Instructions

TurnKey processes personal data only on the Customer's documented instructions: this Addendum, the Terms, the Customer's configuration of the Services, and any further written instruction the Customer gives. TurnKey will tell the Customer if an instruction appears to breach data protection law, and may suspend that instruction until it is resolved. TurnKey will not use the Customer's personal data for its own purposes, will not sell it, and will not train models on it.

3.3 Confidentiality and people

Everyone TurnKey allows near customer data is bound by confidentiality, gets access only where their work needs it, and loses that access when the work ends.

3.4 Security

TurnKey implements the technical and organisational measures in Annex II, appropriate to the risk, and will not materially weaken them during the term.

3.5 Sub-processors

The Customer gives general authorisation for the sub-processors in Annex III. TurnKey imposes data protection terms on each of them no less protective than this Addendum, and remains liable for their acts and omissions. TurnKey will give at least 30 days' notice before adding or replacing a sub-processor, by email to the account address and by updating Annex III. If the Customer reasonably objects on data protection grounds within that period, the parties will work in good faith to find an alternative; if none is found, the Customer may terminate the affected Service and receive a refund of prepaid, unused fees.

3.6 Data subject requests

Taking account of the nature of the processing, TurnKey will help the Customer answer data subject requests — access, correction, deletion, portability, restriction, objection — by the tools in the Services and, where those are not enough, by reasonable assistance. If a request reaches TurnKey directly, TurnKey will not answer it itself (beyond telling the person to contact the Customer) and will forward it to the Customer without undue delay.

3.7 Personal data breach

TurnKey will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer's data, with the facts known at the time: what happened, what categories and roughly how many records and people are affected, the likely consequences, what we are doing about it, and a contact. Updates follow as the facts firm up. TurnKey will not delay a notice in order to complete an investigation.

3.8 Assistance

TurnKey will give the Customer reasonable help with data protection impact assessments and prior consultations, so far as they concern processing by TurnKey and the Customer cannot answer from the information TurnKey already publishes.

3.9 Deletion and return

On termination, and on written request at any time, TurnKey will delete or return the Customer's personal data. Live systems are cleared within 30 days; encrypted backups age out on their normal cycle, within 90 days of termination, and remain protected by this Addendum until they do. TurnKey may keep data the law requires it to keep, for the period the law requires and for no other purpose.

3.10 Audit

TurnKey will make available the information needed to show compliance with this Addendum, and will answer a reasonable security questionnaire once in any 12-month period. Where the Customer's law gives it an audit right, the parties will agree a scope, time and confidentiality first; the Customer bears its own costs and TurnKey's reasonable costs, and an audit may not disrupt the Services or expose another customer's data.

3.11 International transfers

TurnKey processes and stores customer data on infrastructure it operates. Where a transfer of personal data out of the European Economic Area, the United Kingdom or Switzerland takes place, it is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor, and Module Three where the Customer is itself a processor), or the UK Addendum to them, which are incorporated here by reference and completed by Annexes I to III. The parties agree that Clause 17 chooses Irish law and Clause 18 chooses the Irish courts, unless the Customer's own law requires otherwise.

3.12 Liability

Each party's liability under this Addendum is subject to the limitation of liability in the Terms.

Annex I — the processing

Data exporterThe Customer, as described in its order. Contact: the account's billing email.
Data importerNOVA CLOUD LLC dba TurnKey, Dawsonville, Georgia, United States. Contact: jimmy@turnkey.tech.
Subject matterProviding the Services the Customer has bought.
DurationThe term of the agreement, plus the deletion periods in 3.9.
Nature and purposeHosting, storage, retrieval, drafting and analysis performed by the Services at the Customer's instruction; transmission to a language-model provider where the Customer uses a feature that calls one.
Categories of data subjectThe Customer's staff and authorised users; the Customer's own customers, prospects, candidates and contacts, to the extent the Customer puts them into a Service; students and their parents or guardians, for Speedrun.
Categories of personal dataIdentifiers (name, business email, business phone, business address); employment and role data; message and document contents the Customer places in a Service, including email the Customer connects; commercial records (deals, invoices, bids); assessment results, for Speedrun.
Special categoriesNone requested, none required, and the Customer is asked not to submit any.
FrequencyContinuous, for the term.
Competent supervisory authorityWhere the SCCs apply, the authority of the exporter's establishment.

Annex II — technical and organisational measures

These are the measures TurnKey operates today, not aspirations.

AreaMeasure
Encryption in transitTLS on every public endpoint, certificates renewed automatically, HTTP Strict Transport Security on every host, nosniff and frame protections by default.
SecretsEvery credential is encrypted at rest with age-based encryption before it enters the configuration repository; plain-text secrets are never committed, printed to a log, or shown in a support channel. Credentials used for temporary work are rotated in the same session.
Access controlSingle sign-on with one-time email codes and no passwords. Administrative access is limited to named accounts on an explicit allowlist. Machine identities get the narrowest role that works, and a policy in the cluster refuses to grant administrative rights to an identity that is not on the allowlist.
Tenant isolationOne namespace per product; every query in a multi-tenant product is filtered by the tenant's organisation identifier, and tests prove that a cross-tenant read or write fails. Per-customer assistants hold per-customer credentials only.
Assistant containmentAssistants that work inside a customer's business have no access to the infrastructure that runs them: their service-account tokens are scoped so the cluster's API rejects them. They draft; a person sends.
Third-party account accessConnections to a customer's own accounts (mail, CRM, calendar) use OAuth through a broker we run; tokens are stored encrypted and the customer can revoke them at the provider at any time.
BackupsDaily volume backups and continuous database backups to storage TurnKey operates, retained on a rolling schedule and verified by restore drills. A deletion is never performed without a completed, verified backup.
MonitoringPublic endpoint probes with a live status page, cluster health checks, alerting on failures, and a written incident record.
Change controlAll infrastructure is declared in a private Git repository and applied by an automated reconciler; a manual change to a live system is reverted automatically. Changes are reviewed before they are applied and every change is attributable.
Data minimisationPrompt and response text is excluded from usage records. IP addresses in product analytics are stored as salted hashes. Unused data stores are retired after a verified backup.
ResilienceMulti-node cluster, replicated storage, automatic rescheduling on node failure, and a documented restore procedure that has been exercised end to end.
PeopleTurnKey is operated by a small, named team under confidentiality obligations; every person with access is on the allowlist above and is removed when their work ends.

Annex III — sub-processors

The full list, as of . Customers are notified at least 30 days before this list changes.

Sub-processorWhat it does for usData it can see
OpenRouter, Inc. (United States) and the model providers it routes toRuns the language-model requests our Services makeThe contents of a request a Service sends to a model, and its response
PayPal, Inc. (United States)Takes payment and runs subscriptionsBilling name, billing email, amounts, payment status. TurnKey never receives card or bank numbers.
Hosting providers of the servers TurnKey leasesProvide the physical machines and network our platform runs onNo application access; they hold the hardware on which encrypted and running data sits. The current list is available on request.
Namecheap, Inc. (United States)Domain registration and DNSDomain records only. No customer content.
Cloudflare, Inc. (United States)DNS hosting for some domains and validation of TLS certificatesDomain records only. No customer content.

Public data sources a Service reads on a customer's instruction — for example OpenStreetMap for business locations, or a job board for hiring signals — are sources, not sub-processors: we send them no customer data.

4Acceptable Use Policy

↑ top · version 1.0 · effective 19 September 2026

This policy applies to everyone who uses a TurnKey Service. It is short on purpose: the rule is that you may not use our tools to do something that is illegal, deceptive, or damaging to someone else.

4.1 You may not

  1. Break the law, or help someone else break it, with our tools.
  2. Send unsolicited commercial email that does not name a real sender, give a real postal address and carry a working opt-out; ignore an opt-out; send to a purchased or scraped consumer list; or use a false header, a misleading subject line or a disguised sending identity. Our lead tools draft messages and never send them for you: sending them is your act, under your name, and the law applies to you.
  3. Send automated calls or text messages to consumers, or contact any person or business that has told you or us to stop.
  4. Impersonate a person, a company or a public body; or generate content designed to make a reader believe it comes from someone it does not.
  5. Upload or generate malware, run a denial-of-service attack, scan or probe systems you do not own, or try to reach another customer's data, our infrastructure, or a part of a Service you were not given.
  6. Reverse engineer, resell, sublicense or white-label a Service without written agreement, or let someone outside your organisation use your account.
  7. Use the Services for sexual content involving minors, content that sexualises a real person without consent, harassment or threats, incitement to violence, or the promotion of self-harm.
  8. Use the Services to make a decision about a person's credit, employment, housing, insurance or education without a qualified human reviewing it, or in any way that discriminates on a protected characteristic.
  9. Give a language model, through our Services, the data of a person who has not been told about it and would not expect it: medical records, government identifiers, payment card numbers, or special-category data.
  10. Consume shared resources — compute, storage, model usage, crawling — in a way that degrades the Service for others, or work around a usage cap.
  11. Publish, as unaided human work, output a model produced for you where the reader's decision depends on that distinction.

4.2 What we expect instead

4.3 How we enforce it

If we believe this policy is being broken, we will normally contact you first and give you a chance to fix it. Where the breach is causing harm, exposing data, or breaking the law, we may suspend the affected Service or account immediately and tell you straight after. Repeated or deliberate breaches end the agreement under section 1.5. We will cooperate with a lawful request from an authority and will tell you unless we are forbidden to.

4.4 Reporting abuse

Report abuse of a TurnKey service, or a security vulnerability, to jimmy@turnkey.tech. We answer security reports within one business day. Please give us a reasonable time to fix a vulnerability before disclosing it; we will not pursue a good-faith researcher who reports one and does not access, alter or keep other people's data.