Terms of Service
Last updated: 19 July 2026
These terms describe how TEQcloud works: what the service covers, where its edges are, and how billing is handled. They apply to the use of this website and serve as the plain-language reference for our engagements. Where a signed agreement with a client differs from this page, the signed agreement prevails.
Who runs this site
This website is operated by TEQcloud, a sole proprietorship owned by Quinten de Haard, registered with the Dutch Chamber of Commerce (KvK).
- KvK number: 99552434
- VAT (BTW): NL005394507B47
- Registered in: Elst, Netherlands
- Contact: info@teqcloud.net
What this site is
A description of the services TEQcloud provides, including pricing. Nothing on this website constitutes a binding offer or a contract. Any actual engagement begins with a written agreement signed by both parties.
Scope of service
This section explains, in plain language, what the monthly retainer covers and where the edges are. It exists so that nobody buys a plan expecting something it was never meant to include. The short version: we operate the Kubernetes you own. We do not host it, build your application, or guarantee anything outside business hours.
What “managing your cluster” means
You keep ownership of the cluster. It runs on your own account or hardware: AKS, EKS, GKE, on-prem, or a VPS. We receive a kubeconfig and the minimum access needed to do the work, and nothing more. If you leave, you keep everything. There is no infrastructure of ours to be locked into.
Our visibility is bounded by that kubeconfig. We can see and act on what Kubernetes can see: pod scheduling, ingress, certificates, persistent volume claims, CSI behaviour, node readiness as the cluster reports it. We do not by default see or manage the node operating system, the hardware underneath, the cloud account itself, or the code inside your application. Those remain yours, or become a separately scoped project.
Health checks
Periodic, preventive review of cluster state: resource usage, certificate expiry, workload health, and security posture. Frequency follows the plan (monthly on Maintenance, weekly on Administration, continuous monitoring on DevOps). A health check is a look and a written note, not an open-ended remediation budget. Fixes that follow come out of your retainer hours.
Upgrades and patching
We plan, test, and execute upgrades of the Kubernetes control plane and the node-level Kubernetes components, and of the platform components we manage for you (for example the ingress controller, cert-manager, CNI, CSI driver, CoreDNS).
Patching scope is Kubernetes and the components we run, not general operating-system fleet vulnerability management. Keeping every package on every host patched is a separate discipline and, unless explicitly agreed, your responsibility.
A critical CVE in something we manage is handled out of band, meaning outside the normal scheduled upgrade window, as soon as it is practical within business hours.
Monitoring and alerts
We set up and refine alerting so that an alert means something: tuning thresholds, routing, and noise reduction on a stack such as kube-prometheus-stack with Alertmanager, or on your existing tooling. The system watches continuously. Human attention is business hours only. Refining alerts is in scope; authoring bespoke dashboards or going deep into observability tooling as a product is not, and would be project work.
If no monitoring exists yet, standing it up is an onboarding project, not something the monthly retainer silently absorbs.
Incident response
When something breaks at the Kubernetes layer during the hours your plan covers, we pick up the kubeconfig, diagnose, and fix it, then write down what happened. Diagnosis is bounded by what the cluster API exposes. Failures rooted in the node operating system, the hardware, the network underneath, or your application code fall outside the Kubernetes layer; we will say so plainly and, where we can help, scope it separately.
Networking, ingress, certificates
We keep the plumbing working and make changes on request: ingress (ingress-nginx or Traefik), cert-manager, internal DNS, NetworkPolicies. Keeping it running and adjusting it when you ask is in scope. Authoring a complete network-security model from scratch is design work and would be a project.
RBAC, secrets
Least-privilege roles and secret rotation, applied on request and watched for expiry. We avoid holding standing plaintext access to your secrets; access is least-privilege and, where needed, break-glass rather than permanent.
Deployments
We operate your delivery: rolling out what you hand us through Helm or Argo, for example a new image or an updated value. We do not author your Helm charts, write your Dockerfiles, or build your application, even as project work. What is possible here depends on your CI/CD system; we work with what you have rather than imposing a pipeline.
What we do not do
- We do not host your applications. Your cluster is yours.
- We do not offer 24/7 on-call. We work business hours (CET). A P1 is a P1 regardless of plan, but the clock runs during business hours. If genuine round-the-clock cover is a hard requirement, we are honestly not your supplier, and we will say so at intake rather than pretend.
- We do not build your application, its container images, or its Helm charts.
- We do not manage your operating-system fleet, CI/CD product, or full-stack vulnerability surface. Our patching scope is Kubernetes and the components we run.
We can advise on Kubernetes architecture, cluster bring-up (including Talos), GitOps with Argo, and adjacent infrastructure decisions as scoped project work. That is consulting from the Kubernetes seat, billed separately, not part of the retainer.
Response and availability
Response priority is flat across plans: a genuine emergency is treated as an emergency whether you are on Maintenance or DevOps. What the plans buy is hours and cadence, not a different definition of “urgent”. All response happens within business hours. Work that an emergency forces outside the retainer is unplanned work, billed at the unplanned rate by agreement.
Prices and VAT
All prices on this site are excluding VAT. That applies to the monthly retainers, the hourly rates, and fixed-price work such as the cluster audit. Dutch law adds 21% BTW on top of every amount we invoice.
For business clients registered in another EU member state, the reverse-charge mechanism normally applies: we invoice at 0% VAT and you account for it under your own VAT registration. Your invoice states the treatment that applies to you.
Hourly rates
Every hourly rate on this site follows one distinction: was the work planned, or not?
- Planned work: €100 per hour (excluding 21% BTW). Project work, onboarding and intake work, scheduled improvements, and planned on-site visits. The retainer plans are built on this rate: hours bought in advance are planned hours.
- Unplanned work: €150 per hour (excluding 21% BTW). Ad-hoc requests outside your retainer, emergency support beyond what your plan covers, and unplanned on-site visits. It is priced higher because unplanned work bumps the rest of the schedule; everyone else’s planned work waits while yours gets handled.
All hourly billing is in 30-minute increments, rounded to the nearest half hour. This applies across the board: planned work, unplanned work, and travel.
Billing and engagement
- Fixed monthly retainer. The included hours are an envelope, not a target. Quiet months subsidise busy ones; quiet months end quiet.
- Project work is planned work: €100/hour. Scheduled, scoped and quoted up front before any work starts.
- Above-retainer hours are unplanned work: €150/hour, agreed in advance. When a month genuinely needs more than your plan covers, we flag it first. Structural overflow is a signal to move up a plan rather than to run a small plan permanently over its ceiling.
- Onboarding and setup are billable. Establishing access, VPN, kubeconfig, accounts and initial monitoring is planned project work, not free retainer time.
- Work is remote by default. On-site visits happen where genuinely needed and are agreed in advance. Travel is billed as described below.
- Cancellation: one calendar month notice. Notice given partway through a month runs to the end of the following whole calendar month, which is billed in full whether or not the hours are used. That final month is yours to spend: offboarding and handover, or continued maintenance, your call. Handover work beyond the retainer is planned, so it is billed at the planned rate, not the unplanned one. We hand over documentation and access cleanly and do not retain clients through friction.
Travel and on-site work
When we work on site, travel time is billable:
- Travel follows the same planned-versus-unplanned distinction as the visit itself: €100 per hour for a planned visit, €150 per hour for an unplanned one (both excluding 21% BTW).
- We count the total round-trip travel time, rounded to the nearest half hour, and bill it in 30-minute increments. A 40-minute round trip is billed as 30 minutes; a 47-minute round trip is billed as 60 minutes.
- Travel time is not taken from your retainer hours. It is billed on top, alongside the on-site work itself.
Cluster audit
An optional, fixed-price, one-off engagement: read-only access, a written report on control-plane health, workloads, networking, certificates, RBAC, secrets handling and observed risks, and a prioritised list of what to fix first. Paid once, no obligation to continue. A deeper audit aimed at a specific concern is scoped separately as hourly project work.
Reporting
Reporting scales with the plan and with what you actually want. Lower plans get a brief written summary; higher plans and on-request engagements get a fuller report. It is an account of what was sensible to do for the hours spent, not a fixed deliverable you are owed regardless of circumstance.
Use of the site
You may read, link to, and quote from this site for normal informational purposes. You may not:
- Scrape or republish substantial portions of the site without attribution.
- Use the content to train commercial language models without our written permission.
- Attempt to compromise the security or availability of the site.
Accuracy
We make a reasonable effort to keep the information on this site current and correct. Pricing, certifications and service descriptions can change. Where a discrepancy exists between this site and a signed agreement, the signed agreement prevails.
Liability
The website is provided “as is”. We are not liable for damages resulting from reliance on information published here outside of a signed engagement. This does not limit any liability that cannot be excluded under Dutch law.
Governing law
These terms are governed by the laws of the Netherlands. Disputes arising from the use of this website are subject to the exclusive jurisdiction of the competent court in the district of our registered address.
Changes
We may update these terms from time to time. Material changes will be reflected in the “Last updated” date at the top.