Terms and Conditions
Terms of service for Xeon Creative Last updated: 24 August 2026
These Terms and Conditions (the “Terms”) apply when you visit xeon-creative.com, contact Xeon Creative, accept a quote or proposal, purchase a service, install or use Xeon Creative software, connect an account to a Xeon Creative MCP service, or use hosting, websites, SEO, AI or creative services supplied by Xeon Creative.
They are intended to work alongside the proposal, quote, statement of work, order form, invoice, service schedule or subscription details that apply to your specific purchase (together, the “Project Agreement”). The Project Agreement sets out the commercial details for that engagement, such as the scope, deliverables, price, billing schedule, hosting plan, support level, revision allowance, notice period and launch date. If there is a conflict between these Terms and a Project Agreement, the Project Agreement controls the project-specific point in question and these Terms control everything else.
Please read these Terms before using the site or services. If you do not agree with them, do not use the site, software, hosting or services.
1. About Xeon Creative
Xeon Creative is a UK-based web design, hosting, search engine optimisation, AI, MCP and creative services business founded and led by Tom Cullen. Xeon Creative works with sole traders, start-ups, small businesses and growing organisations in Wirral, Liverpool, Chester, Manchester, the North West and across the UK.
For questions, support or formal notices, contact:
- Email: [email protected]
- Telephone: 07776 215125
- Public location: Wirral, Merseyside, CH48 2LA, United Kingdom
- Website: xeon-creative.com
Before publishing this page, the legal name of the contracting party, full postal address and company or VAT details (if applicable) should be added here and kept consistent with your invoices and proposals.
2. Definitions
In these Terms:
- “Xeon Creative”, “we”, “us” or “our” means the Xeon Creative business identified in section 1.
- “You” or “your” means the person, sole trader, partnership, company or other organisation using the site or buying the services.
- “Business Customer” means a customer entering into an agreement wholly or mainly for business, trade, profession or commercial purposes.
- “Consumer” means an individual acting wholly or mainly outside their business, trade, craft or profession.
- “Client Materials” means text, images, video, audio, logos, fonts, data, products, prices, accounts, credentials, code, documents and other material supplied or approved by you.
- “Deliverables” means the final work product expressly included in the relevant Project Agreement.
- “Services” means any web design, development, hosting, domain, migration, maintenance, SEO, AI, MCP, automation, analytics, paid advertising, PPC, content, campaign, social media, video, branding, design, print, training, consultation or related service supplied by us.
- “Software” means any plugin, theme, script, code, MCP server, connector, dashboard, integration, documentation, template or other software supplied by us.
- “MCP Service” means a local, hosted or remote service using the Model Context Protocol or a similar integration layer to expose information, tools or actions to an AI client or other software.
- “Internal MCP Systems” means MCP servers, control planes, worker connections, dashboards, bridges, repositories, credentials, prompts, configurations, logs and other MCP or automation infrastructure that we operate for our own internal business operations or service delivery. Internal MCP Systems are not client-facing Services unless a Project Agreement expressly says otherwise.
- “Client MCP System” means an MCP server, connector, client, automation, dashboard or related integration that we build or configure specifically for you to own, control and manage in your own accounts or environment.
- “Maintenance Package” means a recurring website, hosting, security, backup, update, support, optimisation or monitoring package described in a Project Agreement.
- “Retainer Service” means a recurring arrangement under which you reserve an agreed amount of our time, capacity or ongoing output for a defined period and scope.
- “Connected Account” means a WordPress, hosting, domain, email, analytics, advertising, social, finance, cloud, AI, model, API or other third-party account that you authorise us or a Service to access.
- “Third-Party Service” means a service not operated by Xeon Creative, including WordPress, Elementor, Wix, Squarespace, Shopify, WooCommerce, Google, Google Analytics, Google Tag Manager, Google Search Console, Google Ads, Meta, Instagram, Facebook, LinkedIn, TikTok, FreeAgent, Cloudflare, hosting providers, domain registrars, email providers, payment processors, AI model providers and API providers.
3. When a contract is formed
A contract may be formed when any of the following happens, unless the Project Agreement says otherwise:
- you accept a quote, proposal or order form in writing or electronically;
- you pay a deposit, first invoice or subscription fee;
- you ask us to start work after receiving a quote or proposal;
- you install, activate or use paid Software or an MCP Service; or
- you give us access to an account and instruct us to carry out the relevant work.
If you accept on behalf of an organisation, you confirm that you have authority to bind that organisation. The organisation is responsible for the acts and omissions of its authorised users.
An enquiry, discovery call, audit or general recommendation does not create an obligation to provide Services until a Project Agreement is accepted or we otherwise confirm the engagement.
4. What Xeon Creative provides
Our Services may include the following. This list is illustrative rather than exhaustive; the Services included in your purchase are the Services stated in your Project Agreement.
4.1 Websites and digital products
- WordPress, Elementor, WooCommerce and Shopify website design and development;
- landing pages, campaign pages, sector pages and event or booking websites;
- sector-specific websites and landing pages for trades, therapists, yoga instructors and studios, personal trainers, life or business coaches and other businesses;
- website packages, including Launch-Pad, Orbit, Apex, Launch-Pad+, Orbit+ and Apex+ packages where offered;
- existing website amends and content refreshes, including Wix, Squarespace, WordPress and Elementor edits;
- website emergencies, recovery, technical fixes, bug investigation, plugin or theme conflicts, SSL and mixed-content fixes, mobile and browser fixes, page-speed and Core Web Vitals work, broken links, redirects and 404 resolution;
- WordPress audits, security reviews, spring cleans, database and image optimisation, UX, UI and conversion-rate optimisation;
- property listing, search, filtering, booking-handoff and property-management-platform integrations, including Guesty where expressly agreed;
- online quote forms, enquiry funnels, product pages, listing pages, blogs, custom post types and customer journeys;
- website training, launch support, maintenance, migrations and handover;
- ecommerce configuration, product uploads, payment and delivery integrations;
- domains, DNS, SSL, CDN, caching and hosting where expressly included; and
- website audits, diagnostics, implementation plans and technical documentation.
4.2 SEO, GEO and SEO AI
- technical, on-page, off-page, local, content and AI-search SEO;
- keyword research, search-intent analysis and content planning;
- titles, headings, metadata, structured data, internal links, canonical and crawl signals;
- Google Analytics 4, Google Tag Manager, Google Search Console, Google Business Profile and conversion tracking setup;
- schema, robots.txt, sitemaps,
llms.txt, Markdown content negotiation and AI-discovery improvements; - SEO reporting, measurement, experiments, content recommendations and conversion analysis; and
- Software or services that use automation or AI to assist with SEO, structured data, content, audits, evidence gathering or reporting.
SEO and AI-discovery work is intended to improve clarity, technical accessibility, search visibility and decision-making. It does not guarantee a search position, AI citation, traffic level, lead volume, sale, booking, return on advertising spend or other commercial result.
4.3 MCP, automation and connected systems
Xeon Creative uses Internal MCP Systems to run parts of our own business and to support the delivery of Services. Our Internal MCP Systems are not client-facing products. Clients do not receive access to our internal MCP servers, CEO control plane, worker connections, dashboards, credentials, repositories, prompts, configurations, logs or private endpoints unless a Project Agreement expressly identifies a separate access arrangement.
We may also build or configure a separate Client MCP System for you. A Client MCP System is not the same as our Internal MCP Systems. Unless the Project Agreement says that we are providing an ongoing managed service, you must own, control and manage the Client MCP System, its accounts, credentials, hosting, connected systems, subscriptions, data, security and ongoing operation.
Client MCP Services and related Software may include:
- client-specific WordPress/Elementor control surfaces and MCP integrations;
- client-owned installations of Xeon SEO & AI or technical SEO/GEO Software where expressly agreed;
- a client-specific MCP server, control surface, automation or operator workflow;
- configuration or integration of data from Google Analytics, Google Search Console, Google Ads, Meta Ads, FreeAgent, WordPress, Elementor, Cloudflare or other supported systems;
- local or hosted MCP servers, HTTP bridges, dashboards, connectors, scripts and deployment packages;
- read-only evidence collection, analysis, proposals, dry runs, guarded actions, approval workflows and audit logs;
- integrations with other systems that we agree to support; and
- documentation, training and handover for your Client MCP System.
The exact tools, permissions, transports, limits, support arrangements and supported versions depend on the Project Agreement, Software version, configuration, credentials and Third-Party Services available at the time. A tool being listed in documentation does not mean that the relevant third-party account is authenticated, available or authorised for your use.
4.4 Hosting, infrastructure and support
Where included, we may provide or arrange:
- shared or managed website hosting;
- WordPress installation, updates, staging, backups, caching and performance configuration;
- domain registration or transfer assistance;
- DNS, SSL, CDN, email-routing and security configuration;
- hosting migrations, recovery and rollback planning;
- ongoing website maintenance, technical support and monitoring;
- Maintenance Packages, Retainer Services and ongoing website growth support; and
- hosting for Software, MCP services, dashboards or automation workers.
Hosting is subject to the package limits, fair-use rules, provider terms and technical environment set out in the Project Agreement.
4.5 Creative services
- logo design, brand identity, guidelines, colour and typography systems and creative direction;
- graphic design, bespoke graphics, UI/UX design, advertising creative and content for digital and print;
- social media strategy, post design, scheduling and management across platforms such as Instagram, Facebook, LinkedIn and TikTok;
- promotional videos, short-form video, reels and product showcases;
- business cards, flyers, brochures, branded merchandise, business signage and other printed materials; and
- investor pitch decks, business presentations and related creative direction.
Creative engagement models
Creative and growth work may be provided as a One-off Mission, Sustained Growth arrangement, Strategic Partnership, Graphic Design Retainer, UX/UI Design Retainer, Growth Retainer or Strategic Partnership Retainer. These labels describe possible ways of working only. The Project Agreement controls the actual deliverables, content volume, meeting or support expectations, reserved capacity, revision allowance, timetable and price.
4.6 Marketing, analytics and growth services
Where expressly agreed, we may provide Google Ads or other PPC setup, management and optimisation, Google Analytics 4 and Google Tag Manager event or conversion tracking, local SEO and Google Business Profile support, content strategy, multi-channel campaigns, reporting, conversion-rate optimisation and related lead-generation or growth work. Advertising budgets, media spend, platform fees and third-party subscriptions are separate unless the Project Agreement expressly includes them.
5. Proposals, scope and changes
5.1 Scope
We will provide the Deliverables described in the Project Agreement. Anything not expressly included is outside scope, even if it appears technically related to the project.
Examples of work that may be outside scope include additional pages, products, languages, integrations, content writing, photography, video editing, copy changes after approval, migration of historic data, emergency work, custom functionality, additional revision rounds, paid advertising spend, third-party licence fees and ongoing support.
5.2 Changes and additional work
You may request a change at any time. We will confirm whether the change affects the price, timeline, Deliverables or technical approach. We are not required to start additional work until you approve the revised scope or estimate.
If you ask us to proceed urgently before a written variation is issued, the request may be charged at the rate in the Project Agreement or our then-current rate, and the timeline may change.
5.3 Bespoke pricing and customer expectations
Website builds, website amendments, ecommerce work, SEO, creative work, MCP Services, hosting, Maintenance Packages and Retainer Services are priced for the individual customer unless the Project Agreement expressly says otherwise. The price is based on the agreed build, platform, number and type of pages, products or listings, functionality, integrations, content responsibility, SEO or AI-search work, analytics, migration, design process, revisions, training, launch requirements, support expectations, deadline, hosting and third-party costs.
Package names and any prices, ranges, “starting from” figures, examples or typical inclusions shown on our website or in marketing material are not a promise that the same scope or price applies to every customer. They are general guidance only. The final bespoke price, scope, assumptions, customer responsibilities, timetable and expectations are those set out in the accepted Project Agreement. We will confirm the agreed price before work begins, and any material change must be approved under section 5.2.
5.4 Estimates
Quotes and time estimates are based on the information available when they are prepared. A quote may be withdrawn or expire if its stated validity period ends, a Third-Party Service changes its pricing or functionality, or the assumptions on which it was based are no longer accurate.
6. Your responsibilities
You agree to:
- give us accurate, complete and timely instructions, information, copy, images, data, product details and approvals;
- provide the access, permissions, accounts and credentials needed for the agreed work;
- provide the agreed content, business information, product or listing information, brand assets and other project inputs by the dates stated in the Project Agreement;
- provide required licences and administrator access at project start, keep relevant decision-makers available and give one consolidated response where a consolidated response is requested;
- keep your own copies of important files, databases, website content, email and business records;
- review proofs, staging sites, reports, AI outputs, recommendations and proposed actions carefully before approving them;
- tell us promptly about errors, security concerns, unauthorised activity or changes made by another provider;
- maintain ownership or appropriate licences for all Client Materials and Connected Accounts;
- keep hosting, domain, email, plugin, theme, platform and API licences and administrator accounts in your own name or under your organisation’s control where the Project Agreement requires this;
- ensure that your products, claims, prices, offers, testimonials, policies, marketing and content comply with applicable law and platform rules;
- obtain permissions for people, music, images, fonts, stock assets, testimonials, trademarks, personal data and other material you ask us to use;
- use secure password-management and access practices and never send private keys, application passwords, API tokens or other secrets in a public prompt, repository or unsecured message;
- use MCP Services, Software, hosting and Connected Accounts only for lawful and authorised purposes;
- provide final testing, launch permissions, DNS access and other launch cooperation when required; and
- pay all fees, balances and Third-Party Service charges due under the Project Agreement.
You remain responsible for the decisions made by your business and for checking whether a Deliverable, recommendation, AI output, website, advertisement, automation or connected action is suitable for your circumstances.
7. Client Materials and content approval
You grant us a non-exclusive, worldwide, royalty-free licence to use, reproduce, modify, store and display Client Materials only as reasonably necessary to provide the Services, prepare backups, test a staging environment, communicate with you, meet our legal obligations and maintain records.
You confirm that:
- you have the rights and permissions needed for us to use the Client Materials as instructed;
- the Client Materials do not infringe another person’s rights or breach confidentiality, privacy, advertising, consumer-protection or other legal requirements; and
- any final content you approve is suitable for publication and use by your business.
We may refuse, remove or ask you to replace content that appears unlawful, defamatory, infringing, unsafe, deceptive, malicious or unsuitable for the relevant Third-Party Service. We are not responsible for claims, errors or losses caused by Client Materials or instructions that you supplied or approved.
For ecommerce websites, you are responsible for product descriptions, prices, stock, taxes, shipping, returns, refunds, age restrictions, payment providers, consumer information, terms, privacy notices, cookie consent, accessibility and all other legal or operational requirements of selling online.
8. Project process, feedback and approval
Unless the Project Agreement says otherwise:
- a project begins when the required deposit, information and access have been received;
- we will show work in progress through the agreed communication method;
- you should provide consolidated feedback from the relevant decision-makers;
- approval may be given by email, project-management message, written confirmation or another clear electronic instruction;
- a Deliverable that you approve may be treated as final, and later changes may be chargeable; and
- we may not launch or publish a website, campaign, automation or connected action until the required approval and payment have been received.
You should test a staging website or preview on the devices, browsers and workflows relevant to your business. A website, integration or automation is not treated as approved merely because it is technically available; however, continued use after delivery may be evidence of acceptance unless you have promptly reported a material issue.
Where a Project Agreement uses a fixed website timetable, you must provide consolidated feedback within the stated review period. If no period is stated, feedback should normally be returned within three Business Days. One consolidated review list may be included for a design or staging milestone; separate, late or additional feedback rounds may change the timeline or be charged as additional work.
9. Timelines and delays
Website timelines are bespoke. The Project Agreement may set milestone dates or a target launch date. If it does not, most small-business websites take a few weeks from project kick-off, but complex ecommerce, event or booking systems, large sites, integrations, migrations, content requirements and approval delays may take longer.
We are not responsible for delay caused by:
- late or incomplete content, access, feedback, payment or approval;
- changes to the scope or requirements;
- a Third-Party Service, registrar, hosting provider, platform, API, model provider, payment provider or external reviewer;
- security checks, DNS propagation, domain transfers, email migration or platform verification;
- inaccurate information or unauthorised changes made by you or another supplier; or
- an event outside our reasonable control.
If a delay is likely to be material, we will let you know and agree a revised plan where reasonably possible.
10. Websites, hosting, domains and infrastructure
10.1 Platforms and Third-Party Services
WordPress, Elementor, WooCommerce, Shopify, Google, Meta, Cloudflare, hosting providers, registrars, email providers, payment gateways, plugins, themes, APIs and other Third-Party Services are controlled by their own operators and terms. Their availability, prices, security, functionality, compatibility, verification decisions and future changes are outside our control.
Where a website sends a visitor to a property-management, booking or payment platform such as Guesty, that platform remains responsible for the relevant availability, pricing, payment, booking confirmation and transaction processing unless the Project Agreement expressly assigns a different responsibility. The website’s role may be to display information, provide search and filtering, and send the visitor to the third-party booking flow.
You are responsible for maintaining any account, subscription, licence or payment method that the Project Agreement places in your name. If we pay a Third-Party Service on your behalf, you must reimburse us or pay the relevant charge by the due date.
10.2 Hosting and fair use
Hosting is provided only within the storage, bandwidth, CPU, memory, mailbox, database, file, process, traffic and other limits of the selected plan. Unless a separate service level agreement says otherwise, hosting is provided on a best-efforts basis and does not include a guaranteed uptime percentage, recovery time or response time.
You must not use hosting to store or distribute malware, phishing pages, unlawful content, unauthorised copyrighted material, bulk unsolicited messages, abusive traffic, cryptocurrency-mining workloads, unauthorised proxies, credential-stuffing tools, denial-of-service tools or other activity that harms the infrastructure or another user.
We may limit, suspend or move a site, account, process, mailbox or service where this is reasonably necessary to protect security, availability, other customers, a provider’s network or legal compliance. We will give notice where reasonably possible.
10.3 Domains, DNS and email
Domain registration and account ownership
A domain belongs to the registrant named at the registrar, not automatically to the person who paid an invoice. Unless the Project Agreement says otherwise, you should be the registrant and keep the registrar account and renewal details under your control.
DNS, email and SSL changes
DNS, MX, SPF, DKIM, DMARC, nameserver, SSL and CDN changes can affect websites, email, forms, tracking and third-party verification. We will take reasonable care when carrying out agreed changes, but we are not responsible for delays or losses caused by registrar, DNS, email or provider propagation, blocking, filtering or configuration outside our control.
Email continuity
We do not provide a mailbox, email archive or email-continuity guarantee unless this is expressly included. You are responsible for retaining a suitable backup and business continuity plan for email.
10.4 Backups, migrations and recovery
We may create backups, staging copies or rollback points as part of a project. These are a safety measure, not a substitute for your own independent backups. Backup frequency, retention, storage location and restore testing depend on the Project Agreement and technical environment.
Migration work is performed with reasonable care and skill, but no migration can guarantee that every historic file, database record, email, plugin setting, redirect, form, API connection or third-party integration will transfer without change. You must check the migrated service and keep the source service available until you have approved the migration and rollback window has passed.
10.5 Updates and maintenance
Updates to WordPress, plugins, themes, PHP, browsers, APIs, models and hosting can create incompatibilities or change behaviour. We may recommend staging tests, backups or a separate maintenance package. Unless included in the Project Agreement, ongoing updates, security monitoring, content changes, uptime monitoring and emergency recovery are not included in a one-off website build.
10.6 Website maintenance packages and retainer services
Maintenance Packages and Retainer Services are recurring Services. They are designed to keep a website healthy, supported and improving within the limits of the selected package. They are not automatically a redesign, unlimited support plan, 24-hour emergency service or guarantee that a website will never experience an outage, vulnerability, incompatibility or performance issue.
Launch-Pad+ or entry-level maintenance
Where offered, an entry-level package may include the upkeep of the agreed domain and hosting, routine website and plugin updates, database and media optimisation, image installation or optimisation, basic technical upkeep and ordinary support. The exact inclusions, update frequency, backup arrangements, hosting limits and price are stated in the Project Agreement.
Orbit+ or content and local SEO maintenance
Where offered, an Orbit+ package may include everything in Launch-Pad+ plus an agreed allowance for page or content updates, on-page SEO, content optimisation, Google Business Profile management and related local search support. Any monthly time allowance, number of pages or updates, reporting, approval process and price are bespoke and must be stated in the Project Agreement.
Apex+ or growth maintenance
Where offered, an Apex+ package may include everything in Launch-Pad+ and Orbit+ plus Shopify or WordPress management, ecommerce or large-site support, custom post types or project pages, Google Analytics 4 and Google Tag Manager management, managed PPC or Google Ads, local SEO, campaign or content strategy, conversion-rate optimisation and deeper reporting. A bespoke growth engagement may also include new location or service landing pages, area guides, supporting blog content, internal-link improvements, listing-page checks, broken-link and redirect checks, ranking or indexing checks, testimonial and imagery updates, and other agreed growth work.
The number of pages, listings, articles, updates, checks, amendments and hours included is always the number stated in the Project Agreement. A package described as “monthly growth” does not guarantee a ranking, citation, traffic level, booking level or other commercial outcome.
Requests and service expectations
Unless the Project Agreement states otherwise, maintenance and retainer requests should be sent through the agreed email, ticket or project-management channel and should include the relevant URL, page, account, requested change, deadline and supporting content. We will triage requests by urgency, security, business impact and package scope.
Routine work is normally handled during Xeon Creative’s published business hours, Monday to Thursday, 09:00 to 17:00 UK time. This is a working-hours expectation, not a guaranteed response or resolution time. No 24/7 monitoring, emergency response, uptime commitment or service-level agreement applies unless expressly included in writing.
Reserved capacity, unused time and additional work
A Retainer Service reserves agreed capacity for the relevant billing period. It does not guarantee that every request will be completed immediately or that unused capacity will be converted into a refund. Unless the Project Agreement expressly allows carry-over, unused time, tasks or monthly outputs do not roll over automatically and cannot be exchanged for cash.
Work outside the package scope, work above an agreed limit, urgent work, additional revision rounds, major content creation, new functionality, redesigns, migrations, complex integrations, emergency recovery and work requiring another supplier may be quoted or charged separately.
What maintenance does not normally include
Unless expressly included, a Maintenance Package does not include a new website, a full redesign, a new theme or platform, custom application development, major database repair, historical data migration, email migration, domain disputes, third-party licence fees, advertising spend, PR, photography, video production, legal or compliance advice, extensive copywriting, guaranteed SEO results or recovery from a compromised or deleted site.
Client responsibilities during a package
You must keep the required accounts active, pay hosting and Third-Party Service charges, provide accurate content and approvals, maintain administrator access, tell us about changes made by others, review update or staging notices, keep independent backups where required, and ensure that your website content, forms, booking flow, cookies, analytics, products and customer data remain lawful and accurate.
Pausing, changing or ending a package
You may pause, change or end a Maintenance Package or Retainer Service only in accordance with the Project Agreement. If no notice period is stated, the default notice period for an ongoing monthly service is 30 days, subject to any minimum term and applicable Consumer law. A pause does not automatically preserve unused capacity or prevent Third-Party Service, hosting, domain or licence charges from continuing.
11. MCP Services, internal systems and client-owned MCP systems
The MCP systems we operate for Xeon Creative are separate from any MCP system we build for a client. The following rules apply to that distinction.
11.1 Internal MCP Systems
Internal operational infrastructure
Our Internal MCP Systems include the Xeon Creative CEO MCP, internal worker connections, internal dashboards, bridges, repositories, credentials, prompts, configurations, action logs and other private automation infrastructure that we use to operate our business or deliver Services.
No client access
Internal MCP Systems are not included in a client project and are not licensed, transferred or made available to clients. You must not request, use, probe, copy, reverse engineer or attempt to access them, their credentials, private endpoints, repositories, prompts, configurations or logs. We may use Internal MCP Systems internally to collect evidence, prepare work, manage our operations or provide a Service without giving you access to the underlying system.
11.2 Client-owned MCP Systems
Ownership and administrator control
If we build or configure a Client MCP System for you, you must own and control the relevant hosting, cloud, domain, code repository, model, API, platform and Connected Account subscriptions in your own name or under your organisation. You must retain primary administrator access and keep control of the master credentials. Our access should be limited to the permissions reasonably needed to build, support or maintain the agreed system.
Client management responsibilities
Unless the Project Agreement expressly includes ongoing managed MCP operations, you are responsible for managing the Client MCP System after handover. This includes users, permissions, credentials, secrets, connected accounts, data, backups, monitoring, updates, patches, rate limits, security, legal compliance, provider charges and incident response.
Optional managed service
We may provide hosting, maintenance, monitoring or managed support for a Client MCP System if this is expressly included in the Project Agreement. A managed service does not transfer ownership of your Client MCP System to us. You remain the owner and must retain a primary administrator account, while we operate only within the agreed support scope.
11.3 Authorisation
An MCP Service can only access a Connected Account when you or an authorised administrator provides the relevant permission, credentials, token or connection. You are responsible for deciding which accounts to connect, which permissions to grant and which people or agents may use the connection.
You must not connect an account that you are not authorised to access. You must revoke access and tell us promptly if a credential is exposed, an employee leaves, an integration is no longer needed or you suspect unauthorised use.
11.4 Tools, resources and actions
Tool results
An MCP Service may expose read-only resources, reports, drafts, recommendations or actions. A Connected Account may apply its own permissions and rules. A successful tool call does not guarantee that the third-party system accepted, saved, published, sent, billed or completed the requested action.
Approval and audit controls
Where a Service uses dry runs, proposal IDs, explicit approval phrases, confirm=apply, publish flags, audit logs or similar controls, those controls are intended to reduce accidental changes. They do not remove the need for you to inspect the proposed target, arguments, permissions, evidence and expected result before approving an action.
Platform and policy boundaries
You must not use an MCP Service to bypass authentication, capability checks, rate limits, approval gates, audit controls, robots rules, platform terms or another person’s privacy settings.
11.5 Local, hosted and remote operation
Local MCP servers, stdio processes, HTTP bridges, dashboards and deployment bundles may depend on your computer, operating system, Node.js or PHP version, environment variables, local network, firewall, browser, credentials and installed packages. A local bridge must not be exposed to the public internet without appropriate authentication, access controls and security review.
Hosted or remote MCP Services may depend on our hosting provider, a cloud platform, transport availability, worker configuration, API quotas, model providers and Third-Party Services. We may change, disable or replace an integration when a dependency is discontinued, insecure, unsupported or materially changed.
11.6 Connected data and third-party records
Data made available
You are responsible for the accuracy, legality and sensitivity of data made available to an MCP Service. You must not send passwords, private keys, payment details, special-category personal data or confidential third-party data unless the Project Agreement and the relevant security and data-processing arrangements expressly allow it.
Actions and reconciliation
Actions taken through a Connected Account may create, edit, publish, delete, categorise, send, spend, charge, schedule or otherwise change records in that account. You are responsible for reviewing and reconciling those records. We are not responsible for a third-party action that follows an instruction, permission or approval supplied by you or an authorised user, except to the extent liability cannot lawfully be excluded.
11.7 AI-assisted operation
MCP and SEO AI features may use probabilistic software, AI models, automated extraction, heuristics or generated text. They can produce incomplete, outdated, incorrect, biased or unsafe results. AI output is not a substitute for professional legal, financial, tax, medical, security, accessibility, employment or other regulated advice.
You must review AI-generated or AI-assisted output before publishing it, relying on it, sending it to another person, making a business decision or applying an action to a Connected Account. You must not use the Services for fully automated high-impact decisions about individuals unless you have carried out the legal, fairness, security and human-review work required for that use.
12. SEO, analytics, AI discovery and advertising
12.1 No ranking or commercial guarantee
Search engines, AI answer systems, advertising platforms, social platforms and analytics providers are independent Third-Party Services. We do not guarantee:
- a particular Google, Bing, social or AI-search position;
- inclusion, indexing, crawling or citation;
- a particular number of impressions, clicks, sessions, enquiries, leads, bookings or sales;
- a particular cost per click, cost per lead or advertising return;
- approval or verification by Google, Meta or another platform;
- a particular Core Web Vitals score or page-speed result; or
- that a technical change will produce a particular commercial result.
SEO is affected by competition, search intent, algorithm changes, website quality, content, authority, location, seasonality, platform policies, customer response and many other factors. We will not knowingly promise an outcome that depends on a third party’s ranking or approval decision.
12.2 AI discovery and generated content
Schema, robots.txt, llms.txt, Markdown negotiation, metadata, structured data and other AI-discovery signals may help systems understand a website, but they do not guarantee training use, retrieval, citation or an answer. AI-generated content, summaries, titles, code, recommendations and data classifications may not be unique or accurate. You must approve the final material and confirm that it reflects your business.
12.3 Analytics and advertising accounts
Analytics, Search Console, Google Ads, Meta Ads, pixels, tags and conversion events may be affected by consent settings, browser restrictions, ad blockers, platform changes, duplicate configuration, attribution models, sampling, delays and account permissions. Reports are based on the data available to the connected account and may not represent every user or transaction.
You remain responsible for advertising budgets, campaign claims, audience selection, legal notices, cookie consent, data-sharing settings and platform compliance. We do not place advertising spend unless expressly authorised in the Project Agreement.
13. Acceptable use
You must not use the site, Services, Software, MCP Services, hosting or Connected Accounts to:
- break the law, facilitate fraud or infringe another person’s rights;
- distribute malware, ransomware, spyware, phishing, credential theft or harmful code;
- send spam, unsolicited bulk messages or deceptive communications;
- scrape, crawl, copy, index or process data without the necessary permission;
- impersonate another person or business or misrepresent an affiliation;
- upload content that is defamatory, discriminatory, abusive, exploitative, sexually abusive, threatening or otherwise unlawful;
- interfere with, overload, probe or bypass the security or availability of a system;
- reverse engineer, decompile, evade a licence, remove attribution or defeat a technical protection except where applicable law or an open-source licence expressly permits it;
- use a Third-Party Service in breach of its terms, API rules or privacy requirements;
- attempt to access, probe, copy, reverse engineer or use our Internal MCP Systems, private endpoints, repositories, credentials, prompts, configurations or logs;
- run unattended actions that create material financial, legal, reputational, safety or data-protection risk without suitable human approval; or
- use a Service to make decisions about people in a way that breaches equality, privacy, consumer-protection or other applicable law.
We may investigate suspected misuse, request information, restrict access, suspend a Service or terminate an agreement where reasonably necessary to protect people, systems, data, our rights or a Third-Party Service.
14. Software, licences and intellectual property
14.1 Your materials
You retain ownership of Client Materials. Subject to payment and the Project Agreement, you may use the Deliverables created specifically for you for your business in the way agreed.
14.2 Bespoke Deliverables
Unless the Project Agreement says otherwise, once all invoices for the relevant project have been paid in full, we will assign to you the rights we are legally able to assign in the final bespoke Deliverables created specifically for you. Where an assignment is not possible, we grant you a perpetual, worldwide, royalty-free licence to use the relevant Deliverable for your business.
This does not transfer our pre-existing code, systems, methods, know-how, templates, frameworks, libraries, reusable components, Internal MCP Systems, internal control plane, worker connections, prompts, processes, documentation, working files or general skills. It also does not transfer third-party API access, platform accounts, credentials or provider licences. We may continue to use our background materials and improvements to them, provided we do not disclose your confidential information or reuse your Client Materials improperly.
Where a Project Agreement includes a bespoke client-specific integration, sync plugin or Client MCP System, the rights in the final client-specific implementation will be dealt with as a bespoke Deliverable after full payment. Reusable code, frameworks, internal tools and third-party components remain subject to this section and their applicable licences.
14.3 Third-party and open-source material
Third-party assets and licences
Stock images, fonts, music, plugins, themes, frameworks, APIs, platform components, open-source code and other Third-Party Services are subject to their own licences and terms. They are not automatically assigned to you. You are responsible for ongoing licence fees, account ownership, attribution and renewal where the Project Agreement places those responsibilities with you.
Open-source software
Where Software is distributed under a stated open-source licence, that licence controls the rights to the relevant code. For example, a package identified as GPL-2.0-or-later is governed by that licence for the code covered by it. These Terms govern any separate paid Services, hosting, support, configuration, customisation or connected service.
14.4 Software use
Subject to payment, you receive the licence stated in the Project Agreement or Software documentation. Unless that licence says otherwise, you may not resell, sublicense, rent, publish credentials for, white-label, distribute, clone or operate the Software as a competing hosted service.
You receive no licence or access to our Internal MCP Systems unless a Project Agreement expressly says otherwise. A Client MCP System is controlled by the ownership, access and handover terms in the Project Agreement, but you must retain the primary administrator account and manage it after handover unless an ongoing managed service is expressly included.
We may release updates, patches, security fixes, new versions or replacement components. An update may require a compatible WordPress, PHP, Node.js, hosting, browser, API or Third-Party Service version.
14.5 AI output and ownership
AI-generated output may not be exclusive, may contain third-party material and may not be capable of copyright protection. You are responsible for checking rights, originality, factual accuracy and suitability before use. Any rights available in AI-assisted Deliverables are transferred or licensed only to the extent legally possible and subject to the relevant model provider’s terms.
15. Portfolio and publicity
Unless the Project Agreement says that the work is confidential, we may identify you as a client and display a publicly launched website, logo, screenshots or finished creative work in our portfolio, case studies, presentations and social channels. We will not knowingly publish private information, unpublished campaign material or confidential data.
If you need the project to remain confidential, tell us in writing before launch and we will record the agreed confidentiality period or restriction.
16. Confidentiality
Each party must protect the other party’s confidential information and use it only for the relevant Services. Confidential information does not include information that:
- is public without a breach of these Terms;
- was already known lawfully;
- is received lawfully from someone not under a duty of confidence;
- is independently developed without using the other party’s confidential information; or
- must be disclosed by law, court order, regulator or professional adviser.
This section does not prevent us from using trusted suppliers or Third-Party Services where reasonably necessary to provide the Services, provided that we require appropriate confidentiality and security safeguards where appropriate.
17. Privacy and data protection
Our Privacy Policy explains how we collect and use personal data through the public website. Our Cookie Policy explains the use of cookies and similar technologies.
When we process personal data for you while providing a Service, the parties will comply with applicable UK data-protection law. Where required, we will agree a data-processing addendum or other written instructions covering the subject matter, duration, nature, purpose, data types, data subjects, security measures, sub-processors, international transfers and deletion or return of data.
Unless the Project Agreement says otherwise:
- you are responsible for deciding why and how personal data collected through your website, forms, analytics, marketing, ecommerce or Connected Accounts is processed;
- you are responsible for providing appropriate privacy information, consent mechanisms, cookie controls and data-subject rights processes to your users and customers;
- we may process data only as reasonably necessary to provide the agreed Services and support; and
- you must not provide more personal data than is necessary for the task.
If you believe a security or data-protection incident may have occurred, contact us immediately at [email protected] with the relevant details and do not publish credentials or personal data in a ticket or prompt.
18. Service standards and warranties
We will provide the Services with reasonable care and skill and, where relevant, in accordance with the material description in the Project Agreement.
If you believe a Service or Deliverable does not meet the agreed scope, tell us promptly with enough information for us to investigate. Where appropriate, our first remedy will be to correct, reperform or provide a reasonable workaround for the affected part of the Service.
We do not warrant that:
- a site, Software, MCP Service, hosting service, API, integration or Third-Party Service will be uninterrupted, error-free or available at all times;
- a website will work with every browser, device, plugin, theme, network, assistive technology or future platform version;
- a backup or recovery point will contain every file or restore successfully in every circumstance;
- an AI or automated result will be accurate, complete, current, unbiased or suitable for a particular decision; or
- SEO, AI-discovery, advertising, analytics or creative work will achieve a particular result.
Nothing in these Terms removes or limits a legal right that cannot lawfully be removed or limited. In particular, Consumer Customers retain the protections that apply to consumer contracts and services.
19. Consumer cancellation rights
This section applies only where you are a Consumer and the law gives you a right to cancel a distance or off-premises contract. It does not remove any other legal right you may have.
Usually, a Consumer may cancel a distance contract for Services within 14 days without giving a reason. If you ask us to start the Services during that period, you expressly request early performance. If you cancel after work has started, you may have to pay a proportionate amount for the Services supplied up to the time of cancellation. If the Service is fully performed during the cancellation period after your express request and acknowledgement that the right to cancel will end on full performance, that cancellation right may end when the Service is completed.
Some contracts, including certain fully performed Services, digital content supplied after the required consent and acknowledgement, urgent work or other categories set by law, may have different cancellation rules. We will provide the information required for the relevant contract.
To cancel where this section applies, email [email protected] with a clear statement that you are cancelling and include your name, order or project reference and the date of the contract. You may use the model wording below, but you do not have to use those exact words.
Model cancellation wording
To Xeon Creative at [email protected]: I/We hereby give notice that I/We cancel my/our contract for the supply of the following service: [describe the service]. Ordered on / contract formed on: [date]. Name of consumer(s): [name]. Address of consumer(s): [address]. Date: [date].
Business Customers do not generally receive Consumer cancellation rights, although mandatory law may apply depending on the circumstances.
20. Fees, invoices and payment
20.1 Prices
Prices are in pounds sterling unless the Project Agreement says otherwise. VAT or other taxes will be added where applicable.
All website build prices are bespoke to the customer’s agreed build, platform, pages, features, integrations, content, SEO requirements, revisions, timeline, launch arrangements and support expectations. The same applies to website amendments, ecommerce, booking systems, hosting, SEO, creative work, MCP Services, Maintenance Packages and Retainer Services. The accepted Project Agreement is the final record of the agreed price and scope.
A price, package, range, example or “starting from” figure shown on a public page is general guidance and is not a binding offer or a promise that the same scope will be suitable for every customer. We will confirm the fixed price and assumptions for the particular customer before work begins. Third-Party Service fees, hosting, domains, licences, advertising budgets and other external charges are included only where the Project Agreement expressly says so.
20.2 Deposits and staged payments
Deposits, milestone payments and advance payments are applied to the work and time reserved for your project. If a project ends early, you remain responsible for work completed, non-cancellable costs and other amounts properly due, subject to any Consumer rights and the Project Agreement.
20.3 Recurring services
Hosting, Maintenance Packages, Retainer Services, SEO, support, subscriptions and other recurring Services are billed on the schedule stated in the Project Agreement. The Project Agreement will state the package inclusions, monthly outputs or reserved capacity, billing date, notice period, minimum term, carry-over rules, overage rates and whether the service renews. If it does not state a notice period, either party may normally end an ongoing monthly service by giving 30 days’ written notice, subject to any minimum term and applicable Consumer law.
We may change a recurring price when our supplier costs, scope, resource requirements or service materially change. We will give reasonable notice and you may end the affected recurring Service before the new price takes effect if the change is material and the Project Agreement or law gives you that right.
Recurring fees normally reserve capacity and access for the billing period; they do not automatically promise a fixed number of hours, completed requests, rankings, leads, bookings or other outcomes unless the Project Agreement expressly says so. Unused retainer capacity or monthly outputs do not roll over unless the Project Agreement expressly allows it.
20.4 Late payment and suspension
Pay invoices by the due date stated on the invoice or Project Agreement. If no due date is stated, payment is due within seven calendar days.
For Business Customers, we may charge interest and recovery costs where permitted by law. For any customer, we may pause work, withhold launch or suspend access after giving reasonable notice if an invoice is overdue, unless doing so would breach a mandatory legal right.
Suspension does not cancel amounts already due. We are not responsible for delay or loss caused by a suspension resulting from non-payment or missing information.
21. Refunds, cancellation and termination of Services
You may cancel or terminate a Service in the way stated in the Project Agreement. If it does not state a process, give written notice to [email protected].
If you cancel a project or ongoing Service, you must pay for:
- work completed up to the termination date;
- Deliverables or materials already supplied or approved;
- time reserved or committed where the Project Agreement reasonably allows that charge;
- Third-Party Service, licence, hosting, domain, print, media or supplier costs that cannot be cancelled or recovered; and
- any other amount properly due under the Project Agreement.
If we terminate for your material breach, unlawful use, serious security risk, non-payment or misuse of a Connected Account, we may suspend access and recover amounts due. If we terminate for a reason not caused by you, we will provide any refund or credit required by the Project Agreement or applicable law for prepaid Services not supplied.
Nothing in this section limits a Consumer’s statutory cancellation, refund, repair, repeat-performance or price-reduction rights.
22. Suspension and termination of MCP, Software or hosting access
We may suspend or restrict an MCP Service, Software update channel, hosting account, Connected Account or integration where reasonably necessary to:
- protect security, confidential information, personal data or system availability;
- respond to a vulnerability, abuse report, provider restriction or legal requirement;
- prevent unauthorised access or a harmful action;
- address overdue fees or exceeded usage limits; or
- carry out planned maintenance, migration or emergency recovery.
We will restore access when the reason for suspension has been resolved where reasonably possible. If a service is terminated, we will provide a reasonable export or handover opportunity for your data and configuration where the Project Agreement includes one or where required by law. Additional migration, extraction, recovery or handover work may be chargeable.
Suspension or termination of a managed Client MCP System or Maintenance Package does not transfer ownership of the client’s accounts, code, domain, data or configuration to us. Subject to payment of amounts due, the client remains entitled to the agreed Deliverables and a reasonable handover under the Project Agreement.
After the relevant retention period, we may delete copies of Client Materials, logs, backups, credentials, prompts, outputs and Connected Account data, subject to legal, security, accounting and dispute-hold requirements.
23. Intellectual property complaints and takedown
If you believe that material supplied or published through a Service infringes your rights or another person’s rights, contact us promptly with the URL, the relevant material, the basis of the complaint and your contact details. We may temporarily disable or remove material while the issue is investigated, without deciding the merits of a dispute.
24. Liability
Nothing in these Terms excludes or limits liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation;
- breach of a legal responsibility that cannot lawfully be excluded or limited; or
- any other liability that applicable law does not allow us to exclude or limit.
Subject to the paragraph above and to Consumer law:
- we are not liable for indirect or consequential loss, loss of profit, revenue, business, contracts, opportunity, anticipated savings, goodwill, reputation or data;
- we are not liable for a failure, loss or delay caused by a Client Material, instruction, approval, unauthorised change, Connected Account, Third-Party Service, platform decision, provider outage, DNS propagation, cyber event outside our reasonable control or failure to keep an independent backup; and
- for a Business Customer, our total aggregate liability arising from the relevant Project Agreement will not exceed the total fees paid or payable for the affected Services under that Project Agreement, or, for an ongoing Service, the fees paid or payable for the 12 months before the event giving rise to the claim.
The cap and exclusions in this section apply only to the extent permitted by law and do not remove a Consumer’s statutory rights.
25. Events outside our control
We are not responsible for failure or delay caused by events we could not reasonably prevent or control, including war, terrorism, civil disorder, industrial action, fire, flood, severe weather, epidemic, power or internet failure, cyberattack, provider outage, domain or platform failure, government action, supply-chain disruption, changes to law or a failure of a Third-Party Service.
We will use reasonable efforts to reduce the effect of such an event and resume the affected Service when reasonably possible.
26. Complaints and support
Please raise a support request or complaint by email at [email protected], including your name, project or service reference, the relevant URL or account, a clear description of the issue and the outcome you are seeking.
We will review the issue and try to resolve it fairly. Support hours, response targets, emergency support and maintenance windows apply only if included in the Project Agreement. Nothing in this section prevents you from using any court, regulator or statutory complaint route available to you.
27. Changes to these Terms
We may update these Terms to reflect changes to Services, Software, security practices, Third-Party Services or law. The updated version will be posted on this page with a new “last updated” date.
An update will not retrospectively change the agreed price, scope or rights under a Project Agreement unless you agree or the change is required by law. The version in force when a Project Agreement is accepted normally applies to that engagement, with reasonable updates for security, operation or legal compliance.
28. General legal terms
- Notices: Notices may be sent by email to the address in section 1 or the address stated in the Project Agreement. You must keep your contact details current.
- Assignment: You may not transfer a Project Agreement without our written consent. We may transfer it as part of a reorganisation, sale or transfer of the relevant business, provided your rights are not materially reduced.
- No partnership: These Terms do not create a partnership, employment relationship, agency or joint venture.
- Severability: If a court finds part of these Terms invalid or unenforceable, the rest will continue and the invalid part will be adjusted only as far as needed to make it enforceable.
- No waiver: A failure to enforce a right immediately does not waive that right.
- Entire agreement: The Project Agreement and these Terms contain the agreement for the relevant Services, replacing earlier discussions about the same subject unless expressly incorporated.
- Electronic communication: Email, electronic signatures, online approvals and system records may be used to form and evidence an agreement.
- Third-party rights: A person who is not a party to the relevant agreement has no right to enforce it unless the agreement or law says otherwise.
29. Governing law and jurisdiction
These Terms and any dispute or claim arising from them are governed by the law of England and Wales. The courts of England and Wales will have jurisdiction, except that a Consumer may also have the right to bring proceedings in the courts of the part of the United Kingdom in which they live or under any other mandatory local law.