These Service Terms apply to managed computing, hosting, storage, and backup services provided by Spider Computing Services, LLC ("Spider Computing" or "Provider"). They are part of the Agreement together with the Order and the Master Service Terms. Capitalized terms not defined here have the meanings in the Master Service Terms. These Service Terms supplement the Master Service Terms and, where stated, override the Master Service Terms defaults; anything they do not address is governed by the Master Service Terms, and an Order may override both as described in Section 3.2 of the Master Service Terms.
1. Services
1.1 Managed computing. Spider Computing provides managed computing and hosting for the applications, servers, and data described in the Order (the "Computing Services"). Each client's environment is kept logically separate from every other client's, and Client Data is encrypted at multiple levels.
1.2 Packages. The Order will state which package(s) apply:
- Local packages. A managed hardware platform located at Client's premises, designed to keep services available even when Client's Internet connection is down. Local packages are intended for private and confidential data and for software that should not be exposed to the Internet.
- Remote packages. Hosting in Provider's off-site environment, intended for services that do not store private or confidential data, or for data that is already encrypted. The list of supported software for remote packages is intentionally narrower.
1.3 Supported software. Provider will host and manage the software listed in the Order. Provider may decline to host software it reasonably believes is insecure, unsupported by its vendor, or incompatible with the platform.
1.4 Storage. Storage can be expanded on request. Additional storage is billed at the rates in the Order from the date it is provisioned.
2. Backups
2.1 Always included, always encrypted. Every package includes encrypted remote backups of Hosted Data. Backups are encrypted before they leave the managed server, so a compromise of a backup copy is not a compromise of the data.
2.2 Schedule and retention. Backups run on the schedule stated in the Order, or if none is stated, [BACKUP FREQUENCY, E.G., DAILY], and are kept for [BACKUP RETENTION PERIOD]. Older backups are replaced and deleted on a rolling basis.
2.3 Restores. Client may request a restore through support. Provider will use commercially reasonable efforts to restore from the most recent available backup. Restores are included up to [INCLUDED RESTORES] per month; additional or large-scale restores are billed at [RATE] or as stated in the Order. [CONFIRM: RESTORE FEES]
2.4 Limits. Backups protect against loss of the hosted environment, but no backup system is infallible. Provider is not responsible for data that was never backed up (for example, data created after the last backup, or data Client stores outside the Computing Services), or for data that was corrupted or encrypted by malware before it was backed up and not detected before older backups aged out.
3. Data ownership and control
3.1 Client owns its data. As between the parties, Client owns all Hosted Data. Provider acts as Client's service provider/processor for Hosted Data under Section 9 of the Master Service Terms.
3.2 Limited access. Provider personnel access the contents of Hosted Data only as needed to provide, maintain, secure, or restore the Computing Services, at Client's request, or as required by law, and access is restricted to those with a business need.
3.3 Encryption keys. Encryption keys for Hosted Data and backups are managed as follows: [KEY MANAGEMENT DESCRIPTION]. [CONFIRM: KEY MANAGEMENT] If Client holds a key or passphrase needed to decrypt its data, Provider may be unable to recover data if Client loses it.
4. Client responsibilities
4.1 Data classification. Client is responsible for deciding what data it places in the Computing Services and on which package. Client must keep private, confidential, and regulated data on a Local package unless the data is encrypted before being placed on a Remote package or the Order expressly allows otherwise. Provider is not responsible for consequences of Client placing data on a package not designed for it.
4.2 Regulated data. Section 9.5 of the Master Service Terms applies to protected health information, payment card data, and other regulated data.
4.3 Local package environment. For Local packages, Client will provide a secure, access-controlled location with suitable power, cooling, and network connectivity as specified in the Order, and will not move, open, modify, or disconnect Provider-managed hardware without Provider's approval.
4.4 Licenses. Client is responsible for licenses for its own applications unless the Order states that Provider supplies them.
4.5 Users and access. Client is responsible for its users' accounts, for promptly removing access for departing personnel, and for the activity of its users.
4.6 Hardware ownership. The servers, storage, and other hardware Provider supplies for Local packages, and the hardware in Provider's hosting environment used for Remote packages, are Provider Equipment (as defined in the Master Service Terms). Provider Equipment is owned by the Equipment Lessor, Spider Leasing Services, LLC, and leased to Spider Computing, which supplies it to Client as part of the Computing Services. Title remains with the Equipment Lessor, and Client acquires no ownership interest. Section 6 of the Spider Security Services Service Terms ("Provider Equipment") applies to Provider Equipment supplied for Local packages as if fully stated here, with "Spider Computing" in place of "Spider Security" and "Computing Services" in place of "Security Services." The Equipment Lessor is not a party to the Order; Client will look solely to Spider Computing for the Computing Services, support, repair, and replacement. The Equipment Lessor only owns the equipment and does not access, process, or receive Hosted Data or other Client Data.
5. Acceptable use
Client will not use the Computing Services to: store or distribute unlawful content or content that infringes others' rights; host malware, phishing pages, or command-and-control infrastructure; send spam; mine cryptocurrency; attack, scan, or probe other systems; attempt to access other clients' environments; or use resources in a way that degrades the platform for other clients. Provider may suspend the affected service under Section 6.4 of the Master Service Terms if Client violates this Section.
6. Availability and support [SLA]
6.1 Service level. Provider will use commercially reasonable efforts to make Remote packages available [UPTIME TARGET, E.G., 99.9%] of the time each month, excluding scheduled maintenance, emergency maintenance, Client-caused issues, failures of Client's Internet connection or equipment, and force majeure events. [SLA]
6.2 Service credits. If Provider misses the service level, Client may request a service credit of [SERVICE CREDIT SCHEDULE] within thirty (30) days after the end of the affected month. Service credits are Client's sole remedy for unavailability and do not exceed [SERVICE CREDIT CAP, E.G., 25%] of the monthly fee for the affected service. [CONFIRM: SLA AND CREDITS]
6.3 Maintenance. Scheduled maintenance occurs during [MAINTENANCE WINDOW] with at least [MAINTENANCE NOTICE PERIOD] notice. Emergency maintenance may occur at any time with as much notice as practical. Status updates are posted at status.spider.services.
6.4 Support. Support is available by phone at (888) 271-8668 and by email at support@spiderservices.net during [SUPPORT HOURS]. Target response times are: [RESPONSE TIMES BY PRIORITY]. After-hours support is available for [AFTER-HOURS COVERAGE].
6.5 Local packages. Because Local packages run on Client's premises, their availability depends on Client's power and environment. Provider's commitment for Local packages is to respond to and remediate hardware or software faults within the response times above.
7. End of service: return and deletion of data
7.1 Export period. For [DATA RETURN PERIOD, E.G., 30] days after an Order ends (the "Export Period"), Provider will, on Client's written request, make Hosted Data available for export in [EXPORT FORMAT] or deliver it by a secure transfer method. Assistance beyond a standard export is billed at [RATE]. Provider may withhold export until undisputed fees are paid.
7.2 Deletion. After the Export Period, Provider will delete Hosted Data from the active environment within [DELETION PERIOD, E.G., 30] days and, on request, confirm deletion in writing. Copies in encrypted backups will be deleted as those backups are replaced in the normal rotation described in Section 2.2, and until then remain protected under the Agreement.
7.3 Local hardware. For Provider Equipment used for Local packages, Provider will securely wipe or destroy storage media before the equipment is returned to the Equipment Lessor, redeployed, or disposed of. For Client-owned hardware, Provider will remove its management tools and credentials.
7.4 Earlier deletion. Client may ask Provider to delete Hosted Data earlier, and Provider will do so, except where retention is required by law.
8. Term
The Computing Services begin on the service start date in the Order and continue for the term stated in the Order, subject to the renewal and termination terms in the Master Service Terms.