Service Level Program for Ariba cloud Services. Service Accessibility Warranty Security Miscellaneous



Similar documents
ensure prompt restart of critical applications and business activities in a timely manner following an emergency or disaster

Service Description: Dell Backup and Recovery Cloud Storage

RL Solutions Hosting Service Level Agreement

HOSTING SERVICES ADDENDUM TO MASTER SOFTWARE LICENCE AGREEMENT

Decision on adequate information system management. (Official Gazette 37/2010)

Trinity Online Application - Terms and Conditions of Use

Rajan R. Pant Controller Office of Controller of Certification Ministry of Science & Technology rajan@cca.gov.np

PENELOPE HOSTING SERVICE! Athena Software! Effective Date: March 30, 2015!

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0

Online Back-Up, Off-Site Back-Up, Restore Service of Back-Up.

SPECIAL CONDITIONS FOR HOSTING SERVICES ON A DEDICATED OR VIRTUAL PRIVATE SERVER

For the purpose of this agreement the following words and phrases shall have the meanings detailed below:

ELECTRONIC SIGNATURE AGREEMENT

How To Use A Minicloud Server On An Ovh Cloud (For Free) For A Long Time

CA API Management SaaS

PART D NETWORK SERVICES

1.3 Your access to and use of the Site, including your order of Products through the Site, is subject to these terms and conditions.

DODO WEB HOSTING TERMS OF SERVICE

Dedicated Server Services Specific Terms and Conditions

Licence Fee means the fees calculated as set out on the Website or such other fee as is agreed between You and the Supplier from time to time.

IBX Business Network Platform Information Security Controls Document Classification [Public]

TERMS OF USE 1 DEFINITIONS

Service Specification Schedule For Fujitsu Cloud IaaS Trusted Public S5

Information Crib Sheet Internet Access Service Agreement

Electronic business conditions of use

Data Management Policies. Sage ERP Online

ADDENDUM TO THE BLACKBERRY SOLUTION LICENSE AGREEMENT FOR BLACKBERRY BUSINESS CLOUD SERVICES FOR MICROSOFT OFFICE 365 ( the ADDENDUM )

SRI LANKA AUDITING PRACTICE STATEMENT 1013 ELECTRONIC COMMERCE EFFECT ON THE AUDIT OF FINANCIAL STATEMENTS

SERVICE LEVEL AGREEMENT

BUSINESS ONLINE BANKING AGREEMENT

Merchant Account Terms of Use

CLOUD SERVICE SCHEDULE Newcastle

CLOUD SERVICE SCHEDULE

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10

EASTLINK PERSONAL CLOUD TERMS OF SERVICE

Schedule Document. Leased Lines & Ethernet Based Services. Node4 Limited 29/11/2007

1 Purpose Scope Roles and Responsibilities Physical & Environmental Security Access Control to the Network...

Service Level Agreement for Microsoft Online Services

SaaS Service Level Agreement (SLA)

IBM Managed Security Services (Cloud Computing) hosted and Web security - express managed Web security

HOSTING SERVICES AGREEMENT

Virtual Private Server Services Specific Terms and Conditions

Security Policy JUNE 1, SalesNOW. Security Policy v v

TABLE OF CONTENT. Page 2 of 9 INTERNET FIREWALL POLICY

SaaS Terms & Conditions

THIS SERVICE LEVEL AGREEMENT DEFINES THE SERVICE LEVELS PROVIDED TO YOU BY THE COMPANY ( Exchange My Mail ).

INTERNATIONAL AUDITING PRACTICE STATEMENT 1013 ELECTRONIC COMMERCE EFFECT ON THE AUDIT OF FINANCIAL STATEMENTS

Seaside High-Speed Internet Acceptable Use Policy (AUP)

schedule 2h Definitions additional terms for managed hosting services SERVICE DESCRIPTION

How To Use Adobe Software For A Business

TERMS & CONDITIONS of SERVICE for MSKnote. Refers to MSKnote Limited. Refers to you or your organisation

MCC TERMS AND CONITIONS

AXIS12 DRUPAL IN A BOX ON THE CLOUD

Remote Disaster Recovery Services Suite (nvision Edition)

Voya Financial Advisors, Inc. Registered Representative s Website Terms of Use

Terms and Conditions- OnAER Remote Monitoring Service

PRACTICE NOTE 1013 ELECTRONIC COMMERCE - EFFECT ON THE AUDIT OF FINANCIAL STATEMENTS

Managed Colocation Service Terms and Conditions for CLOUDHPT.COM

COB 302 Management Information System (Lesson 8)

HOSTING SERVICE DESCRIPTION

SAAS MADE EASY: SERVICE LEVEL AGREEMENT

SERVICE LEVEL AGREEMENT. Open Source Support Desk B.V. Hargray, Inc.

Security Policy Revision Date: 23 April 2009

Tk20 Backup Procedure

esnc ACCESS AGREEMENT

Ford Motor Company CA Certification Practice Statement

By using the Cloud Service, Customer agrees to be bound by this Agreement. If you do not agree to this Agreement, do not use the Cloud Service.

THIS SERVICE LEVEL AGREEMENT DEFINES THE SERVICE LEVELS PROVIDED TO YOU BY THE COMPANY.

SERVICE LEVEL AGREEMENT

SYMANTEC SOFTWARE SERVICE LICENSE AGREEMENT Norton 360

Service Level Agreement for Microsoft Online Services

Keyfort Cloud Services (KCS)

IT General Controls Domain COBIT Domain Control Objective Control Activity Test Plan Test of Controls Results

SERVICE LEVEL AGREEMENT

Microsoft Hyper-V Powered by Rackspace & Microsoft Cloud Platform Powered by Rackspace Support Services Terms & Conditions

White Paper: Librestream Security Overview

Information Services. Standing Service Level Agreement (SLA) Firewall and VPN Services

Electronic Prescribing of Controlled Substances Technical Framework Panel. Mark Gingrich, RxHub LLC July 11, 2006

AGREEMENT AND TERMS OF USE

Managed Services Terms and Conditions

Terms of Service. For all retail customers

Aruba Bank Online Terms of Agreement

Computers and Society: Security and Privacy

IT Architecture Review. ISACA Conference Fall 2003

DATA SECURITY AGREEMENT. Addendum # to Contract #

Managing internet security

Transcription:

Service Level Program for Ariba cloud Services Service Accessibility Warranty Security Miscellaneous 1. Service Accessibility Warranty a. Applicability. The Service Accessibility Warranty applies to the applicable Solution. "Solution" or Service means and includes the following products if transacted for and paid for by Customer (or "You"), as identified on a contract between You and Ariba or another SAP company, and for the applicable data center Customer uses to access the Services listed here: http://www.ariba.com/legal/ariba-slp-products-english-2014-03-01. SAP means the SAP company with which You contracted for the Service. b. Warranty. i. Percentage. The Service will be accessible 99.5% percent of the time, seven days a week, twenty-four hours per day, as calculated over a calendar month (the "Service Accessibility Warranty"). The Service Accessibility Warranty of 99.5% corresponds to 522,972 (= 0.995 * 60 * 24 * 365) minutes of uptime per year. ii. Remedy for Non-Compliance. If the Service fails to meet the Service Accessibility Warranty, SAP will issue to Customer's account the number of Total Credit Units resulting from application of the formula below. Customer may use the Credit Units towards any future purchases of Services from SAP. (A) Calculation. The number of Total Credit Units is calculated as follows: Total Credit Units = [Inaccessibility Period (in minutes rounded up) ] X the Per Minute Pro-rated Annual Subscription Fees actually paid (for the individual applicable Solution). "Inaccessibility Period" means the period of time that the Service failed to meet the Service Accessibility Warranty. Only an inaccessibility occurring in the data center used by Customer for its subscribed product(s) will count against the Inaccessibility Period measurement. "Credit Unit". A Credit Unit is a representation of a unit of currency, in the same currency as Customer paid SAP for the applicable Solution, such as Euros, U.S. Dollars or otherwise. One Credit Unit is equal to one unit of currency. For example, if Customer paid in U.S. Dollars, one Credit Unit would equal $1.00

USD. "Annualized Period" means a twelve month period commencing on the anniversary date of Customer's subscription to the applicable Solution. For example, if Customer transacts for a two year subscription to a Service starting on January 1, 2015, then the two Annualized Periods are (a) January 1, 2015, until December 31, 2015; and, (b) January 1, 2016, until December 31, 2016. "Per Minute Pro-rated Annual Subscription Fee" means the amount which Customer actually paid to SAP for the applicable Service that corresponded to the applicable Annualized Period divided by 525,600 (=60*24*365) minutes in a year. Note: If Customer licensed certain Ariba software products prior to December 2006 and is obtaining use of the Ariba Network as a Foundation Services as part of Technical Support Services Fees, then Technical Support Services Fees are used for purposes of calculating the Annual Subscription Fee. c. Scheduled Downtime. When needed, SAP will schedule downtime for routine maintenance or systems upgrades ("Scheduled Downtime") for the Solution. SAP shall exercise commercially reasonable efforts to schedule maintenance and system upgrades outside of peak traffic periods. Generally, such maintenance or system upgrades are scheduled to occur from Saturday, 8:00AM to Saturday, 8:00PM Pacific Time ("Maintenance Window"). SAP reserves the right to extend or change the times of the Maintenance Window. SAP will use commercially reasonable efforts to notify Customers at least 72 hours prior to the occurrence of Scheduled Downtime. d. Exclusions. In calculating the Inaccessibility Period, the following will not apply: (i) Scheduled Downtime for which Customer has been notified at least one business day prior to such Scheduled Downtime; (ii) inaccessibility that is not the fault of SAP (such as failures caused by factors not under SAP s direct control, for example where caused by equipment or software under the control of a third party), and (iii) inaccessibility due to Customer request or where Customer approved in advance. Customer shall be solely responsible for maintaining adequate controls over Customer's Data transmissions to the Service, for monitoring such transmissions, and for bringing to SAP's attention any failure to access the Service within (5) days of inception of any such event. Customer shall be solely responsible for setting applicable data processing and transmission parameters, for inspecting all data input and output for accuracy and completeness. 2. Security Elements. The Service contains the following security elements: a. Physical Security. The Service is either under SAP s control or is located at a secure, third party off-site facility. Access to the hardware, software, and other

elements comprising the Service is limited to authorized personnel only. SAP uses servers with redundant features for maximum accessibility. b. Disaster Recovery. The Service utilizes a disaster recovery plan to allow for SAP to meet the Service Accessibility Warranty stated in this Service Level Program. c. Data Security. Transactions made using the Service are initially stored in a database to prevent loss. All Customer Data resident on the systems is backed up daily. Backups are stored off-site at a secure third party location. Backups include Customer's registration and account information. The Service receives periodic preventive maintenance. This preventive maintenance is scheduled for times outside of peak traffic periods. As applicable, transaction queues wait while maintenance occurs, and they resume processing when maintenance concludes. Only the organizations involved in a Transaction are permitted to see that Transaction, except to the extent SAP is asked to debug a technical issue and needs to access a Transaction document. As applicable [1], the Service runs redundant copies of all of the critical software subsystems related to Transaction routing. This redundancy enables fail-over in the event of an error so that disruption of the Service is minimized. d. Service Security. SAP implements commercially available security software, hardware and techniques to minimize and prevent non-authorized use of the Solution. These include firewalls, intrusion detection software tools, and monitored use of the Solution. The Service also performs authentication of interactive user sessions. For increased security, the Service uses HTTPS, which is HTTP over SSL (Secure Sockets Layer). The SSL security protocol provides data encryption, server authentication, message integrity, and optional client authentication for TCP/IP connections. The Solution's Webservers use a server digital certificate to enable SSL connections. e. Verification by Auditor. As to SAP s data centers hosting the Services in existence as of the date of this document, the commitments to the Service are audited at least once per year by a recognized third party auditor, to verify SAP s performance with these commitments to Security. Please see the WebTrust seal awarded to SAP s unit Ariba. As to any future net new data center to host the Services, SAP will include such data center within scope for the next scheduled audit.

3. Miscellaneous a. Service Integrity. Customer agrees not to: (i) use any device, software or technique to interfere with or attempt to interfere with the proper working of the Solution; (ii) post or send to the Service anything that contains a virus, bug, cancelbot, worm, Trojan Horse or other harmful item; (iii) take any action which imposes an unreasonable or disproportionately large load on the Service such that other users are adversely affected; or (iv) use any device or technology to provide repeated automated attempts to access password-protected portions of the Service for which Customer does not have a valid password issued to Customer by Ariba or SAP. Customer may not allow any third parties to use Customer's password without SAP s prior written consent. Customer also understands that SAP cannot and does not guarantee or warrant that files or non-sap software of any kind, or from any source, available for downloading through the Solution, will be free of infection or viruses, worms, Trojan Horses or other code or defects that manifest contaminating or destructive properties. Customer acknowledges that SAP has the right, but no obligation, to take such actions related to use of the Service (including but not limited to removing content or denying routing of certain data) if SAP reasonably believes that such actions are needed to comply with the law. b. For the convenience of our global customers, this document may be translated into several languages. Please bear in mind that in the event of any ambiguity created by such translations, the substance in the English version will control. c. EXCEPT FOR THE EXPRESS SERVICE ACCESSIBILITY WARRANTY STATED IN THIS SECTION 1, THIS DOCUMENT DOES NOT (I) CREATE ANY OTHER REPRESENTATION OR WARRANTY RELATED TO THE AVAILABILITY, ACCESSIBILITY, OR USABILITY OF THE SOLUTION; or (II) DIMINISH, ALTER OR NEGATE ANY OTHER EXPRESS WARRANTY(IES) IN ANY SIGNED AGREEMENT BETWEEN THE PARTIES. The remedies stated in Section 1 are Customer's sole and exclusive remedies, and SAP s sole liability, for failure to meet the warranties stated in section 1 above. [1] If you use an OnPremise product of Ariba and buy Hosting Services for Ariba or SAP to host a distinct implementation dedicated to you, then this sentence does not apply if Ariba/SAP

performs that hosting through SAP s subcontractor AT&T. Instead, the AT&T hosting does not run redundant copies of all of the critical software subsystems, but the Service will still perform within the Service Accessibility Warranty percentage. Note that for most customers receiving such Hosting Services, AT&T is not utilized. SLP 1 March 2014