Version dated 2 October 2026. Applies to orders expressly incorporating this version.
1. Required service specification
Before production, the parties complete and accept the following specification. Mark inapplicable fields “not applicable”. Unknown information is not a service commitment.
- Customer, order reference and administrative, technical and security contacts.
- Instance and domains; core version, revision and licences; module names, versions and licensing basis.
- Included services; CPU/RAM, storage, traffic, users, entities and environments; alert thresholds and expansion terms.
- Hosting provider and contracting entity; account owner; VPS or dedicated physical server; countries/regions of servers, storage and backups; CDN and support-access countries.
- Enabled integrations, third-party account owners, granted permissions and synchronisation limits.
- Dates, milestones, acceptance criteria, separate prices, payment dates, duration and renewal; fees subject to revised Syntec, billing start date, initial reference month (third month before the start month) and published value.
- Support channel, address, coverage days/hours, time zone, escalation and response/intervention/restoration objectives by severity.
- Backup scope, frequency, retention, encryption, separation, responsibility and verification/restoration-test frequency.
- Recovery point objective (RPO), recovery time objective (RTO), any guaranteed uptime and measurement.
- Authorised subprocessors, transfers and security controls: completed DPA specification attached.
Managed service must not start with unspecified processing locations, backup responsibilities, support or security. Subscription alone does not promise “99.9%”, “24/7” or a recovery objective.
2. Responsibilities
For a fully managed instance, the Provider configures and maintains the system and application within scope, administers technical access, applies relevant patches, performs agreed backups and manages restoration. The Customer administers business accounts, access rights, content, asset licences and its own systems. Any privileged Customer access and consequences of its interventions are documented.
For infrastructure contracted directly by the Customer, the specification allocates hosting-account, operating-system, network, backup, certificate and update responsibility. Installation alone is not ongoing operations. The Provider remains responsible for tasks it accepted.
The Provider may adapt infrastructure for security, performance or operations without materially reducing agreed characteristics, with prior notice of significant changes. Subprocessor, processing-country or access changes remain subject to the DPA and its notice, authorisation and safeguard requirements.
The Order Form fixes the number of managed instances and environments. A domain change or alias pointing to the same instance does not by itself create another billable instance; any technical work is separately agreed. Additional instances require a separate order. Domain owners remain responsible for renewals unless administration is expressly entrusted to the Provider.
3. Source data and technical copies
Damvia connects to authorised cloud sources and may retain copies of originals, previews, download archives, metadata and editorial content in application storage. Keeping source files in Customer storage does not mean no additional copies exist.
The Customer preserves cloud sources and their backups. Instance backups cover, as specified, PostgreSQL, main storage, relevant asset storage, configuration and version materials needed for recovery. Reconnecting cloud storage alone does not reconstruct users, permissions, pages or module data. Synchronisation is not an independent backup.
4. Maintenance and support
Corrective maintenance covers reproducible defects in maintained versions and modules within the agreed environment. The Provider may provide a fix, update or reasonable workaround. Functional enhancements, new modules, additional training, unauthorised modifications, reconstruction after Customer intervention and major third-party API changes are outside the package unless expressly included. Additional paid analysis or work requires an accepted quotation.
The Provider gives reasonable notice of planned maintenance and limits disruption. Urgent security patches may precede full notice, with information as soon as possible. It checks compatibility of included modules and provides a suitable backup or rollback mechanism before migration. Material hardware or software scope changes are agreed with the Customer.
A response objective measures time to examine a request, not guaranteed resolution. Any numerical SLA must specify measurement period and point, limited justified exclusions, credits and caps, and remedies for recurring failure. Credits are not exclusive remedies where law prevents that restriction.
5. Capacity and dependencies
Capacity and quotas come from the specification. The Provider warns of foreseeable excess and proposes adjustment. “Unlimited users” creates no hidden user quota: it means no per-user billing within the agreed resource envelope. An already accepted unlimited commitment is not implicitly reduced. Saturation or abuse may require explained, proportionate measures for security and continuity.
Integrations depend on third-party permissions, quotas and availability. The Provider does not guarantee third-party future decisions but retains agreed diagnostic, information and maintenance obligations.
The specification states storage units (decimal GB/TB or binary GiB/TiB), counted categories, measurement method and period, alert threshold, included capacity and any ordered excess unit price. Originals, previews, temporary archives and backups are not treated as a single chargeable category without prior disclosure. Without an accepted excess price, extra charges require written agreement; a capacity warning is not acceptance of a charge.
6. Exit data inventory
On an authorised contact’s request, the Provider supplies an inventory and secure standard export including Customer content available in the instance, metadata, product records, collections, pages, Customer settings, module business data and exportable relevant logs, subject to third-party rights and security. Intended formats are PostgreSQL for the database, JSON or CSV for structured data where relevant, files in their available format and existing schema/configuration documentation needed to interpret them. The Order Form specifies actually available formats per module and technical scope before signature.
Exports exclude Provider internal secrets, other customers’ data and proprietary code, without withholding business data or metadata necessary for reuse. Customer-owned secrets are securely transferred or replaced. A personal-account export is not an instance export; a full export may require technical intervention.
One standard end-of-contract export and existing documentation are included. Freely requested extra assistance, such as functional redesign at the destination, requires a quotation and cannot reclassify legally free switching operations as paid work.
7. Exit process
The Customer may request switching or self-hosting in writing, identifying the destination and desired date. Default notice to initiate switching is thirty days, followed by a transition period of no more than thirty calendar days. The service continues during the agreed transition with reasonable cooperation, data protection and appropriate continuity. The switching request constitutes notice to end affected services upon successful completion; the Provider confirms the date and financial consequences. Ordinary fees remain payable for service actually supplied; any separate termination charge must comply with the general terms and law.
Where Chapter VI of Regulation (EU) 2023/2854 applies, timing is interpreted under its requirements. If standard transition is technically unfeasible, the Provider explains within fourteen working days of the request and states an alternative period of no more than seven months. The Customer retains the right to extend transition once for a period it considers appropriate. Other more favourable mandatory requirements apply.
Data remains retrievable for at least thirty days after transition. After that period, or earlier on a legally compatible written instruction, production data is deleted within thirty days; backups expire on the DPA’s documented rotation no later than ninety days after production deletion. Backups remain isolated and used only for necessary recovery or legal obligations, with deletions reapplied on restoration. A certificate is available on request.
No switching fees prohibited by that Regulation are charged from 12 January 2027. Before then, any permissible fees must be disclosed before contracting and cannot exceed directly related costs; this contract already includes the standard export. Early-termination charges, ordinary service fees and extra services are distinguished and cannot circumvent the rule.
A dedicated or configured instance is not presumed exempt. Any custom-built-service derogation requires verification of statutory conditions and required pre-contract information and excludes only the specified legal obligations. Open-source rights remain independent.
After delivery and effective takeover on the Customer’s or new provider’s infrastructure, the receiving operator assumes transferred hosting, maintenance, security and compliance operations. The outgoing Provider supplies no continuing service outside the agreed scope, without being released from earlier breaches, transition duties or liabilities that law preserves.