2. Definitions and interpretation
“Agreement” means these Terms together with any Order, Quote, Statement of Work, Service Level Agreement, AMC Schedule or Data Processing Agreement that refers to them.
“AMC” means an annual maintenance contract or other recurring support and maintenance arrangement described in an AMC Schedule or Order.
“Client” means the person or organisation that obtains Services or Products from us.
“Client Data” means all data, including Personal Data, that the Client or its users store in, or that we access in, Client Systems in the course of the Services.
“Client Systems” means the Client’s cloud accounts, subscriptions, tenants, servers, networks, devices, applications, domains and productivity environments (including Microsoft 365, Google Workspace and Zoho) that we access, manage or support.
“Credentials” means usernames, passwords, access keys, API tokens, certificates, recovery codes, multi-factor authentication factors, delegated administrative privileges and any other means of access to Client Systems.
“Order” means a purchase order, order form, signed Quote or Statement of Work accepted in writing (including by email) by both parties.
“Personal Data” has the meaning given in the Digital Personal Data Protection Act, 2023 and, where applicable, the GDPR.
“Products” means third-party software licences, subscriptions, cloud services and hardware that we resell, including those of Amazon Web Services, Microsoft, Google, Zoho, Adobe and Apple.
“Services” means professional, managed, migration, consulting, support, AMC, licensing administration and cloud billing services that we provide.
“Vendor” means the manufacturer, publisher or provider of a Product, and its authorised distributor.
“Vendor Terms” means the end-user, customer or licence terms of a Vendor that govern a Product.
“Website” means devopstechlab.com and all of its pages, forms, tools and content.
2.2Headings are for convenience only. “Including” means “including without limitation”. “Writing” includes email. References to a law include that law as amended or re-enacted.
5. Website content, estimates and third-party links
5.1Content on the Website is general information. It is not professional advice and does not constitute an offer capable of acceptance. A contract is formed only by an Order.
5.2Prices on the Website are indicative, stated exclusive of GST and other taxes unless marked otherwise, and may change without notice. A price is binding only when stated in a Quote or Order, for the validity period stated in it.
5.3Cost calculators, savings figures, guides, case studies and other resources are estimates based on assumptions and information available when published. Actual results depend on your environment and current Vendor pricing. Case study results relate only to the client concerned.
5.4Links to third-party websites are provided for convenience. We do not control and are not responsible for their content, terms or privacy practices.
6. Intellectual property
6.1All intellectual property rights in the Website, our methodologies, tools, scripts, templates, runbook formats, know-how and pre-existing materials (“DevOps TechLab Materials”) remain with us or our licensors.
6.2Subject to full payment, the Client owns deliverables created specifically for it under an Order, excluding DevOps TechLab Materials. We grant the Client a perpetual, non-exclusive, royalty-free licence to use DevOps TechLab Materials incorporated in deliverables (including runbooks) for its internal business purposes.
6.3The Client retains all rights in Client Data and Client Systems. Nothing in the Agreement transfers ownership of any Client tenant, account, domain or data to us.
6.4AWS, Amazon Web Services, Microsoft, Azure, Microsoft 365, Google Cloud, Google Workspace, Zoho, Adobe, Creative Cloud, Apple and other names are trademarks of their respective owners. Their use indicates our credentials as a partner or authorised reseller and does not imply endorsement of the Website or the Services.
6.5Client names and logos shown on the Website are used with the permission of their owners under Section 21, remain their property, and may not be copied or reused by anyone else.
9. Administrative access and credentials
9.1Grant of access. The Client authorises us to access Client Systems to the extent necessary to perform the Services. Wherever the platform supports it, access will be granted through named, role-based or delegated administration (for example, delegated admin roles in Microsoft 365, IAM roles or federated access in AWS, or admin roles in Google Workspace) rather than shared or personal passwords.
9.2Least privilege. We will request only the privileges reasonably required, and will tell the Client when higher privileges are needed for a specific task.
9.3Safeguarding Credentials. We will:
- store Credentials only in an encrypted, access-controlled password vault, and never in plain text, email, chat or tickets;
- restrict access to named personnel with a need to know, each bound by written confidentiality obligations;
- require multi-factor authentication for our personnel and for our vault;
- log access to Client Systems where the platform allows, and make relevant logs available to the Client on reasonable request;
- revoke a person’s access promptly when they no longer need it or leave our organisation.
9.4Use of access. We will use Credentials only to perform the Services and on the Client’s documented instructions. We will not access Client Data except as needed for the Services, will not change account ownership, billing ownership or global security settings without the Client’s written approval, and will obtain approval through the agreed change process for changes classed as high-risk in the Order.
9.5Emergency action. If we reasonably believe that a Client System is under attack, compromised or at imminent risk, we may take proportionate emergency action (such as disabling an account, revoking a session or isolating a resource) without prior approval, and will notify the Client as soon as practicable.
9.6Credentials shared by the Client. The Client is responsible for the security of Credentials before they reach us and for any Credentials it shares through insecure channels. We are not liable for unauthorised access resulting from Credentials compromised outside our control, from actions of the Client’s personnel or other vendors, or from the Client’s failure to follow our written security recommendations.
9.7Handover on exit. On expiry or termination of the relevant Services, and subject to Section 20, we will return or hand over Credentials and administrative roles, remove our access, and confirm this in writing. The Client must then rotate or reset all Credentials to which we had access. We are not responsible for any access occurring after handover through Credentials the Client has not rotated.
10. Client data, confidentiality and security
10.1Roles. For Client Data, the Client is the Data Fiduciary (or controller) and we act as a Data Processor (or processor) on the Client’s documented instructions. Where required by law or requested by the Client, the parties will sign a Data Processing Agreement, which will prevail for the processing of Personal Data.
10.2Confidentiality. Each party will keep the other’s Confidential Information secret, use it only for the Agreement, and disclose it only to personnel, subcontractors and advisers who need to know it and are bound by equivalent obligations. “Confidential Information” includes Client Data, Credentials, system architecture, security information, pricing and business information, but excludes information that is public through no fault of the recipient, already lawfully known to it, independently developed or lawfully received from a third party. Disclosure required by law or a regulator is permitted with prior notice where lawful. These obligations survive for five years after termination, and indefinitely for Credentials and Client Data.
10.3Security measures. We will maintain reasonable security practices and procedures appropriate to the nature of the data, including access control, encryption in transit, secure credential storage, endpoint protection on our devices, logging, staff training and confidentiality undertakings, consistent with the Information Technology Act, 2000 and the rules under it.
10.4Incidents. We will notify the Client without undue delay, and in any event within 24 hours, after becoming aware of a security incident affecting Client Data or Client Systems under our management. We will provide the information reasonably available to us and cooperate with the Client’s investigation and with any report the Client must make to CERT-In, the Data Protection Board of India or another authority. Each party will meet its own statutory reporting obligations.
10.5Sub-processors. We may use sub-processors (such as hosting, ticketing, monitoring and backup providers) under written terms with equivalent protections. A list is available on request, and we will inform Clients who have signed a Data Processing Agreement of material changes.
10.6Location and transfers. Client Data remains in the regions the Client selects for its Client Systems. Our personnel may access it remotely from India. Where Client Data is subject to the GDPR, the Data Processing Agreement will set out the transfer safeguards.
10.7Return and deletion. On termination, and on the Client’s written request made within 30 days, we will return Client Data in our possession in a commonly used format and then delete it, except where retention is required by law, in which case it remains subject to this Section.
10.8Audit. On reasonable written notice, not more than once in any 12-month period and at the Client’s cost, we will answer the Client’s reasonable security questionnaires and provide information needed to demonstrate compliance with this Section.
12. Licensing and product resale
12.1Vendor Terms. Products are supplied subject to the applicable Vendor Terms (including, as relevant, the AWS Customer Agreement, the Microsoft Customer Agreement, Google Workspace and Google Cloud terms, Zoho terms, Adobe General Terms of Use and Apple terms and warranty). The Client must accept Vendor Terms where the Vendor requires it, and is responsible for complying with them. We may be required to share Client details with the Vendor for provisioning, billing, compliance and deal registration.
12.2Commitment and cancellation. Once we place an order with a Vendor at the Client’s request, it is binding for the commitment term set by the Vendor. Cancellations, refunds and seat reductions are possible only within any cancellation window the Vendor allows and are otherwise limited to renewal dates. The Client remains liable for the full commitment term.
12.3Pricing. Vendors may change prices, plans, currency rates and taxes. We may pass on such changes for new orders, additional seats and renewals. Our price commitments in a Quote apply only for its validity period and stated term.
12.4Usage and true-ups. The Client must use Products within the licensed quantities and rules. Any additional usage, overage or true-up identified by the Client, us or the Vendor is chargeable.
12.5Renewals. Subscriptions renew as set out in the Order or as the Vendor’s rules provide. The Client must tell us in writing at least 30 days before a renewal date of any reduction or cancellation.
12.6Hardware. Risk in hardware passes on delivery; title passes on full payment. Hardware is covered only by the manufacturer’s warranty and any AppleCare or extended cover purchased. Returns follow the manufacturer’s and distributor’s policies.
12.7Vendor responsibility. Each Vendor is solely responsible for its Products, including their availability, performance, security and support commitments. We will pass through Vendor warranties and help the Client raise Vendor support cases, but we give no warranty for Products beyond the Vendor’s own.
12.8Change of partner. Once all amounts due to us are paid, we will cooperate with a Client’s reasonable request to transfer its subscriptions or partner-of-record relationship to another partner, as the Vendor’s rules allow.
18. Limitation of liability
18.1Neither party will be liable for any indirect, incidental, special, punitive or consequential loss, or for any loss of profit, revenue, business, goodwill, anticipated savings or data (except the cost of restoring data from available backups where we caused the loss), however arising.
18.2Our total aggregate liability arising out of or in connection with the Agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise, will not exceed the fees paid by the Client to us for the specific Services giving rise to the claim in the 12 months preceding the event giving rise to the liability. For Products, it will not exceed the margin we earned on the relevant Product in that period.
18.3We are not liable for any loss arising from: Vendor products, outages or policy changes; acts or omissions of the Client, its personnel or other vendors; Credentials compromised outside our control; the Client’s failure to follow our written recommendations; or usage charges described in Section 13.
18.4Nothing in the Agreement limits liability for fraud, for death or personal injury caused by negligence, for the Client’s payment obligations, for a party’s indemnity obligations under Section 19.2, or for any liability that cannot be limited by law.
18.5Any claim must be notified in writing within 12 months of the date the claiming party became aware of the facts giving rise to it.
21. Publicity and use of client names and logos
21.1Licence to use Client Marks. The Client grants us a non-exclusive, non-transferable, royalty-free, worldwide licence, for the term of the Agreement and after it ends, until the Client withdraws it under Section 21.5 or asks us to remove the Client Marks, to use the Client’s name, logo and trademarks (“Client Marks”) solely to identify the Client as a customer of DevOps TechLab, including in:
- client lists and logo displays on the Website and our social media channels;
- proposals, presentations, credentials documents and tender responses;
- event, exhibition and printed marketing materials;
- submissions to Vendors for partner programme, competency and designation validation, on a confidential basis.
21.2Manner of use. We will reproduce Client Marks accurately from files supplied or approved by the Client, follow any brand guidelines the Client provides, not alter or distort them, and not use them in a way that suggests the Client endorses us beyond being our customer, or that is misleading or disparaging.
21.3Content that needs prior approval. We will obtain the Client’s prior written approval (email is sufficient) before publishing any:
- case study, success story or project description that names the Client;
- testimonial, quote, video or review attributed to the Client or its personnel;
- figures about the Client’s results, savings, costs, scale or performance;
- names, photographs or job titles of the Client’s personnel;
- press release or public announcement about the engagement.
21.4We will never disclose Confidential Information, Client Data, security information, system architecture or Credentials in any publicity material, whether or not approval has been given.
21.5Opting out and withdrawal. The Client may decline or withdraw the licence in Section 21.1 or any approval under Section 21.3 at any time by written notice to janak@devopstechlab.com or in its Order. We will remove the Client Marks and approved content from the Website and our social media channels within 10 business days and stop using them in new materials. We are not required to recall printed materials already distributed, past social media posts that cannot reasonably be edited, or submissions already made to Vendors.
21.6Ownership. Client Marks remain the property of the Client, and all goodwill from their use accrues to the Client.
21.7Vendor verification. Vendors may contact the Client to verify a reference or project we have submitted for partner programme purposes. The Client may decline to take part.
21.8Our marks. The Client may state that DevOps TechLab is its service provider, but may not otherwise use our name, logo or partner badges without our prior written consent.