-

4CHEMS Enterprise Pack (Template)

Provider: 4CHEMS ([Company Legal Name])
Trust Center URL: [https://www.stressmaniacs.com/trust] (recommended)
Timezone: Europe/Berlin (CET/CEST)


Enterprise Pack Index

  1. Master Subscription Agreement (MSA)
  2. Service Level Agreement (SLA)
  3. Support & Escalation Policy
  4. Data Processing Addendum (DPA) – GDPR Art. 28
  5. Subprocessors List & Update Policy
  6. Data Residency & Processing Locations Policy
  7. Data Retention, Deletion, and Return Policy
  8. Data Export & Portability Policy
  9. Security Policy / Security Whitepaper
  10. Incident Response & Breach Notification Policy
  11. Business Continuity & Disaster Recovery (BCDR) Policy
  12. Change Management & Deprecation Policy
  13. Acceptable Use Policy (AUP)
  14. Procurement: Ordering, PO, Invoicing, and Payment Terms
  15. Vulnerability Disclosure Policy (VDP)
  16. Audit, Compliance, and Customer Due Diligence Policy

Master Subscription Agreement (MSA)

Master Subscription Agreement
Effective Date: [DATE]
Provider: [Company Legal Name], [Address] (“Provider”)
Customer: [Customer Legal Name], [Address] (“Customer”)

1. Purpose and structure

1.1 This MSA governs Customer’s access to and use of Provider’s software-as-a-service platform (“Service”).
1.2 Each order form, statement of work, or online checkout that references this MSA (“Order”) incorporates this MSA by reference. If an Order conflicts with this MSA, the Order controls only for that conflict.

2. Definitions

  • “Customer Data” means all data, content, files, and information submitted to the Service by or for Customer.
  • “Documentation” means Provider’s technical/user documentation for the Service.
  • “Authorized Users” means individuals Customer authorizes to use the Service under Customer’s account.
  • “Confidential Information” has the meaning in Section 10.

3. Subscription and access

3.1 Access grant. During the Subscription Term, Provider grants Customer a non-exclusive, non-transferable right to access and use the Service and Documentation for Customer’s internal business purposes, subject to this MSA and the AUP.
3.2 Authorized Users. Customer is responsible for Authorized Users’ compliance and for maintaining account credentials securely.
3.3 Restrictions. Customer will not (and will not permit others to): (a) reverse engineer the Service; (b) circumvent security; (c) access the Service to build a competing product; (d) use the Service unlawfully; (e) exceed usage limits in an Order.

4. Customer responsibilities

4.1 Customer is responsible for the accuracy, quality, and legality of Customer Data and for obtaining any necessary rights/consents.
4.2 Customer will maintain appropriate technical and organizational measures for its own systems (e.g., endpoint security, access controls).

5. Provider responsibilities

5.1 Provider will provide the Service in accordance with the Documentation and the SLA.
5.2 Provider will implement and maintain a security program as described in the Security Policy.

6. Fees, billing, and taxes

6.1 Fees. Customer will pay fees in the Order. Fees are non-refundable except as expressly stated.
6.2 Invoicing. Provider invoices per the Order. Unless stated otherwise, invoices are due Net 30 from invoice date.
6.3 Taxes. Fees exclude taxes. Customer is responsible for applicable taxes, excluding Provider’s income taxes.

7. Intellectual property

7.1 Provider IP. Provider retains all rights in the Service, Documentation, and Provider materials.
7.2 Customer Data. Customer retains all rights in Customer Data. Provider may process Customer Data only to provide, secure, maintain, and improve the Service as permitted by this MSA and the DPA.
7.3 Feedback. Customer may provide feedback; Provider may use feedback without restriction, without identifying Customer.

8. Confidentiality

8.1 Definition. “Confidential Information” means non-public information disclosed by a party that is marked confidential or should reasonably be understood as confidential. Customer Data is Customer Confidential Information.
8.2 Obligations. Receiving party will protect Confidential Information using reasonable care and not disclose it except to employees/contractors with a need to know who are bound by confidentiality.
8.3 Exclusions. Does not include information that is public, independently developed, or rightfully received from a third party.
8.4 Compelled disclosure. If legally required to disclose, receiving party will (where lawful) give prompt notice and cooperate to limit disclosure.

9. Data protection

9.1 The parties will comply with the DPA (if applicable). The DPA is incorporated by reference.
9.2 If Customer does not provide Personal Data to the Service, this section still applies to any Personal Data processed incidentally (e.g., user account data).

10. Warranty and disclaimers

10.1 Performance warranty. Provider warrants it will provide the Service in a professional manner consistent with generally accepted industry standards.
10.2 Disclaimer. Except as expressly stated, the Service is provided “as is.” Provider disclaims implied warranties including merchantability, fitness, and non-infringement to the maximum extent permitted by law.

11. Indemnities

11.1 IP infringement by Provider. Provider will defend Customer against third-party claims alleging the Service infringes IP rights, and pay covered damages/costs, provided Customer promptly notifies and cooperates.
11.2 Exclusions. Provider’s obligation does not apply to claims arising from: (a) Customer Data; (b) unauthorized modifications; (c) use with non-Provider systems contrary to Documentation; (d) Customer’s breach of this MSA.
11.3 Customer indemnity. Customer will defend Provider against claims arising from Customer Data or Customer’s misuse of the Service.

12. Limitation of liability

12.1 Cap. Except for Excluded Claims, each party’s total liability arising out of this MSA will not exceed the fees paid (or payable) by Customer under the applicable Order in the 12 months preceding the event.
12.2 No consequential damages. Neither party is liable for indirect, incidental, special, consequential, or punitive damages, or loss of profits/revenue, even if advised.
12.3 Excluded Claims. The limitations do not apply to: (a) confidentiality breaches; (b) a party’s infringement indemnity obligations; (c) Customer’s non-payment; (d) willful misconduct or fraud; (e) liability that cannot be limited by law.

13. Term and termination

13.1 Term. This MSA begins on the Effective Date and continues until all Orders expire or are terminated.
13.2 Subscription term. Each Order has a Subscription Term.
13.3 Termination for cause. Either party may terminate an Order if the other materially breaches and fails to cure within 30 days of notice (or 10 days for non-payment).
13.4 Effect. On termination/expiry, Customer’s access ends. Provider will make Customer Data available per the Data Return/Deletion Policy.

14. Suspension

Provider may suspend access if: (a) required by law; (b) Customer breaches the AUP; (c) Customer’s use threatens the security or availability of the Service; or (d) overdue payment, after notice. Provider will narrow suspension to the minimum necessary and restore access promptly when resolved.

15. Governing law and dispute resolution

Governing law: [Germany OR other jurisdiction]
Venue: [Courts/Arbitration]

16. General

Assignment, notices, force majeure, severability, waiver, entire agreement, order of precedence, and relationship of the parties (independent contractors).

Signatures
Provider: ****____**** Date: __
Customer: ****____**** Date: __


Service Level Agreement (SLA)

Service Level Agreement
Effective Date: [DATE]
Applies to the Service under an active paid subscription.

1. Definitions

  • “Monthly Uptime Percentage” = (Total minutes in month − Downtime minutes) / Total minutes in month × 100.
  • “Downtime” means the Service is unavailable for end users due to Provider-controlled issues, excluding Exclusions.

2. Uptime commitment

Provider targets 99.9% Monthly Uptime Percentage.

3. Exclusions

Downtime excludes:
(a) Scheduled maintenance (Section 4),
(b) Force majeure,
(c) Customer’s systems, networks, or misconfiguration,
(d) Beta/preview features labeled as such,
(e) Suspension due to AUP breach or security threat.

4. Maintenance windows

  • Planned maintenance: communicated at least 72 hours in advance, typically outside business hours in Europe/Berlin (CET/CEST).
  • Emergency maintenance: as needed for security or stability; Provider will notify as soon as practicable.

5. Incident communication

Provider will provide status updates for Severity 1 incidents at least every 60 minutes until mitigation.

6. Service credits (optional)

If Monthly Uptime falls below:

  • 99.9% – 99.0%: 5% credit of monthly fee
  • 99.0% – 95.0%: 10% credit
  • < 95.0%: 20% credit

Process: Customer must request credits within 30 days of month end. Credits apply to future invoices; not cash.

7. Sole remedy

Service credits are Customer’s sole remedy for SLA breaches, unless otherwise required by law.


Support & Escalation Policy

1. Support channels

  • Web portal: [URL]
  • Email: [support@stressmaniacs.com]
  • (Optional) Phone for Severity 1: [Phone]

2. Hours of coverage

  • Standard: [Mon–Fri 09:00–17:00 CET/CEST]
  • Severity 1: [24/7 for Enterprise plan OR best-effort outside hours]

3. Severity definitions

  • Severity 1 (Critical): production outage or major security incident; no workaround.
  • Severity 2 (High): major feature degraded; workaround exists.
  • Severity 3 (Medium): limited impact; minor degradation.
  • Severity 4 (Low): general questions, feature requests.

4. Response targets

SeverityInitial responseUpdate cadence
Sev 11 hourhourly
Sev 24 business hoursdaily
Sev 31 business dayweekly
Sev 42 business daysas needed

5. Escalation path

Support → On-call engineer (Sev 1) → Engineering lead → Executive sponsor.


Data Processing Addendum (DPA) – GDPR Art. 28

Data Processing Addendum
Between Provider and Customer, effective [DATE]. Applies when Provider processes Personal Data on behalf of Customer under the Service.

1. Roles

  • Customer is the Controller (or Processor acting on behalf of a Controller).
  • Provider is the Processor.

2. Subject matter and duration

Processing is limited to providing the Service, for the term of the MSA plus any period necessary for return/deletion per policy.

3. Nature and purpose

Hosting, storing, analyzing, transmitting, and otherwise processing Personal Data to deliver and secure the Service; support and incident handling.

4. Types of data and data subjects

  • Data subjects: Customer employees, contractors, and Customer end users (as applicable).
  • Data categories: account identifiers, contact data, usage metadata, and any Personal Data included in Customer Data.

5. Documented instructions

Provider will process Personal Data only on documented instructions from Customer, including transfers, unless required by law (then Provider will notify Customer unless prohibited).

6. Confidentiality

Provider ensures personnel authorized to process Personal Data are under confidentiality obligations.

7. Security measures

Provider implements appropriate technical and organizational measures (TOMs). See Annex 2 for baseline TOMs (aligned with the Security Policy).

8. Subprocessors

8.1 Customer authorizes Provider to use subprocessors listed in the Subprocessors List (Annex 3 / Trust Center).
8.2 Provider will impose data protection obligations on subprocessors no less protective than this DPA.
8.3 Provider remains liable for subprocessors’ performance of obligations under this DPA.
8.4 Provider will provide advance notice of new/changed subprocessors per the Subprocessor Update Policy and offer an objection mechanism.

9. Assistance

Provider will assist Customer (taking into account nature of processing) with:

  • data subject requests (access, deletion, etc.),
  • DPIAs and prior consultations where reasonably required,
  • security and breach information as needed.

10. Personal data breach

Provider will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide available information to support Customer’s notification obligations.

11. Data return and deletion

Upon termination or Customer request, Provider will return and/or delete Personal Data per the Data Retention/Deletion Policy, unless retention is required by law.

12. Audits

Provider will make available information reasonably necessary to demonstrate compliance and allow audits under the Audit Policy (including confidentiality and security constraints).

13. International transfers

The Service is hosted and processed in the EU (Germany and Finland). If Personal Data is transferred outside the EEA/UK/Switzerland (e.g., due to a subprocessor), Provider will use a valid transfer mechanism (e.g., SCCs) and supplementary measures as applicable.

14. Order of precedence

If conflict: DPA controls for data protection terms.

Annex 1 – Processing details

  • Service: [Service name]
  • Processing activities: hosting, access management, support, analytics necessary for service operation, backups, incident response.

Annex 2 – Technical and organizational measures (baseline)

  • Access control (RBAC, least privilege, MFA for admin)
  • Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
  • Logging and monitoring; audit logs for admin actions
  • Vulnerability management (patching SLAs, scanning)
  • Backups and recovery testing (multi-region)
  • Secure SDLC and change control
  • Incident response plan and training

Annex 3 – Subprocessors

See “Subprocessors List & Update Policy” section below.


Subprocessors List & Update Policy

1. Subprocessors list

Provider maintains an up-to-date list of subprocessors that may process Customer Personal Data.

Current subprocessors (fill with your real vendors):

SubprocessorPurposeData typesLocation(s)
[Hosting / IaaS provider]Infrastructure hostingCustomer DataGermany, Finland
[Email provider]Support emailsContact data[EU/EEA or SCC]
[Monitoring provider]Monitoring/alertstelemetry/metadata[EU/EEA or SCC]

2. Update and notice

  • Provider will provide at least 30 days notice before adding/replacing a subprocessor that processes Customer Personal Data.
  • Notice method: Trust Center update + email to Customer admin contacts.

3. Objection mechanism

Customer may object in writing within the notice period on reasonable data protection grounds. The parties will work in good faith to resolve. If unresolved, Customer may terminate the affected Order without penalty for the impacted Service component (commercial handling: [pro-rata credit/refund if offered]).


Data Residency & Processing Locations Policy

1. Default residency

Customer Data is stored and processed in the European Union, specifically:

  • Germany
  • Finland

2. Multi-region architecture note

Customer Data and backups are designed for multi-region resilience across Germany and Finland, subject to the Service’s architecture and Customer configuration.

3. Access from other locations

Provider personnel may access systems from other locations for support/operations only when necessary and under access controls (MFA, logging, least privilege).

4. Cross-border transfers

If a subprocessor causes transfers outside the EEA/UK/Switzerland, Provider uses valid transfer mechanisms (e.g., SCCs) and documents them in the DPA.

5. Customer choice (optional)

Provider may offer region pinning or tenant region preferences for Enterprise plans: [Yes/No/Planned].


Data Retention, Deletion, and Return Policy

1. Retention during subscription

Provider retains Customer Data for the duration of the subscription, including routine backups.

2. Return window after termination

Upon termination/expiry, Customer may export Customer Data for 60 days (“Export Window”). (You can change 60 → 30/90 based on your ops.)

3. Deletion timeline

After the Export Window:

  • Primary systems: deleted within 30 days
  • Backups (multi-region): overwritten/expired within 180 days depending on backup cycles

4. Deletion confirmation

Upon request, Provider will provide written confirmation that Customer Data has been deleted, subject to any lawful retention requirements.

Provider may retain limited data if required by law, court order, or to establish/defend legal claims, and will restrict access to retained data.


Data Export & Portability Policy

1. Export methods

Customer can export Customer Data via:

  • self-serve export in the UI, and/or
  • API endpoints, and/or
  • Provider-assisted export for Enterprise plans.

2. Formats

Default formats (choose what you truly support):

  • Structured: JSON / CSV
  • Attachments: original binary files
  • Reports: [PDF if applicable]

3. Frequency and limits

  • Self-serve exports: up to [X] per day; large exports may run in the background in-product.
  • Provider-assisted exports: within 10 business days depending on size.

4. Integrity

Exports include timestamps, record identifiers, and relationships where feasible. Provider will document schema and versioning.


Security Policy / Security Whitepaper

1. Security governance

  • Security owner: [Role/Team]
  • Policies reviewed at least annually or upon material changes.

2. Identity and access management

  • RBAC and least privilege
  • MFA enforced for admin access
  • SSO supported: SAML 2.0 and OIDC (availability by plan: [All/Enterprise])
  • (Optional) SCIM user provisioning: [Supported/Planned/Not supported]
  • Access reviews at least [quarterly]

3. Encryption

  • In transit: TLS 1.2+
  • At rest: encryption using industry-standard algorithms (e.g., AES-256 or equivalent)
  • Secret management: keys stored in managed KMS/HSM where available; rotation policy [e.g., annually or upon incident]

4. Application security

  • Secure SDLC with code reviews and automated testing
  • Dependency scanning and vulnerability alerts
  • Separation of environments (dev/stage/prod)
  • Principle of least privilege for services and databases

5. Infrastructure security

  • Hardened baseline images
  • Network segmentation; firewalls/security groups
  • Continuous monitoring for availability and suspicious activity
  • Hosting regions: Germany and Finland

6. Logging and monitoring

  • Centralized logs for auth events, admin actions, and critical system events
  • Monitoring and alerting for incidents
  • Log retention: [e.g., 90 days standard, 365 days enterprise]

7. Vulnerability management

  • Vulnerability scanning cadence: [weekly/monthly]
  • Patch timelines (example):
    • Critical: 7 days
    • High: 30 days
    • Medium: 90 days
  • Penetration testing: [annual / on major changes] (or third-party assessment)

8. Data protection

  • Data minimization in telemetry
  • Tenant isolation controls
  • Backups encrypted and access-controlled (multi-region)

9. Personnel security

  • Background checks where lawful
  • Security training on hire and at least annually
  • Offboarding: access revoked within 24 hours

10. Physical security

Relies on data center controls from infrastructure providers; Provider reviews provider attestations where available.


Incident Response & Breach Notification Policy

1. Scope

Applies to security incidents affecting confidentiality, integrity, or availability of the Service, including suspected Personal Data Breaches.

2. Roles and escalation

  • Incident Commander: [Role]
  • Security lead: [Role]
  • Communications lead: [Role]

3. Triage and severity

  • Sev 1: active compromise, widespread outage, or confirmed breach
  • Sev 2: high-risk vulnerability or partial compromise
  • Sev 3/4: lower impact events

4. Response phases

  1. Detect & verify
  2. Contain (short-term)
  3. Eradicate & remediate
  4. Recover & validate
  5. Post-incident review (RCA, corrective actions)

5. Customer notification

  • Provider will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
  • Notification includes (as available): nature of incident, categories/approx. number of records affected, likely consequences, measures taken, recommended Customer actions.

6. Evidence and forensics

Provider preserves relevant logs and evidence subject to legal constraints and confidentiality.


Business Continuity & Disaster Recovery (BCDR) Policy

1. Objectives

  • RPO (Recovery Point Objective): 24 hours (recommended default; set to your actual commitment)
  • RTO (Recovery Time Objective): 8 hours (recommended default; set to your actual commitment)

2. Backup strategy (multi-region)

  • Automated backups of databases and critical storage
  • Backups replicated/stored multi-region across Germany and Finland (where supported by architecture)
  • Backup retention: [e.g., 30 daily, 12 monthly]
  • Backups encrypted and access-controlled

3. Redundancy and failover

  • Multi-region recovery design: Germany ↔ Finland
  • Documented failover procedures and access controls for emergency operations

4. Testing

  • DR test cadence: [annual / semiannual]
  • Post-test review and improvements tracked

5. Crisis communications

  • Status page: [URL]
  • Customer notifications for Sev 1 incidents via [email/portal]

Change Management & Deprecation Policy

1. Change categories

  • Standard changes: routine releases and improvements
  • Material changes: changes impacting security, data processing, APIs, or workflows
  • Breaking changes: require customer action (API deprecation, removal)

2. Communication

  • Release notes: [URL]
  • Material changes: at least 30 days notice where feasible
  • Breaking changes: at least 90 days notice (unless urgent security fixes)

3. Change controls

  • Code review, automated tests, staged rollout, rollback plan
  • Emergency changes allowed with post-change review

Acceptable Use Policy (AUP)

Customer and Authorized Users must not:

  1. Violate laws or regulations.
  2. Upload malware or attempt to disrupt the Service.
  3. Attempt unauthorized access, probing, scanning, or pentesting without written permission.
  4. Use the Service to infringe IP or privacy rights.
  5. Transmit illegal or harmful content.
  6. Abuse rate limits or attempt to bypass usage controls.
  7. Use the Service to build a competing offering or to resell unless explicitly permitted.

Provider may suspend accounts for AUP violations per the MSA.


Procurement: Ordering, PO, Invoicing, and Payment Terms

1. Ordering

Orders may be executed via:

  • signed Order Form, or
  • online checkout (if enabled), or
  • Customer purchase order (“PO”) referencing an Order Form.

2. Purchase orders

  • Provider may accept POs for Enterprise plans.
  • Any PO terms not in the MSA are rejected and will not apply.

3. Invoicing and payment

  • Default: annual invoicing in advance, Net 30
  • Late fees: [e.g., 1.5% per month] or maximum allowed by law
  • Billing contact: [billing@stressmaniacs.com]

4. Currency

EUR unless otherwise specified.


Vulnerability Disclosure Policy (VDP)

1. Reporting

Security researchers and customers may report vulnerabilities to:

  • Email: [security@stressmaniacs.com]
  • Subject: “Vulnerability Disclosure – [short description]”

2. Safe harbor

Provider will not pursue legal action for good-faith research that:

  • avoids privacy violations, data destruction, and service disruption,
  • uses only test accounts or data the reporter owns,
  • gives Provider reasonable time to remediate before public disclosure.

3. What to include

  • Steps to reproduce
  • Impact assessment
  • Affected endpoints/components
  • Proof-of-concept (if safe)

4. Response targets (example)

  • Acknowledgment within 3 business days
  • Status update within 10 business days

Audit, Compliance, and Customer Due Diligence Policy

1. Standard due diligence package

Provider will make available (under NDA if needed):

  • Security Policy/Whitepaper (including SSO: SAML + OIDC)
  • DPA + Subprocessors list
  • SLA + Support Policy
  • High-level architecture overview (including hosting: Germany + Finland, multi-region backups)
  • (Optional) pen-test executive summary or attestation letters

2. Customer audits

  • Frequency: no more than once per year unless a material incident occurs
  • Format: remote documentation review first; on-site only if necessary
  • Notice: 30 days
  • Scope: limited to systems relevant to Customer Data
  • Cost: Customer pays its audit costs; Provider assistance beyond reasonable time may be billable at [rate]

3. Certifications (optional)

List actual certifications/attestations and scope:

  • [ISO 27001 / SOC 2 / etc.][scope + validity dates]
    If not certified, you may state: “Provider maintains a security program aligned with industry standards and may pursue formal certifications based on customer demand.”