Scheduled Export Policy (Automated Data + Configuration Exports)
Owner: 4CHEMS Security/Platform Team
Effective date: [DATE]
Applies to: All paid subscriptions (scope varies by plan)
1) Purpose
This policy reduces customer burden during vendor reviews by providing predictable, self-serve data portability and operational continuity through scheduled exports.
2) What can be exported
Exports may include (depending on features enabled and customer configuration):
2.1 Customer Data Export
- Structured records relevant to the customer tenant/workspace
- Attachments / uploaded files (if applicable)
2.2 Configuration Snapshot (recommended)
- Tenant/workspace settings
- Users, roles, groups, and permissions (excluding secrets)
- Workflows, templates, rules, mappings, and other configurable objects
- Audit-log configuration and integration settings metadata (excluding credentials)
Note: Secrets (API keys, tokens, passwords) are never included in exports. Integrations must be re-authorized by the customer after import/migration.
3) Export frequency options
4CHEMS supports scheduled exports at the following frequencies (plan-based availability):
- Daily
- Weekly
- Monthly
Default frequency per plan (example; adjust to your commercial model):
- Enterprise: Daily / Weekly / Monthly
- Pro: Weekly / Monthly
- Standard: Monthly
4) Export formats
4CHEMS provides exports in one or more of the following formats:
- JSON (canonical export, schema-versioned)
- CSV (human-readable tabular export for core entities)
- Binary files for attachments (original format)
Each export includes a manifest containing:
- Export timestamp (UTC)
- Tenant/workspace identifier
- Export components included (data/config/files)
- Schema/version identifiers
- File list and checksums (e.g., SHA-256) for integrity verification
5) Delivery methods
Exports can be delivered via one or more methods (plan-based availability):
5.1 Pull (self-serve)
- Download via Admin UI or API
- Time-limited download links
5.2 Push (enterprise option)
- Customer-managed object storage location (e.g., S3-compatible bucket / Azure Blob / GCS)
- Delivery uses customer-provided endpoint and credentials, stored and handled securely
6) Retention of export artifacts
Unless otherwise specified in the Order Form:
- Export artifacts stored by 4CHEMS are retained for 30 days (default)
- Enterprise customers may select 60–90 days retention
Customers are responsible for retaining copies in their own storage if longer retention is required.
7) Availability and limits
- Large exports may be queued and completed asynchronously.
- Reasonable rate limits and fair-use controls may apply to prevent service degradation.
- If an export fails, 4CHEMS will retry automatically and/or surface an error to the admin with next steps.
8) Security and privacy
- Exports are encrypted in transit (TLS).
- Exports stored by 4CHEMS (if any) are encrypted at rest.
- Access to exports is restricted to authorized tenant administrators.
- Export events are logged in audit logs (where available).
9) Customer responsibilities
Customers should:
- Validate exports periodically (e.g., verify checksums and completeness)
- Store exports securely in accordance with internal policies
- Test their own import/migration procedures if business continuity depends on it
Exit, Continuity, and Service Shutdown Policy
Owner: 4CHEMS Security/Platform Team
Effective date: [DATE]
Applies to: All subscriptions (enhanced terms may be purchased as an add-on)
1) Purpose
This policy defines 4CHEMS commitments for orderly customer exit, including access to customer data and configuration, and contingency options that reduce “vendor viability” concerns.
2) Standard exit support (termination or expiration)
Upon termination or expiration of an Order:
2.1 Export window
- Customer will have 60 days (default) of access to export Customer Data and Configuration Snapshots (“Export Window”).
- During the Export Window, access may be limited to read-only at 4CHEMS discretion for security and integrity.
2.2 Final export on request
On request during the Export Window, 4CHEMS will provide:
- One final full export of Customer Data and a Configuration Snapshot
- In the formats described in the Scheduled Export Policy
2.3 Deletion timeline
After the Export Window:
- Customer Data in primary systems will be deleted within 30 days
- Backup data will be deleted/overwritten within 180 days (aligned to backup lifecycle)
- 4CHEMS can provide written deletion confirmation upon request, subject to legal retention requirements.
3) Service shutdown / cessation of operations
If 4CHEMS permanently discontinues the Service (“Service Shutdown”), 4CHEMS will:
3.1 Advance notice
Provide notice as early as reasonably possible, and at least 90 days in advance where feasible.
3.2 Continuity period
Maintain one of the following (as determined by 4CHEMS and subject to legal/operational constraints):
- A read-only access period for at least 6 months, or
- A guaranteed data delivery path providing Customer Data and Configuration Snapshots within 30 days of shutdown announcement.
3.3 Data delivery contents
Data delivery will include:
- Full Customer Data export
- Configuration Snapshot
- Export manifest with checksums and schema versions
3.4 Optional migration assistance (enterprise)
Enterprise customers may purchase (or include in their Order):
- A defined number of hours of migration support
- Priority scheduling of final exports
- Dedicated point of contact
4) Source code access: escrow-based option (Enterprise Add-on)
4CHEMS does not provide source code to customers by default. For enterprise customers with heightened continuity requirements, 4CHEMS may offer a Source Code Escrow Add-on governed by an escrow agreement.
4.1 Escrow deposit contents (example)
Deposits may include:
- Source code for the Service components necessary to run the customer-facing service
- Build and deployment instructions
- Infrastructure-as-code and configuration templates (excluding secrets)
- Dependency and version manifests
- Operational runbooks for basic deployment and recovery
4.2 Verification (optional)
An escrow agent may verify on a defined cadence (e.g., quarterly) that the deposit is complete and buildable.
4.3 Release (trigger) events
Escrow materials may be released to Customer only upon defined trigger events, such as:
- Permanent Service Shutdown without a commercially reasonable successor service offered
- Insolvency or bankruptcy proceedings that materially prevent service continuation
- Material breach of continuity obligations not cured within an agreed cure period
4.4 License scope upon release
Upon release, Customer receives a limited license to:
- Use the escrow materials solely to operate, maintain, and support the Service for Customer’s internal business purposes
- Not to sell, publish, or create a competing service
- Not to disclose escrow materials outside Customer’s organization and its contractors under written confidentiality obligations
5) Hosting locations and resilience commitments (context)
- The Service is hosted in the European Union, specifically Germany and Finland.
- Backups are designed for multi-region resilience across these locations.
6) Limitations
- 4CHEMS obligations under this policy may be constrained by applicable law, third-party provider limitations, and security considerations.
- This policy does not modify the MSA/DPA unless expressly incorporated into an Order Form.
7) Contact
For export, exit, or continuity requests:
- Support: [support@stressmaniacs.com]
- Security/Trust: [security@stressmaniacs.com]