Compliance

Standard Service Level Agreement

Transparency, accountability and clear expectations — the minimum service levels, support commitments, responsibilities and operational terms applicable to our hosting, cloud, backup, disaster recovery, cyber security and managed IT services.

Unless a separate signed Service Level Agreement exists between Sautech and the Client, this SLA shall govern the delivery of all services provided by Sautech. It defines how services are delivered, how incidents are managed, the responsibilities of both parties, and the limitations applicable to technology, cyber security, backup and disaster recovery services.

Technology services are provided on a commercially reasonable best-effort basis. While Sautech invests heavily in resilient infrastructure, cyber security, monitoring and business continuity, no provider can guarantee uninterrupted availability, complete protection from cyber threats or successful recovery in every circumstance. This SLA establishes a practical framework that protects both the Client and Sautech while ensuring a professional, reliable and transparent service relationship.

We encourage all clients to review this document carefully and contact us should they require a customised SLA tailored to their specific operational, compliance or business requirements.

01Application of this SLA

This Standard Service Level Agreement (“SLA”) applies to all services supplied by Sautech (Pty) Ltd unless superseded by a separate signed agreement between Sautech and the Client.

Where a signed customer-specific SLA exists, the signed SLA shall prevail.

By utilising any Sautech service — including hosting, cloud services, Microsoft 365, backup, disaster recovery, cyber security, monitoring, connectivity, managed services or consulting services — the Client agrees to this SLA.

02Services Covered

This SLA may apply to:

  • Shared Hosting
  • Dedicated Servers
  • Virtual Servers
  • Cloud Hosting
  • Microsoft 365 Services
  • Backup Services
  • Disaster Recovery Services
  • Connectivity Services
  • Managed IT Services
  • Cyber Security Services
  • Monitoring Services
  • Hosted Applications
  • Storage Services
  • Remote Support Services

03Service Availability

Sautech targets high availability across all platforms.

Unless otherwise agreed in writing, the standard uptime target for hosted services is:

95%Monthly Uptime

The uptime calculation excludes:

  • Scheduled maintenance
  • Emergency maintenance
  • Internet provider failures
  • Fibre outages
  • Power utility failures
  • Third-party cloud provider outages
  • Force majeure events
  • Customer-caused interruptions
  • Cyber attacks against third-party providers

Service availability is measured using Sautech monitoring systems.

No service credits shall apply unless specifically agreed in writing.

04Support Hours

Standard Support

Monday to Friday

08:00 – 17:00

South African business days

Emergency Support

Emergency support may be available outside standard hours for qualifying infrastructure outages.

After-hours support may be billable unless included within a managed services agreement.

05Response Targets

PriorityDescriptionResponse Target
CriticalComplete service outage affecting multiple users2 Hours
HighSignificant business impact4 Hours
MediumSingle user or partial service issue8 Business Hours
LowGeneral requests, changes or information2 Business Days

Response targets are not repair guarantees.

06Backup Services

Where backup services are supplied:

  • Backups are provided on a commercially reasonable best-effort basis.
  • Successful backups do not guarantee successful recovery.
  • Recovery times cannot be guaranteed.
  • Backup integrity cannot be guaranteed in all circumstances.
  • Backup services reduce risk but do not eliminate risk.

Clients remain responsible for:

  • Verifying critical data is protected.
  • Testing restoration procedures.
  • Maintaining copies of critical information where required.

Sautech shall not be liable for loss resulting from failed backups, incomplete backups, corrupted backups or unsuccessful recovery attempts.

07Disaster Recovery Services

Disaster Recovery services are designed to improve business continuity.

Disaster Recovery services do not guarantee:

  • Zero downtime.
  • Zero data loss.
  • Immediate restoration.
  • Recovery of all data.

Actual recovery times and recovery points may vary depending on:

  • Incident type
  • System complexity
  • Infrastructure availability
  • Third-party provider availability
  • Extent of corruption or damage

08Cyber Security Services

Cyber security services reduce risk but cannot eliminate risk.

No security service provided by Sautech guarantees protection against:

  • Ransomware
  • Malware
  • Data breaches
  • Insider threats
  • Phishing attacks
  • Zero-day exploits
  • Advanced persistent threats

The Client acknowledges that cyber incidents may still occur despite security controls being in place.

09Client Responsibilities

The Client remains responsible for:

  • Data ownership
  • Regulatory compliance
  • POPIA compliance
  • Password management
  • User access approvals
  • Employee conduct
  • Security awareness training
  • Verification of backups
  • Validation of business continuity requirements

Managed services do not transfer responsibility for the Client's data, systems, compliance obligations or cyber security governance to Sautech.

10Cyber Insurance & Cyber Warranty

Cyber insurance, cyber warranty or cyber protection benefits shall only apply where explicitly confirmed in writing by Sautech.

No quotation, marketing material, proposal, presentation or website content shall constitute confirmation of cover.

All cyber insurance and warranty products remain subject to:

  • Written confirmation
  • Product eligibility
  • Compliance requirements
  • Insurer conditions
  • Applicable exclusions

11Third-Party Providers

Sautech relies upon third-party providers including but not limited to:

  • Microsoft
  • Check Point
  • SentinelOne
  • N-able
  • Veeam
  • Internet Service Providers
  • Domain Registrars
  • Datacentres
  • Cloud Providers

Sautech shall not be liable for outages, delays or failures caused by third-party providers.

12Force Majeure

Sautech shall not be liable for any failure, delay or interruption caused by events beyond its reasonable control. Such events include:

  • Natural disasters
  • Fire
  • Flooding
  • Civil unrest
  • Labour action
  • Government intervention
  • Power grid failures
  • Fibre cable theft
  • Internet outages
  • Datacentre failures
  • Cloud provider failures
  • Cyber warfare
  • Large-scale cyber attacks
  • Terrorism
  • Pandemic events

Service levels shall be suspended during any force majeure event.

13Limitation of Liability

To the maximum extent permitted by law, Sautech shall not be liable for:

  • Data loss
  • Loss of profits
  • Loss of revenue
  • Business interruption
  • Reputational damage
  • Consequential damages
  • Indirect damages

Regardless of cause.

Sautech's maximum liability shall not exceed the fees paid by the Client during the preceding three months for the affected service.

14Service Suspension

Sautech may suspend services without notice where:

  • Accounts are overdue.
  • Infrastructure security is threatened.
  • Illegal activity is detected.
  • Abuse of services occurs.
  • Continued operation creates risk to other customers.

15Acceptance

Use of any Sautech service shall constitute acceptance of this SLA.

This SLA may be amended from time to time and the latest published version shall apply unless superseded by a signed agreement.