Service Attachment for Managed Services

Effective September 1, 2026. This Service Attachment for Managed Services supersedes and replaces all prior versions. Download PDF

This Service Attachment is between Provider (sometimes referred to as “we,” “us,” or “our”), and the Client found on the applicable Order (sometimes referred to as “you,” or “your”) and, together with the Order, Master Services Agreement, Schedule of Services, and other relevant Service Attachments, forms the Agreement between the parties the terms to which the parties agree to be bound.

The parties further agree as follows:

Services

Provider will deliver only the Services itemized in the Services section of the Order as described in the Schedule of Services. Additional Services may be added only by entering into a new Order including those Services.

Help Desk Support

Helpdesk is available during normal business hours. After-hours support is intended for critical systems outages. After-hours support has a one-hour call back response time and will incur additional charges as defined by the Order.

On-site Support

It is Provider’s intention to provide remote support whenever possible. On-site support is available once it is determined by Provider that the support cannot be provided remotely. Typically, this will be due to hardware issues or network connectivity issues. On-site support is not considered Project work, however, the number of onsite support incidents and the amount of time provided for onsite support per month, if any, shall be defined in the Order.

User Credentials

In connection with such access, Provider or any third-party service provider may issue user credentials allowing Client’s users to access the Services (“User Credentials”). All User Credentials are Provider Confidential Information, as defined in the Master Services Agreement. Client shall not share Provider User Credentials with any third party without Provider’s prior written consent. User credentials may be distributed to authorized employees to access the Services, but no credentials may be transferred to or shared with a third party without our written approval. Provider reserves the right to require that you change Client’s users’ passwords at any time, with reasonable notice. All User Credentials will automatically expire at the end of the Term.

License

Provider hereby grants Client the right to access and use only those software solutions and other information technology Services specified on the Order during the Term. Those Services may be hosted on servers operated by one or more third parties.

License Restrictions

As between the parties, Provider retains all right, title and interest in and to the Services and their various components, along with all intellectual property rights associated therewith. Other than as expressly set forth in this Service Attachment, no license or other rights in or to the Services are granted to you, and all such licenses and rights are hereby expressly reserved. In addition, Client shall not:

For purposes of this Service Attachment, “Provider Materials” means any text, graphical content, techniques, methods, designs, software, hardware, source code, data (including Reference Data), passwords, APIs, documentation or any improvement or upgrade thereto, that is used by or on our behalf to provide the Services.

Third-Party Service Providers

Some components of the Services may be provided through or licensed from Third-Party Service Providers, including but not limited to third-party software, products or services. Provider, and not those third parties, will provide any and all technical support related to the Services, including support related to those third-party components. However, under certain circumstances, pursuant to the terms of applicable third-party license or services agreements, Provider may be obligated to provide certain information to those third parties regarding the Services and/or regarding your identity. Client consents to such disclosures.

Client understands and agrees that third-party services will be warranted only by the Third-Party Service Provider and only as and to the extent set forth in such provider’s license agreement, and that Provider will not be responsible, and makes no warranty, with respect to third-party services other than that which is expressly contained in the applicable Third-Party Services Provider’s agreements.

Third-party software publishers, including but not limited to, Microsoft will be intended third-party beneficiaries of the Agreement, with the right to enforce provisions of the Agreement and to verify compliance. If any third-party software publisher believes in good faith that Client is not complying with its end-user terms and conditions (“End-User License”), Provider will cooperate in good faith with the third-party publisher to investigate and remedy the non-compliance.

Within thirty (30) days of the termination of this Agreement, Provider shall remove, or cause to be removed, all copies of Client’s Services and/or Provider Materials from the Client’s devices, or otherwise render the software, the Services and/or the Provider Materials permanently unusable. Furthermore, Provider shall require that Client return or destroy all copies of the software, the Services and/or the Provider Materials that it received. Client shall reasonably cooperate and assist, as needed, with all such activities.

No High-Risk Use

Client acknowledges that the Services are not fault-tolerant and are not guaranteed to be error-free or to operate uninterrupted. You shall not use the Services in any application or situation where the Services’ failure could lead to death or serious bodily injury of any person, or to severe physical or environmental damage (“High-Risk Use”). High-Risk Use does not include utilization of the Services for administrative purposes, to store configuration data, engineering and/or configuration tools, or other non-control applications, the failure of which would not result in death, personal injury, or severe physical or environmental damage. Client agrees to indemnify and hold harmless Provider from any third-party claim arising out of Client’s use of the Services in connection with any High-Risk Use.

No Illegal Use

Client shall not use the Services in any application or situation where the Services would be used for any illegal manner, for any unlawful purpose, or to violate the rights of others.

Restorable Backup

Prior to installation, or accessing, or using any Services specified on an applicable Order during the Term, Client shall create a full, complete, and restorable electronic backup of all systems which might be affected, in whole or in part, by the installation and/or maintenance of any software-solution and other information technology services specified on an applicable Order during the Term. Client shall, and does hereby, hold Provider harmless in the event of any damage to any system and applications software.

Provider-Supplied Equipment

Provider shall deliver the equipment and applications as identified in the Order (“Equipment”). Provider’s delivery of that Equipment is on a rental basis only and is expressly subject to the terms of this Service Attachment pertaining to Provider-supplied Equipment.

Included Services

The Monthly Service Fee for Equipment includes all fees for the use of the Provider-owned hardware, software, operating systems, and all labor needed to install and maintain all hardware, software, operating systems delivered to client under this section.

Equipment Restrictions

All Equipment must be used by Client for the purpose for which it was intended. Client shall not abuse the Equipment or permit it to be serviced by anyone other than Provider. Neither Client nor Client’s agent shall connect accessories supplied by anyone other than Provider to the Equipment without Provider’s written consent, which shall not be unreasonably withheld. Client shall use the Equipment only in the manner contemplated by the manufacturer and in accordance with law. Client shall not allow anyone other than Provider to disconnect or move the Equipment from the location noted on the Order. Provider must be free to make any changes needed on the Equipment. Any critical business data stored on any Equipment must be backed up by Client.

Ownership of Provided Software

Client acknowledges that its interest in any software installed by Provider on the Equipment is that of a licensee and that the software provided by Provider shall remain the property of Provider and must be returned if requested by Provider in furtherance of the Services or upon termination of this Agreement. Client further agrees to cease the use of any software or Equipment that remains the property of Provider upon cancellation or termination of this Attachment.

Training

Provider shall provide training for Client’s personnel to properly operate newly installed Equipment. Ongoing remote training will be provided at Provider’s discretion.

Additional Client Obligations

Hardware Equipment; Legacy Equipment

Client equipment must be maintained under a manufacturer’s warranty or a current maintenance contract and must meet the minimum environment standards in the Master Services Agreement. All fees, warranties, and liabilities against Provider assume that Client equipment is under a manufacturer’s warranty or maintenance contract. Provider, in its reasonable opinion and supported by manufacturer information, may designate equipment as obsolete, defective, or past its useful service life and recommend its replacement (a “Replacement Recommendation”). A Replacement Recommendation is effective when delivered to Client in writing, including by e-mail or by entry in Client’s support ticket.

Equipment is “Legacy Equipment” if (a) Provider has issued a Replacement Recommendation for it and that equipment has been the subject of three (3) or more support incidents requiring repair or remediation after the date of the Replacement Recommendation; or (b) the equipment is no longer covered by a manufacturer’s warranty or support and Provider has designated it in writing as Legacy Equipment.

Legacy Equipment is deemed removed from the scope of the Services covered by the monthly Service Fees, without any reduction in those Service Fees. Any support, repair, or remediation Provider performs on Legacy Equipment is a Supplemental Service and is billable at the hourly rate stated in the Order or, if none is stated, at Provider’s then-prevailing hourly rate, with a one-hour minimum, plus any parts and Pass-Through Expenses. Provider will identify the billable status of the work in the applicable support ticket before performing it, and Client may decline the work. Provider may also, at its option, decline to service Legacy Equipment. Legacy Equipment is restored to covered scope when it is replaced with equipment meeting the minimum environment standards.

PROVIDER IS NOT RESPONSIBLE FOR ANY DOWNTIME, DATA LOSS, SECURITY EXPOSURE, OR OTHER LOSS ARISING FROM CLIENT’S CONTINUED USE OF LEGACY EQUIPMENT OR OF EQUIPMENT THAT IS THE SUBJECT OF A REPLACEMENT RECOMMENDATION.

Minor On-Site Tasks

Provider may occasionally ask Client to perform simple on-site tasks (e.g., powering down and rebooting a computer). Client agrees to cooperate with all reasonable requests.

Server Upgrades or Repair

Provider will authorize all server upgrades or repairs. Client agrees not to perform any of these actions without notifying us.

Software Media

Client shall obtain and supply all necessary software media with installation keys (if any) upon request.

Except for any software provided by Provider in connection with the Services, Client is solely responsible for obtaining all required software licenses, including all client access licenses, if any, for the software products installed on your computers.

Security and Regulatory Recommendations

Although it is under no obligation to do so, from time to time, Provider may make recommendations regarding regulatory compliance, safety and security related to Client’s network and practices (e.g., multi-factored authentication). If Client fails to adopt or implement the recommended protocols, Client is responsible for any and all damages related to regulatory, security, privacy, or data protection, including but not limited to fines, data breach notification, malware or ransomware costs, restoration, forensic investigation, restoring backups, or any other costs or damages related to Client’s refusal to implement the recommended protocols.

Network Change Coordination

Significant Changes to Client’s Network

Client will notify Provider via email of all significant proposed network changes and will provide us with a reasonable opportunity to comment and follow-up regarding those proposed changes.

Research Regarding Network Changes

Evaluation of network change requests sometimes will require significant research, design, and testing by Provider. These types of requests are not covered by this Service Attachment and will be billed at Provider’s then-current rates for time and materials.

Suitability of Existing Environment

Minimum Standards Required for Services

Client represents, warrants and agrees that its existing environment meets the following requirements or will obtain upgrades to its existing environment to meet the following requirements (“Minimum Standards”):

Healthcare Clients

PCI-DSS (credit card)

All costs required to bring Client’s environment up to these minimum standards are not included in this Service Attachment.

If Client’s environment fails to satisfy the above requirements at any time during the Service term, Provider may suspend further delivery of the Services and/or terminate this Service Attachment upon five (5) business days’ advance, written notice.

Exclusions

Provider is not responsible for failures to provide Services that are caused by the existence of any of the following conditions:

Provider is not responsible for failure to provide Services that occur during any period of time in which any of the following conditions exist:

The following list of items are excluded from the scope of included Services, and may incur additional charges or require a separate billable project:

The following list of items are costs that are considered separate from the Service pricing:

The following is a list of Services Provider does not perform:

Right to Act as Agent and Site Preparation

Provider Obligations

In addition to delivery of the Services, Provider accepts the following obligations under this Service Attachment:

Data Security and Privacy

In addition to its other confidentiality obligations under this Service Attachment, Provider shall not use, edit or disclose to any party other than Client any electronic data or information stored by Provider, or transmitted to Provider, using the Services (“Client Data”). Provider further shall maintain the security and integrity of any Client Data under Provider’s direct control, in accordance with any parameters described in this Service Attachment.

As between Provider and Client, all Client Data is owned exclusively by Client. Client Data constitutes Confidential Information subject to the terms of the MSA, and shall be returned to Client upon request, provided that Client is current in all payments, termination fees, and third-party service fees. Provider may access Client’s User accounts, including Client Data, solely to respond to service or technical problems or otherwise at Client’s request.

Security Incident Response

This subsection applies only where Client’s Order includes Managed Security Services (including the Security Operations Center service described in the Schedule of Services). For purposes of this subsection, a “Security Incident” means unauthorized access to, or compromise of, a Client system, account, or data that is within the scope of the Managed Security Services in the Order, as confirmed by Provider’s Security Operations Center (“SOC”). Alerts, blocked attempts, and events determined to be false positives are not Security Incidents. This definition is separate from, and does not modify, the definition of Security Incident used in the Data Processing Agreement.

For each Security Incident, Provider’s SOC will, twenty-four (24) hours a day, three hundred sixty-five (365) days a year:

Containment authority. Client authorizes Provider to take the containment actions described above without prior approval where the SOC reasonably determines that delay would materially increase the risk of harm to Client, and Client acknowledges that such actions may interrupt access to affected systems, accounts, or data. Provider will notify Client’s designated contact of any containment action taken as soon as reasonably practicable, and in any event within four (4) hours.

Scope. Provider’s obligations under this subsection extend to the first twenty-four (24) hours following confirmation of a Security Incident, consistent with the Incident Response description in the Schedule of Services. Breach-notification planning, in-depth forensic examination, post-breach systems reconfiguration or rebuilds, and any assistance beyond that period are Project Services and will be scoped and quoted separately in writing.

Service credit. If Provider fails to meet an acknowledgment or containment commitment above for a Security Incident, Client will be entitled, upon written request received within thirty (30) days after the Security Incident, to a credit equal to five percent (5%) of the monthly Service Fee for Managed Security Services stated in the Order for the month in which the Security Incident occurred. Only one credit is available per Security Incident, regardless of the number of commitments missed, and total credits under this subsection will not exceed twenty-five percent (25%) of that month’s Service Fee for Managed Security Services. Credits are applied against Client’s next invoice, are not payable in cash, and are Client’s sole and exclusive remedy for a missed commitment under this subsection.

Exclusions. No commitment is missed, and no credit is due, to the extent the delay results from: (a) systems, accounts, endpoints, or locations that are not within the scope of the Order or on which Provider’s security agents or monitoring have not been deployed or have been disabled by Client; (b) Client’s failure to satisfy the Minimum Standards Required for Services or to provide access, credentials, or information reasonably requested by Provider; (c) an action or omission of Client, its Users, or a third party not acting on Provider’s behalf; (d) failure of a Third-Party Service Provider platform, network carrier, or internet connectivity outside Provider’s control; (e) an event covered by the Force Majeure section of the MSA; or (f) Client’s instruction to Provider not to take a containment action.

The commitments in this subsection do not modify the Warranty section of this Service Attachment or the warranty disclaimers, exclusions, or limitations of liability in the MSA, and do not guarantee that a Security Incident will be prevented, detected, or fully remediated.

Maintenance Windows

Routine server and application maintenance and upgrades will occur during scheduled maintenance windows, and some applications, systems or devices may be unavailable or non-responsive during such times.

Warranty

Service Fees

Setup Fee

Prior to the delivery of the Services, Provider will charge a Setup Fee in order to deploy and configure the Services under this Service Attachment. Provider will identify the Setup Fee in an initial invoice, and Client shall pay the Setup Fee, as set forth in the Master Services Agreement (“MSA”). Provider shall have no obligation to continue with the delivery of any Services under this Service Attachment until it receives payment for the Setup Fee.

Service Fee for Cloud and Hosting

Provider will conduct a monthly inventory of the number of users, devices or networks connected or connecting to the Services, based on the Service units identified in the attached (the “Service Units”).

If the number of Service Units determined by Provider in any month is greater than the number of Service Units determined at the beginning of the preceding month, Provider (1) will include in its next invoice charges for all Service Units added during the preceding month, and (2) will increase the number of Service Units invoiced in future months, unless and until Provider determines that the number of Service Units has decreased. Client shall pay Service Fees specified in the Order for the number of Service Units identified in each invoice.

Under no circumstances during the Initial Term may the total number of Service Units decrease to less than the number of Service Units indicated on the first month’s invoice for Services. Provider’s invoices will be based on at least that number, notwithstanding any actual decreases in those numbers. Client shall pay all such charges as set forth in the MSA.

Service Fees for Backup and Disaster Recovery

Provider will conduct a monthly inventory of the environment to be covered by the Services and will determine (1) the total number of client installations and optional plugins covered within the scope of this Service Attachment (collectively, “Backup Units”), and (2) the volume, if any, of offsite data-storage capacity required to back up Client Data rounded to the nearest gigabyte.

If the number of Backup Units determined by Provider in any month is greater than the number of Backup Units determined at the beginning of the preceding month, Provider (1) will include in its next invoice charges for all additional Backup Units placed in service during the preceding month, and (2) will increase the number of Backup Units invoiced in future months, unless and until Provider determines that the number of Backup Units has decreased.

Client shall pay Service Fees specified in the Order. Any devices backed up via the Services must be limited to equipment accessed only by Client’s employees, consultants, contractors or agents who are authorized to use the Services. Client shall not allow any third parties to access any devices connecting to Services within the scope of this Service Attachment.

The fees to be charged will be based on actual number of Backup Units added to the scope of this Service Attachment, as directed by Client, and on the actual volume of any offsite data-storage capacity required to back up Client Data rounded to the nearest gigabyte, subject to a required monthly minimum of the greater of (1) 50 GB, or (2) the data volume identified in the first month’s invoice for Services. In addition, under no circumstances during the Term may the total number of Backup Units decrease to less than the number of Backup Units indicated on the first month’s invoice for Services. Provider’s invoices will be based on at least that number, notwithstanding any actual decreases in those numbers. Client shall pay all such charges as set forth in the MSA. The Fees for the Service are stated in the Order.

Term and Termination

Term

This Service Attachment is effective on the date specified on the Order (the “Service Start Date”). Unless properly terminated by either party, this Attachment will remain in effect through the end of the term specified on the Order (the “Initial Term”).

Renewal

“RENEWAL” MEANS THE EXTENSION OF ANY INITIAL TERM SPECIFIED ON AN ORDER FOR AN ADDITIONAL TWELVE (12) MONTH PERIOD FOLLOWING THE EXPIRATION OF THE INITIAL TERM, OR IN THE CASE OF A SUBSEQUENT RENEWAL, A RENEWAL TERM. THIS SERVICE ATTACHMENT WILL RENEW AUTOMATICALLY UPON THE EXPIRATION OF THE INITIAL TERM OR A RENEWAL TERM UNLESS ONE PARTY PROVIDES WRITTEN NOTICE TO THE OTHER PARTY OF ITS INTENT TO TERMINATE AT LEAST SIXTY (60) DAYS PRIOR TO THE EXPIRATION OF THE INITIAL TERM OR OF THE THEN-CURRENT RENEWAL TERM. ALL RENEWALS WILL BE SUBJECT TO PROVIDER’S THEN-CURRENT TERMS AND CONDITIONS.

Month-to-Month Services

If the Order specifies no Initial Term with respect to any or all Services, then we will deliver those Services on a month-to-month basis. We will continue to do so until one party provides written notice to the other party of its intent to terminate those Services, in which case we will cease delivering those Services at the end of the next calendar month following receipt such written notice is received by the other party.

Early Termination by Client With Cause

Client may terminate this agreement for cause following sixty (60) days’ advance, written notice delivered to Provider upon the occurrence of any of the following:

Early Termination by Client Without Cause

If Client has satisfied all of its obligations under this Service Attachment, then no sooner than ninety (90) days following the Service Start Date, Client may terminate this Service Attachment without cause during the Initial Term upon sixty (60) days’ advance, written notice, provided that Client pays Provider a termination fee equal to fifty percent (50%) of the recurring, Monthly Service Fees remaining to be paid from the effective termination date through the end of the Initial Term, based on the prices identified on the Order then in effect.

Termination by Provider

Provider may elect to terminate this Service Attachment upon thirty (30) days’ advance, written notice, with or without cause. Provider has the right to terminate this Service Attachment immediately for illegal Client conduct. Provider may suspend the Services upon ten (10) days’ notice if Client violates a third-party’s end user license agreement regarding provided software. Provider may suspend the Services upon fifteen (15) days’ notice if Client’s action or inaction hinder Provider from providing the contracted Services.

Effect of Termination

As long as Client is current with payment of: (i) the Fees under this Attachment, (ii) the Fees under any Project Services Attachment or Statement of Work for Off-Boarding, and/or (iii) the Termination Fee prior to transitioning the Services away from Provider’s control, then if either party terminates this Service Attachment, Provider will assist Client in the orderly termination of services, including timely transfer of the Services to another designated provider. Client shall pay Provider at our then-prevailing rates for any such assistance. Termination of this Service Attachment for any reason by either party immediately nullifies all access to our services. Provider will immediately uninstall any affected software from Client’s devices, and Client hereby consent to such uninstall procedures.

Upon request by Client, Provider may provide Client a copy of Client Data in exchange for a data-copy fee invoiced at Provider’s then-prevailing rates, not including the cost of any media used to store the data. After thirty (30) days following termination of this Agreement by either party for any reason, Provider shall have no obligation to maintain or provide any Client Data and shall thereafter, unless legally prohibited, delete all Client Data on its systems or otherwise in its possession or under its control.

Provider may audit Client regarding any third-party services. Provider may increase any Fees for Off-boarding that are passed to the Provider for those third-party services Client used or purchased while using the Service.

Client agrees that upon Termination or Off-Boarding, Client shall pay all remaining third-party service fees and any additional third-party termination fees.

Version history

VersionEffectiveStatus
Service Attachment for Managed ServicesSeptember 1, 2026Current — supersedes and replaces all prior versions. Changes: “Hardware Equipment” replaced with “Hardware Equipment; Legacy Equipment.” Added “Security Incident Response” under Provider Obligations (30-minute acknowledgment and 1-hour containment commitments for Managed Security Services, containment authority, first-24-hour scope, service credit, exclusions) on August 30, 2026, prior to the effective date. Entity name corrected to “The Boom Company” (no “Inc.”) on August 30, 2026 — typographical correction only; no change to terms.
Service Attachment for Managed ServicesJuly 1, 2026Superseded September 1, 2026 — archived version · PDF
Service Attachment for Managed ServicesJune 4, 2023Superseded July 1, 2026 (available on request)
← Back to Legal Hub