Provider agrees to provide Subscriber with access to the OMS or BSP for the purpose of maintaining the Subscriber's eCommerce orders or website. Provider will provide all the necessary system requirements to run the OMS or BSP on the World Wide Web. Exact services required, including disk space and bandwidth requirements, are defined by the hosting package chosen by the Subscriber.
Provider agrees that it will comply with all information and data privacy laws to protect the Subscribers content, and will not use or disclose it to any third party. See section 6 for further information. Provider may also access Subscribers service in order to provide ongoing support for the Subscribers purchased service.
Provider uses Amazon Web Services (AWS) to provide all hosting services. The InfiPlex platform is PCI-compliant, meaning that it does not store credit card numbers or security codes. The InfiPlex platform also uses account passwords that are salted and encrypted for security purposes. This means that user passwords cannot be viewed or retrieved in any way. The only thing an administrator can do is update a password using the administrative tools or the password reset function that is available on the login page.
Provider services are also compliant with Amazon's Personally Identifiable Information (PII) requirements. PII information saved through any of the Provider's applications will only be available for a maximum of 365 days.
Provider has Disaster Recovery plans in place in case there is a disruption of service related to server or instance problems in AWS. The Provider's Recovery Time Objective (RTO) is a maximum of 12 hours. Actual recovery time in many cases is minutes when there are issues with a particular instance that is running Provider's services. As part of the Provider's Recovery Point Objective (RPO), the Provider maintains data back-ups going back a minimum of 4 days.
Servers are set up using the most current OS release from Amazon AWS and all necessary server security settings are established to maintain security. The Provider is not responsible for external hacks. The Provider maintains all necessary OS updates as security threats are known and patches released by Amazon for the OS. Please see section 7 of this document - Limited Warranty and Liability.