DBT Support Master Services Agreement
Last Updated: October 2, 2026
Introduction
This Master Services Agreement (this “Agreement”) is entered into between DBT Support, LLC (“DBT,” “we,” “us,” or “our”) and the customer identified in an applicable Statement of Work (“Customer,” “you,” or “your”). This Agreement governs DBT’s managed IT, cybersecurity, compliance, and related professional services (collectively, the “Services”). By executing an SOW that references this Agreement, Customer agrees to be bound by this Agreement. If an individual executes an SOW on behalf of an organization, that individual represents that he or she has authority to bind the organization. The version of this Agreement applicable to an SOW may be identified in the SOW by effective date and SHA-256 hash as described in Section 20.
1. Definitions and Services Overview
1.1 Definitions.
For purposes of this Agreement:
- “SOW” means a written or electronically executed Statement of Work, order form, service schedule, or similar document that references this Agreement and describes specific Services, deliverables, service levels, pricing, term, assumptions, and other engagement-specific terms.
- “Agreement” means this Master Services Agreement, together with all applicable SOWs, addenda, and exhibits executed or incorporated hereunder.
- “Services” means the managed IT, security, compliance, and related professional services that DBT provides to Customer under one or more SOWs.
- “Communications” means email, ticketing-system messages, chat transcripts, and other correspondence between DBT and Customer regarding the Services.
- “Configurations” means documented system, network, and application settings, policies, or scripts implemented or maintained by DBT under this Agreement.
- “Logs” means event, audit, or security records generated by systems managed by DBT or its third-party vendors in connection with the Services.
- “Third-Party Services” means hardware, software, cloud platforms, or other tools supplied by vendors or licensors whose products are integrated into the Services.
- “Customer Materials” means any data, information, content, systems, software, documentation, equipment, networks, credentials, instructions, or other materials provided or made available by Customer to DBT in connection with the Services.
- “DBT IP” means all software, documentation, methodologies, tools, processes, playbooks, configurations, scripts, templates, know-how, and other materials that are created, developed, owned, or provided by DBT or its licensors in connection with the Services, including modifications, enhancements, derivative works, improvements, and adaptations thereof, but excluding Customer Data and Customer Materials.
- “Customer Data” means all information, data, records, content, and materials provided by Customer to DBT, or collected, processed, transmitted, or stored by DBT on Customer’s behalf, in connection with the Services.
- “Regulated Data” means Customer Data subject to specific legal or regulatory safeguards, including nonpublic personal information, protected health information, payment-card data, education records, or other protected personal or financial information identified in an applicable SOW or addendum.
- “Security Incident” means a confirmed or reasonably suspected unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or material disruption to Customer Data, Customer systems, or Services under DBT’s management, excluding unsuccessful events that do not materially affect confidentiality, integrity, or availability.
- “Supported Systems” means the systems, devices, applications, accounts, networks, and data sources expressly identified in an applicable SOW as being within DBT’s management, monitoring, backup, logging, security, or support scope.
- “Vendor” means any third-party supplier, licensor, subcontractor, or service provider engaged by DBT to deliver, host, or support any portion of the Services, including providers of Third-Party Services.
- “Vendor Terms” means the current license agreements, terms of service, privacy policies, and other contractual documents published by providers of Third-Party Services that govern Customer’s use of such Third-Party Services, as may be updated from time to time by the applicable provider.
1.2 Services Overview.
DBT provides managed IT, security, compliance, and professional Services for business clients. The specific scope, deliverables, service levels, Supported Systems, assumptions, exclusions, and pricing for each engagement will be set forth in one or more SOWs referencing this Agreement. Each SOW is incorporated by reference and governed by this Agreement. Services not expressly included in an SOW are excluded. No proposal, sales discussion, security recommendation, assessment finding, or course of dealing expands DBT’s obligations unless incorporated into a signed SOW or written amendment.
2. Term and Termination
2.1 Effective Date.
This Agreement becomes effective on the date the first SOW is executed by both parties (the “Effective Date”) and continues until terminated in accordance with this Agreement. Each SOW has the term stated in that SOW.
2.2 Termination for Cause.
Either party may terminate this Agreement or an affected SOW upon written notice if the other party materially breaches this Agreement or the SOW and fails to cure the breach within thirty (30) days after written notice. If a breach is not reasonably capable of cure, the non-breaching party may terminate immediately upon written notice.
2.3 Termination without Cause.
The parties may mutually agree in writing to terminate this Agreement or an SOW. Customer has no right to terminate an SOW for convenience unless the applicable SOW expressly provides such a right.
2.4 Suspension.
DBT may suspend affected Services after reasonable notice if Customer fails to pay undisputed amounts when due, if Customer’s acts or omissions create a material security or legal risk, if continued performance would violate law or Vendor Terms, or if a third-party provider suspends a required service. Where practical, DBT will limit suspension to the affected Services and cooperate with Customer to restore Services after the condition is resolved.
2.5 Effect of Termination.
Upon termination or expiration of an SOW, DBT will cease the applicable Services and invoice Customer for Services performed through the effective termination date and for any authorized or non-cancellable third-party commitments, setup fees, expenses, or minimum commitments incurred on Customer’s behalf. Termination does not relieve either party of obligations accrued before termination.
2.6 Transition Assistance.
Upon request, DBT will provide commercially reasonable transition assistance, including export of Customer-owned documentation and data then reasonably available to DBT, at DBT’s then-current professional services rates unless otherwise stated in the SOW. DBT is not required to disclose DBT IP, proprietary tooling, third-party confidential information, or credentials that Customer is not entitled to receive.
2.7 Survival.
Provisions that by their nature should survive termination, including payment, confidentiality, intellectual property, limitations of liability, indemnification, dispute resolution, and data-return obligations, will survive.
3. Payment Terms
3.1 Invoicing and Payment.
DBT will invoice electronically as described in each SOW. Payment is due within thirty (30) days of invoice receipt unless otherwise specified in the applicable SOW.
Customer shall have five (5) business days after receipt of an invoice to notify DBT in writing of any disputed charges, including reasonable detail describing the basis of the dispute. Failure to provide such written notice within this period constitutes acceptance of the invoice and the associated Services.
Customer must pay all undisputed amounts by the original due date. The parties will work in good faith to promptly resolve any disputed amounts, and Customer shall not unreasonably withhold or delay payment of valid charges.
3.2 Late Payments.
Unpaid undisputed balances may accrue interest at the maximum rate allowed by law. Customer agrees to pay DBT’s reasonable collection costs and reasonable attorneys’ fees incurred to collect overdue undisputed amounts.
3.3 Taxes.
Fees are exclusive of applicable sales, use, excise, VAT, or similar taxes. Where required by law, DBT may collect and remit such taxes. Customer is responsible for taxes arising from the Services other than taxes based on DBT’s net income.
3.4 Expenses and Third-Party Charges.
Customer will reimburse reasonable out-of-pocket expenses and third-party charges expressly authorized in an SOW or approved in writing. Non-cancellable vendor commitments incurred for Customer remain payable notwithstanding expiration or termination of the applicable SOW.
4. Customer Responsibilities
Customer agrees to: (a) provide timely access to systems, facilities, personnel, credentials, information, approvals, and decisions reasonably required for the Services; (b) maintain lawful ownership of, authorization to use, and authority to provide Customer Materials and Customer Data; (c) designate authorized contacts who may approve changes and instructions; (d) maintain appropriate network connectivity, power, physical security, and licensing required for the Services; (e) promptly notify DBT of material changes to Supported Systems, users, locations, vendors, or business requirements; (f) maintain complete and current backups unless backup responsibilities are expressly assigned to DBT in an SOW; and (g) use reasonable security practices for systems, accounts, credentials, and devices outside DBT’s management. Customer acknowledges that delays, inaccurate information, unavailable personnel, unsupported systems, or failure to provide required approvals may delay or limit Services.
5. Confidentiality and Record Retention
5.1 Confidential Information.
Each party will protect the other party’s nonpublic information disclosed in connection with the Services (“Confidential Information”) using at least reasonable care and will use Confidential Information only to perform, receive, administer, or enforce the Services and this Agreement. Confidential Information includes Customer Data, security information, credentials, pricing, business plans, and nonpublic technical information.
5.2 Exclusions.
Confidential Information does not include information that the receiving party can demonstrate: (a) was lawfully known without restriction before disclosure; (b) becomes public through no breach of this Agreement; (c) is received lawfully from a third party without confidentiality obligation; or (d) is independently developed without use of the disclosing party’s Confidential Information.
5.3 Required Disclosure.
A receiving party may disclose Confidential Information to the extent required by law, subpoena, court order, or regulator, provided that, where legally permitted, it gives the disclosing party prompt notice and reasonable cooperation to seek protective treatment.
5.4 Retention and Survival.
DBT may retain records of Services, Communications, Configurations, Logs, and Customer Data as reasonably necessary for service delivery, security, billing, legal, backup, or compliance purposes and in accordance with applicable retention obligations. Confidentiality obligations for ordinary Confidential Information survive for five (5) years after disclosure or termination, whichever is later. Obligations for trade secrets survive while the information remains a trade secret, and obligations applicable to Regulated Data survive for so long as DBT retains that Regulated Data or as otherwise required by applicable law.
5.5 Security and Data Protection.
DBT will maintain a written information security program reasonably designed for the nature of the Services and data entrusted to DBT. As applicable to the Services and Supported Systems, DBT will use commercially reasonable administrative, technical, and physical safeguards, which may include access controls, multi-factor authentication, encryption in transit, encryption at rest where supported and appropriate, endpoint security, vulnerability management, logging, incident response, secure credential handling, personnel confidentiality obligations, and vendor oversight. Specific controls, retention periods, regulatory requirements, or customer-specific safeguards that materially exceed DBT’s standard program must be stated in an SOW or addendum.
5.6 Return and Deletion of Customer Data.
Upon termination or expiration of the applicable Services and Customer’s written request, DBT will provide a commercially reasonable export of Customer Data then reasonably available to DBT and will delete Customer Data from active systems when no longer required for Services, legal obligations, security, dispute preservation, or normal backup retention. Data remaining in routine backups may be deleted through ordinary backup expiration cycles.
6. Intellectual Property
6.1 DBT IP.
All DBT IP remains the sole property of DBT or its licensors. Except as expressly stated in an SOW, no ownership interest in DBT IP transfers to Customer.
6.2 Customer Data and Customer Materials.
Customer retains all right, title, and interest in Customer Data and Customer Materials. Customer grants DBT a limited license to access, use, transmit, store, modify, and process Customer Data and Customer Materials solely as reasonably necessary to provide, secure, support, and administer the Services.
6.3 Customer-Specific Deliverables.
Subject to payment of applicable fees, Customer receives a perpetual, non-exclusive, non-transferable (except with a permitted assignment of this Agreement), internal-use license to final policies, reports, diagrams, configurations, and other deliverables specifically created for Customer under an SOW. This license does not include DBT software, reusable templates, methodologies, automation, scripts, tools, generalized know-how, third-party materials, or other DBT IP embedded in or used to create those deliverables.
6.4 Third-Party Intellectual Property.
Third-Party Services and related intellectual property remain subject to the rights of their respective owners and applicable Vendor Terms.
7. Non-Solicitation
During the term of effectiveness of this Agreement and for twelve (12) months thereafter, neither party will solicit for employment or hire any employee of the other party who was directly involved in providing or receiving the Services, without the other party’s prior written consent. General solicitations not specifically directed at the other party’s employees are not restricted.
8. Warranties and Disclaimers
8.1 Service Warranty.
DBT represents that it will perform the Services in a professional and workmanlike manner using qualified personnel and industry-standard practices. DBT’s sole obligation, and Customer’s exclusive remedy, for any breach of this warranty shall be for DBT to re-perform the affected Services at no additional cost.
8.2 Customer Responsibilities for Data and Systems.
Customer is responsible for identifying all systems, locations, data, and applications—including but not limited to on-premises, cloud, and SaaS environments—that require backup, monitoring, or logging Services. DBT will implement such Services only for the systems, locations, data, and applications specifically identified or documented in an applicable SOW.
DBT’s provision of support, monitoring, security, identity, networking, or other Services for a system or application does not, by itself, create any backup, retention, archival, or restoration obligation for that system or its data.
8.3 Backups and Data Accuracy.
Where DBT provides backup or recovery Services, DBT will perform the backup, monitoring, retention, and testing responsibilities expressly stated in the applicable SOW using commercially reasonable care. Customer remains responsible for identifying the systems and data that must be protected, informing DBT of material changes, and participating in restoration testing when reasonably requested. No backup technology can eliminate all risk of data loss, corruption, ransomware impact, or restoration delay.
8.4 Limitations.
DBT does not warrant that the Services or any Third-Party Service will be uninterrupted, error-free, immune from vulnerabilities, or capable of detecting or preventing all threats. DBT is not responsible for failures, delays, or inaccuracies arising from:
(i) data, systems, instructions, or configurations provided or controlled by Customer;
(ii) errors, failures, downtime, data loss, vulnerabilities, or other issues caused by any Third-Party Service; or
(iii) systems, networks, applications, or environments not expressly under DBT’s management as stated in an applicable SOW.
DBT is not responsible for remediation, recovery, or damages arising from issues outside DBT’s control, including any failure of Customer or third parties to maintain systems, apply updates, retain logs, or implement recommended security configurations.
8.5 Disclaimer.
EXCEPT AS EXPRESSLY SET FORTH ABOVE OR IN AN APPLICABLE SOW, THE SERVICES ARE PROVIDED “AS IS.” DBT DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
9. Limitations of Liability
9.1 Maximum Liability.
Except for Customer’s payment obligations, the cumulative, aggregate liability of each party for all claims arising out of or relating to this Agreement—whether in contract, tort, strict liability, or any other legal theory—shall not exceed:
(i) for DBT, the total fees actually paid by Customer to DBT under the applicable SOW giving rise to the claim during the twelve (12) months immediately preceding the date the liability arose; and
(ii) for Customer, the total fees paid and payable to DBT under the applicable SOW giving rise to the claim during the same twelve (12)-month period.
The foregoing limitation does not apply to damages resulting from (a) a party’s gross negligence or willful misconduct, or (b) a party’s breach of its obligations under Section 5 (“Confidentiality and Record Retention”) or Section 7 (“Non-Solicitation”).
9.2 Exclusion of Certain Damages.
In no event shall either party be liable for any indirect, incidental, consequential, special, exemplary, or punitive damages, or for any loss of profits, revenue, data, or goodwill, even if advised of the possibility of such damages.
9.3 Data Restoration.
Where DBT has expressly assumed backup or recovery responsibilities under an applicable SOW, DBT’s obligations relating to loss or corruption of Customer Data are limited to the backup, restoration, and recovery Services expressly stated in that SOW, subject to the limitations of this Agreement. DBT has no restoration obligation for systems, data, or Third-Party Services outside the applicable backup or recovery scope.
9.4 Applicability.
The limitations set forth in this Section 9 apply to the fullest extent permitted by law and regardless of the form of action, but shall not limit liability for a party’s gross negligence, willful misconduct, or violation of confidentiality or non-solicitation obligations.
10. Indemnification
10.1 Customer Indemnification.
Customer will defend, indemnify, and hold harmless DBT and its affiliates, officers, directors, employees, and agents from third-party claims, damages, liabilities, costs, and reasonable attorneys’ fees arising from Customer’s unlawful or unauthorized use of the Services, Customer Materials that infringe third-party rights, Customer’s violation of law, or Customer’s material breach of this Agreement, except to the extent caused by DBT’s negligence or willful misconduct.
10.2 DBT Intellectual Property Indemnification.
DBT will defend Customer against a third-party claim that DBT IP created and supplied by DBT under an SOW directly infringes a United States patent, copyright, or trademark, and will pay damages finally awarded or amounts agreed in settlement, provided Customer promptly notifies DBT, gives DBT control of the defense and settlement, and reasonably cooperates. DBT has no obligation for claims arising from Customer modifications, combinations not supplied by DBT, continued use after notice, compliance with Customer instructions, or Third-Party Services. DBT may modify or replace the affected item or terminate the affected Service and refund prepaid unused fees for that Service.
11. Subcontractors
DBT may use qualified subcontractors and Vendors to perform portions of the Services. DBT will require subcontractors with access to Customer Confidential Information to be subject to appropriate confidentiality and security obligations. DBT remains responsible for the performance of subcontractors acting directly on DBT’s behalf, subject to the limitations of this Agreement, while independent Third-Party Services remain subject to Section 23 and applicable Vendor Terms.
12. Data Backups
Unless backup responsibility is expressly assigned to DBT in an SOW, Customer is responsible for maintaining complete, current, and restorable backups of Customer Data and Customer Materials. Where DBT provides backup, replication, disaster recovery, or off-site storage Services, the protected systems, schedule, retention, recovery objectives, testing, and exclusions will be those stated in the applicable SOW.
12.1 Third-Party Hosted and SaaS Data
Unless an applicable SOW expressly states otherwise, DBT is not responsible for backing up, replicating, exporting, archiving, retaining, restoring, or otherwise protecting data maintained within a Third-Party Service or vendor-controlled environment, including hosted banking platforms, electronic health record systems, cloud applications, SaaS platforms, line-of-business applications, or other systems for which DBT does not control the underlying storage or backup functionality.
Customer is responsible for determining whether the applicable third-party provider maintains adequate backup, retention, recovery, and data-export capabilities and for maintaining any contractual rights necessary to obtain or restore Customer Data from that provider. DBT has no obligation to independently verify the adequacy, completeness, recoverability, or retention practices of a Third-Party Service unless such review is expressly included in an applicable SOW.
Where a Third-Party Service offers a technically supported backup, export, replication, or recovery capability that Customer wishes DBT to manage, DBT will assume responsibility for that function only if the applicable SOW expressly identifies the Third-Party Service, the data or workload to be protected, and DBT’s specific backup or recovery responsibilities.
DBT is not responsible for the failure of a third-party provider to retain, recover, restore, export, or make Customer Data available, except to the extent such failure is directly caused by DBT’s breach of an expressly assumed obligation under an applicable SOW.
DBT will use commercially reasonable care in performing in-scope backup Services, but backup success and restoration may be affected by Customer systems, network conditions, encryption, malware, third-party platforms, unsupported configurations, or other factors outside DBT’s reasonable control. Customer will reasonably cooperate with backup-scope validation and restoration testing.
13. Regulatory Compliance and Industry Addenda
13.1 General Compliance.
Each party will comply with laws and regulations applicable to its own performance and obligations under this Agreement. Customer remains responsible for determining the legal and regulatory requirements applicable to its business, systems, data, retention, and use of the Services. DBT will provide commercially reasonable cooperation and information regarding the Services to support Customer’s compliance efforts.
13.2 HIPAA.
If Customer is a covered entity or business associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and DBT will create, receive, maintain, or transmit protected health information as a business associate, the parties will execute a Business Associate Agreement (“BAA”) governing that activity.
13.3 Financial Institutions and Other Regulated Customers.
For Customers subject to GLBA, NCUA regulations, state financial privacy requirements, FERPA, CMMC, or other regulatory frameworks, DBT will cooperate in good faith and will maintain the security safeguards expressly required of DBT by applicable law to the extent those requirements apply to DBT as a service provider. Customer-specific security, examination-support, notification, data-residency, audit, or regulatory obligations beyond this Agreement must be identified in an applicable SOW or security addendum. DBT may provide reasonable documentation regarding its controls, Vendors, insurance, and Services for Customer due diligence, subject to confidentiality and security restrictions.
14. Insurance
Each party will maintain commercially reasonable insurance appropriate to its business and obligations. Customer will maintain general liability, workers’ compensation as required by law, and cyber liability insurance appropriate to its operations. DBT will maintain general liability and technology errors and omissions/cyber liability insurance consistent with industry standards for the Services. Upon reasonable request, either party will provide evidence of applicable coverage, subject to insurer and policy restrictions.
15. Governing Law; Dispute Resolution
15.1 Governing Law and Venue.
This Agreement is governed by and construed in accordance with the laws of the State of Indiana, without regard to conflict-of-laws principles. Any mediation, arbitration, or court proceeding arising out of or relating to this Agreement will take place in Clark County, Indiana, unless the parties agree otherwise in writing. Each party consents to personal jurisdiction and venue in the state and federal courts having jurisdiction over Clark County, Indiana.
To the extent the parties engage in arbitration, the arbitration will occur in Clark County, Indiana unless the parties agree to another location in writing.
15.2 Negotiation; Mediation; Arbitration.
A dispute will first be subject to good-faith executive-level negotiation. If unresolved, either party may request non-binding mediation. If still unresolved after mediation, the dispute will be submitted to binding arbitration under the Commercial Arbitration Rules of the American Arbitration Association (“AAA”) before a single neutral arbitrator in Clark County, Indiana. THE PARTIES WAIVE THE RIGHT TO A JURY TRIAL AND AGREE THAT DISPUTES WILL BE RESOLVED ON AN INDIVIDUAL BASIS, NOT AS PART OF ANY CLASS, COLLECTIVE, OR REPRESENTATIVE ACTION.
16. Notices
Notices must be in writing and may be delivered by email (with acknowledged receipt), certified mail (return receipt requested), or recognized courier service to the addresses set forth in the applicable SOW or as later designated by either party in writing. Notices are deemed given when received or, in the case of email, when delivery is confirmed.
17. Independent Contractor
DBT is an independent contractor. Nothing in this Agreement creates a partnership, joint venture, agency, or employment relationship between the parties.
18. Marketing Rights
DBT may identify Customer by name as a customer unless Customer provides written notice that it does not wish to be identified. DBT will not use Customer’s logo, issue a press release, publish a case study, or publicly disclose nonpublic details of an engagement without Customer’s prior written consent.
19. Force Majeure
Neither party will be liable for delay or failure to perform (other than payment obligations) to the extent caused by events beyond its reasonable control, including natural disasters, fire, severe weather, war, terrorism, civil unrest, labor disruptions, governmental action, epidemics, widespread utility or telecommunications outages, supply-chain disruptions, or cyberattacks not caused by the affected party’s failure to exercise commercially reasonable security. Force majeure does not excuse obligations relating to confidentiality, data protection, or payment for Services already performed.
The affected party must use commercially reasonable efforts to mitigate the impact of the Force Majeure event and resume performance as soon as reasonably possible.
20. Entire Agreement and Change Control
20.1 Entire Agreement.
This Agreement, together with all executed SOWs, applicable addenda, and incorporated Vendor Terms, constitutes the entire agreement between the parties concerning the Services and supersedes prior or contemporaneous proposals, negotiations, representations, and agreements regarding the same subject matter. An SOW may incorporate a proposal or exhibit by express reference.
20.2 Order of Precedence.
In the event of a conflict or inconsistency, the order of precedence is: (i) a signed amendment or customer-specific security/addendum provision expressly stating that it overrides another document; (ii) the applicable SOW; (iii) this Agreement; and (iv) applicable Vendor Terms, unless the parties expressly agree otherwise in a signed writing.
20.3 Version Identification and Updates.
DBT may publish the current form of this Agreement on its website. Each SOW should identify the governing version by effective date and, where provided, SHA-256 hash. The version identified in the SOW will govern that SOW for its then-current term unless the parties expressly agree in writing to adopt an updated version. DBT may update its standard Agreement from time to time for new or renewed SOWs. If an SOW does not identify a version, the version in effect on the SOW execution date will govern.
20.4 Amendments.
No amendment or modification to an SOW or this Agreement will be effective for an active SOW unless made in writing and signed or electronically accepted by authorized representatives of both parties, except for Vendor Terms that may change in accordance with the applicable vendor agreement and Section 23.
21. Severability and Assignment
If any provision of this Agreement is held invalid or unenforceable, the remaining provisions will remain in full force and effect. Neither party may assign this Agreement or an SOW without the other party’s prior written consent, which will not be unreasonably withheld, conditioned, or delayed; however, either party may assign this Agreement and applicable SOWs without consent to an affiliate or in connection with a merger, reorganization, acquisition, or sale of substantially all assets or equity relating to the business covered by this Agreement, provided the assignee assumes the assigning party’s obligations. Any other attempted assignment is void.
22. No Waiver
Failure to enforce any provision of this Agreement will not constitute a waiver of that or any other provision. A waiver must be in writing and signed by the waiving party.
23. Third-Party Vendors and Flow-Down Terms
DBT’s Services may incorporate or depend upon Third-Party Services. Customer’s use of Third-Party Services is subject to the applicable Vendor Terms, which may be identified in an SOW or maintained at https://www.dbtsupport.com/vendor-terms. Customer acknowledges that Vendor Terms may be updated by the applicable provider independently of DBT.
By executing an SOW that includes Third-Party Services, Customer authorizes DBT to provision and administer those Third-Party Services for Customer. Where a vendor requires affirmative acceptance of Vendor Terms to provision or administer a service, Customer authorizes DBT to accept those terms solely as Customer’s agent for that limited purpose, provided DBT does not knowingly agree to material customer-specific obligations outside the ordinary Vendor Terms without Customer authorization.
DBT will exercise reasonable diligence in selecting and periodically reviewing Vendors that materially support the Services. DBT does not control independent Third-Party Services and is not responsible for their performance, availability, security, data retention, or changes except to the extent a loss is directly caused by DBT’s breach of this Agreement, negligence, or willful misconduct. DBT will reasonably assist Customer with vendor-related incident investigation and escalation for Third-Party Services included in an SOW.
Customer shall not copy, modify, reverse-engineer, benchmark, resell, or use data or outputs from any Third-Party Service to train or develop machine learning or
artificial intelligence systems without DBT’s prior written authorization or unless expressly permitted under the applicable Vendor Terms.
Telemetry, diagnostic, or anonymized operational data collected through DBT-managed Services may be used by DBT and its Vendors for operational analytics, cybersecurity research, or product improvement, provided such data is not reasonably capable of identifying Customer or its users.
Vendor relationships may change from time to time in accordance with Section 26 (Service Platform and Software Changes).
24. Compliance, Export, and Anti-Corruption
Each party will comply with applicable laws, including U.S. export control laws and anti-bribery statutes such as the U.S. Foreign Corrupt Practices Act and the U.K. Bribery Act. Customer will not export, re-export, or transfer any DBT-provided or vendor-provided software or technology in violation of such laws.
25. Security Incident Notification
25.1 Notice.
DBT will notify Customer without unreasonable delay, and in no event later than twenty-four (24) hours after DBT determines that a Security Incident has materially affected or is reasonably likely to materially affect the confidentiality, integrity, or availability of Customer Data or Supported Systems under DBT’s control. Notice may be preliminary and may be updated as additional information becomes available.
25.2 Cooperation.
DBT will provide information reasonably available to DBT regarding the nature of the Security Incident, affected Services or Customer Data, known indicators, containment or remediation actions, and other information reasonably necessary to support Customer’s legal or regulatory notification analysis. The parties will cooperate in good faith to contain, investigate, mitigate, and remediate the Security Incident.
25.3 Customer Notifications.
Unless an SOW or applicable law expressly assigns a notification obligation to DBT, Customer remains responsible for determining whether notice to regulators, members, customers, employees, insurers, law enforcement, or other third parties is required and for making those notifications. DBT will not make public statements identifying Customer regarding a Security Incident without Customer’s consent unless required by law.
26. Service Platform and Software Changes (60-Day Notice)
DBT may modify or replace software, tools, Vendors, or Third-Party Services used to deliver the Services in order to maintain or improve security, reliability, functionality, supportability, or cost effectiveness. DBT will provide at least sixty (60) days’ written notice before a material planned change that is reasonably expected to adversely affect Customer’s operational environment or material functionality. The notice period does not apply where a shorter change window is reasonably required to address an active security risk, legal or regulatory requirement, vendor end-of-life, emergency, or third-party change outside DBT’s control; in those cases DBT will provide notice as soon as reasonably practicable. If a planned material change removes a material contracted function and the parties cannot agree on a reasonable alternative, Customer may terminate the affected Service without early-termination penalty, and DBT will not charge for the discontinued portion after the effective termination date.
27. Headings
The headings and subheadings in this Agreement are for convenience only and do not affect the interpretation or construction of any provision.
28. Limitation Period
Except for actions arising from non-payment, breach of confidentiality, violation of data-protection obligations, indemnification, fraud, gross negligence, willful misconduct, or infringement of intellectual-property rights, any claim or cause of action arising out of or relating to this Agreement must be commenced within two (2) years after the cause of action accrues or such claim will be barred.
Contact Information
DBT Support, LLC3310-4 E 10th St., Ste 313
Jeffersonville, IN 47130
Email: info@dbtsupport.com