Standard Service Level Agreement (SLA) for Workplace Safety
1. Purpose and scope
1.1 Purpose
This Service Level Agreement (SLA) governs Netpower Business Solutions AS’ delivery of Workplace Safety as a service. It is designed to ensure high quality, stable operation, effective support, robust information security and predictability for the customer. The SLA sets out both Netpower’s obligations and the customer’s responsibilities, and forms part of our ISO 27001-certified information security management system (ISMS).
1.2 Scope
The agreement covers:
- Operation of the application in Netpower’s data centres, including monitoring and maintenance of the infrastructure.
- Maintenance, management and further development of the application itself, including source code, bug fixes, security patching, updates and the release of new versions.
- User support, troubleshooting and fault correction according to defined criticality levels.
- Uptime guarantee and compensation arrangements.
- The process for handling support cases from registration to closure.
- An option for an extended on-call service with round-the-clock cover.
- Specific provisions for custom functionality and for operation on customer infrastructure.
- Specific provisions for safety data sheets (SDS) and chemical data.
- Specific provisions for the Exposure Register.
2. Definitions
- Uptime: the time the service is available from Netpower’s outermost network node to the application server. Planned maintenance and the exceptions in clause 9 are not included.
- Response time: the time from a case being registered in Zendesk until troubleshooting has begun. The SLA guarantees the start of troubleshooting, not a resolution time.
- Criticality levels: P1 (critical), P2 (high), P3 (medium), P4 (low); see clause 6.
- ISMS: Netpower’s information security management system, certified to ISO 27001.
- Custom functionality: features or views developed specifically for one customer and not included in the standard version.
- Customer-operated infrastructure: cases where the application runs in the customer’s own environment or data centre rather than in Netpower’s data centres.
3. Operating environment and security
Netpower operates from its own data centres in Stavanger, with a high level of physical and logical protection.
3.1 Physical and logical security
- Access control (personal card and code), security patrols, video and motion surveillance.
- Redundant power supply (UPS and diesel generator with automatic start).
- Redundant cooling and continuous climate control.
- Fire and humidity detectors and an Inergen fire suppression system.
3.2 Infrastructure and redundancy
- Optional High Availability (HA) with load balancing and failover configuration.
- Redundant networking with at least two independent lines to the internet.
- Infrastructure designed for high availability and rapid recovery from failure.
3.3 Server operations and patching
- All servers are operated under established routines for operating system and security patching.
- Critical updates and zero-day vulnerabilities are handled with expedited patching outside the ordinary maintenance window where the risk warrants it.
- IDS/IPS rules, antivirus and anti-malware are updated continuously.
- Firewalls are configured on the principle of least privilege and continuously updated with new signatures.
3.4 Monitoring and incident handling
- Servers, networks and services are monitored continuously, with automatic alerts for downtime, performance and security incidents.
- Incidents are handled under established procedures in Netpower’s ISMS, including logging, analysis and escalation where required.
- Critical incidents are notified immediately and handled in accordance with the SLA.
All of these measures form part of Netpower’s ISO 27001-certified ISMS. The operating environment and security routines are audited annually and updated on an ongoing basis to meet new threats, vulnerabilities and regulatory requirements.
4. Support model, opening hours and channels
4.1 Support levels
- First-line service desk: receiving enquiries, triage, user support and simpler fault correction.
- Second line: application specialists and systems engineers with expertise in the operating environment and the application.
- Third line: developers and architects with in-depth knowledge of the application architecture and code.
Alongside the ordinary support model, customers have access to extensive self-service resources:
- Help pages available via workplacesafety.no, with up-to-date documentation and user guides.
- Training videos available through the help pages and often embedded directly in the customer’s own application.
- Contextual help in the application: the application has built-in tooltips and help icons (!) in the view sets
During implementation and the project phase, the customer has direct access to the project team, including consultants and developers, and should not use the service desk for project-related questions in that period.
4.2 Opening hours and channels
The service desk is staffed on working days from 08:00 to 16:00. During those hours the support centre can be reached on 51 95 80 00, by email at support@workplacesafety.no or support@netpower.no, and through our online support system, either by raising a case or via live chat.
- The primary channel is Zendesk (our online support system).
- Email and telephone may be used, but incoming and outgoing enquiries are always logged in Zendesk.
- At times of high demand, the telephone queue is routed to additional staff to reduce waiting times.
5. Support case process
Every support case follows an established process in Netpower’s service desk. The process ensures that cases are assessed, prioritised and followed up predictably, and that the customer is always kept informed.
- The customer registers the case in Zendesk (the primary channel). Cases raised by email or telephone are always logged in Zendesk as well.
- A ticket ID is created and the customer receives an automatic acknowledgement with the time and reference.
- Service desk staff monitor all cases continuously throughout the day. Criticality (P1-P4) is assessed as soon as the case is registered.
- Troubleshooting begins in first line. If the fault cannot be resolved there, the case is escalated to second or third line with the work carried out documented.
- P1 cases are escalated immediately and given the highest priority. Netpower brings in the best-suited resources at once, including product owners and system architects, so that the full breadth of expertise is mobilised quickly. Other tasks are set aside until the case is under control.
- Communication: all communication about a support case takes place in Netpower’s support system (Zendesk). This gives both the customer and Netpower a complete overview, history and audit trail. For P1 cases the telephone may also be used for rapid clarification, but every update and decision is always logged in Zendesk.
- For larger customers, Netpower can arrange for the customer’s system owners to see and follow every case raised from their organisation. This gives visibility of status and progress, and means that any costs never come as a surprise.
- Once the case is resolved, closure is confirmed with the customer. Documentation and a description of the solution are provided where required or requested.
- Security-related P1 incidents are also treated as information security incidents under the ISMS incident handling procedure, including notification, root cause analysis and corrective action.
6. Criticality and response time (start of troubleshooting)
Response time is the time from the case being registered in Zendesk until troubleshooting has begun. The SLA guarantees the start of troubleshooting, not a resolution time.
|
Criticality |
Standard SLA (08:00-16:00) |
Extended SLA (optional on-call service) |
Description and typical cases |
|
P1 Critical |
1 hour |
30 min (24/7) |
Complete downtime or unavailability of the application. No users can log in or complete critical processes. Critical security incidents threatening the confidentiality, integrity or availability of data. Examples: the whole system down, the database unavailable, a serious data breach. |
|
P2 High |
2 hours |
1 time (24/7) |
Significant functionality unavailable to many users, but not complete downtime. Workarounds exist, but business-critical processes are affected. Examples: creating a new location does not work, severe performance problems that prevent work, an integration with a critical third party fails. |
|
P3 Medium |
4 hours |
4 hours (08:00-22:00, including weekends) |
Functionality is reduced or affects individual users, but core processes still work. Not business-critical. Examples: a fault in the reporting function, limited performance problems, faults in individual modules for which a workaround exists. |
|
P4 Low |
1 day |
N/A |
Cosmetic faults, user questions, minor errors or improvement requests that do not affect operation. Examples: an error in on-screen text, setting up a new user, a requested configuration change. |
Faults relating to user synchronisation and access management
Workplace Safety can be integrated with the customer’s identity environment (for example Azure AD or other AD solutions) using standards such as SCIM. In such cases, access problems may arise from factors outside the application itself, for instance changes in the customer’s identity register, synchronisation routines or configuration.
- Faults attributable to the customer’s identity environment are not treated as application faults under this SLA.
- Response time and criticality for such cases are assessed jointly by Netpower and the customer, and classified according to the actual cause and consequence.
- Netpower assists with troubleshooting and guidance to establish the cause, but operational responsibility for running and configuring the identity environment rests with the customer.
7. Uptime guarantee
Netpower guarantees 99.8% uptime per calendar month. Uptime is measured from Netpower’s outermost network node to the application server. Planned maintenance and the exceptions in clause 9 are not included. Uptime measurement and deviation reporting form part of the ISMS and can be made available for audit.
8. Maintenance window
Primarily Wednesdays 23:59-05:59. Downtime in this window is not automatic; Netpower works to keep any impact to a minimum.
9. Exceptions to uptime measurement
The following do not count as a breach of the uptime guarantee:
- Downtime caused by the customer or by faults in the customer’s equipment.
- Downtime at the customer’s request.
- Force majeure and natural disasters.
- Restarts, security updates and maintenance.
10. Compensation for SLA breaches
Netpower is committed to delivering the services in line with this SLA, and we take responsibility if delivery falls short of the defined targets. To give customers predictability and confidence, the following compensation arrangement applies:
- If the 99.8% uptime guarantee is not met in a calendar month, or
- If fewer than 90% of cases in the month are handled within the agreed response times,
… the customer automatically receives compensation as a credit against the monthly fee.
Level of compensation:
- A 5% reduction in the monthly fee per breach.
- Total compensation per month is capped at 15% of the monthly fee.
Principles:
- The compensation is intended to reflect reduced service quality and restore financial balance for the customer.
- The credit appears on the following invoice, clearly specified as a separate line.
- Compensation is standardised and automatic, so the customer does not have to submit a separate claim.
- This arrangement is a minimum safeguard for the customer and comes in addition to the rights the customer has under the main agreement.
11. Backup and disaster recovery
- Netpower backs up production data daily. Standard hosting includes seven days’ retention before overwriting. Extended retention of up to 21 days is available at additional cost.
- Restore tests are carried out periodically under established routines in our ISO 27001-certified ISMS. Results are documented and reviewed as part of the annual audit.
- Disaster recovery plans are established, documented and form part of the ISMS. The plans are reviewed annually and tested in line with risk assessments and customer needs.
12. Change management and new versions
- Change requests are logged and estimated on an ongoing basis in dialogue with the customer.
- New versions and updates are made available to all licensed customers.
- Upgrades are normally carried out in the agreed maintenance window, with care taken to preserve customer-specific adaptations.
- The customer may choose to stay on an existing version for a limited period, but Netpower reserves the right to require an upgrade where this is necessary for security, stability, maintainability or regulatory reasons.
- Critical security updates and fixes are always distributed, and may be installed outside the maintenance window where necessary.
- Versions older than a defined life cycle (typically six months) are no longer supported, and the customer is obliged to upgrade to a newer version. Netpower always gives notice of life cycles and support periods well in advance.
- Netpower makes sure customer-specific adaptations are preserved through upgrades, and works with the customer on any clarifications beforehand.
- Where critical vulnerabilities or security improvements are identified, Netpower reserves the right to upgrade or patch the application outside the maintenance window, in order to protect information security and reduce the risk of service interruption or data loss. The customer is informed as quickly as possible before, during and after any such upgrade.
13. Custom functionality
For some customers, Workplace Safety is delivered with custom functionality or tailored views developed specifically for their needs. Such deliveries offer great flexibility, but they also carry particular considerations:
- Troubleshooting and fault correction: custom solutions may take longer to analyse and fix than standard functionality, as it may be necessary to involve the developers who know the specific adaptation.
- Upgrades: custom functionality is more likely to be affected by an upgrade than the standard version. Netpower will do its best to preserve the adaptations, but cannot guarantee full compatibility with every new version. Any adjustments needed are agreed with the customer.
- Response time: cases raised against custom functionality are handled within the SLA response times, but resolution time can vary more than for standard functionality. The customer is always kept informed of progress and the expected time to resolution.
- Maintenance: Netpower recommends reviewing custom solutions regularly together with the customer, to ensure compatibility with new functionality and security updates.
Customisation adds value, but it can mean that support, upgrades and fault correction require more time and coordination than for the standard solution.
14. Security, risk assessments and audits
- Netpower is ISO 27001-certified and has an established ISMS.
- Annual risk assessments are carried out of the application and the operating environment.
- The application is risk-assessed at every major release.
- Workplace Safety is penetration tested annually.
- Customers may receive copies of penetration test and risk assessment reports on request.
- External security audits are carried out regularly.
- Netpower supports customers with penetration and vulnerability testing and with audits.
15. Safety data sheets and chemical data
Workplace Safety includes a database of safety data sheets (SDS) and chemical data. Netpower provides secure infrastructure for storing and making that information available, but the customer is responsible for the content.
The customer shall:
- Ensure that uploaded safety data sheets are valid, current and correct.
- Ensure that the chemical data recorded complies with applicable legislation.
- Ensure that employees receive the training they need to use and interpret safety data sheets.
Netpower is not responsible for the content of safety data sheets or chemical data stored in the system, but provides a secure and stable platform for handling that information.
16. Exposure Register
Workplace Safety can include an Exposure Register in which the customer records employees who have been exposed to chemicals or incidents. The register may contain sensitive personal data, including national identity numbers and health-related information.
- The customer is the data controller for information in the Exposure Register and must use the functionality in accordance with the GDPR, working environment legislation and other applicable law.
- Netpower is the data processor and undertakes to operate, protect and store the data in accordance with ISO 27001 and the data processing agreement in force.
- The customer is responsible for ensuring that only necessary and accurate data is recorded, and that access is limited to authorised personnel.
- Netpower makes technical mechanisms such as access control, logging and encryption available, but is not responsible for the quality of the content recorded.
17. Customer responsibilities and cooperation
The customer shall:
- Provide the access and information Netpower needs in order to deliver the service under the agreement.
- Ensure the quality of the data it records.
- Provide feedback without undue delay.
- Use the application for the purpose for which it was developed, and in accordance with applicable laws, regulations and internal routines.
- Ensure that access control and user administration follow the need-to-know principle, and that no unauthorised or unintended use of the system takes place.
- Not use the application for purposes other than those agreed, or store information that is plainly unsuitable for the system (for example health data, unless agreed in writing or regulated in the data processing agreement between the Parties).
Netpower is responsible for delivering a secure and stable solution in accordance with this SLA and the main agreement. The customer is responsible for how the solution is adopted internally, and for any consequences of incorrect use, inadequate access control or storing information beyond what the system is intended for.
18. Limitation of liability
Limitation of liability is governed by the main agreement between Netpower and the customer.
For the avoidance of doubt, Netpower cannot be held liable for faults caused by the customer’s own data, the customer’s systems or third-party deliveries.
19. Option: on-call service / extended SLA
For an additional fee, the customer can order an on-call service.
- Purpose: the on-call service exists to keep the application available and the operational services in Netpower’s data centre running. It applies only to incidents where the application or the server environment is unavailable (P1).
- Not included: the on-call service does not cover user support or fault correction that can be handled within ordinary opening hours. Such cases must be registered in Zendesk and handled in accordance with this SLA.
- Availability: working days 16:00-22:00; weekends and public holidays 09:00-22:00.
- 24/7 option: for P1 incidents (a completely unavailable system), a separate 24/7 agreement can be entered into.
- Registration: Zendesk is always available, 24/7/365, for registering cases.
20. Information security and ISO 27001
- All services covered by this SLA are delivered within Netpower’s information security management system (ISMS), certified to ISO/IEC 27001.
- The ISMS ensures a systematic approach to information security, including risk management, security controls, ongoing monitoring and continuous improvement.
- Netpower carries out annual risk assessments of the application, the operating environment and the associated processes. The application is also risk-assessed at every major release, to ensure new versions do not introduce unacceptable risk.
- Workplace Safety is penetration tested annually by external security partners. Findings are assessed and followed up in accordance with the ISMS.
- On request, customers may receive a copy of the certificate together with reports from risk assessments and penetration tests, subject to the necessary confidentiality considerations.
- Security incidents are handled under a defined information security incident process, including escalation, notification, root cause analysis and documented corrective action.
- Netpower applies equivalent requirements to its subcontractors, and supply chain security is followed up in accordance with ISO 27001 Annex A 5.19.
- Disaster recovery plans and contingency routines are established and reviewed annually.
- Continuous improvement of information security is part of the ISMS, and Netpower is committed to responding to new threats, vulnerabilities and regulatory requirements.
21. Other provisions
Subcontractors, force majeure and dispute resolution follow the provisions of the main agreement.
22. Customer-operated infrastructure
For some customers, Workplace Safety runs on the customer’s own infrastructure or in the customer’s internal data centre. In those cases the following specific provisions apply:
- Netpower is not responsible for physical security, redundancy, power supply, cooling, monitoring or backup of the customer’s operating environment. These are the customer’s responsibility.
- Netpower depends on the customer granting the access needed to carry out updates, troubleshooting or other work. Response times under this SLA run from the point at which such access is granted.
- Netpower cannot guarantee the same uptime or readiness as in its own data centres, since these depend on the customer’s infrastructure and routines.
- The customer must ensure that the operating environment meets minimum security and performance requirements, and that Netpower is given adequate notice and access when needed.
This clause applies only to customers where the application is operated on the customer’s own infrastructure or data centre.