Cloud Service Level and Acceptable Use Policy
Effective: 19 September 2026
This Policy forms part of the Invicast General Service Agreement (“GSA”) and applies to managed and unmanaged cloud infrastructure, including virtual servers, virtual desktops, storage, hosting, networking, backups and future cloud products. Capitalised terms not defined here have the meaning in the GSA.
1. Service model
A Managed Service is configured or technically operated by Invicast to the extent stated in the Order; the portal ordinarily provides status visibility rather than unrestricted administrative control. An Unmanaged Service is provisioned and controlled by the Customer through the portal. For an Unmanaged Service, the Customer is solely responsible for operating systems, applications, users, credentials, security configuration, patching, monitoring, data, licences and backups unless an Order expressly assigns a task to Invicast.
2. Provisioning and suppliers
Invicast may use one or more confidential upstream infrastructure suppliers and may change or substitute a supplier, location or equivalent resource where reasonably required for resilience, compliance, capacity, security or commercial continuity. Supplier identity, wholesale pricing and credentials are confidential. Portal labels and product classes are Invicast commercial descriptions and need not reproduce an upstream label. Provisioning is subject to capacity, verification, wallet balance, licensing and supplier acceptance.
3. Resource specifications and pricing
CPU price and performance may vary by processor class and number of cores. Customer-facing names such as Standard, Dedicated or Throttled are labels for the underlying class stated in the portal or Order. Memory, storage, operating-system image, IP address, traffic, backup, management and other resources may be priced separately. Prices shown before confirmation are based on the selected account currency and currently effective customer rates. A configuration change may immediately change recurring or usage fees. Vendor rates are not Customer rates and do not create a resale margin commitment.
4. Account currency, wallet, invoices and tax
- The onboarding currency becomes the account billing currency unless Invicast approves a migration. All wallet entries, invoices and receipts for that account use that currency.
- Prepaid wallet value is an accounting balance for Invicast services, is not a bank deposit, does not earn interest and is not transferable or redeemable for cash except where law requires.
- Provisioning and renewal may require sufficient cleared wallet funds. Payment notifications remain uncredited until confirmed by Finance.
- The responsible Invicast member company issues the invoice. VAT, withholding, duties, levies or other tax is applied or documented according to the Customer’s status and applicable law as determined from available evidence. The Customer must provide accurate tax information and remains responsible for taxes allocated to it by law or the GSA.
5. Billing cycle and renewal
Resources are billed in the stated hourly, monthly or one-time unit. Monthly services renew on the portal date even if unused, powered off or inaccessible because Customer configuration does not release reserved capacity. Partial periods, minimum commitments and usage rounding may apply. The portal or supplier meter is the authoritative usage record absent manifest error. The Customer must maintain sufficient cleared balance before renewal.
6. Non-payment lifecycle
Invicast may send upcoming, due and overdue notices to the registered email. If payment is not received by the due date, the service may be marked overdue. After the configured grace period, Invicast may power off, restrict or suspend resources without liability for resulting unavailability. After the termination period stated in the portal or notice, Invicast may irreversibly terminate the resource and delete associated data. Automatic termination is applied only when enabled by SuperAdmin policy. Reconnection, recovery, licence, storage and administrative fees may apply. Powering off does not guarantee that charges stop.
7. Availability objective
Unless an Order states a different committed SLA, Invicast targets 99.9% monthly availability for the covered compute host and network. Availability excludes scheduled maintenance notified where practicable, emergency security work, Customer actions or systems, software within a virtual machine, internet or third-party routes outside the supplier edge, attack traffic, suspension, force majeure, beta services and exclusions in the GSA. Status data and supplier monitoring determine availability.
8. Service-credit remedy
Where a signed Order includes credits, the Customer must submit a documented claim through the portal within five business days after the affected month. Credits are calculated only against the recurring fee for the unavailable affected resource, exclude tax and usage, cannot exceed that resource’s fee for the month, have no cash value and are the exclusive remedy for an availability failure. No credit applies to a free, trial, overdue or suspended account.
9. Maintenance and changes
Invicast or its suppliers may maintain, patch, migrate, replace or reconfigure infrastructure. Planned work will be notified where commercially practicable; emergency work may occur without advance notice. The Customer must maintain applications that tolerate ordinary restart, failover and network events. An announced end-of-life, security risk or supplier change may require migration by a stated deadline.
10. Customer security duties
The Customer must use strong unique credentials and multi-factor authentication, restrict administrative ports, apply supported patches, remove default accounts, configure firewalls, encrypt sensitive data, rotate secrets, monitor logs and usage, maintain independent tested backups, and promptly investigate compromise. Credentials supplied for initial access must be changed immediately. Invicast will never request a system password by email.
11. Data and backups
The Customer controls and is responsible for Customer Data and its legality, integrity, classification, retention, restoration and export. Redundancy, snapshots and supplier backups are not a substitute for an independent backup and disaster-recovery plan. Unless a backup service is expressly ordered, Invicast has no duty to back up or recover Customer Data. Deleted, terminated, corrupted or encrypted data may be unrecoverable.
12. Prohibited use
The Customer must not use a cloud service to commit, facilitate or conceal unlawful, fraudulent, harmful or abusive activity, including malware, ransomware, phishing, credential theft, denial-of-service activity, botnets, unauthorised access or scanning, spam, unlawful bulk messaging, copyright infringement, exploitation material, unlawful gambling, sanctions evasion, prohibited surveillance, cryptomining without written approval, open relays or proxies used for abuse, resource theft, or activity that threatens persons, systems, networks or supplier reputation.
13. Fair use and network integrity
The Customer must not degrade shared infrastructure, evade limits, falsify identity or traffic, consume capacity in a manner inconsistent with the ordered profile, or interfere with another tenant. Invicast may rate-limit, filter, isolate, null-route, snapshot for evidence, disable ports, power off or suspend an affected resource where reasonably necessary to protect infrastructure or third parties.
14. Abuse, security and lawful requests
The Customer must promptly respond to abuse and security notices and preserve relevant evidence. Invicast may investigate suspected violations and disclose information to a supplier, competent authority or affected party where lawful and necessary. We may act without notice where delay risks harm, evidence loss, legal breach or broader service interruption. An investigation does not make Invicast responsible for Customer conduct.
15. Licences and images
Operating-system and application images may carry separate licence terms, restrictions and charges. The Customer must not copy, transfer or exceed licensed use. Customer-provided software must be properly licensed. Image availability, version and compatibility may change, and unsupported images may be withdrawn for security or supplier reasons.
16. Service operations
Portal actions such as create, power on, power off, reboot, resize, rename, password reset and terminate are asynchronous instructions. A submitted instruction is not complete until confirmed by the platform. The Customer must verify status before relying on an action and must not repeatedly issue conflicting commands. Resize, image, disk and termination actions may be irreversible and may cause downtime or data loss.
17. Incident support
The Customer must report incidents through the portal with the resource reference, timestamps, symptoms and safe diagnostic detail. Response targets, if any, depend on the support plan and are targets rather than resolution guarantees. Invicast may require temporary diagnostic access subject to approval and logging. Never submit passwords, private keys or full sensitive datasets in a support description.
18. Suspension and termination
In addition to non-payment remedies, Invicast may immediately suspend or terminate a resource for material security risk, prohibited use, false onboarding information, sanctions, unlawful content, supplier direction, urgent legal requirement or material breach. Customer-requested termination authorises permanent deprovisioning. Accrued charges, committed supplier costs and surviving obligations remain due.
19. Risk allocation
Cloud services depend on complex shared systems and third parties. To the maximum extent permitted by law, the disclaimers, indemnities and liability exclusions and caps in the GSA apply. Invicast is not liable for loss caused by Customer configuration, compromised credentials, unsupported software, missing backup, Customer-selected capacity, an unmanaged workload, prohibited use, supplier or internet events outside reasonable control, or suspension permitted by contract. Nothing excludes liability that cannot lawfully be excluded.
20. Changes and contact
Invicast may update this Policy prospectively for law, security, service or supplier changes. Material changes will be notified through the portal or registered email where appropriate. The accepted version remains recorded with onboarding or an Order. Service requests and notices must be submitted through the secure form or authenticated portal.
