Service Specific Terms

Last Updated: July 10, 2019

These Service Specific Terms together with the OVHcloud Terms of Service (the "Terms of Service") apply only to those specific OVHcloud Services purchased by Customer (a) through the execution of an Order Form (b) through Customer's Account via OVHcloud Manager, or (c) through an OVHcloud Partner. In the event of a conflict between these Service Specific Terms and the Terms of Service between Customer and OVHcloud, the terms and conditions of these Service Specific Terms apply, but only to the extent of such conflict. Capitalized terms used herein but not otherwise defined herein shall have the meanings set forth in the Terms of Service. OVHcloud reserves the right to upgrade, update, or discontinue any aspect or feature of an OVHcloud Service in whole or in part. While specific roles and responsibilities are identified as being owned by You or OVHcloud, any roles or responsibilities not set forth in these Service Specific Terms or otherwise provided in the Terms of Service are either not provided with the OVHcloud Services or are assumed to be Your responsibility.

  1. UNIVERSAL SERVICE TERMS (APPLICABLE TO ALL OVHCLOUD SERVICES)

    1. Mitigation (Protection Against DOS and DDOS Attacks)
      1. OVHcloud shall implement commercially reasonable protection against DOS and DDOS-type hacking attempts provided that these attacks are conducted in a manner reasonably considered to be serious enough by OVHcloud to warrant such protection. These protection measures shall not apply in the case of attacks such as SQL injection, brute-force, abuse of security flaws or other similar-type attacks. Given the nature of a potential DOS or DDOS attack and their complexity, OVHcloud shall implement different levels of traffic protection in order to preserve its infrastructure and the OVHcloud Service(s).
      2. Mitigation of a DOS or DDOS attack is only activated on detection of the attack by OVHcloud's tools and for a minimum period of twenty-six (26) hours (the "Mitigation Period"). Once the attack is identified and mitigation is automatically activated, mitigation shall not be deactivated prior to the end of the 26-hour period. During the Mitigation Period, OVHcloud Services may be suspended and/or the Customer may be unable to access the OVHcloud Services.
    2. Self-Service Portals
      1. OVHcloud-provisioned OVHcloud Services can be managed through the OVHcloud Manager ("Manager"). Manager is the central administrative portal for OVHcloud Services. Manager provides purchasing, billing, support, and security services for available products, as well as direct management of the infrastructure.
    3. OVHcloud Service Provisioning
      1. OVHcloud will provide the following provisioning services for the following product families: Dedicated Servers, Virtual Private Servers (VPS), Public Cloud Services and Hosted Private Cloud (the "Base Products"):
        • Implementation of compute, storage, networking (physical servers, physical storage, and physical network devices, etc.) specific to the selected Base Products; and
        • Providing initial network resources including default public IP addresses, where applicable.
      2. You will be responsible for the following provisioning services:
        • Installing and configuring custom or third-party applications, distributions and operating systems, and
        • Creating user accounts and changing default system preferences as needed.
    4. Operations – Monitoring
      1. OVHcloud will provide the following services with respect to monitoring:
        • Monitoring the underlying infrastructure, infrastructure networks, top-layer management and user-management interfaces, and computing, storage and network hardware for availability; and
        • Monitoring capacity and performance for storage infrastructure and network hardware.
      2. You will be responsible for the following services with respect to monitoring:
        • Monitoring the assets deployed or managed within Your Account, including but not limited to operating systems, applications, specific network configurations or network appliances deployed by You, operating systems or application vulnerabilities; and
        • Monitoring the performance of any virtual machines ("VMs").
    5. Incident and Problem Management
      1. OVHcloud will provide incident and problem management services (e.g. detection, severity classification, recording, escalation, and return to service) pertaining to:
        • Infrastructure over which OVHcloud has direct administrative and/or physical access and control, such as servers, storage, and network devices; and
        • Service software over which OVHcloud has direct administrative access and control, such as Manager, management services required to support Your environment and other applications that OVHcloud uses in delivery of the OVHcloud Services.
      2. You are responsible for incident and problem management (e.g. detection, severity classification, recording, escalation, and return to service) pertaining to:
        • Services You have deployed within the infrastructure granted to You, such as VMs, private clouds, and any virtualized infrastructure deployed to support the OVHcloud Services;
        • Performance of user-deployed VMs, custom or third-party applications, Your databases, operating systems imported or customized by You, or other assets deployed and administered by You that are unrelated to OVHcloud platforms;
        • Operating system administration including the operating system itself or any features or components contained within it;
        • Configuration of the OVHcloud Services as it pertains to how you are consuming the OVHcloud Services, such as local backup configurations, firewall configurations, virtual network configuration.
    6. Change Management
      1. OVHcloud will maintain the following change management elements for OVHcloud's infrastructure that supports You:
        • Processes and procedures to maintain the health and availability of the management tools and OVHcloud delivery platform; and
        • Processes and procedures to release code versions, hot fixes and service packs related to Manager and all supporting tools/platforms.
      2. You are responsible for:
        • Management of changes to Your VMs, operating systems, custom or third-party applications, databases, and administration of general network changes within Your control; and
        • Administration of self-service features provided through Manager up to the highest permission levels granted to You, including but not limited to VMs and network functions, backup administration, user configuration and role management and general account management.
    7. Infrastructure Data Recovery
      1. OVHcloud is responsible for data protection, such as routine backups, for OVHcloud's infrastructure required to operate Your service, including top-layer management and user-management interfaces owned and operated by OVHcloud.
      2. OVHcloud is also responsible for data and infrastructure restoration for OVHcloud's infrastructure required to operate Your service, including top-layer management and user-management interfaces owned and operated by OVHcloud.
      3. For the avoidance of doubt, the obligations set forth in this Section 1(G) do not relieve You of Your obligation to protect Your data.
    8. Security
      1. Responsibility for end-to-end security is shared between OVHcloud and You. OVHcloud will provide security for the aspects of the OVHcloud Services over which OVHcloud has sole physical, logical, and administrative level access or control. The primary areas of responsibility as between OVHcloud and You are set forth below.
      2. OVHcloud will use commercially reasonable efforts to provide:
        • Physical Security: OVHcloud Services are hosted in state-of-the-art data center facilities. The following controls are in place at the physical layer in the data centers:
          • Equipment Location: OVHcloud and our corporate parent operate in the United States, EMEA and APAC. A site selection team determines which each data center site. The site selection process includes a rigorous assessment, ensuring that each site has appropriate measures and countermeasures in place.
          • OVHcloud Data Centers: OVHcloud builds and operates its own data centers and many are certified via third-party audit to meet certain compliance certifications. A list of certifications is available at us.ovhcloud.com/overview/certification, and may be updated by OVHcloud from time to time as required. Copies of reports are available upon request – subject to confidentiality and nondisclosure agreements.
        • Information Security: OVHcloud will protect the information systems used to deliver the OVHcloud Services for which OVHcloud has sole administrative level control.
        • Network Security: OVHcloud will protect the network containing OVHcloud’s information systems up to the point where You have some control, permission, or access to modify the networks.
        • Security Monitoring: OVHcloud will monitor for security events involving the underlying infrastructure servers, storage, networks and information systems used in the delivery of the OVHcloud Services over which OVHcloud has sole administrative level control. This responsibility stops at any point where You have some control, permission, or access to modify an aspect of the OVHcloud Services.
        • Patching and Vulnerability Management: OVHcloud will maintain the systems OVHcloud uses to deliver the OVHcloud Services including the application of patches we deem critical for the target systems. OVHcloud will perform routine vulnerability scans to surface critical risk areas for the systems OVHcloud uses to deliver the OVHcloud Services. Critical vulnerabilities will be addressed in a timely manner.
        • PCI Compliance: If an environment is identified as PCI compliant, OVHcloud will enforce Level 1 PCI compliance at the infrastructure level. This includes the security posture, patching, logging, and audit requirements for the offering (compute, network and storage).
      3. You are responsible for the following:
        • Information Security: You are responsible for ensuring adequate protection of the information systems, data, content, or applications that You deploy and/or access on OVHcloud Services. This includes, but is not limited to, any level of patching, security fixes, data encryption, access controls, roles and permissions granted to Your internal, external or third-party users.
        • Security Monitoring: You are responsible for the detection, classification and remediation of all security events that are isolated within Your instance(s), associated with any VMs, operating systems, applications, data or content surfaced through vulnerability tools, or required for a compliance or certification program in which You are required to participate, and which are not serviced by another security program.
        • Network Security: You are responsible for the security of the network over which You have administrative level control. This includes but is not limited to maintaining effective firewall rules, exposing only communication ports that are necessary to conduct business and locking down promiscuous access.
    9. IP Addresses
      1. Each of the Base Products will have a public, fixed, non-transferable IPv4 and/or IPv6 address attached (each an "IP Address").
      2. Each IP Address provided to Customer by OVHcloud will remain the property of OVHcloud.
    10. General
      1. Owing to the highly technical nature of the OVHcloud Services, OVHcloud is subject only to those obligations maintained in the applicable section of the Service Level Agreement regarding our Monthly Availability Commitment.
      2. Given that the network resources provided to the Customer are shared, Customer undertakes not to use the OVHcloud Service(s) in a manner detrimental to OVHcloud's other customers. In particular, the Customer undertakes not to use the public bandwidth in an intensive manner. In such a situation, OVHcloud reserves the right to apply limitations to this bandwidth. The Customer may, if it so wishes, subscribe to additional bandwidth options for the purpose of having unrestricted use of guaranteed public bandwidth.
      3. The Customer is the sole administrator of the OVHcloud Service(s). In this capacity, the Customer confirms it possess all the technical knowledge necessary to ensure correct administration of the resources provided by OVHcloud.
      4. The Customer must have an internet connection in order to log into Manager or any other management interface offered by OVHcloud and access the OVHcloud Services, and is solely responsible for the aforementioned internet connection, particularly its availability, reliability and security.
      5. OVHcloud reserves the right to interrupt the OVHcloud Services in order to perform a technical intervention to improve the operation of the OVHcloud Services.
  2. DEDICATED SERVERS

    1. Service Description
      1. A "Dedicated Server" is a bare metal server that OVHcloud makes available to the Customer for rent on a monthly basis (the "Service(s)" for the purposes of this Section 2). OVHcloud offers five (5) different categories of Services: Infrastructure, HG, Storage, Best Value and Game. The fees, features, and basic hardware and software configurations are described and accessible online via the OVHcloud website.
    2. Customer Obligations
      1. The Service(s) do not have any pre-installed distribution (or operating system). Customer is solely responsible for selecting the distribution (or operating system). It is the Customer's responsibility to acquire the necessary rights to use the selected distribution from a publisher, an authorized third party, or OVHcloud, if applicable. The Customer is solely responsible for installing the selected distribution on the Service(s).
      2. The Customer accepts sole responsibility for the performance of any and all maintenance operations in reference to the Service(s), including but not limited to any updates to the distribution installed on the Service(s) and upgrades.
    3. OVHcloud Obligations
      1. In the context of maintenance operations, OVHcloud may have occasion to replace a component in order to keep the Service(s) in an operational condition. In such cases OVHcloud will replace the component with a new component that is identical or has equivalent features. OVHcloud cannot guarantee the substitute components compatibility with the content (including distributions, systems, software and applications) installed by the Customer in the context of the Service(s).
      2. OVHcloud reserves the right to make any modifications, updates, and/or upgrades to the Service(s) or the Host Server (as defined in Section 4(A)(i)). In the event of a development necessitating such an update or upgrade, the Customer will be given reasonable advance warning, except in urgent cases that may necessitate immediate implementation. If the distribution update or upgrade is not carried out following OVHcloud’s requests, OVHcloud reserves the right to interrupt the connection of the Service(s) to the network.
    4. HG Customizable
      1. In addition to the terms and conditions set forth above, customizable HG servers ("HG Customizable Servers") offered by OVHcloud are subject to the following terms and conditions:
        1. Customers may request upgrades to their HG Customizable Servers by submitting a request to the OVHcloud Customer Success Team (CST) or, where applicable, their OVHcloud account representative.
        2. OVHcloud offers Customers certain disk, GPU and Intel® Optane upgrades for HG Customizable Servers as further detailed on the OVHcloud website (collectively, "Upgrades"). The types and availability of Upgrades are subject to change. OVHcloud cannot guarantee the availability of any Upgrade. The cost of each Upgrade will be communicated to the Customer at the time of purchase.
        3. Any Upgrade requested by Customer and installed on an HG Customizable Server cannot be removed by the Customer for any reason.
        4. The installation of an Upgrade may result in downtime. Any downtime incurred during the installation of an Upgrade is excluded from any time-based calculations related to an HG Customizable Server being Unavailable (as defined in the Service Level Agreement).
  3. Virtual Private Server ("VPS")

    1. Service Description
      1. A Virtual Private Server ("VPS") is a single virtual machine (VM), with resources dedicated to its user, that OVHcloud makes available to the Customer for rent on a monthly or yearly basis (the "Service(s)" for the purposes of this Section 3). The fees, features, and basic hardware and software configurations are described and accessible online via the OVHcloud website.
    2. Customer Obligations
      1. The Service(s) do not have any pre-installed distribution (or operating system). Customer is solely responsible for selecting the distribution (or operating system). It is the Customer's responsibility to acquire the necessary rights to use the selected distribution from a publisher, an authorized third party, or OVHcloud, if applicable. The Customer is solely responsible for installing the selected distribution on the Service(s).
      2. The Customer accepts sole responsibility for the performance of any and all maintenance operations in reference to the Service(s), including but not limited to any updates to the distribution installed on the Service(s) and upgrades.
      3. The virtualization technologies used by OVHcloud for the management of Customer's VPS shall in no way represent any obligation on the part of OVHcloud to ensure the safeguard of the Customer's data. All measures necessary to ensure the backup of the Customer's data remains the exclusive responsibility of the Customer.
    3. OVHcloud Obligations
      1. OVHcloud reserves the right to make any modifications, updates, and/or upgrades to the Service(s). In the event of a development necessitating such an update or upgrade, the Customer will be given reasonable advance warning, except in urgent cases that may necessitate immediate implementation. If the distribution update or upgrade is not carried out following OVHcloud's requests, OVHcloud reserves the right to interrupt the connection of the Service(s) to the network.
  4. PUBLIC CLOUD SERVICES ("PCS")

    1. Definitions
      1. "Host Server": Physical server with attributed memory (RAM) and compute (CPU). Configured and administered by OVHcloud, it is designed to accommodate one or more VMs or Instances administered by the Customer.
      2. "Infrastructure": set of components provided by OVHcloud which permit to host the Customer's public cloud including in particular (depending on the circumstance) the Host Server, the Storage Space, the network, the bandwidth and/or virtualization or cloud computing technology.
      3. "Instance": Virtual server created on the OVHcloud public cloud infrastructure and which enables the development and/or use of application solutions. The Instance, created using cloud computing technologies, includes a Storage Space and a quantity of processor and RAM resources. It is possible to add Object Storage to an Instance.
      4. "Object Storage": Distributed Storage Space based on the Object Storage architecture (management of data as objects). In the OVHcloud public cloud, it may be added to an Instance, particularly when it is used as a Snapshot (as defined below) and/or subscribed to separately.
      5. "Object Storage Container": Head unit of the Object Storage Space that shares the same access right policy, created by the Customer.
      6. "Service(s)": Public Cloud Services for the purposes of this Section 4.
      7. "Storage Space": Disk space attached to an Instance that can be either a 'local' Storage Space or a 'distributed' Storage Space, depending on the characteristics of the Instance. The 'local' Storage Space is directly attached to the Instance for the proper functioning of the operating system. Data is deleted and the disk is reinstalled to its original state every time the Instance is rebooted or stopped. Data in the 'distributed' Storage Space is stored whatever the state of the Instance. 'Distributed' Storage Space is deleted when the Instance is deleted.
    2. PCS Instances

      The following terms apply only to PCS Instances:

      1. Service Description. PCS Instances are computing services offered by OVHcloud and located on OVHcloud-owned Infrastructure for rent on a monthly basis consisting of one or several Instances and/or several Object Storage Containers.
        1. Hardware resources (Host Server, Storage Space, etc.) and the Instances rented by the Customer will remain the exclusive property of OVHcloud.
        2. OVHcloud reserves the right to limit or deny access to certain ports to protect the underlying infrastructure.
        3. The Customer acknowledges that, for security reasons, some features and protocols (such as IRC or peer-to-peer file exchanges) are likely to be restricted under the Services.
      2. Customer Obligations
        1. The Customer undertakes to comply with the license conditions and conditions of use of the operation system on which the Instance is configured by OVHcloud, and the license conditions of use of the applications, in some cases pre-installed on the Instances by OVHcloud.
        2. The Customer shall be the sole administrator of their Instance. OVHcloud shall under no circumstances be involved in the administration of the Customer's Instances.
        3. The Customer may also perform maintenance operations and updates on the aforementioned operating systems and applications pre-installed on the Instance. In such a case, the Customer assumes full responsibility and OVHcloud shall not under any circumstances be held responsible, including without limitation where said operations (maintenance, updates, etc.) are performed in violation of the applicable conditions of use/license conditions, or where the Instance fails to perform and/or operate correctly following maintenance operations and/or updates performed by the Customer.
        4. The Customer shall not use the Services to deploy services which are intended to enable users to download files in large quantities to and from file hosting platforms.
        5. Customer is prohibited from any intrusive activity or any intrusion attempt from the Instance (including, but not limited to port scans, sniffing, spoofing), and any activity or contentious behavior such as traffic exchanging (Hitleap, Jingling), Black Hat SEO (downloading and uploading videos from and to online gaming platforms), crypto-currency mining, video game bots, etc. Anonymization services (Proxy) and cardsharing (CCCam or equivalent) are prohibited.
        6. In order to maintain the service level of the Customer's Instance and all the servers on the Infrastructure, OVHcloud reserves the right to request that the Customer update the operating system running on the Instance and any applications pre-installed by OVHcloud, where a security vulnerability is identified. If the Customer does not act upon such requests, OVHcloud reserves the right to disconnect the Instance, Object Storage Container and/or Infrastructure from the internet.
        7. In the event that OVHcloud finds that the Instance or Object Storage represents a security risk, OVHcloud may send an email to the Customer to inform the latter that the Instance or Object Storage Container will be reinstalled or deleted to maintain the integrity of the Instance or Object Storage Container and the entire Infrastructure. OVHcloud reserves the right to disconnect the Instance and the Object Storage Container from the internet pending the Customer's reinstallation of their Instance. The Customer is responsible for transferring data from the pirated or failing system to the new system within a commercially reasonable time. The sole responsibility of OVHcloud is the installation of the new system.
      3. OVHcloud Obligations
        1. OVHcloud reserves the right to modify the operating systems and applications pre-installed by OVHcloud on the Instance, in particular by way of any updates and/or version upgrades that it deems necessary in its sole discretion.
        2. OVHcloud reserves the right to limit or restrict certain functionality of the Instance in order to guarantee the security of the Infrastructure. OVHcloud shall inform the Customer of the implementation of these restrictions whenever possible.
        3. OVHcloud shall use reasonable endeavors to replace any defective part of Host Server as soon as reasonably possible except where OVHcloud is not directly responsible for the failure or in situations where the repair or replacement procedure requires an interruption of Service which exceeds the usual replacement time. In the latter case, OVHcloud will notify the Customer as soon as reasonably practicable.
    3. Snapshot
      1. Service Description. OVHcloud provides a feature enabling Customer to make instantaneous copies of an Instance ("Snapshots"). A Snapshot is not a perennial backup of the data of the Instance; it is rather an "instantaneous" copy of the Instance. Customers are limited to one Snapshot per VM.
      2. Customer Obligations.
        1. Snapshot does not, under any circumstances, exempt the Customer from their obligation to back up their data. Snapshot is not a disaster recovery tool.
  5. HOSTED PRIVATE CLOUD

    1. Hosted Private Cloud (or Dedicated Cloud) referred to as "DC Services" or "DC"

      The following terms apply only to the DC Services:

      1. Service Description. The DC Services are single-tenant private cloud environments with dedicated computing servers, layer-2 network isolation for workload traffic, dedicated storage volumes, and a dedicated cloud management. Infrastructure capacity may be allocated to a single physical data center or to multiple data centers.
        1. Network Services: Customers have access to the following network services, included as a core service within DC:
          1. Network Address Translation (NAT): Separate controls for source and destination IP addresses, as well as port translation.
          2. Dynamic Host Configuration Protocol (DHCP): Configuration of IP pools, gateways, DNS servers, and search domains.
          3. Firewall: Supported rules include IP 5-tuple configuration with IP and port ranges for stateful inspection for all protocols.
          4. Load Balancing: Simple and dynamically configurable virtual IP addresses and server groups.
          5. Site-to-Site Virtual Private Network (VPN): Uses standardized IPsec protocol settings to interoperate with major VPN vendors.
          6. Static Routing: Static routes for destination subnets or hosts.
        2. DC environments also receive vSphere Enterprise Plus and NSX Enterprise, with access to VMware Standard Switches, VMware Distributed Switches, and the NSX management console.
      2. Ordering Metered Usage Components
        1. For purposes of this Section, "Metered Usage Components" means those OVHcloud Service elements that are billed based on actual usage.
        2. You are obligated to pay for the Metered Usage Components at the then-current rates published by OVHcloud if You purchased the OVHcloud Service directly from OVHcloud, or at the rates agreed with your OVHcloud Partner if You purchase the OVHcloud Service through an OVHcloud Partner. The Customer will be invoiced for such usage charges within the first seven (7) days of the month for the month after the usage was incurred.
        3. Add-on capacity and services for as described above may be purchased at any time to meet new or expanded requirements.
        4. Capacity may be added via OVHcloud Manager, Your OVHcloud Sales Person, or through Your OVHcloud Partner.
      3. Customer Obligations

        Customer is responsible for:

        1. Provisioning Services
          1. Creating and configuring applicable virtual data centers ("VDCs"), VMs, and networks using deployment templates and wizards.
          2. Deploying and maintaining on-premises deployments of vSphere® Replication, Zerto®, or VMware® Hybrid Cloud Extension for use with Disaster Recovery, including but not limited to: installation of vSphere Replication, registering Your local vSphere environment(s), selecting VMs for protection, and assigning a recovery point objective ("RPO") for replication frequency. Customer is responsible for license costs associated with the above referenced products.
        2. Monitoring
          1. Monitoring the assets deployed or managed within Your Account, including but not limited to VMs.
        3. Data Recovery
          1. Data protection, such as routine backups, for the data and content accessed or stored on Your VMs or storage devices, configuration settings, etc.
          2. Data, content, VM, and configuration restorations for assets accessed or stored on Your account.
        4. Virtual Server Deployment Templates
          1. Regardless of OVHcloud patching timelines, You are responsible for deploying and configuring the virtual server deployment templates that You choose to use, patching patches necessary for Your operations, activating related licenses, and maintaining compliance with all applicable license terms.
          2. In order to comply with OVHcloud's legal obligations to OVHcloud's third party licensors, You will not be permitted to export, download, or remove certain templates or any installed forms of certain templates for installation or use outside of the OVHcloud Services, as set forth in the Third Party Terms. You may implement or import Your own virtual server deployment templates so long as You have the legal right to deploy and use the software contained in such templates.
      4. OVHcloud Obligations

        OVHcloud is responsible for:

        1. Monitoring
          1. Providing Customer with a VDC- and VM-level view of compute and storage resource utilization and availability.
        2. Incident and Problem Management
          1. In addition to those incident and problem management services outlined in the Universal Terms, OVHcloud will provide VMware-provided operating system templates, to the extent that:
            1. Published templates cannot be accessed from the Service Catalog (as defined below),
            2. Published templates cannot be instantiated without modification,
            3. Published templates cause errors at first run time,
            4. There are substantial hangs or excessive delays in the retrieval of a template from the Service Catalog,
            5. The configuration of a published template affects the VM's interaction with the hypervisor, and
            6. Time synchronization issues (NTP) exist.
          2. VMware-provided tools, including:
            1. VMware Tools installation and configuration,
            2. VMware Tools optimization, and
            3. Performance tuning as it relates to VMware tools and drivers.
        3. Virtual Server Deployment Templates
          1. Providing a catalog (the "Service Catalog") of supported virtual server deployment templates that You may deploy into Your Hosted Private Cloud environments. The deployment and use of such templates will be subject to the Terms of Service, including any applicable Third Party Terms, and may also be subject to additional fees. OVHcloud will provide these templates, test them for quality, check for viruses, and install security patches from time to time.
          2. Templates provided by OVHcloud that are infrequently used, out of date, or no longer supported may be removed at any time.