VMware Cloud
Specific terms for VMware Cloud. These apply together with WaveCom's General Terms, DPA and its annexes.
Contents · 11 sections
1. Definitions and scope of the Service
The Service is VMware-based cloud infrastructure managed by WaveCom, together with the hardware, network and data storage necessary to provide it. The Service enables the Customer to use and independently manage virtual servers, virtual networks, datastores and other ordered components in accordance with the Service description. The Service is provided within the scope of WaveCom's certified management systems, following ISO 9001:2015, ISO 14001:2015, ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO 22301:2019. Personal data processed as part of the Service is also handled in accordance with the CISPE Data Protection Code of Conduct.
When designing and operating the Service platform, WaveCom takes account of the software vendor's security and hardening guidance and relevant industry good practices. The software vendor's certificates or declarations of conformity apply only within the scope defined by that vendor and do not replace WaveCom's responsibility for secure operation of the Service.
The Customer manages their virtual infrastructure in VMware Cloud Director. When the Service is ordered, WaveCom creates a separate organisation, administrator account and virtual data centre for the Customer. The Customer may act within their assigned roles and permissions.
The Customer orders the Service and changes its resources in WaveCom's Customer Portal. Available options include the number of virtual processors and the amounts of memory, storage, network resources and IP addresses, within the Service's available choices.
The physical infrastructure of the Service and the data of the Customer's virtual machines, platform replication and WaveCom-managed backups are located in Estonia. An additional service in another EU location requires a corresponding Customer order or a separately documented agreement and must comply with clause 12.17 of the General Terms. Clauses 7.10–7.12 govern the handling of technical data for vendor support. The exception for the Customer’s own backup repository is set out in clause 8.2.1.
Estonian law applies to the Service. The Service and its delivery locations are covered by WaveCom's certified management systems under ISO 9001:2015, ISO 14001:2015, ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO 22301:2019. WaveCom confirms the Service’s compliance with the CISPE Data Protection Code of Conduct on the basis of its completed self-assessment.
WaveCom may grant a one-month free trial to a company with an impeccable reputation that has passed WaveCom's checks. Free trials are not offered to private individuals. Before the trial begins, the order specifies the resources, any paid extras and the terms for termination or continuation as a paid service.
The Customer chooses either TB-based or 95th-percentile network traffic billing. One billing model applies to the Service at a time, and the Customer may change it later.
- TB-based billing: the Service fee includes 10 TB of network traffic per month. Inbound and outbound traffic volumes are added together.
- 95th-percentile billing: the rate in each traffic direction is measured every five minutes. The highest 5% of readings in each direction during the billing period are discarded. Billing is based on the highest of all remaining readings, compared with the ordered bandwidth.
Additional usage is charged according to the Price List for the selected billing model. The connection continues when the allowance is exceeded. WaveCom notifies the Customer when the ordered traffic volume under TB-based billing, or ordered bandwidth under 95th-percentile billing, has been exceeded by more than 10%. Excess charges apply from the point at which the ordered volume or bandwidth is exceeded, according to the Price List; the notification threshold does not provide a free additional allowance.
The technical description of the Service includes the following vendor references: vSphere best practices, STIG guides, security hardening guides, vendor compliance information and the VMware Cloud Director description.
2. Maintenance, support and fault resolution
WaveCom monitors the solution 24/7 and is responsible for the operation of the service platform.
Support is available through the Customer Portal or at support@wavecom.ee. Customer support operates on working days from 09:00 to 21:00 and on weekends and public holidays from 12:00 to 17:00. Telephone support at +372 685 0000 is available on working days from 09:00 to 17:00. Enterprise and partner service Customers also have agreed instant messaging channels and an out-of-hours emergency line; details are provided when the Service is ordered.
WaveCom provides support for use of the service platform; support is not provided for operations relating to operating systems and applications inside virtual machines. The WaveCom Knowledge Base also provides an extensive collection of service management guides.
WaveCom begins remedying a Service fault within its area of responsibility immediately and restores the Service as quickly as possible. Less significant faults are generally resolved within one working day; resolution of a fault requiring a vendor fix depends on the availability of that fix.
WaveCom documents incidents relating to the Service. General service disruptions are published on the system status page, where an RSS feed is available. An incident affecting an individual Customer is handled in their support ticket. The affected Customer receives progress information through the Customer Portal support ticket and its email notifications.
To provide a stable and secure service, WaveCom performs regular maintenance, which does not disrupt operation of the highly available VMware Cloud service. For known vulnerabilities, we install vendor updates immediately when available. Where no update is available, we apply the vendor's recommendations and mitigation measures. These measures may, but do not necessarily, reduce certain service platform functions.
When the relevant update becomes available, we test it and then apply it to the service platform at the earliest opportunity.
Maintenance of the management interface may briefly disrupt its use. WaveCom does not give advance notice of such maintenance, but displays a notice in the interface while it is taking place. WaveCom gives at least five calendar days' notice of planned maintenance or improvements affecting the operation of the Service. Planned maintenance is performed outside working hours.
In urgent cases, WaveCom may perform maintenance at other times and make configuration changes without prior notice to the Customer. Information is published on the system status page, where an RSS feed is also available, and customers are notified by email.
The Services are administered and maintained by trained and certified employees. Each employee has an assigned area of responsibility and access only to the components needed for their work. Each responsible person has a deputy.
3. Data security and backup
By default, WaveCom synchronises VMware Cloud data to another WaveCom data centre in Estonia every two hours using VMware vSphere Replication. The number and retention period of historical recovery points are defined in the Service configuration; by default, three recovery points per day are retained for five days. The synchronisation interval and retention of historical recovery points are separate settings. Replication is a disaster recovery measure and does not replace the Customer's long-term backups. The Customer defines a backup and recovery plan appropriate to the risk to their data and orders Veeam backup or DRaaS where necessary. WaveCom monitors the operation of platform replication and error notifications.
When terminating the Service, WaveCom checks the termination request, the requester's authority and the scope of the resources to be deleted. If the Customer has removed the virtual machines and there are no inconsistencies in the request, WaveCom terminates the Service at the agreed time without additional confirmation. If virtual machines remain, WaveCom clarifies with the Customer the instructions for their deletion or the export of data. Where there are reasonable grounds for doubt, WaveCom verifies the request with the representative previously designated by the Customer. After the check, WaveCom removes the virtual machines and Service components from Cloud Director and active datastores at the agreed termination time. No new platform replication recovery points are created, and existing copies expire at the end of the agreed retention period, by default within no more than five days. Veeam backups are deleted under clause 8.2.3 and DRaaS copies under clause 8.3.4. Termination of the Service does not cancel an immutability lock already applied to a backup. Where a switching request has been made, data availability under section 9 is ensured before active Service components are deleted.
4. Responsibilities
WaveCom's area of responsibility is limited to keeping the platform and related services operational.
The Customer is responsible for actions taken through self-service and for the operating systems, applications and security of their virtual servers. The Customer arranges their administration and regular maintenance.
The Customer is strongly advised to use multifactor authentication or another supported form of strong authentication in VMware Cloud Director and the Customer Portal, to use individual accounts and to restrict password-only access. Federated authentication is configured according to the platform's supported capabilities. The Customer also ensures that recovery methods are available and up to date.
Transactions and actions performed using the Customer's self-service and VMware Cloud Director accounts are deemed to have been performed by the Customer, who is responsible for them.
The Customer may grant other persons access to their infrastructure in the management interface. The Customer is responsible to WaveCom for those persons' actions.
When using the Service, the Customer follows good practices, the Knowledge Base recommendations, these specific terms and the Acceptable Use Policy in WaveCom's General Terms.
5. Service level
If a fault within WaveCom's area of responsibility materially interrupts the Service for more than one hour, the Customer may request a credit equal to one month's fee for the affected Service.
The outage duration is measured from WaveCom's monitoring alert or the Customer's fault report, whichever was received earlier.
The Customer requests the credit within 30 days through the Customer Portal or by email. The credit may be used to pay for WaveCom services; it is not paid out in cash.
6. Applicable terms
In addition to these VMware Cloud specific terms, WaveCom's General Terms, Acceptable Use Policy, Price List and the DPA set out in section 12 of the General Terms and its annexes apply.
7. Data processing roles, access and personal data
Section 12 of the General Terms, Annex A and this Service's data processing description apply to VMware Cloud. These provisions constitute the parties' data processing agreement under Article 28 of the GDPR; a separately signed DPA is not required for ordinary use of the Service.
The Customer determines the purposes, types of personal data, data subjects and retention periods for processing in their virtual machines and virtual infrastructure, and acts as controller or as processor for their own customer. WaveCom processes the data on the Customer's behalf for infrastructure provision, storage, transmission, replication, backup, recovery, security, support and deletion, and acts accordingly as processor or subprocessor.
WaveCom does not use the content of the Customer's virtual machines for its own purposes or examine it during routine administration. Technical capability to access data may exist at the infrastructure level; storage, movement, replication and backup constitute processing even if the data is encrypted or its content is not viewed. Access is limited to the Customer's documented instructions and what is necessary for secure operation of the ordered Service, or to a statutory obligation. Addressing an urgent threat does not authorise use of Customer content for another purpose.
The Customer is responsible for the virtual machine's operating system, applications, user accounts, firewall rules, keys, data content, lawfulness and application-level security. WaveCom is responsible for the security of the Service platform, physical infrastructure and its own administrative processes in accordance with the Terms.
The Customer may order encrypted NVMe storage and Veeam backup encryption as paid extras. In supported VMware platform configurations, the Customer may use vTPM to implement guest operating system encryption, such as BitLocker, or a BYOK solution, and manage the keys themselves. Use of these options, secure storage of keys and availability of recovery keys are the Customer's responsibility unless otherwise agreed in writing.
Customer instructions arise from the service order, selected configuration, actions in Cloud Director and the Customer Portal, and documented instructions through customer support. Additional administration or troubleshooting involving virtual machine content is performed only on the basis of the Customer's specific support request and the necessary access.
VMware Cloud production data, platform replicas and WaveCom-managed Veeam backups are retained in Estonia in accordance with clause 1.5. This principle applies by default and does not require the Customer to add a separate note to a support ticket. Stricter restrictions concerning data location or support agreed in a separate contract are followed to the agreed extent. Any processing of personal data in technical vendor support material follows clauses 7.10–7.12. The exception for the Customer’s own backup repository is set out in clause 8.2.1.
WaveCom responds to a lawful authority request concerning Customer data only to the required and necessary extent, checks the authority's competence where possible and notifies the Customer unless notification is prohibited.
Platform-level replication and Veeam backup involve copying the Customer's virtual machine data and constitute processing on the Customer's behalf. Restoration from a backup is based on an action by the Customer in the management interface or a support request. WaveCom employees do not examine the content being restored except on the Customer's specific instruction and to the minimum extent necessary. Automated security analysis in the backup service is described in clause 8.2.4.
WaveCom monitors the Service at infrastructure level using system logs, performance metrics, network metadata and security events. Some of this information, including IP addresses, account identifiers or user data associated with an event, may be personal data. WaveCom processes it to ensure Service operation and security and restricts access by role.
Software vendor support is engaged for an exceptional platform fault or another complex problem that WaveCom's team cannot reasonably resolve with its own resources. Support may be referred to the vendor through a licensing or support intermediary. Licence procurement and billing arrangements, or a change of intermediary, do not give the intermediary access to data in the Customer's Service environment. Technical support is provided by the platform or backup software vendor or its authorised support provider as part of an operation directed and controlled by WaveCom. Vendor support involving personal data must comply with clause 7.12.
Screen sharing and temporary remote control for VMware (Broadcom) and Veeam vendor support take place under the continuous supervision of a WaveCom employee and are limited to the infrastructure issue being resolved. Before the session, the shared view and access are restricted to the necessary technical information. Throughout the session, the WaveCom employee monitors the scope of the actions and immediately stops remote control or screen sharing if an action exceeds the agreed scope or creates a risk of disclosing data to vendor support where such disclosure is not permitted. Before the session continues, the view or access is restricted or a different diagnostic method is selected. The session is not recorded, file transfer is prohibited and the vendor is not given permanent access, the Customer's virtual machine content or access to the guest operating system. Before a session involving personal data, the support provider and communication channel are checked for compliance with clause 7.12. For example, support may help resolve a datastore platform fault under WaveCom's supervision.
Screen views and diagnostics are limited to the necessary technical information; authentication data and Customer content are not transmitted. An IP address, VM or virtual data centre name or another technical identifier may nevertheless be personal data if linked to a natural person. In that case, the data protection and location requirements in clause 7.12 also apply to supervised screen sharing. The roles of parties to the communication channel and processing locations are assessed throughout the contractual vendor support chain.
File transfers are prohibited during remote vendor support sessions. Outside a remote session, a WaveCom employee may send vendor support a diagnostic extract required to resolve the problem, provided its contents have been checked before sending and personal data, authentication credentials and information unnecessary for resolving the problem have been removed.
This permission does not cover the transfer of unchecked support bundles, memory dumps, virtual disks or backups. If a required extract contains personal data, its transfer is subject to the restrictions on personal data processing set out in these terms and to the Customer's documented selection.
A software vendor, licence supplier or intermediary is not a subprocessor of personal data in the Customer's Service environment merely because local software is used, a licence is sold or licence fees are billed. If a specific vendor support operation or forwarding of a support ticket involves processing the Customer's personal data, the general authorisation, contractual and notification procedures in clauses 12.9–12.11 of the General Terms and the location and data protection requirements in clauses 12.17–12.17.1 apply. Before a new actual subprocessor is engaged, the affected Customer is informed of the specific legal entity's name, purpose of processing, data categories and locations.
As an exception, technical information necessary to resolve a fault may be disclosed to Broadcom and Veeam vendor support outside the EU under clause 12.17.1 of the General Terms. Before disclosing personal data, WaveCom checks the agreements, security measures and legal basis for transfer throughout the processing chain, including the communication channel. If the requirements cannot be met, technical information without personal data is used. The Customer's virtual machines, their disks, content and backups are not provided to vendor support, and guest operating system access is not permitted. Any stricter restrictions separately agreed with the Customer remain in place. Clauses 7.12.1–7.12.4 additionally apply to investigating a problem affecting the Customer’s specific virtual machine or application.
The Customer does not need to permit the processing of its personal data outside the European Union for routine service and vendor support. This permission is intended solely for exceptional cases where investigating a serious problem affecting the Customer's specific virtual machine or application in connection with VMware or Veeam software requires such processing by VMware/Broadcom or Veeam vendor support.
The permission covers only the vendor support required to resolve a problem with that Customer's Service. It does not extend to other customers' data, support from other vendors or general platform support. General platform support is governed by the separate provisions in these terms for restricted and supervised vendor support. The permission does not extend the agreed scope of support, the access permitted to vendor support or the scope of data that may be shared.
Such processing of personal data outside the European Union is prohibited by default. A user authorised to manage the Service may permit such processing and withdraw that permission in the Customer Portal under the relevant Service. A history of the selection and its changes is retained. Withdrawal of permission ends further data sharing based on that permission.
If the vendor support required to resolve a specific exceptional case cannot be provided without such processing and the Customer does not grant permission, the vendor may be unable to carry out the necessary diagnostics or resolve the problem. WaveCom will explain the impact of the restriction and possible alternatives to the Customer. The absence of permission does not restrict support that can be provided without disclosing personal data outside the European Union.
8. Additional services
MS Windows Server and application licences. In addition to server resources, WaveCom can provide the Customer with operating system usage rights on request, as specified in the Price List; these are ordered through self-service. The MS Windows operating system requires licensing of at least 8 cores per VM. MS SQL core-based services require licensing of at least 4 cores per virtual machine. The Customer is responsible for ensuring that the number of vCPU cores used in the servers matches the number of licences ordered.
Whenever the number of vCPU cores in a server or servers is changed, the number of licensed cores in the licence service must also be changed.
8.2. Veeam backup solution
WaveCom offers backup of virtual machines and applications using Veeam Enterprise Plus software. The Customer selects an SSD or SAS backup repository when ordering. Backup storage, the number of virtual machines and other available resources can be managed on the cloud service resources page in the Customer Portal. Veeam backups are stored in WaveCom's own infrastructure. Under a special agreement and where technically feasible, the Customer may use its own backup repository, such as file-based or object storage (including S3 and Amazon S3). The repository, service provider and storage region to be used are specified in the special agreement. The Customer’s own repository is not managed by WaveCom. The Customer is responsible for its administration, availability, security and retention settings; WaveCom does not guarantee that repository’s operation or the retention of copies stored in it. WaveCom monitors the operation of its own Veeam backup jobs. If the repository is unavailable, an error notification is emailed to the Customer and WaveCom administrators. WaveCom’s obligations to manage and monitor its own backup jobs remain in place. When the Customer uses its own repository, WaveCom does not guarantee backup, data transfer or recovery speed or duration, or the repository’s performance, capacity, functionality or other service levels. These depend on the Customer’s repository, its configuration and limitations, and the network connection used.
The service management interface, Veeam Enterprise Manager, is integrated into VMware Cloud Director.
The Customer is responsible for configuring and managing their Veeam backup jobs, periodically testing recovery of their virtual machines and applications, and restoring and deleting data. WaveCom monitors the backup platform and backup job error notifications and regularly tests recovery using WaveCom's own virtual machine. WaveCom's test checks the platform's recovery function and does not replace recovery tests of the Customer's virtual machines and applications.
The Customer can delete a backup job themselves in the management interface. Once a job is deleted, no new backups are created; existing copies are removed according to the immutability settings actually applied to them after the relevant lock period expires. When the Service ends, the relevant backup jobs are stopped and the same deletion process applies. Deletion takes place through the backup system's deletion operation after the lock expires; deleting a job does not mean immediate removal of all copies.
Automated security analysis in the Veeam backup service assesses data entropy and file changes to detect signs of ransomware or other malicious modification. Analysis is performed on the Customer's behalf to secure the Service under the DPA; employee access to data content remains within the limits in clauses 7.3 and 7.5.
8.3. VMware Cloud Availability DRaaS
WaveCom offers VMware Cloud Availability (VCDA) for virtual machine migration, replication and disaster recovery. The default DRaaS synchronisation interval is one hour. The number and retention period of recovery points depend on the Customer's selected policy; by default, three recovery points per day are retained for five days.
The Customer orders DRaaS and changes its resources through WaveCom's self-service portal. Available changes include datastore capacity, the number of virtual machines and network services. For DRaaS, WaveCom always creates a separate virtual data centre in Cloud Director, located in a different data centre and receiving data copied from the Customer's primary data centre. The DRaaS management interface is in Cloud Director.
The Customer is responsible for configuring, managing and periodically testing Cloud Availability DRaaS, and for restoring and deleting data. WaveCom monitors DRaaS replication and error notifications and regularly tests the recovery function in a test environment. WaveCom's test does not replace recovery tests of the Customer's virtual machines and applications. Recovery or testing of the Customer's environment is initiated through a Customer action in the management interface or a documented instruction. The amount of recovery resources and any advance reservation are specified in the order.
The Customer can delete replication and its recovery points themselves in the management interface. If the Customer does not delete the copies, they expire according to the selected retention period; the default is five days. No new replication copies are created after the Service is terminated. If the Customer has selected a different retention period, that period applies.
Use of the compute resources of target servers started during recovery or testing is free of charge. After failover, the started target servers are not automatically protected by DRaaS. The Customer activates protection in the recovered environment or performs failback and activates protection in the original environment. After testing or failback, the Customer removes unnecessary recovery resources. Charges for replication, storage and other ordered components apply separately according to the Price List and order.
The frequency of data synchronisation does not determine recovery duration. No fixed recovery time is guaranteed.
8.4. GPU resources and licences
The Customer is allocated the graphics memory and share of GPU compute resources specified by the ordered profile. The agreed resource share and its isolation are ensured through the technical capabilities of NVIDIA vGPU and the VMware platform. GPU use requires an appropriate NVIDIA vGPU licence, which can be ordered from WaveCom; whether the licence is included in the price or charged separately is specified in the order. The Customer ensures that the guest operating system and GPU driver comply with the configuration supported by the Service.
9. Data transfer and termination of the Service
Switching options. The Customer can choose between two methods:
- VCDA connection. The Customer asks the new cloud provider whether it supports switching from WaveCom's cloud through VMware Cloud Director Availability (VCDA). VCDA enables virtual machines to be synchronised to and started in another VMware cloud. WaveCom establishes the supported connection and informs the Customer when it is ready to use.
- Downloading an image. The Customer downloads a VMware template image and transfers it to the new provider or their own infrastructure. WaveCom does not convert the image or adapt its content to another platform.
Data can be downloaded directly from Cloud Director without submitting a request to WaveCom. To arrange a switching schedule, VCDA connection or the download period described in clause 9.4, the Customer notifies WaveCom through the Customer Portal 30 calendar days before switching is to begin. The Customer specifies the new provider or their own infrastructure, the selected switching method and the desired start date. An earlier start may be agreed with WaveCom. Up to 30 calendar days from the start date are available for switching.
Switching and payment. The Customer performs the transfer themselves. Before the Service ends, they restore the required backups, export data and logs, and save the Service settings. WaveCom provides the technical instructions and support necessary for switching and notifies the Customer of known compatibility issues and the risk of interruption.
During switching, the Service continues under the existing contract and service fees. If invoices remain unpaid, WaveCom may suspend virtual machine operation and start-up under clause 3.5 of the General Terms. Statutory rights to retrieve data remain in place.
After switching. Successful switching terminates the contract for the transferred Service. The Customer notifies WaveCom that switching was successful; WaveCom confirms termination of the contract and the download deadline. The data specified in the request remains available for download for at least 30 calendar days after switching ends.
For this purpose, WaveCom retains the necessary data securely in Estonia and leaves the Customer the access in Cloud Director necessary to download it. Compute resources are shut down: virtual machines can no longer be used or started. The data and the environment needed for downloading are not deleted before the download period ends.
After the download period ends, the copies are deleted unless retention is required by law. The Customer may request earlier deletion or order a longer paid retention period.
Ordinary termination. In self-service, the Customer can choose to terminate the Service immediately or at the end of the billing period. A data deletion warning is displayed before termination is confirmed. When the Service ends, virtual machines, disks, templates, settings and other active Service data are deleted. No separate download copy is made. The Customer must download the necessary data before termination and confirms the data deletion choice when terminating. Backups and replicas are deleted at the times described in clause 3.2. The termination request and deletion instructions are checked under the procedure in clause 3.2.
Longer switching and additional charges. If 30 days are technically insufficient for switching, WaveCom provides the reason and a new deadline within 14 working days of receiving the request. Switching may in that case take up to seven months. The Customer may extend the switching period once according to their needs. Switching charges may be imposed only to the extent agreed before the contract was concluded and permitted by law. The volume, price and duration of longer retention are agreed separately.
Data and download methods
| Data | Supported transfer method |
|---|---|
| Virtual machines, vApps, virtual disks and templates | VCDA connection or VMware template image (OVA/OVF with virtual disks). |
| ISOs and other Customer files | Download in the original format. |
| Backups and replication recovery points | The Customer restores the selected recovery points as virtual machines and exports them as VMware templates. |
| Resource, network, security, load balancer and permissions settings | The Customer documents them before the Service is closed. |
| Usage, event and other Customer metadata | Existing Cloud Director export functions; CSV for logs. |
Internal files of WaveCom's backup and replication systems are not transferred separately where the Customer can retrieve their data through supported recovery and export. The Customer's right to obtain all their exportable data and digital assets remains in place. The contract's security and data protection requirements also apply during switching and downloading. Articles 23–30 of the Data Act apply.
Other customers' data and WaveCom's protected platform source code, trade secrets and internal infrastructure configuration are not transferred. These exceptions do not prevent transfer of the Customer's data. The structure of VMware formats is described in the platform export documentation.
VMware Service data processing description
| Field | Description |
|---|---|
| Subject matter and purpose | Providing VMware-based IaaS, virtual servers, GPU, network, storage, replication, backup, recovery and technical support, and ensuring reliability and security, including automated security analysis in the backup service. |
| Duration | From activation of the Service until it ends and service-specific deletion and retention or immutability periods are completed. |
| Nature and operations | Hosting, storage, transmission, organisation, replication, backup, recovery, security monitoring and automated security analysis of backups, deletion and Customer-directed technical support. |
| Data subjects | Persons determined by the Customer, including employees, users, customers, partners, suppliers and others whose data the Customer processes in the Service. |
| Types of data | Identification, contact, usage, location, employment, contract, telemetry, device and other application data determined by the Customer. |
| Special categories of data | Only on the basis of the Customer's lawful decision. The Customer assesses additional safeguards and informs WaveCom of special requirements affecting the Service configuration. |
| Location | Production data, platform replicas and WaveCom-managed backups: Estonia. Additional services in another EU location only under clause 1.5. Clauses 7.10–7.12 apply to limited processing of technical vendor support information outside the EU. The exception for the Customer’s own backup repository is set out in clause 8.2.1. |
| Platform replication | By default, synchronisation every two hours; by default, three historical recovery points per day are retained for five days in another WaveCom data centre in Estonia. No new points are created on termination, and existing points expire at the end of the specified retention period, by default within up to five days. |
| DRaaS replication and deletion | By default, synchronisation every hour; recovery point count and retention follow the Customer's selected policy, by default three recovery points per day for five days. The Customer can delete replication and recovery points themselves. Otherwise they expire according to the selected retention period. |
| Veeam deletion | No new copies are created once a backup job is deleted. Existing copies are removed through the backup system's deletion process after the immutability lock period actually applied to them ends. |
| Subprocessors | Ordinary use of local software does not give the vendor access to data. Vendor support involving personal data is subject to the DPA's general authorisation, notification procedure, contractual obligations and the location and data protection requirements in clauses 7.10–7.12. |
Roles of vendor support and licensing intermediaries
| Party | Role and restriction |
|---|---|
| Licence supplier or intermediary | Supplying licences, billing fees and, where necessary, forwarding support requests. This role does not in itself give access to data in the Customer's Service environment. Where a support ticket containing personal data is forwarded, actual processing is assessed and DPA requirements apply. |
| Platform vendor support | Exceptional platform support within an operation directed by WaveCom. Where personal data is processed, the specific contracting party and processing countries are checked and the DPA's subprocessor requirements are met. Outside the EU, only the limited exception described in clause 7.12 applies. |
| Backup software vendor support | Exceptional backup platform support. Where personal data is processed, the specific contracting party and the entire processing chain are checked. Outside the EU, only the limited exception described in clause 7.12 applies; Customer backups are not provided to vendor support. |
| Vendor support communication channel | Screen sharing or temporary remote control under the continuous supervision of a WaveCom employee in accordance with clause 7.10.1. The session is not recorded and file transfer is prohibited. For a session involving personal data, the communication channel and all processors involved must meet the requirements in clause 7.12. |


