AWS Enterprise Agreement (TOTAL) Flashcards
(81 cards)
Section 1
“Use of the Service Offerings”
- It grants customer the right to use the services,
- Explains how they will access the Services and set up their account(s)
- Introduces the concept of usage of ‘Third Party Content’, and 4. Allows for Affiliates to use the Services (provided an addendum is added).
Section 1.1
“Generally”
- That the Customer can access and use the Services in accordance with the Agreement.
- Service Level Agreements apply to “certain” Services, and
- Customer’s use of the “Service Offerings” will comply with the terms of the Agreement.
Section 1.2
“AWS Account”
- Customer must create one or more AWS Enterprise Accounts in order to access the Services.
- Customer will only create one (1) Enterprise Account per email address (unless specifically permitted otherwise by the Service Terms).
- All AWS Enterprise Accounts will be covered by the terms of the Agreement.
- This Agreement supersedes any acceptance of the AWS Customer Agreement (ie., the online click-thru) 5. HOWEVER, any Customer accounts that do not meet the definition of an “AWS Enterprise Account” will be governed by the click-thru.
Section 1.3
“Third Party Content”
- Customer can choose to use third party content, and
- Use of the third party content will be governed by the terms of this Agreement unless it has its own terms (which may include its own, separate fees).
Section 1.4
“Customer Affiliates”
Customer Affiliate may use the Service Offerings under its own account (and covered by this Agreement), by executing an addendum to this Agreement.
Section 2
“Changes”
The ability for AWS to make changes to the:
- Service Offerings (including discontinuing them), and
- Service Level Agreements
Section 2.1
“To the Service Offerings”
- AWS may make change or discontinue any of the Service Offerings;
- AWS will give 12 month’s notice prior to discontinuing a Service that
- (i) is generally available, AND
- (ii) Customer is using.
- No notice will be given if discontinuation is being done to :
- (i) address an emergency or threat to Security or integrity of AWS,
- (ii) respond to claims, litigation, or loss of license rights related to third-part IP rights, or
- (iii) comply with the law or requests of a government entity
Section 2.2
“To the Service Level Agreements”
- AWS may make changes to the Service Level Agreements, but
- AWS will give 90 days’ notice prior to reducing benefits
Section 3
“Privacy and Security”
- AWS Security Program - ie., how AWS protects Customer Content (including protections, ISO certifications, and SOC 1/2 audits), and
- Data Privacy - ie., where Customer Content is stored, and AWS’ s right (or general lack thereof) to access or use it,
Section 3.1
“AWS Security”
- AWS will implement ‘Security Measures’ in the AWS Network that are designed to protect Customer Content.
- Security Measures will be in line with AWS Security Standards (which are detailed in Attachment B).
- AWS Security Standards may change but will never go down from those in place as of the Effective Date.
Section 3.2
“Data Privacy”
- The Customer specifies what global region(s) their data is stored in.
- AWS will not access, use or move Customer Content except as necessary to
- (i) maintain or provide the Service Offerings, OR
- (ii) as necessary to comply with law(s) or court order
- AWS will give notification (if possible) of any court order for Customer Content prior to AWS doing anything.
- AWS use of Customer Account Information is governed by the Privacy Policy; and
- The AWS Privacy Policy does not apply to Customer Content.
Section 3.3
“Service Attributes”
- AWS may use Service Attributes (ie. Customer info used for invoicing purposes), in BOTH the AWS Region where Customer uses the Services AND in the US (where AWS does it’s billing out of), for:
- Billing and administrative purposes;
- To provide Customer with support services (initiated by Customer), and
- To investigate fraud, abuse or violations of the Agreement
- Service Attributes may be processed wherever AWS maintains support and investigation personnel.
Section 3.4
“AWS Information Security Program”
- AWS is ISO 27001 certified, and
- AWS will maintain a program of at least this standard.
Section 3.5
“Audits of Technical and Organizational Measures”
Customer can get a copy of AWS’s SOC 1/2 audit reports upon request.
NOTE:
- No more than twice a year and
- a NDA must be in place.
Section 4
“Customer Responsibilities”
This covers the specific responsibilities of the Customer as it relates to their:
- Data
- Role in the “shared security model”
- Log-in credentials and account keys
- End users.
Section 4.1
“Customer Content”
- Customer is SOLELY responsible for everything about their data; and
- Customer Content must not violate any Policies or applicable law.
Section 4.2
“Customer’s Security and Redundancy”
Customer is responsible for configuring their instances for the appropriate level security and necessary redundancy.
Section 4.3
“Log-In Credentials and Accounts Keys”
- AWS log-in credentials and private keys generated by the Services:
- Are for Customer’s INTERNAL use only,
- MAY NOT be sold, transferred or sub-licensed
- May be given to Customer’s agents or subcontractors performing work on their behalf.
- That Customer is responsible for all activities that occur under its AWS account(s) (except to the extent AWS caused the breach).
Section 4.4
“End Users”
If Customer is using the AWS Services to provide services to others (“End Users”), then:
- Customer has the relationship with the End Users (not AWS);
- Customer is responsible to the End Users (not AWS);
- Customer will ensure End Users compliance with the Agreement (laws, etc)
- Customer support to the End User is provided by Customer (exception if there is a separate agreement to do otherwise)
Section 5
“Fees and Payment”
This section covers:
- Fees
- Invoicing
- Payment Terms
- Process for Disputed Amounts
- Remedies for Late Payments
- Responsibility for Taxes
Section 5.1
“Service Fees”
- Invoicing is in arrears at the end of each month (unless the website says otherwise);
- Payments are NET 30
- Customer has 30 days from DATE of invoice to give notice of any disputed any amounts.
- Disputes then have 30 days from DATE OF NOTICE to resolve.
- AWS can suspend service until any past due amounts are received.
- No short payment on invoices.
- Fees are effective as of date posted on website (unless otherwise listed on the site)
- AWS can increase or add new fees upon 60 days’ notice.
- Late payments fee = 1.5%/mo
Section 5.2
“Taxes”
- Each party is responsible to pay their own taxes.
- All AWS fees are listed WITHOUT taxes
- AWS will invoice for applicable taxes
- Customer will pay all amounts due to AWS without deducting amounts for applicable taxes.
- Customer can provide AWS a tax exemption certificate (if applicable).
Section 6
“Temporary Limitation of Access and Use Rights”
- AWS can suspend accounts or access to Services (or parts of Services), by providing notice (unless immediate action is warranted), if Customer or their End Users poses a security risk or threat to the functioning of the Service Offerings or to AWS.
- Suspension right is limited to time and portions of the services required to mitigate risk/damages
- Suspension does not relieve Customer of obligation to pay fees for the period of time suspended.
Section 7
“Term; Termination”
- Term of the Agreement
- Various termination rights of the parties.