Service Terms

1. Purpose

These Service Terms supplement the Terms of Service. Only services listed in the Order Form are included. Examples in this document describe common activities and do not create scope by themselves.

2. Shared Delivery Principles

Services may be advisory, project-based, recurring, consumption-based, or a combination. elyXion uses a shared-responsibility model: it performs the tasks allocated to it, while the Customer retains business ownership, lawful-use decisions, and responsibilities not expressly transferred.

Estimates depend on timely Customer cooperation and stable assumptions. Discovery may reveal additional risk or work. Material changes follow change control.

3. Cloud Advisory

Cloud Advisory helps Customers assess options and create informed roadmaps for Microsoft Azure, Microsoft 365, security, identity, platform engineering, cost, governance, and operating models.

Typical outputs may include workshops, current-state assessments, target architectures, risk registers, cost models, governance recommendations, migration waves, and executive roadmaps. Advice represents professional judgement based on supplied information and conditions at the assessment date. It is not a guarantee of vendor pricing, regulatory approval, or future performance.

Unless expressly included, Cloud Advisory excludes implementation, exhaustive penetration testing, legal compliance opinions, procurement, licence resale, and operation of Customer systems.

4. Professional Services

Professional Services include architecture, configuration, migration, integration, remediation, automation, documentation, and knowledge transfer. The SOW identifies environments, Deliverables, acceptance criteria, rollback planning, and Customer dependencies.

The Customer must provide authorised access, maintenance windows, technical owners, validated backups, test users, representative test data, and timely acceptance. Production changes require agreed approval. elyXion may stop a change where risk materially exceeds the approved plan.

Migration completeness depends on source-system quality, vendor capabilities, data formats, and Customer decisions. Archived, corrupt, unsupported, encrypted, or undisclosed data may require separate handling.

5. Managed Services

Managed Services provide defined recurring operational activities such as monitoring, incident coordination, service requests, patch coordination, reporting, governance reviews, and optimisation. They are not unlimited outsourcing. The service description identifies included systems, coverage hours, tooling, request allowance, and exclusions.

The Customer retains ownership of business processes, data classification, end-user behaviour, procurement, licences, and risks outside the managed scope. elyXion may recommend remediation; implementation is included only where stated.

6. Managed Azure

Managed Azure may cover subscriptions, landing zones, policy, identity integration, networking, compute, backup, monitoring, cost visibility, security recommendations, and operational governance.

Microsoft remains responsible for its cloud platform under Microsoft’s terms. The Customer remains responsible for tenant ownership, workload design decisions, data, application behaviour, licence and consumption costs, and Customer-side controls. Budgets and alerts help visibility but do not guarantee a spending ceiling. Azure consumption can continue after an alert.

Backup is included only if configured and identified in the Order Form. Backup success monitoring is not the same as application-consistent recovery assurance; restoration testing must be separately scheduled.

7. Managed Microsoft 365

Managed Microsoft 365 may include tenant administration, identity, Exchange Online, Teams, SharePoint Online, Intune, Defender, configuration reviews, service requests, and governance.

Microsoft service availability and product behaviour are outside elyXion‘s control. The Customer is responsible for acceptable-use rules, records retention decisions, eDiscovery and legal hold instructions, data-owner approvals, and user lifecycle inputs. elyXion will not grant high-risk access without required approval.

Changes to Microsoft defaults, licences, APIs, or roadmap may require service adaptation.

8. Security Services

Security Services may include assessments, Zero Trust and identity design, Conditional Access, privileged access, Microsoft Sentinel, Defender, logging, security recommendations, vulnerability coordination, incident assistance, and governance.

No security service guarantees prevention or detection of every threat. Findings are time-bound and limited by scope, access, evidence, and techniques used. A vulnerability assessment is not a penetration test unless expressly identified. Security monitoring is not a 24/7 security operations centre unless the Order Form says so.

The Customer decides risk acceptance and remediation priorities. elyXion may require written acknowledgement where a Customer declines a material recommendation.

9. Digital Solutions

Digital Solutions may include portals, websites, applications, APIs, automations, Power Platform, Dynamics 365 integration, data solutions, and reporting.

The SOW should define supported browsers, devices, accessibility target, hosting, source-code treatment, environments, release process, data migration, acceptance, warranty period, and ongoing maintenance. Customer content, trademarks, datasets, business rules, and legal notices remain the Customer’s responsibility.

Third-party libraries and open-source components retain their licences. Security patches, platform upgrades, browser changes, and new feature work after acceptance require a support or maintenance arrangement.

10. elyXionPortal

The Portal may provide service visibility, requests, documentation, asset information, recommendations, project updates, cost data, and security insights. Features depend on subscription, integrations, and development stage.

Portal information may be delayed, incomplete, or derived from third-party APIs. It supports decision-making but does not replace authoritative Microsoft consoles, contractual reports, professional judgement, or emergency channels. Recommendations require Customer evaluation and approval before implementation unless pre-authorised.

11. Automation and Infrastructure as Code

elyXion may use Bicep, Terraform, GitHub, Azure DevOps, scripts, APIs, and deployment pipelines. Automation reduces inconsistency but can propagate errors if inputs or permissions are wrong. Source control, review, testing, state management, secrets handling, and release permissions will follow the agreed design.

The Customer must not bypass agreed pipelines or manually alter managed resources in ways that create drift. elyXion may restore the declared configuration after notice, subject to change approval.

12. AI-enabled Features

AI may assist search, summarisation, recommendations, drafting, classification, or support. AI outputs may be inaccurate and require human review. The [AI Usage Policy](../responsible-technology/ai-usage-policy.md) applies. High-impact or regulated decisions are excluded unless separately assessed, designed, and contracted.

13. Onboarding

Onboarding may include scope validation, access setup, asset inventory, baseline assessment, monitoring deployment, documentation intake, and operational handover. SLA targets begin only after the relevant system is accepted into service and onboarding prerequisites are complete.

Pre-existing incidents, unsupported configurations, technical debt, and undocumented dependencies are not assumed into scope merely because discovered during onboarding.

14. Offboarding

elyXion will revoke its access, provide agreed exports, and cooperate with transition. The Customer must nominate recipients and maintain replacement access. Read-only records may be retained for legal, security, billing, and audit purposes according to the Privacy Policy and DPA.

15. Exclusions Common to all Services

Unless expressly included:

  • 24/7 support, threat monitoring, or on-site response;
  • unlimited service requests or project work;
  • legal, tax, audit, certification, or regulatory opinions;
  • end-user training, hardware repair, cabling, telecoms, or physical security;
  • support for end-of-life, unlicensed, or materially altered systems;
  • third-party vendor fees, licences, or commitments;
  • data recovery where no valid backup exists;
  • business ownership of data classification, records retention, or risk acceptance; and
  • implementation of every recommendation identified in an assessment or report.

16. Customer-specific Schedules

Regulated, high-risk, or complex environments may require a service schedule covering sector obligations, segregation, personnel screening, data location, audit evidence, change freezes, incident coordination, recovery objectives, and exit.

Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review