Master Services Agreement

Master Services Agreement

The standard terms behind every Ocala Cyber engagement, for small businesses and home offices in Marion County, FL and surrounding areas.

Document: Master Services Agreement · Version: v2.1.1 · September 2026 · Contact: contact@ocalacyber.com

These are the standard terms behind every Ocala Cyber engagement. They are not what you sign on their own. What you sign is a short Service Order naming you, the work, the price and the dates, and that Service Order brings these terms with it.

Section 1 - The Parties and How This Agreement Works

1.1. The Parties

This Master Services Agreement (the "Agreement") is between Ocala Cyber, Marion County, Florida (contact@ocalacyber.com, (352) 327-8056), and the client identified on a Service Order (the "Client"). Ocala Cyber and the Client are each a "party".

1.2. What this Agreement is

This Agreement sets the standard terms for every engagement between the parties. It is not signed on its own and it does not commit either party to any particular work. There are two ways an engagement starts, and both bring these terms with them.

1.3. One-off work: a Service Order

Project work (an assessment, a setup, an incident response, anything scoped and priced for the occasion) starts with a Service Order. That is a short document naming the Client, the service or services to be performed, the delivery method, the fee, and the expected deliverables and dates. Each Service Order incorporates this Agreement by reference. Signing a Service Order means the Client accepts this Agreement as it stands on that date.

1.4. Ongoing services: enrollment under a Schedule

A subscription or membership (for example Digital Bodyguard) does not use a Service Order. It starts when the Client enrolls in that service, either by completing its enrollment form (online or on paper) or by written agreement with Ocala Cyber. The terms of the service are the Schedule named for it in this Agreement, and enrollment means the Client accepts that Schedule together with this Agreement as they stand on that date. Its price, billing cycle and cancellation terms are stated in its Schedule and at the point of enrollment, not on a Service Order.

1.5. Schedules

Some services carry their own terms. Those are set out in the Schedules to this Agreement and apply only when the Client has purchased that service. A Schedule may set out its own fees, billing and cancellation terms, in which case those govern for that service.

1.6. Order of precedence

Where documents conflict, the order of precedence is: (a) the Schedule for the service in question, (b) this Agreement, (c) the Service Order. A Service Order may vary a term of this Agreement only where it says so expressly and both parties have signed it.

Section 2 - Scope of Services

Ocala Cyber will perform the service or services described on the applicable Service Order, using the delivery method (remote or on-site) stated there, together with any scope notes or special instructions the Service Order records.

Important: Any services not explicitly listed on the Service Order are out of scope. Changes to scope must be agreed upon in writing (email is acceptable) before additional work begins.

Where a service has its own terms, those terms are in the Schedule named for that service and apply in addition to this Agreement.

Section 3 - Fees & Payment

3.1. Agreed Fee

The total fee, the pricing structure (flat, hourly, or to be determined), and any payment notes such as a required deposit or when an invoice is issued are stated on the applicable Service Order. Recurring subscription services are billed as described in the Schedule for that service.

3.2. Payment Terms

3.3. Refund Policy

Fees are non-refundable once work has commenced. If Ocala Cyber is unable to complete the agreed scope due to circumstances within our control, a prorated refund will be issued for unperformed work.

Section 4 - Client Authorization

4.1. Authorization to Assess

By signing this Agreement, the Client confirms that they are the owner of, or have explicit authority over, all systems, networks, accounts, and data that will be reviewed or accessed during this engagement. The Client grants Ocala Cyber permission to perform the agreed services on those systems.

4.2. Cooperation

The Client agrees to provide reasonable access, credentials, and cooperation necessary to complete the engagement. Delays caused by lack of access or cooperation may affect the delivery timeline and are not the responsibility of Ocala Cyber.

4.3. No Unauthorized Access

Ocala Cyber will only access systems, accounts, and data that are explicitly within the agreed scope. The Client acknowledges that any scope expansion requires a written amendment to this Agreement.

Section 5 - Deliverables & Timeline

5.1. Deliverable(s)

The expected deliverables and the estimated delivery date are stated on the applicable Service Order.

5.2. Delivery

Unless otherwise agreed, deliverables will be sent via email in PDF or another format agreed with the Client. Ocala Cyber will make reasonable efforts to meet the estimated delivery date. Delays caused by factors outside our control (e.g., client system access issues, incomplete intake information) will be communicated promptly.

5.3. Revisions

One round of minor revisions is included at no additional charge within 7 days of delivery. Additional revisions or major scope changes will be quoted separately.

Section 6 - Confidentiality

6.1. Client Information

Ocala Cyber agrees to treat all client information - including but not limited to business data, system configurations, credentials, findings, and any information marked confidential - as strictly confidential. This information will not be shared with any third party without the Client's written consent, except as required by law and except for the service providers and subprocessors described in Section 7.7, whose use the Client authorizes by entering into this Agreement.

6.2. Engagement Details

Ocala Cyber will not publicly disclose, reference in marketing materials, or otherwise identify the Client as a customer without prior written permission.

6.3. Mutual Obligation

The Client agrees to keep any proprietary methodologies, tools, templates, or procedures provided by Ocala Cyber confidential and not to share or reproduce them for commercial purposes.

6.4. Duration

Confidentiality obligations survive the termination of this Agreement for a period of five (5) years.

Section 7 - Limitations & Disclaimers

7.1. Nature of Services

Ocala Cyber provides advisory and assessment services, as well as hands-on setup, configuration, and remediation services performed with the Client’s authorization on systems and accounts the Client owns or controls. Our findings represent a point-in-time review based on the information and access available during the engagement. Cybersecurity is not a guarantee - identifying and remediating risks reduces exposure but does not eliminate all possibility of a security incident.

7.2. No Penetration Testing

Unless explicitly stated in Section 2, this Agreement does not authorize any form of penetration testing, exploitation, offensive security activity, or attempts to bypass security controls. Ocala Cyber does not perform offensive security services.

7.3. Limitation of Liability

To the fullest extent permitted by law, Ocala Cyber's total liability arising out of or related to this Agreement - whether in contract, tort, or otherwise - shall not exceed the total fees paid by the Client under this Agreement. Ocala Cyber is not liable for indirect, incidental, consequential, or punitive damages of any kind.

Ocala Cyber's services do not constitute legal advice and do not guarantee compliance with HIPAA, PCI-DSS, SOC 2, CMMC, or any other regulatory framework. Clients requiring formal compliance certification should engage a qualified compliance auditor.

7.5. Third-Party Tools

Ocala Cyber may use third-party tools and software during engagements. We are not responsible for errors, omissions, or limitations of those tools.

7.6. AI Tools Disclosure

Ocala Cyber uses AI-assisted tools - including Anthropic Claude - to support analysis, report drafting, and internal research. This use occurs only with your express written consent, as described in this section When AI tools are used:

Client consent to AI tool use is captured at two points: (a) by signing this Agreement, and (b) by completing the AI Data Handling Agreement acknowledgment at portal intake - a typed-signature checkbox stamped with the current AI Data Handling Policy version (v2.1-2026-08) and recorded with a timestamp in an append-only audit log. Ocala Cyber’s internal Orchestrator refuses to invoke any AI-using tool against a Client whose consent record is missing. The Client may revoke consent at any time by emailing contact@ocalacyber.com; revocation halts AI tooling on future work but does not undo prior runs.

7.7. Data Handling Limitations

Ocala Cyber collects only the information necessary to perform the agreed services. The following data handling practices apply: Anonymization To Minimize AI Exposure. Within its automated tooling, Ocala Cyber removes or tokenizes the following categories of identifying information before submitting client material to an AI tool: company names, employee and client names, physical addresses, phone numbers, email addresses, IP addresses, MAC addresses, and hostnames. Removed values are stored in a secure local keystore on Ocala Cyber devices only and are re-inserted locally. This minimizes the identifying information exposed to any AI service. Every AI provider Ocala Cyber uses operates under commercial terms with model training disabled and no retention of conversations beyond the active session; no credentials, passwords, financial account data, Social Security numbers, or protected health information are submitted to any AI tool. Re-Integration After AI Processing. Once automated AI-assisted work is complete, the identifying information held in the local keystore is re-inserted into the final document on Ocala Cyber's local devices, prior to any client delivery, so that deliverables returned to the Client reflect real values while minimizing what was exposed to an AI system during processing. Analyst Copilot (In-App Engagement Assistant). Ocala Cyber may use an optional in-application assistant to help the analyst plan and run an engagement, enabled only for Clients who have signed this Agreement's AI consent and completed the anonymization process described above. The assistant minimizes identifiers using the same keystore tokenization as other AI-assisted work under this Section - the Client's business name, contact names, and known identifiers are replaced with placeholders before any request is sent, and the placeholders are restored only on Ocala Cyber's local devices. The assistant may not generate a document, run a monitoring check, or take any other action affecting the Client's engagement without an Ocala Cyber analyst's explicit review and approval of that specific action. Online Portal Data Collection. When Clients use the Ocala Cyber client portal (portal.ocalacyber.com), the following information is collected and stored in a cloud database operated by Supabase, Inc. (supabase.com), hosted on Amazon Web Services (AWS) infrastructure in the United States:

Continuous Monitoring Services - Third-Party Data Collection. Clients who subscribe to an ongoing monitoring service (for example, the Cyber Watch bundle) authorize Ocala Cyber to transmit a limited set of identifiers to specialized third-party security-data providers in order to perform the monitoring. These providers are not AI services, and only the specific identifiers needed for each check are sent - never full client documents, profiles, credentials, Social Security Numbers, financial account data, or protected health information. The data transmitted depends on the services selected:

Where the results of these monitoring services are further analyzed with AI assistance, the anonymization process described above is applied before any material is submitted to an AI tool. Monitoring data is retained in accordance with Ocala Cyber’s Data Retention & Destruction Policy and is deleted at the close of the engagement or subscription. The specific third-party providers used for each monitoring service are recorded in Ocala Cyber’s internal AI Data Handling Policy and are available to the Client on request. Security Check - Local Data Collection. The Security Check - WiFi and Check My Security services use a client-run local scan script and browser-based tool. When the Client runs the scan script on their local network, it collects: the local gateway IP address, connected-device information visible on the local subnet, and router/network configuration data. The Security Check - Devices service uses a separate client-run, read-only script that collects endpoint configuration only: antivirus and endpoint-protection status, operating-system and software update status, disk-encryption status, and local and administrator account information. Phones, tablets, and point-of-sale devices cannot run a script; for these, the Client completes a guided checklist in a web browser, selecting the status of each security setting. The Client provides the answers; the checklist never reads or collects files, messages, contacts, or passwords. These scripts and the checklist are read-only and transmit nothing on their own; they never capture the WiFi password, any public-facing IP address, file or message contents, or passwords. Their results reach Ocala Cyber only if the Client chooses to send them, using the one-time engagement code described in the next paragraph. Security Check - Field Kit Result Submission. For the WiFi, Home, Devices, and Mobile & POS checks, the Client may send results to Ocala Cyber by entering a one-time engagement code (format OC-XXXX-XXXX) that Ocala Cyber provides. When the code is entered, the results - for the scripts, the read-only configuration findings described above; for the Mobile & POS checklist, the answers the Client selected, an optional device label, and any notes the Client chooses to add - are transmitted over an encrypted connection to a private cloud storage area operated by Supabase, Inc. (supabase.com) on Amazon Web Services infrastructure in the United States, protected by the one-time code and accessible only to Ocala Cyber. No file contents, messages, passwords, WiFi passwords, or public-facing IP addresses are included. Submitted results are removed from cloud storage once Ocala Cyber retrieves them, and are automatically deleted within 30 days in any case. Before any AI-assisted analysis, the anonymization process described above is applied to these results, exactly as for any other client material. Security Check - Cloud Configuration Data Collection. The Security Check - Cloud service reviews the security configuration of the Client’s cloud productivity suite (Microsoft 365 or Google Workspace). The Client’s own administrator runs a read-only script that signs in to the Client’s own tenant using the Client’s own administrator credentials. Ocala Cyber never sees or receives the Client’s password. The script reads configuration and security settings only: multi-factor authentication status by account, administrator and guest account lists, mailbox and inbox forwarding rules, other mail-handling rules, external file-sharing settings, email-authentication (DKIM) and threat-protection policy settings, the suite’s security (“secure”) score and recommended actions, and tenant, domain, and license context. This configuration data includes user identifiers such as email addresses and display names, and the Client’s domain name(s). The script is read-only; it makes no changes to any setting and never accesses, stores, or transmits message contents, files, documents, or passwords. It produces a single configuration file that the Client provides to Ocala Cyber. The only system the script contacts is the Client’s own Microsoft 365 or Google Workspace tenant; no client identifiers are sent to any third-party security-data provider. The configuration file is processed on Ocala Cyber’s local devices, and the identifying information it contains is removed through the anonymization process described above before any AI-assisted analysis. Home and Individual Services - Direct Setup, Advisory, and Remediation. Ocala Cyber's home and individual services - including Check My Security, Set Up My Security, Incident Response (scam help, a self-guided identity-theft recovery action plan, and account or device compromise recovery), Digital Bodyguard, Rental Guest Device Lockdown, Family Tech Guardian Setup, Digital Legacy Planning, and Kid-Safe Device Setup - are performed directly on the Client's own devices and accounts, with the Client present or with the Client's documented authorization. These services do not transmit Client data to any third-party security-data provider beyond those already listed in this Section. Any backup, password-manager, or similar service the Client chooses to adopt is the Client's own account, funded and controlled by the Client; Ocala Cyber helps configure it but does not operate it and does not retain access to it. Where a written deliverable is produced with AI assistance, identifying context is minimized before submission, following the anonymization process described above; the Client's name and identifiers are added locally, consistent with the practices in this Section. Digital Bodyguard - Forwarded-Content Handling. Clients who subscribe to Digital Bodyguard may forward suspicious emails, text messages, screenshots, or written descriptions to a dedicated Ocala Cyber mailbox (phishing@ocalacyber.com) for review. Automated technical checks (deterministic analysis of headers, links, and attachments; no AI) support that review by flagging signals for the analyst; a person makes every determination and confirms every reply before it is sent. If an AI-assisted summary is ever added to this process, identifying details will be minimized first, consistent with Section 7.7, and this section will be updated before that AI step goes live. Ocala Cyber reviews only what the Client chooses to send; we do not access the Client's mailbox, accounts, or devices to perform this review. Forwarded content is retained in accordance with Ocala Cyber's Data Retention and Destruction Policy. Website Contact Form and Automated Acknowledgments. Inquiries submitted through the public website contact form (ocalacyber.com) are processed by Netlify, Inc. (netlify.com), which delivers each submission to Ocala Cyber by email. An automated acknowledgment email is then sent to the submitter by Resend, Inc. (resend.com). Through the website contact form, the only information these providers process is the name, email address, and message submitted through the form. No engagement data, client documents, or assessment results are ever transmitted to either provider. Client Portal Account Emails. Account-related emails from the Client Portal (portal.ocalacyber.com), such as account invitations and password-reset messages, are also delivered by Resend, Inc. (resend.com). Resend processes only the recipient’s email address and the contents of the message (for example, a sign-in or password-reset link) for the sole purpose of delivering it. No engagement data, client documents, or assessment results are transmitted to Resend. Website Analytics. The public website (ocalacyber.com) uses Google Analytics 4, a measurement service provided by Google LLC (google.com), to understand how visitors find and use the site. This information is collected automatically from website visitors as they browse and includes pages viewed, approximate (city-level) location, device and browser type, and referral source, set using cookies. Google Analytics does not log or store full IP addresses, and this analytics data is never combined with engagement data, client documents, portal submissions, or assessment results. It is used only to measure and improve the website in aggregate, never to advertise to Clients or to identify any individual personally. Google processes this data under Google’s own privacy policy; visitors may opt out using the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout) or by blocking cookies in their browser. Invoicing and Payment Processing. Invoices are issued through Zoho Books, and online payments are processed by Zoho Payments (Zoho Corporation, zoho.com). When the Client pays an invoice online, payment card or bank account details are entered directly with and processed by Zoho Payments; Ocala Cyber never receives, stores, or has access to them. Ocala Cyber retains only standard billing records (the invoice, amount, date, and payment status), which are kept for 7 years in accordance with IRS requirements. Additional commitments:

AI-Assisted Review of Consent-Revocation Requests. If you email Ocala Cyber to revoke your AI Data Handling Agreement, a member of our staff reviews and confirms every such request before any change is made. When enabled, Ocala Cyber may additionally use an AI tool to draft an internal advisory note about whether an email appears to be a genuine revocation request. Before any such use, the sender's email address and name, any other email addresses, and phone numbers in standard formats are removed from the text and replaced with placeholders. The AI tool is not told who sent the email and receives only the redacted text of that one message; details you choose to type into the body of your email may remain in that text. No action is ever taken based on the AI note alone.

7.8. HIPAA & Protected Health Information

Ocala Cyber does not collect, receive, process, transmit, or store Protected Health Information (PHI) as defined under HIPAA. Our engagements assess the security posture of systems and operations - not the patient or health data those systems may contain. The following limitations apply to all engagements:

7.9. FTC Compliance

Ocala Cyber’s data handling practices comply with Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45), which prohibits unfair or deceptive acts or practices in or affecting commerce. The commitments stated in Section 7.7 are accurate descriptions of our actual practices. Clients in financial services - including banks, credit unions, mortgage companies, insurance providers, tax preparers, and financial advisors - may be subject to the FTC Safeguards Rule (Gramm-Leach-Bliley Act). Ocala Cyber’s assessments can support a client’s Safeguards Rule compliance program but do not substitute for the client’s own compliance review and do not constitute a compliance guarantee.

Section 8 - Independent Contractor

Ocala Cyber operates as an independent contractor. Nothing in this Agreement creates an employment relationship, partnership, joint venture, or agency between the parties. Ocala Cyber is responsible for its own taxes, insurance, and business expenses.

Section 9 - Term & Termination

9.1. Term

This Agreement is effective as of the date signed below and remains in effect until the agreed services have been delivered and payment has been received, or until terminated as described below.

9.2. Termination by Either Party

Either party may terminate this Agreement with 5 business days' written notice (email is acceptable). In the event of termination, the Client is responsible for fees covering work completed through the termination date.

9.3. Immediate Termination

Ocala Cyber reserves the right to terminate this Agreement immediately if the Client misrepresents their authority over the systems being reviewed, requests activities outside the agreed scope, or engages in conduct that creates legal or ethical risk.

Section 10 - Governing Law & Disputes

This Agreement shall be governed by the laws of the State of Florida. Any disputes arising from this Agreement that cannot be resolved through good-faith negotiation will be submitted to binding arbitration in Marion County, Florida, under the rules of the American Arbitration Association.

Section 11 - Entire Agreement

This Agreement, together with its Schedules and each signed Service Order, constitutes the entire agreement between the parties regarding the services described in those Service Orders. It supersedes all prior discussions, proposals, or understandings. Amendments must be made in writing and signed (or confirmed via email) by both parties. If any provision of this Agreement is held unenforceable, the rest remains in force.

Section 12 - Acceptance

No separate signature to this Agreement is required. It is accepted either way an engagement starts:

Either route confirms that the Client has had the opportunity to read this Agreement and the Schedule for each service taken.

Ocala Cyber may update this Agreement. An updated version applies to Service Orders signed, and enrollments completed, after it is published; it does not change a Service Order already signed. Clients on an ongoing service are notified before an update applies to them, and may cancel instead.

Schedule A - Digital Bodyguard Membership

Applies only when the Client has enrolled in Digital Bodyguard.

Schedule A is the Digital Bodyguard Membership Agreement, in the version the Client accepted at enrollment, published at ocalacyber.com/digital-bodyguard/join/; each version remains available at the address given in the member's welcome email. No Service Order is used. Membership starts when the Client completes the enrollment form, which records the Client's typed signature, the date and the version accepted. That agreement carries the service's scope, response expectations, reasonable use, included support time and its overage rate, price, billing, cancellation and termination terms, and ranks as this Agreement's Schedule under Section 1.6; Section 3 of this Agreement applies only where it is silent. The endpoint protection software it includes is subject to Schedule B, and the vendors it relies on are listed in Schedule C.

Schedule B - Endpoint Protection Software (Third-Party Licensed)

Applies whenever Ocala Cyber installs, or arranges the installation of, a third-party endpoint protection product (anti-virus or endpoint detection and response software) on a device belonging to the Client, under any service. These terms are in addition to the rest of this Agreement, and are required by the manufacturer of that software as a condition of Ocala Cyber supplying it.

In this Schedule, "Endpoint Software" means the third-party endpoint protection product Ocala Cyber installs and manages, together with its agent software, management console and documentation. "Vendor" means the manufacturer of that product and its licensors. The Vendor currently used is SentinelOne, supplied to Ocala Cyber through its distributor. Ocala Cyber may change the Vendor on notice to the Client, in which case this Schedule applies to the replacement product.

B.1. Nature of the license

The Endpoint Software is licensed, not sold, and is not Ocala Cyber's software. All right, title and interest in the Endpoint Software, and all intellectual property rights in it, remain with the Vendor. The Client receives no ownership interest in it.

Subject to this Agreement, and for so long as the Client's service with Ocala Cyber remains active, the Client is granted a non-exclusive, non-transferable, non-sublicensable right to have the Endpoint Software installed and operated on devices the Client owns or controls, solely as part of the service Ocala Cyber delivers to the Client. No other right or license is granted, by implication or otherwise.

B.2. Restrictions on use

The Client will not, and will not permit any other person to:

(a) modify, translate, adapt or create derivative works of the Endpoint Software or its documentation;

(b) license, sublicense, resell, distribute, lease, rent, lend, transfer, assign or otherwise dispose of the Endpoint Software or its documentation;

(c) disassemble, decompile or reverse engineer the Endpoint Software, except to the extent applicable law expressly permits it despite this restriction;

(d) use the Endpoint Software in any unlawful way, in violation of any law or regulation, or in violation of any third party's property, privacy or personal rights, including to store or transmit infringing, defamatory or otherwise unlawful material;

(e) use the Endpoint Software to store or transmit viruses, malicious code, or any software routine designed to permit unauthorized access to, or to disable, erase or otherwise harm, software, hardware or data;

(f) copy, frame or mirror any part of the Endpoint Software or its content;

(g) access or use the Endpoint Software to build a competing product or service, or copy any of its features or functions;

(h) interfere with or disrupt the integrity or performance of the Endpoint Software;

(i) attempt to gain unauthorized access to the Endpoint Software, to its related systems or networks, or to another user's account;

(j) disclose to any third party, or publish in any medium, any performance information or analysis relating to the Endpoint Software, without the Vendor's consent;

(k) remove, alter or obscure any proprietary notice on or in the Endpoint Software or its documentation, including copyright notices; or

(l) probe, scan or test the vulnerability of the Endpoint Software, attempt to breach its security or authentication measures, or take any action that places an unreasonable or disproportionately large load on its infrastructure.

The Client will tell Ocala Cyber promptly on becoming aware of any breach of this Section B.2.

B.3. The Vendor's liability

The Vendor's liability to the Client in connection with the Endpoint Software is limited, and the Client accepts that limit as a condition of receiving the Endpoint Software.

To the maximum extent permitted by law:

(a) The Endpoint Software is provided by the Vendor without warranties of any kind, whether express, implied or statutory, including any implied warranty of merchantability, fitness for a particular purpose, non-infringement or title. The Vendor does not warrant the results that may be obtained from the Endpoint Software. Endpoint protection software reduces risk; it does not guarantee that malicious software will be prevented, detected or removed.

(b) The Vendor is not liable to the Client for any loss of profits, loss of use, loss of revenue, loss of goodwill, interruption of business, or for any indirect, special, incidental, exemplary, punitive or consequential damages of any kind arising out of or in connection with the Endpoint Software, whether in contract, tort, strict liability or otherwise, even if the Vendor has been advised of the possibility of such damages.

(c) The Vendor's total aggregate liability to the Client arising out of, resulting from or relating to the Endpoint Software will not exceed the limitation of liability the Vendor assumes under the Vendor's own terms of service, and in no event will it exceed the total amount the Client paid Ocala Cyber for the service under which the Endpoint Software was supplied during the twelve months before the event giving rise to the claim. Multiple claims do not expand this limit.

(d) The Client's remedies in respect of the Endpoint Software are against Ocala Cyber under this Agreement, not against the Vendor.

(e) The Vendor is an intended third-party beneficiary of this Section B.3 and of Section B.2, and may enforce them directly.

Nothing in this Schedule excludes or limits any liability, or any right of the Client, that cannot lawfully be excluded or limited under Florida law or under any consumer-protection law that applies to the Client.

B.4. Removal

Ocala Cyber removes the Endpoint Software from the Client's devices, and ends the Client's access to it, on the Client's request and on termination or expiry of the service under which it was supplied. The Client may instead take a license directly from the Vendor, on the Vendor's own terms, if the Vendor offers one.

B.5. Where detection data lives

Detections, alerts and related activity generated by the Endpoint Software are held in the Vendor's management console, which Ocala Cyber operates on the Client's behalf. Ocala Cyber does not retain copies of that data outside the Vendor's console. Data handled under this Schedule is otherwise subject to Section 7.7 (Data Handling Limitations).

Questions? contact@ocalacyber.com | (352) 327-8056

Want a copy? Email contact@ocalacyber.com and we will send the signable document.