DOCS-1: Init document work

This commit is contained in:
Blake Ridgway
2026-07-28 07:20:32 -05:00
parent 8f02a3fc8e
commit 0cbcc962f7
66 changed files with 12224 additions and 71 deletions

242
content/legal/dpa.md Normal file
View File

@@ -0,0 +1,242 @@
# Data Processing Agreement (DPA)
**Arcline IT LLC**
Last updated: May 2026
This Data Processing Agreement ("DPA") forms part of the Master Service
Agreement ("MSA") between Arcline IT LLC ("Data Processor", "Arcline", "we",
"us") and the Customer ("Data Controller", "you").
---
## 1. Definitions
| Term | Definition |
|------|------------|
| **Controller** | The entity that determines the purposes and means of processing personal data |
| **Processor** | The entity that processes personal data on behalf of the Controller |
| **Data Subject** | An identified or identifiable natural person |
| **Personal Data** | Any information relating to an identified or identifiable natural person |
| **Processing** | Any operation performed on personal data (collection, storage, retrieval, transmission, deletion, etc.) |
| **GDPR** | Regulation (EU) 2016/679, the General Data Protection Regulation |
| **CCPA** | California Consumer Privacy Act, as amended |
| **Sub-processor** | A third party engaged by the Processor to process personal data |
---
## 2. Scope and Purpose
### 2.1 Application
This DPA applies whenever Arcline processes personal data on behalf of
Customer in the course of providing Services under the MSA.
### 2.2 Relationship
- **Customer** is the Data Controller
- **Arcline** is the Data Processor
- Customer retains full control over their personal data
- Arcline processes data only on Customer's documented instructions
### 2.3 Duration
This DPA remains in effect for as long as Arcline processes personal data on
behalf of Customer, plus the duration of any data retention obligations.
---
## 3. Description of Processing
### 3.1 Categories of Data Subjects
- Customer's employees, contractors, and agents
- Customer's end users and website visitors
- Individuals who communicate with Customer through their Arcline-hosted services
### 3.2 Categories of Personal Data
- Account information: name, email address, billing address, phone number
- Technical data: IP addresses, server access logs, browser user-agent strings
- Content data: files, databases, emails, and other content stored on Arcline
infrastructure at Customer's direction
- Payment data: processed through Stripe (PCI-DSS compliant); Arcline does
not store full credit card numbers
### 3.3 Special Categories of Data
Arcline does not intentionally process special categories of data (health
information, biometric data, political opinions, religious beliefs, etc.).
Customer agrees not to upload special category data to Arcline infrastructure
without additional contractual safeguards.
### 3.4 Processing Activities
- **Storage:** Customer data stored on Arcline's servers
- **Hosting:** Serving Customer's websites and applications to visitors
- **Backup:** Creating and maintaining backup copies for disaster recovery
- **Email:** Routing and storing email messages (where applicable)
- **Support:** Accessing data for troubleshooting and support purposes
---
## 4. Processor Obligations
### 4.1 Instructions
Arcline will process personal data only on documented instructions from
Customer, unless required to do otherwise by applicable law (in which case
Arcline will notify Customer of that legal requirement before processing,
unless prohibited by law).
### 4.2 Confidentiality
Arcline ensures that all personnel authorized to process personal data have
committed to confidentiality obligations.
### 4.3 Security
Arcline maintains appropriate technical and organizational security measures,
including:
**Technical Measures:**
- Encryption in transit (TLS 1.2+ for all services)
- Firewalls with default-deny rules
- Network segmentation (VLANs)
- Regular security patching
- Intrusion detection and prevention systems (Suricata)
- Access logging and monitoring
- Encrypted off-site backups
**Organizational Measures:**
- Access control based on least privilege
- Security training for personnel
- Incident response procedures
- Regular security assessments
- Vendor due diligence for sub-processors
### 4.4 Sub-processors
Customer authorizes Arcline to engage the following sub-processors:
| Sub-processor | Service | Location |
|---------------|---------|----------|
| Stripe, Inc. | Payment processing | United States |
| Let's Encrypt / ISRG | SSL certificate issuance | United States |
| GitLab B.V. | CI/CD and source control | United States/Europe |
Arcline will notify Customer of any intended changes to sub-processors.
Customer may object within 14 days. If reasonable objections cannot be
resolved, Customer may terminate the affected services.
### 4.5 Data Subject Rights
Arcline will assist Customer in responding to data subject requests under
applicable privacy laws, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
Customer should forward any data subject requests they receive to
**privacy@arcline.it**. Arcline will respond within the timeframe required
by applicable law.
### 4.6 Data Breach Notification
In the event of a personal data breach, Arcline will:
1. Notify Customer within 72 hours of becoming aware of the breach
2. Provide details of the nature, scope, and impact of the breach
3. Describe measures taken to address the breach
4. Cooperate with Customer in notifying supervisory authorities and affected
data subjects, where required
### 4.7 Data Protection Impact Assessments
Arcline will provide reasonable assistance to Customer in conducting data
protection impact assessments, where required by applicable law.
---
## 5. International Transfers
### 5.1 Data Location
Customer data is primarily stored on servers located in the United States.
### 5.2 Adequacy
For transfers of personal data from the European Economic Area (EEA),
Switzerland, or the United Kingdom to the United States, the parties agree
that the Standard Contractual Clauses (SCCs) approved by the European
Commission shall govern such transfers.
### 5.3 Alternative Mechanism
If the SCCs are deemed invalid or insufficient by a competent authority,
Arcline will implement an alternative lawful transfer mechanism.
---
## 6. Data Retention and Deletion
### 6.1 During the Term
Customer data is retained for the duration of the MSA or until Customer
requests deletion.
### 6.2 Upon Termination
Following termination of the MSA:
- **Active data:** Deleted within 30 days of termination
- **Backups:** Deleted within 90 days of termination
- **Access logs:** Anonymized or deleted within 12 months
### 6.3 Deletion Procedures
Data is securely deleted using:
- Secure file deletion (shred/overwrite) for files
- `DROP TABLE` for SQLite databases
- Cryptographic erasure for encrypted backups
### 6.4 Certificate of Deletion
Upon request, Arcline will provide a written certificate confirming that
Customer's data has been securely deleted.
---
## 7. Audit and Compliance
### 7.1 Right to Audit
Customer may request an audit of Arcline's data processing operations, at
Customer's expense, no more than once per 12-month period. Audits must:
- Be conducted during normal business hours
- Give at least 30 days notice
- Not unreasonably interfere with Arcline's operations
- Be performed by a mutually agreed independent auditor
### 7.2 Records of Processing
Arcline maintains written records of all processing activities conducted on
behalf of Customer, as required by Article 30 of the GDPR.
### 7.3 Compliance
Arcline will promptly notify Customer if any instruction from Customer
violates applicable data protection laws.
---
## 8. Liability
### 8.1 Liability Cap
Each party's liability under this DPA is subject to the limitations of
liability set forth in the MSA.
### 8.2 Direct Damages
Notwithstanding the general limitation above, either party may seek direct
damages for breaches of this DPA.
### 8.3 Regulatory Fines
Each party is responsible for administrative fines imposed on them by a
supervisory authority for their own violations of applicable data protection
law.
---
## 9. Governing Law
This DPA shall be governed by the same law as the MSA. Any dispute arising
from this DPA shall be resolved under the dispute resolution provisions of
the MSA.
---
## 10. Order of Precedence
In the event of any conflict or inconsistency between this DPA and the MSA,
this DPA shall prevail with respect to data processing matters.
---
*Questions about this DPA? Contact us at privacy@arcline.it*

317
content/legal/msa.md Normal file
View File

@@ -0,0 +1,317 @@
# Master Service Agreement (MSA)
**Arcline IT LLC**
Last updated: May 2026
---
## 1. Parties
This Master Service Agreement ("Agreement") is between **Arcline IT LLC**
("Arcline", "Provider", "we", "us") and the customer named in the applicable
Order Form ("Customer", "you"). This Agreement governs all Services provided
by Arcline to Customer.
---
## 2. Services
### 2.1 Service Offerings
Arcline provides the following hosting services ("Services"):
- **Shared Web Hosting** — Multi-tenant web server with cPanel control panel
- **WordPress Hosting** — Managed WordPress environment
- **VPS Hosting** — Virtual private servers with root access
- **Domain Registration** — Domain name registration and management
- **SSL Certificates** — Let's Encrypt SSL certificate provisioning
- **Email Hosting** — Self-hosted email services (where available)
### 2.2 Service Levels
Services are provided in accordance with our [Service Level Agreement (SLA)](sla.md),
which is incorporated by reference into this Agreement.
### 2.3 Changes to Services
Arcline may modify, upgrade, or discontinue specific service offerings with
30 days written notice to Customer. In the event of service discontinuation,
Customer will receive a pro-rata refund for any prepaid but unused Service
fees.
---
## 3. Term and Termination
### 3.1 Initial Term
The initial term of this Agreement begins on the date Customer accepts these
terms (by signing an Order Form or creating an Arcline account) and continues
for the duration of the initial billing period selected in the Order Form.
### 3.2 Renewal
This Agreement automatically renews for successive billing periods of equal
length unless either party provides written notice of non-renewal at least
7 days before the end of the current term.
### 3.3 Termination for Convenience
Customer may terminate this Agreement at any time from the client portal or
by contacting support. Services continue until the end of the current billing
period. No refunds are provided for partial months, except as stated in
Section 2.3.
### 3.4 Termination for Cause
Either party may terminate this Agreement immediately upon written notice if:
- The other party materially breaches this Agreement and fails to cure the
breach within 7 days of receiving written notice
- The other party becomes insolvent, files for bankruptcy, or ceases operations
### 3.5 Effects of Termination
Upon termination:
- Customer's access to Services ceases
- Arcline will delete Customer's data after the data preservation period
(14 days for shared hosting, 7 days for VPS)
- Outstanding invoices become immediately due and payable
---
## 4. Fees and Payment
### 4.1 Fees
Customer agrees to pay the fees specified in the Order Form. All fees are
in United States Dollars (USD). Fees do not include taxes, which are
Customer's responsibility.
### 4.2 Invoicing
Fees are billed in advance on a monthly or annual basis as selected in the
Order Form. Invoices are generated on the billing date and sent by email.
### 4.3 Payment Terms
Payment is due upon receipt of invoice. Accounts more than 7 days past due
may be suspended. Suspended accounts are held for 14 days before data is
deleted.
### 4.4 Price Changes
Arcline may change service pricing with 30 days written notice. Price
increases will not exceed 10% annually unless required by changes in
underlying infrastructure costs.
### 4.5 Refunds
- **Monthly plans:** Non-refundable after the billing cycle begins
- **Annual plans:** Pro-rata refund available within the first 30 days
- **Setup fees:** No setup fees are charged
---
## 5. Customer Responsibilities
### 5.1 Account Security
Customer is responsible for:
- Maintaining the confidentiality of login credentials
- All activity occurring under their account
- Promptly notifying Arcline of any suspected unauthorized access
### 5.2 Acceptable Use
Customer must comply with the [Acceptable Use Policy (AUP)](https://arcline.it/aup),
which is incorporated by reference. Violation of the AUP may result in
immediate suspension without refund.
### 5.3 Data Backup
Customer is responsible for maintaining independent backups of their data.
Arcline performs routine backups for disaster recovery purposes but does not
guarantee data availability in all scenarios. VPS customers are solely
responsible for their own backup strategy.
### 5.4 Compliance
Customer represents and warrants that:
- Their content and use of Services complies with all applicable laws
- They hold all necessary rights and permissions for content stored on
Arcline infrastructure
- They will not use Services to violate the rights of others
---
## 6. Provider Responsibilities
### 6.1 Service Delivery
Arcline will provide Services in accordance with this Agreement and the SLA.
### 6.2 Security
Arcline will maintain industry-standard physical and network security measures,
including:
- Firewall protection with default-deny rules
- Regular security updates and patching
- Encrypted data transmission (TLS 1.2+)
- Secure configuration of all servers and network equipment
### 6.3 Privacy
Arcline will not access Customer's files or data except:
- To perform maintenance or troubleshooting
- To investigate suspected AUP violations
- To comply with valid legal process
### 6.4 Incident Notification
Arcline will notify Customer of any security incident involving Customer's
data within 72 hours of becoming aware of the incident.
---
## 7. Intellectual Property
### 7.1 Customer Content
As between the parties, Customer retains all intellectual property rights in
the content, data, and applications they store or process using Arcline's
Services.
### 7.2 Arcline IP
Arcline retains all rights in its proprietary software, infrastructure,
trademarks, and branding. This Agreement does not grant Customer any license
to Arcline's intellectual property beyond what is necessary to use the
Services.
### 7.3 Feedback
Any suggestions, feedback, or feature requests Customer provides may be used
by Arcline without obligation or compensation.
---
## 8. Confidentiality
### 8.1 Definition
"Confidential Information" means any non-public information disclosed by one
party to the other, whether written, oral, or electronic, that is designated
as confidential or reasonably should be understood to be confidential.
### 8.2 Obligations
Each party agrees to:
- Use Confidential Information only for purposes of this Agreement
- Protect Confidential Information using reasonable care
- Not disclose Confidential Information to third parties without written
consent, except to employees and contractors with a need to know
### 8.3 Exclusions
Confidential Information does not include information that:
- Is or becomes publicly available through no fault of the receiving party
- Was already known to the receiving party prior to disclosure
- Is independently developed by the receiving party
- Is required to be disclosed by law
---
## 9. Limitation of Liability
### 9.1 No Indirect Damages
Neither party shall be liable for any indirect, incidental, special,
consequential, or punitive damages, including lost profits, lost revenue,
lost data, or business interruption, even if advised of the possibility of
such damages.
### 9.2 Cap on Liability
Each party's total liability to the other for all claims arising under this
Agreement shall not exceed the total fees paid by Customer to Arcline in the
12 months preceding the claim.
### 9.3 Exceptions
Nothing in this section limits either party's liability for:
- Death or personal injury caused by negligence
- Fraud or willful misconduct
- Breach of confidentiality obligations
- Intellectual property infringement
---
## 10. Indemnification
### 10.1 Customer Indemnity
Customer agrees to indemnify and hold harmless Arcline from any claims,
damages, or expenses arising from:
- Customer's breach of this Agreement
- Customer's violation of applicable law
- Customer's content that infringes third-party rights
### 10.2 Procedure
The indemnified party must:
- Provide prompt written notice of the claim
- Allow the indemnifying party to control the defense
- Provide reasonable cooperation in the defense
---
## 11. Data Processing
### 11.1 Data Processor
To the extent Customer provides Arcline with personal data (as defined by
applicable privacy laws), Customer is the data controller and Arcline is the
data processor. Our [Data Processing Agreement (DPA)](dpa.md) governs such
processing and is incorporated by reference.
### 11.2 Data Location
Customer data is stored on servers located in the United States. Arcline does
not transfer data to other jurisdictions without Customer's consent.
---
## 12. Governing Law and Disputes
### 12.1 Governing Law
This Agreement shall be governed by and construed in accordance with the laws
of the United States and the State of Oklahoma.
### 12.2 Dispute Resolution
Any dispute arising from this Agreement shall first be attempted to be resolved
through good-faith negotiations. If not resolved within 30 days, disputes may
be submitted to binding arbitration in accordance with the rules of the
American Arbitration Association.
### 12.3 Legal Fees
In any action to enforce this Agreement, the prevailing party shall be
entitled to recover reasonable legal fees and costs.
---
## 13. General Provisions
### 13.1 Entire Agreement
This Agreement, together with the Order Form, [SLA](sla.md),
[AUP](https://arcline.it/aup), [Privacy Policy](https://arcline.it/privacy),
and [DPA](dpa.md), constitutes the entire agreement between the parties
regarding the subject matter.
### 13.2 Amendments
Arcline may amend this Agreement with 14 days written notice. Continued use
of Services after the effective date constitutes acceptance.
### 13.3 Assignment
Customer may not assign this Agreement without Arcline's written consent.
Arcline may assign this Agreement in connection with a merger, acquisition,
or sale of assets.
### 13.4 Severability
If any provision of this Agreement is found to be unenforceable, the
remaining provisions shall remain in full force and effect.
### 13.5 Waiver
Failure to enforce any provision of this Agreement shall not constitute a
waiver of that provision.
### 13.6 No Third-Party Beneficiaries
This Agreement is for the sole benefit of the parties and their permitted
assigns and does not confer any rights on third parties.
### 13.7 Notices
All legal notices under this Agreement shall be sent in writing to:
- **Arcline IT LLC** — by email to legal@arcline.it
- **Customer** — to the email address on file in the customer portal
---
## 14. Definitions
| Term | Definition |
|------|------------|
| **Order Form** | The service order, plan selection, or checkout process through which Customer selects specific Services |
| **Services** | Hosting and related services provided by Arcline under this Agreement |
| **SLA** | Service Level Agreement, available at [docs.arclineit.com/legal/sla] |
| **AUP** | Acceptable Use Policy, available at [arcline.it/aup](https://arcline.it/aup) |
| **DPA** | Data Processing Agreement, available at [docs.arclineit.com/legal/dpa] |
---
*To accept this Agreement, create an account or sign the applicable Order
Form. Questions? Contact us at [arcline.it/contact](https://arcline.it/contact)*

183
content/legal/sla.md Normal file
View File

@@ -0,0 +1,183 @@
# Service Level Agreement (SLA)
**Arcline IT LLC**
Last updated: May 2026
Applies to: All Arcline shared hosting, WordPress hosting, and VPS hosting services.
---
## 1. Overview
This Service Level Agreement ("SLA") governs the availability and performance
of services provided by Arcline IT LLC ("Arcline", "we", "us") to you ("Customer").
This SLA is incorporated by reference into the Arcline Terms of Service and
Master Service Agreement.
Arcline operates self-hosted infrastructure on owned hardware. We do not use
AWS, Azure, GCP, Cloudflare, or any hyperscale cloud provider. We are
transparent about what this means for availability, and we believe honesty
about our capabilities serves our customers better than inflated promises.
---
## 2. Uptime Commitment
| Service Tier | Monthly Uptime Target | Annual Uptime Target |
|-------------|----------------------|---------------------|
| Shared Hosting | 99.0% | 98.5% |
| WordPress Hosting | 99.0% | 98.5% |
| VPS Hosting | 99.5% | 99.0% |
| Network (edge) | 99.5% | 99.0% |
**Calculated as:**
```
Uptime % = (Total Minutes in Month Downtime Minutes) ÷ Total Minutes × 100
```
---
## 3. Service Credits
If we fail to meet the uptime target in a given calendar month, you may request
a service credit. Credits are applied to your next invoice and are not
redeemable for cash.
| Monthly Uptime | Credit |
|----------------|--------|
| Below target but ≥ 95% | 10% of monthly fee |
| 90% 94.99% | 25% of monthly fee |
| Below 90% | 50% of monthly fee |
### How to Request a Credit
1. Email **support@arcline.it** with subject line "SLA Credit Request"
2. Include your account email and the month in question
3. We will verify our monitoring data and respond within 5 business days
Credits must be requested within 30 days of the end of the month in which
the downtime occurred.
**Limitation:** Total credits in any single month shall not exceed the
Customer's monthly service fee for the affected service.
---
## 4. Exclusions
The following are excluded from SLA calculations and are not eligible for
service credits:
### Scheduled Maintenance
- Announced maintenance windows with at least 48 hours notice
- Emergency security patches (notice as circumstances permit)
- We schedule maintenance during off-peak hours (midnight6 AM ET) when possible
### Customer-Caused Downtime
- Configuration errors by the Customer
- Exceeding resource limits (CPU, RAM, disk I/O, bandwidth)
- Failure to maintain payment on the account (past-due accounts)
- Actions taken by the Customer that trigger abuse prevention mechanisms
### Force Majeure
- Natural disasters, war, civil unrest, pandemic, or other events beyond
reasonable control
- Upstream network outages (BGP issues, transit provider failures) — we will
work to mitigate but do not guarantee alternate routing
- Power outages at our facility — we maintain UPS and generator backup but
do not guarantee 100% uptime
### Third-Party Services
- DNS propagation delays when changing nameservers
- SSL certificate issuance delays by Let's Encrypt or other CAs
- Email deliverability issues caused by receiver-side filtering
### VPS-Specific Exclusions
- Guest operating system crashes or misconfiguration
- Resource exhaustion caused by the Customer's workload
- Actions taken by the Customer's users
---
## 5. Monitoring
Arcline measures uptime using our internal monitoring system (`arcline-uptime`),
which performs checks from multiple locations at 1-minute intervals. Monitoring
results are available at [status.arclineit.com](https://status.arclineit.com).
We monitor:
- **HTTP services** — connection success, HTTP 200 status, response within 10s
- **TCP services** — successful TCP connection to service port
- **Network** — ping response from edge router
- **Infrastructure** — system load, disk usage, temperature sensors
In the event of a disagreement about uptime, Arcline's monitoring data shall
be the primary source. Customers are encouraged to run independent monitoring
and may submit their own monitoring data for consideration.
---
## 6. Maintenance Windows
### Routine Maintenance
- Typically performed TuesdayThursday between midnight and 6 AM ET
- Announced on [status.arclineit.com](https://status.arclineit.com) at least
48 hours in advance
- Brief service interruptions (< 15 minutes) for routine updates
### Emergency Maintenance
- Security vulnerabilities (CVSS 7.0): patched within 24 hours
- Critical hardware failures: immediate intervention
- Notice provided via status page and email as time permits
---
## 7. Incident Response
| Severity | Definition | Initial Response | Update Frequency |
|----------|-----------|-----------------|------------------|
| **Critical** | Service unavailable, all customers affected | 30 minutes | Every 60 minutes |
| **Major** | Service degraded or partially unavailable | 1 hour | Every 2 hours |
| **Minor** | Isolated issue affecting few customers | 2 hours | Every 4 hours |
| **Maintenance** | Planned work with brief interruption | Per schedule | Per schedule |
Response times are measured from the time Arcline becomes aware of the issue
(automated alert or customer report), not from the start of the incident.
---
## 8. Support Response Times
| Priority | Channel | Target Response |
|----------|---------|-----------------|
| Emergency (service down) | Ticket + email | 30 minutes (business hours) |
| High (degraded service) | Ticket | 2 hours (business hours) |
| Normal (general inquiry) | Ticket | 24 hours |
| Low (feature request) | Ticket | 48 hours |
**Business hours:** MondayFriday, 9 AM6 PM ET.
**After hours:** Best-effort for Critical and Major incidents only.
---
## 9. Data Preservation
In the event of account suspension or termination:
- **Shared/WordPress hosting:** Data preserved for 14 days after suspension
- **VPS hosting:** Data preserved for 7 days after suspension
- **Final deletion:** Data is securely erased after the preservation period
We do not provide data recovery for accounts that have been deleted for more
than 30 days.
---
## 10. SLA Exceptions and Changes
Arcline reserves the right to modify this SLA with 30 days written notice to
active customers. Material changes will be emailed and posted to our status
page.
---
*Questions about this SLA? Contact us at [arcline.it/contact](https://arcline.it/contact)*