Version 1 Effective date: 23 December 2025 Version history

This annex is part of the Agreement defined by the General Terms and Conditions of Service (article 7). It applies to every Managed Service, unless the Order Form provides for a different allocation.

Article 1 Allocation

The following table shows, area by area, which party is in charge.
Area Bunker Customer
Datacenters, network, servers and storage Operation, redundancy and physical security Not involved
System, Kubernetes and platform Installation, updates and hardening Not involved
Software version and patches Deployment of the vendor's corrective releases (Terms, article 9) Report its compatibility constraints
Instance backups Backup of the instance database, kept for 30 days, and restoration Additional export of its data where its own obligations require it
Secrets stored by the instance Encryption of the secrets the instance keeps (source connection credentials, keys) Choice and rotation of the credentials it provides
Monitoring Monitoring of availability and resources Not involved
User accounts and rights Account management tools Creation, rights, review and deletion of its users' accounts
Access options Offering single sign-on, multi-factor authentication, an IP allow-list or private access, where the software allows it Activation of the options offered
Connected data sources Technical connection Choice of sources, dedicated connection accounts, read-only and limited to what is necessary
Security of sources outside Bunker Not involved Security, backup and logging of its source databases and applications
Data content Not involved Lawfulness, retention periods, information of data subjects
Sensitive data Advice on suitable measures Prior written notice before connecting sensitive data, password hashes or payment data
Security incident Protective measures (Terms, article 10) and notification (DPA, article 11) Rotation of the credentials it controls, notifications to the authority and to data subjects

Article 2 Customer commitments

The commitments of article 7.2 of the Terms apply: dedicated and limited connection accounts, change of credentials on request or after an incident, activation of the access options offered, prior notice before connecting sensitive data.