Regular Security Audits: Penetration testing, vulnerability assessments, and compliance audits.
Data Privacy & Compliance: Adherence to GDPR, HIPAA, or other industry-specific regulations.
Audit Trails & Monitoring: Tracking user activity and system access.
Data Backup & Disaster Recovery Plans: Regular backups and procedures to recover data in case of failure.
Updates
Release Cycles: Usually quarterly or bi-annual updates, but this can vary based on the vendor.
Patch Management: Frequent patches for security vulnerabilities or minor bug fixes, often rolled out as needed.
Major Version Updates: Scheduled less frequently, involving significant new features or architecture upgrades.
Update Delivery: Managed via automated deployment, with notifications or rollout plans provided to clients.
Testing & Rollout: Major updates are typically tested thoroughly before deployment, sometimes in a staging environment, before releasing to all users.
Data Ownership and Portability
Data Ownership: Usually, clients retain full ownership of their data stored within the platform. SaleboxAI will act as a data processor, with the client holding rights over the data.
Data Access & Control: Clients are generally granted access to their data, with rights to export or transfer it at any time.
Data Portability: Most vendors support data export features in standard formats (CSV, JSON, etc.) to enable migration or backup.
Data Deletion: Policies typically allow clients to request complete deletion of their data upon contract termination.
Scaling Up / Down
Flexible Plans: Subscription-based models offering tiered plans or usage-based billing.
Easy Scaling: Agreements that allow organizations to scale resources, features, or user seats up or down with minimal notice.
Pro-rated Billing: Adjustments to billing based on usage changes within billing cycles.
Contract Terms for Scaling: Often included in service level agreements (SLAs), with specific procedures outlined for adding or reducing capacity, possibly subject to review or approval.
The terms & conditions for contract renewal and cancellation
Renewal Cycles: Usually annual or multi-year terms, automatically renewing unless explicitly canceled prior to renewal date.
Notice Period: Often 30-90 days’ notice required for cancellation before renewal.
Early Termination: May involve penalties or fees, depending on contract terms.
Data Access Post-Cancellation: Policies typically specify whether users can retrieve their data after cancellation or if data will be deleted.
Renewal Options: Possibility to renegotiate terms, upgrade/downgrade plans, or extend contracts at renewal.
Compliance
GDPR (General Data Protection Regulation) – for handling data of EU citizens.
HIPAA (Health Insurance Portability and Accountability Act) – if dealing with healthcare data.
ISO/IEC 27001 – International information security standards.
SOC 2 – Service organization control reports detailing security, availability, processing integrity, confidentiality, and privacy.
CCPA (California Consumer Privacy Act) – for handling California residents' data.
Other Industry-Specific Standards: Such as PCI DSS for payment data, depending on the industry.