Always-On Protection (AOP) Service Election
Review the Master Agreement and service levels below, then complete the Service Election to enroll.
AOP Master Agreement — v0.2
Please review the complete agreement before accepting below.
Always-On Protection Master Agreement
This Always-On Protection Master Agreement (“Agreement”) is between Quantum Loop Solutions, Inc. DBA WineryConnect (“WineryConnect,” “Provider,” “we,” or “us”) and the client identified in an accepted Service Election (“Client,” “you,” or “your”). The Agreement begins on the Effective Date shown in the Service Election.
1. What AOP Is
Always-On Protection (“AOP”) is WineryConnect’s managed IT stewardship service for winery and hospitality environments. Its purpose is to help keep the Client’s technology reliable, supportable, secure, recoverable, and able to support revenue-producing operations. AOP combines automated monitoring and management with human support and stewardship by WineryConnect’s Grape Squad.
AOP is an ongoing management relationship, not a guarantee that technology will never fail. WineryConnect’s job is to watch, advise, coordinate, respond, and continuously improve the managed environment within the agreed scope.
2. One Agreement; Service Level Chosen Separately
The Client’s selected AOP level, locations, current inclusions, fees, and any special terms are stated in the Service Election and the referenced AOP Service Matrix. Current standard pricing is Guard $59, Shield $119, and Fortress $179 per user per month, plus $39 per additional managed device per month. The accepted Service Election controls the Client’s actual pricing.
CCF is a Fortress-level systems-integration capability, not a separate AOP tier. CCF requires a minimum of three Fortress seats. For an eligible Client, CCF carries no separate platform subscription fee. CCF-enabled Data Stewardship includes up to two hours per Client account per month unless the Service Election states otherwise; unused included time expires monthly. Additional Data Stewardship is billable at the Client’s Fortress-discounted service rate.
WineryConnect may evolve the names, packaging, tools, and standard service descriptions used within AOP. We will not materially reduce the Client’s purchased service during a paid service period without notice and agreement.
3. What WineryConnect Owns
WineryConnect is responsible for:
· operating the monitoring, management, security, backup-monitoring, documentation, and support functions included in the Client’s selected AOP level;
· receiving and triaging Client technology issues and determining a reasonable next action;
· taking reasonable ownership of the support chain rather than simply redirecting the Client: when another vendor, carrier, software provider, or hardware provider appears to be responsible, WineryConnect may coordinate with that party on the Client’s behalf within the agreed scope;
· making commercially reasonable recommendations to improve reliability, security, lifecycle condition, recoverability, and revenue continuity; and
· communicating material incidents or conditions that WineryConnect identifies and that reasonably require Client action.
4. Revenue-Critical Systems and Continuity
Winery and hospitality technology often supports point-of-sale, payments, reservations, tasting-room operations, events, guest connectivity, production, and other time-sensitive functions. WineryConnect will use commercially reasonable efforts to prioritize incidents that prevent or materially impair the Client’s ability to transact or operate.
Where practical, WineryConnect may recommend or implement resilience measures such as documented offline procedures, backup connectivity, redundant power, spare equipment, segmented networks, or recovery procedures. Such measures are included only when expressly stated in the Service Election, Service Matrix, or an approved project.
5. Included Services vs. Billable Work
The AOP subscription pays for the recurring managed service associated with the selected tier — including the applicable software subscriptions, monitoring, human system health checks, routine management, service coordination, ordinary remote support, reporting/advisory work, and other services identified in the applicable Service Matrix. Fortress + CCF also includes the stated monthly Data Stewardship time. AOP is not an unlimited on-site, project, remediation, recovery, or Data Stewardship labor agreement.
Work that may be billed separately includes, without limitation:
· on-site labor, billed at the selected tier’s discounted service rate, plus mileage at $0.70 per mile;
· project work, installations, migrations, redesigns, major upgrades, and new deployments;
· remediation or repair of pre-existing conditions, unsupported systems, or conditions outside the managed baseline;
· significant incident-response, recovery, reconstruction, or forensic work beyond routine triage and coordination;
· work caused by Client-requested changes, actions by Client personnel, or actions/failures of third parties outside WineryConnect’s control;
· work on systems, locations, devices, accounts, or vendors outside the defined AOP scope; and
· for CCF clients, Data Stewardship beyond the included monthly amount.
Before undertaking material out-of-scope work, WineryConnect will seek authorization when reasonably practical. In an urgent event where delay is likely to increase business interruption, loss, or risk, WineryConnect may take reasonable stabilizing actions and promptly communicate what was done.
6. Service Requests and Response
AOP response targets are targets for acknowledgement and beginning triage, not guaranteed resolution times. The standard published targets are Guard: next business day; Shield: same day; Fortress: two hours. Actual resolution depends on the nature of the issue, Client access and decisions, third-party vendors, replacement equipment, connectivity, and other circumstances.
A “Critical / P1” incident generally means a material outage or security event affecting multiple users, a site, or a revenue-critical function with no reasonable workaround. WineryConnect may reclassify a ticket after triage based on actual impact.
7. Shared Responsibility
AOP works best when responsibilities are explicit. WineryConnect is responsible for the services it has agreed to perform. The Client remains responsible for its business decisions, users, data ownership, legal/regulatory obligations, and systems or vendors not placed within WineryConnect’s managed scope.
The Client agrees to:
· maintain properly licensed and reasonably supportable hardware and software;
· provide timely administrative, physical, vendor, and facility access needed to perform the service;
· identify authorized contacts and promptly report suspected security incidents, outages, employee departures, or material technology changes;
· not disable, remove, bypass, or materially interfere with agreed monitoring, management, backup, security, documentation, or CCF integration tools;
· use reasonable security practices and consider WineryConnect recommendations, including MFA, supported software, secure credentials, and appropriate access controls; and
· make final business decisions where WineryConnect presents alternatives, cost/risk tradeoffs, or recommendations.
8. Cybersecurity and Security Incidents
WineryConnect will use commercially reasonable administrative, technical, and operational safeguards appropriate to the AOP services being provided and will continuously work to improve its security practices. No provider can guarantee that a system will be immune from compromise, malware, credential theft, social engineering, insider action, vendor compromise, zero-day vulnerability, or other security event.
If WineryConnect becomes aware of a material security incident affecting systems or data within the managed scope, we will notify the Client within a commercially reasonable period after confirming the incident and will coordinate reasonable containment and recovery actions within the AOP scope. Legal notification duties, regulatory reporting, counsel, cyber-insurance notifications, and formal forensic services remain the Client’s responsibility unless separately engaged.
The parties will reasonably cooperate in determining what occurred. Responsibility for an incident should follow the actual cause and each party’s contractual duties rather than the mere fact that WineryConnect provides managed services.
9. Actions of Employees, Users, and Third Parties
Each party is responsible for the acts and omissions of its personnel within the scope of their employment or engagement. WineryConnect is not responsible for losses caused by Client personnel, former personnel, contractors, guests, or other persons who obtain or misuse Client access, except to the extent caused by WineryConnect’s breach of an express obligation under this Agreement.
WineryConnect relies on third-party products and services such as internet carriers, cloud platforms, security products, backup platforms, point-of-sale systems, payment processors, device manufacturers, and software vendors. Their products and services are outside WineryConnect’s direct control. WineryConnect will use reasonable efforts to manage and coordinate those dependencies where they are in scope, but is not a guarantor of third-party performance.
10. Backups, Recovery, and Business Continuity
Where backup is included in the selected tier, WineryConnect will steward the backup systems and services that have been identified and placed within the Client’s managed backup scope, including monitoring configured backup jobs and responding to alerts as described in the Service Matrix.
“Verified backups” does not mean unlimited backup capacity or a guarantee that every system, account, device, or byte of Client data is backed up.
Backup can include a range of services up to and including full enterprise backup architecture and, depending on scope and size, may cost extra. Storage, software or cloud licenses, appliances, capacity, implementation, restore testing, disaster-recovery architecture, offline or immutable copies, alternate-site recovery, and full continuity plans may require additional services or charges. Any specific recovery-time or recovery-point commitment must be stated in writing.
11. Changes, Recommendations, and Risk Acceptance
WineryConnect may identify a condition that materially increases operational or security risk. We will explain the condition and a reasonable recommended action. If the Client elects not to implement a material recommendation, WineryConnect may document the Client’s risk acceptance, limit responsibility for consequences attributable to that condition, or, where the risk makes responsible service impracticable, decline to manage the affected system.
12. Acceptable Managed Environment
WineryConnect may decline, limit, or separately price support for unsupported or end-of-life systems, systems for which necessary access is unavailable, environments that prevent deployment of required management/security controls, or conditions that present an unreasonable risk to the Client, WineryConnect, other clients, or third parties.
13. Fees, Billing, and Scope Changes
Recurring fees are billed as stated in the Service Election. Standard AOP pricing is per seat, with a seat primarily representing one named person and one managed endpoint. Additional managed devices are billed at the then-current published device rate; at the date of this Agreement, that rate is $39/device/month. POS stations and printers are not counted as additional managed devices.
The Client authorizes WineryConnect to adjust recurring charges when the managed environment materially changes, subject to reasonable notice and an updated Service Election or other written/electronic acceptance where appropriate.
Billable service labor is charged from WineryConnect’s standard rate, currently $99/hour, less the selected AOP tier discount: Guard 10%, Shield 20%, Fortress 30%. The same Fortress-discounted rate applies to Data Stewardship beyond the included CCF amount. On-site mileage is currently $0.70/mile. Published rates may change prospectively; the Service Election records the rates applicable at acceptance.
14. Term, Review, and Termination
Unless the Service Election states otherwise, AOP is month-to-month after activation. Either party may terminate on 30 days’ written notice. WineryConnect may suspend service for material non-payment or material interference with required management/security controls after reasonable notice when circumstances permit.
Because managed environments evolve, the parties may periodically review the selected service level, covered environment, fees, risks, and recommendations. A change in service level or commercial scope may be accepted through a new or amended Service Election without replacing this Master Agreement.
15. Onboarding and Offboarding
Onboarding may include discovery, documentation, deployment of tools, inventory, configuration baselining, credential/access setup, connection of authorized data sources, and identification of material gaps. AOP begins stewardship of the agreed managed environment; it does not make material pre-existing deficiencies free to remediate. Significant work needed to bring an inherited environment to an appropriate support, security, backup, reliability, or data-quality baseline may be separately scoped and billed.
Upon termination and payment of outstanding amounts, WineryConnect will reasonably cooperate in removing WineryConnect-managed agents and transferring Client-owned documentation, credentials, configuration information, and Client Data that WineryConnect is permitted to transfer. Significant migration, cleanup, export, transformation, or transition labor may be billable.
16. Confidentiality, Client Data, and CCF
16.1 Confidential Information
Each party will use reasonable care to protect the other party’s non-public business information and will use it only as needed to perform or receive the services, administer the relationship, comply with law, or protect legitimate rights.
16.2 Client Ownership of Data
As between the Client and WineryConnect, Client Data remains the Client’s data. Enrollment in AOP or CCF does not transfer ownership of the Client’s business, customer, transaction, financial, operational, or other source data to WineryConnect.
“Client Data” means information belonging to or supplied on behalf of the Client that WineryConnect accesses, receives, copies, synchronizes, stores, transforms, reconciles, or otherwise processes in providing the services.
16.3 CCF Stores Client Commerce Data
For Clients enrolled in CCF, the Client expressly authorizes WineryConnect to connect to approved Client systems and to retrieve, copy, synchronize, store, normalize, reconcile, link, transform, and otherwise process Client Data within CCF as reasonably necessary to provide the subscribed CCF and Data Stewardship services.
Depending upon the systems connected by the Client, this may include substantial portions of the Client’s commerce and operating history, including information concerning products, customers, customer contact information, orders, order lines, discounts, taxes, tenders and payment-related records, refunds, gift cards, memberships or clubs, fulfillment, inventory, accounting-related records, system identifiers, and other operational information made available through connected systems.
The purpose of maintaining this data in CCF is to create and steward useful, durable information across the Client’s connected systems and to provide the integrations, reconciliation, reporting, evidence, data-quality, operational, and other CCF services for which the Client has enrolled.
16.4 Authorization and Lawful Access
The Client represents that it has the authority to permit WineryConnect to access and process the Client Data and connected systems made available to WineryConnect.
The Client remains responsible for its own obligations regarding notices, consents, privacy policies, data collection, retention requirements, and other legal or contractual obligations applicable to information the Client collects from its customers, employees, vendors, or other persons.
WineryConnect will process Client Data in accordance with this Agreement and the Client’s authorized use of the services.
16.5 Limited Use of Client Data
WineryConnect will use Client Data only as reasonably necessary to:
· provide, support, secure, maintain, troubleshoot, and administer the AOP, CCF, Data Stewardship, and other services the Client has subscribed to;
· perform actions requested or authorized by the Client;
· maintain backups, records, audit trails, reconciliation evidence, and other operational records reasonably required to provide those services;
· investigate or respond to security, reliability, data-quality, or support issues affecting the Client;
· comply with applicable law or a legally binding governmental or judicial requirement; or
· protect the Client, WineryConnect, or others against fraud, abuse, security threats, or unlawful activity where reasonably necessary.
WineryConnect will not sell Client Data.
WineryConnect will not use Client Data for advertising, unrelated marketing, creation of commercial data products, benchmarking products, generalized analytics for the benefit of other clients, or other purposes unrelated to delivering the Client’s subscribed services.
16.6 Aggregated Data, Artificial Intelligence, and Future Uses
The parties recognize that aggregated or de-identified Client information could potentially be useful in the future for purposes such as industry benchmarking, generalized analytics, product development, research, or the training or improvement of artificial-intelligence or machine-learning systems.
The Client does not grant WineryConnect permission for those uses under this Agreement.
WineryConnect will not use Client Data, including Client Data that has been aggregated, anonymized, de-identified, or otherwise transformed, for such secondary purposes unless WineryConnect first obtains the Client’s express written or electronically recorded authorization describing the proposed use.
Similarly, WineryConnect will not use Client Data to train or improve a general-purpose or cross-client artificial-intelligence or machine-learning model without the Client’s express written or electronically recorded authorization.
Use of software incorporating artificial intelligence solely as a tool to perform an authorized service for the Client does not by itself constitute permission to use Client Data to train the provider’s or WineryConnect’s models. Any third-party AI processing of Client Data remains subject to the other confidentiality, security, and service-provider provisions of this Agreement.
16.7 Service Providers and Subprocessors
WineryConnect may use cloud hosting providers, infrastructure providers, security vendors, software platforms, integration providers, and other vetted service providers to process or store Client Data where reasonably necessary to provide the services.
WineryConnect will require such providers to handle Client information subject to applicable contractual, confidentiality, security, and data-use restrictions appropriate to the services they perform.
Use of such a provider does not expand WineryConnect’s rights to use Client Data beyond the purposes permitted by this Agreement.
16.8 Security and Separation
WineryConnect will use commercially reasonable administrative, technical, and operational safeguards appropriate to the nature of the Client Data and services being provided.
WineryConnect will use reasonable measures to logically separate Client environments, credentials, and Client Data from those of other clients and to restrict access to personnel and service providers who reasonably require such access to perform authorized functions.
The Client authorizes WineryConnect to access managed systems, connected systems, credentials, APIs, and information to the extent reasonably necessary to perform the services.
16.9 Payment Card and Authentication Data
CCF may receive transaction and tender information made available by connected commerce systems, but CCF is not intended to function as a repository for full payment-card numbers, card verification values, or other sensitive authentication data prohibited from general storage under applicable payment-card requirements.
WineryConnect may store integration credentials, tokens, keys, or similar secrets where reasonably necessary to operate authorized connections and will apply safeguards appropriate to their sensitivity.
16.10 Data Accuracy and Source Systems
CCF depends upon information supplied by Client systems and third-party systems. WineryConnect does not warrant that source information supplied by another system is complete, accurate, timely, or internally consistent.
CCF may preserve source information, normalize it, identify conflicts, associate records across systems, and create stewarded or derived records as part of the subscribed service. Unless otherwise expressly agreed, CCF does not make WineryConnect the system of record for the Client’s legal, accounting, tax, payment-processing, or regulatory obligations.
Client decisions made using CCF remain Client business decisions.
16.11 Data Retention, Export, and Termination
During the Client’s CCF subscription, WineryConnect may retain Client Data and historical versions of that data where reasonably useful to provide integrations, reconciliation, auditability, stewardship, reporting, recovery, or other subscribed CCF functions.
Following termination of CCF, WineryConnect will reasonably cooperate with the Client in making Client Data available for export in a commercially reasonable form when technically practicable. Significant export, transformation, migration, or transition services may be billable.
After an appropriate transition period, WineryConnect may delete Client Data that is no longer reasonably required to provide services, subject to normal backup-retention cycles, legal obligations, security requirements, dispute preservation, financial records, and WineryConnect’s right to retain evidence of the parties’ agreements, instructions, transactions, stewardship actions, and service history.
Any Client Data retained following termination remains subject to the confidentiality and use restrictions of this Agreement.
16.12 Required Disclosure
If WineryConnect is legally compelled to disclose Client Data, WineryConnect may make the required disclosure. Where legally permitted and reasonably practical, WineryConnect will notify the Client before doing so so that the Client may seek appropriate protection or otherwise respond.
17. No Warranty of Perfect Availability or Security
Technology and security involve inherent risk. Except for obligations expressly stated in this Agreement, AOP and CCF are provided on a commercially reasonable-efforts basis. WineryConnect does not warrant uninterrupted or error-free operation, prevention of all attacks or failures, compatibility of all third-party systems, perfect synchronization or accuracy of third-party data, or recovery from every loss scenario.
18. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY WILL BE LIABLE TO THE OTHER FOR INDIRECT, SPECIAL, INCIDENTAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS OR LOST BUSINESS, ARISING FROM THIS AGREEMENT, EVEN IF ADVISED THAT SUCH DAMAGES ARE POSSIBLE.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WINERYCONNECT’S AGGREGATE LIABILITY ARISING OUT OF AOP OR CCF SERVICES WILL NOT EXCEED THE AOP FEES PAID BY CLIENT DURING THE THREE (3) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM, EXCEPT TO THE EXTENT A DIFFERENT LIMIT IS REQUIRED BY LAW OR EXPRESSLY AGREED IN WRITING.
This limitation should be reviewed by WineryConnect’s counsel and insurers before release.
19. Insurance, Legal, and Regulatory Matters
Each party is responsible for maintaining insurance appropriate to its business. WineryConnect does not provide legal, regulatory, tax, accounting, or insurance advice to the Client.
Where an event may trigger legal, regulatory, contractual, tax, accounting, or cyber-insurance obligations, WineryConnect may recommend that the Client promptly contact counsel, its accountant, its insurer, or other qualified advisors.
20. General Terms
· This Agreement, together with the accepted Service Election and incorporated Service Matrix/proposal, is the parties’ agreement for AOP and supersedes prior AOP understandings on the same subject.
· Amendments must be in writing or accepted through an authorized electronic workflow that records the terms accepted.
· Neither party may assign this Agreement in a manner that materially impairs the other party’s rights without reasonable notice, except in connection with a merger, reorganization, or sale of substantially all relevant assets.
· If part of this Agreement is unenforceable, the remainder remains effective.
· Notices may be delivered electronically to the designated business contacts unless law requires another method.
· Governing law and venue: [NEW YORK — TO BE CONFIRMED BY COUNSEL].
21. Electronic Acceptance
The Client may accept this Agreement by physical signature, electronic signature, clicking an acceptance control in CCF or another WineryConnect enrollment system, or otherwise ordering or activating AOP after being presented with these terms.
The person accepting represents that they have authority to bind the Client.
WineryConnect will retain a durable record of the accepted Agreement version, Service Election, material commercial terms, acknowledgements, identity of the accepting person, and acceptance date and time.
Service levels & commercial terms
Review the complete commercial terms for every available service level before selecting one below. The Standard Billing Rate, discount, and effective billing rate below are contractual/billable-labor terms and are not part of your recurring monthly subscription charge.
AOP Guard
- Per-seat monthly rate
- $59.00/mo
- Standard billing rate
- $99.00/hr
- Billing discount
- 10.00%
- Effective billing rate
- $89.10/hr
- Travel / mileage
- Billable at standard mileage/travel rate
- Onboarding
- Separate Quote
- Inclusions
- Datto RMM monitoring, device inventory, basic patch management.
- Exclusions
- Project work, significant incident response, on-site work.
AOP Shield
- Per-seat monthly rate
- $119.00/mo
- Standard billing rate
- $99.00/hr
- Billing discount
- 20.00%
- Effective billing rate
- $79.20/hr
- Travel / mileage
- Billable at standard mileage/travel rate
- Onboarding
- Separate Quote
- Inclusions
- Guard, plus Datto EDR, BullPhish ID, Dark Web ID, Inky.
- Exclusions
- Project work, significant incident response, on-site work.
AOP Fortress
- Per-seat monthly rate
- $179.00/mo
- Standard billing rate
- $99.00/hr
- Billing discount
- 30.00%
- Effective billing rate
- $69.30/hr
- Travel / mileage
- Billable at standard mileage/travel rate
- Onboarding
- Included
- Inclusions
- Shield, plus security baseline enforcement, automation-driven remediation, patch lifecycle governance, endpoint compliance.
- Exclusions
- Significant incident response and on-site work beyond scope.
Additional Managed Device monthly rate: $39.00/mo per device.