8am to 6pm Monday to Friday (Sydney timezone)
After Hours - for high priority issues
8am to 6pm Monday to Friday (Sydney timezone)
After Hours - for high priority issues
Australian Hosting Specialists

AWS Support Agreement - Service Level Statement
This Service Level Statement sets out details relating to the delivery of Habitat3's AWS Support Service.
a) General Service Details
Habitat3;
-
Provides the following services to maintain and support your AWS environment;
- Monitor for malicious activity using AWS CloudTrail and AWS GuardDuty
- Schedule and complete regular server operating level patch updates
- Monitor backups using AWS CloudWatch to identify any failures
- Monitor daily AWS Budgets to identify any overspend beyond set levels
- Monitor outgoing data using AWS Budgets and AWS CloudWatch
- VPC flow logs are collected to allow for post incident analysis
- IAM User Management – add, remove, delete accounts using AWS IAM best practices for security and maintenance
- Manage DNS and provide SSL certificates as required (clients to implement SSL within their webserver).
- Maintain AWS Security groups and VPC as required
- Provide general advice and guidance on future plans and optimisation (up to 2 hours per month). Additional consulting services are charged at $165 per hour.
- Provide the support package for the quoted fees on a per AWS account basis
- Require that each client have an AWS Developer Support plan (as a minimum) in place with AWS at all times. Learn more at: https://aws.amazon.com/premiumsupport/plans/
- Requires delegated access to the AWS Billing Console to allow for budget alert management.
- Provides support between 8am and 6pm (Sydney time) Monday to Friday excluding national public holidays.
-
Provides support if an AWS service is causing a web-server to be inaccessible- 24 hours a day, 7 days a week (after hours) - the appropriate Helpdesk ticket must be submitted via the Habitat3 Support Centre website. https://www.habitat3.net.au/support
-
Send an email to clients' at least 24 hours prior to any system maintenance causing downtime notifying when the maintenance will commence and cease.
-
Respond to client requests within 4 business hours of logging the request via the Habitat3 website.
-
Provides comprehensive training on how clients’ are to request support.
-
Attend to support requests only when a support ticket has been submitted via the Habitat3 support page.
-
Completes training with you to ensure that you are sufficiently briefed in how to use the Habitat3 support service.
-
Hold the appropriate levels of Insurance
-
Provide your AWS account root access details at commencement of the support agreement.
-
Provide a quote to reconfigure your web-servers (Habitat3 App Modernisation Service) to allow for auto-scaling/load balancing if AutoScaling Management is required.
-
Up to 2 hours of reactive support is provided as part of the AWS Support Package per month.
-
Additional support hours in a calendar month are provided at a fee of $165 inc GST per hour.
17. Standard EC2 system based alerts:
-
CPU above 90% for 5 minutes (can be customised)
-
Memory above 90 minutes for 5 minutes (requires installation of the cloudwatch agent, can be customised)
-
HDD above 90% usage (requires installation of the cloudwatch agent, can be customised)
-
Network bandwidth alerts (can be customised)
18. AWS Service Alerts
-
AWS GuardDuty alerts (uses threat intelligence feeds, such as lists of malicious IP addresses and domains, and machine learning to identify unexpected, potentially unauthorized, and malicious activity within your AWS environment, alerts when there is a potential threat)
-
AWS Backup Failures
-
AWS System Patch notifications
-
AWS Config (Alerts on non-compliance like user without MFA, EBS Disk not encrypted etc)
19. AWS Budget Alerts
-
Daily budget alert when 80% budget is reached
-
Daily budget alert when 100% budget is reached
b) Habitat3's secure support web-portal website
-
Account Holders are provided with access to a secure, support web-portal to make requests relating to security (eg. updating a password) and billing (eg. adding a user account)
-
Account Holders can nominate an Authorised Representative (AR) to act on their behalf. This is done via the support web-portal or on the initial service activation web-form. An Authorised Representative can only be nominated on the service activation form if the Account Holder is completing the form. Authorised Representatives can be nominated by the Account Holder at a later date.
-
Authorised Representatives can access the support web-portal and therefore can make all billing and security requests.
-
Exceptions are that Authorised Representatives cannot;
-
cancel a subscription/service
-
nominate another Authorised Representative
-
remove an Account Holder
-
change the password of the Account Holder on the VPS
-
-
The requests above must be made by the Account Holder not an Authorised Representative.
-
Account Holders must provide an email address, the first and last name and the mobile phone number of the nominated Authorised Representative/s.
-
Authorised Representatives must be employed by the Habitat3 client they are representing and therefore have the same email domain name as the Account Holder (eg. employee@companyname.com.au).
-
Habitat3 does not record the password set by Account Holders for the support web-portal.
-
The support web-portal and all associated support ticket information (including Habitat3 client personal details are hosted by FreshWorks - privacy policy located at: https://www.freshworks.com/security/
-
It is the client's responsibility to advise Habitat3 that an Authorised Representative has left the client's employment and should be disabled. This is done via a ticket in the Habitat3 web portal.
-
If Habitat3 determines an Authorised Representative has left the client's employment we will automatically revoke that Authorised Representative's web portal account and they will no longer be able to make requests.
d) Habitat3 Server & Data Security
AWS DataCentres
-
Habitat3 uses AWS DataCentres located in Australia unless otherwise specified by you.
Data Ownership and Control
-
The account is controlled by the Account Holder nominated in the Habitat3 AWS Support Agreement.
Habitat3 access
-
Habitat3 staff may have the ability to access data stored within a client's webserver on AWS EBS storage.
-
Habitat3 completes rigorous background checks on all Habitat3 staff including an Australian National Police Check and all staff are required to sign a confidentiality agreement.
Passwords
-
It is the client's responsibility to select strong passwords for all AWS and Habitat3 related services.
Data Breach
-
Habitat3 will always notify you via email as soon as possible if a data security breach affecting your data is identified.
-
The Office of the Australian Information Commissioner’s Guide to securing personal information: ‘Reasonable steps’ to protect personal information discusses security considerations that may be relevant under APP 11 when outsourcing your server hosting requirements.
-
If any illegal activities (eg. copyright infringement) are conducted by any Habitat3 clients within any Habitat3 hosting services then Habitat3 holds the Habitat3 client responsible and liable to all relevant authorities.
-
Habitat3 expects clients to only connect to the Habitat3 Virtual Private Server from PCs that are protected by business grade AntiVirus software.
e) Data Protection Laws
-
Habitat3 is an Australian company with Australian shareholders focused on providing Australian based companies only with Australian-based technology services.
-
Habitat3 does not consider itself an APP Entity based on the criteria set by the Office of the Australian Information Commissioner.
-
Habitat3 does not warrant compliance with Data Protection Laws designed to protect those located in jurisdictions outside Australia including Europe.
-
Habitat3 does not have a Data Processing Addendum in place with the providers of its Australian (Sydney) located DataCentre/infrastructure providers.
-
Habitat3 clients as personal information controllers must not store the personal information of individuals located in the EU on Habitat3’s Hosted Virtual Private Servers (personal information processor) as Habitat3 does not warrant compliance with the GDPR.
-
If you store data owned by the Australian Federal Government you should review your use of Habitat3's services and its upstream AWS datacentre provider's iRAP certification at : https://aws.amazon.com/compliance/irap/
g) AWS Usage Agreement
-
You agree to allow Habitat3 to open an AWS Account on your behalf and you agree to the AWS Customer Agreement at - https://aws.amazon.com/agreement/
h) Microsoft Webservers
-
Webservers will have as standard a non-default RDP port open to allow administrative access.
-
Webservers will have port 80 open to allow http traffic.
-
Webservers are managed by clients and Habitat3 support is limited to AWS environment support only.
-
Webservers will be temporarily disconnected from the Internet if any DOS type attack is detected.
j) Service Change Requests
-
Any requests associated with changing your service that impacts your fee must be approved by the Account Holder or Authorised Representative of the Habitat3 Account.
-
The next monthly invoice will reflect the change for the full month.
k) Miscellaneous
-
Any data drives sent to Habitat3 by a Habitat3 Client for data uploading into the data centre must be clearly labelled with your business name. If this is not done we cannot guarantee the return of your drive (eg. flash or USB external hard drive). To allow for return of your drive please enclose an Express Post envelope fully addressed to the location you wish to have it sent.
-
All AWS fees and charges are billed to you by AWS.
-
All Habitat3 fees and charges are billed to you by Habitat3.
Standard EC2 service based alerts
-
CPU above 90% for 5 minutes
-
Memory above 90 minutes for 5 minutes (requires installation of the CloudWatch Agent on client servers)
-
HDD above 90% usage (requires installation of the cloudwatch agent, can be customised)
-
Network traffic bandwidth alerts (can be customised)
AWS Service alerts:
-
AWS GuardDuty alerts (uses threat intelligence feeds, such as lists of malicious IP addresses and domains, and machine learning to identify unexpected, potentially unauthorized, and malicious activity within your AWS environment, alerts when there is a potential threat)
-
AWS Backup Failure alerts
-
AWS System Patch notifications
-
AWS Config (Alerts on non-compliance like user without MFA, EBS Disk not encrypted etc)
-
AWS outgoing data alerts
AWS Budget alerts:
-
Daily cost budget alert (80%)
-
Daily cost budget alerts (100%)
More details of Habitat3’s AWS Support Services are provided online at:
https://www.habitat3.net.au/aws-support-service-statement
The details are subject to change but Habitat3 will always communciate with you any significant changes and keep the details of the service updated online.