Services Terms

The standard terms that apply to every TrueTech Group client engagement under a signed Order.

Effective August 1, 2026 · Version 2026-08

These Services Terms (the "Terms") are between TrueTech Group LLC, an Oregon limited liability company ("TrueTech," "we," "us"), and the business client identified in a signed Order ("Client," "you"). They apply to managed IT, support, professional services, software, hosted services, custom development, and the resale of hardware and licensing that we provide under an Order. An Order is a short signed document that names the services, quantities, fees, and term, and states that these Terms apply. The Order and these Terms together are the complete agreement for that engagement.

How these Terms bind

Read these Terms before signing an Order. The Order you sign identifies the version of these Terms in effect on its date, and that version governs the Order for its full term. If anything in an Order conflicts with these Terms, the Order controls for that engagement. We keep every prior version available from our legal index.

1. How these Terms work

Orders. Each engagement is authorized by a signed Order. No proposal, estimate, quote, email, ticket, purchase order, invoice, or course of dealing creates an Order unless it is signed by authorized representatives of both parties and states that these Terms apply. An Order may cover recurring services, a fixed project, a software subscription, or a purchase.

Precedence. If documents conflict, the Order controls for the engagement it covers, then these Terms. Terms printed on a purchase order, vendor portal, or invoice are administrative only and do not change the agreement.

Versions and changes. The version in effect on the date an Order is signed governs that Order for its term, including any renewal the Order provides for. We may publish a new version for future Orders. We will not apply a new version to an Order already in force unless we give you at least 30 days' written notice and you either accept it in writing or continue past the effective date without terminating the affected Order, which you may do without penalty during that notice period.

Separate relationships. Unless an Order says otherwise, an Order for one service (for example, managed IT support) does not amend an Order for another (for example, a software subscription). Each Order stands on its own for term, fees, and termination.

2. Services we provide

An Order selects one or more of the following. Where an Order does not include a service, nothing in these Terms obligates us to provide it.

Managed IT and end-user support

Managed endpoint security, monitoring, patching, and identity protection on a per-endpoint basis, and day-to-day helpdesk support for your employees on a per-user basis. The standard scope, hours, and included support are described in Section 3.

Professional services

Senior technical and IT strategy work billed hourly: identity and licensing administration, provisioning, escalations, security response, infrastructure and SaaS administration, automation, lifecycle planning, and documentation. An Order may set a monthly minimum and a monthly authorization ceiling.

Scoped projects

Defined work with a written scope, deliverables, assumptions, estimated effort or fixed price, dependencies, and decision points, approved in writing before implementation begins.

Software and hosted services

Access to software we build and operate, including TrueTech Suite and its add-ons, web applications we host, and integrations with your business systems, on a subscription or usage basis stated in the Order.

Custom development

Software, automation, integrations, and application extensions built specifically for you under an Order that states the deliverables, acceptance criteria, and ownership treatment.

Hardware and licensing resale

Procurement of hardware, software licenses, and subscriptions on your behalf, under the terms in Section 9.

3. Standard service practices

These practices apply to managed IT, support, and professional services unless the Order states different ones.

Hours and channels

Business hours are Monday through Friday, 8:00 a.m. to 5:00 p.m. Pacific Time. Requests may be submitted at any time by email to your dedicated support address, which creates a tracked ticket, or through the support portal. Phone is for critical issues: active security incidents and outages affecting multiple employees. Routine response occurs during business hours. We make reasonable efforts to accommodate employees in other time zones.

Prioritization and response

Requests are triaged by business impact. Critical issues are prioritized promptly, including outside business hours when we are reasonably available. Unless an Order states a specific response or resolution commitment, these Terms do not establish guaranteed response times or continuously staffed after-hours support. After-hours technician time is professional services.

Included end-user support

The per-user helpdesk fee covers ordinary end-user troubleshooting and service restoration: password resets and account unlocks for existing users; email, connectivity, VPN, printing, and peripheral troubleshooting; application troubleshooting for standard business tools; security questions and help reporting suspicious activity; workstation troubleshooting and remote assistance for managed devices; user-level configuration that does not require tenant, server, network, licensing, or vendor administration; ticket coordination and escalation; and basic guidance on the proper use of your standard technology.

Professional services

Work beyond ordinary end-user support is professional services billed at the hourly rate in the Order: account lifecycle and access provisioning, onboarding and offboarding; hardware procurement, builds, upgrades, and deployment; escalations involving servers, networks, firewalls, certificates, SaaS platforms, tenants, integrations, or vendors; security incident response, tenant hardening, and risk documentation; licensing analysis and vendor coordination; Microsoft 365, Google Workspace, identity, VPN, and service-account administration; automation, fleet policy, process standardization, and documentation; and infrastructure, backup, server, and network work. Where the Order sets a monthly minimum, that minimum is billed each month and reserves senior capacity for you. Unused minimum hours do not roll over. We will not exceed the Order's monthly authorization or begin a scoped project without your written approval.

Out of scope

The following are outside recurring managed-service and helpdesk fees: hardware, software, subscriptions, shipping, and other third-party purchases; third-party vendor, registrar, licensing, consulting, and service fees; data recovery, forensic investigation, or incident response beyond routine initial triage; legal, HR, employment, accounting, tax, regulatory, or compliance advice, which we do not provide and will refer to qualified professionals; and separately scoped initiatives. We will identify the applicable path in writing, whether a referral, a third-party quote, professional services, or a scoped project, and will not initiate an out-of-scope purchase or engagement without your written approval.

Tooling

Per-endpoint and per-user fees include the licensing, deployment, and management of the security, monitoring, remote management, and service-management platforms we use to deliver the services. The Order lists the current platforms. We select and manage tooling and may substitute functionally equivalent platforms, and we will notify you of any material platform change.

Counts and reconciliation

Endpoint counts include active workstations and production servers under management. User counts include active employees based on authentication in the prior 30 days, excluding service, system, and IT administrator accounts. Both reconcile each billing cycle from management-platform telemetry and directory data, and billing adjusts the following month.

Recommendations, not mandates

Our findings, assessments, and recommendations are professional opinions based on the information available at the time. You retain sole authority and responsibility for decisions about your environment, including whether to implement a recommendation. A decision not to implement a recommendation is not a basis for a claim against us. IT security is an evolving discipline; our services are designed to materially improve your security posture, but no measure can guarantee that every vulnerability will be found or that an incident will not occur.

4. Your responsibilities

Authorized representative. You will designate a representative with authority to approve expenditures, authorize access changes, and make binding decisions under the Order.

Access. You will provide and maintain the administrative, system, application, mailbox, database, network, and physical access reasonably necessary to design, deliver, secure, support, and verify the ordered services, and will promptly tell us about changes that affect that access. Access is granted for the active Order and its documented transition period, uses the least privilege compatible with effective delivery, and belongs to the Order rather than to any individual. If required access is withdrawn, we may pause only the affected service after reasonable notice.

Cooperation. You will timely provide the decisions, information, personnel, environments, licenses, and materials identified as your dependencies. Where we identify an immediate security risk requiring your action, you will make reasonable efforts to respond in the timeframe we communicate. Delay may affect delivery, risk, timing, or cost, and schedule relief will be proportionate to the actual impact.

Employee communication. You will tell your employees how to reach support. We will provide materials to help.

Your own compliance. You are responsible for the lawfulness and accuracy of your instructions and for having the rights necessary to give us access to the data and systems involved. You remain responsible for laws that apply solely to your business, content, employment decisions, or regulated activity unless an Order expressly assigns an obligation to us.

5. Fees and payment

You will pay the fees in the Order. Unless the Order states otherwise, fees exclude taxes, third-party fees, travel, and approved expenses, which we pass through at cost. Recurring services are invoiced monthly from actual counts and actual or minimum professional-services hours, whichever is greater, with hours itemized by date and description. Projects and purchases are invoiced as the Order states.

Invoices are due within 15 days of the invoice date. You will raise any good-faith dispute with reasonable detail within 15 days of receipt and pay the undisputed portion on time. Late amounts accrue a service charge of 1.5 percent per month or the maximum rate Oregon law allows, whichever is less. If an invoice remains unpaid more than 15 days past due, we may suspend services after written notice, and we are not liable for delay, security risk, or business impact arising from a suspension for non-payment.

You are responsible for transaction taxes on your purchases, excluding taxes on our income, payroll, or property. We keep records supporting usage and time-based charges for two years and will explain any charge on request.

6. Your data and our technology

You own your data. Client Data means the files, email, records, databases, credentials, configuration values, business rules, and other information you provide, that we collect from your systems, or that is generated for you through the services, including personal data within it. As between us, you retain all rights in Client Data and in the materials you supply. We acquire no ownership interest in Client Data by performing the services.

Limited license to process. You grant us and our approved providers a limited, non-exclusive right, for the term of the Order and its documented transition and backup periods, to host, copy, transmit, transform, and otherwise process Client Data solely to provide, secure, support, maintain, meter, and transition the services, to comply with law, and for any additional purpose the Order expressly states. We do not sell Client Data and do not use it for advertising.

We own our technology. TrueTech Technology means everything we own, license, or develop outside a client-specific assignment or that is of general applicability: platforms, source and object code, APIs, connectors, reusable modules, templates, models, algorithms, prompts, schemas, metadata structures, context frameworks, taxonomies, architectures, deployment tooling, methods, documentation frameworks, know-how, and improvements to any of them. We retain all right, title, and interest in TrueTech Technology and in the general methods used to produce results for you. No fee purchases our source code or transfers TrueTech Technology unless an Order expressly identifies the item and contains signed assignment language.

Derived data. Where the services classify, tag, summarize, index, embed, score, or otherwise derive artifacts from Client Data, the derived artifact remains Client Data to the extent it identifies you or a person, contains your specific values, or would reveal or reconstruct Client Data. We own the general algorithm, model, schema, prompt, and method used to create it. Changing format through hashing, tokenization, embedding, summarization, or aggregation does not by itself make data unrestricted.

Configuration and deliverables. Your specific configuration values, forms, mappings, workflows, and content are Client Data and are included in your exit export. We retain the generic engine, schema, templates, and tools that interpret or run them. Custom deliverables are owned as the Order elects: TrueTech-owned with a license to you, assigned to you on full payment (excluding TrueTech Technology and third-party materials, with an embedded license so the deliverable works), or split as the Order lists. If an Order is silent, deliverables are TrueTech-owned and licensed to you for internal use.

Usage and service data. We may use identifiable system-generated event, performance, error, security, and billing data only to provide, secure, support, maintain, meter, and transition the ordered service and to comply with law. We may use data that has been de-identified so it cannot reasonably be linked to you, a person, or a device to measure and improve our services, and we will not attempt to re-identify it or disclose it in a way that singles you out.

Feedback. You grant us a royalty-free right to use voluntary feedback about the services that does not contain Client Data or your confidential information.

7. Security and data handling

Safeguards. We maintain documented administrative, technical, and physical safeguards appropriate to the nature and volume of the data and the services: unique identities and least-privilege access, multifactor authentication where supported, encryption in transit and at rest, separation of environments, logging and monitoring, vulnerability handling and patching, and personnel confidentiality obligations. This is a scoped standard, not a promise of perfect security. Specific controls, backup and recovery commitments, and evidence we can provide are stated in the Order where a service requires them.

Credentials. We store your credentials and access information in encrypted credential-management tools, limit their use to the authorized purpose, keep them out of ordinary tickets and work artifacts, and return, rotate, revoke, or delete them at exit. Neither party will place credentials in an Order, invoice, ticket, or unprotected message.

People and providers. Access to your systems and data is limited to TrueTech personnel and approved subcontractors and service providers who need it for the services and who are bound by written confidentiality and data-protection obligations. We remain responsible for their performance. Our hosting, infrastructure, and AI providers act under contract as our service providers, process your data only on our instructions, and are bound by the no-training and retention controls in Section 8. We will give 30 days' notice before a material change in how or where your personal data is processed, except in an emergency, in which case notice follows as soon as practicable. A third-party service you select or contract directly is not our subprocessor because we integrate with it.

Security incidents. A Security Incident is a confirmed unauthorized access to, acquisition, disclosure, alteration, or material loss of Client Data, or a confirmed compromise of service security affecting Client Data. Blocked attacks, scans, and failed logins that do not compromise data are not Security Incidents. We will investigate a suspected incident promptly and notify you without undue delay and no later than 48 hours after confirmation, sooner if law requires, with what is known about the nature, affected data, likely consequences, containment, and a contact, followed by updates and a closure summary. We will not notify individuals or make a public statement naming you without your instruction unless law independently requires it. Each party bears its own ordinary response costs; third-party investigation, notification, and restoration costs are allocated to the extent caused by a party's breach or negligence. You will promptly notify us of a security event in your own systems or credentials that may affect the services.

Where data is processed. We operate our infrastructure in the United States. No international transfer is implied; if Client Data must cross a regulated border, we will document the arrangement before transfer.

Return and deletion. During the Order and for 30 days after it ends, you may export Client Data and your configuration in commonly usable formats, with the mappings needed to understand them. At your direction or at the end of that period we delete Client Data from active systems, including indexes, caches, and recoverable derivatives, except what law requires us to retain, which is segregated and deleted when the requirement ends. Backups age out on their disclosed cycle and are restored only for disaster recovery. On request we provide a record describing the deletion performed. At exit we transfer your administrative accounts, domains, certificates, and credentials, revoke what is no longer needed, and will not withhold your credentials as leverage in a fee dispute.

Evidence and questions. On reasonable request and subject to confidentiality, we provide a description of material controls, the categories of providers with access to your data, an incident summary, and other evidence stated in the Order. You may send a reasonable written security questionnaire once a year and after a material incident or service change. No penetration test or scan of our systems is permitted without a separately signed scope.

8. AI-assisted services

We use automation and machine-learning tools as methods of delivering the services, under human oversight, and some of our software includes features that summarize, extract, match, classify, or suggest. Two rules apply everywhere. Client Data, prompts, retrieval context, and outputs are never used to train or improve a generalized model, by us or by any provider we work with. Any AI provider that processes Client Data acts as our service provider under contract, with no-training and retention controls configured, and processes your content only to return a result to you. If a provider cannot support a promised control, we will not send it the affected data.

Where an Order authorizes an AI-enabled service that processes Client Data, the Order identifies the purpose, data categories, retention, and human-review controls. We minimize what is submitted, and we will not submit credentials, secrets, or regulated data classes unless the Order specifically authorizes them with safeguards. Training a model dedicated to you requires your written opt-in in an Order stating the data, purpose, ownership, retention, and exit treatment. We will follow the change notice in Section 7 before materially changing the purpose or location of AI processing involving Client Data.

Output from automated features can be incomplete or wrong. It is decision support, not professional, legal, financial, or engineering advice. We remain responsible for the testing, review, confidentiality, security, and acceptance obligations in the Order regardless of the tools used, but we do not warrant that AI output is unique, independently copyrightable, or accurate without the agreed validation. The services will not make solely automated decisions with legal or similarly significant effects on a person unless an Order expressly describes the use and its safeguards.

9. Third-party products, hardware, and licensing

When we procure hardware, software licenses, or subscriptions for you, we act as reseller or purchasing agent as the Order states. Third-party products are governed by the manufacturer's or publisher's own terms, warranties, and support, which you accept by using the product. We pass those terms through and do not add to them. We are not the manufacturer and make no warranty of our own on third-party products; our responsibility is to order what you approved, deliver it, and coordinate with the vendor on your behalf as professional services where needed.

Purchases require your written approval of the item and price before we order. Purchases are invoiced on order and are due under Section 5 whether or not the vendor has delivered. Special-order, licensed, opened, or subscription items are non-returnable except as the vendor allows. Title to hardware passes to you on delivery; risk of loss passes on delivery to your address. Licenses and subscriptions are registered in your name or tenant where the vendor permits, and remain yours if our relationship ends. Vendor price changes, renewal terms, and discontinuations are outside our control, and we will tell you about them when we learn of them.

Open-source and other third-party components in software we build remain under their own licenses. We identify material components on request, provide required notices, and will not knowingly include a component in a way that would require disclosure or licensing of your proprietary material without your written approval.

10. Confidentiality

Confidential Information means non-public information disclosed by either party that is marked confidential or that a reasonable person would understand to be confidential, including Client Data, credentials, network architecture, security assessments, source code, business processes, financial information, personnel information, customer lists, proprietary tools, pricing, and trade secrets. It excludes information the recipient can show was already known without restriction, independently developed, lawfully received from a third party, or public without breach.

Each party will use the other's Confidential Information only for the engagement, protect it with at least reasonable care and no less than it uses for its own comparable information, and disclose it only to personnel, advisers, and approved providers who need it and are bound by comparable obligations. A party may disclose Confidential Information when legally required, giving prompt notice where lawful so the discloser may seek protection, and disclosing only what is required. These obligations continue for five years after disclosure, for as long as a trade secret remains a trade secret, and for personal data and credentials for as long as law requires. Either party may seek equitable relief for a breach.

11. Warranties and disclaimers

Each party represents that it has authority to enter into the Order and that its signer is authorized. We warrant that services will be performed in a professional and workmanlike manner consistent with generally accepted practices for similar services, that we have the right to grant the licenses we grant, that we will not knowingly introduce malicious code, and that we will materially follow the data and security commitments in these Terms and the Order. For 60 days after acceptance, we warrant that a custom deliverable we authored will materially conform to the written acceptance criteria in the Order. For a breach of these warranties we will re-perform the service or correct the nonconformity, and if we cannot do so after reasonable attempts, you may terminate the affected item and receive a refund of prepaid unused fees.

Your environment may contain vulnerabilities, misconfigurations, legacy systems, undisclosed changes, unimplemented recommendations, third-party failures, or malicious acts that predate the Order or are outside our reasonable control. We are not responsible for loss arising from such conditions except to the extent directly caused by our breach, gross negligence, or willful misconduct. We use reasonable efforts to identify and communicate material conditions we encounter but do not warrant that every latent condition will be discovered.

EXCEPT AS EXPRESSLY STATED IN THESE TERMS OR AN ORDER, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES, SOFTWARE, AND DELIVERABLES ARE PROVIDED WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE, THAT ALL VULNERABILITIES WILL BE IDENTIFIED OR REMEDIATED, OR THAT AUTOMATED OUTPUT IS ACCURATE. THIRD-PARTY PRODUCTS CARRY ONLY THE WARRANTY THEIR VENDOR PROVIDES.

12. Limitation of liability

NEITHER PARTY IS LIABLE TO THE OTHER FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, DATA, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATED TO AN ORDER, EVEN IF ADVISED OF THE POSSIBILITY. Reasonable data-restoration, incident-response, substitute-service, and transition costs caused by a party's breach or negligence are direct damages, subject to the cap below.

EXCEPT AS STATED IN THE NEXT PARAGRAPH, EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATED TO AN ORDER, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, WILL NOT EXCEED THE FEES PAID OR PAYABLE UNDER THAT ORDER IN THE TWELVE MONTHS BEFORE THE FIRST EVENT GIVING RISE TO THE CLAIM. For an Order in force less than twelve months, the cap is the fees paid or payable for its first twelve months.

For breach of confidentiality, misuse of personal data, or a Security Incident caused by a party's breach of these Terms or negligence, the cap is two times the amount above. The limits do not apply to a party's payment obligations, fraud, intentional misconduct, or knowing violation of law. Each cap applies in aggregate to all claims under the affected Order; Orders are not aggregated with one another. These limits reflect a reasonable allocation of risk, our pricing depends on them, and we would not enter into an Order without them.

13. Indemnification

We will defend you against a third-party claim that an unmodified deliverable we authored, used as authorized, infringes a United States copyright, patent, or trade secret, and will pay the resulting judgment or settlement we approve. This does not cover your materials or specifications, unauthorized modifications or combinations, third-party products we did not select or modify, or continued use after we provide a replacement or notice to stop. If a claim arises we may procure continued rights, modify or replace the affected item without material loss of function, or terminate it and refund prepaid fees for the unavailable portion. We will also defend and indemnify you against third-party claims arising from our gross negligence, willful misconduct, or breach of confidentiality.

You will defend and indemnify us against third-party claims arising from materials or specifications you were not authorized to supply, from your failure to act on a critical security recommendation within a reasonable time, from pre-existing conditions in your environment as described in Section 11, or from your breach of the Order.

Indemnification requires prompt notice, reasonable cooperation, control of the defense by the indemnifying party with qualified counsel, and no settlement that admits fault by or imposes non-monetary obligations on the protected party without its consent, not unreasonably withheld.

14. Term, suspension, termination, and exit

Term and renewal. Each Order states its term. Unless the Order says otherwise, a recurring-services Order continues month to month after its initial term on the same terms until replaced or terminated. No automatic multi-month or multi-year renewal applies unless the Order clearly says so.

Termination for convenience. Unless the Order states a different notice period, either party may terminate a recurring-services Order on 30 days' written notice. You will pay for services performed and expenses incurred through the effective date. Fixed-price projects and subscriptions with a committed term may be terminated for convenience only as the Order provides.

Termination for cause. Either party may terminate an Order if the other materially breaches it and does not cure within 30 days after detailed written notice, or within 10 days for non-payment of undisputed fees, or immediately if the other party becomes insolvent or ceases business in the normal course. If you terminate for our uncured breach, we refund prepaid fees for services not provided after the termination date.

Suspension. We may suspend the narrowest practicable portion of a service for a material security threat, unlawful use, immediate material harm, or undisputed non-payment after notice and cure, with notice when safe, preserving export access, and restoring service promptly once the cause is resolved.

Effect of termination. On termination or expiration, we deliver your credentials, documentation, and data as described in Section 7, you pay amounts owed for services performed, each party stops using the other's materials except as needed for transition and legal retention, and Sections 5 through 15 survive to the extent they by nature should.

15. General terms

Independent contractor. We are an independent contractor. We control the methods, tools, and personnel used to perform the services, including qualified subcontractors for whose performance we remain responsible. Nothing in an Order creates an employment, agency, partnership, joint-venture, or fiduciary relationship.

Publicity. Neither party will use the other's name, logo, or relationship publicly without prior written approval.

Assignment. Neither party may assign an Order without the other's consent, not unreasonably withheld, except to a successor in a merger, acquisition, or sale of substantially all relevant assets that assumes the obligations in writing.

Force majeure. Neither party is liable for delay caused by events beyond its reasonable control, including natural disasters, pandemic, government action, power or internet outages, and third-party service disruptions, if it promptly notifies the other and mitigates. Force majeure does not excuse payment for services delivered or the confidentiality and security safeguards that remain practicable.

Notices. Legal notices must be in writing and are effective when delivered personally, when sent by email with confirmation of receipt, or three business days after certified mail to the addresses in the Order. A support ticket is not legal notice.

Governing law and disputes. Orders and these Terms are governed by the laws of the State of Oregon without regard to its conflict-of-laws rules. The parties will first attempt in good faith to resolve any dispute through negotiation between authorized representatives for 30 days, then through mediation in Marion County, Oregon, before litigation. Litigation will be brought exclusively in the state or federal courts located in Oregon, and each party consents to their jurisdiction.

Entire agreement. The Order and the version of these Terms it identifies are the complete agreement for that engagement and supersede prior communications on that subject. A proposal or strategy document provides planning context but does not authorize work unless an Order says so. Amendments must be in writing and signed by both parties. If a provision is unenforceable it will be reformed to the minimum extent necessary and the rest remains in effect. A waiver must be written and applies only to the stated instance. Electronic signatures and counterparts are valid.

Questions about these Terms?

TrueTech Group LLC
20495 Butteville Rd NE BLDG 2
Hubbard, Oregon 97032

Scroll to Top