Data Backup Policy
1. Purpose and Scope
This Data Backup and Restoration Policy establishes the terms, limitations, responsibilities, procedures, and expectations governing any backup, snapshot, replication, retention, archive, export, restoration, disaster-recovery, or related data-protection function provided, facilitated, managed, configured, monitored, or made available by Spark Rack.
This Policy applies to:
- All Spark Rack Customers;
- All End Users accessing Services through a Customer;
- All resellers and reseller customers;
- All Spark Rack hosting, server, network, storage, database, email, domain, DNS, backup, monitoring, managed, and infrastructure Services;
- All backup products purchased from Spark Rack;
- All backups performed by Spark Rack personnel;
- All backups initiated through the Customer Portal or a control panel;
- All courtesy, emergency, migration, temporary, or incidental backups;
- All snapshots, replicas, recovery points, exports, and retained copies;
- All Customer Data and Customer Content processed through the Services; and
- All third-party backup or storage systems used to support a Spark Rack Service.
This Policy is incorporated into and forms part of the Spark Rack Terms of Service. Capitalized terms not separately defined in this Policy have the meanings assigned to them in the Terms of Service.
2. Core Backup Principle
Every backup, snapshot, replica, export, retention system, restoration process, and disaster-recovery measure provided or performed by Spark Rack is provided on a best-effort basis unless a separately signed written agreement expressly states otherwise.
No Spark Rack backup should ever be treated as absolute, guaranteed, complete, comprehensive, current, error-free, corruption-free, malware-free, uninterrupted, permanently available, fully restorable, or infallible.
Customer must never treat a Spark Rack backup as Customer’s only backup, only recovery method, only archive, only disaster-recovery system, or only means of preserving important data.
Spark Rack maintains reasonable safety systems, operational controls, monitoring, retention procedures, and recovery processes appropriate to the applicable Service. Those measures reduce risk but cannot eliminate every possibility of:
- Backup failure;
- Partial backup;
- Missing files;
- Missing databases;
- Missing messages;
- Missing configuration data;
- Data corruption;
- Backup corruption;
- Undetected corruption;
- Malware contamination;
- Ransomware contamination;
- Retention failure;
- Deletion;
- Overwriting;
- Storage failure;
- Software failure;
- Hardware failure;
- Human error;
- Configuration error;
- Application inconsistency;
- Authentication failure;
- Encryption-key loss;
- Third-party failure;
- Natural disaster;
- Cyberattack;
- Service interruption;
- Failure to meet a desired recovery point;
- Failure to meet a desired recovery time;
- Failure to satisfy a legal or regulatory obligation; or
- Any other event affecting backup availability, completeness, integrity, or restorability.
3. No Absolute Guarantee
Spark Rack does not guarantee that any backup will be created successfully.
Spark Rack does not guarantee that every file, folder, database, mailbox, message, configuration, account, log, application, system state, or other item will be included in a backup.
Spark Rack does not guarantee that a backup will be available when requested.
Spark Rack does not guarantee that a backup will restore successfully.
Spark Rack does not guarantee that restored data will be complete, current, uncorrupted, application-consistent, operational, or compatible with the current environment.
Spark Rack does not guarantee that backup or restoration activity will satisfy any legal, contractual, regulatory, insurance, industry, security, continuity, or compliance requirement applicable to Customer.
No company, platform, storage system, backup provider, cloud provider, data center, software vendor, or technical process can eliminate all risk or guarantee perfect backup success, complete data preservation, or universal restorability under every circumstance.
4. Shared Responsibility
Data protection is a shared responsibility between Spark Rack and Customer.
Spark Rack is responsible only for backup functions expressly included in the applicable Order, Service description, statement of work, or separately signed written agreement.
Customer remains responsible for:
- Determining which data is important;
- Determining which data must be backed up;
- Determining how often backups are required;
- Determining how long backups must be retained;
- Determining where backup copies should be stored;
- Determining whether geographically separate copies are required;
- Determining whether offline, immutable, or air-gapped copies are required;
- Determining whether application-consistent backups are required;
- Determining whether transaction-consistent database backups are required;
- Determining whether encryption is required;
- Protecting Customer-controlled encryption keys;
- Maintaining independent backup copies outside Spark Rack-controlled systems;
- Testing Customer’s independent backup copies;
- Testing restoration procedures;
- Documenting recovery procedures;
- Maintaining business-continuity and disaster-recovery plans;
- Ensuring that backup settings match Customer’s requirements;
- Monitoring Customer-controlled backup jobs;
- Reviewing backup status and failure notifications;
- Correcting errors that prevent backup completion;
- Maintaining sufficient storage capacity;
- Maintaining valid licenses and credentials;
- Maintaining access to source systems;
- Protecting backup credentials;
- Protecting backup destinations;
- Maintaining accurate contact information;
- Responding promptly to backup warnings and notices;
- Validating restored data before returning it to production;
- Meeting Customer’s own legal and regulatory obligations; and
- Maintaining risk controls appropriate to Customer’s operations.
5. Customer’s Independent Backup Obligation
Customer must maintain at least one current backup copy of all important Customer Data outside the production Service and outside any single backup system controlled by Spark Rack.
For critical, irreplaceable, regulated, or business-essential data, Customer should maintain multiple independent copies using appropriately separated systems, credentials, locations, and failure domains.
Customer’s independent backup strategy should be designed so that a failure, compromise, deletion, suspension, termination, or outage affecting Spark Rack does not eliminate Customer’s ability to recover its data.
Customer should not rely exclusively on:
- A single backup destination;
- A single storage provider;
- A single data center;
- A single geographic region;
- A single set of credentials;
- A single administrator;
- A single backup format;
- A single backup schedule;
- A single recovery point;
- A single snapshot;
- Replication alone;
- Synchronization alone;
- RAID alone;
- A recycle bin;
- A version-history feature;
- An undelete feature;
- A temporary migration copy;
- A courtesy backup;
- A control-panel backup stored on the same server;
- A backup stored under the same compromised credentials;
- A backup accessible from the same production environment;
- A backup whose restoration has never been tested; or
- Any backup that Customer cannot independently access and verify.
6. Services Do Not Include Backups Unless Expressly Stated
A hosting, server, network, storage, email, domain, DNS, database, monitoring, management, security, or support Service does not include backups merely because Spark Rack has technical access to the applicable system.
Backups are included only when the applicable Order, Service description, statement of work, or separately signed written agreement expressly identifies:
- That backups are included;
- The systems or data covered;
- The intended backup frequency;
- The intended retention period;
- The intended backup destination;
- The intended backup type;
- Any restoration entitlement;
- Any applicable charges;
- Any stated exclusions; and
- Any separately agreed service commitment.
The absence of an express backup description means Customer is solely responsible for arranging, performing, monitoring, retaining, and testing backups.
7. Types of Backup and Recovery Functions
Depending on the applicable Service, Spark Rack may provide, facilitate, or interact with one or more of the following:
- File-level backups;
- Folder-level backups;
- Full-system backups;
- Image-based backups;
- Virtual-machine snapshots;
- Volume snapshots;
- Storage snapshots;
- Database dumps;
- Database-native backups;
- Application-aware backups;
- Control-panel backups;
- Mailbox backups;
- Email exports;
- Account exports;
- Configuration backups;
- Object-storage copies;
- Incremental backups;
- Differential backups;
- Full backups;
- Continuous or near-continuous replication;
- Point-in-time recovery records;
- Transaction-log backups;
- Off-site copies;
- Cross-region copies;
- Immutable copies;
- Offline copies;
- Archive copies;
- Temporary migration copies;
- Pre-maintenance snapshots;
- Emergency recovery copies;
- Customer-initiated downloads;
- Third-party backup integrations; or
- Other data-protection methods described in an applicable Order.
Each method has different limitations. The presence of one type of data-protection function does not mean that another type is included.
8. Backup Is Not the Same as Replication
Replication generally copies data or changes from one system to another. Replication may improve availability but is not necessarily a historical backup.
Replication may reproduce:
- Accidental deletion;
- Malicious deletion;
- File corruption;
- Database corruption;
- Ransomware encryption;
- Malware;
- Unauthorized changes;
- Application errors;
- Misconfiguration;
- Incorrect permissions;
- Incomplete transactions; and
- Other undesirable source-system changes.
Replication must not be treated as a substitute for an independently retained, historically versioned, and tested backup.
9. Backup Is Not the Same as Synchronization
File synchronization, directory synchronization, mailbox synchronization, object synchronization, and similar functions may copy source changes to a destination.
Synchronization may also copy deletion, corruption, encryption, or unauthorized modification to the synchronized destination.
A synchronized copy is not necessarily a backup and must not be treated as a complete recovery strategy unless it independently retains historical versions and has been tested for restoration.
10. RAID Is Not a Backup
RAID, disk mirroring, storage redundancy, erasure coding, and similar technologies may reduce the effect of certain hardware failures.
They do not necessarily protect against:
- Accidental deletion;
- Malicious deletion;
- Malware;
- Ransomware;
- Application corruption;
- Filesystem corruption;
- Database corruption;
- Unauthorized access;
- Administrator error;
- Catastrophic system failure;
- Data-center loss;
- Credential compromise;
- Logical corruption;
- Fire;
- Flood;
- Theft;
- Legal seizure;
- Account termination; or
- Failure of the storage array as a whole.
RAID and storage redundancy are not backups.
11. Snapshots Are Not Guaranteed Backups
Snapshots may capture a point-in-time state of a disk, volume, virtual machine, filesystem, database, or storage system.
Snapshots may depend on:
- The continued existence of the source storage system;
- The continued integrity of the source volume;
- Available snapshot capacity;
- Compatible storage metadata;
- A functioning snapshot chain;
- Correct storage permissions;
- Correct encryption keys;
- Application quiescence;
- Filesystem consistency;
- Database consistency;
- Retention settings;
- Provider-specific implementation; and
- The absence of storage-level failure or compromise.
A snapshot stored on the same underlying platform or storage system may be lost together with the production data.
Unless expressly stated otherwise, a snapshot is a convenience and recovery tool, not an independently guaranteed backup.
12. Backups Are Not Archives
A backup is generally intended to support recovery from data loss or system failure. An archive is generally intended to preserve records for long-term reference, evidentiary, historical, legal, or regulatory purposes.
Backup retention systems may automatically expire, rotate, consolidate, prune, overwrite, or delete recovery points.
Backups may not preserve:
- Original metadata;
- Original file timestamps;
- Original access-control information;
- Original chain-of-custody information;
- Original message headers;
- Original cryptographic signatures;
- Every historical version;
- Every deleted item;
- Every transaction;
- Every log entry;
- Every legal record;
- Every audit record; or
- Information in a format suitable for long-term access.
Customer must not use a backup as a substitute for a records-management, archiving, e-discovery, legal-hold, or regulatory-retention system unless Spark Rack expressly agrees in writing to provide those functions.
13. Backup Is Not Disaster Recovery
A backup may provide a source from which data can be restored. A complete disaster-recovery program may also require:
- Replacement infrastructure;
- Alternate facilities;
- Network connectivity;
- DNS changes;
- IP address changes;
- Application deployment;
- Operating-system installation;
- License activation;
- Credential recovery;
- Encryption-key recovery;
- Configuration restoration;
- Database recovery;
- Application validation;
- Security validation;
- User acceptance testing;
- Communication procedures;
- Vendor coordination;
- Recovery priorities;
- Recovery personnel;
- Documented procedures;
- Periodic exercises;
- Business-continuity planning; and
- Management decisions outside the scope of a backup Service.
Unless expressly included in a signed statement of work, Spark Rack backup Services do not constitute a complete disaster-recovery or business-continuity service.
14. Intended Backup Frequency
Any stated backup frequency describes the intended schedule and does not guarantee that a backup will begin, complete, or become restorable during every stated interval.
For example, a description such as “daily backup” ordinarily means that Spark Rack intends to attempt a backup approximately once per day. It does not mean that:
- Every calendar day will contain a successful backup;
- The backup will run at a specific time;
- The backup will complete within twenty-four hours;
- Every item will be captured;
- The backup will represent the end of the day;
- The backup will represent the beginning of the day;
- The backup will be application-consistent;
- The backup will be immediately available;
- The backup will remain available for the entire retention period; or
- The backup will restore successfully.
Backup schedules may be delayed, skipped, interrupted, retried, rescheduled, consolidated, or otherwise affected by operational conditions.
15. Backup Windows
Backup activity may occur during a defined or variable backup window.
A backup window is not a guaranteed completion period. Backup activity may extend beyond the intended window because of:
- Large data volume;
- High file count;
- High change rate;
- Slow source storage;
- Slow destination storage;
- Network congestion;
- Application locks;
- Database locks;
- Storage snapshots;
- Deduplication processing;
- Compression processing;
- Encryption processing;
- Verification processing;
- Previous jobs still running;
- Maintenance;
- Software updates;
- Third-party limitations;
- Resource contention;
- System instability;
- Retry operations; or
- Other technical conditions.
16. Backup Retention
Any stated retention period describes the intended maximum period during which recovery points may ordinarily remain available.
A stated retention period does not guarantee:
- That every scheduled recovery point exists;
- That every recovery point remains available for the entire period;
- That every recovery point is complete;
- That every recovery point is uncorrupted;
- That every recovery point is restorable;
- That recovery points are evenly spaced;
- That the oldest possible recovery point is always available;
- That a deleted recovery point can be recovered;
- That a terminated Service continues to receive retention;
- That suspended Services continue to receive retention; or
- That retention satisfies Customer’s legal or regulatory obligations.
Recovery points may be consolidated, pruned, expired, removed, overwritten, or invalidated according to storage limits, job dependencies, retention rules, technical conditions, or Service status.
17. Recovery Point Objective
A recovery point objective, commonly described as an RPO, identifies a target amount of data loss measured in time.
Unless a separately signed written agreement expressly guarantees an RPO:
- Any stated RPO is a target only;
- The actual newest usable recovery point may be older;
- Multiple scheduled recovery points may be unavailable;
- Recent changes may not be captured;
- Open files may not be captured;
- Uncommitted transactions may not be captured;
- Data generated during a failed job may be absent; and
- Customer may experience greater data loss than the target suggests.
18. Recovery Time Objective
A recovery time objective, commonly described as an RTO, identifies a target period for restoring data or service.
Unless a separately signed written agreement expressly guarantees an RTO:
- Any stated RTO is an estimate or target only;
- Restoration may take longer than expected;
- Restoration may depend on Customer approval;
- Restoration may depend on replacement infrastructure;
- Restoration may depend on third-party providers;
- Restoration may depend on data volume;
- Restoration may depend on available bandwidth;
- Restoration may depend on backup integrity;
- Restoration may depend on application compatibility;
- Restoration may require manual intervention;
- Restoration may be delayed by a widespread incident;
- Restoration may be delayed by security investigation;
- Restoration may be delayed by identity verification; and
- Restoration may ultimately be unsuccessful.
19. Backup Completeness
A backup may omit data because of:
- Excluded paths;
- Excluded file types;
- Excluded databases;
- Excluded mailboxes;
- Excluded accounts;
- Excluded volumes;
- Excluded applications;
- Excluded virtual machines;
- Excluded storage systems;
- Incorrect configuration;
- Unsupported software;
- Unsupported filesystems;
- Unsupported database engines;
- Unsupported encryption;
- Insufficient permissions;
- Expired credentials;
- Authentication failure;
- Locked files;
- Open files;
- Changing files;
- Database activity;
- Application activity;
- Storage failure;
- Network interruption;
- Backup-agent failure;
- Backup-software failure;
- Third-party API failure;
- Insufficient storage capacity;
- Insufficient memory;
- Insufficient CPU;
- Job timeout;
- File corruption;
- Path-length limitations;
- Filename limitations;
- Permission changes;
- Mount failures;
- Detached storage;
- Application inconsistency;
- Human error;
- Undetected software defects; or
- Other technical conditions.
A successful job status does not necessarily prove that every intended item was included.
20. Backup Integrity
Spark Rack may use checksums, job-status reporting, storage verification, consistency checks, or other controls where supported.
Such controls reduce risk but may not detect:
- Application-level corruption;
- Logical database corruption;
- Corruption that existed before backup;
- Maliciously altered data;
- Incorrect but technically valid files;
- Missing records;
- Missing relationships;
- Undetected bit errors;
- Incomplete transaction sets;
- Incorrect permissions;
- Incorrect configuration;
- Invalid application state;
- Malware that is not detected by available tools;
- Encryption performed before backup;
- Corruption introduced by source applications;
- Corruption introduced during transmission;
- Corruption introduced during storage;
- Corruption introduced during restoration; or
- Other conditions that do not cause the backup job to report failure.
21. Application Consistency
Unless expressly stated otherwise, backups may be crash-consistent rather than application-consistent.
A crash-consistent backup may resemble the state of a system following an unexpected power loss. Applications may require additional recovery, replay, repair, reconciliation, or manual intervention after restoration.
Application-consistent backups may require:
- Application-aware backup software;
- Database-native backup tools;
- Filesystem freeze or quiescence;
- Application pause;
- Transaction-log capture;
- Valid application credentials;
- Supported application versions;
- Correct plugins or agents;
- Sufficient processing time;
- Customer cooperation;
- Consistent application configuration; and
- Additional licensing or fees.
Customer is responsible for identifying applications that require application-consistent backup and confirming that the selected Service expressly supports that requirement.
22. Database Backups
Database backups may require special handling because copying database files while the database is active may produce an inconsistent or unusable result.
Unless expressly included, Spark Rack does not guarantee:
- Transaction consistency;
- Referential integrity;
- Point-in-time recovery;
- Transaction-log preservation;
- Replication-log preservation;
- Stored-procedure preservation;
- Trigger preservation;
- User and privilege preservation;
- Encryption-key preservation;
- Database-version compatibility;
- Extension compatibility;
- Character-set compatibility;
- Collation compatibility;
- Successful recovery of every table;
- Successful recovery of every record; or
- Successful startup of the restored database.
Customer should maintain database-native dumps or other application-appropriate copies where database recoverability is important.
23. Email and Mailbox Backups
Email backups may not capture every message, folder, attachment, rule, alias, forwarder, identity, contact, calendar item, task, setting, spam-filter state, or mailbox configuration.
Messages may be omitted because they:
- Arrived after the backup began;
- Were deleted before the backup captured them;
- Were held in a transient delivery queue;
- Were stored on a remote client only;
- Were stored by a third-party email service;
- Were outside the selected mailbox scope;
- Exceeded size limits;
- Contained unsupported content;
- Were inaccessible due to permissions;
- Were corrupted;
- Were encrypted in an unsupported manner;
- Were quarantined outside the backup scope;
- Were retained only in temporary storage; or
- Were otherwise unavailable during the backup.
Email backup does not guarantee successful redelivery, preservation of original metadata, or compatibility with every email client or server.
24. Website and Hosting Backups
Website or hosting backups may include only the components identified in the applicable Service.
Depending on configuration, backups may exclude:
- External databases;
- External object storage;
- External email;
- External DNS;
- External APIs;
- Third-party content;
- Remote-mounted filesystems;
- Temporary files;
- Cache files;
- Session files;
- Logs;
- Large files;
- Unsupported symlinks;
- Container volumes;
- Application secrets;
- Encryption keys;
- Control-panel settings;
- Service-level configuration;
- Operating-system configuration;
- Firewall configuration;
- Scheduled tasks;
- License files;
- Third-party integrations; or
- Other components outside the selected backup scope.
25. Server and Virtual-Machine Backups
A server or virtual-machine backup may not preserve every hardware, network, firmware, boot, driver, hypervisor, license, security, or platform dependency.
Restoration may require:
- A compatible hypervisor;
- A compatible virtual-hardware version;
- A compatible operating system;
- Compatible storage drivers;
- Compatible network drivers;
- A compatible boot mode;
- Compatible partitioning;
- Compatible disk size;
- Compatible encryption configuration;
- Replacement licenses;
- New IP addresses;
- New network configuration;
- DNS changes;
- Certificate reissuance;
- Application repair;
- Filesystem repair;
- Database repair;
- Bootloader repair;
- Manual configuration; or
- Customer validation.
26. Configuration Backups
Configuration backups may not capture every setting needed to recreate a Service.
Configuration may exist across:
- Operating-system files;
- Application files;
- Environment variables;
- Secrets-management systems;
- Control-panel databases;
- External APIs;
- DNS providers;
- Network devices;
- Firewall systems;
- Load balancers;
- Certificate systems;
- Licensing platforms;
- Identity providers;
- External storage systems;
- Customer documentation;
- Third-party providers; or
- Other systems outside the backup scope.
Customer must maintain independent documentation of configurations, credentials, dependencies, and recovery procedures.
27. Logs and Audit Records
Logs and audit records may be subject to separate rotation, retention, storage, and capacity limits.
A general system backup does not guarantee preservation of:
- Every application log;
- Every security log;
- Every authentication log;
- Every access log;
- Every network-flow record;
- Every audit event;
- Every administrator action;
- Every message-delivery event;
- Every DNS event;
- Every transaction record;
- Original log ordering;
- Original timestamps;
- Cryptographic integrity evidence;
- Chain of custody;
- Long-term searchability; or
- Admissibility for a legal or regulatory purpose.
28. Encryption
Backups may be encrypted in transit, at rest, or both where supported by the applicable Service.
Encryption reduces certain risks but does not guarantee:
- Backup completeness;
- Backup integrity;
- Backup availability;
- Successful restoration;
- Protection from credential compromise;
- Protection from authorized-user misuse;
- Protection from malware operating with authorized access;
- Protection from deletion;
- Protection from key loss;
- Protection from implementation defects; or
- Compliance with every legal or regulatory requirement.
29. Encryption Keys and Passwords
Customer is responsible for preserving any Customer-controlled password, passphrase, key, certificate, recovery code, token, secret, or other information required to decrypt or access a backup.
If a Customer-controlled encryption key or password is lost, forgotten, destroyed, revoked, overwritten, or unavailable:
- Spark Rack may be unable to access the backup;
- Spark Rack may be unable to restore the backup;
- The data may be permanently unrecoverable;
- Identity verification will not recreate the missing key;
- Administrative access may not bypass the encryption;
- No refund or credit is due merely because the backup cannot be decrypted; and
- Spark Rack has no obligation to weaken or circumvent encryption.
30. Malware and Ransomware
Backups may contain malware, ransomware, compromised files, malicious scripts, stolen credentials, backdoors, web shells, corrupted applications, or other harmful content that existed in the source environment.
Backup completion does not mean that backup contents are clean or safe.
Malware scanning, when provided, may fail to detect:
- New malware;
- Unknown malware;
- Obfuscated malware;
- Encrypted malware;
- Fileless malware;
- Inactive malware;
- Custom malware;
- Malicious configuration;
- Compromised credentials;
- Hidden persistence;
- Supply-chain compromise;
- Malicious database content;
- Malicious code stored in archives;
- Malicious content stored in unsupported formats; or
- Other threats not recognized by available tools.
Spark Rack may decline, delay, isolate, scan, quarantine, or condition a restoration when the requested recovery point may contain malicious or unsafe content.
31. Backup Isolation and Immutability
Some backup systems may use separate storage, restricted credentials, object lock, write-once controls, immutability, or other protective measures.
Those measures reduce risk but do not guarantee protection against:
- Administrative misconfiguration;
- Credential compromise;
- Provider compromise;
- Software defects;
- Retention-policy errors;
- Malicious insiders;
- Authorized deletion;
- Legal deletion requirements;
- Account closure;
- Encryption-key loss;
- Storage-platform failure;
- Data corruption;
- Natural disaster;
- Simultaneous system failure; or
- Other extraordinary events.
Unless expressly stated, Spark Rack does not guarantee that a backup is offline, air-gapped, immutable, geographically separate, or isolated from production credentials.
32. Geographic Separation
A backup described as “off-site,” “remote,” “cross-region,” or “geographically separate” may be stored at a different logical or physical location from the source system.
Such descriptions do not guarantee:
- A specific distance from the source;
- A different state or country;
- A different power grid;
- A different flood zone;
- A different seismic zone;
- A different telecommunications provider;
- A different corporate provider;
- A completely independent failure domain;
- Immediate access during a regional event; or
- Protection from a widespread or correlated incident.
33. Backup Verification
Spark Rack may perform one or more forms of backup verification where supported, including:
- Job-completion checks;
- File-count checks;
- Size checks;
- Checksum verification;
- Storage-health checks;
- Catalog verification;
- Metadata verification;
- Test extraction;
- Test mounting;
- Test restoration;
- Database validation;
- Application startup testing; or
- Manual review.
No verification method proves with absolute certainty that:
- Every intended item exists;
- Every item is correct;
- Every item is uncorrupted;
- Every item is free from malware;
- Every application will start;
- Every database will recover;
- Every dependency is present;
- Every permission is correct;
- Every recovery procedure is documented;
- Every recovery point remains usable; or
- The backup will restore successfully during an actual emergency.
34. Successful Status Is Not a Guarantee
A backup job may report “successful,” “completed,” “healthy,” “verified,” “protected,” or similar status based on the information available to the backup system.
Such a status means only that the applicable software did not report a recognized fatal error under its configured checks.
It does not guarantee:
- Full inclusion of all intended data;
- Application consistency;
- Database consistency;
- Absence of source corruption;
- Absence of malware;
- Absence of hidden errors;
- Successful future restoration;
- Compatibility with replacement infrastructure;
- Compliance with Customer requirements; or
- Business continuity.
35. Restoration Testing
Customer should periodically test restoration of important data into a safe, isolated, and non-production environment.
Restoration testing should evaluate, as applicable:
- Whether the recovery point is accessible;
- Whether the backup can be decrypted;
- Whether files can be extracted;
- Whether databases can be opened;
- Whether applications can start;
- Whether permissions are correct;
- Whether dependencies are available;
- Whether data is complete enough for Customer’s purpose;
- Whether the restored environment is secure;
- Whether malware is present;
- Whether users can authenticate;
- Whether integrations function;
- Whether DNS and network changes are understood;
- Whether recovery documentation is accurate;
- Whether recovery personnel understand their roles;
- Whether the actual recovery time is acceptable; and
- Whether Customer’s continuity objectives can be met.
Unless expressly included in an Order, Customer is responsible for requesting, scheduling, funding, supervising, and validating restoration tests.
36. Test Restores Do Not Guarantee Future Restores
A successful restoration test demonstrates only that the tested recovery point was restored under the specific conditions existing during that test.
It does not guarantee that:
- Another recovery point will restore;
- A future recovery point will restore;
- The same recovery point will remain available;
- The same recovery point will restore after platform changes;
- The same recovery point will restore to different hardware;
- The same recovery point will restore during a widespread emergency;
- The same recovery point will restore after credential or key changes;
- The same recovery point contains every required item; or
- The same recovery procedure will remain valid indefinitely.
37. Restoration Requests
Restoration requests must be submitted through the designated support or Customer Portal channel.
Spark Rack may require:
- Account authentication;
- Identity verification;
- Proof of Account authority;
- Identification of the affected Service;
- Identification of the requested recovery point;
- Identification of the requested files or systems;
- Confirmation of the intended destination;
- Confirmation that existing data may be overwritten;
- Confirmation that Customer has created a current copy of existing data;
- Confirmation of applicable charges;
- Security review;
- Malware review;
- Customer availability for validation;
- Written authorization; or
- Other information reasonably necessary to perform the restoration.
38. Restoration Method
Depending on the applicable Service and circumstances, Spark Rack may restore data by:
- Restoring files to the original location;
- Restoring files to an alternate directory;
- Providing a downloadable archive;
- Restoring a database;
- Providing a database dump;
- Restoring a mailbox;
- Providing an email export;
- Mounting a snapshot;
- Creating a replacement virtual machine;
- Restoring a volume;
- Restoring an entire account;
- Restoring selected configuration;
- Transferring data to Customer-provided storage;
- Providing access to a recovery environment; or
- Using another reasonable recovery method.
Spark Rack determines the technically appropriate restoration method unless otherwise agreed in writing.
39. Restoration May Overwrite Current Data
A restoration may overwrite, replace, merge with, duplicate, alter, or otherwise affect current data.
Potential consequences include:
- Loss of changes made after the recovery point;
- Duplicate files;
- Duplicate database records;
- Conflicting messages;
- Changed permissions;
- Changed ownership;
- Changed timestamps;
- Changed application state;
- Changed configuration;
- Broken integrations;
- Invalid sessions;
- Credential mismatch;
- Data inconsistency;
- Service interruption; or
- Other unintended effects.
Customer should create a separate backup of current data before authorizing a restoration that could overwrite or alter the production environment.
40. Partial Restoration
Spark Rack may be unable to restore only a selected file, mailbox, table, message, record, database, directory, configuration item, or other component.
A partial restoration may be unavailable because of:
- Backup format;
- Encryption;
- Compression;
- Deduplication;
- Snapshot design;
- Application design;
- Database dependencies;
- File relationships;
- Storage limitations;
- Software limitations;
- Licensing limitations;
- Third-party restrictions;
- Backup corruption;
- Unavailable catalog information; or
- Other technical constraints.
Spark Rack may require restoration of a larger data set, complete account, complete database, complete volume, or complete system.
41. Restoration Destination
Restoration to the original environment may be impossible, unsafe, or inappropriate.
Spark Rack may require restoration to:
- An alternate directory;
- An alternate account;
- An isolated server;
- A replacement virtual machine;
- A temporary recovery environment;
- Customer-provided storage;
- An external storage service;
- A secure download package;
- A new database;
- A new mailbox;
- A quarantined location; or
- Another technically suitable destination.
42. Restoration Priority
Restoration requests are handled according to available personnel, technical resources, severity, Customer impact, security considerations, Service level, and operational conditions.
During a widespread outage, cyberattack, natural disaster, data-center event, or other major incident:
- Multiple Customers may request restoration simultaneously;
- Restoration queues may form;
- Critical shared infrastructure may receive priority;
- Security containment may receive priority;
- Restoration may be delayed;
- Available personnel may be limited;
- Replacement hardware may be limited;
- Bandwidth may be limited;
- Storage may be limited;
- Third-party providers may be delayed; and
- Normal support targets may not apply.
43. Restoration Charges
Unless expressly included in the applicable Service, restoration work may be billable.
Charges may apply for:
- Backup retrieval;
- Media retrieval;
- Data extraction;
- Data transfer;
- Temporary storage;
- Temporary infrastructure;
- Emergency work;
- After-hours work;
- Manual database recovery;
- Application repair;
- Filesystem repair;
- Malware analysis;
- Security review;
- Large-scale restoration;
- Multiple restoration attempts;
- Customer-requested testing;
- Third-party charges;
- Shipping or media costs;
- Professional services; and
- Other work outside the included Service scope.
Payment of a restoration charge does not guarantee successful restoration.
44. Customer Validation After Restoration
Customer must promptly inspect and validate restored data.
Customer should verify:
- Required files are present;
- Required databases are present;
- Required messages are present;
- Applications function correctly;
- Permissions are appropriate;
- Credentials are secure;
- Malware is not present;
- Configuration is correct;
- Integrations function correctly;
- Transactions are reconciled;
- Data is sufficiently current;
- Security updates are applied;
- Exposed credentials are rotated;
- Restored systems are appropriately isolated before validation; and
- Business operations can safely resume.
Spark Rack’s completion of a restoration request does not constitute Customer acceptance testing or certification that the restored environment is ready for production use.
45. Reporting Restoration Problems
Customer must report apparent restoration problems promptly after receiving or accessing restored data.
A report should identify:
- The affected Account;
- The affected Service;
- The requested recovery point;
- The restoration date;
- The missing or defective data;
- The expected result;
- The actual result;
- Relevant error messages;
- Relevant logs;
- Whether current data has been modified since restoration; and
- Any other information needed to investigate.
Delay in reporting may result in expiration, rotation, alteration, or loss of other potentially usable recovery points.
46. Courtesy and Incidental Backups
Spark Rack may create a backup, snapshot, copy, export, archive, or recovery point as a courtesy or for Spark Rack’s own operational purposes.
Examples include:
- Pre-maintenance snapshots;
- Migration copies;
- Temporary troubleshooting copies;
- Emergency engineering copies;
- Platform-maintenance copies;
- Security-investigation copies;
- Upgrade rollback points;
- Data-center migration copies;
- Storage-migration copies;
- System-replacement copies; or
- Copies created by a control panel or platform automatically.
Courtesy or incidental copies:
- Are not guaranteed;
- May not include all Customer Data;
- May not be retained;
- May be deleted at any time;
- May be inaccessible to Customer;
- May not be restorable;
- May exist only temporarily;
- May be overwritten;
- May be created solely for Spark Rack’s operational purpose; and
- Do not create an ongoing obligation to provide backups.
47. Migration Copies
Data copied for a migration is intended to support the migration process and is not necessarily a retained backup.
A migration copy may:
- Be incomplete;
- Exclude unsupported data;
- Exclude data changed after the copy began;
- Be deleted after migration;
- Be stored temporarily;
- Be overwritten by a later copy;
- Require source-system access;
- Depend on third-party tools;
- Contain application inconsistencies;
- Be modified during conversion;
- Be incompatible with the destination; or
- Fail to preserve all metadata or settings.
Customer must maintain an independent backup before any migration.
48. Backup Notifications
Spark Rack may provide notifications concerning backup success, failure, delay, storage capacity, retention, configuration, or restoration.
Notifications are a convenience and may fail because of:
- Incorrect contact information;
- Email filtering;
- Mailbox failure;
- Messaging failure;
- Notification-system failure;
- Third-party provider failure;
- Customer Portal access issues;
- API failure;
- Configuration error;
- Software defects;
- Network interruption; or
- Other technical conditions.
Customer remains responsible for monitoring backup status even when notifications are expected.
49. Monitoring Limitations
Spark Rack may monitor backup job status, storage health, capacity, transfer status, agent status, or other operational indicators.
Monitoring does not guarantee detection of:
- Every failed backup;
- Every partial backup;
- Every omitted file;
- Every omitted database;
- Every corrupt recovery point;
- Every application inconsistency;
- Every expired credential;
- Every missing dependency;
- Every malware infection;
- Every retention error;
- Every storage defect;
- Every provider failure;
- Every configuration mistake;
- Every silent software error; or
- Every circumstance that could prevent restoration.
50. Customer-Controlled Backup Jobs
When Customer configures, initiates, schedules, modifies, disables, pauses, deletes, or otherwise controls a backup job, Customer is responsible for:
- Correct source selection;
- Correct destination selection;
- Correct schedule;
- Correct retention settings;
- Correct exclusions;
- Correct credentials;
- Correct encryption settings;
- Sufficient destination capacity;
- Reviewing job results;
- Responding to failures;
- Testing restoration;
- Protecting backup access;
- Maintaining required licenses;
- Maintaining source and destination availability;
- Maintaining network connectivity; and
- Ensuring that the backup meets Customer’s requirements.
Spark Rack is not responsible for a Customer-controlled backup that fails because of Customer configuration, Customer action, Customer omission, or a Customer-controlled system.
51. Third-Party Backup Services
Backup Services may depend on third-party software, storage, networks, APIs, data centers, licenses, or providers.
Spark Rack does not control every aspect of a third-party service and is not responsible for third-party:
- Outages;
- Software defects;
- Storage failures;
- Security incidents;
- Data loss;
- Retention changes;
- Pricing changes;
- Feature changes;
- Service discontinuation;
- API limitations;
- Rate limits;
- Account restrictions;
- Legal restrictions;
- Regional availability;
- Encryption implementation;
- Restoration limitations;
- Performance limitations;
- Contractual limitations; or
- Other acts or omissions outside Spark Rack’s reasonable control.
Spark Rack may replace, modify, migrate, or discontinue a third-party backup component when reasonably necessary.
52. Source-System Limitations
A backup cannot reliably capture data that the source system does not expose, permit, retain, or make accessible.
Backup limitations may arise from:
- Application design;
- Operating-system restrictions;
- Filesystem restrictions;
- Database restrictions;
- Encryption;
- Digital-rights controls;
- Permissions;
- Locked files;
- Third-party APIs;
- Cloud-provider restrictions;
- Vendor licensing;
- Export restrictions;
- Data-location restrictions;
- Customer configuration;
- Insufficient privileges;
- Unsupported versions;
- Legacy software;
- Source corruption;
- Source unavailability; or
- Other conditions outside Spark Rack’s control.
53. Unsupported Systems and Data
Spark Rack may decline to back up or restore:
- Unsupported operating systems;
- Unsupported filesystems;
- Unsupported databases;
- Unsupported applications;
- Unsupported control panels;
- Unsupported storage formats;
- End-of-life software;
- Unlicensed software;
- Unlawful content;
- Malicious content;
- Data that creates a security risk;
- Data protected by unavailable encryption keys;
- Data located on inaccessible systems;
- Data subject to conflicting legal restrictions;
- Corrupted backup chains;
- Technically incompatible data; or
- Any data outside the agreed Service scope.
54. Storage Capacity
Backup jobs may fail, stop, truncate, prune, or expire recovery points when available storage capacity is insufficient.
Customer is responsible for monitoring capacity on Customer-controlled backup destinations.
Where Spark Rack controls the backup destination, Spark Rack may:
- Apply storage limits;
- Apply retention limits;
- Remove expired recovery points;
- Prune older recovery points;
- Pause backup activity;
- Require an upgrade;
- Bill overages;
- Restrict new backups;
- Notify Customer; or
- Take another reasonable capacity-management action.
55. Excessive Data Change or Growth
Rapid data growth, unusually high change rates, excessive file counts, large databases, high transaction volume, or unexpectedly large backups may affect:
- Backup completion time;
- Backup-window completion;
- Storage capacity;
- Retention;
- Network utilization;
- System performance;
- Verification time;
- Restoration time;
- Backup cost;
- Recovery-point availability; and
- Overall backup reliability.
Spark Rack may require Customer to purchase additional storage, increase Service capacity, reduce the protected data set, change the schedule, or adopt another backup architecture.
56. Performance Impact
Backup activity may affect source-system, storage, database, application, or network performance.
Potential effects include:
- Higher CPU usage;
- Higher memory usage;
- Higher disk activity;
- Higher network usage;
- Database locks;
- Application pauses;
- Snapshot pauses;
- Longer response times;
- Reduced throughput;
- Temporary service degradation;
- Increased storage usage;
- Increased log activity; and
- Other temporary resource effects.
Spark Rack may adjust backup timing, concurrency, bandwidth, frequency, or method to protect service stability.
57. Maintenance and Service Changes
Backup systems may be affected by maintenance, upgrades, migrations, replacements, configuration changes, software changes, storage changes, network changes, and platform changes.
Spark Rack may:
- Change backup software;
- Change storage providers;
- Change storage locations;
- Change backup formats;
- Change compression methods;
- Change encryption methods;
- Change schedules;
- Change retention implementation;
- Change verification methods;
- Change restoration procedures;
- Change network paths;
- Change monitoring tools;
- Migrate existing recovery points;
- Decline to migrate incompatible recovery points;
- Expire obsolete recovery points; or
- Take other reasonable actions needed to operate the Service.
58. Suspension
Backup creation, retention, access, or restoration may be limited, paused, or discontinued while an Account or Service is suspended.
During suspension:
- New backups may not run;
- Existing recovery points may continue to age;
- Retention periods may continue to expire;
- Customer access may be disabled;
- Restoration may be unavailable;
- Backup storage may be reclaimed;
- Third-party services may be suspended;
- Encryption keys may become inaccessible;
- Backup agents may stop communicating; and
- Data may become permanently unrecoverable.
Customer remains responsible for maintaining independent backups before and during any suspension.
59. Cancellation and Termination
Customer must retrieve all required backup data before cancellation or termination becomes effective.
After cancellation or termination:
- Backup jobs may stop immediately;
- Backup access may end immediately;
- Recovery points may be deleted immediately;
- Recovery points may expire according to ordinary retention;
- Backup storage may be reclaimed;
- Third-party backup accounts may be closed;
- Backup catalogs may be removed;
- Encryption keys may be destroyed or become inaccessible;
- Temporary recovery environments may be removed;
- Restoration may no longer be possible;
- Data-export requests may be declined; and
- No further backup obligation remains unless expressly agreed in writing.
Spark Rack has no obligation to retain Customer backups after cancellation, expiration, or termination unless a separately signed written agreement expressly states otherwise.
60. Immediate Cancellation
If Customer requests immediate cancellation, Customer acknowledges that backups, snapshots, recovery points, and retained copies may become inaccessible or be deleted without further notice.
Customer must not request immediate cancellation until Customer has:
- Downloaded required data;
- Verified downloaded data;
- Tested independent backups;
- Completed required migrations;
- Preserved required legal records;
- Preserved required compliance records;
- Preserved required encryption keys; and
- Confirmed that Spark Rack-held recovery points are no longer needed.
61. Deleted Data
Deletion from a production system does not guarantee immediate deletion from every backup, log, cache, snapshot, replica, disaster-recovery copy, or residual storage system.
Conversely, deletion from a production system does not guarantee that a recoverable backup copy exists.
Deleted information may:
- Remain temporarily in retained recovery points;
- Remain until ordinary backup expiration;
- Remain subject to a legal hold;
- Remain in disaster-recovery systems;
- Remain in temporary migration copies;
- Be overwritten through ordinary storage cycles;
- Be inaccessible for selective recovery;
- Be permanently deleted immediately; or
- Be unrecoverable despite appearing in a backup catalog.
62. Privacy Deletion Requests
A privacy deletion request does not necessarily require immediate deletion from disaster-recovery or backup systems when Applicable Law permits delayed deletion from those systems.
Information retained in backups after an approved deletion request may remain restricted from ordinary use until:
- The applicable recovery point expires;
- The backup is overwritten;
- The storage media is destroyed;
- The backup is otherwise deleted; or
- Deletion is required through another technically reasonable process.
If retained information is restored, Spark Rack or Customer may need to reapply the deletion request where required by Applicable Law.
63. Legal Holds and Preservation
Spark Rack may preserve backup data beyond ordinary retention when reasonably necessary to comply with:
- A valid preservation request;
- A subpoena;
- A warrant;
- A court order;
- Pending litigation;
- Anticipated litigation;
- An arbitration;
- A governmental investigation;
- A security investigation;
- An abuse investigation;
- An insurance matter;
- A contractual dispute; or
- Another legal obligation.
A legal hold does not guarantee that:
- A requested backup exists;
- The backup is complete;
- The backup is uncorrupted;
- The backup contains every requested record;
- The backup is selectively searchable;
- The backup can be restored;
- The backup preserves original metadata;
- The backup satisfies evidentiary requirements; or
- The backup can be produced in a requested format.
64. E-Discovery and Litigation Support
Backup Services do not include e-discovery, forensic preservation, chain-of-custody documentation, litigation support, expert testimony, legal review, or evidentiary certification unless expressly included in a signed statement of work.
Any such work may require:
- Separate professional-service fees;
- Legal review;
- Forensic tools;
- Special preservation procedures;
- Custodian identification;
- Chain-of-custody documentation;
- Search and filtering;
- Format conversion;
- Privilege review;
- Secure production methods; and
- Additional time and resources.
65. Regulatory and Contractual Compliance
Spark Rack does not represent or warrant that a backup Service, backup schedule, retention period, recovery point, restoration process, or disaster-recovery measure will make Customer compliant with any law, regulation, contract, insurance requirement, industry framework, audit standard, or certification program.
No backup Service is automatically represented as compliant with:
- HIPAA;
- HITECH;
- PCI DSS;
- GLBA;
- FERPA;
- CJIS;
- FISMA;
- FedRAMP;
- SOX;
- SEC recordkeeping requirements;
- FINRA requirements;
- GDPR;
- United Kingdom data-protection requirements;
- Canadian privacy requirements;
- State privacy laws;
- State breach-notification laws;
- Government recordkeeping requirements;
- Legal-hold obligations;
- Insurance-policy requirements;
- Professional licensing requirements;
- Contractual retention requirements;
- ISO standards;
- SOC reporting requirements;
- NIST frameworks;
- CIS controls;
- Industry-specific standards; or
- Any other compliance framework.
Customer is solely responsible for determining:
- Which requirements apply;
- Whether the selected Service satisfies those requirements;
- Whether a written addendum is required;
- Whether encryption is sufficient;
- Whether retention is sufficient;
- Whether immutability is required;
- Whether geographic restrictions apply;
- Whether audit logging is required;
- Whether restoration testing is required;
- Whether documentation is sufficient;
- Whether vendor due diligence is sufficient;
- Whether regulatory approval is required; and
- Whether additional technical or organizational controls are needed.
66. No Compliance Certification
A backup job’s successful status, a restoration test, an operational report, a Service description, or a support response does not constitute:
- A legal opinion;
- A compliance certification;
- An audit opinion;
- An attestation;
- A guarantee of regulatory compliance;
- A guarantee of contractual compliance;
- A guarantee of insurance coverage;
- A guarantee of evidentiary admissibility;
- A guarantee of business continuity; or
- A guarantee against data loss.
67. Regulated and Sensitive Data
Customer must not use a backup Service for regulated or Sensitive Personal Information unless the Service is appropriate for that information and all required agreements and safeguards are in place.
Customer is responsible for:
- Classifying protected data;
- Determining encryption requirements;
- Determining access-control requirements;
- Determining geographic restrictions;
- Determining retention requirements;
- Determining deletion requirements;
- Obtaining required consents;
- Entering required agreements;
- Maintaining required audit records;
- Limiting administrator access;
- Monitoring backup access;
- Protecting encryption keys;
- Responding to privacy requests;
- Responding to security incidents; and
- Meeting all applicable legal obligations.
68. Customer Data Ownership
As between Customer and Spark Rack, Customer retains Customer’s ownership rights in Customer Data and Customer Content.
Customer grants Spark Rack and authorized Service Providers a limited right to copy, transmit, store, encrypt, compress, deduplicate, verify, restore, migrate, and otherwise process Customer Data as reasonably necessary to provide and protect the backup Service.
This limited processing right does not transfer ownership of Customer Data to Spark Rack.
69. Backup Privacy and Confidentiality
Backup data may contain confidential, proprietary, personal, regulated, privileged, or sensitive information.
Spark Rack limits access to backup data according to legitimate operational, support, security, legal, and administrative need.
Spark Rack personnel or authorized Service Providers may access backup data when reasonably necessary to:
- Perform a restoration;
- Troubleshoot a backup failure;
- Verify backup integrity;
- Investigate a security incident;
- Investigate Abuse;
- Perform a migration;
- Maintain backup infrastructure;
- Comply with legal process;
- Protect the Services; or
- Perform another authorized function.
70. No AI Training
Spark Rack does not use backup data, restored data, backup metadata, recovery-point information, backup logs, Customer Data, or Customer Content for artificial-intelligence or machine-learning training.
Spark Rack does not authorize Service Providers, partners, vendors, or other third parties to use backup data for:
- AI model training;
- Machine-learning training;
- Model fine-tuning;
- Model evaluation;
- Model improvement;
- Data labeling;
- Embedding generation for unrelated purposes;
- Synthetic-data creation;
- Behavioral profiling;
- Automated prediction; or
- Any substantially similar purpose.
71. Security Incidents Affecting Backups
If Spark Rack becomes aware of a suspected security incident affecting backup systems, Spark Rack may:
- Restrict access;
- Disable backup jobs;
- Disable restoration;
- Revoke credentials;
- Rotate keys;
- Isolate storage;
- Preserve evidence;
- Investigate affected systems;
- Coordinate with Service Providers;
- Notify affected Customers where required or appropriate;
- Notify authorities where required;
- Restore from alternate copies where available;
- Require Customer action;
- Delay restoration pending security review; or
- Take other reasonable protective measures.
A security incident may result in loss, corruption, unavailability, or delayed access even when backup safety systems were in place.
72. Natural Disasters and Extraordinary Events
Backups may be affected by events beyond Spark Rack’s reasonable control, including:
- Fire;
- Flood;
- Hurricane;
- Tornado;
- Earthquake;
- Lightning;
- Severe weather;
- Power-grid failure;
- Telecommunications failure;
- Data-center failure;
- Carrier failure;
- Supply-chain disruption;
- Hardware shortage;
- War;
- Terrorism;
- Civil unrest;
- Pandemic;
- Governmental action;
- Cyberattack;
- Ransomware;
- Distributed denial-of-service attack;
- Cloud-provider failure;
- Software-vendor failure;
- Regional Internet disruption;
- Simultaneous infrastructure failures; or
- Other events outside Spark Rack’s reasonable control.
73. Customer Actions Affecting Backups
Spark Rack is not responsible for backup failure, loss, corruption, or unavailability caused by Customer or an End User, including:
- Deleting a backup;
- Disabling a backup job;
- Changing a schedule;
- Changing retention;
- Changing exclusions;
- Removing an agent;
- Revoking credentials;
- Changing permissions;
- Changing encryption keys;
- Losing a password;
- Removing source data;
- Removing a storage mount;
- Blocking backup traffic;
- Exhausting storage capacity;
- Allowing an Account to become past due;
- Requesting cancellation;
- Requesting immediate deletion;
- Ignoring backup warnings;
- Installing incompatible software;
- Using unsupported software;
- Allowing a system to become compromised;
- Providing incorrect instructions;
- Failing to verify restoration;
- Failing to maintain independent copies; or
- Otherwise interfering with backup operation.
74. Resellers
A reseller remains responsible for establishing appropriate backup terms, disclosures, retention requirements, restoration procedures, and independent backup obligations with its End Users.
Resellers must not represent that Spark Rack backups are:
- Guaranteed;
- Infallible;
- Always complete;
- Always current;
- Always available;
- Always restorable;
- Guaranteed to satisfy a particular RPO;
- Guaranteed to satisfy a particular RTO;
- Guaranteed to satisfy regulatory compliance;
- Guaranteed to prevent data loss; or
- More extensive than the Service actually purchased.
A reseller is responsible for all backup commitments it independently makes to its End Users.
75. Backup Documentation
Customer should maintain current documentation identifying:
- Protected systems;
- Protected data;
- Excluded data;
- Backup schedules;
- Retention periods;
- Backup destinations;
- Encryption methods;
- Encryption-key locations;
- Recovery procedures;
- Recovery priorities;
- Application dependencies;
- External dependencies;
- Required credentials;
- Required licenses;
- Responsible personnel;
- Emergency contacts;
- Alternative infrastructure;
- DNS procedures;
- Network procedures;
- Testing history;
- Known limitations;
- Legal requirements;
- Regulatory requirements; and
- Customer acceptance criteria.
Spark Rack is not responsible for Customer’s failure to maintain adequate recovery documentation.
76. Business-Continuity Planning
Customer must maintain a business-continuity plan appropriate to Customer’s operations.
The plan should address:
- Loss of production data;
- Loss of backup data;
- Loss of Spark Rack access;
- Loss of Customer Portal access;
- Loss of administrative credentials;
- Loss of encryption keys;
- Loss of a data center;
- Loss of a network provider;
- Loss of a domain;
- Loss of DNS;
- Loss of email;
- Loss of application licenses;
- Loss of key personnel;
- Cyberattack;
- Ransomware;
- Natural disaster;
- Third-party failure;
- Extended restoration time;
- Partial restoration;
- Unavailable recovery points;
- Manual business operations;
- Customer and employee communication;
- Regulatory notification; and
- Alternative service providers.
77. Risk Acceptance
By using a Spark Rack backup Service, Customer acknowledges and accepts that:
- No backup system is perfect;
- No storage system is immune from failure;
- No retention system is immune from error;
- No security control eliminates all risk;
- No monitoring system detects every failure;
- No verification process proves absolute completeness;
- No successful job status guarantees restoration;
- No restoration test guarantees future restoration;
- No replica guarantees historical recovery;
- No snapshot guarantees independent protection;
- No backup guarantees legal compliance;
- No backup guarantees business continuity;
- Some data loss may occur;
- Some downtime may occur;
- Some recovery points may be unavailable;
- Some restored data may be incomplete;
- Some restored systems may require repair;
- Some data may be permanently unrecoverable;
- Customer must maintain independent backups; and
- Customer must maintain its own continuity and recovery plan.
78. No Warranty
To the maximum extent permitted by Applicable Law, all backup and restoration Services are provided “as is,” “as available,” and on a best-effort basis.
Spark Rack disclaims all express, implied, and statutory warranties concerning backups and restorations except warranties that cannot lawfully be disclaimed.
This disclaimer includes any implied warranty of:
- Merchantability;
- Fitness for a particular purpose;
- Accuracy;
- Completeness;
- Availability;
- Durability;
- Security;
- Data integrity;
- Non-infringement;
- Regulatory compliance;
- Successful restoration;
- Uninterrupted operation;
- Compatibility;
- Error-free operation;
- Recovery within a particular time;
- Recovery to a particular point;
- Preservation of every item; or
- Prevention of data loss.
79. Limitation of Liability
Any limitation of liability in the Spark Rack Terms of Service applies fully to backup and restoration Services.
To the maximum extent permitted by Applicable Law, Spark Rack is not liable for losses arising from or relating to:
- Backup failure;
- Partial backup;
- Missing data;
- Expired recovery points;
- Deleted recovery points;
- Corrupted backups;
- Unrestorable backups;
- Unavailable backups;
- Delayed restoration;
- Failed restoration;
- Incomplete restoration;
- Application inconsistency;
- Database inconsistency;
- Malware in a backup;
- Ransomware in a backup;
- Customer failure to maintain independent copies;
- Customer failure to test restoration;
- Customer failure to respond to warnings;
- Third-party backup failure;
- Encryption-key loss;
- Credential loss;
- Suspension;
- Cancellation;
- Termination;
- Loss of business;
- Loss of revenue;
- Loss of profits;
- Business interruption;
- Loss of reputation;
- Legal or regulatory penalties;
- Failure to satisfy compliance obligations;
- Cost of reconstructing data;
- Cost of replacement services;
- Loss of evidence;
- Loss of records;
- Loss of Customer relationships;
- Loss of End User data; or
- Any other consequence of data loss or failed recovery.
80. Service Credits and Refunds
Customer is not entitled to a refund, credit, damages, or reimbursement merely because:
- A backup failed;
- A backup was incomplete;
- A recovery point was unavailable;
- A recovery point expired;
- A backup was corrupted;
- A restoration took longer than expected;
- A restoration was incomplete;
- A restoration failed;
- Data was lost;
- Customer lacked an independent backup;
- A third-party provider failed;
- A stated target was not met; or
- The backup did not satisfy Customer’s compliance obligations.
A Service credit applies only when expressly provided by a separate Service Level Agreement and only according to that agreement’s terms.
81. No Oral Backup Guarantees
No oral statement, support response, sales conversation, technical recommendation, status message, control-panel label, monitoring result, or informal communication creates a guarantee concerning:
- Backup success;
- Backup completeness;
- Backup retention;
- Backup integrity;
- Backup availability;
- Restoration success;
- Recovery time;
- Recovery point;
- Compliance;
- Business continuity; or
- Data-loss prevention.
Only a separately signed written agreement that specifically identifies the guaranteed obligation may modify the best-effort standard in this Policy.
82. Interpretation of “Protected,” “Backed Up,” and Similar Terms
Terms such as:
- “Protected”;
- “Backed up”;
- “Healthy”;
- “Successful”;
- “Verified”;
- “Completed”;
- “Available”;
- “Recoverable”;
- “Redundant”;
- “Replicated”;
- “Off-site”;
- “Immutable”;
- “Secure”;
- “Daily”;
- “Continuous”;
- “Automatic”;
- “Managed”;
- “Monitored”;
- “Disaster recovery”;
- “High availability”; or
- Similar descriptive terms
must be interpreted according to the applicable technical context, Service description, and written limitations. They do not create an absolute guarantee or eliminate Customer’s independent backup obligations.
83. Changes to Backup Services
Spark Rack may modify a backup Service to reflect:
- Technology changes;
- Security changes;
- Storage changes;
- Vendor changes;
- Data-center changes;
- Software changes;
- Licensing changes;
- Legal requirements;
- Capacity limitations;
- Product changes;
- Operational improvements;
- Service discontinuation;
- Threat conditions;
- Cost changes;
- Availability changes; or
- Other legitimate business or technical reasons.
Spark Rack will provide reasonable notice of material changes when commercially practicable.
84. Discontinued Backup Services
If a backup Service is discontinued, Spark Rack may:
- Offer a replacement Service;
- Offer migration to another system;
- Provide a limited export period;
- Require Customer to retrieve backups;
- Provide notice of a deletion date;
- Decline to migrate incompatible recovery points;
- Expire existing recovery points;
- Refund an unused prepaid base fee where required by the Terms of Service; or
- Take another commercially reasonable action.
Customer is responsible for retrieving and independently preserving required backup data before the discontinuation date.
85. Policy Changes
Spark Rack may update this Policy to reflect:
- Changes in backup technology;
- Changes in recovery practices;
- Changes in security threats;
- Changes in law;
- Changes in compliance requirements;
- Changes in third-party services;
- Changes in Service offerings;
- Operational experience;
- Clarifications;
- New backup methods;
- New restoration methods; or
- Other developments affecting backup or recovery Services.
Continued use of an affected Service after an updated Policy takes effect constitutes acceptance of the updated Policy.
86. Conflict with Other Documents
If this Policy conflicts with a separately signed written agreement that expressly identifies a specific backup obligation, the separately signed written agreement controls only for that specific obligation.
General descriptions, marketing materials, sales statements, support statements, website labels, dashboard statuses, or control-panel text do not override this Policy.
87. Severability
If any provision of this Policy is found invalid or unenforceable, that provision will be modified or severed only to the minimum extent necessary, and the remaining provisions will remain effective.
The invalidity of one provision does not create an absolute backup guarantee or eliminate Customer’s independent backup responsibilities.
88. Contact Information
Questions, backup requests, restoration requests, or concerns regarding this Policy should be submitted through the appropriate support, account, legal, or service-management channel in the Spark Rack Customer Portal.
Written correspondence may be mailed to:
Spark RackAttn: Data Backup and Restoration
PO Box 2215
Valdosta, GA 31604
United States
89. Customer Acknowledgment
By ordering, accessing, or using a Spark Rack Service, Customer acknowledges and agrees that:
- All Spark Rack backups are provided on a best-effort basis unless a separately signed written agreement expressly states otherwise.
- No backup should be treated as absolute, complete, current, error-free, corruption-free, malware-free, permanently available, fully restorable, or infallible.
- A successful backup status does not guarantee complete or successful restoration.
- A successful restoration test does not guarantee future restoration.
- Replication, synchronization, RAID, snapshots, version history, and recycle-bin functions are not substitutes for independent backups.
- Backups are not automatically archives, legal-hold systems, compliance systems, business-continuity systems, or complete disaster-recovery systems.
- Spark Rack cannot guarantee that every file, database, message, configuration, or record will be captured or restored.
- Spark Rack cannot guarantee a particular recovery point or recovery time unless expressly stated in a separately signed written agreement.
- Spark Rack cannot guarantee that backup Services will satisfy Customer’s legal, regulatory, contractual, insurance, audit, or compliance obligations.
- Safety systems, monitoring, verification, encryption, redundancy, immutability, and geographic separation reduce risk but cannot eliminate all risk.
- Customer must maintain current, independent backup copies outside the production Service and outside any single Spark Rack-controlled backup system.
- Customer is responsible for periodically testing independent backups and restoration procedures.
- Customer is responsible for maintaining required passwords, encryption keys, licenses, credentials, documentation, and recovery instructions.
- Customer is responsible for determining whether the selected backup Service is appropriate for Customer’s data and obligations.
- Customer is responsible for retrieving required data before suspension, cancellation, expiration, or termination.
- Some data may be permanently lost or unrecoverable even when reasonable backup safety systems were in place.
- No company, provider, platform, storage system, or technical process can guarantee perfect backup success, complete preservation, universal restorability, or absolute compliance under every circumstance.
- Customer accepts the risks inherent in backup, storage, restoration, and disaster-recovery processes.