Legal · Terms of service

Terms of Service

The terms on which The Holm Team provides information technology services to businesses. Written to be read by the person who signs it.

This page is a summary. Where a signed Master Services Agreement, Statement of Work, Service Level Schedule or Data Processing Addendum exists between us, those documents govern and this page does not modify them. Nothing on this page is legal advice.
Effective: August 2026Questions: team@holm.team
01

Agreement structure

These Terms govern every engagement between The Holm Team (“Provider,” “we,” “us”) and the business that engages us (“Client,” “you”). Requesting, approving or paying for services — including approving a quote electronically through your client hub — accepts them.

The business is a sole proprietorship — not a corporation, not a limited liability company — so there is no separate legal entity. Your agreement is with the business owner personally, and the proprietor is personally answerable under it. This matters because it is exactly the sort of thing worth establishing about anyone you are about to hand administrative control of your systems to, and because you would learn it at signature anyway.

An engagement is normally documented across five instruments:

  • These Terms — the baseline, published here and applying to anything not covered elsewhere.
  • Master Services Agreement (MSA) — the signed contract: liability, confidentiality, termination, the commercial frame.
  • Statement of Work (SOW) — what is actually being delivered, at what price, on what schedule. A quote we send and you approve is a SOW.
  • Service Level Schedule — response and resolution targets, maintenance windows, support hours.
  • Data Processing Addendum (DPA) — how we handle personal information you remain responsible for, plus a Business Associate Agreement where protected health information is involved.

Order of precedence. Where two of these conflict, the more specific document controls, in this order: the SOW for the engagement it describes; then the DPA or BAA on anything concerning data protection; then the Service Level Schedule on service levels; then the MSA; then these Terms. A published page never overrides a document you have signed.

02

Scope of services

We deliver two shapes of work, and they are billed differently. A managed agreement is recurring: monitoring, patching, backup verification, endpoint and identity administration, vendor coordination, documentation, and support for the systems named in your SOW, at a recurring fee. Project work — migrations, rebuilds, hardening engagements, assessments — is scoped, quoted and invoiced separately, whether or not you also hold a managed agreement.

Anything not named in the SOW is out of scope. Systems, sites, or headcount added during the term are quoted before they are covered — we would rather re-quote than silently absorb an estate that has doubled. Work that falls outside the licensing perimeter in section 11 is never in scope at any price.

Service levels. Response and resolution targets, maintenance windows, and support hours are set out in the Service Level Schedule to your Master Services Agreement. Service level credits, where applicable, are Client’s sole and exclusive remedy for a failure to meet a service level.

Quotes are valid for 30 days from issue unless the quote states otherwise.

03

Client responsibilities

Most of what determines whether an IT engagement works sits on your side of the line. Stated plainly, you agree to:

  • Give us accurate and complete information about your systems, including the ones nobody documented.
  • Provide timely access — physical, remote, and administrative — to the systems we are asked to support.
  • Hold valid licences for your own software and keep them current; we administer your licences, we do not underwrite them.
  • Appoint an authorised contact who can make decisions and approve spend, and tell us when that person changes.
  • Make decisions promptly where a decision blocks work, and accept that a blocked engagement's schedule moves.
  • Fund the controls you ask us to recommend, or record in writing that you have declined them.
  • Keep unsupported and end-of-life systems off the network, or accept in writing the risk of leaving them on it.

Declined recommendations are recorded. If we recommend a control — multi-factor authentication, endpoint detection, immutable backups, replacing an unsupported system — and you decide against it, we write that down, date it, and keep it with your record. This is not a gotcha. It is how both of us stay clear about who accepted which risk, and it protects you as much as it protects us.

04

Fees, invoicing and late payment

Managed agreement fees are invoiced in advance for the coming period. Project work is invoiced on the milestones stated in the SOW, or on completion where none are stated. Pass-through hardware, software and third-party services are invoiced at the point they are ordered.

Invoices are due within 14 days of issue unless your MSA or SOW sets different net terms. A balance outstanding past its due date may carry a late charge or interest at the rate stated on the invoice or in your MSA, and we may suspend non-urgent work — not monitoring, not an active incident — until the account is settled. Suspension is a last resort and you will hear from a person before it happens.

Rates, methods, disputes and refunds are set out on the payments page.

05

Taxes

Fees are exclusive of tax. You are responsible for applicable California sales and use tax, and for any other tax or duty properly chargeable on what we supply, except tax on our own income.

Where an invoice mixes categories, each line states its own tax treatment — service, hardware, prewritten software, or non-taxable — because California taxes them differently and separately stated labour is only untaxed if it is, in fact, separately stated.

A change is coming. California Senate Bill 122, signed 2026-06-29, extends sales and use tax to prewritten software regardless of how it is delivered — expressly including remotely accessed software and SaaS — for transactions on or after 2027-01-01. Custom software remains exempt, and genuine managed services remain untaxed. In practice: subscriptions we resell to you are likely to become taxable on that date, and the labour that surrounds them is not. Our invoices are already structured to charge them separately.

06

Confidentiality

Each party will protect the other’s confidential information with at least the care it uses for its own, use it only to perform or receive the services, and disclose it only to people who need it and are bound to equivalent obligations. The duty is mutual and survives termination.

It does not cover information that is public through no fault of the receiving party, was already lawfully held, is independently developed, or is lawfully received from a third party. Where disclosure is compelled by law, the compelled party will give the other notice where it is lawfully able to, so that party can seek protection.

Your credentials, network diagrams, configurations and security posture are your confidential information, and they are the part of it we are most careful with.

07

Data protection

You remain responsible for the personal information in your systems. We maintain it on your behalf and do not own it. Our commitments, and the categories we process, are set out in the privacy policy and data processing terms.

  • Reasonable security. California Civil Code §1798.81.5 requires a business that maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information. We maintain your data, so that duty is ours directly — not merely contractual — and we flow the same requirement down to any subcontractor we route your data through.
  • Immediate breach notice to you. California Civil Code §1798.82(b), as amended by SB 446 effective 2026-01-01, requires a business that maintains computerised personal information it does not own to notify the owner immediately following discovery of a breach. Our commitment matches the statute: on discovering a breach of data we hold for you, you hear from us immediately and in writing, with what we know at that point — not a polished summary days later. We record the discovery time and the time you were notified.
  • Protected health information. If your business is a HIPAA covered entity, a Business Associate Agreement is signed before we touch a system that holds protected health information. There is no informal start.
  • Controlled Unclassified Information. Engagements involving CUI, or a contract that flows down DFARS 252.204-7012, require a separate written addendum agreed before work begins. Those clauses impose obligations directly on us, including rapid incident reporting, and they are not accepted by silence.
08

Intellectual property

You own your data. All Client data, documentation of your environment, and content you supply remain yours throughout and after the engagement.

We own our tools. Our scripts, automations, runbooks, configuration baselines, document templates, know-how and methods remain ours, including anything we improve while working for you. Nothing in an engagement transfers them.

Where we leave one of our tools or templates in your environment, you get a perpetual, non-exclusive, royalty-free licence to keep using it for your own internal business purposes — so a script that keeps your backups honest does not stop working the day the agreement ends. That licence does not extend to reselling it or providing it to a third party as a service.

Third-party software, hardware and services we procure for you carry their own vendor licence terms, which bind you directly.

09

Warranty and disclaimer

This section and the next allocate risk between two businesses. They are the two clauses on this page worth reading slowly.

Warranty. Provider warrants that Services will be performed in a professional and workmanlike manner consistent with generally accepted industry standards. Client’s exclusive remedy for a breach of this warranty, and Provider’s entire liability, is for Provider to re-perform the deficient Services at no additional charge, provided Client notifies Provider in writing within thirty (30) days of performance.

Disclaimer. EXCEPT AS EXPRESSLY STATED ABOVE, THE SERVICES AND ANY DELIVERABLES ARE PROVIDED “AS IS.” PROVIDER DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. Provider does not warrant that any system, network, or service will be uninterrupted, error-free, or secure against every threat, and does not guarantee the prevention of unauthorized access, malware, ransomware, or data loss. Client acknowledges that no security measure is capable of eliminating all risk.

Provider does not warrant, and is not responsible for, third-party products, software, or services, including cloud, telecommunications, and hardware vendors, beyond passing through such warranties as those vendors provide and permit to be assigned.

We will say this in plainer words, because it matters more than the formatting suggests: nobody can promise you will not be breached, and any provider who does is either careless with language or selling something. What we will do is monitor, patch on a defined cadence, verify backups by restoring them, and tell you the truth about your exposure. That reduces risk. It does not eliminate it, and we will not pretend otherwise to win the work.

10

Limitation of liability

Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY LAW, PROVIDER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STATUTE, INDEMNITY, OR OTHERWISE, SHALL NOT EXCEED THE TOTAL FEES PAID BY CLIENT TO PROVIDER UNDER THIS AGREEMENT IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

Exclusion of Indirect Damages. NEITHER PARTY SHALL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR ANY LOST PROFITS, LOST REVENUE, LOST BUSINESS, LOSS OF USE, OR LOSS OR CORRUPTION OF DATA, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Exceptions. The limitations above do not apply to a party’s breach of confidentiality obligations, Client’s payment obligations, or to any liability that cannot be limited or excluded under California law.

Allocation of Risk. The parties acknowledge that these limitations are an essential element of the bargain, that the fees reflect this allocation of risk, and that Provider would not enter into this Agreement without them. Client is responsible for maintaining its own insurance, including cyber liability insurance, appropriate to its business.

What the exception actually covers. California Civil Code §1668 makes contracts void where their object is to exempt anyone from responsibility for their own fraud, willful injury to the person or property of another, or violation of law, whether willful or negligent. We do not attempt it. The cap above does not reach fraud, willful misconduct, gross negligence, or a violation of law — including a failure of the reasonable security duty in section 07 — and no reading of this page should suggest that it does.

11

Licensed trades

We configure, manage, monitor and secure equipment that already exists. Physically installing it is a different trade with a different licence, and we are candid about where that line sits.

Licensed Trades. Provider is not a licensed contractor under Division 3, Chapter 9 of the California Business and Professions Code and does not perform low-voltage cabling, electrical, or construction work. Provider is not licensed by the Bureau of Security and Investigative Services and does not install, service, monitor, or respond to alarm systems, does not perform locksmithing, and does not provide investigative services as defined in Business and Professions Code section 7521. Provider is not a telecommunications carrier and does not resell voice services. Where a project requires any such work, Provider will define the requirement and Client will engage an appropriately licensed provider directly.

In practice this is a service, not a limitation. On a project that needs drops pulled or a rack mounted, we write the specification, name the standard, review the licensed contractor’s work against it, and take over the moment the equipment is powered. You get a specialist on each side of the line instead of a generalist on both.

12

Term, termination and offboarding

Managed agreements run for the term stated in the MSA and renew for successive periods of the same length unless either party gives written notice before the renewal date. Either party may terminate for material breach that is not cured within thirty (30) days of written notice. Project engagements end when the SOW is complete.

Offboarding is a deliverable, not a punishment. However an agreement ends, and whoever ended it:

  • Your data is exported and returned in a usable, documented format within thirty (30) days of the effective date of termination, and deleted from our systems after that window closes.
  • Administrative credentials, tenant ownership, domain and certificate control, licence subscriptions and documentation are handed to you or your new provider.
  • Our own administrative access is removed and you are told when it was removed.
  • Transition assistance beyond the handover itself is available at our then-current hourly rate, quoted before it starts.

Fees for services already properly delivered remain payable. Hostage-taking of credentials, tenants or data is not a collection method we use, and no unpaid balance changes the offboarding commitments above.

13

Subcontractors

We may use subcontractors and third-party services to deliver parts of an engagement — a specialist for a discipline we do not hold, a vendor for a platform we resell. We remain responsible for their performance to you as if it were our own, and we flow down our confidentiality and security obligations, including the reasonable security requirement in section 07, before they touch your data.

Where a subcontractor will have access to your systems or your data, we tell you who they are. The DPA lists the subprocessors in use and how you are notified when that list changes.

14

Non-solicitation

During an engagement and for twelve (12) months after it ends, neither party will knowingly solicit for employment the other’s personnel or subcontractors who were directly involved in the work. General advertising not targeted at those people, and hiring someone who responds to it, is not a breach of this section.

15

Governing law and venue

These Terms and every engagement under them are governed by the laws of the State of California, without regard to its conflict-of-laws rules. The parties submit to the exclusive jurisdiction of the state and federal courts located in San Diego County, California, and consent to that venue.

Talk to us first. Write to team@holm.team and we will make a good-faith effort to resolve the matter directly before either of us involves a court. There is no forced arbitration clause in these Terms.

If any provision is held unenforceable, it is limited or severed to the minimum extent necessary and the remainder stands. A waiver on one occasion is not a waiver on any other. These Terms, together with the documents named in section 01, are the entire agreement between us on their subject matter.

16

Force majeure

Neither party is liable for delay or failure to perform caused by events beyond its reasonable control — natural disaster, fire, flood, epidemic, war, civil unrest, government order, labour action, or failure of the public utility or telecommunications infrastructure.

For an IT provider the realistic causes are more specific, and they are expressly included: outages at an upstream cloud, connectivity, or hosting provider; failure or withdrawal of a third-party product or service; and third-party security incidents — including supply-chain compromise of a vendor, a vulnerability disclosed with an exploit already in the wild, or an attack on infrastructure we do not control — where the incident was not caused by our negligence.

The affected party will notify the other promptly and both will resume as soon as the event allows. Payment for services already properly delivered is not excused, and this section is not a defence to a failure we caused.

The Holm Team · team@holm.team

Services provided under our Master Services Agreement — holm.team/legal/terms

A summary published for reference. Your signed agreement governs, and nothing here is legal advice.