Legal
SOFTWARE AS A SERVICE (SaaS)
SERVICE LEVEL AGREEMENT
1. Purpose
This Service Level Agreement ("SLA") defines the operational service levels, support commitments, availability targets, incident response procedures, and responsibilities applicable to the Trustful Clinical Budgeting ("TCB") cloud platform.
The purpose of this document is to establish clear expectations regarding the delivery and support of the TCB platform while ensuring transparency between Trustful Clinical Budgeting ("Vendor", "Software") and its Clients.
This SLA forms part of the applicable Software License Agreement, Subscription Order, Commercial Proposal, Statement of Work, Purchase Order, or other written agreement between Trustful Clinical Budgeting and the Client.
This SLA does not transfer ownership of copyright, industrial property rights, or any other rights of any kind, nor does it transfer ownership of the software or Client Data, and it does not replace any commercial agreement governing prices, licensing or payment terms.
2. Scope
This SLA applies to all Clients with an active subscription to the Trustful Clinical Budgeting platform.
The commitments described in this document apply to the production environment of the TCB platform.
Unless otherwise agreed in writing, this SLA covers the standard functionality of the TCB Software-as-a-Service (SaaS) platform and does not include:
- Custom software development;
- Consultancy services;
- Configuration projects beyond the agreed implementation scope;
- Third-party software;
- Third-party integrations;
- Customer-developed reports;
- Customer-developed interfaces.
Professional Services provided under separate commercial agreements are excluded from this SLA.
3. Definitions
In addition to terms defined elsewhere in this Agreement, the following definitions shall apply:
- "Availability"
- means the percentage of time during a calendar month that the production TCB platform is available for normal Client use, excluding scheduled maintenance and other exclusions defined within this SLA.
- "Business Hours"
- means the specific hours during which the Vendor's customer support team is available to respond to support requests, as specified in Section 6 of this Agreement.
- "Client"
- means the legal entity purchasing a subscription to the TCB platform.
- "Customer Data"
- means all information uploaded, entered, imported, created or stored by the Client within the TCB platform, including but not limited to:
- clinical trial budgets
- contracted budgets
- vendor information
- purchase orders
- forecasts
- invoices
- performed activities
- analytics
- reports
- attachments
- user-generated information
- "Downtime"
- means any period during which the Service is unavailable to the Client, excluding Scheduled Maintenance and SLA Exclusions as defined herein.
- "Service Level Agreement (SLA)"
- means this agreement outlining the expected level of service between the Vendor and Client.
- "Emergency Maintenance"
- means maintenance activities that must be performed immediately to preserve platform security, integrity, availability or stability. Emergency Maintenance may be performed without advance notice whenever reasonably necessary.
- "Enhancement Request"
- means a request for new functionality, modifications, workflow improvements, reports, dashboards or other features that are not defects within the existing platform. Enhancement Requests are evaluated according to the TCB Product Roadmap and are outside the scope of standard support services.
- "Incident"
- means any event that disrupts the normal operation of the Service.
- "Maintenance Window"
- means the scheduled period of time during which the Vendor may perform maintenance on the Service infrastructure, potentially resulting in Service unavailability.
- "Response Time"
- means the period of time measured from the moment the Vendor receives a support request until the Vendor acknowledges receipt and commences work to resolve the issue.
- "Resolution Time"
- means the period of time measured from the moment the Vendor acknowledges receipt of a support request until the reported issue is resolved.
- "Service"
- means the Trustful Clinical Budgeting cloud-based Software-as-a-Service platform.
- "Unplanned Downtime"
- means the total time during which the production Trustful Clinical Budgeting platform is unavailable to all or substantially all Users due to a failure of the Service that is within the reasonable control of Trustful Clinical Budgeting. Unplanned Downtime is measured from the time the outage is detected by the Vendor's monitoring systems or reported by the Client (whichever occurs first) until normal production service has been restored.
- "Uptime"
- means the total time in a given calendar month, measured in minutes, during which the Service is available for use, expressed as a percentage of the total time in the same calendar month.
- "User"
- means an individual authorised by the Client to access the TCB platform using unique login credentials.
4. Overview of services
TCB is a cloud-based SaaS platform developed to support the financial planning, budgeting, execution, tracking, analysis, and reporting of clinical trials throughout the study lifecycle. The platform is designed for Sponsors, Contract Research Organizations (CROs), biotechnology companies, and other organisations involved in clinical trial financial management.
Depending on the subscribed services, the TCB platform may include one or more of the following modules:
- RFP
- Client
- Vendor
- Analytics
- SBI (Site&Budget Investigator)
- GlobalOps (Global Operations)
The Vendor continuously enhances the platform through periodic software releases, usability improvements, performance optimisation, security updates, and new functionality. The Service is delivered as a multi-tenant cloud platform and is accessible through supported web browsers via a secure internet connection.
5. Service performance standards
5.1 Uptime Commitment
The Vendor guarantees a minimum Service Uptime of 99.5% per calendar month, which corresponds to approximately 3.5 hours of maximum unplanned downtime per calendar month, depending on the number of days in the month.
The following periods are excluded from the availability calculation:
- Planned Maintenance
- Emergency Maintenance
- Force Majeure events
- Internet outages outside the Vendor's control
- Cloud infrastructure failures outside the Vendor's reasonable control
- Customer network failures
- Customer hardware failures
- Unsupported browser configurations
- Third-party integrations not managed by the Vendor
- Client configuration errors
The Vendor continuously monitors platform availability and performance and will make commercially reasonable efforts to restore normal service as quickly as possible in the event of an unplanned interruption.
5.2 Performance Metrics and KPIs
Trustful Clinical Budgeting is committed to providing a responsive, reliable, and high-performing cloud platform that supports the financial management of clinical trials throughout the study lifecycle.
The performance targets described below represent the Vendor's operational objectives under normal operating conditions and are intended to provide Clients with an indication of expected platform performance. Actual performance may vary depending on data volume, concurrent system usage, internet connectivity, browser configuration, third-party infrastructure, and other environmental factors beyond the Vendor's reasonable control.
| Performance Metric | Target Performance |
|---|---|
| Platform Availability | ≥ 99.5% per calendar month |
| User Authentication (Login) | Typically completed within 5 seconds |
| Standard Page Loading | Typically within 3 seconds |
| Navigation Between Platform Modules | Typically within 3 seconds |
| Dashboard and Analytics Loading | Typically within 10 seconds, depending on the volume and complexity of the data displayed |
| Standard Report Generation | Typically completed within 30 seconds |
| Invoice Generation | Typically completed within 30 seconds |
| Excel Export | Typically completed within 1 minute |
| Excel Import Processing | Typically completed within 5 minutes for standard project files* |
*Processing times for Excel imports may vary depending on the size of the uploaded file, the complexity of the data structure, the number of validation rules performed during import, and current system workload.
The Vendor continuously monitors platform performance and regularly implements software enhancements, infrastructure improvements, database optimisation, and performance tuning activities to maintain an efficient user experience.
The Vendor reserves the right to introduce additional monitoring metrics and performance improvements as the TCB platform evolves.
Performance Exclusions
The performance targets described in this Section do not apply where delays or reduced performance result from circumstances outside the reasonable control of the Vendor, including but not limited to:
- Client internet connectivity or network performance;
- Client hardware or workstation limitations;
- Unsupported or outdated web browsers;
- Third-party software, integrations, or external services;
- Very large customer-specific datasets or unusually complex reporting requests;
- Force majeure events;
- Scheduled or Emergency Maintenance performed in accordance with this Agreement.
Performance targets described in this Section constitute operational objectives and shall not be interpreted as individual guaranteed response times for every user transaction or platform request.
5.3 Measurement
The Vendor continuously monitors the availability, performance, and operational health of the TCB platform using commercially reasonable monitoring and logging tools. Vendor shall measure Service performance using industry-standard monitoring tools.
5.4 Service Warranty
TCB uses commercially reasonable efforts to provide a reliable and continuously available Service in accordance with the commitments described in this Service Level Agreement.
Except as expressly stated in this SLA or the applicable Software License Agreement, the Service is provided on an "as available" basis. The Vendor does not warrant that the Service will be uninterrupted, error-free, or free from defects at all times. The Vendor will use commercially reasonable efforts to promptly investigate and resolve reported Incidents in accordance with the response targets defined in this Agreement.
6. Support and maintenance
6.1 Support Availability
Support Services are intended to assist Clients with issues affecting the normal use of the Platform, including incident investigation, troubleshooting, defect resolution, user guidance, and general technical assistance. The Vendor shall provide technical support during the following hours:
- Standard Support: Monday to Friday, 9:00 AM to 5:00 PM Eastern Time, excluding national holidays.
- Extended Support (if applicable): 24 hours a day, 7 days a week, 365 days a year.
6.2 Support Channels
The Vendor shall provide support through the following channels:
- Email Support: support@trustfulclinical.com
- Live Teams Chat per Client: Available during standard support hours
6.3 Support Scope
Standard Support includes assistance with:
- User login and authentication issues;
- Platform availability and access issues;
- Errors affecting platform functionality;
- Budget management and workflow issues;
- Invoice management functionality;
- Dashboard and Analytics functionality;
- Excel import and export functionality;
- User administration and role management;
- Investigation of suspected software defects;
- Questions relating to the standard functionality of the Platform.
Support also includes guidance on the intended use of existing platform features and assistance in diagnosing reported issues.
6.4 Support Exclusions
Unless otherwise agreed in writing, Standard Support does not include:
- Development of new functionality;
- Custom reports or dashboards;
- Custom integrations with third-party systems;
- Consultancy services;
- Configuration work outside the agreed implementation scope;
- Data migration projects;
- User training beyond the agreed implementation period;
- Recovery of data deleted by the Client;
- Issues caused by third-party software or infrastructure outside the Vendor's control.
Requests outside the scope of Standard Support may be delivered under a separate Software License Agreement.
6.5 Incident Management
All reported Incidents are managed through a structured incident management process consisting of the following stages:
- Incident Logging
- Incident Classification
- Initial Investigation
- Severity Assessment
- Root Cause Analysis (where applicable)
- Resolution or Workaround
- Client Confirmation
- Incident Closure
Throughout the Incident lifecycle, the Vendor will keep the Client informed regarding the progress of material Incidents.
Each Incident will be assigned a Severity Level based on:
- Business impact;
- Number of affected users;
- Availability of a workaround;
- Effect on critical business processes;
- Urgency of resolution.
The Vendor reserves the right to adjust the assigned Severity Level following investigation where appropriate.
Severity 1 – Critical
A Critical Incident is one that causes a complete loss of the production Service or prevents substantially all Users from performing essential business activities. No reasonable workaround is available.
Severity 2 – High
A High Severity Incident significantly affects important platform functionality but does not prevent all Users from working. A temporary workaround may exist.
Severity 3 – Medium
A Medium Severity Incident affects individual features but allows Users to continue working.
Severity 4 – Low
Low Severity requests include:
- General questions;
- Cosmetic issues;
- Enhancement requests;
- Feature suggestions;
- Documentation clarification;
- Minor usability improvements.
These requests do not materially affect normal business operations.
6.6 Planned Maintenance
To maintain the security, stability, and performance of the Platform, the Vendor performs periodic maintenance activities.
These activities may include:
- Software updates;
- Security patches;
- Infrastructure maintenance;
- Database optimisation;
- Performance improvements;
- Deployment of new functionality.
Whenever reasonably possible, Planned Maintenance will:
- Be scheduled outside normal Business Hours;
- Be communicated to Clients at least 72 hours in advance;
- Minimise disruption to production services.
6.7 Emergency Maintenance
Emergency Maintenance may be performed without prior notice where necessary to:
- Address critical security vulnerabilities;
- Protect Client Data;
- Restore platform stability;
- Prevent service interruption;
- Resolve critical infrastructure failures.
Emergency Maintenance shall not be considered Unplanned Downtime for the purposes of Service Availability calculations.
6.8 Platform Updates
Trustful Clinical Budgeting continuously improves the Platform through regular software releases.
Updates may include:
- New features;
- Performance improvements;
- Security enhancements;
- Regulatory updates;
- Bug fixes;
- User interface improvements;
- Analytics enhancements.
Platform updates included within the Client's subscription are provided without additional licence fees unless otherwise agreed.
The Vendor will use commercially reasonable efforts to ensure that updates remain backward compatible with existing platform functionality.
6.9 Feature Changes
TCB continuously develops and improves the Platform. The Vendor may introduce new features, modify existing functionality, replace components, or discontinue obsolete features as part of the ongoing evolution of the Service.
The Vendor will use commercially reasonable efforts to ensure that such changes do not materially reduce the overall functionality of the subscribed Service.
Where a material functional change may significantly affect the Client's use of the Platform, the Vendor will make commercially reasonable efforts to provide advance notice through appropriate communication channels.
7. Client responsibilities
7.1 Required Client Actions
To enable effective delivery of the Service, the Client agrees to:
- Maintain accurate User information;
- Ensure Users protect their login credentials;
- Assign appropriate User permissions;
- Maintain reliable internet connectivity;
- Use supported web browsers;
- Promptly report suspected Incidents;
- Provide sufficient information to enable investigation;
- Test configuration changes where requested;
- Notify the Vendor of changes to authorised contacts.
The Client is responsible for the accuracy, completeness, and legality of all Customer Data entered into the Platform.
7.2 Supported Browsers
The Client is responsible for accessing the Platform using supported web browsers.
Trustful Clinical Budgeting supports the two most recent stable versions of the following browsers:
- Google Chrome
- Microsoft Edge
- Mozilla Firefox
- Apple Safari
Use of unsupported or outdated browsers may result in reduced functionality or degraded performance and is excluded from the Service Level commitments described in this Agreement.
7.3 Fair Use
The Client shall use the Platform in a reasonable manner consistent with its intended purpose and shall not intentionally or negligently use the Service in a way that materially degrades platform performance, compromises security, or adversely affects other Clients.
The Client shall not intentionally upload excessive volumes of data, perform automated activities beyond the intended use of the Platform, or otherwise use the Service in a manner that places an unreasonable burden on the Platform's infrastructure.
Where the Vendor reasonably determines that such use materially impacts the performance, availability, or security of the Service, the Vendor may take proportionate measures to protect the Platform, including temporarily limiting the affected activity while working with the Client to resolve the issue.
7.4 Notification of Issues or Incidents
The Client shall promptly report any Service issues or Incidents to the Vendor through the designated support channels.
When reporting an Incident, the Client shall provide:
- A detailed description of the issue.
- Steps to reproduce the issue, if applicable.
- Any error messages received.
- Impact assessment (number of users affected, business processes impacted).
- Any additional information requested by the Vendor to facilitate resolution.
8. TCB responsibilities
The Vendor shall use commercially reasonable efforts to:
- Maintain the availability of the production Platform in accordance with this SLA;
- Monitor the operational health of the Platform;
- Perform regular system backups;
- Apply security patches and software updates;
- Investigate reported Incidents in a timely manner;
- Maintain appropriate technical and organisational security measures;
- Protect Customer Data from unauthorised access;
- Maintain an audit trail of significant system activities where applicable;
- Continuously improve the functionality, security, and performance of the Platform.
The Vendor will regularly review support trends, incident history, and Client feedback to identify opportunities for continuous improvement and enhance the overall quality of the Service. While the Vendor maintains commercially reasonable administrative, technical, and organisational safeguards to protect the confidentiality, integrity, and availability of Customer Data, no internet-based service, software application, or electronic communication system can be guaranteed to be completely secure or free from vulnerabilities. The Vendor continuously monitors and improves its security controls as part of its ongoing information security program.
8.1 Customer Data Backup and Recovery
The Vendor performs regular backups of the production environment to support disaster recovery and business continuity objectives. Backup copies are maintained for disaster recovery purposes and are not intended to replace the Client's own business records or internal data retention processes. Where technically feasible, the Vendor will use commercially reasonable efforts to assist in the recovery of Customer Data following an unintended data loss event. However, restoration of individual records, files, or historical data cannot be guaranteed in all circumstances.
9. SLA Exclusions
The following circumstances shall be excluded from Downtime calculations and Service Level obligations:
9.1 Force Majeure Events
Events beyond the reasonable control of the Vendor, including but not limited to:
- natural disasters;
- flood, fire, earthquake, or severe weather conditions;
- acts of government or regulatory authorities;
- war, terrorism, civil unrest, or armed conflict;
- strikes or labour disputes;
- widespread internet or telecommunications failures;
- denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks;
- pandemic or public health emergency;
- widespread cyber security incidents affecting third-party infrastructure;
- failures of utility providers;
- failures of cloud infrastructure providers outside the Vendor's reasonable control;
- or any other event beyond the Vendor's reasonable control that materially affects the delivery of the Service.
9.2 Scheduled Maintenance
Any Scheduled Maintenance performed during the designated Maintenance Windows communicated to the Client.
9.3 Client-caused Disruptions
Service unavailability caused by the Client's acts or omissions, including but not limited to:
- Unauthorized modifications to the Service by the Client.
- Client's equipment, software, or network connections.
- Client's breach of its obligations under this Agreement or the Software License Agreement.
- Client's negligence or willful misconduct.
9.4 Third-party Service Interruption
Service unavailability due to failures of third-party services or infrastructure outside the Vendor's direct control, including but not limited to:
- Internet connectivity issues not attributable to the Vendor.
- Failures of third-party hosting providers, data centers, or cloud service providers.
- Failures of third-party applications or services integrated with the Service.
9.5 Beta or Trial Services
Any features or services designated as beta, preview, trial, or evaluation are provided "as is" and are excluded from the SLA guarantees.
10. Term and termination
10.1 Term
This SLA shall commence on the Effective Date and shall continue for the duration of the Software License Agreement, unless earlier terminated in accordance with this Section 10.
10.2 Renewal
This SLA shall automatically renew concurrently with the renewal of the Software License Agreement, unless either Party provides written notice of non-renewal at least 30 days prior to the end of the then-current term.
10.3 Effect of Termination
Upon termination or expiration of this SLA for any reason:
- The Vendor shall cease providing the Service to the Client.
- The Client shall pay all undisputed fees accrued through the effective date of termination.
11. Governing law
This Service Level Agreement shall be governed by and interpreted in accordance with the laws of the Portuguese Republic.
12. Miscellaneous
12.1 Amendment
The Vendor may revise or update this SLA from time to time to reflect improvements to the Service, operational practices, technological advancements, or applicable legal and regulatory requirements. The most current version of this SLA will be published on the Trustful Clinical Budgeting website and shall supersede all previous versions as of its effective date. Continued use of the Services following the publication of an updated SLA constitutes acceptance of the revised terms, except where otherwise agreed in writing between the Parties.
12.2 Severability
If any provision of this Service Level Agreement is determined to be invalid, illegal, or unenforceable by a court or other competent authority, the remaining provisions shall remain in full force and effect.
12.3 Language
This Service Level Agreement is published in the English language. In the event that translations are provided for convenience, the English version shall prevail in the event of any inconsistency or conflict.
13. Statement of changes
| Version | Date | Section Changed | Change |
|---|---|---|---|
| 1.0 | 11-Nov-2025 | Initial release |