Cloud infrastructure management

Service legal standards — Infrastructure management – AutoScaling – Multi-AZ – IAM – CMP

Documentation codeTCPL-14
Version1.0
Effective date18/08/2026
Review date18/08/2027
Department in chargeLegal

PART I - PURPOSE AND SCOPE

1.1. This Documentation sets forth the legal standards, terms of provision, and terms of use for the cloud infrastructure management service group: AutoScaling, Multi-AZ, IAM, and cloud management platform (CMP) (hereinafter referred to as the “Service”) provided by Pho Tue SoftWare Solutions Joint Stock Company (brand HiTechCloud, hereinafter referred to as “HiTechCloud”) to organizations and individuals registering to use the service (hereinafter referred to as the “Customer”).

1.2. The scope of application includes HiTechCloud cloud infrastructure management features and services: autoscaling mechanism (AutoScaling), multi-availability zone deployment (Multi-AZ), identity and access permissions management system (IAM), and centralized cloud management platform (Cloud Management Platform – CMP).

1.3. This Documentation is an integral part of the Service Agreement between HiTechCloud and the Customer, along with the policy system published at https://hitechcloud.vn/tai-lieu-ho-tro/. In the event of a conflict, the terms of any separate written agreement between the two Parties shall take precedence, followed by this Documentation, and finally the general published policies.

Part II – Definitions

2.1. “IAM”: the identity management, Authentication, and Permissions system for Users, user groups, and API keys in the Customer's Account.

2.2. “RBAC”: a role-based permissions model in which access rights are assigned to roles and users are assigned to roles.

2.3. “Principle of least privilege”: the principle that each account and role is granted only the exact and necessary permissions required for the job, without excess privileges.

2.4. “Audit Log”: a log recording administrative actions (who, what, when, from where) on accounts and resources, used for tracing and reconciliation.

2.5. “AutoScaling”: a mechanism that automatically increases or decreases the quantity/configuration of resources according to threshold policies configured by the Customer.

2.6. “Multi-AZ”: a resource deployment model across multiple availability zones separated by power, cooling, and networking to increase fault tolerance.

Part III – Service description and configuration

3.1. The CMP platform provides a centralized management interface for all of the Customer's Cloud resources: provisioning, configuration, Monitoring, Alerts, and cost reporting. The IAM system allows the Customer to create users, roles, and access policies according to the RBAC model; HiTechCloud recommends applying the principle of least privilege and multi-factor authentication for administrative accounts.

3.2. All administrative actions via CMP and API are recorded in the Audit Log with timestamps, operator identifiers, and source addresses; the Audit Log is retained for a minimum of 90 (ninety) days and the Customer may export it to their own system. Administrative actions by HiTechCloud human resources on Customer resources (when delegated for support) are also logged for reconciliation.

3.3. AutoScaling policies (trigger thresholds, maximum/minimum limits, scaling steps) are configured entirely by the Customer. Resources automatically provisioned by the system in accordance with the Customer's policy are billed as manually provisioned resources; the Customer is solely responsible for all costs arising from policies they configure, including when consumption increases due to abnormal Traffic or improper threshold configuration.

3.4. Multi-AZ deployment increases fault tolerance at the infrastructure layer but does not automatically guarantee application continuity; the Customer is responsible for designing applications compatible with failover between availability zones.

Part IV – SLA and compensation

4.1. HiTechCloud commits to a minimum CMP Admin portal and management API availability of 99.9% (ninety-nine point nine percent) per month; commits that the AutoScaling mechanism executes according to configured policies under conditions where infrastructure has available resources and the Customer's configuration is valid.

4.2. SLA does not apply to: consequences of scale policies or IAM policies misconfigured by the Customer; unauthorized account access due to the Customer exposing Authentication information or failing to enable Multi-factor authentication; interruptions of individual single resources that fall under the SLA of the respective service.

4.3. The sole form of compensation when HiTechCloud commits an SLA commitment Violation is a fee credit in the subsequent Billing cycle according to the credit rate table published at https://hitechcloud.vn/tai-lieu-ho-tro/. The Customer must submit a credit request within 30 (thirty) days from the time the Incident occurred accompanied by supporting data; SLA does not apply to Maintenance time notified at least 48 (forty-eight) hours in advance, Force majeure events, errors arising from the Customer's systems, applications, configurations, or actions, or errors from third-party Providers beyond the reasonable control of HiTechCloud.

4.4. The total Indemnity of HiTechCloud arising out of or related to the Service shall under no circumstances exceed the total Service fee actually paid by the Customer for the most recent Billing cycle. HiTechCloud is not liable for indirect damages, consequential damages, lost profits, lost business opportunities, business interruption, data loss caused by Customer fault, or damage to commercial reputation, even if advised in advance of the possibility of such damages.

PART V - FEES AND PAYMENT

5.1. The Customer shall pay 100% (one hundred percent) of the service fee for each cycle in advance within 03 (three) working days from the date HiTechCloud releases a fee notification, payment request, or invoice. The Service is only initialized or renewed after HiTechCloud receives full payment; paid fees are non-refundable except as expressly provided in this documentation or in the refund policy published at https://hitechcloud.vn/tai-lieu-ho-tro/.

5.2. Late payments incur late interest of 0.05%/day (zero point zero five percent per day) calculated on the overdue amount and the actual number of overdue days. HiTechCloud reserves the right to execute Service suspension after 07 (seven) days from the due date if payment is not received and Service termination after 15 (fifteen) days; all risks and damages arising from service suspension or termination due to late payment are the Customer's responsibility.

5.3. Resource costs arising from AutoScaling and provisioning operations via CMP/API are recorded based on actual usage and aggregated in the fee notice of the period; the Customer has budget Alert tools and is responsible for setting appropriate Alert thresholds.

5.4. Service fees are calculated based on the registered cycle (monthly, quarterly, or annual) according to the configuration and price schedule published at the time of subscription or Renewal. Mid-cycle configuration Upgrades are charged the difference prorated over the remaining time; Downgrades apply only from the subsequent cycle and do not incur any Obligation to refund the difference.

5.5. Service fees do not include value-added tax and other taxes, fees, and charges under legal regulations (if any). HiTechCloud releases valid e-invoices for each billing cycle; pricing schedules may be adjusted for subsequent cycles with at least 30 (thirty) days' prior notification and will not apply retroactively to already paid cycles.

PART VI – RIGHTS AND OBLIGATIONS OF THE PARTIES

6.1. HiTechCloud has the Obligation to: maintain CMP, IAM, and Audit Logs as described; enforce the principle of least privilege for access by HiTechCloud Human resources to the Customer's environment and only access when granted Delegation or required by Law; provide transparent cost reporting tools; and notify Maintenance at least 48 (forty-eight) hours in advance.

6.2. HiTechCloud reserves the right to: (i) require the Customer to provide accurate and complete identification information upon registration and upon request by a competent State authority; (ii) suspend part or all of the Services upon detecting signs of a Law Violation or Violation of this Documentation; (iii) perform infrastructure Maintenance and Upgrade with at least 48 (forty-eight) hours of prior notice, except in Critical cases to prevent an Information security Incident; (iv) modify the infrastructure architecture provided that it does not reduce the committed service quality.

6.3. The Customer has the Obligation to: manage the Lifecycle of users and API keys, revoking permissions of Human resources upon Resignation; enforce internal RBAC and least privilege; conduct Periodic reviews of Audit Logs; configure and assume responsibility for autoscaling policies and incurred costs; and secure authentication credentials while enabling multi-factor authentication for privileged accounts.

6.4. The Customer has the right to: (i) use the Service according to registered and published configurations and specifications; (ii) request technical support through HiTechCloud's official channels; (iii) request fee credits when HiTechCloud is in Violation of the SLA pursuant to Part IV; and (iv) receive notifications regarding Maintenance, policy changes, and price schedule adjustments within the timelines specified in this document.

Part VII – Acceptable use and prohibited conduct

7.1. The Customer must not use the Service to store, transmit, or disseminate information in Violation of Vietnamese law, including, but not limited to: content infringing on national security or opposing the State; pornographic, depraved, gambling, or superstitious content; fraudulent information or impersonation of Organizations or individuals; content infringing upon Intellectual property rights, Trade secrets, or personal data of a Third party; and malware, vulnerability exploit code, or cyberattack tools under the Regulations of the Cybersecurity Law (Luật An ninh mạng) 2018, the Law on Cyberinformation Security (Luật An toàn thông tin mạng) 2015, and Decree 53/2022/ND-CP (Nghị định 53/2022/NĐ-CP).

7.2. It is strictly prohibited to share privileged accounts among multiple unidentified individuals; scan or exploit CMP/IAM vulnerabilities, engage in login session Spoofing, or execute unauthorized privilege escalation; and use management APIs to generate disruptive load or exceed platform anti-Abuse Quotas.

7.3. Deleting, modifying, or concealing Audit Logs or interfering with Logging mechanisms is strictly prohibited; any intentional act to erase traces is deemed a serious Violation and constitutes grounds for Service termination under Part IX.

7.4. Upon detecting prohibited acts, HiTechCloud reserves the right to immediately suspend the relevant Service without prior notice, preserve evidence, notify, and coordinate with competent state authorities in accordance with legal regulations. The Customer assumes full legal liability and shall indemnify all damages caused to HiTechCloud or third parties arising from violations committed by itself or by end users under the Customer's management.

Part VIII – Security and personal data

8.1. Both Parties commit to Compliance with the Law on Personal Data Protection No. 91/2025/QH15 (Luật Bảo vệ dữ liệu cá nhân số 91/2025/QH15) and Decree No. 356/2025/NĐ-CP detailing a number of Articles of the Law on Personal Data Protection (Nghị định số 356/2025/NĐ-CP quy định chi tiết một số điều của Luật Bảo vệ dữ liệu cá nhân). For Personal data that the Customer collects, stores, and processes on the Service infrastructure, the Customer is the Personal Data controller and is responsible for the legal basis of processing and the Consent of the Data subject; HiTechCloud is the Personal Data processor, processing only to the extent necessary to provide the Service per lawful instructions of the Customer.

8.2. User identity information in IAM (full name, email, login logs) is personal data processed under the Law on Personal Data Protection (Luật Bảo vệ dữ liệu cá nhân) No. 91/2025/QH15 and Decree No. 356/2025/ND-CP for the sole purpose of authentication, permissions, and ensuring account security; Audit Logs are only provided to the Customer owning the account or competent state authorities upon lawful request.

8.3. Each Party has the obligation to maintain the confidentiality of contract information, configuration information, technical information, data, and trade secrets of the other Party obtained during the provision and use of the Service; and not disclose them to third parties without prior written consent, except when provided pursuant to a lawful request from a competent state authority. The confidentiality obligation remains valid for 02 (two) years after Service termination.

PART IX – SUSPENSION AND TERMINATION

9.1. HiTechCloud reserves the right to suspend part or all of the Service in the following cases: (i) Customer is overdue on Payment by more than 07 (seven) days from the due date; (ii) Customer commits a Violation of the acceptable use Regulation in Part VII; (iii) at the request of a competent State authority; (iv) when there is a Critical need to prevent Information security risks to the shared system or to other customers. Suspension time due to Customer Error is not counted toward the SLA and does not give rise to a refund Obligation.

9.2. The Service terminates when: (i) the Customer delays Payment by more than 15 (fifteen) days from the due date; (ii) a Party commits a serious Violation and fails to remedy it within 15 (fifteen) days from the date of receiving written Notification from the other Party; (iii) the term of use expires and the Customer does not perform a Renewal; (iv) both Parties reach a written Agreement on termination; or (v) under a decision of a competent State authority.

9.3. Within 07 (seven) days from the Service termination date, the Customer has the right to request the export of its data in standard formats supported by the system; data export support costs (if any) shall follow the published fee schedule. After the aforementioned period, all Customer data will be permanently deleted from the system, cannot be Restored, and HiTechCloud shall have no further retention Obligation unless otherwise provided by law.

PART X – VALIDITY AND APPLICABLE LAW

10.1. This Documentation takes effect from the date of issuance and applies to all service cycles initiated or renewed after the Effective date. Contracts, Appendices, minutes, and service confirmation slips signed with a valid Digital signature in accordance with the Law on Electronic Transactions No. 20/2023/QH15 (Luật Giao dịch điện tử số 20/2023/QH15) and Decree No. 23/2025/NĐ-CP on electronic signatures and trust services (Nghị định số 23/2025/NĐ-CP về chữ ký điện tử và dịch vụ tin cậy) have legal validity equivalent to physically signed and stamped documents.

10.2. This Documentation is governed by and construed in accordance with Vietnamese law. Any arising dispute shall first be resolved through negotiation and mediation within 30 (thirty) days; if an agreement is not reached, the dispute shall be submitted to the competent People's Court in Ho Chi Minh City for resolution.

10.3. In the event that any Terms of this Documentation are declared invalid or unenforceable, the remaining Terms shall remain in full force and Validity. This Documentation, together with the Service Agreement and policies published at https://hitechcloud.vn/tai-lieu-ho-tro/, constitutes the entire Agreement between the Parties regarding the Service.

Documentation issued by HiTechCloud and subject to amendment with 30-day prior notification on https://hitechcloud.vn/tai-lieu-ho-tro/.

Revision history

Current version (v1.0)by
Updatedby HiTechCloud
Follow category: Cloud infrastructure managementGet notified when new documents are added to this category.

If this article did not answer your question, please contact HiTechCloud for help.

Contact