Service Level Agreement
Supplier: Isodora AB, org.nr 559565-0424, Svampvägen 167, 122 63 Enskede, Sweden
Zuletzt aktualisiert: 18. September 2026
Dieses SLA beschreibt die Servicelevel der Isodora-Plattform. Die Stufe Standard (Target) gilt, sofern in einem Order Form über sales@isodora.se nichts Höheres vereinbart ist.
1. Definitions
“Availability” means the ability for Customer to authenticate and access core features of the Service via the public internet.
“Downtime” means minutes during which the Service is unavailable, excluding the Exclusions in section 6.
“Monthly Period” means a calendar month.
“Service Credits” means the credits described in section 5 and are Customer’s sole monetary remedy for failure to meet an Availability commitment, unless mandatory law provides otherwise.
“Core Features” means: (i) login and user session, (ii) access to projects and frameworks, (iii) viewing and managing analysis outputs and tasks, and (iv) database-backed retrieval of Customer content stored in the Service.
2. Scope of this SLA
This SLA covers:
- The Isodora web application and APIs (Next.js hosted on Vercel).
- Database access and storage required for the Service (Supabase).
- Essential transactional emails used by standard flows (e.g., invitations, verification, notifications) delivered via Resend, subject to third-party exclusions.
This SLA does not cover
- AI output quality, correctness, completeness, or model behavior.
- Outages caused by third parties outside Supplier’s control (see section 6), including incidents at Vercel, Supabase, Resend, OpenAI / Vercel AI Gateway, Opper, Azure OpenAI, Mistral, Stripe, Sentry, and LangChain/LangSmith.
- Customer’s own network, device, browser, identity provider (SSO/IdP), or security configurations.
- Beta/preview features or modules explicitly marked as “best effort”.
- Planned maintenance as described in section 6.
3. Data residency and hosting
Supplier configures the Service to use EU-based hosting and data residency for each underlying provider where supported by the selected plan and configuration. Database hosting (Supabase) uses EU (Stockholm, eu-north-1) or US (us-east-1) depending on where the customer organisation was created, matching the Sub-processors page. AI agent monitoring (LangSmith) is configured with EU data residency when enabled. Application hosting (Vercel), email delivery (Resend), and default-profile AI model inference (OpenAI) are provided by US-based providers that rely on Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework. Customer acknowledges that certain operational metadata, support logs, and platform telemetry may be processed outside the EU in accordance with each provider’s terms and the parties’ data processing agreement.
4. Service Levels
Supplier offers the following SLA tiers. The Standard (Target) tier applies by default. Business and Enterprise require an Order Form via sales@isodora.se.
5. Service Credits (Business and Enterprise)
Service Credits are calculated on the fixed monthly subscription fee for the portion of the Service covered by this SLA, excluding one-time fees, professional services, usage-based AI costs, and third-party passthrough fees.
If measured Availability for a Monthly Period is below the committed level, Customer may claim: 99.9% down to 99.0% — 5% credit; 99.0% down to 95.0% — 10% credit; below 95.0% — 25% credit.
Credit cap: total Service Credits are capped at 50% of the relevant monthly subscription fee per Monthly Period, unless otherwise agreed in writing.
Claim process: Customer must submit a written request to legal@isodora.se within 30 days after the end of the affected Monthly Period, including the timeframe, description, and supporting evidence. Supplier’s measurements and logs are the primary reference.
Payment: Service Credits are applied as a credit on the next invoice. No cash refunds.
6. Exclusions (not counted as Downtime)
The following do not count as Downtime and are excluded from Availability calculations:
- Planned maintenance notified at least 48 hours in advance. Supplier will normally schedule maintenance outside business hours. Up to 2 hours of planned maintenance per month is excluded.
- Third-party incidents outside Supplier’s reasonable control, including outages of Vercel, Supabase, Resend, OpenAI, Vercel AI Gateway, Opper, Azure OpenAI, Mistral, Stripe, Sentry and/or LangChain/LangSmith, or the public cloud/network infrastructure they rely on.
- Issues caused by Customer’s configuration, integrations, scripts, misuse, violation of rate limits, or security policies.
- Force majeure events.
7. Support, incident handling, and communications
7.1 Severity: Sev-1 (Critical) — Service largely unusable or a significant risk to data integrity. Sev-2 (High) — material feature impaired; workaround may exist. Sev-3 (Medium) — non-critical feature issue or degraded performance. Sev-4 (Low) — questions, minor bugs, feature requests.
7.2 Response time targets (not resolution guarantees). Standard: Sev-1 within 8 business hours; Sev-2 within 1 business day; Sev-3 within 2 business days; Sev-4 within 5 business days. Business: Sev-1 within 4 business hours; Sev-2 within 1 business day; Sev-3 within 2 business days; Sev-4 within 5 business days. Enterprise (unless otherwise agreed): Sev-1 within 1 hour (24/7 if agreed), otherwise within 2 business hours; Sev-2 within 4 business hours; Sev-3 within 1 business day; Sev-4 within 5 business days.
7.3 For Sev-1 incidents, Supplier will provide an initial status update as soon as practicable after confirmation, then updates at least every 4 hours during business hours. For Sev-2, updates at least daily during business hours until resolved. For Sev-1, Supplier may provide a root-cause summary within 10 business days after restoration.
8. Availability measurement
Availability (%) = (Total minutes in period – Downtime minutes) / Total minutes in period × 100.
Supplier measures availability primarily using Supplier monitoring and logs (application health, API reachability, and error rates). Short interruptions under 5 minutes may be aggregated if recurring and materially affecting use.
9. Backups and disaster recovery targets
Supplier configures database backups through Supabase according to Supplier’s configuration.
Targets (best effort, not guarantees): RPO up to 24 hours; RTO 8–24 hours, depending on incident type, data volume, and third-party constraints.
10. Changes to this SLA
Supplier may update this SLA to reflect changes in the Service, underlying providers, or security requirements. Material adverse changes will be notified at least 30 days in advance via email to the account administrator. Enterprise changes follow the Order Form.
11. Third-party dependencies and pass-through
The Service depends on third-party providers for hosting, database, email delivery, AI model inference, payments, error monitoring, and agent monitoring. Supplier cannot provide service levels that exceed what these providers enable for the applicable plan and delivery. Where third-party terms or incidents constrain Supplier’s ability to meet an SLA commitment, Supplier will use commercially reasonable efforts to escalate and restore service but is not responsible for third-party breaches outside Supplier’s reasonable control.
SLA tiers
Customer’s tier is specified in the Order Form or Agreement. If none is specified, Standard (Target) applies.
| Tier | Availability | Support hours | Service credits |
|---|---|---|---|
| Standard (Target) | 99.5% target (not a guarantee) | Business hours (Mon–Fri 09:00–17:00 CET/CEST) | No |
| Business (Committed, conditional) Requires Order Form via sales@isodora.se. | 99.9% per Monthly Period | Business hours (Mon–Fri 09:00–17:00 CET/CEST) | Yes |
| Enterprise (Committed, conditional) Requires Order Form via sales@isodora.se. | 99.95% per Monthly Period | As agreed (may include 24/7 for Sev-1) | Yes (as agreed) |
4.1 Standard (Target)
Availability target: 99.5% per Monthly Period (target only; no service credit commitment). Support: business hours, response targets in section 7. This is the default tier.
4.2 Business (Committed, conditional)
Availability commitment: 99.9% per Monthly Period, subject to the conditions below. The Business commitment applies only to the extent the critical third-party services used for Customer’s production environment are on SLA-eligible plans, and Customer uses the Service in accordance with the Agreement. If conditions are not met, Standard (Target) applies. Business requires an Order Form via sales@isodora.se.
4.3 Enterprise (Committed, conditional)
Availability commitment: 99.95% per Monthly Period, subject to agreed prerequisites (SLA-eligible plans with critical providers, agreed incident contacts and escalation paths, and any additional controls in the Order Form). If prerequisites are not met, the Business or Standard tier applies as appropriate. Enterprise requires an Order Form via sales@isodora.se.
11.1 Third-party provider overview
The Service depends on third-party providers. This table is rendered from the same data source as the public Sub-processors page. Supplier cannot provide service levels that exceed what these providers enable for the applicable plan.
| Provider | Current plan | Role | Provider SLA | Data location |
|---|---|---|---|---|
| OpenAI, L.L.C. | Standard API | KI-Inferenz, Embeddings und Interview-Sprache-zu-Text für das Standard-US-Modellprofil. Wird nicht für Chat, Analyse, Dokumentenerstellung oder Transkription genutzt, wenn dem Mandanten ein in der EU gehostetes Paket zugewiesen ist. | None (best-effort) | Vereinigte Staaten |
| Opper Technology AB | As contracted | EU-KI-Gateway (Stockholm). Leitet Prompts und Modellausgaben für Opper-gestützte Profile weiter, einschließlich der in der EU gehosteten Azure- und Mistral-Pakete. | None (best-effort) | Schweden (AWS eu-north-1, Stockholm) |
| Microsoft Ireland Operations Limited (Azure OpenAI) | Azure OpenAI (Sweden) | Azure-OpenAI-Inferenz in Schweden für Organisationen mit dem Azure-GPT- oder gemischten EU-Paket (Chat, Analyse, Dokumentenerstellung und zugehörige Sprache-zu-Text über den EU-Katalog). | Azure service SLA (conditional on plan) | Schweden (Azure Sweden) |
| Mistral AI SAS | API | In der EU gehostete Sprachmodelle und Voxtral-Sprache-zu-Text in Frankreich für Organisationen mit dem Mistral- oder gemischten EU-Paket. | None (best-effort) | Frankreich |
| Supabase, Inc. | Pro (paid) | Datenbank, Dateispeicher und Authentifizierung | None (best-effort) | EU (eu-north-1, Stockholm) oder USA (us-east-1) — entsprechend der Region Ihres Mandanten |
| Vercel, Inc. | Pro | Serverless-Computing und Content Delivery (CDN) | None (best-effort) | Vereinigte Staaten (EU-Edge-Regionen für die Auslieferung) |
| Stripe, Inc. | Standard | Abonnement- und Zahlungsabwicklung | Stripe published uptime SLA | Vereinigte Staaten |
| Resend (Plus Five Five, Inc.) | Standard | Versand transaktionaler E-Mails | None (best-effort) | Vereinigte Staaten |
| Functional Software, Inc. (Sentry) | Team | Fehlerverfolgung und Überwachung der Anwendung | None (best-effort) on current plan | Europäische Union, sofern verfügbar, andernfalls Vereinigte Staaten |
| LangChain, Inc. (LangSmith) | Developer (free) | Observability und Tracing von KI-Agenten | None (best-effort) | Europäische Union (LangSmith EU, eu.smith.langchain.com) |
None of the above providers offer a formal uptime SLA on Supplier’s current Standard plans, except where a provider publishes one (for example Stripe or Azure, subject to their terms). The Standard (Target) tier reflects this reality. Business and Enterprise tiers are conditional on upgrading to SLA-eligible plans with the relevant providers (see sections 4.2 and 4.3). Supplier will update this table when plans or providers change.
Anhang A — Kundenauswahl (Standard)
SLA-Stufe: Standard (Target)
Supportkanal: ops@isodora.se
Incident-Kontakt des Anbieters: ops@isodora.se
Ansprüche auf Service Credits: legal@isodora.se