Service Level Agreement

Supplier: Isodora AB, org.nr 559565-0424, Svampvägen 167, 122 63 Enskede, Sweden

Last updated: September 18, 2026

This Service Level Agreement (SLA) describes the service levels for the Isodora platform (the “Service”). It is incorporated into and governed by the applicable Terms of Service (the “Agreement”). In case of conflict, this SLA prevails for service level topics. The Standard (Target) tier applies unless a higher tier is agreed in an Order Form via sales@isodora.se.

1. Definitions

“Availability” means the ability for Customer to authenticate and access core features of the Service via the public internet.

“Downtime” means minutes during which the Service is unavailable, excluding the Exclusions in section 6.

“Monthly Period” means a calendar month.

“Service Credits” means the credits described in section 5 and are Customer’s sole monetary remedy for failure to meet an Availability commitment, unless mandatory law provides otherwise.

“Core Features” means: (i) login and user session, (ii) access to projects and frameworks, (iii) viewing and managing analysis outputs and tasks, and (iv) database-backed retrieval of Customer content stored in the Service.

2. Scope of this SLA

This SLA covers:

  • The Isodora web application and APIs (Next.js hosted on Vercel).
  • Database access and storage required for the Service (Supabase).
  • Essential transactional emails used by standard flows (e.g., invitations, verification, notifications) delivered via Resend, subject to third-party exclusions.

This SLA does not cover

  • AI output quality, correctness, completeness, or model behavior.
  • Outages caused by third parties outside Supplier’s control (see section 6), including incidents at Vercel, Supabase, Resend, OpenAI / Vercel AI Gateway, Opper, Azure OpenAI, Mistral, Stripe, Sentry, and LangChain/LangSmith.
  • Customer’s own network, device, browser, identity provider (SSO/IdP), or security configurations.
  • Beta/preview features or modules explicitly marked as “best effort”.
  • Planned maintenance as described in section 6.

3. Data residency and hosting

Supplier configures the Service to use EU-based hosting and data residency for each underlying provider where supported by the selected plan and configuration. Database hosting (Supabase) uses EU (Stockholm, eu-north-1) or US (us-east-1) depending on where the customer organisation was created, matching the Sub-processors page. AI agent monitoring (LangSmith) is configured with EU data residency when enabled. Application hosting (Vercel), email delivery (Resend), and default-profile AI model inference (OpenAI) are provided by US-based providers that rely on Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework. Customer acknowledges that certain operational metadata, support logs, and platform telemetry may be processed outside the EU in accordance with each provider’s terms and the parties’ data processing agreement.

4. Service Levels

Supplier offers the following SLA tiers. The Standard (Target) tier applies by default. Business and Enterprise require an Order Form via sales@isodora.se.

5. Service Credits (Business and Enterprise)

Service Credits are calculated on the fixed monthly subscription fee for the portion of the Service covered by this SLA, excluding one-time fees, professional services, usage-based AI costs, and third-party passthrough fees.

If measured Availability for a Monthly Period is below the committed level, Customer may claim: 99.9% down to 99.0% — 5% credit; 99.0% down to 95.0% — 10% credit; below 95.0% — 25% credit.

Credit cap: total Service Credits are capped at 50% of the relevant monthly subscription fee per Monthly Period, unless otherwise agreed in writing.

Claim process: Customer must submit a written request to legal@isodora.se within 30 days after the end of the affected Monthly Period, including the timeframe, description, and supporting evidence. Supplier’s measurements and logs are the primary reference.

Payment: Service Credits are applied as a credit on the next invoice. No cash refunds.

6. Exclusions (not counted as Downtime)

The following do not count as Downtime and are excluded from Availability calculations:

  • Planned maintenance notified at least 48 hours in advance. Supplier will normally schedule maintenance outside business hours. Up to 2 hours of planned maintenance per month is excluded.
  • Third-party incidents outside Supplier’s reasonable control, including outages of Vercel, Supabase, Resend, OpenAI, Vercel AI Gateway, Opper, Azure OpenAI, Mistral, Stripe, Sentry and/or LangChain/LangSmith, or the public cloud/network infrastructure they rely on.
  • Issues caused by Customer’s configuration, integrations, scripts, misuse, violation of rate limits, or security policies.
  • Force majeure events.

7. Support, incident handling, and communications

7.1 Severity: Sev-1 (Critical) — Service largely unusable or a significant risk to data integrity. Sev-2 (High) — material feature impaired; workaround may exist. Sev-3 (Medium) — non-critical feature issue or degraded performance. Sev-4 (Low) — questions, minor bugs, feature requests.

7.2 Response time targets (not resolution guarantees). Standard: Sev-1 within 8 business hours; Sev-2 within 1 business day; Sev-3 within 2 business days; Sev-4 within 5 business days. Business: Sev-1 within 4 business hours; Sev-2 within 1 business day; Sev-3 within 2 business days; Sev-4 within 5 business days. Enterprise (unless otherwise agreed): Sev-1 within 1 hour (24/7 if agreed), otherwise within 2 business hours; Sev-2 within 4 business hours; Sev-3 within 1 business day; Sev-4 within 5 business days.

7.3 For Sev-1 incidents, Supplier will provide an initial status update as soon as practicable after confirmation, then updates at least every 4 hours during business hours. For Sev-2, updates at least daily during business hours until resolved. For Sev-1, Supplier may provide a root-cause summary within 10 business days after restoration.

8. Availability measurement

Availability (%) = (Total minutes in period – Downtime minutes) / Total minutes in period × 100.

Supplier measures availability primarily using Supplier monitoring and logs (application health, API reachability, and error rates). Short interruptions under 5 minutes may be aggregated if recurring and materially affecting use.

9. Backups and disaster recovery targets

Supplier configures database backups through Supabase according to Supplier’s configuration.

Targets (best effort, not guarantees): RPO up to 24 hours; RTO 8–24 hours, depending on incident type, data volume, and third-party constraints.

10. Changes to this SLA

Supplier may update this SLA to reflect changes in the Service, underlying providers, or security requirements. Material adverse changes will be notified at least 30 days in advance via email to the account administrator. Enterprise changes follow the Order Form.

11. Third-party dependencies and pass-through

The Service depends on third-party providers for hosting, database, email delivery, AI model inference, payments, error monitoring, and agent monitoring. Supplier cannot provide service levels that exceed what these providers enable for the applicable plan and delivery. Where third-party terms or incidents constrain Supplier’s ability to meet an SLA commitment, Supplier will use commercially reasonable efforts to escalate and restore service but is not responsible for third-party breaches outside Supplier’s reasonable control.

SLA tiers

Customer’s tier is specified in the Order Form or Agreement. If none is specified, Standard (Target) applies.

TierAvailabilitySupport hoursService credits
Standard (Target)99.5% target (not a guarantee)Business hours (Mon–Fri 09:00–17:00 CET/CEST)No
Business (Committed, conditional)
Requires Order Form via sales@isodora.se.
99.9% per Monthly PeriodBusiness hours (Mon–Fri 09:00–17:00 CET/CEST)Yes
Enterprise (Committed, conditional)
Requires Order Form via sales@isodora.se.
99.95% per Monthly PeriodAs agreed (may include 24/7 for Sev-1)Yes (as agreed)

4.1 Standard (Target)

Availability target: 99.5% per Monthly Period (target only; no service credit commitment). Support: business hours, response targets in section 7. This is the default tier.

4.2 Business (Committed, conditional)

Availability commitment: 99.9% per Monthly Period, subject to the conditions below. The Business commitment applies only to the extent the critical third-party services used for Customer’s production environment are on SLA-eligible plans, and Customer uses the Service in accordance with the Agreement. If conditions are not met, Standard (Target) applies. Business requires an Order Form via sales@isodora.se.

4.3 Enterprise (Committed, conditional)

Availability commitment: 99.95% per Monthly Period, subject to agreed prerequisites (SLA-eligible plans with critical providers, agreed incident contacts and escalation paths, and any additional controls in the Order Form). If prerequisites are not met, the Business or Standard tier applies as appropriate. Enterprise requires an Order Form via sales@isodora.se.

11.1 Third-party provider overview

The Service depends on third-party providers. This table is rendered from the same data source as the public Sub-processors page. Supplier cannot provide service levels that exceed what these providers enable for the applicable plan.

ProviderCurrent planRoleProvider SLAData location
OpenAI, L.L.C.Standard APIAI inference, embeddings, and interview speech-to-text for the default US model profile. Not used for chat, analysis, document generation, or transcription when the tenant is assigned an EU-hosted pack.None (best-effort)United States
Opper Technology ABAs contractedEU AI gateway (Stockholm). Routes prompts and model output for Opper-backed profiles, including EU-hosted Azure and Mistral packs.None (best-effort)Sweden (AWS eu-north-1, Stockholm)
Microsoft Ireland Operations Limited (Azure OpenAI)Azure OpenAI (Sweden)Azure OpenAI inference in Sweden for organizations assigned the Azure GPT or mixed EU model pack (chat, analysis, document generation, and related speech-to-text via the EU catalog).Azure service SLA (conditional on plan)Sweden (Azure Sweden)
Mistral AI SASAPIEU-hosted large language models and Voxtral speech-to-text in France for organizations assigned the Mistral or mixed EU model pack.None (best-effort)France
Supabase, Inc.Pro (paid)Database, file storage, and authenticationNone (best-effort)EU (eu-north-1, Stockholm) or US (us-east-1) — matching your tenancy region
Vercel, Inc.ProServerless compute and content delivery (CDN)None (best-effort)United States (EU edge regions for delivery)
Stripe, Inc.StandardSubscription and payment processingStripe published uptime SLAUnited States
Resend (Plus Five Five, Inc.)StandardTransactional email deliveryNone (best-effort)United States
Functional Software, Inc. (Sentry)TeamApplication error tracking and monitoringNone (best-effort) on current planEuropean Union where available, otherwise United States
LangChain, Inc. (LangSmith)Developer (free)AI agent observability and tracingNone (best-effort)European Union (LangSmith EU, eu.smith.langchain.com)

None of the above providers offer a formal uptime SLA on Supplier’s current Standard plans, except where a provider publishes one (for example Stripe or Azure, subject to their terms). The Standard (Target) tier reflects this reality. Business and Enterprise tiers are conditional on upgrading to SLA-eligible plans with the relevant providers (see sections 4.2 and 4.3). Supplier will update this table when plans or providers change.

Appendix A — Customer selections (Standard)

SLA Tier: Standard (Target)

Support channel: ops@isodora.se
Supplier incident contact: ops@isodora.se
Service credit claims: legal@isodora.se