Skip to content

rxnet

Documentation

Cited by
D1, and D3 clause 7.8(d)

Relates to rxnet — Software as a Service. Not a Schedule to the Master Subscription Agreement.


STATUS OF THIS DOCUMENT

(a) This document is published in the Documentation for rxnet, at https://broadstack.com.au/p/rxnet/documentation. Under clause 2.2 of the Master Subscription Agreement, the Documentation forms part of the Agreement and ranks below every other document forming the Agreement.

(b) The Service Level Agreement (Schedule 2) refers to the registers in this document. Each register states the clause that refers to it.

(c) The Provider may update this document. For an incident, the Severity definitions current when the incident is raised apply. For a travel approval, the country register current when the approval is given applies.

(d) The worked availability calculation and the service level summary are explanatory. If either is inconsistent with the Service Level Agreement, the Service Level Agreement prevails.

Last updated: 24 August 2026


1. SEVERITY DEFINITIONS

Referred to by the Service Level Agreement, clause 6.3(c). The definitions current when an incident is raised apply to that incident.

Severity Name Definition Examples
1 Critical The Service is Unavailable, or a core business function is unusable, for all or most Authorised Users. There is no workaround. Or a confirmed security incident affects Customer Data. Complete outage; data corruption; confirmed unauthorised access to Customer Data; login failure affecting all users
2 High A major function is unusable or severely degraded. A workaround exists but it is difficult. A significant group of Authorised Users is affected. A core module fails; severe performance degradation; a report or export function fails for all users
3 Medium A function does not work as documented. A reasonable workaround exists. The business effect is limited. A minor feature fails; incorrect display of data; intermittent error affecting few users
4 Low A cosmetic issue, a documentation error, or a question. There is no effect on business operation. Spelling error in the interface; a request for information; a feature request


2. WORKED AVAILABILITY CALCULATION

Referred to by the Service Level Agreement, clause 3.4. This calculation is explanatory. Clause references below are to the Service Level Agreement.

Scenario

Item Value
Measurement Period A 31 day month
Total Minutes 44,640
Unavailable Minutes recorded 70

Breakdown of Unavailable Minutes

Event Minutes Excluded? Reason
Scheduled Maintenance, notified, within the 4 hour cap 20 Yes Clause 3.5(a)
Customer network fault 10 Yes Clause 3.5(d)
Database fault 30 No Provider fault
Supplier Fault at a transit provider 10 No Clause 3.5A(b)
Total 70

Calculation

Excluded Minutes = 20 + 10 = 30
Downtime         = 70 - 30 = 40
Monthly Availability = ((44,640 - 40) / 44,640) x 100
                     = (44,600 / 44,640) x 100
                     = 99.9103...%
                     = 99.91% (rounded to two decimal places)

Result

99.91% is below the 99.99% commitment. It falls in the band "99.00% to below 99.99%". The Service Credit is 5% of the monthly Fee for the affected Service. See clause 5.2.

The maximum Service Credit in any Measurement Period is 25% of the monthly Fee, under clause 5.6. A month at 97.9% availability and a month at 40% availability both attract a 25% credit.

Second example — no credit payable

If the same month recorded 30 Unavailable Minutes, of which 27 were Excluded Minutes, Downtime would be 3 minutes. Monthly Availability would be ((44,640 - 3) / 44,640) x 100 = 99.99% (rounded to two decimal places). That meets the 99.99% commitment. No Service Credit is payable.



3. SERVICE LEVEL SUMMARY

This summary is explanatory. Clause references are to the Service Level Agreement, which prevails over this summary.

Commitment Target Clause Remedy
Monthly Availability 99.99% 3.1 Service Credit, clause 5.2. Capped at 25% of the monthly Fee, clause 5.6
Supplier Fault (carrier, transit, edge) Counts as Downtime 3.5A(b) No exclusion available
Public Internet Fault Excluded, evidence required 3.5A(c)-(e) Capped at 60 minutes per month, clause 3.5A(f)
Public Signal Interface response, 95th percentile 500 milliseconds ms 3.8 Severity 3 incident
Public Signal Interface response, 99th percentile 1,500 milliseconds ms 3.8 Severity 3 incident
Scheduled Maintenance notice, service-interrupting work 5 Business Days. No fixed window 4.1 Un-notified minutes count as Downtime
Scheduled Maintenance, downtime cap 4 hours per month 4.3 Minutes above the cap count as Downtime
Emergency Maintenance, downtime cap 2 hours per month 4.4(d) Minutes above the cap count as Downtime
Severity 1 response 15 minutes, 24x7 6.4 Escalation, clause 6.6
Severity 1 restoration 4 hours in Business Hours, 8 hours outside Business Hours 6.4 Escalation, clause 6.6
Escalation Three levels, time triggered. Roles may be held by one individual 6.6 Customer notification and Severity 1 update cadence at Level 3
Response target achievement 95% of the Customer’s incidents, per Severity 6.5
On-Premises Component Managed by the Provider; no availability commitment, no Health Check measurement, no Service Credit 6.10 Incident management under clause 6; response and restoration targets, clause 6.4
Hosting facilities Located in Australia 7.1 Breach of the Agreement; termination right under the Master Subscription Agreement, clause 16.2, where material
Data residency, data at rest Australia only 8.1 Breach of the Agreement; termination right under the Master Subscription Agreement, clause 16.2, where material
Data residency, edge transit Global edge network, disclosed 8.4 Disclosed limitation, not a breach
Monthly report 10 Business Days 10.1
Record retention 7 years 10.2
Recovery Time Objective 8 hours 11.4
Recovery Point Objective 1 hour 11.4 Bounded by the transaction log capture interval
Backup immutability 14 days, immutable to administrative accounts 11.2(b) Breach of the Agreement; termination right under the Master Subscription Agreement, clause 16.2, where material
Backup integrity verification Every 7 days 11.2(c)
Backup restore test Every 3 months 11.2(d)


4. SUBCONTRACTORS AND THIRD PARTY SERVICES

Clause 4.5(c) of the Master Subscription Agreement requires the Provider to keep this list current. Clause references in the table are to the Service Level Agreement.

Party Role Location of data handled Accesses Customer Data at rest?
Facility operator(s) engaged by the hosting subcontractor Hosting facilities in Australia, selected and managed by the hosting subcontractor under clause 7.1(b) Australia No. Physical hosting only
Next Step Infrastructure Services (nsis.com.au) Hosting subcontractor: hosting infrastructure, server support, monitoring and alert escalation, and backup operation. See clause 7.3 Australia Yes
Operator of the edge network Reverse proxy and distributed denial of service mitigation at the network edge. See clause 7.2 Global. See clause 8.4 No. Data in transit only
Security operations and alerting providers engaged by the hosting subcontractor Managed detection and response, and alert escalation. See the Security Controls and Security Incident Notification Practice document Sydney, Australia No. System event telemetry and application metrics only. See clause 7.3(d)


5. APPROVED TRAVEL COUNTRIES

Referred to by the Service Level Agreement, clause 8.3(d). The register current when a travel approval is given applies to that approval.

5.1 Basis for listing

A country is listed only where its privacy law has been assessed as equivalent to, or stronger than, the Australian Privacy Principles. The Provider treats a country as meeting that standard where a European Commission adequacy decision for it is in force. The decision must be under article 45 of the General Data Protection Regulation (EU) 2016/679. See European Commission, "Adequacy decisions", https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en (accessed 20 August 2026). A GDPR adequacy decision assesses equivalence to the GDPR standard, not to the Australian Privacy Principles directly. In the absence of an Australian equivalence mechanism, the Provider treats it as the closest available external benchmark. Confirm this basis with a qualified lawyer before relying on it, and before adding a country not already on the European Commission's list.

5.2 Country register

Country Basis Scope limitation
Any European Union or European Economic Area member state Subject to the GDPR directly None
United Kingdom EC adequacy decision Covers GDPR and Law Enforcement Directive matters
New Zealand EC adequacy decision None
Japan EC adequacy decision None
Republic of Korea EC adequacy decision None
Switzerland EC adequacy decision None
Canada EC adequacy decision Commercial organisations only — confirm the receiving arrangement falls within scope before relying on it
United States EC adequacy decision (EU-US Data Privacy Framework) Limited to organisations certified under the Data Privacy Framework — confirm before relying on it
Andorra EC adequacy decision None
Argentina EC adequacy decision None
Brazil EC adequacy decision Confirm the decision is still current before relying on it
Faroe Islands EC adequacy decision None
Guernsey EC adequacy decision None
Isle of Man EC adequacy decision None
Israel EC adequacy decision None
Jersey EC adequacy decision None
Uruguay EC adequacy decision None

5.3 Updating this register

The Provider may add or remove a country from clause 5.2, on the basis in clause 5.1 only. Removing a country takes effect immediately for any new approval under clause 8.3(d) of the Service Level Agreement. It does not affect an approval already in force.



END OF SERVICE LEVEL AGREEMENT — PUBLISHED REGISTERS