This Master Services Agreement (hereinafter, the "MSA") sets out the general framework applicable to the professional cybersecurity and artificial intelligence services provided by HODEITEK SL (Tax ID B56478027, registered office at Markole, Aretxabaleta, 20550, Gipuzkoa, Spain), such as penetration testing, Red Team, Security Operations Center (SOC) services and regulatory compliance consulting (ENS, NIS2, DORA, GDPR).
This document is a public informational framework. The binding terms of each specific engagement — scope, schedule, fees and particular conditions — are always formalized in a signed service agreement executed by both parties before work begins, available on request through our contact form.
1. Purpose and scope
This MSA governs the relationship between HODEITEK SL and its clients for the provision of professional services expressly contracted. It does not apply to mere browsing of the website hodeitek.com, which is governed by the website Terms and Conditions.
2. Relationship with the website Terms and Conditions
For any client with a signed service agreement, this MSA and that service agreement prevail over the website Terms and Conditions with respect to the provision of the contracted professional services. The website Terms and Conditions continue to apply, in any case, to general browsing and use of hodeitek.com.
3. Execution of the service agreement
Each service is provided under a service agreement (signed proposal, statement of work or equivalent document) that specifies the scope, schedule, fees and any particular conditions. In the event of any discrepancy between this MSA and the signed service agreement for a specific engagement, the terms of that agreement prevail.
4. Service levels (SLA)
The service levels applicable to each engagement — first-response times, resolution times, availability and other operational commitments — are set out in the signed service agreement, available on request. This document does not set general SLA figures.
5. Confidentiality
Both parties undertake to keep confidential any information they access in connection with the provision of the service, including findings, reports, access credentials and any technical, commercial or organizational information of the client. The scope, duration and exceptions to this obligation — as well as, where applicable, a separate non-disclosure agreement (NDA) — are specified in the signed service agreement, available on request.
6. Intellectual property of deliverables
Ownership and the conditions of use of reports, findings, methodologies and other deliverables generated during the provision of a service are governed by what is specifically agreed in the signed service agreement, available on request. In all cases, HODEITEK SL retains ownership of its pre-existing methodologies, tools, templates and know-how, regardless of the foregoing.
7. Limitation of liability
The liability limits applicable to each contracted service — including, where applicable, quantitative caps, exclusions and professional liability insurance coverage — are set out in the signed service agreement, available on request. This document does not, by itself, set any liability figures or caps.
8. Client audit rights
A client with a signed service agreement holds audit rights over the provision of the service. The specific scope, notice period and audit method (documentary, on-site or through a designated third party) are defined in that agreement, available on request. These audit rights are compatible with, and may rely on, the scope of HODEITEK SL's ISO 27001 and ENS certifications.
9. Security incident response
If, during the provision of a service, HODEITEK SL detects or confirms a security incident affecting the client's systems, data or deliverables, it will:
- Notify the client without undue delay, within the period set in the signed service contract.
- Preserve the relevant forensic evidence for subsequent analysis.
- Carry out a root cause analysis (RCA) within the period set in the signed service contract.
- Deliver an incident report to the client with the analysis findings and the measures taken.
- Notify the Spanish Data Protection Agency (AEPD) when the incident constitutes a personal data breach that must be reported under Article 33 of the GDPR.
Detailed escalation and communication procedures are specified, where applicable, in the signed service agreement.
10. Data protection and data processing agreement
When the provision of a service involves processing the client's personal data on its behalf, both parties will execute a data processing agreement under Article 28 of the GDPR, available on request.
11. Term and termination
The term, grounds for early termination and effects of the completion of each service are defined in the corresponding signed service agreement.
12. Amendments to this framework document
HODEITEK SL may update this MSA on a general basis. Conditions already agreed in a signed service agreement are not affected by subsequent changes to this document, unless expressly agreed otherwise between the parties.
13. Governing law and jurisdiction
This MSA is governed by Spanish law. For the resolution of any dispute, the parties submit to the Courts and Tribunals of San Sebastián (Gipuzkoa), with express waiver of any other jurisdiction, unless the signed service agreement expressly provides otherwise.