Service Level Agreement

SyncMate — WYHEN Pty Ltd (ABN 57 688 078 999) Version 1.0 · Effective 31 August 2026 · Owner: Founder/Technical Operator · Review: annually

1. Scope

This SLA applies to the SyncMate SaaS platform provided to the Customer, including the web application, document extraction, ledger and reporting functions, and the Xero integration.

2. Availability

Metric Commitment
Monthly availability target 99.5%
Measurement Calendar month, excluding Excluded Downtime
Evidence Hosting provider status data (Cloudflare, Supabase/AWS) plus internal deployment and error logs
Reporting Quarterly availability and incident report to the Customer on request

Excluded Downtime: failures of the Customer's own network or devices; failures of third-party services the Customer directs us to use (Xero, the Customer's identity provider); force majeure; and downtime caused by the Customer's misuse of the service. Deployments are rolling and do not require planned downtime; if planned maintenance is ever required, at least 5 business days' notice is given and it is scheduled outside 09:00–18:00 AEST business hours.

3. Support response and resolution targets

Support hours: 09:00–17:30 AEST, Monday to Friday, excluding NSW public holidays. P1 incidents are accepted 24/7 by email.

Priority Definition Response Workaround / Resolution
P1 — Critical Service unavailable to all users, or confirmed data loss or security incident 1 hour Workaround within 8 hours; resolution within 2 business days
P2 — High Major function unusable (e.g. extraction or Xero publishing failing) with no workaround 4 business hours 2 business days
P3 — Medium Function impaired but a workaround exists 1 business day Next scheduled release
P4 — Low Cosmetic issue, question, or enhancement request 3 business days By agreement

Contact: contact@wyhen.com.au. Priority is assigned by WYHEN in consultation with the Customer; the Customer may escalate a disputed priority to the Founder.

4. Security incident notification

WYHEN notifies the Customer's nominated contact within 24 hours of becoming aware of a security incident affecting the Customer's data, stating the nature of the incident, the categories and approximate volume of data involved, the likely consequences, and the remediation taken or planned. Where WYHEN acts as Data Processor, the Customer as Controller determines regulator and data-subject notification; WYHEN supports that assessment with logs and evidence.

5. Backup, recovery and continuity

Metric Commitment
RPO (maximum data loss) 24 hours
RTO (maximum restoration time) 1 business day
Backup frequency Daily automated backups with point-in-time recovery
Backup location AWS ap-southeast-2 (Sydney), Australia
Restore testing Annually, documented; result recorded in the risk register

The Business Continuity and Disaster Recovery Plan is available to the Customer on request.

6. Data location and handling

Customer data is stored in Australia (AWS Sydney), including backups. Transient processing occurs at OpenAI and Google enterprise API endpoints in the United States for document extraction only; those providers are contractually prohibited from training models on submitted data and do not retain it after processing.

7. Service reporting

On request, and at least quarterly for enterprise customers, WYHEN provides: measured availability, incident summary (count by priority, response and resolution times), security incidents (if any), material changes to subprocessors, and the status of open vulnerability remediation.

8. Service credits

Where monthly availability falls below 99.5%, the Customer may request a service credit against the following month's fees: 5% for availability below 99.5%, 10% below 99.0%, 25% below 95.0%. Credits are requested in writing within 30 days of the affected month and are the sole remedy for availability shortfalls.

9. Exclusions and limits

This SLA does not cover the availability of Xero, the Customer's accounting data held in Xero, or any third-party service outside WYHEN's control. WYHEN does not operate a staffed 24/7 security operations centre.

10. Review

This SLA is reviewed annually and on any material change to the platform architecture or hosting arrangements.