KD Technical Services Inc. — Master Services Agreement
KD Technical Services Inc. (dba KDTS) · 4132 196 Street, Langley, BC V3A 1A1, Canada
Version 1.1 · Effective September 9, 2026
This Master Services Agreement (the "Agreement") is made between KD Technical Services Inc., doing business as KDTS, of 4132 196 Street, Langley, British Columbia V3A 1A1 ("KDTS"), and the person or organization that accepts a KDTS quote, proposal, statement of work, managed services agreement, or other engagement document (the "Client"). KDTS and the Client are each a "Party" and together the "Parties".
The Client agrees that accepting any KDTS quote, proposal, Statement of Work, Managed Services Agreement, or Change Order — whether by signature, electronic acceptance, email confirmation, purchase order, payment, or by authorizing KDTS to proceed — constitutes acceptance of this Agreement as of the date of that acceptance (the "Effective Date"). This Agreement sets out the legal and commercial framework under which KDTS provides information technology services to the Client. Every engagement document accepted by the Client is governed by, and incorporated into, this Agreement.
1. Definitions
1.1 "Agreement" means this Master Services Agreement together with every Quote, Statement of Work, Managed Services Agreement, Change Order, and Schedule incorporated by reference.
1.2 "Backup Services" means data backup, replication, archival, business continuity, or disaster recovery services that the Client has expressly purchased under an Engagement Document. Backup Services do not include any backup-related activity that is not specifically described in an Engagement Document.
1.3 "Business Hours" means 8:30 a.m. to 5:00 p.m. Pacific Time, Monday through Friday, excluding British Columbia statutory holidays.
1.4 "Change Order" means a written document, accepted by both Parties, that modifies the scope, pricing, timeline, or terms of an Engagement Document.
1.5 "Client Environment" means all networks, systems, devices, software, data, cloud tenants, and infrastructure owned, leased, or controlled by the Client or its third-party vendors, excluding KDTS's own internal systems.
1.6 "Deliverables" means reports, documentation, configurations, scripts, or other work product that KDTS creates specifically for the Client under an Engagement Document.
1.7 "Engagement Document" means any Quote, Statement of Work, Managed Services Agreement, Change Order, or other written or electronic document issued by KDTS and accepted by the Client that describes Services to be performed.
1.8 "Incident" means any actual or suspected security compromise, malware event, unauthorized access, outage, data loss, or similar occurrence affecting the Client Environment.
1.9 "KDTS Tools" means the software, agents, scripts, automation, monitoring systems, documentation, methods, and know-how that KDTS uses to deliver the Services, whether owned by KDTS or licensed to it.
1.10 "Managed Services" means recurring monitoring, maintenance, support, security, or administration services provided for a recurring fee under a Managed Services Agreement.
1.11 "Managed Services Agreement" or "MSA Schedule" means an Engagement Document that describes recurring Managed Services, the covered systems and users, the recurring fee, and any service-specific terms.
1.12 "Quote" means a written or electronic pricing or service offer issued by KDTS which, once accepted by the Client, forms a binding engagement under this Agreement.
1.13 "Rate Card" means KDTS's then-current schedule of hourly rates, minimums, billing increments, surcharges, and fees, the current version of which is set out in Schedule B.
1.14 "Services" means all managed, professional, project, advisory, procurement, and support services that KDTS provides under this Agreement or any Engagement Document.
1.15 "Statement of Work" or "SOW" means an Engagement Document that describes a project or defined body of work, including scope, deliverables, assumptions, timeline, and pricing.
1.16 "Third-Party Products" means hardware, software, licences, subscriptions, cloud services, and support provided by any vendor other than KDTS, including Microsoft, Google, Huntress, ConnectWise, Syncro, Ubiquiti, Datto, Axcient, and the distributors through which KDTS resells them.
1.17 "Unsupported Systems" means hardware or software that is end-of-life, no longer receives vendor security updates, is unlicensed or improperly licensed, is excluded from management under an Engagement Document, or for which KDTS has not been given the access or permissions needed to manage it.
2. Structure of the Agreement
2.1 Framework. This Agreement is the framework. The specific Services, deliverables, pricing, and service commitments for each engagement are set out in Engagement Documents. Each Engagement Document is subject to this Agreement.
2.2 Quotes and Statements of Work. Project, procurement, and one-time work is described in a Quote or SOW. A Quote or SOW will identify, at minimum, the Services or products to be provided, pricing, and any assumptions or exclusions. Quotes are valid for thirty (30) days from issue unless a different validity period is stated.
2.3 Managed Services Agreements. Recurring Services are described in a Managed Services Agreement, which will identify the covered users, devices, and systems; the recurring fee; the billing basis; and any service-specific inclusions or exclusions.
2.4 Order of Precedence. If there is a conflict between documents, the following order applies unless a document expressly states otherwise: (a) an accepted Change Order; (b) the applicable Engagement Document; (c) this Agreement; (d) any Schedule. Terms printed on the Client's purchase orders, vendor onboarding forms, or payment remittances do not bind KDTS unless KDTS has expressly accepted them in writing.
2.5 Change Orders. Changes to the scope, pricing, or timeline of an Engagement Document are effective only when documented in a Change Order accepted by both Parties. An email exchange in which KDTS describes the change and the Client confirms it in writing is a valid Change Order. KDTS is not obliged to perform out-of-scope work until a Change Order is accepted, and may bill out-of-scope work requested informally at Rate Card rates.
2.6 Independent Contractor. KDTS is an independent contractor. Nothing in this Agreement creates a partnership, joint venture, agency, fiduciary, or employment relationship between the Parties.
2.7 Non-Exclusive. This Agreement is not exclusive. KDTS may provide similar services to other clients, subject to its confidentiality obligations.
3. Scope of Services
3.1 Services. KDTS provides the Services described in the applicable Engagement Document. Services may include managed IT support and monitoring; Microsoft 365, Entra ID, and Google Workspace administration; server, network, and endpoint support; security tooling and monitoring; backup and business continuity; cabling and network hardware; procurement and licensing of Third-Party Products; and project and advisory work.
3.2 Standard of Effort. KDTS performs the Services on a commercially reasonable efforts basis. Unless an Engagement Document expressly includes them, Services do not include: (a) legal, accounting, regulatory, or compliance representation; (b) penetration testing or digital forensics; (c) the cost of hardware, software, or licensing; (d) remediation of Unsupported Systems; (e) management of third-party vendors beyond reasonable coordination; (f) physical security or facilities work; (g) custom software development; or (h) any task requiring access or permissions the Client has not granted. KDTS may offer excluded items under a separate Engagement Document.
3.3 Tools and Methods. KDTS selects the tools, vendors, and methods it uses to deliver the Services and may change them, provided the change does not materially reduce the Services. KDTS may replace or discontinue a Third-Party Product where the vendor changes, discontinues, or reprices it, or where KDTS determines it presents a security risk.
3.4 Shared Responsibility. Service delivery is governed by the Shared Responsibility Model in Schedule A. KDTS is responsible for the duties expressly assigned to it; the Client is responsible for its own decisions, internal controls, and actions; and third-party vendors are responsible for their own products and platforms. Any responsibility not expressly assigned to KDTS remains with the Client.
3.5 Dependencies. Many Services depend on the Client providing and maintaining administrative access, valid licensing, functioning hardware and internet connectivity, accurate information, timely decisions, and a supported environment. KDTS is not responsible for delays, failures, or gaps caused by missing access, inaccurate information, expired licensing, third-party outages, Unsupported Systems, or the Client's failure to act on KDTS's recommendations.
3.6 KDTS Tools in the Client Environment. Delivering the Services may require KDTS to install monitoring agents, remote access software, security software, scripts, or other KDTS Tools in the Client Environment. The Client grants KDTS permission to do so and receives a limited right to the benefit of those tools for the duration of the Services. KDTS Tools are not sold or transferred to the Client and must be removed at KDTS's direction when the Services end. The Client will not disable, tamper with, or remove KDTS Tools without KDTS's agreement.
3.7 Systems Outside KDTS Management. KDTS is not responsible for the performance, security, or integrity of systems it does not manage; for data stored outside managed systems; for changes made by the Client's staff or other vendors; or for Unsupported Systems. Work needed to accommodate or remediate such systems is billable at Rate Card rates or under a Change Order.
3.8 Use of AI-Assisted Tools. KDTS may use AI-assisted tools to help draft documentation, analyze logs and alerts, write scripts, and otherwise deliver the Services more efficiently. KDTS reviews AI-assisted output before relying on it, and remains responsible for the Services it delivers. KDTS will not knowingly submit Client personal information to a consumer-grade AI service, and will identify on request the AI tools it uses and where they process data.
3.9 No Guarantee of Outcomes. Unless an Engagement Document expressly states otherwise, KDTS does not guarantee that Incidents will be prevented, that systems will be available without interruption, that any regulatory or audit outcome will be achieved, or that a recommendation will produce a particular business result.
4. Term, Termination, and Suspension
4.1 Term of this Agreement. This Agreement starts on the Effective Date and continues until terminated under this Section 4. Individual Engagement Documents have their own terms, which govern the relevant engagement.
4.2 Term of Managed Services. Unless a Managed Services Agreement states otherwise, Managed Services have an initial term of twelve (12) months starting on the service start date. After the initial term, Managed Services continue month to month with no fixed term until either Party terminates them under Section 4.3.
4.3 Termination of Managed Services. After the initial term, either Party may terminate Managed Services by giving the other Party at least sixty (60) days' written notice. If the Client terminates Managed Services during the initial term other than for KDTS's uncured material breach, the Client remains responsible for the recurring fees for the balance of the initial term, together with any non-cancellable Third-Party Product costs KDTS has committed to on the Client's behalf.
4.4 Termination of Projects. Either Party may terminate a SOW or Quote for convenience on written notice. The Client will pay for all Services performed and all products ordered or provisioned up to the termination date, plus any non-cancellable Third-Party Product costs and reasonable wind-down effort.
4.5 Termination for Cause. Either Party may terminate this Agreement or any Engagement Document on written notice if the other Party: (a) materially breaches this Agreement and fails to cure the breach within thirty (30) days of written notice; (b) becomes insolvent, makes an assignment for the benefit of creditors, or ceases to carry on business; or (c) engages in unlawful conduct, or conduct that threatens the safety of the other Party's personnel or the security of its systems.
4.6 Suspension. KDTS may suspend some or all Services on written notice, without liability, if: (a) the Client has not paid an undisputed invoice within fifteen (15) days after KDTS sends an overdue notice; (b) the Client Environment presents a security or operational risk to KDTS, its systems, or its other clients; (c) required access, information, or cooperation is withheld; (d) the Client's staff are abusive or threatening toward KDTS personnel; or (e) Third-Party Product licensing required for the Services has lapsed because of Client inaction. Services resume once the issue is resolved, subject to Section 7.19.
4.7 Effect of Termination. When this Agreement or an Engagement Document ends: (a) all fees accrued to the termination date become due; (b) KDTS stops the affected Services; (c) KDTS will remove, or direct the Client to remove, KDTS Tools from the Client Environment; (d) the Client's access to KDTS-provided portals and tools ends; (e) KDTS has no obligation to retain Client data or documentation more than thirty (30) days after termination unless required by law or agreed in writing; and (f) KDTS will provide transition assistance on request at Rate Card rates.
4.8 Transition Assistance. On request, KDTS will provide reasonable offboarding support, including transferring documentation and credentials to the Client or its new provider, coordinating vendor changes, and exporting data where practical. Transition assistance is billable at Rate Card rates unless an Engagement Document includes it, and is conditional on the Client's account being paid in full.
4.9 Survival. Sections 7 (Fees), 8 (Confidentiality), 9 (Privacy and Security), 10 (Intellectual Property), 12 (Limitation of Liability), 13 (Indemnification), 15 (Dispute Resolution), and any other provision that by its nature should survive, survive termination or expiry of this Agreement.
5. Client Responsibilities
5.1 Cooperation. The Client will: (a) provide timely access to its people, premises, systems, and documentation; (b) supply accurate and complete information; (c) maintain the internet connectivity, power, and physical conditions the Services require; (d) ensure KDTS personnel have the administrative privileges the Services require; (e) promptly notify KDTS of Incidents, outages, or suspected misuse; (f) follow KDTS's reasonable security recommendations; and (g) make decisions and approvals in a timely manner.
5.2 Licensing and Infrastructure. Unless an Engagement Document states otherwise, the Client is responsible for acquiring and maintaining all Third-Party Product licences, subscriptions, warranties, and support contracts; for ensuring its hardware and software meet reasonable minimum standards; and for the physical security of its premises, network closets, and equipment.
5.3 Designated Contacts. The Client will designate a primary contact with authority to make decisions and approve work, and a backup contact. KDTS may rely on instructions from those contacts, and from any Client staff member who reasonably appears to have authority, until the Client tells KDTS otherwise in writing.
5.4 Security. The Client is responsible for its own security policies, acceptable-use rules, and staff conduct; for using multi-factor authentication where KDTS makes it available; for protecting credentials; for promptly telling KDTS when staff join or leave so accounts can be created or disabled; and for reporting suspicious activity. Failure to implement KDTS's security recommendations may reduce the effectiveness of the Services and limits KDTS's responsibility for resulting Incidents.
5.5 Regulatory Compliance. The Client is solely responsible for its own compliance with laws and regulations that apply to its business, including privacy law, and for any filings, notifications, or attestations those laws require. KDTS's recommendations are technical and operational, not legal or compliance advice.
5.6 Data. The Client owns and is responsible for its data, including its accuracy, classification, lawful use, and retention. Unless the Client has purchased Backup Services, KDTS has no responsibility for the existence, integrity, or recoverability of Client data.
5.7 Backup Services Acknowledgement. KDTS recommends that every Client maintain tested, offline or immutable backups of its systems and data. Where the Client declines to purchase Backup Services from KDTS for any system, or chooses to rely on its own or another vendor's backup arrangement, the Client accepts full responsibility for that decision and agrees to hold KDTS harmless from any loss, cost, or claim arising from the loss, corruption, unavailability, or unrecoverability of data on those systems, including in the event of hardware failure, ransomware, or other Incident.
5.8 Third-Party Vendors. The Client is responsible for its contracts with its other vendors — including line-of-business software providers, internet providers, and telecom carriers — and for maintaining the support subscriptions needed for KDTS to escalate issues to them. KDTS's role with other vendors is reasonable coordination unless an Engagement Document says otherwise.
5.9 No Interference. The Client will not disable, uninstall, bypass, or interfere with KDTS Tools, or make configuration changes to managed systems without coordinating with KDTS. Doing so may suspend or degrade the Services, void any service commitments, and result in additional fees to restore the environment.
5.10 Timely Payment. Continued delivery of the Services depends on payment of KDTS's invoices as they fall due.
6. Warranties and Disclaimers
6.1 KDTS Warranty. KDTS warrants that it will perform the Services in a professional and workmanlike manner consistent with generally accepted industry practice for small-business managed service providers. If the Client notifies KDTS in writing within thirty (30) days that a Service was not performed in accordance with this warranty, KDTS will re-perform the non-conforming Service at no additional charge. Re-performance is the Client's sole remedy for breach of this warranty.
6.2 No Warranty of Error-Free Operation. KDTS does not warrant that the Services, KDTS Tools, or any system in the Client Environment will be error-free, uninterrupted, or secure from every threat.
6.3 Third-Party Products. KDTS resells and supports Third-Party Products but does not manufacture or control them. Any warranty for a Third-Party Product is provided by its vendor. KDTS makes no warranty about vendor response times, product behaviour, availability, pricing stability, or defects, and will assist with vendor warranty claims as a billable Service unless an Engagement Document includes that assistance.
6.4 Cybersecurity. Threats evolve constantly and no security program eliminates risk. KDTS does not guarantee that any attack, breach, malware infection, unauthorized access, or data loss will be prevented or detected. Detection depends on the coverage of the tools deployed and the telemetry available. Residual risk always remains, whatever Services the Client purchases.
6.5 Backup and Recovery. Unless the Client has purchased Backup Services, KDTS has no responsibility for the creation, testing, verification, or restoration of backups and no liability for data loss. Where Backup Services are purchased, KDTS's obligations are limited to those stated in the Engagement Document, and recovery times and recovery points depend on the backup platform, the volume of data, the available bandwidth, and the condition of the systems being restored.
6.6 Unsupported Systems. KDTS provides no warranty for Unsupported Systems. Support for them is best-effort only, and work on them may be declined or billed at Rate Card rates.
6.7 Exclusive Warranties. The warranties in this Section are the only warranties KDTS gives. All other warranties, conditions, and representations, whether express, implied, or statutory — including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement — are excluded to the fullest extent permitted by law.
7. Fees, Billing, and Payment
7.1 Fees. Fees are stated in the applicable Engagement Document or, where not stated, are billed at Rate Card rates. Fees may include recurring Managed Services fees, hourly time-and-materials charges, fixed project pricing, Third-Party Product charges, onboarding fees, and expenses.
7.2 Invoicing. Unless an Engagement Document states otherwise: (a) Managed Services fees are invoiced monthly in advance; (b) time-and-materials work is invoiced in arrears; (c) Third-Party Products are invoiced when ordered or provisioned, and recurring subscriptions are invoiced monthly or annually to match the vendor's billing; and (d) project milestones are invoiced as set out in the SOW.
7.3 Payment Terms. All invoices are due and payable upon receipt. "Receipt" means the date KDTS delivers the invoice by email or portal. The Client may not defer payment on the basis of its own internal approval cycles or payment runs. Where an Engagement Document states different payment terms, those terms apply only to that engagement.
7.4 Late Payment. Any amount not paid within thirty (30) days of the invoice date is overdue. Overdue amounts bear interest at one and one-half percent (1.5%) per month, being eighteen percent (18%) per annum, or the maximum rate permitted by law if lower, from the due date until paid in full. The Client will reimburse KDTS's reasonable costs of collection, including collection agency fees and legal costs. KDTS's acceptance of a late payment does not waive its rights.
7.5 Disputed Invoices. If the Client disputes an invoice, it must notify KDTS in writing within fifteen (15) days of the invoice date, identifying the disputed items and the reason. Undisputed portions must be paid on time. The Parties will work in good faith to resolve the dispute within thirty (30) days. An invoice not disputed within the fifteen-day window is deemed accepted.
7.6 No Set-Off by Client. The Client may not withhold, reduce, or set off payment of any invoice on account of any claim, credit, or dispute it has or asserts against KDTS.
7.7 Third-Party Products. Where KDTS orders hardware, software, licences, subscriptions, or cloud services on the Client's behalf: (a) the Client is responsible for the full cost, including any minimum or committed term the vendor imposes; (b) such charges are non-refundable and non-cancellable once ordered or provisioned, except to the extent the vendor allows; (c) pricing is subject to vendor price changes and currency fluctuation; (d) the Client is responsible for the vendor's early-termination charges if the Client ends the Services before a committed term expires; and (e) hardware is supplied subject to the manufacturer's warranty only.
7.8 Vendor Price Changes. Vendor price changes for Third-Party Products pass through to the Client and are not a change to the scope of the Services. KDTS will make reasonable efforts to give advance notice of material changes, but the absence of notice does not relieve the Client of the adjusted charge. Continued use of a Third-Party Product after a price change is acceptance of the new price.
7.9 Taxes. Fees exclude GST, PST, and any other applicable taxes, duties, or levies, which will be added to invoices where required. The Client is responsible for all such taxes other than taxes on KDTS's income.
7.10 Expenses and Travel. Reasonable out-of-pocket expenses incurred in performing the Services — including parts, shipping, parking, and mileage or travel time for work outside KDTS's normal service area — are billed at cost or at the Rate Card rate, as applicable.
7.11 Time-and-Materials Billing. Hourly Services are billed at the Rate Card rate in effect when the work is performed. Onsite visits are subject to a one (1) hour minimum and are billed in fifteen (15) minute increments thereafter. Remote work is billed in fifteen (15) minute increments. Work performed outside Business Hours at the Client's request, or in response to an emergency, is billed at the after-hours rate in the Rate Card.
7.12 Metric-Based Fees and True-Up. Where Managed Services fees are based on user, device, mailbox, or similar counts, KDTS may determine counts from its own management and licensing systems and adjust billing to reflect actual counts. KDTS's systems of record are authoritative. The Client will review counts shown on invoices and raise any discrepancy within the dispute window in Section 7.5.
7.13 Annual Adjustment. KDTS may increase recurring Managed Services fees once per year, on not less than thirty (30) days' written notice, by up to the greater of five percent (5%) or the most recent annual change in the Consumer Price Index for British Columbia. Increases driven by vendor pricing are governed by Section 7.8 and are not subject to this limit.
7.14 Out-of-Scope Work. Work outside the scope of an Engagement Document — whether requested by the Client or made necessary by Client action or inaction, environmental issues, or third-party failures — is billable at Rate Card rates.
7.15 Emergency and Unplanned Work. Where KDTS responds to an emergency or Incident at the Client's request: (a) the work is billable at Rate Card rates, including any after-hours rate; (b) a Change Order or Quote is not required — verbal or written authorization from a Client contact is sufficient; (c) KDTS will invoice the work performed, the hours incurred, and any products or third-party costs; and (d) payment is not contingent on the outcome of the Incident.
7.16 Catch-Up Billing. KDTS may issue catch-up invoices for Services, licences, or products that were delivered or provisioned but not invoiced in the relevant period because of timing or administrative delay, and for corrections to earlier invoices. Catch-up invoices will identify the service period and are due on receipt.
7.17 Payment Methods. KDTS accepts electronic funds transfer, e-Transfer, cheque, and credit card. Payments by credit card may be subject to a processing surcharge of up to two and four-tenths percent (2.4%) of the invoice total, which will be disclosed before the payment is processed. KDTS may change its accepted payment methods on thirty (30) days' notice. Current banking coordinates appear on each invoice; the Client is responsible for confirming payment instructions before remitting, and KDTS is not liable for funds misdirected because the Client relied on instructions not shown on a KDTS invoice.
7.18 Non-Refundable. Fees paid are non-refundable except as this Agreement expressly provides. Prepaid Managed Services fees and Third-Party Product charges are non-cancellable, and early termination does not relieve the Client of committed-term obligations.
7.19 Consequences of Non-Payment. If an invoice remains unpaid thirty (30) days after the invoice date, KDTS will issue an overdue notice. If payment is not received within fifteen (15) days of that notice, KDTS may, at its discretion and without liability: (a) reduce the Services, including deferring non-critical maintenance and withholding Deliverables; (b) suspend the Services under Section 4.6; and (c) where the account remains unpaid sixty (60) days or more after the invoice date, on seven (7) days' further notice cancel, suspend, or decline to renew Third-Party Products KDTS maintains on the Client's behalf, including Microsoft 365, security, backup, and monitoring subscriptions. The Client acknowledges that cancelling such subscriptions may cause loss of data, configurations, or pricing, for which KDTS is not responsible, and that the Client remains liable for all vendor charges incurred. Reinstatement is at KDTS's discretion, requires payment in full of all outstanding amounts, interest, and collection costs, is subject to a reinstatement fee of two hundred fifty dollars ($250), and may be conditioned on prepayment or a deposit of up to two (2) months' fees.
7.20 KDTS Set-Off. KDTS may apply any amount it owes the Client, including credits or deposits, against amounts the Client owes KDTS.
8. Confidentiality
8.1 Confidential Information. "Confidential Information" means non-public information one Party discloses to the other in connection with this Agreement, in any form, including business and financial information, system configurations, network diagrams, credentials, security findings, incident details, pricing, and the terms of this Agreement and any Engagement Document. It does not include information that is or becomes public without breach, was already known to the receiving Party, is independently developed, or is rightfully received from a third party without restriction.
8.2 Obligations. Each Party will protect the other's Confidential Information with at least reasonable care; use it only to perform or receive the Services; limit access to personnel, contractors, and advisors who need it and are bound by comparable obligations; not disclose it to third parties without consent; and promptly notify the other Party of any unauthorized disclosure.
8.3 Compelled Disclosure. A Party required by law, court order, or regulator to disclose Confidential Information will, where lawful, give the other Party prompt notice, disclose only what is required, and cooperate reasonably with efforts to limit the disclosure.
8.4 Use of Client Information by KDTS. KDTS uses Client information, system data, logs, and telemetry only to deliver, secure, and improve the Services and to meet its legal obligations. KDTS does not sell Client information. KDTS may use aggregated, de-identified data for internal benchmarking and service improvement.
8.5 Third-Party Platforms. Delivering the Services requires KDTS to use third-party platforms — such as remote management, security monitoring, ticketing, documentation, and cloud tools — that will process or store Confidential Information under their own security and privacy terms. KDTS selects reputable, industry-recognized platforms and is not responsible for the independent acts of those vendors.
8.6 Return or Destruction. On written request or when this Agreement ends, each Party will return or securely destroy the other's Confidential Information, except that KDTS may retain copies as required by law, for insurance purposes, or in routine backups, which remain subject to this Section.
8.7 Duration. Confidentiality obligations continue for five (5) years after this Agreement ends, and indefinitely for credentials, security information, and personal information.
9. Privacy, Data Protection, and Security
9.1 Applicable Law. Each Party will comply with the privacy and data protection laws that apply to it, including British Columbia's Personal Information Protection Act (PIPA) and, where applicable, the federal Personal Information Protection and Electronic Documents Act (PIPEDA). The Client is the organization responsible for the personal information in its custody; KDTS processes that information on the Client's behalf as a service provider.
9.2 KDTS Safeguards. KDTS will maintain administrative, technical, and physical safeguards appropriate for a managed service provider, including multi-factor authentication on its remote management and administrative tools, access controls, and secured credential storage; will limit access to Client systems and data to personnel who need it; and will ensure those personnel are bound by confidentiality obligations.
9.3 Client Safeguards. The Client will maintain internal safeguards appropriate to its business, enforce multi-factor authentication and least-privilege access where available, keep its own accounts and devices secure, follow KDTS's security recommendations in a timely manner, and maintain backups for any system not covered by Backup Services. KDTS is not responsible for Incidents resulting from the Client's failure to meet these obligations.
9.4 Data Ownership. Client data remains the Client's property at all times. KDTS acquires no rights in it beyond what is needed to deliver the Services.
9.5 Data Residency and Cross-Border Processing. KDTS operates only in Canada and performs the Services from within Canada. However, many of the platforms KDTS uses to deliver the Services — and many of the Third-Party Products the Client licenses — are operated by vendors that store or process data in the United States or other jurisdictions, and that data may be subject to the laws of those jurisdictions. KDTS prefers Canadian data residency where the vendor offers it, will tell the Client on request which platforms process Client data outside Canada, and will help the Client evaluate alternatives where residency is a business or regulatory requirement. The Client is responsible for determining whether cross-border processing is acceptable for its data.
9.6 Access and Processing. KDTS accesses Client systems and data only as needed to deliver the Services. KDTS will not use Client data for any other purpose, and will not transfer Client-identifiable information outside Canada except as described in Section 9.5, as required by law, or as approved by the Client.
9.7 Incident Notification. Each Party will notify the other without unreasonable delay after confirming an Incident that affects the other Party's data or systems, describing what is known about the Incident, the data affected, and the containment steps taken. Unless an Engagement Document says otherwise, KDTS does not make regulatory breach notifications, notify affected individuals, or engage legal counsel on the Client's behalf; those remain the Client's responsibility. KDTS will provide reasonable technical assistance with those activities at Rate Card rates.
9.8 Incident Response Limits. KDTS will provide reasonable assistance in containing and remediating Incidents affecting managed systems. Unless expressly contracted, KDTS does not provide forensic investigation, evidence preservation to a legal standard, breach counsel, ransom negotiation, or public communications, and does not guarantee recovery of affected systems or data. KDTS may take reasonable protective actions — such as isolating a device or disabling an account — without prior approval where it believes doing so is necessary to contain an active threat.
9.9 Prohibited Use. The Client will not use the Services or KDTS Tools for unlawful activity, to host or distribute malware, to violate vendor licence terms, or to circumvent security controls. KDTS may suspend the Services immediately if it detects such activity.
9.10 Residual Risk. The Client acknowledges that no managed service, security tool, or backup system eliminates risk, and accepts the residual risk that remains after the Services are delivered.
10. Intellectual Property
10.1 Pre-Existing IP. Each Party keeps all rights in the intellectual property it owned or developed before the Effective Date or outside this Agreement.
10.2 KDTS Tools. KDTS owns, or is licensed to use, all KDTS Tools, including its scripts, automation, documentation templates, procedures, monitoring configurations, and know-how, and any improvements to them made while delivering the Services. The Client receives only the limited right to benefit from KDTS Tools during the Services described in Section 3.6.
10.3 Deliverables. Once paid for in full, Deliverables created specifically for the Client are licensed to the Client on a perpetual, non-exclusive basis for its internal business use. Deliverables may incorporate KDTS Tools or reusable components, which remain KDTS's property. The Client may not resell, sublicense, or distribute Deliverables without KDTS's written consent.
10.4 Client Materials. The Client grants KDTS a non-exclusive licence to use the Client's data, systems, and materials as needed to deliver the Services.
10.5 General Knowledge. KDTS may use the general skills, ideas, and know-how it develops while delivering the Services for any purpose, provided it does not disclose the Client's Confidential Information.
10.6 Third-Party IP. Third-Party Products are licensed under their vendors' terms, and the Client is responsible for complying with those terms.
10.7 Restrictions. The Client will not copy, reverse engineer, modify, or redistribute KDTS Tools, use them after the Services end, or use them to build a competing service. A breach of this Section may cause KDTS irreparable harm, and KDTS may seek injunctive relief in addition to any other remedy.
11. Service Levels and Support
11.1 Support Hours. Standard support is provided during Business Hours. After-hours support is available on a best-effort basis and is billed at the after-hours rate in the Rate Card unless a Managed Services Agreement includes after-hours coverage.
11.2 Service Commitments. Response-time or other service commitments apply only where a Managed Services Agreement expressly states them. Otherwise, KDTS provides the Services on a commercially reasonable efforts basis. Where a response time is stated, it means the time until KDTS acknowledges a request and begins work; resolution times are estimates and are not guaranteed.
11.3 Prioritization. KDTS prioritizes requests by business impact: outages, security events, and issues affecting many users take precedence over issues affecting a single user, which take precedence over questions and non-urgent requests. If a Managed Services Agreement defines priority levels, those definitions apply.
11.4 Exclusions. Service commitments do not apply to issues caused by third-party vendors, internet or cloud outages, Client misconfiguration or unauthorized changes, Unsupported Systems, active security Incidents, missing access or approvals, force majeure events, or environments in which KDTS Tools have been disabled or removed.
11.5 Monitoring Limits. Monitoring and security tools detect only what they are deployed to see. Gaps in agent coverage, logging, or vendor telemetry reduce detection, and alerts may require Client action. KDTS is not responsible for missed detections caused by insufficient coverage or Unsupported Systems.
11.6 Client Cooperation. The Client will report issues promptly with enough detail to reproduce them, make affected users and systems available, refrain from making further changes to affected systems during remediation, and keep its escalation contacts current. Failure to cooperate extends timelines and voids any service commitment.
11.7 Informal Statements. Only service commitments written in an Engagement Document are binding. Verbal statements, emails, or ticket notes do not create service level obligations.
12. Limitation of Liability
12.1 Cap. To the fullest extent permitted by law, KDTS's total aggregate liability for all claims arising out of or relating to this Agreement and every Engagement Document, whether in contract, tort (including negligence), statute, or otherwise, will not exceed the total fees the Client paid to KDTS for Services under the Engagement Document giving rise to the claim during the twelve (12) months immediately before the event giving rise to the claim. Fees for Third-Party Products are excluded from this calculation. This cap applies regardless of the number of claims or theories asserted.
12.2 Excluded Damages. To the fullest extent permitted by law, KDTS is not liable for any: (a) lost profits, revenue, business, or opportunity; (b) loss, corruption, unavailability, or unauthorized disclosure of data; (c) business interruption or downtime; (d) cost of breach notification, forensics, credit monitoring, or regulatory fines or penalties; (e) reputational harm; (f) failures of Third-Party Products or vendors; or (g) indirect, consequential, special, exemplary, or punitive damages — in each case even if KDTS was advised of the possibility, and whether or not the Services included monitoring, security, or backup.
12.3 Unpurchased and Unmanaged. KDTS has no liability for losses arising from systems it does not manage; from Unsupported Systems; from the Client's decision not to purchase Backup Services, security monitoring, or other risk-reducing Services KDTS has recommended; from missing telemetry or access; or from vulnerabilities or misconfigurations introduced by the Client or other vendors.
12.4 Client Decisions. Decisions the Client makes based on KDTS's advice, reports, or recommendations are the Client's own, and KDTS is not liable for their outcomes.
12.5 Allocation of Risk. The Parties agree that KDTS's pricing reflects the limitations in this Section, that KDTS does not control the Client Environment or the Client's vendors and staff, and that these limitations are a fundamental part of the bargain.
12.6 Proportionate Liability. Where more than one party contributes to a loss, KDTS's liability is limited to its proportionate share and is not joint and several.
12.7 Exceptions. Nothing in this Agreement limits liability for fraud or wilful misconduct, for death or personal injury caused by a Party's negligence, for the Client's obligation to pay fees, or for any liability that cannot be limited by law.
13. Indemnification
13.1 By KDTS. KDTS will defend and indemnify the Client against third-party claims that KDTS Tools or Deliverables, as provided by KDTS and used as permitted, infringe a Canadian patent, copyright, or trademark. This does not apply to claims arising from Client materials or instructions, Third-Party Products, modifications not made by KDTS, or use contrary to this Agreement. If an infringement claim arises, KDTS may procure the right for the Client to continue using the item, replace or modify it, or withdraw it and refund any prepaid unused fees. This is the Client's sole remedy for infringement claims.
13.2 By Client. The Client will defend and indemnify KDTS, its owners, employees, and contractors against third-party claims, including regulatory proceedings, arising from: (a) Client data, materials, or instructions; (b) the Client's breach of its security, privacy, or Shared Responsibility obligations; (c) Unsupported Systems or systems not managed by KDTS; (d) the Client's decision not to purchase Backup Services or other recommended Services; (e) the Client's or its users' violation of law or vendor licence terms; (f) claims by the Client's employees or contractors; or (g) regulatory fines or findings attributable to the Client's own compliance obligations.
13.3 Procedure. The Party seeking indemnity will give prompt written notice of the claim, allow the indemnifying Party to control the defence and settlement (provided no settlement admits fault on behalf of, or imposes obligations on, the indemnified Party without its consent), and cooperate reasonably at the indemnifying Party's expense.
13.4 Relationship to Liability Cap. Indemnity obligations are subject to Section 12 except to the extent the law prohibits limiting them.
14. Insurance
14.1 KDTS Insurance. KDTS maintains, at its own expense, commercial general liability insurance of not less than two million dollars ($2,000,000) per occurrence, and technology errors and omissions and cyber liability insurance of not less than three million dollars ($3,000,000) in the aggregate, with reputable insurers. KDTS will provide a certificate of insurance on reasonable request.
14.2 Client Insurance. The Client is responsible for maintaining insurance appropriate to its own operations, including cyber liability coverage sufficient to respond to a breach, business interruption, and any regulatory exposure of its business. The Services are not a substitute for insurance, and the Client's failure to insure does not shift risk to KDTS.
14.3 No Expansion of Liability. Insurance limits do not increase or replace the limitations in Section 12.
15. Dispute Resolution and Governing Law
15.1 Good-Faith Discussion. The Parties will first try to resolve any dispute through good-faith discussion between the Client's principal contact and KDTS's owner. Either Party may start this process by written notice describing the dispute.
15.2 Mediation. If the dispute is not resolved within thirty (30) days of that notice, either Party may require non-binding mediation before a mediator agreed by the Parties, conducted in Langley or Vancouver, British Columbia, or by video. Each Party bears its own costs and the Parties share the mediator's fees equally.
15.3 Litigation. Except for claims to recover unpaid fees, to protect Confidential Information or intellectual property, or for injunctive relief, neither Party will start court proceedings until the steps in Sections 15.1 and 15.2 have been completed or forty-five (45) days have passed since the notice of dispute, whichever is earlier.
15.4 Governing Law and Courts. This Agreement is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable in it, without regard to conflict-of-laws rules. The Parties attorn to the exclusive jurisdiction of the courts of British Columbia, and agree that any proceeding will be brought in the courts, tribunal, or registry having jurisdiction over Langley, British Columbia, including the Civil Resolution Tribunal or Provincial Court (Small Claims) where the amount in dispute falls within their limits.
15.5 Time Limit for Claims. To the extent permitted by law, no claim other than a claim for unpaid fees may be brought more than twelve (12) months after the events giving rise to it.
15.6 Continued Performance. During a dispute, both Parties will continue to perform their obligations, including payment of undisputed amounts, unless the nature of the dispute makes that unreasonable.
15.7 Injunctive Relief. Either Party may seek interim or injunctive relief from a court at any time to protect Confidential Information, intellectual property, or the security of its systems.
16. Force Majeure
16.1 Excused Delay. Neither Party is liable for a delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control, including natural disaster, fire, flood, severe weather, epidemic, government action, labour disruption, utility or telecommunications failure, internet or cloud service outages, supply chain disruption, or widespread cyberattack, malware, or zero-day vulnerability.
16.2 Notice and Mitigation. The affected Party will notify the other as soon as practical, make reasonable efforts to limit the impact, and resume performance when the event ends. Timelines and service commitments are extended for the duration of the event.
16.3 Extended Events. If a force majeure event continues for more than thirty (30) consecutive days, either Party may terminate the affected Engagement Document on ten (10) days' written notice, with the Client remaining responsible for Services performed and non-cancellable third-party costs to that date.
16.4 Vendor Failures. For clarity, outages or failures of Microsoft, Google, internet service providers, security or backup platform vendors, or any other vendor outside KDTS's control are force majeure events to the extent they materially affect KDTS's performance.
17. General
17.1 Entire Agreement. This Agreement, with all Engagement Documents and Schedules, is the entire agreement between the Parties about the Services and replaces all prior proposals, discussions, and understandings on the subject.
17.2 Amendments. KDTS may update this Agreement from time to time by publishing a revised version at kdts.ca/terms with a new version number and effective date. The revised version applies to Engagement Documents accepted after its effective date, and to ongoing Managed Services thirty (30) days after KDTS gives the Client notice of the change. Amendments to a specific Engagement Document require a Change Order.
17.3 Assignment. Neither Party may assign this Agreement without the other's written consent, not to be unreasonably withheld, except that KDTS may assign it to a successor in a sale, merger, or reorganization of its business.
17.4 Subcontractors. KDTS may use subcontractors and specialist partners to deliver parts of the Services. KDTS remains responsible for their work and will bind them to confidentiality and security obligations consistent with this Agreement.
17.5 Notices. Formal notices under this Agreement must be in writing and delivered by email with confirmation of receipt, by courier, or by registered mail. Notices to KDTS go to ken@kdts.ca and to KD Technical Services Inc., 4132 196 Street, Langley, BC V3A 1A1. Notices to the Client go to the primary contact and address on its most recent Engagement Document. Routine operational communication may occur through email, phone, or the support ticketing system.
17.6 Publicity. Neither Party will issue a press release or public marketing statement naming the other without consent. KDTS may identify the Client as a client in non-public proposals and references unless the Client objects in writing.
17.7 Severability and Waiver. If any provision is held unenforceable, it will be read down to the extent necessary and the rest of the Agreement remains in effect. A Party's failure or delay in exercising a right is not a waiver of it. Waivers must be in writing.
17.8 Electronic Acceptance and Signatures. This Agreement and any Engagement Document may be accepted and become binding without a physical signature. Acceptance of a Quote, SOW, or Managed Services Agreement by electronic signature, email confirmation, click-through, purchase order, payment, or by authorizing KDTS to proceed is binding acceptance of this Agreement. Electronic and scanned signatures have the same effect as originals, and documents may be signed in counterparts.
17.9 Interpretation. Headings are for convenience only. "Including" means "including without limitation". References to days are calendar days unless stated otherwise. Dollar amounts are in Canadian dollars.
17.10 Location of Performance. KDTS performs the Services from its offices and from Client premises within British Columbia, and remotely from within Canada.
Schedule A — Shared Responsibility Model
This Schedule allocates responsibilities between KDTS, the Client, and third-party vendors for all Services. Where a responsibility is not expressly assigned to KDTS in this Schedule or an Engagement Document, it remains with the Client. If this Schedule conflicts with an Engagement Document, the Engagement Document governs for that engagement only.
A.1 KDTS Responsibilities (where the Service is purchased)
-
Monitoring and maintaining the endpoints, servers, network equipment, and cloud tenants covered by a Managed Services Agreement.
-
Deploying, updating, and maintaining KDTS Tools on covered systems.
-
Applying operating system and supported application updates where KDTS has the required control and access.
-
Administering Microsoft 365, Entra ID, and Google Workspace tenants as specified, including user, mailbox, licence, and security policy changes on request.
-
Monitoring security alerts from the tools KDTS has deployed, triaging them, notifying the Client of significant events, and taking reasonable containment action on covered systems.
-
Monitoring backup job status and initiating restores on request, where Backup Services are purchased.
-
Maintaining documentation of the covered environment and providing recommendations for security improvement, modernization, and risk reduction.
-
Responding to support requests during Business Hours.
A.2 Client Responsibilities
-
Ownership of its business, security, acceptable-use, and data-handling policies and the conduct of its staff.
-
Final decisions on security recommendations, and acceptance of the risk of declining them.
-
User lifecycle: promptly telling KDTS when staff join, change roles, or leave.
-
Using multi-factor authentication and protecting credentials.
-
Maintaining valid licensing for all software and Third-Party Products, and current support contracts with its other vendors.
-
Giving KDTS the administrative access, permissions, and information needed to deliver the Services.
-
Physical security of premises, network closets, servers, and devices; internet connectivity and power.
-
Backups for any system not covered by Backup Services, and verification that those backups work.
-
Compliance with laws that apply to its business, including privacy law, and all regulatory filings and notifications.
-
Prompt reporting of Incidents and cooperation during remediation.
-
Maintaining appropriate insurance, including cyber liability coverage.
A.3 Vendor Responsibilities
Third-party vendors — including Microsoft, Google, security and backup platform providers, internet and telecom carriers, and line-of-business software providers — are responsible for the availability, security, patching, and performance of their own products and platforms. KDTS cannot be held responsible for failures originating in vendor platforms.
A.4 Shared Responsibilities
Both Parties share responsibility for reducing the attack surface, investigating anomalies, keeping escalation contacts current, coordinating during outages, and sharing relevant information and logs.
A.5 Backup and Recovery
Unless Backup Services are purchased for a system, KDTS has no responsibility for the backup or recoverability of that system's data, and the Client accepts that risk under Section 5.7. Where Backup Services are purchased, KDTS's responsibility is limited to the systems, retention, and testing described in the Engagement Document. Recovery time and recovery point depend on the backup platform, data volume, bandwidth, and system condition, and are estimates unless the Engagement Document guarantees them.
A.6 Legacy and Unsupported Systems
KDTS provides no warranty or service commitment for Unsupported Systems. Support is best-effort, may be declined, and is billable at Rate Card rates. The Client bears all risk of continuing to operate Unsupported Systems, including incompatibility with KDTS Tools, backup, and security tooling, and is responsible for replacing or upgrading them.
A.7 Security Monitoring
Where the Client purchases endpoint detection and response, identity monitoring, or similar security Services, detection is limited to the systems, accounts, and tenants on which the tools are deployed and to the telemetry those tools receive. KDTS's role is to deploy and maintain the tooling, triage alerts, notify the Client of significant events, and take reasonable containment steps on covered systems. It does not include forensic investigation, legal breach response, or a guarantee that every threat will be detected.
Schedule B — Standard Rates and Billing Reference
Current as of September 2026. KDTS may update this Schedule from time to time; the version published at kdts.ca/terms when work is performed applies. Rates stated in an Engagement Document take precedence over this Schedule for that engagement.
B.1 Hourly Rate
Standard rate for technical Services: $165.00 per hour.
B.2 Onsite Work
One (1) hour minimum per visit, then billed in fifteen (15) minute increments.
B.3 Remote Work
Billed in fifteen (15) minute increments at the standard rate.
B.4 After-Hours and Emergency Work
Work performed outside Business Hours at the Client's request, or emergency response at any time, is billed at one and one-half times (1.5x) the standard rate, subject to a one (1) hour minimum.
B.5 Travel
Travel within KDTS's service area (Burnaby to Abbotsford) is included in onsite billing. Travel outside the service area is billed at the standard rate for travel time plus mileage at the Canada Revenue Agency prescribed rate.
B.6 Payment Terms
All invoices are due upon receipt. Overdue amounts bear interest at 1.5% per month (18% per annum). Credit card payments may be subject to a processing surcharge of up to 2.4%.
B.7 Reinstatement Fee
$250.00 to reinstate Services suspended for non-payment, in addition to payment in full of all outstanding amounts.
B.8 Taxes
All rates exclude GST and PST, which are added where applicable.
Acceptance
No signature is required for this Agreement to take effect. The Client accepts this Agreement by accepting any KDTS Engagement Document as described in Section 17.8. Where the Parties choose to sign a copy, the signature blocks below may be used.
© 2026 KD Technical Services Inc.. Version 1.1 — Effective September 9, 2026.
