CyberTwice

Legal

CyberTwice ATTEST Subscription Details

Subscription details for the CyberTwice ATTEST Service, offered via the Microsoft Marketplace. Version 1.0, dated April 1, 2023.

1. Introduction and Definitions

All CyberTwice Services are offered and can be subscribed to by You via the Microsoft Marketplace (both Microsoft Azure Marketplace and the Microsoft AppSource). Any subscription is subject to the general terms and conditions specified on the marketplaces, further detailed by the CyberTwice contractual framework, specifically the CyberTwice Subscription Agreement. As stated therein, every solution can have specific terms relevant to the nature of the service, i.e. the Subscription Details. These CyberTwice ATTEST Subscription Details provide subscription details for the CyberTwice ATTEST Service, which captures and centrally stores all surveillance and communication streams within the Microsoft Teams environment for attestation purposes.

1.1 Definitions

  • CyberTwice ATTEST - The Microsoft Azure-based Attestation service from CyberTwice which allows for the Capture and replay (Communicate) of enterprise communication & surveillance Interactions, enabling Attestation (Comply).
  • ATTEST Replay - The Microsoft Teams App (Application), which allows a user to search & replay Interaction captured in the CyberTwice ATTEST Service.
  • ATTEST Management Portal - The web portal which allows for the administration of the CyberTwice ATTEST Service.
  • Attestation - an act of showing or evidence showing that something is true.
  • Interaction - An interaction is a (enterprise) communication or surveillance stream captured within the CyberTwice ATTEST Service, examples are Microsoft Teams calls, (Microsoft Teams) phone calls, Microsoft Teams meetings, public announcement (paging systems), intercoms calls or camera footage.
  • Pricing Component - The drivers of cost within the CyberTwice ATTEST Service as defined in §2.3.
  • Type - the type of media used within an Interaction, e.g., video, audio.
  • Recording Hour - see §2.3.
  • Overage - see §2.3.
  • Storage - see §2.3.
  • Microsoft (MS) Marketplace - being both Microsoft Azure Marketplace and the Microsoft AppSource.
  • Transcription - see §2.3.
  • Recorded User / Group - see §2.3.
  • Pricing Plan or Plan - see §2.1.
  • Advanced Services - see §2.2.
  • Microsoft Cognitive Services - services inherent to Microsoft Azure.
  • Retention Period - see §2.3.

2. Pricing Plans

2.1 Pricing Plans

The CyberTwice ATTEST Service is offered via the Microsoft Marketplace, where four Pricing Plans are available, namely: 'Per User', 'Starter', 'SMB' (Small to Medium size Businesses) and 'Business'.

2.2 Advanced Services

Each Pricing Plan consists of a fixed and a variable fee:

  • Fixed monthly fee, which includes a defined recording and storage volume, respectively, Recording Hours and Storage (in GiB).
  • Variable fee, which can be on Overage, being the volume exceeding the volume included in the respective Pricing Plan for each Pricing Component, i.e., the Recording Hours and Storage (and for the "Per User" plan, the Recorded Users); Advanced Services, being features and functionality, typically Microsoft Azure Cognitive Services switched on within the CyberTwice ATTEST Management Portal or the ATTEST Replay application, e.g., the speech-text service (Transcription).

The price for each Plan is given on the CyberTwice ATTEST Pricing page.

2.3 Pricing Components

The CyberTwice Attest Services pricing is based on the following Pricing Components:

  • Recording Hours - The duration of the captured interaction, i.e., a teams call, meeting, or 'phone call' (Interaction). This metric is irrespective of the media type (Type) in the interaction, so it can include audio, video, or screen capture.
  • Storage - The total storage capacity in GiB used. The storage used is dependent on multiple factors, namely Recording Hours, Type, and the period during which the Interaction must remain stored in CyberTwice ATTEST (Retention Period).
  • Recorded User - A user is known in the Microsoft Active Directory that has been placed in the recorded (Microsoft Azure) group (Recorded Group), for which all Interactions will be recorded in CyberTwice ATTEST. (is only a Pricing Component in the 'User' Plan).
  • Transcription - An Advanced Service comprising the conversion of the audio in an Interaction to a text (speech-to-text), whereby the duration (in minutes) of the Interaction is the measure of calculation.

3. Suspension and Cancelation

3.1 In accordance with the Microsoft Commercial Marketplace Terms of Use and our Subscription Agreement, we may suspend or cancel your access to any Offers or CyberTwice Services for any of your violations of these terms. As per these terms, Suspension or Cancellation of access for non-payment could result in data loss. Therefore, for the CyberTwice ATTEST Offers, we uphold the policy specified in this article.

3.2 Suspension

When your account has been Suspended, the recording and processing of the resulting data function will remain active. However, the ATTEST Replay application in Microsoft-Teams will be blocked, so access to all your data is blocked, i.e., Customer can, amongst others, no longer play the calls. The ATTEST Management Portal remains available, but a clear banner indicates that the Subscription is Suspended. At the same time, a notification email will be sent to the Registered User, the user from whom the email account is used to subscribe to the CyberTwice ATTEST Service or any other email address entered for this purpose in the Attest Management Portal.

3.3 Cancellation (or Unsubscribe)

When a Customer Unsubscribes or Cancels a Subscription the recording and all processing of corresponding data will stop on the end date of the Subscription and access to the ATTEST Replay application will be blocked for all users. The ATTEST Management Portal remains available displaying a clear banner indicating that the Subscription is Unsubscribed or Cancelled. Three (3) working days after the end date of the Subscription Term all data will be removed from the CyberTwice ATTEST Service, irrespective of the Retention Period set. The Registered User will be informed of the exact end date by email in a timely manner, typically ten (10) calendar days before and on the end date of the Subscription.

Note: If Customer wants to retain any data upon cancellation, Customer must download all relevant data for the CyberTwice ATTEST Service before the end date using the ATTEST Replay application. As per §3.1, We cannot be held responsible or liable for any loss of data caused by Customers' neglect in this matter.

3.4 Cancellation upon Suspension

In case the Subscription is Suspended as per §3.3 the only option for the Customer to access, and if desired retrieve, it's data is by paying the outstanding fees before the Subscription is automatically cancelled and the data is deleted as described in §3.3. Customer will be notified by email to the Registered User in a timely manner as per §3.3.

3.5 Cancellation Notice

Irrespective of the reason for Cancellation of the CyberTwice ATTEST Subscription it remains the sole responsibility of the Customer to ensure a proper abandonment of our CyberTwice Service, taking due notice of the stated in §3.3 Cancelation and §4.2 Compliance Recording. At the same time, the sole obligation of Us is to inform the Registered User as stated in these Articles.

4. Specific Features

4.1 Retention

Retention is the total period that Interactions, including any associated data, like the Transcription, meta-data, remain stored in the Cybertwice ATTEST Service. The Retention Period can be set in the ATTEST Management Portal for all Recorded Groups. When the Retention Period for an Interaction ends all Interaction Data will be automatically deleted from the CyberTwice ATTEST Service.

4.2 Compliance Recording

A selectable feature of the CyberTwice ATTEST Service is Compliance recording. Compliance recording is an inherent feature within Microsoft Teams, mainly intended for financial services organizations to ensure that every Interaction is recorded for attestation. A consequence of setting this feature is that, if for whatever reason a call from the Microsoft Teams environment is not accepted, or better said not recorded, by the CyberTwice ATTEST Service the Microsoft Teams call will not be established. In essence, the Microsoft Teams user will be prohibited by Microsoft Teams from interacting, i.e. prohibited from making phone calls, teams calls and teams meetings.

4.3 Encryption & Authenticity

4.3.1 Data Encryption

The CyberTwice ATTEST Service ensures that all Interactions with the CyberTwice ATTEST Service are fully encrypted using an AES-GCM encryption with a 256-bit length Key, a 96-bit Nonce (IV) and a 128-bit authentication tag. The unique key is encrypted/wrapped with a 2048-bit RSA stored in an Azure-hosted (HSM) (Key Vault).

4.3.2 Authenticity

The authenticity of all Interactions stored within the CyberTwice ATTEST Service is ensured by signing of all the data. The signature is created by hashing (SHA256) a selected set of metadata/properties of the blob that includes the encryption metadata, tenant ID, the encrypted size and the original size. The hashed data is signed with an RSA-2048 key using RS256 (RSA signature with SHA-256). In order to verify the actual blob is authentic at least one block of data needs to be decrypted (this verifies the encryption key is correct).

5. Miscellaneous

5.1 Data Protection

The CyberTwice ATTEST Service captures, stores and processes Interactions, including any associated meta-data. We fully recognize that the data held within the CyberTwice ATTEST Service may contain Personal Data, which is subject to various privacy laws.

We ensure that we take appropriate technical and organizational measures to safeguard this information as stipulated in the CyberTwice Data Processing Agreement and detailed in our Legal, Security and Privacy section of which the Encryption and Authenticity feature highlighted under §4.3 of the CyberTwice ATTEST Service is an underpinning example.

CyberTwice ATTEST Subscription Details - Version 1.0 - dated April 1, 2023