Maintenance & Support Policy
Deeboon provides infrastructure maintenance and support services for clients, divided into three service tiers to match each client's usage patterns and system ownership structure.
Our Working Standards
Across every project Deeboon supports, we apply a shared baseline of working standards: security configuration following best practices, systematic data backups, and system monitoring to catch issues as early as possible. These standards cover the Server/Infrastructure level according to generally controllable standards, and form the foundation of every service tier. Care at the Application level of the website (such as WordPress Core, Plugins, Themes, or other non-WordPress application systems) follows the scope specified separately under each service tier below.
Service Tier Overview
| Standard Maintenance & Support | Client-owned Account Support | Enterprise Infrastructure Support | |
|---|---|---|---|
| Server/Cloud Account Owner | Deeboon | Client | Agreed case-by-case |
| Fee Structure | Flat monthly fee (Server/Infrastructure level) | Charged per intervention | Agreed case-by-case |
| Best suited for | Clients who want Deeboon to manage Server/Infrastructure without managing the account themselves | Clients who want to own the account themselves | Business-critical systems requiring a higher level of guarantee |
1. Standard Maintenance & Support
For clients who have Deeboon directly manage the Server/Cloud Account, this service includes the following:
- The fee is a flat monthly rate covering Server/Infrastructure-level care: Security Setup, Backup, and Monitoring, based on generally controllable standards at the server level.
- This monthly fee does not include care or troubleshooting at the Application level of the website — for example, updating WordPress Core, Plugins, Themes, or resolving Application-level issues — regardless of whether the cause is a lack of updates, plugin conflicts, or other factors. This scope applies to all types of Application systems, not limited to WordPress.
- Deeboon will investigate and resolve Application-level issues once notified by the client, and will inform the client of the additional scope of work and cost (per-incident) for consideration before proceeding each time.
- Any instances where Deeboon has previously assisted with Application-level issues at no charge were case-by-case decisions made to maintain a good client relationship. This does not form part of the standard service scope and does not constitute a precedent binding Deeboon to provide the same service free of charge in the future.
2. Client-owned Account Support
For clients who own their own Server/Cloud Account, Deeboon provides intervention and troubleshooting services upon request, under the following conditions:
Scope of Service
- Investigate and resolve issues as requested by the client, or by prior agreement for scheduled inspections.
- The scope of each intervention will be communicated to and confirmed with the client before proceeding, except in pre-agreed emergency cases.
- Does not include ongoing proactive monitoring, unless an additional scope is agreed upon.
- Covers both Server/Infrastructure-level and Application-level work (e.g., WordPress Core, Plugins, Themes) as requested each time, charged on a per-incident basis for both levels alike.
Access Requirements
- The client must grant the Deeboon team full (100%) access to the systems relevant to each intervention.
- This service is direct hands-on troubleshooting, not advisory or instructional support for the client to fix issues themselves — since root-cause investigation typically requires deep, step-by-step, hands-on inspection and cannot be summarized into advance instructions or handed off as a recommendation.
- If access is incomplete or direct intervention cannot be granted, Deeboon reserves the right to decline to proceed with that case.
Fees
- Charged per intervention (per-incident), based on the nature and complexity of the work.
- The client is directly responsible for Cloud/Server costs according to the provider's billing, separate from Deeboon's service fees.
3. Enterprise Infrastructure Support
For businesses where the website or system is central to operations, every minute of downtime carries significant business cost.
Deeboon can design an Enterprise-level service that raises the level of stability and guarantee beyond the standard service, which may cover:
- High Availability / Redundant Infrastructure
- Clear Service Level Agreements (SLAs) for Uptime and response time
- Disaster Recovery plans
- 24-hour monitoring and incident response
- A higher level of damage guarantee than the standard service
This service tier requires a needs assessment and mutually agreed terms on a case-by-case basis.
Response Times
Deeboon sets response levels based on issue severity (used as guidance for Standard Maintenance & Support and Client-owned Account Support):
| Severity | Example | Response Approach |
|---|---|---|
| Critical | Website completely down, inaccessible | Respond as quickly as possible during business hours, top priority |
| High | Core functions partially unusable | Respond within business hours |
| Normal | General issues, no impact on core usage | Handled per normal work queue |
Communication During Incidents
When an incident affecting system usage occurs, Deeboon will communicate with the client continuously as appropriate to the situation. Once the issue is resolved, Deeboon will provide the client with a summary of the root cause and the resolution approach, for transparency and to reduce the chance of recurrence.
Scope of Responsibility
Deeboon operates under good system administration standards covering security, backups, and monitoring. However, regardless of service tier, Deeboon is not liable for damages in the following cases:
- Business or revenue losses.
- Data damage or loss arising from force majeure, cyberattacks, or system failures outside of Deeboon's control.
- Damage to business reputation or image.
- Damage caused by third-party actions.
- Damage resulting from insufficient or untimely system access being granted.
Clients who require a higher level of guarantee may discuss upgrading to Enterprise Infrastructure Support.
Third-Party License and Service Costs
Costs for licenses of tools, plugins, software, or third-party services used on the website or system — including annual fees and renewals — are the client's direct responsibility.
Work Outside the Service Scope
If, during system maintenance, work is identified that falls outside the agreed scope — such as new feature development, fixing issues caused by pre-existing system architecture from before the service began, changes to Business Logic, fixing and restoring a system following a cyberattack or breach (see "Cybersecurity Incidents & Hacking" below for details), or (for Standard Maintenance & Support clients) Application-level updates and fixes such as WordPress Core, Plugins, or Themes — Deeboon will notify the client of the scope and provide a quote for consideration before proceeding each time. Deeboon will not proceed in advance without client confirmation.
Cybersecurity Incidents & Hacking
Fixing, restoring, or otherwise responding to a website or system that has been attacked, hacked, or infected with malware is always considered work outside the scope of the standard monthly maintenance fee, regardless of the cause, and regardless of whether the damage appears at the Application level or spreads to affect the Server/Infrastructure level. Deeboon will notify the client of the scope of work and provide a remediation quote (per-incident) for consideration before proceeding each time.
To help reduce the risk of attack, clients are required to keep WordPress Core updated on a regular basis, at minimum twice per year, whether performed by the client themselves or through an update service from Deeboon. Meeting this minimum requirement does not constitute a guarantee that the website will not be attacked or breached, since security vulnerabilities can arise from many factors outside Deeboon's control — for example, zero-day vulnerabilities with no available patch, third-party plugins or themes, leaked account credentials, or attacks originating from other systems outside Deeboon's responsibility.
Deeboon is not liable for damages arising from a cyberattack, regardless of whether the client has met the minimum update requirement above. This is consistent with what is already stated under "Scope of Responsibility" in this policy.
PDPA Compliance
Deeboon recognizes the importance of personal data protection under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), and follows these practices:
- Where the service involves accessing or processing personal data belonging to the client or the client's end users, Deeboon acts as a Data Processor, acting only per the client's instructions and stated purposes.
- Deeboon will safeguard any personal data accessed during service delivery with appropriate security measures, and will not use or disclose it beyond the purpose of the service.
- For projects involving significant access to end-user personal data (such as customer databases, membership systems, or transaction systems), it is recommended that a separate Data Processing Agreement be established to further clarify PDPA scope and responsibilities beyond this policy.
- The client, as the Data Controller, is responsible for determining the purposes and legal basis for data processing, and for notifying data subjects of their rights as required by law.
Confidentiality and Data Ownership
All client data and systems that Deeboon accesses in order to perform maintenance remain the full property of the client. Deeboon will keep confidential any data accessed during the course of service, and will not disclose or use it beyond the purpose of the service. Upon termination of service, Deeboon will transfer access rights and related data back to the client as appropriate.
Contact Us
If you have any questions about this policy or your system maintenance plan, please contact us at:
Email: info@deeboon.com
Last updated: September 7, 2026