Service Schedule
TMW Shield DDoS Protection – Service Schedule and License Terms
This Service Schedule ("Schedule") sets out the specific terms for the "TMW Shield" DDoS protection service ("Service") provided by Tizian Maxime Weigt, trading as TMW Global Networks ("Provider") to the customer identified in the applicable order or service contract ("Customer").
Unless explicitly stated otherwise, this Schedule forms part of and is subject to the Provider's general terms and conditions and any master service agreement between Provider and Customer ("Main Agreement"). In case of conflict, any individually negotiated written agreement prevails over this Schedule, and this Schedule prevails over general online terms for the scope of the Service.
See also: Terms & Conditions and Privacy Policy.
1. Definitions
1.1 “Protected Assets” means the IP prefixes, IP addresses, ASN, domains, or services that the Parties agree in writing to protect using the Service.
1.2 “Clean Traffic” means traffic toward the Protected Assets after processing by the Service's filtering mechanisms, excluding traffic identified as malicious or non-compliant with this Schedule.
1.3 “DDoS Attack” means an intentional attempt to make Customer's services unavailable or to degrade their performance by generating malicious network or application traffic against the Protected Assets.
1.4 “Mitigation” means the technical measures taken by the Provider to detect, classify, rate-limit, block, or otherwise filter traffic associated with a DDoS Attack while attempting to preserve Clean Traffic.
1.5 “Service Order” means the order, proposal, or contract document specifying commercial terms for the Service (pricing, term, mitigation profile, capacity, locations, and other parameters).
2. Scope of Service
2.1 Provider will deliver DDoS protection for the Protected Assets as described in the Service Order and technical service description (e.g. L3/L4 volumetric mitigation, always-on or on-demand modes, BGP diversion, GRE/IPIP tunnels, or direct handoff on Provider's network).
2.2 The Service monitors traffic to the Protected Assets for anomalies and DDoS patterns and, upon detection, attempts to separate suspicious traffic from Clean Traffic and to drop or rate-limit malicious flows.
2.3 The Service is a mitigation and risk reduction service, not an absolute guarantee of uninterrupted availability; residual impact (e.g. partial packet loss, increased latency, collateral blocking of some legitimate traffic) may occur during Mitigation events.
3. Relationship to Other Services
3.1 The Service can be provided as:
- an add-on to Provider IP transit, hosting, or remote protection services, or
- a standalone DDoS protection service (e.g. remote GRE/BGP scrubbing).
3.2 Where the Service is bundled with network or hosting products, the term of this Schedule will not exceed the term of the underlying connectivity or hosting agreement unless explicitly agreed otherwise in writing.
3.3 Any additional connectivity, hosting, or professional services are governed by their respective service descriptions and are not included in this Schedule unless explicitly referenced.
4. Service Activation and Configuration
4.1 As a condition of activation, Customer must provide all technical information necessary for delivery of the Service, including (as applicable) ASNs, IP prefix lists, BGP configuration details, tunnel endpoints, contact information, and escalation paths.
4.2 Provider will, in coordination with Customer, deploy the required routing and filtering configuration to direct traffic for Protected Assets through the Service (for example, adjusting BGP announcements, static routes, and/or tunnel configurations).
4.3 Customer is responsible for promptly informing Provider of any material changes to its network topology, IP addressing, or routing that may affect the Protected Assets or the effectiveness of the Service.
4.4 Test traffic and controlled simulations may be performed by mutual agreement to validate configuration and detection thresholds; any DDoS test or penetration test involving the Service must be agreed in advance with Provider, including date, time, and expected patterns.
5. Service Levels
5.1 Unless otherwise specified in the Service Order, Provider operates the Service on a best-effort basis with commercially reasonable efforts to detect and mitigate DDoS Attacks promptly, in line with industry practices.
5.2 If the Parties agree on quantitative SLA targets (e.g. time-to-detect, time-to-mitigate, maximum unmitigated attack size), these will be documented in the Service Order or a separate SLA document. Such targets, service credits, and exclusions shall form part of this Schedule only if explicitly referenced.
5.3 Any service credits are the sole and exclusive remedy for failure to meet agreed SLA targets, and will be applied as future service credits (not cash refunds), subject to the conditions and claim procedures defined in the SLA.
6. Customer Responsibilities
6.1 Customer shall:
- maintain accurate and up-to-date technical information as required under Section 4;
- ensure its systems meet the minimum technical requirements (e.g. BGP capability, tunnel endpoints, routing policies, firewall rules) communicated by Provider; and
- maintain a reachable 24/7 NOC or emergency contact for DDoS-related escalations.
6.2 Where the Service is deployed using BGP, Customer must follow Provider's routing guidelines (e.g. announcing specific prefixes only via Provider for protection) to ensure proper diversion and mitigation of attack traffic.
6.3 Customer must cooperate with Provider during active incidents, including implementing recommended changes, providing logs or packet captures, and approving temporary measures (e.g. temporary blackholing or stricter filtering) when necessary to stabilize the network.
6.4 Customer is solely responsible for the security, configuration, and availability of its own applications, operating systems, and infrastructure components that are not explicitly part of the Service (e.g. web server hardening, application-layer WAF, rate limiting on origin servers).
7. Acceptable Use and Prohibited Activities
7.1 Customer may not use the Service or underlying infrastructure for any unlawful purposes or in violation of applicable law, including but not limited to attacking third-party systems, distributing malware, or hosting illegal content.
7.2 Customer may not deliberately generate or commission DDoS traffic (other than controlled tests agreed under Section 4.4) for purposes other than the protection of its own services, and may not resell or expose the Service as a DDoS "stresser/booter" or similar offering.
7.3 Provider may suspend or restrict the Service, with or without prior notice, where Customer's use of the Service:
- violates this Schedule or the Main Agreement;
- presents a material risk to Provider's infrastructure or to third parties; or
- significantly exceeds reasonable and expected use (e.g. repeated abnormal traffic for non-legitimate purposes).
8. Technical and Capacity Limitations
8.1 The Service is designed to mitigate DDoS Attacks up to the technical thresholds and capacities described in the Service Order and/or Provider's technical documentation. Attacks exceeding those thresholds may result in reduced effectiveness, residual service impact, or the need for emergency measures (e.g. traffic blackholing).
8.2 The effectiveness of the Service depends on factors beyond Provider's direct control, including upstream carriers, third-party networks, and the behavior of intermediary systems on the path between end-users and the Protected Assets.
8.3 Provider does not guarantee mitigation of every possible attack vector or zero downtime; sophisticated attacks, zero-day vectors, or combined multi-layer attacks may cause partial or temporary unavailability despite active Mitigation.
9. Emergency Measures and Suspension
9.1 In order to protect the stability of its network and other customers, Provider may, in good faith:
- temporarily block or rate-limit traffic toward specific prefixes or protocols;
- null-route or withdraw specific routes; or
- temporarily disable the Service for specific Protected Assets or tunnels,
if necessary to address extreme or unexpected events, including but not limited to DDoS Attacks beyond design capacity.
9.2 Provider will, where reasonably possible, coordinate emergency measures with Customer and restore normal operation as soon as practicable once the situation has stabilized.
9.3 Repeated abuse or violation of the Acceptable Use rules may result in termination for cause according to the Main Agreement.
10. Fees and Billing
10.1 Fees for the Service (recurring charges, setup fees, burst or overage charges, and professional services) are defined in the Service Order.
10.2 Unless otherwise agreed, recurring fees are billed in advance for each billing period; any variable or overage-based components may be billed in arrears based on Provider's measurement systems.
10.3 In case of non-payment or significant payment default, Provider may suspend or terminate the Service in accordance with the Main Agreement, after any required notice period.
11. Data, Logs and Privacy
11.1 For the purpose of delivering and improving the Service, Provider may collect, store, and process network telemetry and security data relating to the Protected Assets, including but not limited to flow records, packet samples, attack fingerprints, and alert logs.
11.2 To the extent such data includes personal data within the meaning of applicable data protection laws (e.g. IP addresses linked to individuals), Provider will process such data as a processor or controller (as applicable) in accordance with the Main Agreement and any separate data processing agreement.
11.3 Provider may use aggregated and anonymized statistics derived from attack and traffic data (e.g. attack volume trends, vectors) for reporting, capacity planning, and improvement of the Service, provided that no Customer-identifying information is disclosed to third parties without Customer's consent.
12. Intellectual Property and License
12.1 All intellectual property rights in the Service, including filtering logic, rule sets, eBPF/XDP programs, configuration templates, management portals, and documentation, remain the sole property of Provider or its licensors.
12.2 Subject to full payment of applicable fees and compliance with the Main Agreement and this Schedule, Provider grants Customer a non-exclusive, non-transferable, limited license to use the Service for the term set out in the Service Order, solely for protection of the Protected Assets.
12.3 Customer may not reverse engineer, decompile, or attempt to derive the source code of software or filtering logic used in delivering the Service, except to the limited extent permitted by mandatory law.
13. Liability
13.1 The liability provisions of the Main Agreement and/or Provider's general terms and conditions apply to the Service.
13.2 In particular, and without prejudice to mandatory law, Provider's liability for slight negligence may be limited to foreseeable, contract-typical damages, and any liability for indirect or consequential damages (such as loss of profit, loss of data, or loss of goodwill) may be excluded to the extent permitted by law.
13.3 Customer acknowledges that the Service is designed to reduce the likelihood and impact of DDoS Attacks but cannot eliminate all risks; allocation of residual risk and Customer's internal business continuity measures remain Customer's responsibility.
14. Term and Termination
14.1 The initial term of the Service and any renewal terms are specified in the Service Order.
14.2 Each Party may terminate the Service in accordance with the notice periods and termination rights set out in the Main Agreement, including for cause in the event of material breach.
14.3 Termination of the Service does not affect any other services that remain in force under separate orders or schedules, unless expressly stated otherwise.
15. Governing Law and Jurisdiction
15.1 Unless otherwise agreed in the Main Agreement, this Schedule is governed by the laws of the Federal Republic of Germany, excluding its conflict of laws provisions and the UN Convention on Contracts for the International Sale of Goods (CISG).
15.2 To the extent legally permissible, the exclusive place of jurisdiction for all disputes arising out of or in connection with the Service shall be the registered office of Provider.