CSS Service Agreement
Incorporated in our Quotes and other Forms
SERVICE AGREEMENT
Computer Sales & Services, Inc.
1. AGREEMENT STRUCTURE; SERVICES
1.1 Agreement Documents. This Agreement, each executed quote, proposal, service schedule, order form, statement of work (“SOW”), and any expressly incorporated addendum constitute the entire agreement for the applicable services. If documents conflict, the order of precedence is: (a) a later signed SOW or service schedule that expressly identifies the provision being superseded; (b) this Agreement; and (c) any other incorporated document.
1.2 Scope. CSS will provide only the services expressly identified as included in the applicable SOW or service schedule. A description of CSS as a managed service provider, technology advisor, security provider, or similar term does not expand the scope of services.
1.3 Supported Environment. Unless otherwise stated in an SOW, covered software and hardware must be commercially supported by the applicable manufacturer or publisher. CSS may decline to support obsolete, end-of-life, end-of-support, unlicensed, materially insecure, or undocumented systems, or may support them on a best-efforts, separately billable basis.
1.4 Changes. Changes to scope, quantities, locations, devices, users, security requirements, or service levels may require a written change order, revised service schedule, or SOW and an equitable adjustment to fees.
2. FEES; BILLING; PAYMENT
2.1 Fees. Client shall pay the fees stated in the applicable service schedule, quote, or SOW. Unless otherwise stated, recurring managed-service fees are billed monthly in advance and project, hardware, software, travel, after-hours, and out-of-scope charges are billed as incurred.
2.2 Taxes. Client is responsible for applicable sales, use, excise, and similar taxes, excluding taxes based on CSS’s net income.
2.3 Payment. Invoices are due within thirty (30) days unless the applicable service schedule states otherwise. Undisputed past-due amounts may accrue lawful interest and may result in suspension after reasonable notice. Client shall promptly identify any disputed charge and pay all undisputed amounts when due.
2.4 Payment Security. CSS may require electronic payment authorization through a payment processor. Client shall not transmit complete payment-card credentials by ordinary email or include them in this Agreement.
3. TERM; RENEWAL; TERMINATION
3.1 Term. The initial term is stated in the applicable service schedule. Unless otherwise stated there, recurring services renew for successive one-year terms unless either Party gives at least thirty (30) days’ written notice before the then-current term expires.
3.2 Termination for Cause. Either Party may terminate for a material breach not cured within thirty (30) days after written notice; provided that CSS may suspend or terminate sooner for nonpayment, unlawful use, material security risk, or conduct that threatens CSS, Client, or third-party systems.
3.3 Transition. Upon termination and payment of all undisputed amounts, CSS will reasonably cooperate in transition. Transition, export, documentation, migration, and offboarding work beyond ordinary account closure is billable at CSS’s then-current rates unless otherwise stated in an SOW.
4. CLIENT COOPERATION AND RESPONSIBILITIES
4.1 Access and Information. Client shall timely provide authorized access, accurate information, facilities, credentials, licenses, approvals, and knowledgeable personnel reasonably necessary for CSS to perform the services.
4.2 Authorized Instructions. CSS may rely on instructions from Client’s designated contacts. Client is responsible for promptly updating its authorized-contact list and for the acts and omissions of its employees, contractors, vendors, and authorized users.
4.3 Legal and Regulatory Requirements. Client is responsible for identifying laws, regulations, contractual requirements, data classifications, retention duties, and industry-specific obligations applicable to Client and its data, unless an SOW expressly assigns a particular compliance service to CSS.
4.4 Delay. CSS is not responsible for delay, failure, or increased cost to the extent caused by Client’s failure to satisfy its responsibilities under this Agreement.
5. CYBERSECURITY RISK; NO SECURITY GUARANTEE
5.1 Shared Responsibility. Client acknowledges that cybersecurity is a shared responsibility and that no computer system, network, cloud service, telecommunications system, security product, backup system, or cybersecurity practice can provide absolute protection.
5.2 No Guarantee. CSS will perform the services expressly purchased by Client using commercially reasonable care. Antivirus, endpoint protection, patching, monitoring, firewall management, backup monitoring, email security, multifactor authentication, or other IT or security-related services are intended to reduce risk and do not constitute a warranty, insurance policy, or guarantee that unauthorized access, malware, ransomware, phishing, business email compromise, social engineering, credential theft, zero-day exploitation, data loss, or service interruption will not occur.
5.3 External Events. To the fullest extent permitted by law, CSS is not responsible for loss to the extent arising from attacks or acts of third parties; compromised, reused, weak, stolen, or voluntarily disclosed credentials; Client or third-party acts or omissions; zero-day vulnerabilities; or defects, compromises, or outages involving third-party hardware, software, cloud, SaaS, Internet, telecommunications, hosting, identity, or security services.
5.4 Unsupported or Altered Systems. CSS is not responsible for loss to the extent caused by unsupported systems, unauthorized changes, disabled security controls, unapproved software, or changes made by Client or a third party without CSS’s knowledge or authorization.
6. PHISHING; SOCIAL ENGINEERING; FINANCIAL FRAUD
6.1 Verification Procedures. Client is solely responsible for establishing and enforcing procedures to independently verify requests involving wire transfers, ACH transactions, banking changes, payroll changes, vendor payment instructions, purchases, gift cards, disclosure of sensitive information, password resets, or account-credential changes. Verification should use a known, independent communication method and not contact information supplied solely in the request being verified.
6.2 Allocation of Risk. To the fullest extent permitted by law, CSS shall not be liable for losses resulting from Client or Client personnel acting on fraudulent communications, impersonation, phishing, social engineering, business email compromise, or fraudulent payment instructions, except to the extent caused by liability that may not lawfully be excluded or limited.
7. SECURITY CONTROLS; RECOMMENDATIONS; RISK ACCEPTANCE
7.1 Minimum Controls. CSS may condition managed services on Client maintaining reasonable minimum-security standards, including supported operating systems, multifactor authentication, managed endpoint protection, patching, backups, email security, administrative-access controls, and other safeguards reasonably appropriate to Client’s environment, and the training of Client’s own employees, contractors or authorized personnel doing business with Client, other than CSS.
7.2 Recommendations. CSS may recommend products, services, upgrades, replacements, configurations, policies, training, or safeguards. If Client declines, delays, disables, removes, fails to renew, or otherwise fails to implement a material recommendation, Client acknowledges and accepts the increased risk.
7.3 Documentation. CSS may document Client’s acceptance or rejection of a material recommendation in a proposal, ticket, email, risk-acceptance form, or other written record. To the fullest extent permitted by law, CSS is not responsible for loss to the extent caused by Client’s failure to implement or maintain a recommended safeguard.
7.4 Material Risk. If Client refuses to correct a condition CSS reasonably determines presents a material security risk, CSS may decline to manage the affected system or suspend or terminate the affected service upon written notice.
8. BACKUP; DISASTER RECOVERY; MALICIOUS ACTIVITY
8.1 Backup Scope. Unless backup and disaster-recovery services are expressly included in an SOW, Client is responsible for maintaining adequate backups and recovery capability.
8.2 No Recovery Guarantee. Where CSS provides backup or disaster-recovery services, Client acknowledges that such services reduce risk but cannot guarantee that every file, application, configuration, system, or point in time will be recoverable. Client shall identify critical systems and communicate required recovery-time objectives, recovery-point objectives, retention requirements, and legal or regulatory requirements.
8.3 Malicious Activity. Virus infection, malware, ransomware, encryption by a threat actor, destructive cyberattack, data reconstruction, forensic recovery, and rebuilding following malicious activity are outside ordinary managed-service coverage and are separately billable unless an SOW expressly states otherwise.
9. CYBERSECURITY INCIDENT RESPONSE; DATA BREACH
9.1 Notice to CSS. Client shall promptly notify CSS of any known or suspected cybersecurity incident affecting systems supported by CSS.
9.2 Incident Services. Unless expressly included in Client’s service plan, investigation, forensics, containment, eradication, restoration, data reconstruction, legal or regulatory assistance, notification support, and other incident-response work are additional billable services. CSS’s assistance after an incident is not an admission that CSS caused or was responsible for the incident.
9.3 Legal Notifications. Each Party remains responsible for legal obligations imposed directly upon it. Client is responsible for obtaining legal advice regarding notices to affected persons, regulators, insurers, law enforcement, or other parties, except for a reporting obligation imposed directly on CSS by applicable law.
9.4 Louisiana Personal Information. Nothing in this Agreement relieves either Party of duties that cannot lawfully be transferred or waived under the Louisiana Database Security Breach Notification Law, La. R.S. 51:3071 et seq., including applicable duties concerning reasonable security procedures and breach notification.
10. THIRD-PARTY PRODUCTS AND SERVICES
10.1 Third-Party Terms. Hardware, software, cloud services, licenses, subscriptions, telecommunications, and other third-party products may be governed by separate vendor terms, warranties, acceptable-use policies, and privacy terms. Client authorizes CSS to procure or administer such products when included in an SOW.
10.2 Vendor Failures. CSS does not manufacture or control third-party products and, to the fullest extent permitted by law, is not liable for vendor defects, vulnerabilities, outages, discontinuation, price changes, licensing changes, data practices, or failures outside CSS’s reasonable control.
10.3 Pass-Through Rights. To the extent assignable, CSS will pass through to Client applicable manufacturer or vendor warranties or remedies received by CSS for Client’s benefit.
11. CONFIDENTIALITY; CLIENT DATA
11.1 Confidential Information. Each Party shall use reasonable care to protect the other Party’s nonpublic business, technical, security, pricing, and personal information disclosed in connection with the services and shall use such information only for purposes of the relationship, except as required by law or as reasonably necessary to perform the services.
11.2 Client Data. As between CSS and Client, Client retains ownership of Client data. Client grants CSS and its approved service providers the limited rights reasonably necessary to host, access, transmit, copy, process, back up, and otherwise handle Client data to provide the services.
11.3 Security Information. Client shall not disclose CSS security architecture, credentials, security reports, penetration-test results, or other information that could reasonably facilitate an attack, except to Client’s professional advisors, insurers, regulators, or as required by law.
12. CYBER INSURANCE
Client acknowledges that managed IT and cybersecurity services are not substitutes for insurance. CSS strongly recommends that Client maintain cyber liability and crime coverage appropriate to its operations, including, where appropriate, coverage for ransomware, breach response, business interruption, social engineering, fraudulent funds transfer, forensic investigation, regulatory proceedings, notification expense, and data restoration. Client is responsible for selecting coverage and limits with its insurance and legal professionals.
13. WARRANTY DISCLAIMER
EXCEPT FOR EXPRESS OBLIGATIONS STATED IN THIS AGREEMENT OR AN APPLICABLE SOW, AND TO THE FULLEST EXTENT PERMITTED BY LAW, THE SERVICES ARE PROVIDED WITHOUT ANY OTHER WARRANTY, EXPRESS OR IMPLIED, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ERROR-FREE OPERATION, UNINTERRUPTED OPERATION, OR ABSOLUTE SECURITY. CSS DOES NOT WARRANT THAT ALL THREATS, DEFECTS, VULNERABILITIES, OR INCIDENTS WILL BE DETECTED, PREVENTED, OR REMEDIATED.
14. LIMITATION OF DAMAGES AND LIABILITY
14.1 Excluded Damages. TO THE FULLEST EXTENT PERMITTED BY LAW, CLIENT SHALL HAVE NO RIGHT OF SETOFF OR CLAIM AGAINST CSS FOR LOST PROFITS, LOST REVENUE, LOST BUSINESS, LOSS OF GOODWILL, LOSS OF USE, LOSS OR CORRUPTION OF DATA, BUSINESS INTERRUPTION, COST OF RECREATING DATA, OR OTHER SPECIAL, INDIRECT, INCIDENTAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, EVEN IF SUCH DAMAGES WERE FORESEEABLE OR CSS WAS ADVISED OF THEIR POSSIBILITY.
14.2 Aggregate Cap. TO THE FULLEST EXTENT PERMITTED BY LAW, CSS’S AGGREGATE LIABILITY TO CLIENT OR ANY PERSON CLAIMING BY OR THROUGH CLIENT, ARISING FROM OR RELATING TO THIS AGREEMENT OR THE SERVICES, WHETHER IN CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE, SHALL NOT EXCEED THE FEES ACTUALLY PAID BY CLIENT TO CSS FOR THE SERVICES DIRECTLY INVOLVED DURING THE THIRTY (30) DAYS IMMEDIATELY PRECEDING THE OCCURRENCE TO WHICH THE CLAIM RELATES.
14.3 Nonwaivable Liability. Nothing in this Agreement excludes or limits liability that cannot lawfully be excluded or limited, including liability for intentional or gross fault or physical injury to the extent prohibited by Louisiana Civil Code article 2004.
14.4 Allocation of Risk. The Parties acknowledge that the fees reflect the allocation of risk in this Agreement and that CSS could not provide the services at the agreed pricing if CSS were required to insure or guarantee Client against all cybersecurity incidents, data loss, business interruption, fraudulent transactions, third-party failures, or technology risks.
15. INDEMNIFICATION
15.1 Client Indemnity. To the fullest extent permitted by law, Client shall defend, indemnify, and hold harmless CSS and its officers, directors, employees, agents, affiliates, and subcontractors from third-party claims, damages, liabilities, costs, and reasonable attorneys’ fees to the extent arising from Client’s instructions, specifications, unlawful conduct, misuse of services, infringement, Client data or content, acts or omissions of Client’s employees, contractors, vendors, or authorized users, failure to maintain security measures for which Client is responsible, or failure to follow documented material security recommendations, except to the extent caused by CSS fault for which liability may not lawfully be excluded or limited.
15.2 Procedure. The indemnified Party shall give reasonably prompt notice of a covered claim and reasonable cooperation. The indemnifying Party may control the defense with counsel reasonably acceptable to the indemnified Party, but may not settle a claim in a manner that admits fault by, imposes nonmonetary obligations on, or fails to fully release the indemnified Party without written consent.
16. NON-SOLICITATION
During the term and for twelve (12) months thereafter, to the extent permitted by applicable Louisiana law, Client shall not knowingly solicit for employment an employee of CSS who materially performed services for Client, except through a general solicitation not directed at CSS personnel. If Client hires such an employee in violation of this Section, the Parties agree that CSS’s recruiting, training, replacement, and business-disruption costs are difficult to determine and that Client shall pay CSS liquidated damages of Eighty Thousand Dollars ($80,000.00), not as a penalty, subject to reduction or nonenforcement to the extent required by applicable law.
17. FORCE MAJEURE
Neither Party is liable for delay or failure caused by events beyond its reasonable control, including natural disaster, fire, flood, severe weather, epidemic, war, terrorism, civil disturbance, labor disruption, utility failure, Internet or telecommunications failure, widespread cloud or vendor outage, governmental action, or cyberattack not caused by that Party’s fault; provided that the affected Party uses commercially reasonable efforts to mitigate and resume performance. Payment obligations for services already rendered are not excused.
18. CLAIMS; GOVERNING LAW; VENUE
18.1 Claim Period. To the fullest extent permitted by law, any action by Client arising out of or relating to this Agreement or the services must be commenced within one (1) year after the cause of action accrues.
18.2 Louisiana Law. This Agreement is governed by the laws of the State of Louisiana, without regard to conflict-of-law principles.
18.3 Venue. Exclusive venue for any action arising from or relating to this Agreement shall lie in a court of competent jurisdiction in Terrebonne Parish, Louisiana, and each Party consents to personal jurisdiction there.
18.4 Attorneys’ Fees. If CSS is required to institute collection proceedings for undisputed past-due amounts, Client shall pay reasonable attorneys’ fees and costs to the extent permitted by law. In any other action, attorneys’ fees shall be awarded only when authorized by contract or applicable law.
19. LOUISIANA PUBLIC BODY CUSTOMERS
If Client is a “public body” and CSS is a “provider” within the meaning of La. R.S. 51:2112, the Parties shall comply with applicable requirements of La. R.S. 51:2111 et seq. to the extent applicable to the services and incorporated into the public-body contract. Nothing in this Section transfers to CSS an obligation imposed directly upon Client unless this Agreement or an SOW expressly states otherwise. If a public-body-specific addendum or mandatory governmental term conflicts with this Agreement, that term controls only to the extent required by law.
20. NOTICES
Contractual notices under this Agreement shall be in writing and delivered personally, by nationally recognized overnight courier, by certified mail return receipt requested, or by email with confirmation of transmission to the addresses stated below or to a replacement address designated by notice. Operational tickets and routine service communications are not contractual notices unless they expressly state otherwise.
21. ASSIGNMENT; SUBCONTRACTORS
21.1 Assignment. Neither Party may assign this Agreement without the other Party’s written consent, not to be unreasonably withheld, except that CSS may assign it in connection with a merger, reorganization, sale of substantially all assets, or change of control.
21.2 Subcontractors. CSS may use qualified employees, affiliates, vendors, and subcontractors to perform services and remains responsible for its contractual obligations, subject to the limitations and exclusions in this Agreement.
22. ENTIRE AGREEMENT; AMENDMENT; SEVERABILITY
22.1 Entire Agreement. This Agreement and incorporated documents supersede prior or contemporaneous proposals, representations, discussions, and agreements concerning the same subject matter.
22.2 Amendment. No amendment or modification is effective unless in writing and signed by authorized representatives of both Parties, except that an executed service order, change order, or SOW may modify the services and fees it expressly addresses.
22.3 Severability. If a provision is held invalid or unenforceable, it shall be enforced to the maximum extent permitted by law and the remaining provisions remain in effect.
22.4 Waiver. A waiver is effective only in writing and only for the specific instance stated. Delay or failure to enforce a provision is not a continuing waiver.
22.5 Survival. Provisions that by their nature should survive termination, including payment obligations, confidentiality, cybersecurity risk allocation, warranty disclaimers, limitations of liability, indemnification, claims, and governing law, survive.
23. COUNTERPARTS; ELECTRONIC SIGNATURES
This Agreement may be executed in counterparts and by electronic signature, each of which is deemed an original and all of which together constitute one instrument. Additionally, by signing a quote, service intake form, or any other form referencing this document, customer acknowledges this agreement, and does not require the signature of CSS.






