Master Services Agreement & Statement of Work

Milestones, assumptions, exclusions, acceptance criteria, and managed support SLAs.

Scope of Work (Summary)

  • Core Databricks deployment in client tenant with secure networking, SSO/SCIM, Unity Catalog.
  • Ingestion templates, Delta Lake patterns, IaC/CI/CD, monitoring, cost governance, runbooks.
  • GxP-aware validation pack (fit-for-purpose). Enhanced CSV package optional.
  • Optional add-ons (also available standalone): Source Connectors (EDC, CTMS, Safety, eTMF, LIMS) and Write-back framework/use cases.

Milestones & Payments (example: Core + 2 connectors)

  1. M1: Kickoff, Requirements & Architecture (20%)
    Deliverables: discovery outputs, target architecture, validation approach, project plan.
  2. M2: Security & Landing Zone (20%)
    Deliverables: SSO/SCIM, network & secrets, workspace provisioning.
  3. M3: Core Platform Build (20%)
    Deliverables: Unity Catalog taxonomy, Delta patterns, ingestion templates, IaC/CI/CD, monitoring.
  4. M4: Integrations Build & UAT (30%)
    Deliverables: two connectors live (incremental ingestion, harmonization, DQ, curated outputs), UAT sign-off.
  5. M5: Handover & Hypercare Start (10%)
    Deliverables: runbooks, training, acceptance, transition to managed support.

Write-back (if included)

  • Governance & workflows (maker/checker), audit trails, idempotent flows, error handling.
  • Framework delivery, first use case UAT, controlled release with validation evidence.

Assumptions

  • Client provides timely access to environments, SSO/IDP, credentials, sandbox/test data, data dictionaries, security reviews.
  • Databricks/cloud/security tooling licensed by client.
  • Validation is fit-for-purpose; enhanced CSV available as add-on.
  • Study template variability priced per template beyond the first.

Exclusions

  • Dashboard/report building, statistical programming, or custom AI models (we enable them).
  • Full SOP authoring & CSV program management (available as add-on).
  • 24×7 support (available as add-on).

Acceptance Criteria

  • Core: secure deployment, SSO, UC established, ingestion templates/jobs running, monitoring live, validation evidence, runbooks delivered.
  • Connectors: initial + incremental loads, DQ checks, harmonized outputs, lineage, UAT sign-off.
  • Write-back: maker/checker approvals, audit trails, error handling/retry, UAT sign-off, controlled release validation complete.

Service Levels (Managed Support)

Coverage: business hours (agreed time zone), excluding holidays.
Response Times: P1: 2h first response/1 business day workaround; P2: 4h/2 business days; P3: 1 business day/fix scheduled.
Availability & DR: best-effort aligned to client cloud SLOs; DR per client infra.
Reporting: monthly ticket metrics and platform health review.

Commercial Terms

  • Invoices at milestones; net 30. Travel and pass-through costs pre-approved and billed at cost.
  • Change control for out-of-scope requests with fee/timeline impact.
  • 30-day warranty for defects in delivered code/configs not caused by third-party/client changes.
  • IP: client owns deliverables; Pharmastructure retains templates/accelerators with a perpetual internal-use license to client.
  • Security & compliance: least-privilege access; no PHI in non-prod without approval; data processing under DPA; regional controls respected.
  • Confidentiality: mutual NDA; publicity requires consent (Design Partner includes reference rights).
  • Termination for convenience with 30 days’ notice; client pays for work performed to date.