Statement of Work
The fixed-scope terms that apply to every OvernightOps engagement. These terms are accepted when you authorize payment at checkout.
Last updated 1 October 2026
This Statement of Work ("SOW") is entered into between the client identified at checkout ("Client", "you") and DataRiver New Zealand Limited, NZBN 9429050155972, trading as OvernightOps ("Provider", "we", "us"). By authorizing payment you accept this SOW together with our Terms of Service.
1. Engagement model and asynchronous boundaries
The Client engages the Provider strictly on an asynchronous, deliverable-based basis. The engagement does not include synchronous meetings, daily stand-ups, video or voice calls, or direct chat communications. All requirements, questions and feedback are exchanged exclusively through structured order metadata, Git pull-request commentary, or the secure delivery portal.
The deliverable, turnaround tier and price are fixed at the moment of checkout and correspond exactly to the deliverable SKU selected.
2. Input requirements and the SLA clock
Execution commences upon payment authorization and the provision of complete target specifications, being either (a) read-only repository access via a repository URL and a read-only deploy token, or (b) at least 250 characters of written specification covering the current state, the target state, the environments involved and the acceptance criteria.
If the inputs provided are incomplete, ambiguous, or cannot be used (for example, an expired or insufficiently permissioned token), the delivery clock is paused from the moment we notify you until usable inputs are supplied. The paused time does not count toward the turnaround commitment.
3. Deterministic deliverables and output format
Deliverables are limited to the exact technical artifact selected at checkout. Depending on the SKU, the completed artifact may include:
- Infrastructure: a modular Terraform or Bicep codebase with remote state configuration, a typed variable schema and validation evidence.
- CI/CD: production-ready GitHub Actions or Azure DevOps YAML with caching, secret binding and artifact publishing.
- DevSecOps: an integrated quality gate or static-analysis pipeline stage, scanning configuration and a prioritised remediation plan; or a hardened multi-stage Dockerfile with image scanning and automated SBOM generation.
- Observability: Prometheus scrape configuration, an OpenTelemetry collector pipeline and production Grafana dashboards with alert rules.
- Integration: an event-driven serverless bridge with OAuth 2.0 authentication, schema validation, retry handling and error capture.
Delivery is formally executed when a pull request is pushed to the Client's repository, or when an artifact bundle is made available through the secure delivery portal, and the Client is notified.
4. Objective acceptance criteria
A deliverable is deemed accepted when it satisfies the acceptance criteria selected at checkout, which by default include:
- the deliverable compiles or validates cleanly (for example, a green build or a passing
terraform validate); - a step-by-step deployment runbook is included;
- no secrets are hardcoded, and configuration is supplied through environment variables or a managed secret store;
- any standard security scan defined for the SKU completes without blocking regressions.
5. Revision window and change control
The Client is entitled to one (1) structured revision cycle within 48 hours of delivery. Revisions are limited to correcting deviations from the specification submitted at checkout. Any expansion of scope, additional resource definitions, architectural redesign, or new integrations constitutes a separate engagement requiring its own authorization.
6. Payment terms and cancellation
All payments are authorized through Stripe at checkout and are final. Because compute and engineering capacity are allocated immediately upon checkout, fees are non-refundable once execution has commenced, except where the delivery guarantee in clause 7 applies or as required by applicable consumer law.
7. Delivery guarantee
If we do not deliver the agreed artifact in accordance with the selected turnaround tier and the acceptance criteria in clause 4 — and the delay is not attributable to paused inputs under clause 2 or to circumstances beyond our reasonable control — the Client may request a 100% refund in accordance with our Refund & Guarantee policy.
8. Confidentiality and mutual NDA
Each party will keep confidential all non-public information received from the other in connection with the engagement and will use it solely to perform or receive the services. Authorization of an order incorporates standard mutual non-disclosure obligations protecting the Client's intellectual property and trade secrets. These obligations survive completion of the engagement.
9. Data handling, security and retention
- Least privilege: we require only read-only repository access and sanitized configuration. We never request production administrative credentials or production database connections.
- Client-side encryption: deploy tokens are encrypted in the browser before transmission and can only be decrypted on the Provider's delivery machine.
- Ephemeral workspaces: codebases are processed in isolated environments and wiped after delivery and verification.
- Zero code retention: we do not retain copies of the Client's source code after the revision window closes.
10. Intellectual property
On full payment, all intellectual property rights in the delivered artifacts vest in the Client. The Provider retains ownership of its pre-existing tools, templates and know-how, and grants the Client a perpetual, non-exclusive licence to use any such materials embedded in the deliverables to the extent required to use them.
11. Limitation of liability
To the maximum extent permitted by law, the Provider's aggregate liability under this SOW is limited to the fees paid for the affected work order. The Provider is not liable for indirect, consequential or incidental loss. Nothing in this SOW limits rights that cannot be limited under applicable law, including the New Zealand Consumer Guarantees Act 1993 where it applies.
12. Governing law and disputes
This SOW is governed by the laws of New Zealand. The parties will first attempt to resolve any dispute in good faith through written communication, and the New Zealand courts will have non-exclusive jurisdiction.
13. Contact
Notices to the Provider should be sent to [email protected]. The Provider is DataRiver New Zealand Limited, NZBN 9429050155972, https://datariver.co.nz/.