Web Hosting - Terms of Use

The following terms of use define what you can expect from us and conversely, what we expect from you, our customer. Questions or concerns on the following content may be directed to us at webhosting@doit.wisc.edu.

Additional terms of service include support policy, backups, maintenance, and cancellation of service.

Web Hosting Service -- Terms of Use


Eligibility for this Service:

This service is available to the University of Wisconsin and its affiliates.

This service is not available to host individual/personal websites for students, faculty, or staff.

Responsible Use:

Customers using this service are required to:

Inappropriate Use Policy:

We reserve the right to remove a website or application if the website or application compromises the confidentiality, integrity, or availability of University data or information systems; violates University policies or laws that govern the use of University data; or performs a function that is inappropriate for a non-restricted data environment (Web Hosting Service has a dedicated restricted hosting environment). Examples of inappropriate use of this service include, but are not limited to:

  • Security issues resulting from software flaws
  • Site neglect and failure to apply security patches
  • Spam or other inappropriate commercial activity
  • Publication or collection of information inappropriate for a public facing web server such as credit card numbers, protected health information, social security numbers, or FERPA protected information

Restricted and PCI Data:

Restricted Data: Customers are required to inform Web Hosting Service if they intend to handle restricted data in an application that is part of their account. If your website processes restricted data or may need to do so, please contact Web Hosting Service. Web Hosting Service has a dedicated environment for restricted data accounts. Applications handling restricted data are subject to an initial consultation and review process through their development by UW-Madison IT Security.

The hosting platform and application access should be as restrictive as possible and only open to the audience it serves. Web Hosting Service will implement firewall rules, but the customers are responsible for ensuring their application is as restrictive as possible. For more information, please see Secure Application Coding Guidelines.

PCI / Credit Card Processing: E-commerce services at the UW Madison are managed and provided by Accounting Services: http://www.bussvc.wisc.edu/acct/policy/rpa/rpapol404.html via CashNET: http://www.bussvc.wisc.edu/acct/policy/rpa/tabcashnettutorial.html

HIPAA Covered Data

The Web Hosting Service restricted data hosting environment is not suitable for handling protected health information (PHI), subject to the Health Insurance Portability and Accountability Act (HIPAA) privacy rule. We reserve the right to decline a request of hosting a website or application if the data processed by the website or application are determined to be protected health information subject to HIPAA Privacy Rule by the UW-Madison HIPAA Privacy Officer or HIPAA Security Officer.

For more information, please see the UW-Madison HIPAA Guidelines.

If your website collects or stores health information or may have the need to do so, please contact PHI Governance Group, HIPAA Security Officer, or HIPAA Privacy Officer.

Compliance

It is your responsibility to comply with Restricted Data Security Standards. If your application stores, processes, transmits, handles or otherwise accesses restricted data as defined by UW-Madison IT Security, and Web Hosting Service is not notified, the University will take appropriate action to enforce compliance.

Web Hosting Account

A web hosting account is defined as a web accessible directory on one of our hosting platforms that is billed to a single fund/invoice. Where multiple platforms or billing sources are needed, there will need to be multiple web hosting accounts. However, multiple websites on the same hosting platform can be part of one account. Please see our Additional Domains page for more information.

Free Bronze Service web hosting accounts are available to customers who only need static web pages (i.e. HTML-only), because these sites typically require much less in support time and server resources.

Each web hosting account gets a test domain for developing/testing content before production release. The other domain is the customer's Production domain. Customers should only advertise their Production domain and reserve the test domain for development and testing.

Note: Java customers have development, test, QA (Quality Assurance), and production environments.

You can apply for any type of account (Bronze, Nickel, Silver, Gold or Platinum) via our Account Request Form.

Division of Responsibilities:

Web Hosting is responsible for maintaining a stable environment for application development and web access. Customers are responsible for all the content of their site(s) and all web application development, including testing and troubleshooting. Web Hosting will strive to maintain the availability of the services at all times. In the event of an outage, Web Hosting staff members will resolve the issue promptly and provide appropriate information to users via available channels.

Web Site Development Assistance:

Customers interested in partnering with a DoIT developer can contact us at webhosting@doit.wisc.edu with a detailed description of the assistance needed, including preferred development language and environment, if known (i.e. ASP.NET, PHP, Java, WebLogic/Tomcat, open source). We will put the customer in touch with the most appropriate development group for their needs.

Web Site Load Testing Assistance:

Customers who need assistance with testing of web-based applications, please contact the Software and Load Testing (SALT) team.

Backups:

The web hosting service utilizes DoIT's Bucky Backup service to protect data and recover it if needed. We maintain the last two versions of a particular file no older than sixty days. We also maintain nightly backups going back 9 days for all customer MySQL databases hosted on our servers.

For more information, see: Web Hosting - Web Site Backup and Recovery.

Support Policy:

Support requests for Web Hosting Service are primarily handled via email to webhosting@doit.wisc.edu during business hours. We will make every effort to respond to requests within 24 hours.

Please contact the DoIT Help Desk for site support outside of business hours.

Infrastructure Maintenance:

Maintenance and upgrades to our platforms are conducted during regularly scheduled maintenance windows.

This service is not recommended for sites that cannot accommodate infrequently scheduled maintenance outages or sites that require a highly customized hosting environment (i.e. specialized software installation, server restarts to pick up configuration changes). The Web Hosting environment is robust enough to support many of UW-Madison's high profile websites. In some cases, however, a dedicated server hosted on the DoIT Platform may be more appropriate.

Cancellation:

Customers can contact us at any time to cancel service and billing on an account. See our Cancellation page for detailed instructions.

Questions/comments on web hosting? Send email to webhosting@doit.wisc.edu




Keywords:polices, terms, appropriate use, guidelines, best practices, restricted data, PCI, HIPAA, security, responsibilities   Doc ID:44461
Owner:Jake S.Group:DoIT Web Hosting
Created:2014-10-24 11:46 CSTUpdated:2016-08-26 10:01 CST
Sites:DoIT Web Hosting
Feedback:  0   0