3. Service Operation
Service operation is divided into the main phases "Setup" and "Regular Operation":

3.1 Setup Phase
To prepare the Intershop Commerce Platform for the go live, Intershop sets up the necessary system environments as described in section 1.1. In this context, the following services are provided:
3.1.1 General
During the setup phase a Service Manager from Intershop coordinates the operational activities (see below).
3.1.2 Definition and Alignment of
- CI/CD processes
- User and groups for accessing the DevOps environments and business management tools
- Rules for using and invalidating the page cache
- Backup and recovery processes
- Monitoring processes
- Reporting processes
- Emergency processes
3.1.3 Installation and Configuration
- CI/CD Services
- Installation and configuration of the application environments
- Intershop application environments
- User and access management
- Setting up monitoring and reporting
3.1.4 Rollout and Go Live
- Assistance during go-live operation to make the commerce solution accessible to end customers (according to the go-live check list)
- Increased attention in the days before and after the go live
3.1.5 Migration of an Existing E-Commerce Solution
The migration of an existing e-commerce solution (data and/or custom code) is not included in the initial setup services. Necessary infrastructure or migration support must be booked separately.
3.2 Regular Operation
3.2.1 Categories of Defects
The defect definitions, response times, and correction time limits indicated below apply to any fault which may occur in a PRODUCTION environment. Category A defects only apply to the PRODUCTION environment.
- Category A: The platform presents faults in core functions, provides wrong results, and interrupts in the PRODUCTION environment. As a result, the PRODUCTION environment is either inaccessible to end users or end users cannot place an order.
- Category B: This refers to a serious defect which occurs on a local level and only affects a single module or function. The application does not work as agreed in the specification or documentation, but it is still available. The general work on the application is not compromised and the end users can still place orders in the environment.
- Category C: Any defect not defined under A or B; this includes any subject matter which is not urgent and would require further clarification, e.g., proposals for modifications or requests for improvement.
Any defects related to the UAT and INT environments (also known as NON-PRODUCTION) will be addressed with lower priority.
3.2.2 Business Hours
Regular business hours are in general:
Monday to Friday from 09:00 to 17:00, exceptions are published on the Intershop Support website.
|
Info
Premium Support including 24/7 Emergency Hotline can be booked as an additional option, see Service Levels.
|
3.2.3 Support
Technical support accepts technical problems and user enquiries only during business hours. These are prioritized by the Intershop Service Desk according to their importance and then initiated for processing.
The emergency stand-by service for receiving and dealing with Category A faults is available 24/7 (only available if premium support has been booked).
3.2.4 Response Time
The response time defines the maximum time span in which the customer receives a confirmation of the progress of claims processing.
Intershop warrants the following response times in the event of malfunctions:
|
Category
|
Standard Response Times (during business hours)
|
Premium Response Times (24/7)
|
|
A
|
60 minutes*
|
30 minutes
|
Note
24/7, Premium support customers have to send a Category A Alert via the emergency hotline number.
|
|
|
B
|
4 hours*
|
2 hours*
|
|
C
|
1 day*
|
1 day*
|
*during business hours
On request, Intershop will provide the customer an incident report for all category A faults after the fault has been rectified (Premium Support only).
The service desk staff classifies and records all claims in the Intershop ticket system.
3.2.5 System Availability
Intershop warrants availability of the PRODUCTION environment of at least 99.6% per quarter (measured from the interface between network data center and Internet service provider). Our Premium support elevates the availability to 99.9%.
Excluded from this are:
- Events beyond Intershop's control (e.g. force majeure)
- Interruptions and disruptions due to the conduct of the customer or its subcontractors, such as misoperation of the platform (e.g. page cache deletion at peak time), import of invalid data or deployment of inperformant or faulty customizations that lead to excessive resource consumption
- Planned downtime/maintenance or load/stress/penetration/vulnerability testing windows
- Customer installations running on an outdated release (see chapter “Continuous Releases”)
3.2.6 Maintenance
Scheduled maintenance work may be necessary, for example, to perform operating system updates, install security patches or new software versions in the system. Necessary regular maintenance windows (time and duration) are agreed with the customer in advance if possible. The aim is to consolidate the maintenance windows for non-safety-relevant work in times of low sales with minimal restriction of system availability. Additional information is provided before work begins.
Maintenance windows are times during which an IT system is not available due to planned work or a severe impairment of regular operation exists.
Maintenance windows are considered planned downtimes. The total downtime per calendar month may not exceed 8 hours. For the unlikely case of a security or emergency issues Intershop will perform necessary steps with short notice to the customer.
3.2.6.1 Weekly Maintenance Slot
Duration: up to 4 hours based on activities, not more than 8 hours per month
Time slot: To be scheduled with the customer.
Services:
- Maintenance activities on infrastructure side
- Deployment of hotfixes
- Deployment of 3rd party fixes (database, application and search servers) including security updates
- Smaller modifications (template errors, spelling errors, etc.)
- Replacement / enhancement of minor components
3.2.7 Capacity Management
Capacity management includes the following:
- Ongoing monitoring of load parameters and system utilization (CPU, hard disks, network bandwidth)
- Sizing to ensure handling of traffic peaks based upon agreed plans
- Ensuring that customizations are implemented in a performant and resource efficient way
3.2.8 Performance Management
Performance management includes the following:
- Ongoing performance monitoring of critical performance parameters regarding their changes (response time behavior, etc.)
- Tuning / Optimization and configuration changes of the Intershop base applications excluding customizations
3.2.9 Security Management
Security management includes the following:
- Definition, setup and maintenance of system authorizations and accesses
- Installation of security-relevant software updates
- Installation of standard patches and hotfixes of the operating system and 3rd-party software
- Installation of standard patches and hotfixes of the Intershop applications in coordination with the implementation partner
- DDoS (Basic) protection via Microsoft Azure
3.2.10 Technical Monitoring
Technical monitoring by the Intershop operations team includes the continuous automatic monitoring of:
- Functional components of the infrastructure
- Functional components of the application environments
- Critical parameters of the Intershop application environments
Technical monitoring checks the availability of technical components and processes, but does not correct the functioning of the application in regards to business processes, content or integration of 3rd-party services. These are in the responsiblity of the implementation partner and customer, see RACI matrix.
3.2.11 Incident Management
Incident management relates to quickly rectifying technical or system malfunctions in order to minimize their impact on business operations. Included functions depend on the chosen service package:
- Provision of a ticket system for reporting and tracking errors
- Analysis of technical faults of the base applications, the core application environments and the infrastructure (not including customizations)
- Checking technical error logs
- Restoration of operation after malfunctions
- Logging of error states and system load
3.2.12 Problem Management
Problem Management is about the sustainable elimination of repeated technical reproduction of misconduct, if possible.
Furthermore, this includes the incorporation of fixes into the next release for the affected standard Intershop base application (see also Concept - Continuous Releases for details).
3.2.13 Deployments
Deployments include the installation of customizations of Intershop software.
Necessary deployments (time and duration) are planned and agreed to in advance with the customer, if possible analogous to the maintenance windows. Additional information is provided before work begins. The deployment process refers to one production environment or one non-production environment per release (version).
3.2.14 Backup and Recovery
Regular backups of the customers data are done for all databases and the shared file service.
RPO (Recovery Point Objective, data loss)
- Shared File Service: 24 hours
- The backup of shared file service for production environment takes place daily at night and does not affect proper operation.
- The backup of shared file service will be copied geo-redundant once a day to another Azure region (data center).
- Database: 5-10 minutes
- The production and non-production databases are operated as an active-active cluster.
RTO (Recovery Time Objective)
- In principle, all application tiers are designed redundantly for live production clusters to prevent downtimes in case of failure. Container-based applications are orchestrated by Kubernetes and use auto-healing mechanisms such as automated pod restarting and pod transfer to alternative nodes.
- Depending on the failure, recovery takes maximum 30 minutes. Excluded are failures caused by the deployment of faulty customer/partner releases.
- Whole platform: 24 hours (depending on severity of the failure and availability of the Azure services)
3.3 Cloud Hosting
The necessary cloud infrastructure services are provided within the framework of a subcontractor contract. Details are regulated in the DPA (data processing agreement). Intershop uses Microsoft Azure Services (Microsoft Azure Global Cloud) to provide the service. The customer hereby consents to the use of the subcontractor. Intershop is responsible for all communication and collaboration with the provider.