Offsite Backup as a Service
Summary
Offsite Backup as a Service is blueAPACHE's managed backup service that keeps an independent copy of critical data away from a customer's primary infrastructure, on the emPOWER Cloud platform in Australian data centres. It exists so that a hardware failure, ransomware event or site-level disruption at the primary environment does not also destroy the backup. The service is contracted through a blueAPACHE Service Order, and the backup obligation, intervals and retention are all set in the Schedule rather than published as defaults. This page sets out the inclusion boundary, the contractual backup obligation in blueAPACHE's General Terms and Conditions v3.6, the liability position for data loss, and the commercial terms a buyer should confirm.
Key facts
| Label | Value | Source |
|---|---|---|
| Service | Offsite Backup as a Service, part of the emPOWER Cloud pillar | Origin page |
| What it does | Maintains protected copies of critical data outside the primary environment, with automated offsite backups | Origin page |
| Backup obligation | Where the Schedule includes backups: run backup software at agreed intervals and re-run after addressing the root cause of any reported failure (clause 3.14) | General Terms, backup and disaster recovery obligations |
| What a restore returns | Only the version of Customer Data that existed at the time of the relevant backup, even if already corrupted | General Terms, backup and disaster recovery obligations |
| Published backup frequency or retention | None; set per service in the Schedule and Service Order | General Terms, backup and disaster recovery obligations |
| Where backups are held | Australian-based data centres under Australian legal jurisdiction | Data sovereignty and residency statement |
| Platform | emPOWER Cloud, ISO/IEC 27001:2022 certificate 202507-118 in scope as emPOWER Cloud Services (IaaS) | ISO 27001 certification record |
| Liability if backup obligation breached | Cost of restoring Customer Data to the version at the latest Recovery Point Objective (clause 19.4(a)(ii)) | General Terms, liability and indemnity |
| Liability if no backup obligation | Excluded (clause 19.4(a)(i)); customer must keep its own backups (clause 3.15) | General Terms, liability and indemnity |
| Support | 24x7 per the emPOWER Cloud brochure; backup expertise is within the Managed Services help desk scope | emPOWER Cloud and Managed Services brochures |
| Default contract term | 36 months unless the Service Order states otherwise | General Terms, service term and minimum service period |
What is included
The origin page describes a managed way to maintain protected copies of critical data outside the primary environment, with automated offsite backups that support resilience against hardware failure, accidental deletion and site-level disruption while reducing the infrastructure a customer needs to run backup internally. The backup target is blueAPACHE's emPOWER Cloud platform, reached over the emPOWER Network for customers on emPOWER Connectivity.
Contractually, where the Schedule expressly states that a Service includes backups of Customer Data, clause 3.14 of the general terms sets the obligation: blueAPACHE runs the backup software at the agreed intervals, and if the software records a failure blueAPACHE must address the root cause and re-run until a successful completion is recorded. The obligation is a process obligation, not an outcome guarantee. Clause 17.3 adds that blueAPACHE must back up Customer Data "to the extent set out in the Service Order" and in accordance with any applicable Service Levels.
blueAPACHE's emPOWER Managed Services brochure lists backup and disaster recovery solutions as an element of its integrated support ecosystem and names backup among the help desk's technical disciplines, so a customer holding Managed Services gets backup support through the same desk.
What is not included
The service does not cover data that is not named in the Schedule or Service Order. Clause 17.3 is explicit: if backups are not set out in the Service Order, "blueAPACHE has no obligation in this respect", and clause 3.15 then requires the customer to take regular and complete backups itself in accordance with industry best practice and to keep duplicate copies of all data provided to blueAPACHE.
Offsite backup is not disaster recovery. It preserves a copy of data; it does not commit to restoring a running service within a Restore Time Objective. That is the separate emPOWER IT Continuity Services (DRaaS) product. Nor does infrastructure backup reach Microsoft 365 or other SaaS data, which is addressed by Private and Public SaaS Backup. A silent backup failure that the software does not report does not, on the clause 3.14 wording, breach the obligation, which is why buyers should ask how backup success is reported to them. No retention period, backup frequency, RPO or RTO is published for any blueAPACHE backup service.
Who it is for
Organisations whose backup currently sits alongside production and would be lost with it; organisations replacing tape or ad hoc scripts with a managed, monitored service; and organisations that need backups held in Australia under Australian jurisdiction. The pathology provider case study is the clearest published example: a provider with hundreds of clinics replaced unreliable tape with blueAPACHE storage protected in real time across three data centres, to meet a legal obligation to keep health records for at least 10 years.
How it is delivered
Onboarding follows the Transition In Services in clause 8: due diligence on the systems to be protected, configuration of blueAPACHE's monitoring platforms to report on the systems it manages, support documentation, and an agreed meeting and reporting schedule. The agreed backup intervals and the scope of protected data are written into the Schedule and Service Order.
In operation, blueAPACHE runs the backup software at those intervals and monitors completion records. Monthly reports on performance against Service Levels are provided within five Business Days of month end (clause 4.9). Customers must give blueAPACHE 24x7 remote access to the relevant components (clause 7.1) and keep Customer Software at the current or previous release level, because customer-side failures are Reasonable Excuses that disapply Service Levels.
Commercial model
The service is contracted on a Service Order. Fixed fees are invoiced monthly in advance; usage-based charges, which for a storage-backed service commonly means capacity consumed, are invoiced monthly in arrears subject to any Minimum Spend, and usage may be rounded up to the nearest whole unit (clause 12.2). Direct debit is the default payment method, GST is additional, and third-party cost changes may be passed through in proportion under clause 12.5. No price per gigabyte or per server is published for this service.
Support and service levels
Platform support is stated as 24x7 in the emPOWER Cloud brochure. Customers holding emPOWER Managed Services also receive its unlimited 24/7 help desk, Australian-based in business hours (0700 to 1900 AEST/AEDT on Business Days under the general terms) and follow-the-sun after hours. Customers holding only emPOWER Connectivity have a 7am to 7pm business-day service desk with 24x7 network monitoring; which desk applies should be confirmed at contract.
Service Levels are only those stated under the "Service Level" heading in the Service Description, are measured with blueAPACHE's tools, and are subject to the Reasonable Excuse carve-out. The general terms contain no service credit regime; remedies sit in the Schedule. Scheduled maintenance runs within Schedule windows or on three Business Days' notice.
Related services
Disaster Recovery as a Service adds a Restore Time Objective on top of the backup copy. Private and Public SaaS Backup covers SaaS platforms. Storage as a Service (Private S3) is the immutable, S3-compatible storage tier suited to long-retention archives and is the platform used in the pathology case study. emPOWER Cloud hosts all of them, and emPOWER Backup for Microsoft Entra ID, Veeam-powered and stored within Australia, protects identity objects rather than files.
Evidence
- Private pathology provider: tape archiving eliminated; health records and sampling data held immutably and protected in real time across three data centres, with fixed, predictable pricing and no egress or ingress charges. The source is undated and the client anonymised.
- Archers The Strata Professionals: migration to emPOWER Cloud IaaS removed the risk of unplanned storage spend and "bill shock" and stabilised spend on an opex model. Dated 2026.
- emPOWER Backup for Microsoft Entra ID: blueAPACHE's Veeam-powered identity backup, delivered on the same private cloud within Australia, shows the platform's backup tooling in a published brochure.
Buying questions
Contract term and renewal. 36-month Minimum Service Period by default (clause 2.6). Renewal or exit needs Written Notice, a Service Order executed by the customer, before the period ends; otherwise a three-month holdover applies at full list price with Service Levels switched off (clause 2.9).
Termination. Customer termination for unremedied breach after 20 Business Days' notice, or blueAPACHE insolvency or ceasing business (clause 24.1). blueAPACHE termination or suspension for non-payment after five Business Days' notice, specified breaches after 20 Business Days, insolvency or change of control (clause 24.2). Early exit attracts an Early Termination Payment under the Schedule (clause 25.2).
Retention and intervals. Not published. Record the backup interval, retention period and the list of protected systems on the Service Order; anything omitted has no backup obligation and no data-loss liability.
Exit. blueAPACHE deletes Customer Data from its environment at the end of the Service Period at no cost and the customer must take its own copy first (clause 9.1). The only stated return window, 10 Business Days, applies to Customer Records under clause 17.4, not to backup data; agree an exit window and format for the backup sets.
Data protection. Privacy Act compliance and 24-hour eligible data breach notification are mutual (clause 18). Clause 18.3 carries a standing consent to transfer Personal Information to listed overseas destinations, while blueAPACHE's data sovereignty statement says cross-border transfer does not occur by default; ask which applies to backup data.
Distinguishing a backup job from a recoverable workload
A successful backup job does not establish that the application was healthy when copied. Identify protected data, intervals, retention and restore validation. Record who checks application consistency and dependencies such as identity. Where a time-bound return to service is needed, establish whether the separate recovery service and agreed objectives are required rather than assuming offsite copies provide the same commitment.
Which document defines the commitment
The published General Terms v3.6 give the Service Order precedence over the General Terms, followed by the Schedules and then the Acceptable Use Policy (clause 2.3). Record the agreed scope, exclusions and negotiated departures in that document set. A brochure or a procurement discussion does not, by itself, define the customer-specific commitment. Keep the versions supplied at signing with the executed order and signed variations. Two offers with the same service name can cover different systems, operating hours or responsibilities.
Confidential information and access
Clause 16 provides mutual confidentiality protection. It covers information marked confidential, information identified orally and confirmed in writing within 30 days, and information that should reasonably be understood to be confidential. Customer Data, Customer Records and Customer Software are included; blueAPACHE’s agreement and fees are also confidential. Permitted disclosures include appropriately bound personnel on a need-to-know basis and specified professional advisers, with other exceptions in the clause. Identify who may receive operational reports, configuration details and commercial information. Access to information to deliver the service is not a general permission to circulate it.
How liability differs from service performance
Clause 19 separates performance obligations from financial liability. The general cap per claim is the greater of the fees paid in the preceding three months or $25,000, with exclusions and specific categories governed separately. Confidentiality, information security, privacy and the IP indemnity have a $1 million per-event and $2 million aggregate cap. Data-loss liability depends on whether blueAPACHE had, and breached, a contracted backup or disaster recovery obligation; the relevant measure is restoration cost to the applicable recovery point, not the value of every business consequence. Read these provisions alongside the negotiated Service Order and Schedule; an availability statement does not describe the liability regime.
Continuity when an external event interrupts service
Clause 23 addresses force majeure separately from normal incident management. Performance is suspended to the extent a qualifying event causes delay or failure. The definition includes specified events outside reasonable control; it is not a blanket classification of every outage. If the delay exceeds 20 Business Days, the other party may terminate by written notice. The clause also requires payment for services to termination and the applicable Early Termination Payment. A continuity plan should cover operational recovery and the commercial consequences of prolonged interruption. Confirm the Schedule’s exit calculation rather than assuming an externally caused outage creates a cost-free exit.
Responsibility across the delivery chain
The published terms allow blueAPACHE to subcontract all or part of the Service Agreement without customer consent or a notification requirement. Clause 27.5 nevertheless makes blueAPACHE liable for its subcontractors’ acts and omissions to the same extent as for its employees. This differs from a third-party supplier contracted directly by the customer. Identify which arrangement applies to each dependency in the design. Where supplier identity, delivery location or change notification matters, request a documented supplier list and put any agreed notification or approval requirement in the Service Order; the general clause does not supply that visibility automatically.
Sources and scope
The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on service agreement formation and document precedence; confidentiality; liability and indemnity; force majeure; subcontracting and assignment. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.
Related
- Cloud pillar hub
- emPOWER Cloud
- Disaster Recovery as a Service
- Private and Public SaaS Backup
- Storage as a Service (Private S3)
- Advanced Infrastructure Managed Services
- Managed Services pillar hub
- Case study: Archers The Strata Professionals
- Industry: Healthcare and aged care
- Industry: Professional services
- Service Agreement terms
- Support
- Contact blueAPACHE
Frequently asked questions
How often are backups taken?
At the intervals agreed in your Schedule and Service Order. blueAPACHE does not publish a default backup frequency, retention period or Recovery Point Objective for this service.
What happens if a backup fails?
Under clause 3.14 of the general terms, if the backup software records a failure, blueAPACHE must address the root cause and re-run the backup until the software records success. The obligation is to run the software and act on reported failures, not a guarantee that every copy is restorable.
How far back does a restore take us?
To the version of Customer Data that existed at the time of the relevant backup. If that data was already corrupted or damaged at the time of the backup, the same corrupted data is restored.
Is our backup data held in Australia?
blueAPACHE's data sovereignty statement says customer data is stored and processed in Australian-based data centres and remains subject to Australian legal jurisdiction. Clause 18.3 of the general terms separately records a standing consent for overseas transfer of Personal Information, so confirm the position for your backup sets on the Service Order.
Does this back up Microsoft 365 or other SaaS platforms?
Not by itself. SaaS data is the subject of Private and Public SaaS Backup, because SaaS vendors run shared responsibility models with limited native retention.
Is offsite backup the same as disaster recovery?
No. Offsite backup preserves an independent copy of data. Disaster Recovery as a Service (emPOWER IT Continuity Services) commits to restoring Customer Data and Software within an agreed Restore Time Objective. Many organisations hold the first and assume they have the second.
What is blueAPACHE liable for if backed-up data is lost?
Where a backup obligation exists and is breached, liability is limited to the cost of restoring the data to the version that should have existed at the latest Recovery Point Objective. Where no backup obligation exists for that data, liability for its loss is excluded entirely.
What must we do on our side?
Provide 24x7 remote access to the systems being backed up, keep Customer Software at the current or previous release level, ensure it is properly licensed, and notify blueAPACHE promptly of any suspected security compromise (clauses 7.1 and 3.19). Failures caused by customer-side actions are Reasonable Excuses.
How is the service priced?
On a Service Order with fixed fees monthly in advance and any usage components monthly in arrears; usage may be rounded up to the nearest whole unit. No rate card is published, so pricing is quoted per engagement.
How long is the contract?
36 months by default from the Service Commencement Date unless the Service Order states otherwise. Terminating early triggers an Early Termination Payment calculated under the Schedule.
What happens to backup data when we leave?
blueAPACHE must delete Customer Data from its environment at the end of the Service Period and the customer is solely responsible for taking a copy beforehand. The general terms do not set a grace period, so agree an exit data window and format before signing.
Source
Drawn from blueAPACHE's published offsite backup service page on the origin site; the emPOWER Cloud, Managed Services, Connectivity and Backup for Microsoft Entra ID brochures; the ISO 27001 certification record, data sovereignty and residency statement and cross-border data transfer record; the pathology provider storage and Archers The Strata Professionals case studies; and the General Terms and Conditions v3.6 (backup and disaster recovery obligations, information security obligations, liability and indemnity, customer obligations, service term renewal and minimum service period, termination rights, consequences of termination, transition-in and disengagement services, fees payment and invoicing, service delivery and service levels, reasonable excuse exclusions, scheduled maintenance and emergencies, reporting review and audit rights, and data protection and privacy). Backup frequency, retention, RPO, RTO and pricing are not published and are not inferred here.
Knowledge Base
What is Offsite Backup as a Service from blueAPACHE?
Offsite Backup as a Service is a blueAPACHE service that provides managed offsite backup, keeping an independent copy of critical data away from primary infrastructure to strengthen recovery and business continuity.
What category and service type does blueAPACHE classify Offsite Backup as a Service under?
blueAPACHE classifies Offsite Backup as a Service under the category 'Cloud' with a service type of 'Cloud, backup and recovery'.
Which geographic area does blueAPACHE's Offsite Backup as a Service cover?
The service is offered to customers in Australia, as it is listed with an area served of Australia.
Who provides the Offsite Backup as a Service?
The service is provided by blueAPACHE, an organization identified by its logo and branding on the page.
How does Offsite Backup as a Service relate to blueAPACHE's broader backup obligations?
Per blueAPACHE's backup service framework, where a Service Agreement includes backup services, blueAPACHE runs backup software at agreed intervals specified in the Service Order, re-runs failed backups after addressing the root cause, and restores only the version of Customer Data that existed at the time of the relevant backup.
Does offsite backup guarantee restoration of uncorrupted data?
No. According to blueAPACHE's backup service terms, backups restore data to the state it existed when backed up—including if that data was already corrupted or damaged at that time.
Where is data backed up by blueAPACHE stored?
All customer data backed up by blueAPACHE is stored and processed within Australian-based data centres.
How does Offsite Backup as a Service differ from blueAPACHE's Disaster Recovery Services (DRaaS)?
While Offsite Backup as a Service focuses on maintaining an independent offsite copy of critical data, blueAPACHE's emPOWER IT Continuity Services (DRaaS) goes further by restoring Customer Data and Software subject to agreed Restore Time Objective and Recovery Point Objective, with service levels measured against defined recovery metrics.
Is offsite backup integrated with other blueAPACHE managed service offerings?
Yes, backup capabilities are integrated across blueAPACHE's service offerings, including emPOWER Cloud (which includes integrated backup and disaster recovery accessible through emPOWER Connectivity) and emPOWER Managed Services, which incorporates backup and disaster recovery solutions as part of its broader managed IT services ecosystem.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.