MigraSync Service Responsibilities Agreement
MigraSync Service Responsibilities Agreement
Effective date: 19 July 2026
Last updated: 19 July 2026
Version: 1.0
Published at: https://migrasync.com/responsibilities/
Preamble
This Service Responsibilities Agreement (the “Agreement”) defines the division of duties, ownership, and accountability between MigraSync (“Provider”, “we”, “us”, “our”) and the customer, site administrator, or authorized agent who installs or uses the MigraSync Plugin and related services (“Customer”, “you”, “your”).
This Agreement applies to all MigraSync products and services, including self-serve SaaS features and handcrafted professional services, unless a signed Statement of Work expressly overrides a section for a specific engagement.
By checking the acceptance box in the MigraSync Plugin, creating an account, purchasing a plan, submitting a service request, or starting a migration, backup, restore, or related job, you acknowledge that you have read this Agreement and agree to the responsibilities allocated below.
This Agreement supplements—and does not replace—our Terms of Service, Privacy Policy, and Refund & Cancellation Policy. If there is a conflict on billing or refunds, the Terms and Refund Policy control. If there is a conflict on data protection, the Privacy Policy controls. If there is a conflict on operational duties for product use, this Agreement controls.
1. Parties and capacity
| Party | Identity and role |
| Provider | Elliyas Ahmed, operating as MigraSync (https://migrasync.com), based in Bangladesh. MigraSync is a software product brand. |
| Customer | The individual or organization that holds a MigraSync Account, purchases entitlements, and/or authorizes use of the MigraSync Plugin on a WordPress site. |
| Site Administrator | Any WordPress administrator who configures the MigraSync Plugin, API keys, vault keys, or job settings on a connected site. Actions taken in the Plugin bind the Customer. |
| End Client (if applicable) | Where an agency or consultant uses MigraSync on behalf of a third party, the contracting Customer remains the Account holder unless we agree otherwise in writing. The Customer is responsible for obtaining End Client authority. |
You represent that you have lawful authority to bind the Customer (and, where relevant, the End Client) to this Agreement and to process the content you select for migration, backup, or restore.
Merchant of Record: Paid SaaS orders are processed by Freemius.com. Freemius’s Buyer Terms apply to checkout, tax, invoicing, and payment-related matters. Product support remains with MigraSync at [email protected].
2. Covered products and services
This Agreement covers the following product lines (collectively, the “Services”):
| Product / service | Description |
| Blogger → WordPress Migration | Self-serve import via Blogger API (OAuth) or Google Takeout / local file, subject to plan entitlements (trial, Starter, Standard). |
| WordPress Cloud Backup | Scheduled or manual packaging of site data and encrypted storage in MigraSync Managed Cloud (Essential, Pro, and eligible trials). |
| WP Restore | Restoration of an encrypted Managed Cloud backup to a WordPress site, on eligible plans. |
| WordPress → WordPress migration / clone | Site transfer or clone performed using backup and restore capabilities (not a separate entitlement unless stated at checkout). |
| Done-For-You (DFY) / Professional Services | Handcrafted migration or related work ordered via service request or written SOW (e.g. DFY Standard, Pro, Premium). |
| Account, dashboard, APIs, and support | Registration, API keys, plan sync, job history, and documented support channels. |
Plan limits, validity windows, retention, and pricing shown at Pricing and in the Plugin UI are authoritative for entitlements.
3. Shared responsibility model
MigraSync operates a shared responsibility model, consistent with leading cloud and SaaS practice. We secure and operate the control plane and Managed Cloud. You secure and operate your WordPress host, credentials, content rights, and operational choices.
3.1 Responsibility matrix (at a glance)
| Domain | Provider (MigraSync) | Customer |
| Platform availability | Operate Core APIs, quota enforcement, and Managed Cloud with commercially reasonable care | Maintain your host, domain, DNS, SSL, and WordPress stack |
| Plugin runtime | Ship and maintain the MigraSync Plugin; document system requirements | Install, update, and configure the Plugin; meet PHP/WordPress/host minimums |
| Authentication | Issue and validate API keys; protect Core authentication systems | Safeguard Account credentials, API keys, and 2FA; revoke compromised keys |
| Content ownership & legality | Process content only to deliver the Services you request | Own or hold lawful rights to all content migrated, backed up, or restored |
| Encryption keys | Provide encryption mechanisms for Managed Cloud backups | Generate, store, and recover the Master Vault Key; we cannot restore without it |
| Backup scope & retention | Enforce plan caps; execute retention/auto-purge as configured | Choose scope, schedule, and retention; monitor job success; renew subscriptions |
| Migration quality | Provide tools to import eligible Blogger content and media per selected scope | Review imports; configure theme, permalinks, redirects, SEO, and post-migration QA |
| Data controller / processor | Act as processor for job data you submit through the Services | Act as controller of site and blog content; ensure lawful basis for processing |
| Third-party services | Integrate documented providers (e.g. cloud storage, Freemius) | Comply with Google/Blogger and host terms; resolve host/Google outages affecting your jobs |
| Professional / DFY work | Deliver agreed scope in SOW or package description | Provide access, prerequisites, timely feedback, and acceptance within the review window |
4. Provider responsibilities
MigraSync will:
- Provide the Services described for your active entitlements, including migration tooling, Managed Cloud backup storage, restore capabilities where eligible, and the customer dashboard.
- Authenticate and authorize Plugin and API requests using your Account and API key, and enforce plan quotas and product gates.
- Protect Managed Cloud with industry-standard encryption at rest for backup archives (AES-256 class), using keys you control where the product design so requires.
- Limit use of Customer Content to performing the jobs you initiate, operating the platform, providing support you request, and complying with law—as further described in the Privacy Policy. We do not sell your content or use it for advertising.
- Apply retention and deletion rules published in the Terms (per-backup auto purge, subscription grace periods, customer-initiated purge).
- Provide support through documented channels for platform and Plugin issues within plan entitlements.
- Notify of material changes to this Agreement or related policies by updating the published documents and the “Last updated” date.
- For DFY / professional services, perform the work described in the applicable package or Statement of Work with reasonable skill and care, and return or revoke temporary access credentials after delivery where practicable.
MigraSync does not, unless separately agreed in writing:
- Provide general web hosting, domain registration, or unmanaged server administration
- Guarantee perfect visual/layout parity with Blogger or another source site
- Guarantee SEO rankings, traffic, email list continuity, or third-party gadget behavior
- Guarantee recovery from ransomware, malware, or host-level compromise of your live server
- Provide unlimited custom theme design, plugin development, or DevOps outside a paid SOW
- Reconstruct encrypted backups if you lose the Master Vault Key
5. Customer responsibilities
You agree to:
5.1 Lawful use and authority
- Use the Services only for lawful purposes and only for content and sites you own or are authorized to process.
- Ensure Site Administrators and agencies acting for you are authorized to bind you.
- Comply with Google’s terms when using Blogger OAuth, APIs, or Takeout exports.
- Not use the Services to infringe intellectual property, privacy, or other rights, or to distribute malware, spam, or illegal material.
5.2 Environment and Plugin
- Run a supported WordPress version with the MigraSync Plugin and a valid API key.
- Meet documented system requirements (including PHP version, OpenSSL/JSON, HTTPS outbound access, memory, and disk)—see Documentation — System requirements.
- Keep WordPress, PHP, and the Plugin reasonably up to date; resolve host or security-plugin blocks that prevent loopback or API calls.
- Sync plan status in the Plugin after purchase or cancellation and contact support if entitlements do not update within a reasonable time (e.g. 24 hours).
5.3 Credentials and secrets
- Protect Account passwords, API keys, Google OAuth sessions, and host/admin credentials.
- Store the Master Vault Key in a durable, offline or password-manager location you control. Loss of the Master Vault Key may make backups permanently unrestorable.
- Not embed API keys in public repositories, client-side scripts, or shared channels.
- For DFY engagements, provide temporary access only as needed and rotate credentials after the engagement ends.
5.4 Migration-specific duties
- Complete Google OAuth or supply a complete, valid Takeout/local export, as applicable.
- Select an appropriate migration package for blog size (Starter vs Standard slot rules).
- Review imported posts, pages, media, comments, and authors before treating the migration as complete.
- Configure WordPress theme, menus, redirects, analytics, forms, and SEO yourself (or via a separate professional engagement).
- Accept that migration success depends on Google/Blogger availability, export integrity, and your hosting capacity.
5.5 Backup- and restore-specific duties
- Choose backup scope, schedule, and auto-purge retention appropriate to your risk tolerance.
- Monitor backup job success and investigate failures promptly.
- Renew backup subscriptions if you require ongoing protection; understand that long retention settings do not preserve data after subscription grace expires.
- Export or download critical recovery points before grace periods end if you choose not to renew.
- Before restore, understand that restore may overwrite site data; take additional precautions on production sites as you deem necessary.
- Verify restored sites (content, media, plugins, themes, and critical workflows) after restore completes.
5.6 Operational monitoring
- Maintain independent hosting and domain control; MigraSync is not your host.
- Maintain your own change-management and rollback practices for production sites.
- Not circumvent quotas, reverse engineer Core, abuse APIs, or impose unreasonable load.
6. Product-specific allocations
6.1 Blogger → WordPress Migration
| Responsibility | Owner |
| Lawful rights to Blogger content | Customer |
| OAuth / Takeout / export completeness | Customer |
| Slot allocation and entitlement enforcement | Provider |
| Import tooling, queueing, media handling (within scope) | Provider |
| Hosting capacity during import | Customer |
| Post-import theme, design, redirects, SEO | Customer |
| Layout/gadget/email/SEO outcome guarantees | Neither (explicitly out of scope) |
6.2 WordPress Cloud Backup
| Responsibility | Owner |
| Selecting what to include (DB, media, plugins, themes) | Customer |
| Building archive on Customer’s server | Plugin (runs on Customer infrastructure) |
| Encrypting with Master Vault Key before upload | Plugin / Customer key custody |
| Storing encrypted archives in Managed Cloud | Provider |
| Plan storage caps and quota enforcement | Provider |
| Retention / auto-purge while entitlement is active | Provider (per Customer settings) |
| Renewing subscription / acting before grace expiry | Customer |
| Malware scanning of live site | Customer (unless separate service) |
6.3 WP Restore
| Responsibility | Owner |
| Selecting the backup point to restore | Customer |
| Providing valid Master Vault Key | Customer |
| Executing restore job and overwriting target data as designed | Plugin / Provider platform |
| Confirming destructive overwrite risk before proceed | Customer |
| Post-restore functional verification | Customer |
| Fixing incompatible plugins/themes after restore | Customer |
6.4 WordPress → WordPress migration / clone
Treated as backup on source + restore on destination unless a DFY SOW states otherwise. Customer is responsible for both sites’ hosts, credentials, DNS cutover, and post-cutover validation.
6.5 Done-For-You / Professional Services
| Responsibility | Owner |
| Accurate service request / SOW scope | Customer & Provider (mutual) |
| Providing staging URL, admin access, OAuth/Takeout, and prerequisites on time | Customer |
| Performing handcrafted work within purchased package or SOW | Provider |
| Included revisions and acceptance window (as stated for the package) | Per package / SOW |
| Work outside scope (theme redesign, unlimited DevOps, custom plugins) | Out of scope unless new SOW |
| Fees, payment link, and refunds for DFY | As stated at order / Refund Policy; may differ from self-serve SaaS |
Delivery is complete when the agreed deliverables are made available for Customer review. Changes requested after the acceptance window or outside the package description constitute new scope.
7. Data roles, processing, and subprocessors
- Customer is the data controller (or equivalent) for personal data contained in Blogger or WordPress content and backups.
- MigraSync is the data processor for processing performed to deliver the Services you request through the Account and Plugin.
- Processing purposes, retention, security measures, and international transfers are described in the Privacy Policy. A formal Data Processing Agreement (DPA) is available on request.
- Subprocessors may include infrastructure and commercial providers (for example Managed Cloud storage and Freemius). Use of Google services for Blogger access is under Customer’s relationship with Google.
- Starting a job in the Plugin constitutes instruction to process the selected data for that operation.
8. Intellectual property and Customer Content
- Customer Content (posts, pages, media, databases, and similar materials you process through the Services) remains yours.
- You grant MigraSync a limited, worldwide, non-exclusive license to host, transmit, encrypt, store, and process Customer Content solely to provide the Services.
- The MigraSync software, branding, documentation, and platform remain Provider property. No ownership transfer is implied by this Agreement.
- Feedback you provide may be used to improve the Services without obligation to you.
9. Acceptance of risk and acknowledgements
By accepting this Agreement in the MigraSync Plugin or otherwise, you acknowledge that:
- Migration and backup jobs run primarily on your WordPress server; host limits can cause failures or incomplete jobs.
- Encrypted Managed Cloud backups are not recoverable without your Master Vault Key.
- Restore and certain purge actions are destructive and may permanently overwrite or delete data.
- Third-party outages (Google, your host, Freemius, network providers) may delay or prevent jobs; Provider is not liable for those third-party failures beyond commercially reasonable mitigation.
- Entitlements expire or pause according to plan rules; unpaid backup data is deleted after published grace periods.
- Self-serve tools do not include unlimited professional services.
10. Warranties, liability, and indemnity
- The Services are provided “as is” and “as available” to the fullest extent permitted by law, except where mandatory consumer protections apply.
- Liability caps, exclusions, and non-excludable rights are as stated in the Terms of Service.
- You agree to indemnify and hold MigraSync harmless from claims arising from: (a) content you lack rights to process; (b) unlawful use of the Services; (c) loss of Master Vault Key or credentials under your control; (d) instructions given by your Site Administrators or agents; and (e) End Client disputes where you acted as intermediary—except to the extent caused by Provider’s willful misconduct.
11. Suspension and enforcement
We may suspend or terminate access for Terms violations, abuse, fraud, security risk, or unlawful content, as described in the Terms of Service. Suspension may interrupt migrations, backups, and restores in progress.
12. Changes
We may update this Agreement from time to time. The Last updated date and Version will change when we do. Material changes will be published on migrasync.com. Continued use of the Services after the effective date constitutes acceptance, except where mandatory law requires explicit re-consent. Plugin acceptance checkboxes may present the then-current version.
13. Governing law and disputes
Governing law, dispute resolution, and consumer protections follow the Terms of Service. Contact [email protected] first so we can attempt prompt resolution.
14. Contact
| Purpose | Contact |
| Product & responsibilities questions | [email protected] |
| Security | [email protected] |
| Website | https://migrasync.com |
| Freemius billing | [email protected] |
15. Related documents
- Terms of Service
- Privacy Policy
- Refund & Cancellation Policy
- Cookie Policy
- Security
- Pricing
- Freemius Buyer Terms
16. Plugin acceptance statement
When presented in the MigraSync Plugin, the following statement (or substantially equivalent wording) constitutes acceptance of this Agreement:
I have read and agree to the MigraSync Service Responsibilities Agreement. I understand which duties belong to MigraSync and which belong to me for migration, backup, restore, and related services, including custody of my Master Vault Key and lawful rights to the content I process.
Acceptance is recorded for the Account / connected site context in which the Plugin is used and applies to subsequent jobs under the then-current version unless we require re-acceptance after a material update.
17. Legal notice
This document is provided for transparency and operational clarity between the parties. It is not legal advice. If you use MigraSync for business-critical, regulated, or multi-client agency workloads, review this Agreement with your own counsel and request a DPA where required.
For questions: [email protected]