MigraSync Service Responsibilities Agreement

MigraSync Service Responsibilities Agreement

Effective date: 19 July 2026
 
Last updated: 19 July 2026
 
Version: 1.0
 
Published at: https://migrasync.com/responsibilities/

Preamble

This Service Responsibilities Agreement (the “Agreement”) defines the division of duties, ownership, and accountability between MigraSync (“Provider”, “we”, “us”, “our”) and the customer, site administrator, or authorized agent who installs or uses the MigraSync Plugin and related services (“Customer”, “you”, “your”).

This Agreement applies to all MigraSync products and services, including self-serve SaaS features and handcrafted professional services, unless a signed Statement of Work expressly overrides a section for a specific engagement.

By checking the acceptance box in the MigraSync Plugin, creating an account, purchasing a plan, submitting a service request, or starting a migration, backup, restore, or related job, you acknowledge that you have read this Agreement and agree to the responsibilities allocated below.

This Agreement supplements—and does not replace—our Terms of Service, Privacy Policy, and Refund & Cancellation Policy. If there is a conflict on billing or refunds, the Terms and Refund Policy control. If there is a conflict on data protection, the Privacy Policy controls. If there is a conflict on operational duties for product use, this Agreement controls.

1. Parties and capacity

PartyIdentity and role
ProviderElliyas Ahmed, operating as MigraSync (https://migrasync.com), based in Bangladesh. MigraSync is a software product brand.
CustomerThe individual or organization that holds a MigraSync Account, purchases entitlements, and/or authorizes use of the MigraSync Plugin on a WordPress site.
Site AdministratorAny WordPress administrator who configures the MigraSync Plugin, API keys, vault keys, or job settings on a connected site. Actions taken in the Plugin bind the Customer.
End Client (if applicable)Where an agency or consultant uses MigraSync on behalf of a third party, the contracting Customer remains the Account holder unless we agree otherwise in writing. The Customer is responsible for obtaining End Client authority.

You represent that you have lawful authority to bind the Customer (and, where relevant, the End Client) to this Agreement and to process the content you select for migration, backup, or restore.

Merchant of Record: Paid SaaS orders are processed by Freemius.com. Freemius’s Buyer Terms apply to checkout, tax, invoicing, and payment-related matters. Product support remains with MigraSync at [email protected].

2. Covered products and services

This Agreement covers the following product lines (collectively, the “Services”):

Product / serviceDescription
Blogger → WordPress MigrationSelf-serve import via Blogger API (OAuth) or Google Takeout / local file, subject to plan entitlements (trial, Starter, Standard).
WordPress Cloud BackupScheduled or manual packaging of site data and encrypted storage in MigraSync Managed Cloud (Essential, Pro, and eligible trials).
WP RestoreRestoration of an encrypted Managed Cloud backup to a WordPress site, on eligible plans.
WordPress → WordPress migration / cloneSite transfer or clone performed using backup and restore capabilities (not a separate entitlement unless stated at checkout).
Done-For-You (DFY) / Professional ServicesHandcrafted migration or related work ordered via service request or written SOW (e.g. DFY Standard, Pro, Premium).
Account, dashboard, APIs, and supportRegistration, API keys, plan sync, job history, and documented support channels.

Plan limits, validity windows, retention, and pricing shown at Pricing and in the Plugin UI are authoritative for entitlements.

3. Shared responsibility model

MigraSync operates a shared responsibility model, consistent with leading cloud and SaaS practice. We secure and operate the control plane and Managed Cloud. You secure and operate your WordPress host, credentials, content rights, and operational choices.

3.1 Responsibility matrix (at a glance)

DomainProvider (MigraSync)Customer
Platform availabilityOperate Core APIs, quota enforcement, and Managed Cloud with commercially reasonable careMaintain your host, domain, DNS, SSL, and WordPress stack
Plugin runtimeShip and maintain the MigraSync Plugin; document system requirementsInstall, update, and configure the Plugin; meet PHP/WordPress/host minimums
AuthenticationIssue and validate API keys; protect Core authentication systemsSafeguard Account credentials, API keys, and 2FA; revoke compromised keys
Content ownership & legalityProcess content only to deliver the Services you requestOwn or hold lawful rights to all content migrated, backed up, or restored
Encryption keysProvide encryption mechanisms for Managed Cloud backupsGenerate, store, and recover the Master Vault Key; we cannot restore without it
Backup scope & retentionEnforce plan caps; execute retention/auto-purge as configuredChoose scope, schedule, and retention; monitor job success; renew subscriptions
Migration qualityProvide tools to import eligible Blogger content and media per selected scopeReview imports; configure theme, permalinks, redirects, SEO, and post-migration QA
Data controller / processorAct as processor for job data you submit through the ServicesAct as controller of site and blog content; ensure lawful basis for processing
Third-party servicesIntegrate documented providers (e.g. cloud storage, Freemius)Comply with Google/Blogger and host terms; resolve host/Google outages affecting your jobs
Professional / DFY workDeliver agreed scope in SOW or package descriptionProvide access, prerequisites, timely feedback, and acceptance within the review window

4. Provider responsibilities

MigraSync will:

  1. Provide the Services described for your active entitlements, including migration tooling, Managed Cloud backup storage, restore capabilities where eligible, and the customer dashboard.
  2. Authenticate and authorize Plugin and API requests using your Account and API key, and enforce plan quotas and product gates.
  3. Protect Managed Cloud with industry-standard encryption at rest for backup archives (AES-256 class), using keys you control where the product design so requires.
  4. Limit use of Customer Content to performing the jobs you initiate, operating the platform, providing support you request, and complying with law—as further described in the Privacy Policy. We do not sell your content or use it for advertising.
  5. Apply retention and deletion rules published in the Terms (per-backup auto purge, subscription grace periods, customer-initiated purge).
  6. Provide support through documented channels for platform and Plugin issues within plan entitlements.
  7. Notify of material changes to this Agreement or related policies by updating the published documents and the “Last updated” date.
  8. For DFY / professional services, perform the work described in the applicable package or Statement of Work with reasonable skill and care, and return or revoke temporary access credentials after delivery where practicable.

MigraSync does not, unless separately agreed in writing:

5. Customer responsibilities

You agree to:

5.1 Lawful use and authority

  1. Use the Services only for lawful purposes and only for content and sites you own or are authorized to process.
  2. Ensure Site Administrators and agencies acting for you are authorized to bind you.
  3. Comply with Google’s terms when using Blogger OAuth, APIs, or Takeout exports.
  4. Not use the Services to infringe intellectual property, privacy, or other rights, or to distribute malware, spam, or illegal material.

5.2 Environment and Plugin

  1. Run a supported WordPress version with the MigraSync Plugin and a valid API key.
  2. Meet documented system requirements (including PHP version, OpenSSL/JSON, HTTPS outbound access, memory, and disk)—see Documentation — System requirements.
  3. Keep WordPress, PHP, and the Plugin reasonably up to date; resolve host or security-plugin blocks that prevent loopback or API calls.
  4. Sync plan status in the Plugin after purchase or cancellation and contact support if entitlements do not update within a reasonable time (e.g. 24 hours).

5.3 Credentials and secrets

  1. Protect Account passwords, API keys, Google OAuth sessions, and host/admin credentials.
  2. Store the Master Vault Key in a durable, offline or password-manager location you control. Loss of the Master Vault Key may make backups permanently unrestorable.
  3. Not embed API keys in public repositories, client-side scripts, or shared channels.
  4. For DFY engagements, provide temporary access only as needed and rotate credentials after the engagement ends.

5.4 Migration-specific duties

  1. Complete Google OAuth or supply a complete, valid Takeout/local export, as applicable.
  2. Select an appropriate migration package for blog size (Starter vs Standard slot rules).
  3. Review imported posts, pages, media, comments, and authors before treating the migration as complete.
  4. Configure WordPress theme, menus, redirects, analytics, forms, and SEO yourself (or via a separate professional engagement).
  5. Accept that migration success depends on Google/Blogger availability, export integrity, and your hosting capacity.

5.5 Backup- and restore-specific duties

  1. Choose backup scope, schedule, and auto-purge retention appropriate to your risk tolerance.
  2. Monitor backup job success and investigate failures promptly.
  3. Renew backup subscriptions if you require ongoing protection; understand that long retention settings do not preserve data after subscription grace expires.
  4. Export or download critical recovery points before grace periods end if you choose not to renew.
  5. Before restore, understand that restore may overwrite site data; take additional precautions on production sites as you deem necessary.
  6. Verify restored sites (content, media, plugins, themes, and critical workflows) after restore completes.

5.6 Operational monitoring

  1. Maintain independent hosting and domain control; MigraSync is not your host.
  2. Maintain your own change-management and rollback practices for production sites.
  3. Not circumvent quotas, reverse engineer Core, abuse APIs, or impose unreasonable load.

6. Product-specific allocations

6.1 Blogger → WordPress Migration

ResponsibilityOwner
Lawful rights to Blogger contentCustomer
OAuth / Takeout / export completenessCustomer
Slot allocation and entitlement enforcementProvider
Import tooling, queueing, media handling (within scope)Provider
Hosting capacity during importCustomer
Post-import theme, design, redirects, SEOCustomer
Layout/gadget/email/SEO outcome guaranteesNeither (explicitly out of scope)

6.2 WordPress Cloud Backup

ResponsibilityOwner
Selecting what to include (DB, media, plugins, themes)Customer
Building archive on Customer’s serverPlugin (runs on Customer infrastructure)
Encrypting with Master Vault Key before uploadPlugin / Customer key custody
Storing encrypted archives in Managed CloudProvider
Plan storage caps and quota enforcementProvider
Retention / auto-purge while entitlement is activeProvider (per Customer settings)
Renewing subscription / acting before grace expiryCustomer
Malware scanning of live siteCustomer (unless separate service)

6.3 WP Restore

ResponsibilityOwner
Selecting the backup point to restoreCustomer
Providing valid Master Vault KeyCustomer
Executing restore job and overwriting target data as designedPlugin / Provider platform
Confirming destructive overwrite risk before proceedCustomer
Post-restore functional verificationCustomer
Fixing incompatible plugins/themes after restoreCustomer

6.4 WordPress → WordPress migration / clone

Treated as backup on source + restore on destination unless a DFY SOW states otherwise. Customer is responsible for both sites’ hosts, credentials, DNS cutover, and post-cutover validation.

6.5 Done-For-You / Professional Services

ResponsibilityOwner
Accurate service request / SOW scopeCustomer & Provider (mutual)
Providing staging URL, admin access, OAuth/Takeout, and prerequisites on timeCustomer
Performing handcrafted work within purchased package or SOWProvider
Included revisions and acceptance window (as stated for the package)Per package / SOW
Work outside scope (theme redesign, unlimited DevOps, custom plugins)Out of scope unless new SOW
Fees, payment link, and refunds for DFYAs stated at order / Refund Policy; may differ from self-serve SaaS

Delivery is complete when the agreed deliverables are made available for Customer review. Changes requested after the acceptance window or outside the package description constitute new scope.

7. Data roles, processing, and subprocessors

  1. Customer is the data controller (or equivalent) for personal data contained in Blogger or WordPress content and backups.
  2. MigraSync is the data processor for processing performed to deliver the Services you request through the Account and Plugin.
  3. Processing purposes, retention, security measures, and international transfers are described in the Privacy Policy. A formal Data Processing Agreement (DPA) is available on request.
  4. Subprocessors may include infrastructure and commercial providers (for example Managed Cloud storage and Freemius). Use of Google services for Blogger access is under Customer’s relationship with Google.
  5. Starting a job in the Plugin constitutes instruction to process the selected data for that operation.

8. Intellectual property and Customer Content

  1. Customer Content (posts, pages, media, databases, and similar materials you process through the Services) remains yours.
  2. You grant MigraSync a limited, worldwide, non-exclusive license to host, transmit, encrypt, store, and process Customer Content solely to provide the Services.
  3. The MigraSync software, branding, documentation, and platform remain Provider property. No ownership transfer is implied by this Agreement.
  4. Feedback you provide may be used to improve the Services without obligation to you.

9. Acceptance of risk and acknowledgements

By accepting this Agreement in the MigraSync Plugin or otherwise, you acknowledge that:

  1. Migration and backup jobs run primarily on your WordPress server; host limits can cause failures or incomplete jobs.
  2. Encrypted Managed Cloud backups are not recoverable without your Master Vault Key.
  3. Restore and certain purge actions are destructive and may permanently overwrite or delete data.
  4. Third-party outages (Google, your host, Freemius, network providers) may delay or prevent jobs; Provider is not liable for those third-party failures beyond commercially reasonable mitigation.
  5. Entitlements expire or pause according to plan rules; unpaid backup data is deleted after published grace periods.
  6. Self-serve tools do not include unlimited professional services.

10. Warranties, liability, and indemnity

  1. The Services are provided “as is” and “as available” to the fullest extent permitted by law, except where mandatory consumer protections apply.
  2. Liability caps, exclusions, and non-excludable rights are as stated in the Terms of Service.
  3. You agree to indemnify and hold MigraSync harmless from claims arising from: (a) content you lack rights to process; (b) unlawful use of the Services; (c) loss of Master Vault Key or credentials under your control; (d) instructions given by your Site Administrators or agents; and (e) End Client disputes where you acted as intermediary—except to the extent caused by Provider’s willful misconduct.

11. Suspension and enforcement

We may suspend or terminate access for Terms violations, abuse, fraud, security risk, or unlawful content, as described in the Terms of Service. Suspension may interrupt migrations, backups, and restores in progress.

12. Changes

We may update this Agreement from time to time. The Last updated date and Version will change when we do. Material changes will be published on migrasync.com. Continued use of the Services after the effective date constitutes acceptance, except where mandatory law requires explicit re-consent. Plugin acceptance checkboxes may present the then-current version.

13. Governing law and disputes

Governing law, dispute resolution, and consumer protections follow the Terms of Service. Contact [email protected] first so we can attempt prompt resolution.

14. Contact

PurposeContact
Product & responsibilities questions[email protected]
Security[email protected]
Websitehttps://migrasync.com
Freemius billing[email protected]

15. Related documents

16. Plugin acceptance statement

When presented in the MigraSync Plugin, the following statement (or substantially equivalent wording) constitutes acceptance of this Agreement:

I have read and agree to the MigraSync Service Responsibilities Agreement. I understand which duties belong to MigraSync and which belong to me for migration, backup, restore, and related services, including custody of my Master Vault Key and lawful rights to the content I process.

Acceptance is recorded for the Account / connected site context in which the Plugin is used and applies to subsequent jobs under the then-current version unless we require re-acceptance after a material update.

17. Legal notice

This document is provided for transparency and operational clarity between the parties. It is not legal advice. If you use MigraSync for business-critical, regulated, or multi-client agency workloads, review this Agreement with your own counsel and request a DPA where required.

For questions: [email protected]