Trust and Compliance

Trust and Compliance

Trust & Compliance

Trust & Compliance

Last Updated: [Insert Date]

1. Overview

This document combines our Terms & Conditions, Privacy Policy, Data Protection, Security Practices, and Compliance Framework into a single reference. It defines how we operate, protect data, and deliver IT services responsibly.

2. Services

  • IT Support (remote and on-site)
  • Infrastructure & network management
  • Cybersecurity services
  • Project delivery and consulting

3. Legal & Usage Terms

  • Use services lawfully
  • No unauthorised system access or misuse
  • Client responsible for system compliance
  • Services may be suspended for breach or non-payment

4. Data Protection & Privacy

We comply with UK GDPR and Data Protection Act 2018.

  • Data collected: contact, technical, support, billing
  • Legal basis: contract, legitimate interest, legal obligation
  • Retention: up to 6 years (financial), 12–24 months (logs)

5. Cookie Usage

  • Essential cookies
  • Analytics cookies
  • User preference cookies

Users can manage cookies via browser or consent banner.

6. Security Framework

Core Principles

  • Confidentiality
  • Integrity
  • Availability

Controls

  • Role-based access control
  • Multi-factor authentication
  • Encryption (data in transit & at rest)
  • Continuous monitoring & logging
  • Patch management

7. Infrastructure & Endpoint Security

  • Firewalls and segmentation
  • Endpoint protection & encryption
  • Secure remote access
  • Device compliance policies

8. Incident Response

  • Threat containment
  • Investigation and remediation
  • Client notification when required
  • 72-hour breach reporting (if applicable)

9. Backup & Disaster Recovery

  • Automated backups
  • Offsite storage
  • Recovery testing
  • Defined RTO/RPO

10. Data Processing (DPA)

When acting as a processor:

  • Process data only under instruction
  • Maintain strict confidentiality
  • Implement security controls
  • Support data subject rights

Client Responsibilities

  • Ensure lawful data use
  • Provide clear instructions
  • Maintain GDPR compliance

11. Third-Party Management

  • Vendors assessed for security
  • Data shared only where necessary
  • Contractual safeguards enforced

12. Liability & Risk

  • No liability for indirect losses
  • No guarantee of uninterrupted service
  • Liability limited to service value

13. Compliance Alignment

  • UK GDPR
  • Data Protection Act 2018
  • Industry best practices

14. Updates

This document may be updated periodically.

15. Contact

Email: [Insert Email]

Address: [Insert Address]

Scroll to Top