Trust and Compliance
Trust & Compliance
Last Updated: [Insert Date]
1. Overview
This document combines our Terms & Conditions, Privacy Policy, Data Protection, Security Practices, and Compliance Framework into a single reference. It defines how we operate, protect data, and deliver IT services responsibly.
2. Services
- IT Support (remote and on-site)
- Infrastructure & network management
- Cybersecurity services
- Project delivery and consulting
3. Legal & Usage Terms
- Use services lawfully
- No unauthorised system access or misuse
- Client responsible for system compliance
- Services may be suspended for breach or non-payment
4. Data Protection & Privacy
We comply with UK GDPR and Data Protection Act 2018.
- Data collected: contact, technical, support, billing
- Legal basis: contract, legitimate interest, legal obligation
- Retention: up to 6 years (financial), 12–24 months (logs)
5. Cookie Usage
- Essential cookies
- Analytics cookies
- User preference cookies
Users can manage cookies via browser or consent banner.
6. Security Framework
Core Principles
- Confidentiality
- Integrity
- Availability
Controls
- Role-based access control
- Multi-factor authentication
- Encryption (data in transit & at rest)
- Continuous monitoring & logging
- Patch management
7. Infrastructure & Endpoint Security
- Firewalls and segmentation
- Endpoint protection & encryption
- Secure remote access
- Device compliance policies
8. Incident Response
- Threat containment
- Investigation and remediation
- Client notification when required
- 72-hour breach reporting (if applicable)
9. Backup & Disaster Recovery
- Automated backups
- Offsite storage
- Recovery testing
- Defined RTO/RPO
10. Data Processing (DPA)
When acting as a processor:
- Process data only under instruction
- Maintain strict confidentiality
- Implement security controls
- Support data subject rights
Client Responsibilities
- Ensure lawful data use
- Provide clear instructions
- Maintain GDPR compliance
11. Third-Party Management
- Vendors assessed for security
- Data shared only where necessary
- Contractual safeguards enforced
12. Liability & Risk
- No liability for indirect losses
- No guarantee of uninterrupted service
- Liability limited to service value
13. Compliance Alignment
- UK GDPR
- Data Protection Act 2018
- Industry best practices
14. Updates
This document may be updated periodically.
15. Contact
Email: [Insert Email]
Address: [Insert Address]
