Legal · B2B services
Client Terms of Business.
The standard business-to-business terms that sit behind a proposal or Statement of Work.
Version dated 22 September 2026
These Terms of Business apply to B2B services provided under Build ALONG The Way using the trading brand VJ Digital Growth Partner (“Agency”, “we”, “us”, “our”). Business address: 4th Floor, 18 St. Cross Street, London, EC1N 8UN.
1. Business-to-business basis
These Terms are intended only for clients acting wholly or mainly for purposes relating to their trade, business, craft or profession. By entering into an Agreement, the Client confirms that it is contracting in the course of business and not as a consumer.
2. The Agreement and order of precedence
When the Client accepts a proposal, quotation, order form or Statement of Work issued by us, an agreement is formed between us and the legal entity identified as the Client in that document.
The Agreement consists of:
- the relevant Statement of Work, proposal, order form or quotation (“SOW”);
- the Data Processing Schedule, where applicable;
- these Client Terms of Business; and
- any other document expressly incorporated in writing.
If documents conflict, the Data Processing Schedule prevails on processor obligations and personal-data processing; the SOW prevails on engagement-specific commercial terms; and these Terms apply otherwise.
3. Services and standard of performance
We will provide the Services described in the SOW with reasonable care and skill. Services may include digital strategy, search-engine optimisation, paid advertising, social advertising, content, website design or development, conversion optimisation, analytics, tracking, CRM, automation, email marketing, AI-assisted work, consultancy and related digital-growth services.
Only Services and Deliverables expressly included in the SOW are included in our fees. Advice, ideas or possibilities discussed informally do not become contractual Deliverables unless added to the agreed scope.
4. Scope, assumptions and changes
The SOW should identify the scope, Deliverables, assumptions, exclusions, timing, fees, third-party costs, advertising budget, term and Client responsibilities. Either party may propose a change. We are not required to carry out additional or changed work until scope, timing and charges have been agreed in writing.
Out-of-scope work may be quoted separately, charged at an agreed hourly or day rate, or declined.
5. Client responsibilities
The Client is responsible for its own business and will:
- provide accurate, complete and timely information, instructions and materials;
- provide required access to websites, domains, analytics, advertising accounts, CRM systems and other platforms;
- provide approvals, feedback and decisions within reasonable timescales;
- appoint an authorised point of contact with authority to give instructions and approvals;
- maintain appropriate licences, permissions, registrations and regulatory approvals for its business;
- ensure its products, services, offers, prices, warranties, fulfilment, customer service and business practices comply with applicable law;
- maintain appropriate backups and security where those responsibilities sit with the Client; and
- notify us promptly of any fact, restriction, complaint, investigation or legal issue that could materially affect the Services.
6. Client Materials, claims and representations
“Client Materials” means information, instructions, data, claims, representations, offers, prices, warranties, testimonials, reviews, images, trade marks, copy, product information, service descriptions, legal wording, customer data and other materials supplied, selected, required or approved by the Client.
The Client is responsible for ensuring that Client Materials and the Client’s underlying business, products and services are accurate, lawful, not misleading, appropriately substantiated and do not infringe third-party rights.
Unless the SOW expressly requires us to perform a defined verification or compliance-review service, we are entitled to rely on Client Materials without independently auditing or verifying their factual, scientific, technical, financial, legal or regulatory accuracy.
The Client must not ask us to publish or promote a claim that the Client cannot reasonably substantiate. If we raise a concern, the Client will provide suitable evidence, amend the claim or obtain appropriate professional advice.
7. Client approvals and sign-off
Where we submit advertising, copy, designs, websites, promotions, offers, targeting, campaigns or other Deliverables for approval, the Client is responsible for reviewing them promptly.
Approval confirms, to the best of the Client’s knowledge and subject to any responsibility expressly accepted by us in the SOW, that Client-specific facts, prices, claims, offers, product or service descriptions, mandatory disclosures and business information are accurate and authorised for use.
We may rely on approval given by the Client’s authorised contact. We are not responsible for inaccuracies introduced by the Client or another supplier after our approval or handover.
8. Compliance responsibility and regulated matters
Unless expressly included in the SOW, our Services do not include legal, regulatory, tax, accounting, financial, medical or other regulated professional advice, and we do not act as the Client’s compliance officer.
The Client is responsible for identifying laws, sector rules, professional restrictions, licensing requirements and mandatory disclosures that apply to its business, products, services and promotions, including any special rules that apply to regulated sectors.
We may refuse, pause or remove work that we reasonably believe is unlawful, materially misleading, infringing, unsafe or contrary to a binding platform rule. Doing so does not transfer the Client’s compliance responsibility to us.
9. Client decisions and use of recommendations
We may make recommendations about strategy, budget, creative, positioning, technology, channels or optimisation. The Client remains responsible for commercial decisions and for deciding whether and how to act on recommendations.
Forecasts, models, scenarios and estimates are based on assumptions and available information. They are not promises of future performance.
10. Client delays and dependencies
Our timetable depends on timely Client cooperation and third-party dependencies. If the Client delays access, content, approvals, information, payment or feedback, we may reasonably adjust the timetable and reschedule resources.
We are not responsible for delay to the extent caused by the Client or a person for whom the Client is responsible. If a material delay causes additional work or cost, we may agree a revised timetable and additional charges before resuming.
11. Access, credentials and account security
The Client will provide access using secure and appropriate methods and will not unnecessarily share passwords. Where possible, role-based access should be used. Each party is responsible for protecting credentials it controls and promptly reporting suspected compromise.
We are not responsible for unauthorised access caused by compromised Client credentials, insecure Client practices or changes made by the Client or another supplier, except to the extent directly caused by our breach of the Agreement.
12. Fees, invoices and payment
Fees are stated in the SOW and exclude VAT unless expressly stated otherwise. Monthly retainers and recurring managed-service fees are invoiced monthly in advance unless the SOW says otherwise. Project invoicing and deposits will be set out in the SOW.
Unless the SOW states otherwise, invoices are due within 14 days of the invoice date. If the Client genuinely disputes an invoice, it must notify us promptly with reasons and pay the undisputed amount when due.
For overdue undisputed amounts, we may exercise our rights under applicable late-payment law, including statutory interest and debt-recovery costs where available. If the contract specifies a different interest rate, that contractual rate will apply as permitted by law.
13. Suspension for non-payment or risk
If an undisputed invoice remains overdue after reasonable notice, we may suspend some or all Services until payment is received. We may also suspend where continuing work would create a material legal, security, safety or platform-compliance risk.
We are not responsible for delay caused by a lawful suspension. Suspension does not cancel amounts already due.
14. Media spend and third-party costs
Unless the SOW expressly says otherwise, Agency fees do not include advertising or media spend, hosting, domains, stock assets, software licences, platform fees, paid data, third-party production or other external costs.
Where practicable, the Client should own and directly fund core advertising and platform accounts. If we incur an approved third-party cost on the Client’s behalf, the Client will reimburse it according to the SOW or invoice terms.
Media spend and pass-through third-party charges are not Agency professional fees and are excluded when calculating any fee-based liability cap.
15. Third-party platforms and suppliers
Our work may depend on third-party platforms and suppliers that we do not control. These may include search engines, advertising networks, social platforms, hosting providers, domain registrars, CRM systems, analytics platforms, AI services, email systems, plugins, APIs and software vendors.
Third parties may change algorithms, policies, prices, interfaces or APIs; reject advertising; suspend or close accounts; remove functionality; change attribution; experience outages or security incidents; or discontinue products.
To the fullest extent permitted by law, we are not liable for third-party acts, omissions, outages, policy decisions or service changes outside our reasonable control, except to the extent a loss was directly caused by our own breach of the Agreement or failure to exercise reasonable care and skill.
16. No guarantee of marketing or commercial results
Unless a specific result is expressly stated in the SOW as a contractual guarantee, we do not guarantee and are not in breach merely because the Services do not achieve a particular search ranking, traffic level, impression level, click volume, engagement level, lead volume or quality, conversion rate, cost per lead or acquisition, return on advertising spend, sales, revenue, profit, market share, AI-search visibility or other KPI or commercial outcome.
Targets, benchmarks, forecasts, projections and performance models are objectives or good-faith estimates, not guarantees. Past performance and case studies do not guarantee future results.
17. Search, SEO and AI-search services
Search engines and AI-search or generative-answer systems control their own indexing, ranking, citation and presentation systems. We do not guarantee indexing, ranking position, visibility, traffic or continued performance, and we are not responsible solely because an algorithm or platform change affects results.
We are not required to use techniques that we reasonably believe breach material platform rules, create unacceptable legal or reputational risk, or are likely to damage the Client’s digital assets.
18. Paid advertising
Where we manage paid advertising, budgets and our authority to change them will be described in the SOW or agreed in writing. Advertising platforms ultimately control billing, delivery, approval and auction outcomes.
The Client remains responsible for the lawfulness and substantiation of its products, services, claims, offers, landing-page information and fulfilment. We do not guarantee ad approval, account availability, spend delivery, lead quality or commercial return.
19. Websites, software and development
Where we provide website or development services, functionality and supported environments will be those stated in the SOW or reasonably implied by the agreed scope. Ongoing hosting, maintenance, support, accessibility auditing, legal compliance review and security monitoring are not included unless expressly stated.
Third-party themes, plugins, libraries, fonts, APIs and software remain subject to their own licence terms, updates and availability. We are not responsible for later incompatibility or failure caused by a third-party change outside our reasonable control.
The Client remains responsible for its own statutory website information, business claims, policies and sector-specific notices unless we have expressly agreed to prepare or maintain a particular item.
20. Intellectual property — Client Materials
The Client retains ownership of intellectual property it provides to us. The Client grants us a non-exclusive, worldwide licence during the Agreement to use, copy, adapt, host, transmit and process Client Materials to the extent reasonably necessary to provide the Services.
The Client warrants that it has the rights, licences, permissions and lawful basis necessary for us to use the Client Materials as instructed.
21. Intellectual property — Agency Materials and Deliverables
We retain ownership of our pre-existing and general methodologies, know-how, templates, processes, frameworks, prompts, software, libraries, reusable code, tools, systems and other materials developed independently of the Client (“Agency Materials”).
Unless the SOW states otherwise, once all undisputed fees relating to a final bespoke Deliverable have been paid in full, we assign to the Client the intellectual-property rights that we own in that final bespoke Deliverable, excluding Agency Materials and third-party materials.
To the extent Agency Materials are embedded in a fully paid Deliverable and are necessary for normal use of it, we grant the Client a perpetual, non-exclusive licence to use those embedded Agency Materials for the Client’s own business purposes. Third-party materials remain subject to their own licence terms.
Editable source files, working files, internal drafts, proprietary tools, reusable components and development resources are included only if expressly stated in the SOW.
22. Portfolio and case-study use
Unless the engagement is expressly confidential, we may identify the Client as a client and show publicly launched, non-confidential work in our portfolio. We will obtain written approval before publishing confidential commercial information, non-public performance figures or a substantive case study attributed to the Client.
The Client may ask us not to use its name or brand publicly and we will reasonably respect that request.
23. Artificial intelligence
We may use appropriate AI tools to assist with research, analysis, ideation, drafting, coding, optimisation and production support. AI-assisted output may require human review and may not be unique.
We will take reasonable steps appropriate to the engagement to protect Client confidential information and personal data. We will not knowingly submit Client confidential information or Client-controlled personal data to a general-purpose AI service in a way that would breach our contractual or legal obligations or permit inappropriate secondary use.
Specific Client restrictions on AI use must be agreed in the SOW before the relevant work begins.
24. Confidentiality
Each party must keep the other party’s confidential information confidential and use it only for the Agreement. This does not apply to information that is lawfully public, already lawfully known without a duty of confidence, independently developed, lawfully obtained from a third party, or required to be disclosed by law or a competent authority.
A party may share confidential information with personnel, contractors and professional advisers who genuinely need it for the Agreement and are subject to appropriate confidentiality duties.
25. Data protection
Each party will comply with applicable data-protection law in relation to its own activities. Where each party independently determines the purposes and means of processing, each acts as an independent controller for that processing.
Where we process personal data on the Client’s behalf as processor, Schedule 1 to these Terms applies unless the parties sign a different compliant data-processing agreement.
The Client is responsible for ensuring that personal data supplied to us has been collected and disclosed lawfully, that the Client has an appropriate lawful basis for the processing it instructs, and that required privacy information has been provided.
26. Subcontractors
We may use employees, freelancers, specialist contractors and service providers to help deliver the Services. We remain responsible for our contractual obligations when using subcontractors. Where a subcontractor processes Client personal data as a sub-processor, the Data Processing Schedule applies.
27. Non-exclusivity and conflicts
Unless the SOW expressly grants exclusivity, our relationship is non-exclusive and we may provide services to other organisations, including businesses operating in the same broad sector. We will not use the Client’s confidential information for another client and will manage material conflicts appropriately.
28. Client indemnity
To the fullest extent permitted by law, the Client will indemnify us against third-party claims and associated losses, liabilities, damages, costs and reasonable professional fees arising directly from:
- Client Materials that infringe another person’s intellectual-property, privacy, confidentiality or other rights;
- a false, misleading, unsubstantiated or unlawful Client claim, representation, offer, promotion, warranty or business statement supplied, required or approved by the Client;
- the Client’s products, services, fulfilment, customer service, business practices or regulatory obligations, except to the extent we expressly accepted responsibility for the relevant matter in the SOW;
- the Client’s unlawful instruction or material breach of applicable law;
- personal data that the Client did not have the right or lawful basis to provide or instruct us to process; or
- the Client’s material breach of clause 20 or another warranty in the Agreement.
This indemnity does not apply to the extent the claim or loss was caused by our own breach of the Agreement, negligence, unauthorised alteration or unlawful act. We will take reasonable steps to mitigate indemnified losses and will not settle a material third-party claim in a way that admits wrongdoing by the Client without consulting the Client, where reasonably practicable.
29. Liability — liabilities that cannot be excluded
Nothing in the Agreement excludes or limits either party’s liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be excluded or limited.
30. Liability — specific exclusions
Subject to clause 29 and to the fullest extent permitted by law, we will not be liable merely because a forecast, target, recommendation, campaign or strategy does not achieve the Client’s expected commercial result, where we have provided the Services with the standard required by the Agreement.
Subject to clause 29, we will not be liable to the extent a loss results from:
- inaccurate, incomplete, unlawful or misleading Client Materials or information;
- Client instructions, Client decisions or Client-approved claims or materials;
- the Client’s delay, non-cooperation, failure to follow agreed dependencies or failure to follow material advice;
- changes made by the Client or another supplier without our knowledge or approval;
- a third-party platform, supplier, algorithm, policy, suspension, outage or service change outside our reasonable control;
- the Client’s failure to maintain backups, security or access controls that are the Client’s responsibility;
- an event outside our reasonable control; or
- use of a Deliverable for a purpose or in a context materially different from that for which it was supplied.
These exclusions do not protect us to the extent the relevant loss was directly caused by our own breach of the Agreement or failure to exercise reasonable care and skill, subject to the other limitations in the Agreement.
31. Liability — excluded categories of loss
Subject to clause 29, and to the fullest extent permitted by law, we will not be liable under or in connection with the Agreement, whether in contract, tort (including negligence), misrepresentation, breach of statutory duty, restitution or otherwise, for loss of profit, revenue, sales, business, contracts, opportunity, anticipated savings, goodwill or reputation, or for indirect or consequential loss or damage, whether or not foreseeable.
For clarity, this clause does not exclude the Client’s obligation to pay fees and approved charges properly due under the Agreement.
32. Liability — overall cap
Subject to clause 29, our total aggregate liability arising out of or in connection with a particular SOW, whether in contract, tort (including negligence), misrepresentation, breach of statutory duty, restitution or otherwise, will not exceed 100% of the Agency professional fees paid or payable under that SOW during the 12 months immediately preceding the event giving rise to the claim.
If the SOW has been in force for less than 12 months when the event occurs, the cap is the Agency professional fees paid or payable under that SOW during that shorter period. For a fixed-price project lasting less than 12 months, the cap is the total Agency professional fees paid or payable for that project.
VAT, advertising or media spend, software or licence charges, hosting, production costs and other pass-through third-party expenditure are not Agency professional fees for the purpose of this cap. Multiple claims arising from the same or substantially the same event or series of connected events are treated as one claim for application of the cap.
33. Cybersecurity and data loss
Neither party guarantees that internet-based systems or third-party services will be entirely secure or uninterrupted. We will comply with the security obligations we have accepted under the Agreement and any applicable Data Processing Schedule.
Subject to clause 29, we are not responsible for a cyber incident, unauthorised access, malware, data loss or service interruption caused by systems outside our control, compromised Client credentials, Client security failures, unauthorised Client or third-party changes, or a third-party provider outside our reasonable control, except to the extent directly caused by our own breach.
The Client is responsible for maintaining backups where the SOW assigns that responsibility to the Client. Our liability for a data or security incident caused by our breach remains subject to clause 32 unless applicable law prevents that limitation.
34. Mitigation
Each party must take reasonable steps to minimise loss arising from a breach or incident. We are not liable for loss that could reasonably have been avoided or reduced by the Client taking reasonable mitigating action.
35. Allocation of risk
The parties acknowledge that the fees have been agreed taking account of the allocation of commercial risk in the Agreement and that the limitations and exclusions are intended to allocate risk between businesses. The Client is responsible for maintaining insurance appropriate to its own business, activities and exposures.
Each limitation and exclusion is intended to operate separately. If a particular provision is unenforceable, the remaining provisions continue to apply to the fullest extent permitted by law.
36. Term and termination
The term of each engagement is stated in the SOW. If the SOW contains an initial or minimum term, the Client remains responsible for charges committed for that term unless the SOW provides otherwise or a right to terminate for breach applies.
Unless the SOW states a different arrangement, an ongoing monthly engagement may be terminated for convenience after any minimum term by giving 30 days’ written notice.
Either party may terminate an SOW immediately by written notice if the other party commits a material breach that cannot reasonably be remedied, or commits a remediable material breach and fails to remedy it within 14 days after written notice. Termination rights relating to insolvency apply subject to applicable insolvency law.
37. Consequences of termination and handover
On termination, amounts already due remain payable and the Client will pay for properly completed work and non-cancellable third-party commitments incurred in accordance with the Agreement up to the effective termination date.
Subject to payment of undisputed amounts due, we will provide a reasonable handover of final Client-owned Deliverables and access or credentials that we control and are required to transfer. Extensive migration, reconstruction, export or transition assistance outside the agreed scope may be charged at an agreed rate.
Personal data will be returned or deleted in accordance with the Data Processing Schedule where applicable. Provisions intended by their nature to survive termination, including confidentiality, intellectual property, payment, data protection, indemnity, liability and dispute provisions, will survive.
38. Force majeure
Neither party is liable for delay or failure caused by circumstances beyond its reasonable control, which may include major internet or cloud outages, natural disasters, war, terrorism, civil disturbance, government action, widespread cyber incidents, industrial disputes or failure of critical infrastructure. This does not excuse payment obligations that had already fallen due.
39. Assignment
The Client may not assign or transfer the Agreement without our prior written consent, not to be unreasonably withheld. We may assign the Agreement as part of a genuine sale, merger, investment or restructuring of our business, provided this does not materially reduce the Client’s contractual protections.
40. Relationship of the parties
The parties are independent contractors. Nothing in the Agreement creates a partnership, employment relationship, fiduciary relationship, joint venture or general agency relationship. Neither party may bind the other except to the extent expressly authorised in writing.
41. Entire agreement and non-reliance
The Agreement contains the entire agreement between the parties concerning its subject matter and supersedes previous discussions, proposals and representations relating to that engagement, except for documents expressly incorporated into the Agreement.
Each party acknowledges that it has not relied on a statement that is not set out in the Agreement when entering into it. Nothing in this clause excludes liability for fraud or fraudulent misrepresentation.
42. Variation
A variation to the Agreement is effective only if agreed in writing by authorised representatives of both parties. Email is sufficient where it clearly records the agreed change.
43. Waiver and severability
A failure or delay in enforcing a right does not waive that right. If a provision is held invalid or unenforceable, it will be modified to the minimum extent necessary where possible, and the remaining provisions continue in effect.
44. Third-party rights
Unless the Agreement expressly states otherwise, a person who is not a party to the Agreement has no right to enforce any term of it under the Contracts (Rights of Third Parties) Act 1999.
45. Notices
Formal notices under the Agreement must be sent to the addresses or email contacts stated in the SOW or another address formally notified by a party. Email may be used unless the SOW expressly requires another method.
46. Dispute escalation
Before starting court proceedings, each party should, where reasonably practicable, refer a material dispute to a senior representative and attempt in good faith to resolve it. This does not prevent either party seeking urgent injunctive relief or taking steps necessary to preserve a legal right.
47. Governing law and jurisdiction
The Agreement and any non-contractual obligations arising from it are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction.
Schedule 1 - Data Processing Schedule
Applies where the Agency acts as processor for Client personal data
1. Application and definitions
This Schedule forms part of the Agreement where Build ALONG The Way, using the trading brand VJ Digital Growth Partner (“Processor” or “Agency”), processes personal data on behalf of the Client (“Controller”). Data-protection terms have the meanings given by applicable UK data-protection law.
Where the Agency independently determines the purposes and essential means of a processing activity, it acts as controller for that activity and this Schedule does not convert that activity into processor processing.
2. Processing details
| Item | Details |
|---|---|
| Subject matter | Processing required to provide the digital-growth, marketing, website, analytics, CRM, advertising, automation or related services described in the SOW. |
| Duration | For the duration of the relevant Services plus a limited period reasonably required for secure return, deletion, backup expiry, dispute handling or legal compliance. |
| Nature | Access, collection, organisation, analysis, storage, alteration, segmentation, transmission, retrieval, deletion and other processing necessary to deliver the Services. |
| Purpose | Providing the Services on the Client’s documented instructions. |
| Data subjects | Depending on scope: Client customers, prospects, leads, subscribers, website visitors, Client personnel and other individuals identified by the Client. |
| Personal data | Depending on scope: names, contact details, CRM data, enquiry data, website interaction data, marketing preferences, campaign data, identifiers, customer-status or transaction-related information and other data identified in the SOW. |
| Sensitive data | Not intended unless specifically identified and agreed in writing in advance. The Client must not provide special-category, criminal-offence, children’s or similarly sensitive information without prior written agreement. |
3. Documented instructions
The Agency will process Client personal data only on the Client’s documented instructions, including instructions in the Agreement, SOW, approved change requests and written operational directions, unless UK law requires otherwise.
If applicable law requires processing outside the Client’s instructions, we will inform the Client before processing unless the law prohibits us from doing so. We will tell the Client if, in our reasonable view, an instruction infringes applicable data-protection law.
4. Confidentiality
We will ensure that people authorised to process Client personal data are subject to appropriate confidentiality obligations.
5. Security
Taking account of the nature, scope, context and purposes of processing, available technology, implementation cost and risks to individuals, we will maintain appropriate technical and organisational measures designed to protect Client personal data.
Measures may include, where relevant to the processing and systems used, access controls, least-privilege access, multi-factor authentication, secure password management, encryption in transit, encryption at rest where appropriate, endpoint security, patching, backups, logging, secure deletion, confidentiality requirements, incident response and supplier-security controls.
The Client acknowledges that appropriate measures depend on the actual processing and that no system can be guaranteed absolutely secure.
6. Sub-processors
The Client gives general written authorisation for us to use suitable sub-processors where reasonably necessary to provide the Services. We will require each sub-processor that processes Client personal data to be bound by data-protection obligations offering an equivalent level of protection as required by applicable law.
We remain responsible to the Client for our obligations relating to sub-processor processing as required by law. A current list of material sub-processors will be available on request.
Where required, we will give reasonable notice before appointing a new material sub-processor that will process Client personal data. The Client may object on reasonable and documented data-protection grounds. The parties will work in good faith to identify a practical solution; if none is reasonably available, either party may terminate the affected processing service without penalty for the unperformed future portion of that service.
7. International transfers
We will not make a restricted transfer of Client personal data outside the United Kingdom unless an appropriate legal transfer mechanism applies. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses or another lawful safeguard.
The Client authorises restricted transfers carried out through approved sub-processors where the applicable safeguard is in place and the transfer is necessary for the Services.
8. Data-subject rights
Taking account of the nature of the processing, we will provide reasonable assistance through appropriate technical and organisational measures to help the Client respond to requests by individuals exercising their data-protection rights.
If we receive a request that relates solely to Client-controlled personal data, we will normally refer it to the Client and will not respond substantively unless instructed by the Client or legally required to do so.
9. Personal-data breaches
We will notify the Client without undue delay after becoming aware of a personal-data breach affecting Client personal data processed by us as processor. As information becomes available, we will provide reasonable details necessary to assist the Client with its legal assessment and notification obligations.
Notification of an incident is not an admission of fault or liability.
10. Compliance assistance
Taking account of the nature of processing and information available to us, we will provide reasonable assistance with the Client’s obligations relating to security, breach assessment and notification, data-protection impact assessments and prior consultation with the ICO where required.
Substantial assistance outside the ordinary scope of the Services may be charged at an agreed reasonable rate unless the assistance is required because of our own breach of this Schedule.
11. Records and information
We will maintain records required of us by applicable data-protection law and will make available information reasonably necessary to demonstrate compliance with the processor obligations that apply to us.
12. Audits and inspections
We will allow for and contribute to audits and inspections required by applicable law. Unless there is a serious incident, regulator requirement or reasonable evidence of material non-compliance, an audit must be requested on reasonable written notice, occur no more than once in a 12-month period, take place during normal business hours, minimise disruption and protect other clients’ confidential information.
The Client will normally bear its own audit costs and our reasonable costs of supporting an exceptional or extensive audit, unless the audit identifies a material breach by us.
13. Return and deletion
At the end of the relevant Services, at the Client’s choice and subject to applicable law, we will return or delete Client personal data that we process as processor and will delete remaining copies within a reasonable period.
This does not require immediate deletion from encrypted or immutable backups where individual deletion is impracticable, provided the backup data remains protected, is not restored for ordinary business use and is deleted or overwritten through the normal backup lifecycle. We may retain information where UK law requires retention.
14. Client responsibilities
The Client is responsible for the lawfulness of its instructions and warrants that it has an appropriate lawful basis for relevant processing; has provided required privacy information; has lawfully collected and disclosed personal data to us; and will not instruct us to process unnecessary sensitive information without prior agreement.
15. Costs
Ordinary compliance assistance reasonably required for the agreed processing is included in the Services. Exceptional assistance, bespoke security questionnaires, audits, migration work or legal-review support beyond the agreed scope may be charged where reasonable and agreed, except to the extent required because of our breach.
16. Liability and conflict
Liability arising under this Schedule is subject to the liability provisions in the Client Terms of Business except to the extent applicable law prevents a particular limitation. If this Schedule conflicts with another part of the Agreement on processor obligations, this Schedule prevails for that matter.