Ventrix IT

Terms & Conditions

THIS AGREEMENT is effective as of the date set forth in the Order Form.

PARTIES:

  • VENTRIX IT LIMITED (“VENTRIX”)
  • The individual, firm, or company named in the Order Form (the “Customer”).

1. Definitions and Interpretation.

  • Abnormal Hours: Support provided outside Service Hours.
  • Authorised Representative: A person authorised in writing to bind the relevant party under this Agreement.
  • Charges: All fees, expenses and amounts payable by Customer under this Agreement and the Service Schedules.
  • Commencement Date: The date the Customer accepts the Order Form or as otherwise stated in the Order Form.
  • Confidential Information: Information of a confidential nature disclosed by a party (including business, financial, technical, security and Personal Data), whether disclosed before or after the Commencement Date.
  • Contract/Agreement: These Terms & Conditions, the Order Form(s), and all Service Schedules and their appendices.
  • Customer Data: Data (including Personal Data) provided by or on behalf of Customer or generated for Customer in providing the Services.
  • Data Protection Laws: UK GDPR, Data Protection Act 2018, PECR and any amending or successor laws.
  • Delivery: Delivery or availability of Goods or Services as notified by VENTRIX IT (including deemed delivery for remote/virtual items).
  • Equipment: Hardware specified in the Order Form or Service Schedule.
  • Force Majeure Event: As defined in clause 14.
  • Goods: Hardware, third‑party software or other items set out in an Order Form or Service Schedule.
  • Initial Term: The initial period stated in the Order Form for the relevant Service(s).
  • Intellectual Property Rights (IPR): All intellectual property rights including copyright, database rights, patents, trademarks, trade secrets and related rights.
  • Order Form: The ordering document executed by the parties referencing these Terms & Conditions.
  • Personal Data / Controller / Processor / Data Subject: As defined in Data Protection Laws.
  • Renewal Term: As defined in clause 12.1.
  • Service Hours: Monday–Friday 08:00–18:00 UK time (excluding UK public holidays) unless otherwise stated in the Order Form.
  • Service Schedule: A schedule describing a particular service (e.g., Service Desk Agreement, Security Services, BCDR, Cloud/Domain/Telecoms/Broadband, Network Monitoring, etc.).
  • Support Services: Services described in the Service Desk Agreement and applicable Service Schedules.
  • Tariff: VENTRIX IT’s then‑current pricing for usage‑based charges and add‑ons (e.g., call rates, storage) notified to Customer or published by VENTRIX IT.
  • Term: Initial Term plus any Renewal Terms.

1.2 Interpretation. Headings are for convenience only and do not affect interpretation. Words in the singular include the plural and vice versa. “Including” means “including, without limitation”.

1.3 Order of precedence. In case of conflict, the following order applies: (a) the Order Form; (b) the relevant Service Schedule for the applicable service; (c) these Terms & Conditions. Where a Service Schedule contains a service‑specific limitation or cap of liability, that service‑specific provision prevails for claims arising from that service.

1.4 No reliance. Each party acknowledges it has not relied on any statement not set out in the Agreement (save for fraudulent misrepresentation).

2. Orders, Delivery and Acceptance

2.1 Quotations are valid for the period stated in the Order Form or, if not stated, for 10 business days from issue.

2.2 Orders placed by Customer are offers to purchase. Orders become binding when accepted by VENTRIX IT in writing. Customer is responsible for verifying accuracy of order details.

2.3 Substitution. VENTRIX IT may provide alternative Goods/Services of equivalent functionality and performance, acting reasonably and with prior notice where practicable.

2.4 Delivery dates are estimates only. VENTRIX IT is not liable for delays caused by third parties or events outside its reasonable control.

2.5 Refused Delivery. If Customer refuses Delivery without prior written agreement, VENTRIX IT may store Goods at Customer’s cost (including insurance) or terminate and resell the Goods and recover associated losses.

2.6 Acceptance/Deemed Acceptance. Deliverables will be deemed accepted on the earlier of: (a) Customer’s written acceptance; (b) Customer’s first productive use; or (c) 10 business days after Delivery if no written rejection with reasonable detail is provided.

3. Goods and Services

3.1 Scope is as set out in the Order Form and applicable Service Schedules. Changes must be agreed in writing via a change order.

3.2 Cancellation after acceptance may incur the agreed Cancellation Fee at the discretion of VENTRIX IT.

3.3 Title and Risk. Title in Goods passes on full cleared payment; risk passes on Delivery. Customer will maintain adequate insurance while risk resides with Customer.

3.4 Site Preparation & Access. Customer will prepare the Site per VENTRIX IT’s reasonable instructions and provide access, safety inductions, and necessary facilities.

3.5 Maintenance Services are provided as set out in the Service Schedule.

3.6 Aborted Visits. If an engineer is denied access or turned away, VENTRIX IT may charge for the aborted visit at the applicable rate.

3.7 Expenses. Reasonable out‑of‑pocket expenses (e.g., travel, parking, accommodation) are chargeable where agreed in the Order Form or Tariff.

4. Charges, Price Adjustments and Changes

4.1 Travel & Expenses. On‑site visits may incur mileage (e.g., £0.45 + VAT per mile) and reasonable expenses per the Order Form/Tariff.

4.2 Service Changes / Improvements. VENTRIX IT may modify or enhance Services. Material changes will be notified at least 30 days in advance. If a change has a material adverse effect, Customer may object in writing. The parties will discuss in good faith; if unresolved, Customer may terminate the affected service on 14 days’ notice without early termination fees.

4.3 Changes to ThirdParty Terms VENTRIX IT shall not be liable for any changes to services, pricing, features, functionality or availability arising from modifications made by third‑party suppliers, licensors or carriers. Where such changes materially affect the Services, VENTRIX IT will notify the Customer and may reasonably modify the affected Services or Charges to reflect the updated third‑party terms.

4.4 Annual Indexation. Charges may be adjusted annually in line with CPI plus up to 5%, with 30 days’ written notice. If an increase exceeds CPI + 5%, Customer may object within 14 days; if unresolved, either party may terminate the affected service on 14 days’ notice with no penalty.

4.5 Customercaused Costs. Where Customer’s acts/omissions cause additional costs (e.g., delays, incomplete instructions, access failures, incorrect information), VENTRIX IT may adjust Charges on written notice.

4.6 Document Errors. Typographical/clerical errors may be corrected without liability.

4.7 Change Control. Scope changes will be documented in a change order specifying impact on Charges, timelines and dependencies.

5. Equipment (including Loans/Rentals)

5.1 Disposal undertaken by VENTRIX IT applies only to Equipment owned or leased by VENTRIX IT; such items will be securely erased with no backups retained.
5.2 Loan/Rental Equipment remains VENTRIX IT property; Customer is responsible for loss or damage and must maintain insurance at full reinstatement value against all risks.
5.3 Return. Loaned Equipment must be returned to VENTRIX IT’s registered office within 15 business days of termination at Customer’s expense; failure to do so may incur replacement/repair costs and rental fees up to return.
5.4 Quality & Wear. Customer will not modify Equipment and will return it in good condition (fair wear and tear excepted). Restocking or refurbishment fees may apply where condition standards are not met.

6. Customer Responsibilities

6.1 The Customer shall cooperate fully with VENTRIX in all matters relating to the provision of Support Services. Upon VENTRIX’s request, the Customer will designate a project manager with the authority to make decisions on the Customer’s behalf regarding Support Services.

6.2 The Customer shall provide VENTRIX with access to the Site, necessary equipment, data, and other facilities as reasonably required for the provision of Support Services.

6.3 VENTRIX IT’s ability to meet service levels and timelines is dependent on timely Customer cooperation, access, approvals and third‑party coordination. Delays caused by Customer dependency failures shall not constitute a breach of this Agreement.

6.4 The Customer agrees to supply any information reasonably requested by VENTRIX and warrants that all such information will be accurate and complete in all material respects.

6.5 The Customer shall comply with any operational or technical requirements outlined by VENTRIX before Support Services are delivered.

6.6 Should the Customer request a change to the scope or delivery of Support Services, VENTRIX will only be obligated to accommodate such changes upon mutual written agreement. This agreement will include adjustments to Charges, timelines, and any relevant terms. If VENTRIX requests a change, the Customer shall not unreasonably withhold or delay consent.

6.7 Where the Customer declines, delays or limits any security, resilience, backup or compliance recommendation made by VENTRIX IT, the Customer acknowledges that such decision increases risk and accepts full responsibility for the resulting consequences. VENTRIX IT shall have no liability for incidents arising from such declined or restricted measures.

6.8 VENTRIX shall not be held responsible for any issues resulting from the Customer’s failure to implement VENTRIX’s recommendations.

6.9 The Customer shall:

6.9.1 Ensure that the Equipment is used and maintained responsibly and in accordance with the manufacturer’s operational guidelines.

6.9.2 Use only materials and supplies approved by VENTRIX for the Equipment’s operation and maintenance.

6.9.3 Ensure that only VENTRIX or its authorized agents conduct repairs, maintenance, or adjustments on the Equipment.

6.9.4 Promptly notify VENTRIX of any material faults or operational defects once they are identified.

6.9.5 Maintain the Equipment in accordance with environmental conditions recommended by the original manufacturer.

6.9.6 Ensure the Equipment is operated only by competent personnel employed or supervised by the Customer.

6.10 Should VENTRIX be required to perform Services due to the Customer’s failure to comply with the responsibilities outlined in this clause, the Services will be charged at VENTRIX’s standard rates, including the cost of any necessary parts.

7. Warranties and Remedies

7.1 Services. VENTRIX IT warrants that Services will be performed with reasonable skill and care.

7.2 Goods. Goods are provided subject to applicable manufacturer warranties. Customer’s remedies are as per manufacturer terms.

7.3 Service Remedies. For breach of the warranty in 7.1, VENTRIX IT will, at its option, re‑perform the affected Services, provide a reasonable workaround, or refund the portion of Charges paid for the non‑conforming Services.

7.4 Exclusions. Except as expressly stated, all other warranties (express or implied) are excluded to the extent permitted by law. VENTRIX IT does not warrant uninterrupted or error‑free operation.

7.5 Future Compatibility. VENTRIX IT does not guarantee that Services will remain compatible with future technologies, standards, regulations or vendor frameworks unless expressly agreed

7.6 No Professional Advice. Any information, recommendations or guidance provided by VENTRIX IT are technical in nature only and do not constitute legal, financial, regulatory or insurance advice. The Customer remains responsible for obtaining independent professional advice where required.

7.7 Customercaused Issues. VENTRIX IT is not responsible for defects arising from misuse, unauthorised modifications, or operation contrary to manufacturer/VENTRIX IT instructions.

8. Payment Terms

8.1 Payment Period. Net 30 days from invoice unless otherwise stated in the Order Form.

8.2 No Set‑off. Payments are made without set‑off, deduction or counterclaim, save as required by law.

8.3 Application of Funds. VENTRIX IT may apply amounts due from Customer against amounts VENTRIX IT owes to Customer.

8.4 Short‑Term Contracts. If the Term is 3 months or less, fees are payable in equal monthly instalments during the term (for a one‑month term, the total is due on or before the Commencement Date).

8.5 Method. Payments must be made as stated on the invoice; default method is Direct Debit unless agreed otherwise. Administrative fees may apply if Direct Debit is cancelled without agreement.

8.6 Late Payment. Without prejudice to other rights, VENTRIX IT may: (a) charge interest under the Late Payment of Commercial Debts (Interest) Act 1998; (b) apply a late payment fee of up to £60 + VAT per incident; (c) suspend Services (in whole or part) upon written notice; and/or (d) terminate under clause 12 if non‑payment persists.

8.7 Prepayment & Credit. For purchases exceeding £250 + VAT, VENTRIX IT may require prepayment. A standard credit limit of £1,000 + VAT applies unless agreed otherwise in writing. VENTRIX IT may revise or withdraw credit at its discretion.

8.8 Acceleration. On material breach or insolvency, VENTRIX IT may declare all accrued Charges immediately due and payable.

8.9 Non‑Refundable Set‑up Fees. One‑time set‑up and onboarding fees are non‑refundable unless otherwise agreed.

9. Limitation of Liability

9.1 Non‑excludable liabilities. VENTRIX IT does not limit or exclude liability for: (a) death or personal injury caused by its negligence; (b) fraud or fraudulent misrepresentation; (c) breach of title warranties implied by section 12 Sale of Goods Act 1979 and section 2 Supply of Goods and Services Act 1982; or (d) any other liability which cannot lawfully be limited or excluded.

9.2 Aggregate cap (general). Subject to clause 9.1 and except where a Service Schedule states a different cap for a specific service, VENTRIX IT’s total aggregate liability arising out of or in connection with the Agreement (whether in contract, tort (including negligence), breach of statutory duty or otherwise) shall not exceed the total Charges paid or payable in the 12 months immediately preceding the event giving rise to the claim.

9.3 Service‑specific caps prevail. If a Service Schedule (e.g., the Service Desk Agreement) specifies a different cap (e.g., equal to one month of fees for that service), that service‑specific cap prevails for claims relating to that service.

9.4 Excluded heads of loss. Subject to clause 9.1 and to the extent permitted by law, VENTRIX IT shall not be liable for: (a) loss of business, sales, revenue, profits, contracts or anticipated savings; (b) loss of or damage to reputation or goodwill; (c) loss or corruption of data, software or information; (d) any indirect, special or consequential loss; whether or not foreseeable or advised.

9.5 Data & Security. Customer remains responsible for appropriate backups and security unless expressly agreed in writing. Nothing in this Agreement excludes liability to the extent doing so would contravene Data Protection Laws.

9.6 Notification. Customer must notify VENTRIX IT in writing of any claim within 28 days of becoming aware; VENTRIX IT will have 90 days to attempt resolution.

9.7 Severability of limitations. If any limitation/exclusion is found invalid, it shall be deemed severed to the minimum extent necessary without affecting the remaining limitations.

9.8 Cybersecurity Disclaimer. The Customer acknowledges that, despite the implementation of cybersecurity services, controls and best practices, no information technology environment is completely secure, and VENTRIX IT does not warrant or guarantee the prevention of all cyberattacks, security breaches, data loss events, or unauthorised access incidents.

9.8.1 VENTRIX IT shall not be responsible for, nor held liable for, any cyber incident, breach, malware infection, ransomware attack, data compromise or unauthorised access where such incident arises from:

(a) Sophisticated or previously unknown threats, including zero‑day vulnerabilities;

(b) Acts or omissions of the Customer or its users, including failure to follow security advice, poor password practices, or social engineering;

(c) Third‑party software, services, platforms, networks or vendors not under the direct control of VENTRIX IT;

(d) Customer decisions to decline, delay or limit recommended security measures.

9.8.2 Cybersecurity services are provided on a risk‑mitigation and best‑endeavours basis only, and the Customer retains ultimate responsibility for the security, integrity and lawful processing of its systems and data, subject always to applicable law.

9.8.3 Any liability of VENTRIX IT arising from security services shall be subject to the limitations and financial caps set out in this Agreement, and VENTRIX IT shall not be liable for any indirect, consequential, business interruption, reputational or loss‑of‑profits damages arising from any cyber incident

10. Data Protection and Data Processing (Article 28 UK GDPR)

10.1 Roles. For processing of Personal Data by VENTRIX IT on behalf of Customer, Customer is Controller and VENTRIX IT is Processor.

10.2 Subject matter & duration. Processing relates to provision of the Services for the Term and any reasonable post‑termination return/erasure window.

10.3 Nature & purpose. Hosting, storage, transmission, support, monitoring, configuration, security and continuity services, as described in the Service Schedules.

10.4 Types of Personal Data & data subjects. Customer employee/contractor/user contact data, authentication data, device identifiers, logs; data subjects include Customer’s personnel and users.

10.5 Documented instructions. VENTRIX IT shall process Personal Data only on documented instructions from Customer, unless required by law (in which case VENTRIX IT will, where lawful, inform Customer).

10.6 Security measures. VENTRIX IT will implement appropriate technical and organisational measures commensurate with risk, including role‑based access controls, encryption (where applicable), logging/monitoring, vulnerability management, and staff confidentiality.

10.7 Personnel. VENTRIX IT ensures personnel authorised to process Personal Data are subject to confidentiality obligations and appropriate training.

10.8 Sub‑processors. Customer authorises VENTRIX IT to appoint sub‑processors. VENTRIX IT will: (a) maintain a list of sub‑processors available on request; (b) impose data protection obligations no less protective than this clause; and (c) notify Customer in advance of material changes (Customer may object on reasonable grounds; the parties will discuss in good faith; if unresolved, Customer may terminate only the affected service).

10.9 International transfers. VENTRIX IT will not transfer Personal Data outside the UK/EEA unless a lawful transfer mechanism is in place (e.g., adequacy, IDTA/Addendum).

10.10 Assistance. Taking into account the nature of processing, VENTRIX IT will assist Customer with data subject requests, security, DPIAs and consultations with the ICO, on reasonable request and at Customer’s cost where disproportionate.

10.11 Breach notification. VENTRIX IT will notify Customer without undue delay upon becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.12 Return/Deletion. Upon termination, VENTRIX IT will, at Customer’s written choice, return or securely delete Personal Data, unless retention is required by law (in which case data will be protected and deleted after the retention period).

10.13 Records & audits. VENTRIX IT will maintain records of processing activities and, upon reasonable prior notice, make available information necessary to demonstrate compliance and allow audits by Customer or a mandated auditor once per 12 months (or more if required by law). Audits shall minimise disruption and protect security/confidentiality; auditors shall sign appropriate NDAs.

10.14 Changes in law. Either party may propose amendments to ensure ongoing compliance; both parties will act reasonably and in good faith.

11. Restrictions (Non‑Solicitation)

11.1 During the Term and for 12 months thereafter, Customer shall not directly or indirectly solicit or employ any VENTRIX IT employee or contractor materially involved in providing the Services.

11.2 If Customer breaches 11.1, it shall pay liquidated damages equal to 50% of the individual’s annual remuneration (or contract value) as a genuine pre‑estimate of loss, without prejudice to other remedies. General, non‑targeted recruitment (e.g., public adverts) is excluded.

12. Term and Termination

12.1 Term and Renewal. This Agreement commences on the Commencement Date and continues for the Initial Term. Thereafter, it renews automatically for successive periods equal to the Initial Term unless either party gives not less than 90 days’ written notice of non renewal prior to the end of the then current term.

12.2 Non Payment. VENTRIX IT may suspend Services and/or terminate this Agreement with immediate effect if Customer fails to pay any amount due within 14 days after receipt of a written demand.

12.3 Suspension for Risk. VENTRIX IT may suspend any Service immediately where continued provision would expose VENTRIX IT to legal, regulatory, security or reputational risk, including but not limited to misuse of services, suspected unlawful activity, or material breaches of the Acceptable Use Policy. Suspension under this clause shall not give rise to any refund or liability.

12.4 Material Breach / Insolvency.

12.4.1 Either party may terminate by written notice if the other commits a material breach which, if capable of remedy, is not remedied within 30 days after written notice describing the breach in reasonable detail.

12.4.2 Either party may terminate immediately on written notice if the other becomes insolvent, has an administrator or receiver appointed, enters into an arrangement with creditors, or suffers any analogous event.

12.5 Effect of Termination. On termination: (a) all accrued Charges become immediately due; (b) VENTRIX IT will, on request and subject to prior settlement of all outstanding Charges, make available Customer Data held by VENTRIX IT in a commonly used format; and (c) any transition assistance is chargeable at VENTRIX IT’s standard rates unless otherwise agreed in writing.

12.6 Obsolete Technology. VENTRIX IT may discontinue support for obsolete equipment or software on reasonable written notice; where this affects prepaid Services, VENTRIX IT will provide a pro rata refund of unused fees for the affected Services.

12.7 Survival. Clauses intended by their nature to survive (including Payment, Confidentiality, Intellectual Property, Data Protection, Liability, AUP/Enforcement, and Survival) continue after termination or expiry.

12.8 Offboarding and Transition Assistance.

12.8.1 Upon termination, expiry, or non-renewal of any Service, VENTRIX IT will provide reasonable offboarding and transition assistance in accordance with its standard offboarding procedures, a copy of which is available upon request.

12.8.2 Offboarding services include, but are not limited to, the removal of monitoring tools, transfer of administrative access, coordination with incoming providers, data transfer (where applicable), and decommissioning of services.

12.8.3 All offboarding and transition services shall be chargeable on a time and materials basis at VENTRIX IT’s then-current standard professional services rates, unless otherwise agreed in writing.

12.8.4 A minimum charge equivalent to one (1) working day shall apply to any offboarding request, regardless of scope.

12.8.5 VENTRIX IT will, where reasonably practicable, provide the Customer with an estimated level of effort prior to commencing offboarding work. Any estimate is indicative only and not a fixed quotation.

12.8.6 Where the Customer requests partial offboarding (including the termination of specific services only), the same charging structure shall apply.

12.8.7 VENTRIX IT shall not be responsible for delays or issues arising from third-party providers, incomplete instructions, or lack of cooperation from the Customer or its representatives during the offboarding process.

12.8.8 Offboarding services shall not commence until all undisputed outstanding Charges have been paid or suitable payment arrangements have been agreed.

12.8.9 VENTRIX IT reserves the right to prioritise active Customers over offboarding activities where resource constraints exist.

13. Intellectual Property Rights

13.1 Ownership. All IPR in materials, software, configurations, documentation and tools supplied by VENTRIX IT remain the property of VENTRIX IT or its licensors, unless expressly transferred in writing.

13.2 Licence to Deliverables. Subject to payment of Charges, VENTRIX IT grants Customer a non‑exclusive, non‑transferable licence to use deliverables internally for the Term and any agreed extension for the relevant Service.

13.3 Residuals & Tools. VENTRIX IT may use its general knowledge, skills and experience developed while providing the Services (“residuals”), and retains ownership of its templates, scripts, methodologies, and tools.

13.4 Customer Materials. Customer grants VENTRIX IT a limited licence to use Customer’s materials, logos and systems access solely to perform the Services.

13.5 Marketing Reference. The Customer permits VENTRIX IT to list the Customer’s name and logo as a client reference, unless the Customer objects in writing.

14. Force Majeure

14.1 Neither party is liable for delay or failure due to a Force Majeure Event beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, industrial action, utility/telecom failures, and compliance with law.

14.1.2 Force Majeure Events include widespread cyber incidents, supply chain disruptions, upstream provider outages, or government‑mandated service restrictions beyond the reasonable control of the affected party.

14.2 Force Majeure includes significant cyber events or upstream provider outages impacting service delivery where not caused by the affected party’s negligence or wilful misconduct.

14.3 If a Force Majeure Event continues for more than 90 days, either party may terminate the affected Services on written notice.

14.4 Payment obligations for Services already provided are not excused.

15. Assignment

15.1 VENTRIX IT may assign, sub‑contract or transfer its rights or obligations without Customer consent, including to Group companies or in connection with a merger, acquisition or sale of business.

15.2 Customer may not assign, sub‑contract or transfer its rights or obligations without VENTRIX IT’s prior written consent (not to be unreasonably withheld).

16. Notices

16.1 Notices must be in writing and delivered by: (a) first‑class post to the registered address; or (b) email to the Authorised Representative’s email address stated in the Order Form (with delivery/read receipt if available).

16.2 Deemed receipt: (a) post 48 hours after posting; (b) email on successful delivery confirmation or, if unavailable, 24 hours after sending absent a bounce‑back.

16.3 Either party may update notice details by written notice.

16.4 Operational communications (e.g., tickets/changes) may be delivered via VENTRIX IT’s support portal or email; legal notices must follow 16.1.

17. Severability

If any provision is held invalid, illegal or unenforceable by a court, it shall be severed to the minimum extent necessary, and the remainder shall continue in full force and effect.

18. Waiver

No failure or delay exercising any right or remedy constitutes a waiver. A waiver is effective only if in writing and signed by the waiving party and applies only to the circumstances for which it is given.

19. Entire Agreement

This Agreement (including the Order Form and all Service Schedules and appendices) constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior proposals, understandings and communications, except in the case of fraudulent misrepresentation.

20. Third‑Party Rights

No third party shall have rights to enforce any term of this Agreement under the Contracts (Rights of Third Parties) Act 1999.

21. Confidentiality

21.1 Each party will protect the other’s Confidential Information using at least the same degree of care it uses for its own, and not less than reasonable care.

21.2 Confidential Information may be disclosed to employees, contractors and advisers who need to know it for the purposes of this Agreement and who are under confidentiality obligations.

21.3 Exceptions: information that is (a) public other than due to breach; (b) received lawfully from a third party without confidentiality obligations; (c) independently developed without use of the disclosing party’s information; or (d) required to be disclosed by law or regulator, provided (where lawful) prompt notice is given to allow protective steps.

21.4 On request, each party will return or destroy Confidential Information, except where retention is required by law or reasonable back‑ups (in which case the information will be protected and destroyed per retention policies).

21.5 Nothing prevents VENTRIX IT from using residual knowledge/know‑how (without disclosing Customer Confidential Information) gained in the ordinary course of providing the Services.

22. No Partnership

Nothing in this Agreement creates a partnership, joint venture or agency relationship. Neither party may bind the other.

23. Governing Law and Jurisdiction

This Agreement is governed by and construed in accordance with the laws of England and Wales. The parties submit to the non‑exclusive jurisdiction of the courts of England and Wales.

24. Survival

Clauses relating to Charges and Payment, Confidentiality, Intellectual Property, Data Protection, Liability, AUP Enforcement, and Survival shall survive termination or expiry, together with any other provisions which by their nature are intended to survive.

SCHEDULE A – SERVICE DESK AGREEMENT (SDA)

A1. Scope & Coverage

A1.1 VENTRIX IT provides remote Service Desk Support during Service Hours for covered devices and users listed in the asset/register associated with the Order Form.

A1.2 Work outside Service Hours, project work, consultancy and training are excluded unless expressly stated.

A2. Service Levels

A2.1 Response Time: SLA targeted response time during Service Hours.

A2.2 Exclusions: Professional Services, project‑based tasks, planned changes, out‑of‑hours work (unless purchased), and failures caused by Customer non‑compliance with AUP/Security Best Practices.

A2.3 Remedy: Failure to meet targets does not constitute breach where due to exclusions. If VENTRIX IT offers service credits (if any), such credits are the sole remedy for SLA shortfalls for SDA.

A2.4 Service Credits: Where service credits are provided, they shall constitute the Customer’s sole and exclusive remedy for service level failures, and shall not give rise to termination or additional liability.

A3. Incident Handling

A3.1 Remote support via email/phone/remote tools; on‑site dispatch if remote resolution is not feasible and included in the Order Form.

A3.2 VENTRIX IT will make reasonable attempts to contact users; repeated unavailability may incur administrative charges.

A4. Best/Reasonable Endeavours

A4.1 Support for mainstream Microsoft and common third‑party apps is provided on a reasonable endeavour’s basis (not a guarantee of resolution).

A5. Exclusions (consolidated)

A5.1 Enhancements/upgrades/software additions, end‑user training, hardware parts, unlicensed software, environments below minimum standards, third‑party changes without VENTRIX IT approval, and incidents from cyberattacks where Customer declined recommended controls.

A6. SDA Liability Cap

A6.1 For claims arising solely from SDA Services, VENTRIX IT’s aggregate liability is capped at an amount equal to one month of SDA fees for the affected service (this cap prevails for SDA claims per clause 9.3).

 

SCHEDULE B – SECURITY SERVICES

B1. Shared Responsibility

B1.1 VENTRIX IT mitigates risk through controls; Customer retains responsibility for policy, user behaviour, approvals and backups unless otherwise agreed.

B1.2 The Customer acknowledges that cybersecurity services reduce risk but do not eliminate it. While VENTRIX IT applies recognised industry standards and security best practices, it does not guarantee that security incidents, attacks, or data breaches will not occur. The Customer remains responsible for governance, user behaviour, data classification, and business risk decisions.

B2. Third‑Party Solutions & Best Practices

B2.1 VENTRIX IT may substitute third‑party solutions with comparable alternatives, covering its internal migration efforts; third‑party/provider fees remain Customer’s responsibility.

B2.2 VENTRIX IT’s Best Practices may be updated with reasonable notice; urgent security updates may be implemented promptly with post‑notification.

 B3. Restart Windows

B3.1 Default restart window is 22:00 Saturday–22:00 Sunday. Custom windows can be requested and may affect delivery.

B4. Security Services Menu (illustrative)

B4.1 Security Assessments (annual baseline; additional on request).

B4.2 Password Policy Enforcement on Windows domains (third‑party apps excluded unless agreed).

B4.3 Baseline GPO Security management and updates.

B4.4 Automated Microsoft Patching (devices must be powered and connected).

B4.5 Third‑party patching for common apps where supported (line‑of‑business apps excluded unless agreed).

B4.6 24/7 Endpoint Security Monitoring; severity‑based response.

B4.7 DNS Filtering, Anti‑Virus/EDR, SPAM Filtering via third parties.

B4.8 Firewall/UTM configuration and leasing options.

B4.9 Phishing Testing & Training (reports to designated IT contact).

B4.10 Security Log Management (retention up to three months unless otherwise agreed).

B4.11 Dark Web Monitoring, Automated Port Monitoring.

B4.12 Device Password Rotation for core network devices (up to three devices per cycle, semi‑annually).

B4.13 Application Control, Email Authentication (SPF/DMARC) tuning, Secured VPN, Web Content Filtering.

B4.14 MFA, Firmware Security Patching, Device Encryption, Device Tracking & Remote Wipe, Email Encryption.

B4.15 Password Manager, MDM/MAM, Secure Software Bundles, Cyber Security Stack (per‑endpoint pricing; opting out of components does not reduce bundled price where a stack price applies).

B5. Incident Response (Reference)

B5.1 On suspected security incidents: notify VENTRIX IT; VENTRIX IT will triage, contain (with Customer approvals where appropriate), eradicate, recover and provide a summary. Time and materials may apply unless included in a retainer.


SCHEDULE C – BUSINESS CONTINUITY & BACKUP (BCDR)

C1. Definitions

Protected Data: Files, folders, servers or other data explicitly listed in the Order Form as in‑scope for backup and protection.

C2. Scope & Responsibilities

C2.1 VENTRIX IT backs up only Protected Data listed in the Order Form. Customer must notify VENTRIX IT promptly of scope/volume changes.

C2.2 Where monitoring is provided, VENTRIX IT checks backup completion and investigates failures per the applicable SLA.

C2.3 Customer is responsible for periodic DR testing and for informing VENTRIX IT of business changes impacting RTO/RPO.

C3. Solutions

C3.1 Air‑Gapped USB Backups (rotation schedule recommended; not auto‑monitored unless purchased; physical security is Customer’s responsibility).

C3.2 On‑Prem and Cloud Backup solutions (stable internet required for cloud; schedules pre‑configured; agent requirements apply).

C3.3 Business Disaster Recovery (BDR) solutions combining local and cloud protection with monitoring and reporting.

C3.4 Long‑Term Archiving (cloud storage; retrieval billed per data volume).

C3.5 Insurance Compliance Checks (technical only; not legal/financial advice).

C3.6 DR Planning & Testing (assistance available; chargeable unless included).

C3.7 Router/Switch Config Backups (retention up to 90 days).

C3.8 M365/Google Workspace/Cloud SaaS Backup via third parties; at least daily incremental where supported; coverage per provider capabilities.

C4. RTO/RPO & Restore Priority

C4.1 RTO and RPO targets are set in the Order Form; actual recovery times may vary with incident conditions.

C4.2 Restore priority will be agreed with Customer (e.g., critical systems first).


SCHEDULE D – CLOUD, DOMAIN, BROADBAND & NETWORK MONITORING SERVICES

D1. Cloud Services

D1.1 Provision of cloud infrastructure via third‑party providers; location selected based on availability and performance.

D1.2 Uptime: 99% monthly for network connectivity and power, excluding scheduled maintenance, Customer‑caused outages, and third‑party failures (including DoS).

D1.3 Customer responsibilities include sufficient bandwidth and notifying VENTRIX IT of service‑impacting changes.

D2. Domain Name Management

D2.1 DNS configuration, ownership updates, nameserver adjustments, and domain purchase/renewal for standard extensions.

D2.2 Additional fees may apply for DNS changes, transfers, and SSL certificates (not included unless purchased).

D3. Broadband Services

D3.1 Managed broadband includes circuit, router/modem rental (if applicable), static IP, 24/7 monitoring, and Service Desk Support.

D3.2 Performance depends on carrier infrastructure, congestion and local conditions.

D3.3 4G/Mobile Failover available; performance subject to mobile coverage; not advised for high‑bandwidth workloads.

D3.4 Redundant circuits can be provisioned for resilience; automatic failover supported where devices are configured accordingly.

D4. Network Device Monitoring

D4.1 Standard: 24/7 uptime monitoring and remote diagnostics for designated devices.

D4.2 Enhanced: Adds password management, firmware updates, automated configuration backups, and on‑site support when remote resolution fails.

D5. Ventrix IT Cloud Telephone System

D5.1 Service Overview. Hosted telephony using approved carrier infrastructure; includes system configuration, call routing, voicemail, extension management and monitoring. Call recording available where purchased with storage set out in the Order Form. Additional call channels may be purchased. Support is provided under the SDA.

D5.2 Call Charging & Tariff Policy.

D5.2.1 Bundled Minutes: Inclusive minutes are as set out in the Order Form; no implied minimum allocation.

D5.2.2 Pooled Minutes: Minutes are pooled across all extensions unless otherwise stated.

D5.2.3 Included Calls: Inbound calls and outbound calls to standard UK geographic and mobile numbers included in the purchased bundle.

D5.2.4 Overages: Invoiced monthly in arrears at VENTRIX IT’s prevailing Tariff; billed per underlying carrier increments.

D5.2.5 International/Premium/Special: Not included unless expressly stated; billed separately at Tariff and may include carrier surcharges.

D5.2.6 No Rollover: Unused minutes do not carry forward.

D5.2.7 Recording Storage Overages: Additional storage available at Tariff; failing upgrade, VENTRIX IT may apply deletion/archiving after notice.

D5.2.8 Carrier Pass‑Through: Carrier‑imposed charges, regulatory fees and tariff adjustments are passed through without markup unless otherwise agreed; VENTRIX IT is not responsible for carrier tariff changes.

D5.2.9 Fraud Controls: VENTRIX IT may temporarily restrict calling or apply spend limits if fraud/compromise/abnormal usage is suspected, notifying Customer where possible.

D5.2.10 Billing & Disputes: Usage and overages billed monthly in arrears; disputes within 14 days of invoice; late carrier data may appear on subsequent invoices.


SCHEDULE E – ACCEPTABLE USE POLICY (AUP)

E1. Purpose

To ensure lawful, safe and responsible use of Services and protect Customer systems, other users and the wider network.

E2. Prohibited Activities

Customer must not (and must ensure Users do not):

(a) use Services for unlawful, harmful, infringing, defamatory, harassing or discriminatory purposes;

(b) transmit malware, attempt unauthorised access, or conduct penetration testing/vulnerability scanning without VENTRIX IT’s written consent;

(c) send unsolicited bulk communications or spoof identities;

(d) use unlicensed or pirated software, bypass security controls, or disable monitoring/AV/EDR agents;

(e) interfere with network integrity or other users’ service;

(f) store or transmit material violating IPR or privacy rights.

E3. Security Obligations

Customer will:

(a) maintain unique user accounts and strong authentication (including MFA where provided);

(b) keep endpoints powered and connected during maintenance windows;

(c) implement vendor/VENTRIX IT‑recommended critical updates promptly;

(d) maintain software licence compliance;

(e) restrict admin privileges;

(f) report suspected incidents to VENTRIX IT without undue delay.

E4. Abuse Handling SLA

VENTRIX IT will acknowledge abuse/security notifications within 4 business hours during Service Hours and will work to mitigate material risks promptly based on severity and impact.

E5. Enforcement

VENTRIX IT may suspend or restrict Services to address security, legal or network‑integrity risks, providing notice where practicable. Repeated or material breaches may result in termination per clause 12. Charges may apply for remediation caused by Customer breaches.

Scroll to Top