These terms and conditions can be superseded by the following service terms and conditions:
1.1 These Terms and Conditions apply to the provision of services by InfoSec Governance Ltd, a company registered in England and Wales under company number 12289766 whose registered office is at 73 Duke Street, Darlington, County Durham, DL3 7SD (“Service Provider”, “we”, “us” or “our”), to the customer purchasing such services (“Customer”, “you” or “your”).
1.2 These Terms and Conditions apply to all services provided by the Service Provider including, but not limited to:
1.3 The Customer shall be deemed to have accepted these Terms and Conditions upon acceptance of a quotation, purchase order, statement of work, proposal or upon commencement of the Services, whichever occurs first.
1.4 These Terms and Conditions, together with any quotation, statement of work, service schedule or service-specific terms, constitute the entire agreement between the parties (“Contract”).
1.5 Where service-specific terms apply, including Cyber Essentials or Cyber Essentials Plus terms, those service-specific terms shall take precedence in the event of conflict.
1.6 The Customer acknowledges that it has not relied upon any representation, warranty, statement or promise not expressly set out within the Contract.
2.1 “Business Day” means any day other than a Saturday, Sunday or public holiday in England and Wales.
2.2 Headings are for convenience only and shall not affect interpretation.
2.3 Words importing the singular shall include the plural and vice versa.
3.1 The Service Provider shall perform the Services using reasonable care, skill and diligence.
3.2 The Service Provider may make changes to the Services where required to comply with applicable law, regulatory requirements, certification requirements or security best practice.
3.3 Any dates provided for performance of the Services are estimates only and time shall not be of the essence.
3.4 The Service Provider may utilise employees, contractors, associates or subcontractors in the delivery of the Services.
4.1 The Customer shall:
a) provide all information reasonably required for the performance of the Services;
b) ensure such information is accurate, complete and not misleading;
c) provide timely access to systems, personnel, premises, networks and documentation where required;
d) obtain all necessary permissions, licences and authorisations required for the Service Provider to perform the Services;
e) cooperate fully with the Service Provider.
4.2 The Service Provider may rely upon information supplied by the Customer and shall not be liable for any losses arising from inaccurate, incomplete or misleading information provided by the Customer.
4.3 The Customer remains solely responsible for the operation, management, maintenance and security of its information systems, infrastructure, software, devices, policies and procedures.
4.4 The Service Provider may suspend performance of the Services where the Customer fails to provide reasonable cooperation, access or information.
5.1 Fees shall be as specified within the quotation, statement of work or proposal.
5.2 Unless otherwise stated, Fees are exclusive of VAT and any applicable taxes.
5.3 The Service Provider shall be entitled to recover reasonable expenses incurred in the delivery of the Services including travel, accommodation, subsistence, third-party costs and materials.
5.4 Additional work requested by the Customer which falls outside the agreed scope shall be chargeable at the Service Provider’s prevailing rates.
6.1 The Service Provider may invoice:
a) upon completion of the Services;
b) upon commencement of the Services;
c) at agreed project milestones; or
d) on dates specified within the quotation.
6.2 Payment shall be due within thirty (30) days of the invoice date unless otherwise agreed in writing.
6.3 Time for payment shall be of the essence.
6.4 The Service Provider reserves the right to charge interest and compensation in accordance with the Late Payment of Commercial Debts (Interest) Act 1998.
6.5 All payments shall be made without deduction, withholding, counterclaim or set-off except where required by law.
6.6 The Service Provider may suspend Services or withhold certification, reports or deliverables where payment remains outstanding.
6.7 Any outstanding payment which is overdue and not collected, can be subject to external debt collection and additional fees.
7.1 Quotations remain valid for thirty (30) days unless withdrawn earlier.
7.2 Any amendment requested by the Customer may result in revised Fees and delivery timescales.
7.3 The Service Provider reserves the right to amend the scope, methodology or delivery of Services where necessary to comply with legal, regulatory, certification or security requirements.
8.1 Each party shall keep confidential all confidential information disclosed by the other party.
8.2 Neither party shall disclose confidential information to any third party except:
a) where required by law;
b) to professional advisers;
c) to employees, contractors or subcontractors who require access for performance of the Services.
8.3 Confidentiality obligations shall survive termination of the Contract for a period of five (5) years.
9.1 All intellectual property rights in methodologies, templates, tools, software, scripts, reports, working papers, training materials, documentation, processes and know-how developed, owned or used by the Service Provider shall remain vested in the Service Provider.
9.2 Upon payment of all Fees due, the Customer shall receive a non-exclusive, non-transferable licence to use deliverables supplied solely for its internal business purposes.
9.3 The Customer shall not reproduce, resell, distribute or commercially exploit deliverables without prior written consent.
10.1 The Customer acknowledges that no cyber security service can guarantee protection against cyber attack, ransomware, malware infection, unauthorised access, data breach, insider threat, denial of service attack or any other security incident.
10.2 The Services are designed to assist in identifying risks, improving security posture and supporting compliance requirements but do not guarantee the prevention of security incidents.
10.3 Recommendations and advice provided by the Service Provider are advisory in nature and implementation remains the responsibility of the Customer.
11.1 Where the Service Provider processes personal data on behalf of the Customer, the Customer shall be the data controller and the Service Provider shall act as data processor unless otherwise agreed in writing.
11.2 Both parties shall comply with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and any successor legislation.
11.3 The Service Provider shall implement appropriate technical and organisational measures to protect personal data.
11.4 Details regarding personal data processing are set out within the Service Provider’s Privacy Notice and Data Protection Policy.
12.1 Nothing in these Terms shall limit or exclude liability for:
a) death or personal injury caused by negligence;
b) fraud or fraudulent misrepresentation; or
c) any liability which cannot lawfully be excluded.
12.2 Subject to clause 12.1, the aggregate liability of the Service Provider arising from or in connection with the Contract shall not exceed the greater of:
a) the Fees paid under the Contract; or
b) £10,000.
12.3 The Service Provider shall not be liable for:
a) indirect or consequential losses;
b) loss of profits;
c) loss of revenue;
d) loss of business opportunity;
e) loss of contracts;
f) loss of goodwill or reputation;
g) loss of anticipated savings;
h) loss of data;
i) business interruption;
j) third-party claims.
12.4 The Service Provider shall not be liable for losses arising from:
a) inaccurate information supplied by the Customer;
b) the Customer’s failure to implement recommendations;
c) security incidents occurring before, during or after the Services;
d) misuse of any deliverables supplied.
13.1 The Service Provider may assign, subcontract or delegate any part of the Services.
13.2 The Customer may not assign or transfer its rights without prior written consent.
14.1 The Service Provider may terminate the Contract immediately where the Customer:
a) commits a material breach;
b) fails to pay any undisputed invoice when due;
c) becomes insolvent or enters administration, liquidation or similar proceedings.
14.2 Termination shall not affect accrued rights or obligations.
15.1 Neither party shall be liable for delay or failure resulting from circumstances beyond its reasonable control including:
15.2 If such circumstances continue for more than ninety (90) days either party may terminate the affected Services.
16.1 All notices shall be in writing and delivered by email, courier or recorded delivery.
16.2 Notices sent by email shall be deemed received on the next Business Day following transmission.
Failure or delay in exercising any right shall not constitute a waiver of that right.
If any provision is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
These Terms and Conditions shall be governed by and construed in accordance with the laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction to hear any dispute arising from or in connection with the Contract.
Last Updated: 14 July 2026 | Version 2.0