Supportwise Managed IT Services — Terms & Conditions
These Terms & Conditions govern the provision of managed IT support services by Supportwise IT Services Ltd, a company registered in England and Wales under company number 12306849, whose registered office is Site E, Nexus House, Lakeside Business Park, South Cerney, Gloucestershire, GL7 5XL (“Supportwise”, “We”, “Us”, “Our”). Our VAT registration number is GB 341 5501 34.
They apply together with the Proposal, Schedules and any Data Processing Agreement issued to you (together, the “Agreement”). Where a per-customer Managed IT Services Agreement is signed, that Agreement and its Schedules set out the specific Services, Service Levels and Charges; these Terms provide the standard clauses behind it. If there is any conflict, the signed Agreement prevails, followed by its Schedules, then these Terms; the Data Processing Agreement prevails over all of them on data-protection matters.
Schedule 1 (Services), Schedule 2 (Service Levels) and Schedule 3 (Charges) are issued with each customer’s signed Managed IT Services Agreement and set out the detail specific to that customer; they are not published on this page. A copy of the Schedules in force for You is available on request at any time.
1. Definitions and Interpretation
“Services” means the managed IT support services set out in the Proposal or Schedule 1. “Contract” / “Agreement” means the agreement for the purchase and sale of the Services. “Charges” means the fees set out in the Proposal or Schedule 3. “SLA” means the service levels in Schedule 2. “Supported Environment” has the meaning in clause 5. “You”/“Your” means the individual or organisation for whom We provide the Services (the “Client”). “Writing” includes electronic mail and comparable means of communication. Words defined in the Data Protection Legislation carry the same meaning here.
2. The Contract
2.1 Any Proposal is valid for 30 days from its date of issue and does not constitute an offer.
2.2 The Agreement begins when You confirm acceptance of Our Proposal and these Terms — including by electronic signature of a Managed IT Services Agreement — and We acknowledge that acceptance. It continues for the term stated in the Proposal or clause 8.
2.3 These Terms apply to the exclusion of any terms You seek to impose, and any implied by trade, custom, practice or course of dealing.
2.4 Any variation must be in writing and signed by an authorised representative of each party.
3. Description of Services
3.1 We shall provide the Services with reasonable skill and care, to the standard reasonably expected of a competent provider of managed IT support services.
3.2 We may make changes to the Services required to conform with any safety or statutory requirements.
3.3 We may allow others to provide the Services (in Our place or with Us) and remain responsible for their performance and Our obligations under the Agreement.
3.4 Additional services or variations will be agreed separately in writing, with costs agreed by both parties before the work commences.
4. Managed Services (IT Support)
4.1 We require administrator-level access to the systems We support at all times.
4.2 We provide telephone, online and (where the Services include it) on-site support. Standard hours are 09:00 to 17:00, Monday to Friday, excluding English public holidays. Support requested outside these hours, where agreed, is charged at £80 + VAT per hour.
4.3 We may install monitoring, remote-access and security software on Your devices as necessary to deliver the Services. Such software remains licensed to and owned by Us and will be removed or disabled on termination.
4.4 Requests for support may be made by email to support@supportwise.co.uk, by telephone on 0330 113 8949 (office hours), or via the support portal. You must state the ticket number when querying progress.
4.5 We retain the right to decide the appropriate course of action for each incident and whether support is delivered remotely or on-site. No guarantee is given as to the time required to resolve an incident, save for the targets in Schedule 2.
4.6 Support is provided on a labour-only basis. Replacement parts, hardware and software licences are invoiced separately. Support does not include recovery from vandalism, theft, break-in or misuse; such work is charged at Our prevailing rate, notified before it commences.
4.7 You are responsible for maintaining and proving appropriate licensing for all software on Your systems, except software installed by Us under clause 4.3.
5. Supported Environment
5.1 We support devices and operating systems that are currently supported by their manufacturer and correctly licensed for business use. Any device running an operating system that has reached end of life, or a consumer / Home edition not licensed for business use, falls outside the Supported Environment until upgraded.
5.2 Where a device falls outside the Supported Environment, We will advise You and agree any remedial steps or costs before proceeding. We are not liable for issues arising from devices outside the Supported Environment. This clause is deliberately drafted by reference to manufacturer support and licensing so that it remains current as products reach end of life.
6. Service Levels
6.1 We shall use reasonable endeavours to meet the response and resolution targets in Schedule 2, measured in working hours from the time a ticket is logged.
6.2 We shall provide a periodic service report covering ticket volumes, performance against the SLA, patch status and security posture, and maintain a clear escalation route with named contacts.
7. Client Responsibilities
7.1 You shall provide Us with the access, information and co-operation reasonably required to deliver the Services, including administrator-level access to the systems being supported.
7.2 You shall operate Your equipment properly and securely and ensure only competent, authorised persons use it.
7.3 We will not be liable for a failure to provide the Services where that failure results from You not providing reasonable access, information or co-operation, or from You acting against Our written recommendation.
7.4 You shall inform Us of any known significant data breach within the same timeline as applies to the ICO (within 24 hours of discovery), so that immediate action can be taken.
8. Term and Termination
8.1 Unless the Proposal states otherwise, the initial term is twelve (12) months from the commencement date, after which the Agreement continues on a rolling monthly basis unless either party gives notice under clause 8.2.
8.2 Either party may terminate by giving one (1) month’s written notice, to take effect at or after the end of the initial term. Termination on such notice is without penalty; You pay only for Services delivered up to the termination date.
8.3 Either party may terminate immediately on written notice if the other commits a material breach not remedied within 30 days of written notice, or becomes insolvent.
8.4 We may suspend or terminate the Services on written notice if You fail to pay an undisputed sum by its due date and do not remedy this within 14 days of a reminder.
9. Charges and Payment
9.1 The Charges are set out in the Proposal or Schedule 3. Prices on Our website are indicative only.
9.2 Support model. Depending on Your plan:
- All-inclusive per-user plans include unlimited remote support during standard hours within the flat per-user Charge, with no separate support billing.
- Management-fee plans carry a management fee of £2.50 + VAT per user per month, which includes a support allowance of 15 minutes per user per month; support beyond the allowance is charged at £60 + VAT per hour, billed in 15-minute blocks.
- Pay-as-you-go customers (those who do not take the management fee) are charged for all support at £60 + VAT per hour, billed in 15-minute blocks.
In every case, out-of-hours support agreed under clause 4.2 is charged at £80 + VAT per hour.
9.3 Invoices are billed monthly for active users and are payable within five (5) days of the invoice date by Direct Debit. Charges exclude VAT, which is added where applicable. Billing runs on the 1st of the month; changes take effect and first invoice on the 1st of the month following the change, without proration to the sign date.
9.4 We may increase the per-user Charges once in any 12-month period. Any increase is capped at £5 per user per month, notified in writing at least 30 days in advance, and normally in line with CPI. There are no other inflators within the term.
9.5 If an undisputed invoice is not paid by its due date We may suspend the Services, charge interest at 8% above the Bank of England base rate under the Late Payment of Commercial Debts (Interest) Act 1998, apply a reasonable administrative charge per reminder, and recover reasonable costs of recovery.
10. Administrative Access and Resilience
10.1 On onboarding We shall audit and document all administrative access (including Azure, Entra, Bitdefender and Microsoft 365) and every multi-factor authentication (MFA) arrangement, replacing undocumented knowledge held by any single individual with a maintained access register.
10.2 We shall register MFA to more than one authorised person, configure a secure break-glass administrator account, and provide You with a current overview of who holds what access, reviewed at agreed intervals, so that no single person’s absence can lock You out.
11. Data Protection
11.1 In providing the Services We act as a processor and You as controller. The parties shall comply with the Data Protection Agreement (Addendum A), which governs the processing of personal data.
11.2 Personal data is held within the UK or EEA, with UK data residency applied where the relevant service makes it available. We shall notify You of any personal data breach within 24 hours of becoming aware of it.
11.3 “Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018 and related laws, as amended from time to time.
12. Confidentiality
12.1 Each party shall keep the other’s confidential information strictly confidential and use it only to perform the Agreement, except as required by law. We shall not disclose Your confidential information without Your written permission.
12.2 We may state that You are a client of Supportwise for reference purposes only, disclosing no confidential information in doing so.
13. Insurance
13.1 We shall maintain, throughout the term, the following insurance cover and provide certificates on request:
- Public Liability — £2,000,000;
- Professional Indemnity — £1,000,000;
- Cyber — £250,000.
14. Liability
14.1 Nothing in the Agreement limits or excludes either party’s liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot be limited or excluded by law.
14.2 Subject to clause 14.1, Our total liability arising out of or in connection with the Agreement, whether in contract, tort (including negligence) or otherwise, is limited to £1,000,000 in aggregate for claims relating to professional negligence, and £250,000 in aggregate for claims relating to loss or corruption of data or cyber incidents.
14.3 For the avoidance of doubt, liability for loss or corruption of data caused by Our negligence is not excluded and is covered up to the limit in clause 14.2.
14.4 Subject to clauses 14.1 to 14.3, neither party is liable for indirect or consequential loss, or for loss of profit, revenue or anticipated savings. We are not liable for loss or damage caused by matters outside Our reasonable control, including denial-of-service attacks or malware not attributable to Our negligence.
15. Exit and Handover
15.1 On termination or expiry We shall, at no charge, provide a complete handover of all administrative access and MFA arrangements, transfer all relevant documentation to You or Your incoming provider, and support the transition for a reasonable agreed period. There is no penalty for termination on notice.
16. Events Outside Reasonable Control (Force Majeure)
16.1 Neither party is liable for any failure or delay in performing its obligations to the extent caused by events beyond its reasonable control, including power or internet failure, industrial action, fire, flood, acts of terrorism or war, or government action.
17. General
17.1 You may not assign or sub-contract the Agreement without Our written consent. We may sub-contract delivery but remain responsible for the Services.
17.2 If any provision is held invalid or unenforceable, the remaining provisions continue in full force, with the offending part severed.
17.3 No delay or failure to exercise a right is a waiver of it. Nothing in the Agreement creates a partnership or agency between the parties. A person who is not a party has no right to enforce the Agreement.
17.4 Notices under the Agreement must be given in writing.
18. Governing Law and Jurisdiction
18.1 The Agreement is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the English courts.
Addendum A — Data Processing Agreement
This Addendum forms part of the Agreement and is made under Article 28 of the UK GDPR. You are the “Controller” and Supportwise is the “Processor”. It governs the processing of personal data by the Processor on behalf of the Controller in connection with the Services.
A1 Status. The Controller is the controller and the Processor the processor of the personal data described in Annex 1. Each party shall comply with its obligations under the Data Protection Legislation. The Controller shall ensure it has a lawful basis for the processing.
A2 Processor obligations. The Processor shall: process personal data only on the Controller’s documented instructions unless required otherwise by law; ensure persons authorised to process are under a duty of confidentiality; implement appropriate technical and organisational measures under Article 32; not engage a sub-processor except under section A3; assist the Controller with data-subject requests, breach notification, DPIAs and prior consultation; at the Controller’s choice delete or return personal data at the end of the Services; make available information necessary to demonstrate compliance and contribute to audits; and immediately inform the Controller if, in its opinion, an instruction infringes the Data Protection Legislation.
A3 Sub-processors. The Controller grants general authorisation to engage the sub-processors listed in Annex 2. The Processor shall inform the Controller of any intended addition or replacement, giving a reasonable opportunity to object, shall impose equivalent data-protection obligations on each sub-processor by written contract, and remains fully liable for each sub-processor’s performance. Microsoft, in respect of the Controller’s own Microsoft 365 tenant, is engaged directly by the Controller and is not a sub-processor of the Processor.
A4 Location. Personal data is held within the UK or EEA, with UK data residency applied wherever the relevant service makes it available. The Processor shall not transfer personal data outside the UK or EEA without the Controller’s prior written consent and a valid transfer mechanism.
A5 Breach and requests. The Processor shall notify the Controller without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting the Controller’s data, and shall promptly notify any data-subject or authority request, responding only on the Controller’s documented instructions or as required by law.
A6 Return and deletion. On termination the Processor shall, at the Controller’s choice, return and/or securely delete the personal data, save where retention is required by law. Support ticket records are anonymised within 30 days of the end of the Agreement.
A7 Audit. The Processor shall, on reasonable written request and no more than once in any 12-month period (or following a breach), provide information reasonably necessary to demonstrate compliance and contribute to audits, subject to reasonable notice and confidentiality.
A8 Contact. The Processor’s contact for data-protection matters is Christopher Otter (christopher.otter@supportwise.co.uk).
Annex 1 — Description of the Processing
- Subject matter. Processing of personal data by the Processor in the course of providing the managed IT support Services under the Agreement.
- Duration and frequency. Continuous, for the term of the Agreement, and thereafter only as permitted by section A6 — support ticket records are anonymised within 30 days of the end of the Agreement.
- Nature and purpose. Administration, monitoring, protection and support of the Controller’s IT estate: Microsoft 365 tenancy and user accounts (including joiners, leavers and licence assignment), endpoints and network devices, backup, endpoint protection, remote access and remote support sessions, and the recording, triage and resolution of support tickets, together with the licence and billing administration that follows from them.
- Categories of data subject. The Controller’s employees, workers, contractors and other authorised users of the Controller’s IT systems; and the Controller’s own contacts where their personal data is present in systems the Processor administers.
- Types of personal data. Name; work email address and telephone number; job title, role and department; Microsoft 365 and directory account identifiers, sign-in and licence-assignment data; device identifiers, assignment and monitoring or telemetry data; support ticket content and the correspondence attached to it, including any personal data a data subject chooses to include; and remote-session logs. Where necessary to resolve a ticket or to carry out a migration or backup on the Controller’s instructions, mailbox and file content may be accessed incidentally.
- Special category data. None is required or requested by the Processor. Where such data is present in the Controller’s mailboxes, files or systems it may be accessed only incidentally in the course of the Services, and is processed on the same terms as all other personal data under this Addendum.
- Limits on use. The Processor processes the personal data only to deliver the Services on the Controller’s documented instructions, and for no purpose of its own.
Annex 2 — Authorised Sub-processors: ConnectWise (RMM / PSA); ScreenConnect / ConnectWise (remote access and remote support sessions); SkyKick (Microsoft 365 / SaaS management and analysis); Axcient (Microsoft 365 and data backup); Bitdefender (endpoint protection / antivirus). All UK/EEA, UK where available.