CAMBITION IT SERVICES LIMITED
Terms and Conditions
Last updated: September 2026
Company number 08084429. Registered office: 6th Floor, Amp House, Dingwall Road, Croydon CR0 2LX. Trading address: Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridge CB22 7RG.
Agreement
By this Agreement CAMBITION IT SERVICES LIMITED (company number 08084429) whose registered office is at 6th Floor, Amp House, Dingwall Road, Croydon CR0 2LX (the Company) agrees to provide the Services described in the Particulars to the Client named in the Particulars, and the Client agrees to accept those Services, pay the Charges and comply with these Terms and Conditions.
The Particulars are the separate order, quotation, proposal or other commercial document issued by the Company that identifies the Client, the Products, the Charges and the term. These Terms and Conditions do not themselves list what a Client is buying.
Notices to the Company should be sent to the trading address at Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridge CB22 7RG and by email to the address stated in the Particulars, with a copy to the registered office.
1. Interpretation
1.1 Words defined in the Particulars have those meanings. In these Terms and Conditions:
Agreement means the contract formed by the Particulars, these Terms and Conditions and any applicable Supplementary Terms.
Approved AI Tools means xAI Grok (Grok Business, Grok Enterprise or the xAI API) and xAI Grok Bot, including any successor xAI service notified under condition 11.7.
Bribery Act means the Bribery Act 2010.
Business Day means a day other than a Saturday, Sunday or public holiday in England, excluding 24 December to 1 January inclusive.
Charges means the charges in the Particulars.
Client Data means Data, Confidential Information and Personal Data of the Client.
Confidential Information has the meaning in condition 10.
Configuration Services means configuration work specified in an Annexe.
Data means data input into the Software or other Services by the Client, its Personnel or Customers, or by the Company on the Client’s behalf.
Data Protection Legislation means the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025, PECR and any successor UK data-protection law.
Giacom means the relevant Giacom Group company listed at giacom.com/company-details with registered office at 41 Lothbury, London EC2R 7HF, group VAT 386614858.
Hosting Services means the services that allow authorised users to access the Software or other hosted Products.
Normal Business Hours means 09:00 to 17:30 UK time, Monday to Friday, excluding public holidays and 24 December to 1 January inclusive.
Particulars means the order, quotation, proposal or other commercial document issued by the Company that identifies the Client, the Products, the Charges and the term for that Client.
Personal Data, controller, processor, process, sub-processor and data subject have the meanings in Data Protection Legislation.
Personnel means officers, employees, consultants, contractors and advisers of the relevant party.
Product means a service or software item named on the Particulars.
Services means the Products and related work the Company agrees to provide under the Particulars, including Configuration Services, Hosting Services, Maintenance and Support and Technical Support Services as applicable.
Software means the Company’s proprietary PSA / ITSM platform (the Cambition Portal) and any other Company software licensed under condition 2.
Third Party Service means a Product supplied by a vendor and resold or provisioned by the Company.
UK GDPR means the UK General Data Protection Regulation as defined in the Data Protection Act 2018.
Vendor Terms means the vendor’s then-current terms for a Third Party Service, including Giacom Service Specific Terms, the Microsoft Customer Agreement, the N-able Software Services Agreement, SentinelOne’s terms and Gladinet’s hosted terms.
1.2 Headings do not affect interpretation. A person includes a body corporate. Words in the singular include the plural. A reference to a statute is to that statute as amended or replaced.
1.3 Writing includes email. A notice sent by email to the address in the Particulars is given when sent, unless the sender receives an automated delivery-failure report. Faxes are not used.
2. Software Licence
2.1 The Company grants the Client a non-exclusive, non-transferable licence for its Personnel and Customers to access and use the Software through the Hosting Services solely for the Client’s internal business purposes. The licence ends if this Agreement is terminated under condition 14.
2.2 Access is by unique credentials. Credentials must be kept confidential. The Client is responsible for use made with its credentials, except unauthorised use caused by the Company’s Personnel.
2.3 The Client shall notify the Company immediately if it knows or suspects credentials have been compromised.
2.4 The Client shall not: (a) store or transmit unlawful, harmful, defamatory, obscene or infringing material through the Services; (b) abuse, disrupt or attack the Services; (c) copy, modify or distribute the Software; (d) reverse engineer the Software except as a law that cannot be excluded allows; (e) use the Software to provide a bureau service to third parties; (f) transfer its rights; (g) obtain unauthorised access; or (h) use the Software, Data or outputs to train or fine-tune a foundation model or other general-purpose AI model.
2.5 The Company may enter similar agreements with other clients and independently develop similar services.
2A. Third Party Services
2A.1 Some Products are supplied by a third-party vendor and resold or provisioned by the Company. The Company’s key suppliers are:
(a) Giacom, through Giacom Cloud Market, including Microsoft 365, Azure, Exchange Online, Exclaimer, Bitdefender and Acronis where those Products are on the Particulars;
(b) N-able Technologies Ltd and N-able Solutions ULC, for N-central (N-able hosted cloud) and the SentinelOne EDR bolt-on; and
(c) Gladinet, Inc., for CentreStack Online hosted on Amazon Web Services in the United States.
2A.2 Use of a Third Party Service is also subject to the Vendor Terms identified on the Particulars or accepted when the Product is provisioned. The Client shall accept the Microsoft Customer Agreement before Microsoft services are provisioned.
2A.3 If the Vendor Terms and this Agreement conflict on licence, acceptable use, vendor service levels, data location or cancellation of that Product, the Vendor Terms prevail for that Product only. This Agreement prevails on fees payable to the Company, the Company’s support, the Company’s liability cap and termination of the Company’s Services.
2A.4 The Client shall not use a Product in a way that puts the Company in breach of its contract with Giacom or the vendor. Microsoft New Commerce Experience seat terms, mid-term reductions and Azure consumption billed in arrears follow the Vendor Terms. If the Client stops paying the Company, the Company may still be liable to Giacom for the committed term. The Client remains liable to the Company for those fees.
2A.5 The Company is not the vendor and does not warrant the vendor’s product beyond this Agreement. Vendor downtime is not a breach of Schedule 1 except to the extent Schedule 1 says otherwise.
2A.6 A Product listed in this condition applies only if it is named on the Particulars.
3. Maintenance Services
3.1 The Company shall provide release management and change control for the Software and Hosting Services that it operates, and shall implement new releases and patches as it reasonably considers necessary.
3.2 The Company shall keep service interruptions to a minimum and shall use reasonable efforts to avoid unscheduled downtime.
3.3 Maintenance includes scheduled error corrections and updates to features in the Software Specification. Additional features requested by the Client may be charged separately.
3.4 Maintenance of a Third Party Service is performed by the vendor under the Vendor Terms. The Company shall pass through vendor maintenance notices that affect the Client where it is reasonably able to do so.
4. Technical Support Services
4.1 The Company shall provide the Technical Support Services in Schedule 2 during Normal Business Hours, unless the Particulars specify otherwise.
5. Service Level Arrangements
5.1 Schedule 1 applies from the start of the month after the later of: (a) the Commencement Date; and (b) satisfactory completion of any Configuration Services named on the Particulars. Where there are no Configuration Services, Schedule 1 applies from the Commencement Date.
6. Client’s obligations
6.1 The Client shall give the Company timely co-operation, access to premises, systems and information reasonably required to provide the Services, and shall ensure that information it supplies is accurate.
6.2 The Client shall prepare its premises and systems at its own cost, appoint a Project Manager with authority to bind the Client, keep contact details current, and comply with applicable law.
6.3 The Client shall obtain any consent it needs from its Personnel and Customers for the Company to provide the Services, including the tools in condition 11B.
6.4 The Client shall not, during the Term and for six months after, solicit the Company’s employees or contractors who have worked on the Services, except as a result of a bona fide public recruitment campaign. If the Client hires such a person in breach, it shall pay the Company a sum equal to 20% of the first year’s remuneration of that person.
6.5 The Client shall comply with the Bribery Act, maintain adequate procedures, and promptly report any request for an undue financial or other advantage in connection with this Agreement.
7. Company’s obligations
7.1 The Company shall provide the Services with reasonable care and skill and in material accordance with the Particulars.
7.2 Deliverables for Configuration Services shall be provided as set out in the Annexe.
7.3 The Company warrants that it has the right to grant the licence in condition 2. If the Software does not materially conform to the Software Specification, the Company’s obligation is to use reasonable efforts to correct the non-conformity. That is the Client’s exclusive remedy for breach of this warranty. The Company does not warrant that use of the Software will be uninterrupted or error-free.
8. Charges and payment
8.1 Charges are as set out in the Particulars. Recurring Charges are invoiced monthly in advance unless the Particulars say otherwise. Azure and other consumption Products are invoiced in arrears when the vendor bills the Company.
8.2 Time-and-materials work is charged at the rates in the Particulars against approved timesheets.
8.3 Third-Party Fees approved in advance are payable in addition to the Company’s Charges. The Company shall provide supporting documentation.
8.4 Charges are exclusive of VAT.
8.5 Invoices are payable within 30 days of the invoice date unless the Particulars say otherwise.
8.6 If a sum is overdue, interest accrues daily at 4% a year above the Bank of England base rate, or at the rate under the Late Payment of Commercial Debts (Interest) Act 1998 if higher, from the due date until payment.
8.7 All sums become due immediately on termination.
8.8 The Client shall pay without set-off, counterclaim or deduction, except as required by law.
8.9 The Company may suspend Services for non-payment after giving not less than 7 days’ written notice.
9. Intellectual property
9.1 The Company and its licensors own the Intellectual Property Rights in the Software, Hosting Services and Company materials. The Client owns the Intellectual Property Rights in Client Data.
9.2 The Client grants the Company a licence to use Client Data solely to provide and administer the Services.
9.3 The Company shall indemnify the Client against a claim that the Software infringes a third party’s Intellectual Property Rights in the United Kingdom, subject to the Client giving prompt notice, sole conduct of the defence and reasonable co-operation. The Company may modify the Software, procure a licence, or terminate the affected Service and refund prepaid unused Charges.
9.4 The indemnity does not apply to infringement caused by the Client’s modification, combination with other software, or use outside this Agreement.
9.5 This condition 9 is the Client’s exclusive remedy for intellectual-property infringement.
10. Confidentiality
10.1 Each party shall keep the other’s Confidential Information confidential and use it only to perform this Agreement.
10.2 Confidential Information includes the Software, Charges, Client Data, and information marked confidential or that ought reasonably to be considered confidential.
10.3 The obligation does not apply to information that is public other than by breach, already lawfully in the recipient’s possession, independently developed, or required to be disclosed by law or a competent authority. Where disclosure is required by law, the recipient shall (if lawful) give the other party as much notice as reasonably practicable.
10.4 The Company may disclose Confidential Information to Personnel, sub-processors and professional advisers who need it to perform this Agreement and who are bound by confidentiality.
10.5 This condition survives termination for five years, and indefinitely for trade secrets.
11. Data Protection
11.1 Both parties shall comply with Data Protection Legislation. This condition 11 is in addition to those obligations.
11.2 Schedule 3 sets out the subject-matter, nature, purpose, types of Personal Data, categories of data subject, sub-processors, transfers and duration.
11.3 For Personal Data processed in providing the Services, the Client is the controller and the Company is the processor. For the Company’s own staff, invoicing and accounts, the Company is the controller.
11.4 The Company shall process Personal Data only on the Client’s documented instructions, including this Agreement and the Particulars, unless UK law requires otherwise.
11.5 The Company shall: (a) ensure persons authorised to process Personal Data are bound by confidentiality; (b) take appropriate technical and organisational measures; (c) assist the Client, taking into account the nature of processing, with data-subject requests and with DPIAs and consultations with the Information Commission; (d) delete or return Personal Data on termination in accordance with Schedule 3; (e) make available information reasonably necessary to demonstrate compliance; and (f) notify the Client without undue delay after becoming aware of a personal data breach.
11.5(b)(iv) Restricted transfers of Personal Data outside the UK shall take place only where the data protection test required by UK law is met and an appropriate safeguard is in place (the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, UK adequacy regulations, or another mechanism approved under Data Protection Legislation).
11.6 The Client warrants that it has a lawful basis and all notices and consents needed for the Company to process Personal Data as described in Schedule 3, including the transfers and sub-processors listed there.
11.7 The Client generally authorises the Company to appoint the sub-processors in Schedule 3 and on the live sub-processor page. The Company shall give not less than 14 days’ notice of a change of sub-processor (except in an emergency). The Client may object on reasonable data-protection grounds. The Company shall impose written terms on each sub-processor no less protective than this condition 11 and remains liable to the Client for that sub-processor’s processing.
11.8 The Company shall not use Personal Data to make a solely automated decision producing legal or similarly significant effects concerning an individual, except where Data Protection Legislation permits it and Articles 22A to 22D of the UK GDPR are applied.
11.9 The Company may update Schedule 3 on not less than 30 days’ notice to reflect a change of sub-processor, hosting location or law, provided the update is no less protective of the Client.
11A. Artificial Intelligence Tools (Grok and Grok Bot only)
11A.1 The only artificial intelligence tools the Company uses in connection with the Services are the Approved AI Tools. The Company shall not use any other generative AI system in connection with Client Data without the Client’s prior written consent.
11A.2 The Approved AI Tools may be given access to Client Data solely to the extent necessary for the Company to perform the Services and administer the Client’s account. That access is for the same administrative purposes as access by the Company’s Personnel. Where Grok Bot is used, it may retain files, session state and memory in its hosted environment only for that purpose and only for as long as needed to provide the Services. The Company shall not connect Grok Bot to the Client’s production systems, or store Client credentials in Grok Bot, except as reasonably required to perform the Services and with appropriate access control and human oversight.
11A.3 The Company shall: (a) use only a business, enterprise or API tier of the Approved AI Tools whose provider terms prohibit training on customer content, and shall not use a consumer or personal Grok account (including Grok on X or a personal SuperGrok account) in connection with Client Data; (b) enable Privacy Mode, or the equivalent no-training setting, on Grok Bot and keep it enabled; and (c) not accept provider credits or other benefit in exchange for permitting training on Client Data.
11A.4 The Company shall not, and shall contractually require the providers of the Approved AI Tools not to: (a) use Client Data to train, fine-tune or otherwise improve any foundation model or general-purpose AI model; (b) use such information to develop or improve products or services offered to any third party; or (c) retain such information for any purpose other than providing the Services and the Company’s related administration, security, abuse-monitoring and support, except where UK law requires retention.
11A.5 The Client acknowledges that the Approved AI Tools are operated by X.AI LLC (and, in the case of Grok Bot, may also involve Anysphere, Inc.) and that Personal Data submitted to those tools is processed in the United States as a restricted transfer under condition 11.
11A.6 Outputs of the Approved AI Tools are assistive only. The Company remains responsible to the Client as if the relevant acts were carried out by its own Personnel.
11A.7 X.AI LLC and any Grok Bot infrastructure provider that processes Personal Data are sub-processors under condition 11.7.
11A.8 The Client shall not submit Client Data to a publicly available or consumer-tier AI service in connection with the Services.
11A.9 This condition 11A does not limit conditions 10 or 11.
11B. Monitoring, security and file-access tools
11B.1 In order to provide the Services the Company may install and operate monitoring, security and file-access software on devices and systems covered by the Particulars, including N-able N-central (hosted by N-able, not on the Company’s own servers), SentinelOne endpoint software forming part of the Company’s EDR service, and Gladinet CentreStack.
11B.2 The Client authorises that installation and operation. Those tools may collect the device, security and file data described in Schedule 3. That access is for the same administrative and protective purposes as access by the Company’s Personnel.
11B.3 The Client shall not remove, disable or interfere with those tools while the relevant Services are live, and shall obtain any consent it needs from its own Personnel.
11B.4 SentinelOne uses endpoint telemetry to detect attacks and to improve detection. That is part of how the EDR Product works and is not limited by condition 11A.
11B.5 CentreStack Online is hosted by Gladinet, Inc. on Amazon Web Services in the United States. Files the Client stores on that platform are processed in the United States under Schedule 3.
11B.6 N-able, SentinelOne and Gladinet are sub-processors under condition 11.7.
11B.7 This condition 11B does not limit conditions 10 or 11.
12. Limitation of liability
12.1 This condition 12 sets out the Company’s entire financial liability arising under or in connection with this Agreement, including liability in contract, tort (including negligence), misrepresentation or otherwise.
12.2 Nothing in this Agreement limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be limited or excluded by English law.
12.3 Subject to condition 12.2, the Company shall not be liable for loss of profits, loss of business, loss of goodwill, loss of anticipated savings, loss of or corruption of data (except to the extent the Services expressly include backup and the loss is caused by the Company’s negligence in performing that backup), or any special, indirect or consequential loss.
12.4 Subject to condition 12.2, the Company’s total liability in any Year shall not exceed the Charges paid or payable by the Client in that Year.
12.5 The Service Level Arrangements state the Client’s exclusive remedy for unavailability of the Hosting Services, except for the right to terminate where this Agreement expressly gives that right.
12.6 This condition 12 survives termination.
13. Anti-bribery
13.1 Each party shall comply with the Bribery Act and the Relevant Requirements, maintain adequate procedures, and not engage in any activity that would constitute an offence under sections 1, 2 or 6 of the Bribery Act.
14. Term and termination
14.1 This Agreement starts on the Commencement Date, continues for the Initial Term in the Particulars, and then renews for successive periods of 12 months unless either party gives not less than 90 days’ written notice to expire at the end of the then-current period.
14.2 Either party may terminate immediately by written notice if the other: (a) fails to pay any sum within 14 days after written notice that it is overdue; (b) commits a material breach that is irremediable, or fails to remedy a remediable material breach within 30 days after written notice; or (c) repeatedly breaches in a way that reasonably justifies the opinion that its conduct is inconsistent with it intending to give effect to this Agreement.
14.3 The Company may terminate immediately if the Client undergoes a change of control within the meaning of section 1124 of the Corporation Tax Act 2010, other than an internal reorganisation that does not change the ultimate beneficial ownership.
14.4 Either party may terminate immediately if the other is unable to pay its debts, enters insolvency, administration, liquidation or an arrangement with creditors, or any equivalent event occurs.
14.5 On termination: (a) all licences end; (b) the Client shall stop using the Software and Third Party Services provisioned by the Company, except Microsoft tenants the Client continues directly with Microsoft; (c) each party shall return or destroy the other’s Confidential Information on request, except copies required by law or held in routine backups; (d) accrued rights survive; (e) conditions which by their nature should survive shall survive, including 8, 9, 10, 11, 12 and 17.
14.6 The Company may suspend Services if a termination event has occurred or is about to occur, in an emergency, or in the event of an actual or suspected security breach. The Company shall lift the suspension when the reason for it has ended.
15. Notices
15.1 Notices under this Agreement shall be in writing and delivered by hand, pre-paid first-class post or email to the addresses in the Particulars (and, for the Company, also to the trading address in the preamble).
15.2 A notice is deemed given: (a) if delivered by hand, on the Business Day of delivery; (b) if sent by pre-paid first-class post, on the second Business Day after posting; (c) if sent by email, when sent, unless the sender receives an automated delivery-failure report.
16. Assignment
16.1 The Client shall not assign or subcontract this Agreement without the Company’s prior written consent, not to be unreasonably withheld.
16.2 The Company may assign or subcontract this Agreement, and may use sub-processors as provided in condition 11.
17. General
17.1 This Agreement is the entire agreement and supersedes previous agreements relating to its subject-matter. Each party acknowledges it has not relied on any representation not set out in this Agreement.
17.2 A variation must be in writing and signed by both parties, except that the Company may update Schedule 3 as provided in condition 11.9.
17.3 Neither party is in breach, or liable for delay, to the extent the breach or delay is caused by circumstances beyond its reasonable control, provided it gives notice and uses reasonable efforts to mitigate.
17.4 A waiver must be in writing. Failure to enforce a right is not a waiver.
17.5 If a provision is invalid, it shall be modified to the minimum extent necessary to make it valid. The rest of the Agreement remains in force.
17.6 Nothing in this Agreement creates a partnership or agency.
17.7 A person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce this Agreement.
17.8 This Agreement is governed by English law. The courts of England and Wales have exclusive jurisdiction. The parties shall first attempt to resolve a dispute through CEDR mediation if either party requests it, without prejudice to either party’s right to seek interim relief.
Schedule 1 — Service Level Arrangements
1. Availability target. The Company shall use reasonable efforts to make the Hosting Services that it operates available for 99.5% of each calendar month, excluding Excused Downtime.
2. Availability is calculated as: ((Total minutes in the month − Excused Downtime minutes − Unexcused Downtime minutes) / (Total minutes in the month − Excused Downtime minutes)) × 100.
3. Excused Downtime means scheduled maintenance notified at least 24 hours in advance, Client-caused outages, third-party vendor outages, and events beyond the Company’s reasonable control under condition 17.3.
4. Measurements are taken at five-minute intervals at the Company’s boundary, not at the Client’s premises.
5. If monthly availability falls below 99.5%, the Client may claim a service credit of 5% of that month’s Hosting Charges for each full 1% below the target, capped at 25% of that month’s Hosting Charges. Credits are the exclusive remedy for unavailability, except the termination rights in this Agreement.
6. Credits do not apply to Third Party Services except to the extent the vendor issues an equivalent credit that the Company actually receives, which the Company shall pass through.
Schedule 2 — Technical Support
1. The Client shall log incidents through the Cambition Portal or the support email in the Particulars.
2. Priority and response targets during Normal Business Hours:
| Priority | Meaning | Target response |
|---|---|---|
| P1 Critical | Service down or a security incident affecting live operations | 1 Business Hour |
| P2 High | Major function unusable; no reasonable workaround | 4 Business Hours |
| P3 Medium | Degraded function; workaround available | 1 Business Day |
| P4 Low | General enquiry, change request or minor defect | 2 Business Days |
3. Response is the time until a technician acknowledges and begins diagnosis, not the time to resolve.
4. The Company may reclassify priority on reasonable grounds.
5. Support for a Third Party Service is provided by the Company as first line where the Particulars include managed support for that Product. Second-line support is provided by the vendor under the Vendor Terms.
Schedule 3 — Data Protection Statement
A. Roles
3.1 For Personal Data processed in the course of the Services the Client is the controller, the Company is the processor, and the persons listed in paragraph E are sub-processors.
3.2 Where the Company processes Personal Data to run its own business (invoicing, staff, accounts), the Company is the controller.
B. Purpose
3.3 The Company processes Personal Data only to: (a) provide, administer, support, secure and bill the Services; (b) operate the tools in condition 11B; (c) provision Third Party Services; (d) operate the Approved AI Tools under condition 11A; (e) comply with UK law; and (f) exercise or defend legal claims. The Company shall not sell Personal Data or use it for its own marketing.
C. Types of Personal Data
3.4 Depending on the Products on the Particulars, Personal Data may include: identity and contact data; billing data; tickets and diagnostic logs; N-central device inventory, health, patch status, remote-session metadata and device usernames; SentinelOne process names, file hashes, command lines, network metadata, detections and rollback events; CentreStack files, folders, permissions and access logs; Microsoft mailbox, identity and tenant data; Exclaimer directory attributes and email in transit for signatures; Bitdefender endpoint telemetry; Acronis backup content and metadata; and, for the Approved AI Tools, only items the Company’s Personnel submit to administer the Services.
3.5 The Company does not seek special category or criminal-offence data. If the Client stores such data in a mailbox, file, backup or ticket, the Client remains the controller of that decision.
D. Data subjects
3.6 Personnel and users of the Client; contacts in the Client’s directories, mailboxes or files; and individuals who use a monitored or backed-up device.
E. Sub-processors
3.7 The Company may use the sub-processors below, but only where the relevant Product is on the Particulars (except Grok / Grok Bot, which the Company uses to administer the Services). The live list is published at https://cambition.co.uk/sub-processors/. If that page and this Schedule differ, the page as it stood when the processing started prevails for that processing.
| Sub-processor | Role | Personal Data | Location |
|---|---|---|---|
| Relevant Giacom Group company, 41 Lothbury, London EC2R 7HF | Cloud Market provisioning and billing | Account, order, tenant, billing | United Kingdom (Ireland if a Giacom Ireland entity is used) |
| Microsoft Ireland Operations Limited / Microsoft Corporation | Microsoft 365, Azure, Exchange Online | Identity, mailbox, tenant, cloud-service data | UK / EEA primary; other Microsoft regions as configured |
| Exclaimer Limited | Email signatures | Directory attributes; email in transit if server-side | Azure region selected at provision |
| Bitdefender SRL | Endpoint / email security via Giacom | Endpoint and threat telemetry | Vendor region for that SKU |
| Acronis International GmbH | Backup via Giacom | Backup content and metadata | Vendor region for that SKU |
| N-able Technologies Ltd and N-able Solutions ULC | N-central hosted cloud (AWS), not a Cambition server | Device inventory, health, patch, remote-session metadata, device usernames | N-able hosted cloud on AWS. Confirm instance region from the N-central URL |
| SentinelOne, Inc. | EDR bolt-on — EU Central 1 console euce1-swprd6.sentinelone.net | Endpoint threat telemetry | European Union (Frankfurt / AWS eu-central-1). UK to EEA covered by adequacy. SentinelOne is a US company; group support may involve affiliates outside the EU |
| Gladinet, Inc. on Amazon Web Services | CentreStack Online hosted file access | Files, folders, permissions, access logs | United States (AWS US Data Center) |
| X.AI LLC | Grok backend administration | Only data Personnel submit to administer the Services | United States |
| Anysphere, Inc. (Cursor) | Grok Bot infrastructure where used | Same as Grok, plus Bot files / session state | United States |
3.8 The Company shall impose written terms on each sub-processor no less protective than this Schedule and remains responsible to the Client for that processing.
F. International transfers
3.9 Personal Data processed by Gladinet, X.AI LLC and Anysphere is processed in the United States. That is a restricted transfer. It takes place only where necessary for CentreStack Online or the Approved AI Tools, the data protection test is met, and an appropriate safeguard is in place (UK IDTA or UK Addendum to the EU SCCs).
3.10 Personal Data processed by SentinelOne for the Company’s EDR service is hosted at rest in the European Union (EU Central 1). A transfer from the United Kingdom to the EEA is not a restricted transfer while UK adequacy regulations for the EEA remain in force.
3.11 The Company does not represent that Personal Data processed by CentreStack Online or by the Approved AI Tools remains in the United Kingdom.
G. Duration
3.12 The Company processes Personal Data for the Term and then deletes or returns it within 90 days after termination, except where UK law requires retention or a copy must be kept to defend a claim.
3.13 Vendor retention follows that vendor’s terms. xAI enterprise / API inputs and outputs are currently deleted within 30 days unless Zero Data Retention is enabled. Grok Bot may retain files and session state only for as long as needed to perform the task. CentreStack files remain until the Client or the Company deletes them or the tenant is closed.
H. Instructions and security
3.14 This Schedule, conditions 11, 11A and 11B and the Particulars are documented instructions.
3.15 The Company shall maintain encryption in transit, access control, multi-factor authentication for administrative access, logging, patching and least-privilege access appropriate to the Services.