Data Services Terms
These terms govern business engagements for Insightnix Data Services, including managed dashboard and reporting services.
1. Contracting party
Insightnix Data Services is provided by Isodev Limited, trading as Insightnix Data Services (“Insightnix”, “we”, “us” or “our”). Full company and contact details are set out in section 14.
These Terms apply to Services ordered by a business, public body, charity, research institution or other organisation (“Client”, “you” or “your”). They are not intended as consumer terms. A person accepting an Order for an organisation confirms that they have authority to bind it.
Definitions
In these Terms:
- “Business Day” means a day other than a Saturday, Sunday or public holiday in England when banks in London are open for business;
- “Client” means the person or organisation identified in the Order;
- “Client Data” means data, files, credentials, content and instructions supplied or made available by or for the Client;
- “Client Materials” means Client Data together with any branding, documentation, specifications and other materials the Client supplies or makes available for the Services;
- “Deliverables” means the dashboards, reports, models, documentation or other outputs expressly identified in the Order;
- “Order” means an accepted quotation, proposal, statement of work, order form or other written document incorporating these Terms;
- “Services” means the services described in the Order; and
- “Third-Party Service” means software, hosting, data, an API, a licence or infrastructure supplied by a person other than Insightnix.
A statement of work agreed under a signed services agreement is an Order for the purposes of these Terms. Where a services agreement is used, it incorporates and is subject to these Terms unless expressly stated otherwise.
Non-binding enquiries
Submitting an online enquiry, selecting a configuration, ticking a form acknowledgement, viewing a displayed plan or discussing preliminary requirements does not by itself require either party to proceed or create a contract for paid Services. These steps allow us to assess the request and prepare a tailored quotation.
The website configurator records preliminary service preferences for review and does not calculate, reserve or agree a price. Indicative build times, plan descriptions and enquiry acknowledgements are invitations to discuss requirements only and are not offers capable of acceptance.
Contract formation
A binding engagement begins only when a written quotation, proposal, statement of work, order form or other Order issued by us is accepted in writing by the Client, unless the Order states another formation process. A contract may also be formed where we expressly confirm acceptance and begin work at the Client’s written request.
The contract consists of the accepted Order, these Terms, any agreed data-processing or security schedule, and any document expressly incorporated by reference. References to Services and Deliverables mean the services and outputs identified in the applicable Order.
Order of precedence
In the event of conflict, a signed client-specific amendment takes priority, followed by the Order, an agreed Data Processing Agreement for data-protection matters, these Terms and then general Website descriptions. A purchase order issued by the Client is an administrative document only and does not add to or replace the contract unless we expressly agree to its relevant wording in writing.
Business-to-business basis
Unless we expressly agree otherwise, the Services are supplied for business, professional, institutional or organisational purposes. The Client confirms that it enters the contract in the course of business and that the individual accepting the Order has authority to bind it.
2. The services
Service categories
Depending on the accepted Order, the Services may include:
- requirements discovery and data-source review;
- data extraction or connection from Excel, CSV, Google Sheets, databases, cloud warehouses, APIs, business applications or multiple sources;
- data cleaning, normalisation, validation, transformation, modelling and preparation for reporting;
- KPI definitions, metric logic, semantic models and reporting structures;
- design and build of Power BI, Tableau or Excel dashboards, scorecards and reports;
- operational reporting, management KPIs, finance and performance reporting, forecasting and planning analysis;
- one-off, monthly, weekly or daily refresh arrangements;
- automated reports, threshold alerts, row-level security, historical-data migration, machine-learning or forecasting components; and
- documentation, training, handover, maintenance, support or priority support.
Included work
Only work expressly described in the Order is included. The platform, number and type of dashboards, data sources, environments, refresh method, integrations, outputs, support level, timetable, assumptions, exclusions and responsibilities are those stated in the Order.
A plan label such as Starter, Professional or Enterprise is a scoping aid and does not independently define the Deliverables. Dashboard counts have the meaning agreed in the Order and may distinguish pages, reports, workbooks, files, models and environments. Website descriptions and configurator selections are indicative and do not expand an accepted scope.
Excluded work
Unless expressly included, the Services do not cover source-system remediation or repair, data entry, a comprehensive data audit, business-process ownership, legal or regulatory compliance advice, penetration testing, custom software or mobile-app development, permanent data hosting, procurement of enterprise licences, guaranteed real-time operation, 24-hour support, regulated professional decisions, remediation of defects in third-party systems, or responsibility for decisions made using a Deliverable.
Discovery and assumptions
Initial scope, price and timetable may rely on samples, schemas, demonstrations and statements supplied by the Client. If fuller access reveals materially different volume, complexity, data quality, security, permissions or integration requirements, the parties will use the change-control process before the affected work proceeds.
Delivery method
Services may be delivered remotely, in a Client-controlled environment, in an agreed cloud service or through another arrangement stated in the Order. We may use documented development, testing and deployment practices appropriate to the scale and risk of the engagement.
No implied exclusivity or outcome
We do not promise exclusivity, a particular financial result, increased revenue, regulatory approval, a perfect forecast, uninterrupted third-party refresh or adoption by users. Deliverables are tools to support analysis and reporting; the Client remains responsible for business decisions and operational implementation.
3. Quotes and engagement
Quotations and scope documentation
We review the submitted options, available information, data sources, technical dependencies and required scope before preparing a tailored quotation. Only an accepted Order states the binding scope and price. Unless stated otherwise, a quotation remains open for acceptance for 30 days.
The Order should identify the objective, Deliverables, data sources, platform, environments, refresh frequency, material assumptions, dependencies, timetable, fees, acceptance method, support arrangements and Client responsibilities. A requirement not reasonably apparent from the Order is outside scope.
Project governance
Each party will nominate an authorised contact. Decisions, approvals and instructions from that contact may be relied upon. The Client will consolidate stakeholder feedback and resolve internal conflicts. We are not responsible for delay caused by inconsistent or late instructions from multiple stakeholders.
Timetables and dependencies
Delivery dates are reasonable estimates unless the Order expressly states that a date is fixed. A timetable assumes timely access to complete information, data, systems, licences, approvals, decision-makers, Client personnel, third-party systems and feedback.
Where a Client dependency is delayed or an agreed source, platform or requirement changes, relevant dates will move by at least the resulting delay and may require reasonable rescheduling.
Change control
Either party may request a change. We may assess its effect on scope, architecture, data volume, source complexity, refresh frequency, security requirements, risk, fees, resources, Deliverables and delivery dates.
A material change is not binding until the parties agree its effect on fees, timing and responsibilities in writing. We may pause affected work while a change is assessed and are not required to perform changed work at the original price or timetable.
Review and acceptance
The Client must review each Deliverable against the agreed requirements and notify us of any reproducible material non-conformity within 10 Business Days after delivery or demonstration, unless the Order specifies another review period. The notice must describe the issue in sufficient detail for us to reproduce it.
Where a timely rejection identifies a material failure to meet the agreed requirements, we will use reasonable efforts to correct the issue and resubmit the affected Deliverable. Minor defects that do not materially prevent the agreed use do not justify rejection and may be handled through the normal correction or support process or an agreed issue list.
A Deliverable is accepted when the Client confirms acceptance, uses it in production other than for agreed testing, fails to issue a valid rejection within the review period, or accepts a later version after correction.
Client-requested early use
If the Client chooses to deploy, distribute or rely on a draft or unaccepted Deliverable, it does so subject to the known draft status and remains responsible for additional validation. We may charge for work required to reverse or correct changes caused by premature production use.
4. Fees and payment
Fees, taxes and charging models
Fees, billing frequency and any setup, migration, support, licence or usage charges are stated in the Order. Unless expressly stated otherwise, fees exclude VAT and similar applicable taxes. The Client must pay taxes that we are legally required to charge.
An Order may use a fixed fee, recurring fee, time-and-materials rate, usage-based charge or a combination. A fixed fee assumes the stated scope and dependencies. Time-and-materials work is charged for time reasonably spent, including agreed meetings, investigation, documentation, deployment and support.
Submitting a configurator selection or enquiry does not generate, reserve or agree a price.
Setup fees and invoicing
A setup or mobilisation fee is payable before build work begins where the Order requires it. Once work has begun, that fee is non-refundable except to the extent required by law or where we materially fail to provide the corresponding Services.
Recurring fees are invoiced in advance. One-off, milestone and time-and-materials fees are invoiced as stated in the Order. Invoices are payable by the due date stated in the Order or, if none is stated, within 30 days of the invoice date.
Expenses and third-party charges
Reasonable out-of-pocket expenses are chargeable only where the Order permits them or the Client approves them in writing in advance. Pre-approved travel, specialist data, licences, cloud usage, connectors, APIs, capacity and viewer licences may be charged in addition to service fees where the Order so provides.
The Client is responsible for charges incurred in its own accounts. Where we procure or administer a Third-Party Service for the Client, provider price changes, minimum terms, renewal rules and non-cancellable costs may be passed through on reasonable notice.
Invoice disputes
A genuine invoice dispute must be raised promptly with reasons and supporting detail. The Client must pay the undisputed amount when due, and the parties will work in good faith to resolve the disputed balance.
Late payment
Without limiting any statutory right, overdue sums may accrue statutory interest, fixed compensation and recovery costs under the Late Payment of Commercial Debts (Interest) Act 1998, or interest at the rate stated in the Order where lawful. We may suspend affected Services after giving appropriate notice and may recover reasonable collection costs.
No set-off
Except where required by law or agreed in writing, the Client must pay invoices without set-off, counterclaim, deduction or withholding. If a withholding is legally required, the Client will provide the relevant evidence and cooperate in obtaining any available relief.
5. Term and termination
Commencement and duration
An Order begins on the start date stated in it or, if none is stated, on acceptance. A one-off build ends when the Deliverables are accepted and all agreed handover obligations are completed.
A recurring engagement continues for any initial term stated in the Order. If the Order states no initial term, it continues month to month after commencement. Completion of a build does not automatically include indefinite maintenance, refresh monitoring or support.
Suspension
We may suspend all or part of the Services where an invoice is materially overdue, the Client fails to provide a critical dependency, continued access or processing may be unlawful or insecure, required licences have expired, a Third-Party Service is unavailable, or Client conduct creates a material risk to systems, personnel or another customer.
Where reasonably practicable, we will give notice and an opportunity to remedy the cause and will restore the affected Services when it is resolved.
Termination for breach or insolvency
Either party may terminate an Order immediately by written notice if the other commits a material breach that cannot be remedied or fails to remedy a remediable material breach within 14 days after written notice.
Either party may terminate immediately if the other becomes insolvent, ceases business or enters a formal insolvency process, except where mandatory law prevents termination on that ground.
Termination for convenience
A right to terminate for convenience exists only where the Order provides it. Unless otherwise stated, after any initial term either party may terminate a monthly recurring service on at least 30 days’ written notice. The Client remains liable for committed fees, completed work, non-cancellable third-party costs and reasonable wind-down work.
Consequences of termination
Accrued rights and payment obligations remain due. Subject to payment of undisputed outstanding fees, we will provide agreed Deliverables for which payment has been made and reasonable export, handover or exit material then available where included in the Order or separately charged.
Each party will return or stop using the other’s confidential material as required, subject to legal retention and backup cycles. Client Personal Data will be returned or deleted in accordance with section 12.
Survival
Provisions concerning payment, confidentiality, intellectual property, data protection, liability, dispute resolution, governing law and any term intended by its nature to continue will survive termination.
6. Client responsibilities
Information and cooperation
The Client must provide timely, complete and reasonably accurate requirements, data samples, definitions, documentation, access, credentials, licences, decisions and feedback. It must appoint an authorised contact able to give instructions, approve scope and coordinate relevant stakeholders.
The Client must identify any legal, regulatory, security, accessibility, retention or sector-specific requirements before they affect design or delivery.
Lawfulness of Client Materials
The Client warrants that it has all rights, notices, lawful bases, permissions and contracts needed for us to access, receive and process Client Materials and connect to relevant systems. It must not provide data that is excessive for the purpose or subject to a restriction incompatible with the Services.
The Client must not provide special-category data, criminal-offence data, children’s data, payment-card data, authentication secrets or other high-risk information unless its use is necessary, lawful and expressly agreed with appropriate safeguards.
Accounts and credentials
The Client is responsible for its users, accounts, tenant configuration, identity provider, licence assignments and credential security. It must limit administrative access, revoke access when no longer required and promptly notify us of suspected compromise. Shared personal accounts should not be used where named or service accounts are reasonably available.
Source systems and backups
The Client must maintain appropriate source-system controls, licences, backups and continuity arrangements. Unless expressly agreed, the Client remains responsible for the availability and integrity of its source systems and original data. Our working copies and exports are not a substitute for the Client’s own backups.
Validation and decisions
The Client must test Deliverables in its environment and review KPI definitions, calculations, classifications, permissions, forecast assumptions and important totals against authoritative records before production reliance.
The Client remains responsible for decisions, communications and actions taken using Deliverables and must retain appropriate human oversight of operational, financial, employment, safety, legal or other consequential decisions.
Authorised and lawful use
The Client must ensure that its users comply with platform licences, security guidance, intellectual-property restrictions, third-party terms and applicable law. It must not use Deliverables to facilitate unlawful discrimination, unauthorised surveillance, re-identification, fraud or decisions prohibited by law.
Delay and additional work
We are not responsible for delay or additional work caused by incomplete, inaccurate, changing or inaccessible Client Materials or dependencies. Material additional work may be subject to an agreed change.
Indemnity for Client Materials
The Client will indemnify Insightnix against third-party claims, regulatory costs, losses and reasonable expenses to the extent arising from an allegation that Client Materials or a Client instruction infringes another person’s rights, is unlawful, or was supplied without the necessary authority or lawful basis, except to the extent caused by our breach, negligence, unlawful conduct or unauthorised departure from the Client’s instruction.
7. Third-party platforms
Deliverables may depend on products and services supplied by third parties, including Microsoft Power BI, Microsoft Fabric, Tableau, Microsoft Excel, databases, cloud warehouses, APIs, connectors, email services and hosting platforms.
Provider terms and Client accounts
Third-Party Services are supplied under their providers’ terms. Unless the Order expressly states that we will procure or administer them, the Client contracts directly with the provider and is responsible for determining that its intended use is permitted and for maintaining sufficient accounts, permissions, capacity, regions, subscriptions, licences and administrator access.
Production environments and access
Where practicable, production Deliverables and credentials will be placed in or transferred to Client-controlled accounts. Administrative access granted to us must be limited to what is reasonably required and may be revoked when no longer needed or at the end of the engagement.
Availability and change
Third-party availability, security, performance, compatibility, feature changes, usage limits, authentication methods, APIs, licensing, support and pricing are outside our control. We do not warrant uninterrupted operation of a Third-Party Service.
If a provider change materially affects the Services, we will use reasonable efforts to advise on a practical workaround, migration or scope change. Additional work or third-party cost requires written agreement.
Procurement and payment
If we arrange a licence or usage charge as reseller, agent or administrator, it may be subject to the provider’s price, minimum term, renewal and cancellation rules in addition to any administration fee stated in the Order.
Open-source and reusable components
Deliverables may use open-source or generally available components. Those components remain subject to their own licences. We will not knowingly incorporate a component that requires disclosure of the Client’s proprietary material merely through ordinary use unless the Client has agreed.
APIs and source limitations
API output is subject to provider quotas, schema, latency, completeness, availability and permissions. We do not warrant that an API will provide every historical record, remain free or return identical results over time.
Artificial intelligence services
We will not submit confidential Client Data to a public generative-AI service for model training or unrelated use without the Client’s authorisation. Where an AI or machine-learning service is included, the Order should identify its purpose, relevant provider or environment, material limitations and review responsibilities.
References to third-party products do not imply sponsorship or endorsement, and those providers are not parties to the agreement between Insightnix and the Client.
8. Client data and confidentiality
Ownership and permitted use
Client Data and other materials supplied by or for the Client remain the Client’s property or that of its licensors. The Client grants us only the rights reasonably required to deliver, secure and support the Services and meet legal obligations.
We will use Client Data only for the applicable Order, legal compliance, security and the exercise or defence of legal rights. We will not sell it, use it for advertising, use it to train a general-purpose model, publish it on Insightnix or use identifiable Client Data for another client.
Confidential information
Confidential information means non-public business, technical, financial, security or personal information that is marked confidential or would reasonably be understood to be confidential.
Confidential information does not include information that the receiving party can demonstrate was lawfully known without restriction, becomes public without breach, is independently developed without use of the confidential information, or is lawfully received from another person without a duty of confidence.
Use and protection
Each party will use the other’s confidential information only for the contract, protect it using at least reasonable care and disclose it only to personnel, professional advisers and engaged service providers who need it and are bound by suitable confidentiality obligations.
We will limit access to authorised personnel and subprocessors authorised under the applicable data-processing terms. We may create limited logs, validation evidence, project records and technical metadata needed for security, troubleshooting, delivery and audit.
Required disclosure
A party may disclose confidential information where required by law, a court or competent authority. Where legally permitted, it will give prompt notice, cooperate on protective measures and disclose only what is required.
Aggregated and anonymised information
We may use information that has been irreversibly anonymised and aggregated so that neither the Client nor any individual is reasonably identifiable for internal service improvement, capacity planning, security analysis and general statistical understanding. We will not publish identifiable Client performance or confidential benchmarks without permission.
Publicity and case studies
We will not identify the Client, display its logo, publish a case study, disclose its Deliverables or use it as a public customer reference without prior written permission. General anonymous descriptions of capability may be used only where they do not identify the Client or reveal confidential information.
Return and secure disposal
Client Data will be returned or deleted as stated in the Order, section 12 and any applicable processor terms. Physical media, temporary extracts and credentials will be securely disposed of or revoked when no longer needed, subject to legal retention and backup limitations. Non-personal working files are handled according to the Order and our documented retention practices.
9. Intellectual property
Background materials
Each party retains ownership of intellectual property owned or developed independently of the Order. Our background materials include pre-existing and reusable methods, templates, routines, libraries, connectors, utilities, calculation patterns, know-how, documentation structures and generic components that are not uniquely created from the Client’s confidential information.
Client Materials
The Client retains all rights in Client Data, branding, requirements, documentation, specifications and other materials supplied by it. The Client grants us a non-exclusive licence to copy, adapt, transform and otherwise use Client Materials only as reasonably required to provide the Services and meet legal obligations.
Bespoke Deliverables
Ownership or licensing of bespoke Deliverables is as stated in the Order. Once all relevant undisputed fees are paid, copyright owned by Insightnix in bespoke dashboards, reports and documentation expressly identified in the Order as Client-owned is assigned to the Client. We will execute a reasonable confirmatory document if required.
If the Order is silent, upon full payment the Client receives a perpetual, worldwide, royalty-free, non-exclusive licence to use the final Deliverables for its internal business purposes. We retain ownership of background materials, generic components, techniques and know-how embedded in them. Where our background materials are embedded in a Client-owned Deliverable, the Client receives the same licence to use them as necessary to use, maintain and modify that Deliverable for its internal business purposes.
Source files and development artefacts
PBIX files, Tableau workbooks, Excel models, scripts, notebooks, data models, configuration files and other editable source materials are included only to the extent stated in the Order or reasonably required for an agreed handover. Transfer of a final dashboard does not automatically include every working file, development environment, internal note, reusable library, deployment script or third-party component.
Third-party materials
Open-source software, platform components, fonts, data and other third-party materials remain subject to their own licences and are not assigned by us.
Payment and authorised users
No intellectual-property right transfers before full payment of the relevant undisputed fees. The Client may allow its employees and contractors to use the Deliverables for the authorised purpose, provided they comply with applicable restrictions and confidentiality obligations.
Modifications
The Client may configure or modify Deliverables to the extent permitted by the Order and third-party licences. We are not responsible for defects, security issues or incorrect results caused by changes made by the Client or another supplier after handover.
Infringement claims
If a Deliverable created by us is alleged to infringe a third party’s UK intellectual-property right, we may obtain a right to continue use, modify or replace the affected item, or terminate the affected part and refund prepaid unused fees attributable to it.
This remedy depends on prompt notice, our control of the defence and the Client’s reasonable cooperation. It does not apply to Client Materials, combinations required by the Client, unauthorised modifications or use outside the agreed scope.
10. Warranties and disclaimers
Professional standard
We warrant that the Services will be performed with reasonable skill and care by personnel with appropriate experience, consistent with a competent provider of comparable business-intelligence and data services.
Correction period
For 30 days after acceptance of a one-off Deliverable, we will correct at no additional charge a reproducible material defect caused by our failure to implement the agreed requirements, provided the Client notifies us promptly and has not altered the affected component.
Data quality
Unless a comprehensive audit is expressly included, we rely on Client Data and instructions and perform only the validation reasonably associated with the agreed work. We may flag apparent anomalies but do not warrant that source data is complete or accurate or that every error, omission, duplicate, bias or inconsistency will be identified.
Third-party services, security and availability
We do not warrant that a Third-Party Service will be continuously available or that every future provider update will remain compatible. We use reasonable security measures but do not warrant that systems will be uninterrupted or immune from every attack. Refresh schedules may be affected by source availability, provider limits, credentials, gateways, network conditions and Client changes.
Forecasts and analytical models
Dashboards, alerts, statistical analysis, forecasts and machine-learning outputs depend on the data, assumptions, definitions and methods used. Forecasts and model outputs are probabilistic and may be affected by drift, bias, missing information and external events. They are analytical aids, not guarantees of future events, savings, revenue, compliance or business outcomes.
The Client must determine whether model validation, monitoring, explainability, fairness assessment, human oversight or professional review is required for its use case.
No regulated professional advice
Unless expressly included, we do not provide legal, tax, audit, accounting, investment, medical, safety or other regulated professional advice.
Remedy for service defects
If the Client reports a reproducible material failure to meet an express specification within the applicable acceptance or warranty period, our primary obligation is to re-perform or correct the affected Service within a reasonable time. If correction is not reasonably possible, we may refund the fee attributable to the materially defective part.
Excluded warranties
Except for warranties expressly stated in the contract and terms that cannot lawfully be excluded, all implied warranties, conditions and representations—including implied terms as to satisfactory quality, fitness for a particular purpose and achievement of a commercial result—are excluded to the fullest extent permitted in a business-to-business contract. This does not exclude any statutory obligation to exercise reasonable skill and care where it applies.
11. Liability
Liability that is not limited
Nothing in the contract excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, breach of title, deliberate unlawful conduct, the Client’s obligation to pay valid fees, or any other liability that cannot lawfully be excluded or limited.
Excluded loss
Subject to the preceding paragraph, neither party is liable for indirect or consequential loss. We are not liable for loss of profit, revenue, business, contracts, anticipated savings, opportunity, goodwill, reputation or production arising from the Services, whether direct or indirect, except where the Order expressly provides a service credit or another remedy.
Client Materials, systems and third parties
We are not liable to the extent a loss results from inaccurate or incomplete Client Materials, a Client instruction, failure to maintain licences, backups or access controls, unauthorised modification, use outside the agreed purpose, a Client system, a Client-supplied credential, or an outage or change in a Third-Party Service.
We are not liable for loss or corruption that could reasonably have been avoided through the Client’s required backups, security controls or compliance with documented instructions.
General liability cap
Subject to the liabilities that cannot be limited, our total aggregate liability arising from an Order, whether in contract, tort including negligence, misrepresentation, restitution, breach of statutory duty or otherwise, is limited to 100% of the fees paid or payable under that Order during the 12 months immediately preceding the event giving rise to the claim.
For an event arising within the first 12 months of an Order, the general cap is the fees paid or payable for that first 12-month period.
Enhanced liability cap
Our separate total aggregate liability for breach of confidentiality, infringement by a Deliverable created by us, or breach of data-protection obligations arising from an Order is limited to 200% of the fees used to calculate the general cap for the same period.
Application of the caps
Connected acts, omissions or events are treated as one claim for the purpose of the caps. The caps apply in the aggregate and are not multiplied by the number of affected users, records, Deliverables, causes of action or claimants.
The exclusions and limits do not reduce either party’s liability under an express indemnity unless the relevant indemnity expressly states otherwise.
Reasonableness and insurance
The parties agree that the fees, allocation of responsibilities, availability of insurance and opportunity for the Client to obtain additional protection are relevant to the reasonableness of these limitations. A different cap may be agreed in the Order, potentially with an adjusted fee.
Notification and mitigation
A party seeking recovery must notify the other within a reasonable time after becoming aware of the relevant event and take reasonable steps to mitigate avoidable loss. Nothing in this paragraph requires notification earlier than is reasonably practicable or limits a statutory period that cannot lawfully be reduced.
12. Data protection
Each party must comply with applicable data-protection law, including the UK GDPR, the Data Protection Act 2018, relevant provisions of the Data (Use and Access) Act 2025 and PECR where applicable.
Independent controller activities
For business contact, billing, contract, security and compliance information used for our own purposes, each party acts as an independent controller. Our controller processing is described in the Privacy Policy.
Processor relationship
Where we process personal information on behalf of the Client (“Client Personal Data”), the Client is the controller and Insightnix is the processor unless an Order or separate Data Processing Agreement states otherwise. The following terms constitute the parties’ Article 28 processor agreement.
Processing particulars
The subject matter is delivery and support of the Services. Processing lasts for the Order and the applicable deletion or return period.
The nature of processing may include collection, receipt, access, recording, organisation, structuring, storage, retrieval, consultation, validation, transformation, modelling, analysis, visualisation, transmission, restriction, export and deletion. The purpose is to provide the agreed dashboard, reporting, integration, migration, forecasting, support and security activities.
The categories of personal information and people are those described in the Order, documented instructions or Client Materials and may include business contact, employment, customer, supplier, operational, transaction, identifier and usage information relating to employees, workers, customers, users, suppliers, contractors or other persons connected with the Client.
Client obligations
The Client determines the purposes and essential means of processing; gives lawful documented instructions; ensures a lawful basis and appropriate transparency; limits data to what is necessary; handles individual rights; carries out required risk assessments; and does not instruct us to process unlawfully.
The Client must inform us before providing special-category, criminal-offence or other high-risk personal information.
Our processor obligations
We will:
- process Client Personal Data only on documented instructions, including instructions about international transfers, unless UK law requires otherwise; where legally permitted, we will tell the Client before processing required by law;
- immediately inform the Client if, in our reasonable opinion, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it;
- ensure authorised personnel are bound by confidentiality and receive access only where necessary;
- implement appropriate technical and organisational measures proportionate to risk, including access control, authentication, encryption in transit where supported, secure configuration, backup or recovery arrangements where applicable, logging, vulnerability management and incident procedures;
- taking account of the nature of processing, assist the Client through appropriate technical and organisational measures with requests from individuals;
- taking account of the processing and information available, assist the Client with security, breach notification, data-protection impact assessments and prior-consultation obligations;
- notify the Client without undue delay after becoming aware of a personal-data breach affecting Client Personal Data and provide available information reasonably needed for the Client’s assessment and notifications;
- maintain information reasonably necessary to demonstrate compliance with these processor obligations and make it available on request; and
- not combine Client Personal Data with another client’s data except where technically necessary within a properly segregated multi-tenant service.
Subprocessors
The Client gives general written authorisation for us to use subprocessors reasonably required for hosting, cloud, communications, support, security and delivery. We will ensure each subprocessor is bound by written data-protection obligations offering an equivalent level of protection.
On request, we will provide the current categories or list of material subprocessors. We will give reasonable advance notice of a material new subprocessor where practicable, allowing the Client to object on reasonable data-protection grounds. If no reasonable alternative is available, either party may terminate the affected part of the Services without liability for future fees. We remain responsible to the Client for our subprocessor’s performance of its processor obligations.
International transfers
We will not make a restricted transfer of Client Personal Data except on documented instructions and using a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum or another permitted safeguard.
The Client authorises transfers inherent in subprocessors or platforms identified in the Order or otherwise approved under this section.
Deletion and return
At the Client’s choice and subject to payment of undisputed fees, we will return or securely delete Client Personal Data after the Services end and delete existing copies, unless UK law requires retention.
If the Client gives no choice, we may securely delete the Client Personal Data after 30 days. Data in protected backups may remain beyond that period until overwritten in the normal cycle, provided it is put beyond ordinary use and remains protected.
Audit
On reasonable written notice, no more than once in any 12-month period unless required by a regulator or a confirmed material incident, we will provide information reasonably necessary to demonstrate compliance and allow a proportionate audit by the Client or an independent auditor bound by confidentiality.
Audits must avoid unreasonable disruption, protect other clients and systems, and take place during normal business hours. The Client bears its audit costs unless the audit identifies a material breach by us.
Separate Data Processing Agreement
A separate Data Processing Agreement may supplement or replace this section. Where it conflicts, the expressly agreed client-specific agreement prevails for the relevant processing.
13. General
Notices
Operational notices may be sent by email to the designated contacts. A notice of termination or material breach must be clearly identified and sent to the most recent notified business email or registered office, with a copy to any designated contract contact.
An email notice is treated as received when delivered without an error message during normal business hours, or on the next Business Day if sent outside those hours, unless the sender knows it was not received.
Force majeure
Neither party is liable for delay or failure caused by an event beyond its reasonable control, including widespread network or cloud failure, natural disaster, epidemic, industrial dispute, utility failure, war, civil emergency, government action or a cyberattack not caused by that party’s failure to use reasonable measures. Payment obligations are not excused.
The affected party will notify the other and take reasonable steps to mitigate the impact. If a material failure continues for more than 60 days, either party may terminate the affected Service.
Assignment and subcontracting
Neither party may assign an Order without the other’s prior written consent, not to be unreasonably withheld for a bona fide group reorganisation or business transfer. We may assign the contract to a group company or successor to substantially all of the relevant business and may use qualified subcontractors while remaining responsible for the Services as provided by the contract.
Non-solicitation
During an Order and for six months afterwards, neither party will knowingly solicit for employment personnel of the other who were materially involved in the Services, except through a general recruitment campaign not targeted at those personnel. This does not prevent a person from independently applying.
Entire agreement and reliance
The accepted Order, these Terms and any documents expressly incorporated form the entire agreement for the engagement and replace prior proposals and discussions concerning the same subject. Each party acknowledges that it has not relied on a statement not included in the contract, without excluding liability for fraud or fraudulent misrepresentation.
Variation
A change to an active Order must be agreed in writing by authorised representatives. We may update the Website version of these Terms for future Orders.
A material change to an existing recurring engagement takes effect only as permitted by the Order or after reasonable written notice and does not retrospectively alter accrued rights.
Waiver and severability
Failure or delay in exercising a right is not a waiver. A waiver applies only to the specific instance stated.
If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable or, if that is not possible, removed. The remaining contract continues.
Third-party rights
Except where the Order expressly provides otherwise, a person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce the contract. The parties may vary or terminate the contract without the consent of any third party.
Relationship
The parties are independent contractors. The contract does not create a partnership, joint venture, employment, fiduciary or agency relationship, and neither party may bind the other except as expressly authorised.
Dispute escalation
Before commencing court proceedings, senior representatives will attempt in good faith to resolve a dispute through written escalation and a meeting. This does not prevent urgent injunctive relief, debt recovery or action needed to preserve a limitation period.
Governing law and jurisdiction
The contract and non-contractual obligations arising from it are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction unless the Order expressly provides an agreed alternative dispute process or mandatory law requires otherwise.
14. Contact
Insightnix Data Services
Email: build@insightnix.com
Postal address: Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ
Contracting party: For these Terms and each accepted Order, “Insightnix”, “we”, “us” and “our” mean Isodev Limited, a company registered in England and Wales under company number 16866628, whose registered office is at Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ, trading as Insightnix Data Services.
Questions about an active engagement should also be sent to the project contact identified in the applicable Order.
Contract and project correspondence
Please quote the Client name, Order reference and affected Deliverable where available. Do not send production credentials, full datasets or sensitive personal information through an initial ordinary email unless an agreed secure method is unavailable and the transfer is authorised.
Privacy and security matters
Data-subject requests and controller-level privacy concerns should use the route stated in our Privacy Policy. A suspected security incident affecting an active Client environment should also be reported immediately through the project or emergency contact stated in the Order.