Don’t Let Your Domain Be the Weak Link

.

.

.

.

.

.

Let’s talk first…

We’re not a big legal company—we’re a friendly, local business that genuinely wants to help you. If you’re reading these terms because something is unclear, worrying you, or doesn’t seem quite right, please email me at [email protected] or book my diary or call 01675461310.

Legal and technical wording can sometimes make straightforward issues feel more complicated than they really are. We would always much rather have an open conversation, understand the problem and work together to sort it out before anyone feels they need to take a formal or legal route

Discus Systems plc

Business Service Terms

Version: [1.0]
Effective from: 01/01/2026
Published at: https://www.discus.co.uk/msa

These terms explain how we provide our managed IT, cybersecurity, connectivity, cloud, software, hardware and professional services.

We have tried to make them straightforward. Where we use a technical or legal term, we explain what it means.

These terms apply only where the Customer is acting in the course of a business. They are not intended for consumers.


The important things to know

This section highlights the terms most likely to affect the Customer. It forms part of the Agreement, but the detailed sections below provide the full wording.

Most of our services are on 30-day terms

Unless an Order says otherwise, a recurring Service operates on a rolling 30-day basis. Either party may end it by giving at least 30 days’ written notice.

Some Services require us to make a longer commitment to a supplier or network provider. These may have a minimum term, annual commitment, fixed renewal date or longer cancellation period.

Examples include:

The applicable Order will explain the term and cancellation arrangements for these Services. Those specific arrangements take priority over the standard 30-day position.

Cybersecurity reduces risk but cannot remove it

Cybersecurity Services are designed to reduce risk, identify threats and help the Customer respond to incidents. No security product, monitoring service or technical control can guarantee that every attack, vulnerability, data loss or business interruption will be prevented.

The Customer must continue to follow sensible security practices and respond promptly to our recommendations and alerts.

We only provide what has been ordered

The precise Services, equipment, licences, response targets and exclusions are set out in the relevant Order or Service Description. A Service is not included simply because it is commonly provided as part of another managed service package.

Some Services depend on other providers

We use software vendors, cloud providers, carriers, distributors and other specialist suppliers. Their systems, licence terms, service availability and commercial decisions can affect the Services we provide.

Where a third-party provider changes, withdraws or stops supporting a product, we may need to change, replace or discontinue the affected Service.

The Customer also has responsibilities

We need timely access, accurate information, suitable equipment and cooperation from the Customer. The Customer must maintain appropriate insurance, internal procedures and business-continuity arrangements.

Where backups are not expressly included in an Order, the Customer remains responsible for arranging and checking its own backups.

Payment problems can affect the Services

Invoices must be paid by the date shown on them. We may suspend Services where an invoice remains overdue after notice, or immediately where suspension is reasonably necessary to protect systems, data, users or other customers.

Our liability is limited

We accept responsibility where the law requires us to do so. However, our liability is limited in the circumstances explained in section 17. We do not accept unlimited responsibility for indirect losses, lost profit, loss of anticipated savings or problems caused by matters outside our reasonable control.


1. Who the Agreement is between

We, us or Discus means Discus Systems plc, company number 03449736, whose registered office is:

Discus Systems plc
Patrick Farm Barns
Meriden Road
Hampton-in-Arden
Solihull
West Midlands
B92 0LT

Customer or you means the business, organisation or other legal entity identified as the customer in an Order.

Each is a party, and together they are the parties.


2. What makes up the Agreement

2.1 Agreement documents

The agreement between us consists of:

  1. the applicable Order;
  2. any applicable Statement of Work or Service Description;
  3. any applicable data-processing schedule;
  4. these Business Service Terms; and
  5. any third-party licence or service terms that must apply to a particular product or Service.

An Order includes a signed order form, accepted quotation, proposal, statement of work, service schedule, order confirmation or other written record describing the products or Services ordered by the Customer.

2.2 How the Customer accepts the Agreement

The Customer accepts the Agreement when it does any of the following:

The Customer confirms that the person placing or approving an Order has authority to do so on its behalf.

2.3 Priority between documents

Where documents conflict, the following order of priority applies:

  1. the applicable Order or signed Statement of Work;
  2. the applicable data-processing schedule, for data-protection matters;
  3. the applicable Service Description;
  4. these Business Service Terms; and
  5. any proposal, supporting document or third-party terms.

A specific term written into an Order therefore takes priority over a general term in this document.


3. The Services

3.1 What we will provide

We will provide the Services described in the applicable Order with reasonable care and skill.

Depending on what the Customer orders, the Services may include:

3.2 Service boundaries

The Order will identify what is included. Anything not identified as included is outside the scope of the Service and may be quoted or charged separately.

Examples of separately chargeable work may include:

We will normally tell the Customer before carrying out separately chargeable work, except where immediate action is reasonably necessary to contain a security incident or prevent material harm.

3.3 Timing

Any implementation date, delivery date or project milestone is an estimate unless the Order expressly says it is guaranteed.

We are not responsible for a delay caused by:

3.4 Remote and onsite access

The Customer authorises us to access its systems, accounts, networks and premises to the extent reasonably required to provide the Services.

We will follow the Customer’s reasonable safety and security procedures when attending its premises, provided those procedures have been supplied to us in advance.


4. Support and service levels

4.1 Support arrangements

Support hours, contact methods, priorities and response targets will be stated in the applicable Order or Service Description.

A response target is the time in which we aim to acknowledge and begin assessing an issue. It is not a guaranteed resolution time unless the Order expressly says otherwise.

4.2 Resolution

Resolution times can be affected by:

4.3 Maintenance

We may carry out planned and emergency maintenance.

Where reasonably practical, we will provide advance notice of maintenance likely to cause material disruption. Emergency maintenance may be completed without advance notice where this is necessary to protect systems, data or users.


5. Cybersecurity Services

5.1 What security Services are intended to do

Security Services are intended to lower the likelihood or impact of security incidents. They may include monitoring, filtering, alerting, configuration, training, investigation and response.

They are not a guarantee that:

5.2 Shared responsibility

Cybersecurity is a shared responsibility.

The Customer must:

5.3 Security recommendations

We may identify risks or recommend additional products, configuration changes or remedial work.

Unless the relevant work is included in the Order, the Customer decides whether to accept the recommendation and is responsible for the risk of delaying or declining it.

We may ask the Customer to confirm in writing that it has chosen not to act on a material recommendation.

5.4 Security incidents

Unless expressly included in the Order, extensive incident response, forensic investigation, legal support, regulatory reporting, data recovery and system rebuilding are additional Services.

We may take proportionate emergency action where we reasonably believe this is necessary to contain an active threat. This may include disconnecting equipment, disabling accounts, blocking traffic or suspending part of a Service.

We will try to contact the Customer before taking emergency action where it is reasonably safe and practical to do so.

5.5 Testing and monitoring authority

The Customer confirms that it has the legal authority to permit us to monitor, scan, test and manage the systems, users and accounts covered by the Order.

The Customer is responsible for informing its staff and other users about authorised monitoring where required.


6. Backups and recovery

6.1 Backups must be ordered

We are only responsible for backing up data, systems or devices where a backup Service is expressly included in an Order.

Where backup is not included, the Customer remains responsible for:

6.2 Limitations

Backup and recovery Services may be affected by retention periods, storage capacity, connection speed, software compatibility, corrupted source data and the time at which an incident is discovered.

We do not guarantee that every file or system can be restored unless a specific recovery commitment is stated in the Order.

6.3 Customer checks

The Customer must tell us promptly if:


7. Contract length, renewals and cancellation

7.1 Standard 30-day Services

Unless an Order clearly states otherwise, each recurring Service:

Charges remain payable during the notice period.

7.2 Special-Term Services

Some Services require a longer commitment because we must enter into a corresponding commitment with a vendor, licensor, carrier, distributor or other provider.

These Special-Term Services may include:

The applicable Order will state, where relevant:

The terms stated in that Order apply instead of the standard 30-day arrangement.

7.3 Supplier commitments

Where the Customer cancels a Special-Term Service before the end of its committed term, the Customer must pay:

We will not charge more than the amount reasonably required to cover the commitment and costs arising from the cancellation.

7.4 Reducing quantities

A reduction in users, licences, sites, devices, connections or capacity is treated as a partial cancellation.

For standard 30-day Services, the reduction will normally take effect after 30 days’ notice.

For Special-Term Services, the reduction may not take effect until the next renewal or commitment date.

7.5 How to give notice

Cancellation notice must be sent to:

Email: [email protected]

Notice takes effect when received during a Working Day. A notice received outside normal business hours is treated as received on the next Working Day.


8. Products, hardware and software

8.1 Orders for products

An Order for hardware, software or another product is subject to availability and our acceptance.

We may use an equivalent product where the quoted item is no longer available, but we will obtain the Customer’s approval where the replacement materially changes the specification or price.

8.2 Delivery and risk

Risk of physical loss or damage passes to the Customer when a product is delivered to the Customer’s premises or nominated delivery address.

Ownership of a product sold by us does not pass to the Customer until we have received full payment for it.

Until ownership passes, the Customer must:

8.3 Vendor warranties

Where a product is covered by a manufacturer or vendor warranty, we will provide reasonable help to make a valid warranty claim.

Our responsibility does not extend beyond the warranty or remedy available from the manufacturer unless the Order expressly states otherwise or the problem was caused by our failure to use reasonable care and skill.

8.4 Returns

Products ordered specifically for the Customer may not be returnable. Any return is subject to our prior approval and may be subject to restocking, collection, configuration or licence charges.

8.5 Licences

Software and cloud products are licensed rather than sold.

The Customer must comply with:

The Customer must not copy, resell, reverse engineer or permit unauthorised access to licensed products except where the law expressly permits it.


9. Third-party providers

9.1 Use of suppliers

We may use third-party providers to deliver all or part of a Service.

These may include:

We remain responsible for the parts of the Service we have agreed to provide, subject to the limitations in this Agreement.

9.2 Third-party terms

Some products and Services require the Customer to accept additional provider terms.

We will make those terms available where reasonably practical. Use of the relevant product or Service constitutes acceptance of any mandatory end-user terms brought to the Customer’s attention.

9.3 Provider changes

A provider may:

Where this affects the Customer, we will take reasonable steps to explain the impact and, where practical, offer an alternative.

9.4 End-of-life products

We may decline to support equipment, software or systems that are obsolete, unsupported or outside the manufacturer’s recommended lifecycle.

Where we agree to continue limited support:


10. Customer responsibilities

The Customer must:

  1. provide accurate and complete information;
  2. provide timely decisions, approvals, access and assistance;
  3. nominate suitable authorised contacts;
  4. maintain lawful licences for software not supplied by us;
  5. ensure its equipment, cabling, power and environment are suitable;
  6. maintain appropriate internal controls and policies;
  7. ensure that its users follow reasonable instructions;
  8. comply with applicable laws and regulations;
  9. avoid making unauthorised changes to managed systems;
  10. maintain appropriate insurance and business-continuity arrangements; and
  11. cooperate with investigations into faults and security incidents.

We are not responsible for a failure or delay to the extent it results from the Customer’s failure to meet these responsibilities.

Additional work caused by that failure may be charged at our then-current rates after we notify the Customer.


11. Acceptable use

The Customer must not use a Service:

The Customer is responsible for use of the Services by its employees, contractors, guests and authorised users.

We may block or suspend prohibited activity where reasonably necessary.


12. Charges and invoices

12.1 Charges

The Customer must pay the charges stated in the Order, together with VAT and any other applicable tax.

Recurring charges may be invoiced in advance. Usage, project work, additional support and other variable charges may be invoiced in arrears or as stated in the Order.

12.2 Payment

Invoices are payable within the period stated in the Order or on the invoice. Where no payment period is stated, payment is due within 14 days of the invoice date.

12.3 Invoice questions

The Customer must raise a genuine invoice query promptly and provide enough information for us to investigate it.

A query about part of an invoice does not allow the Customer to withhold an undisputed amount.

12.4 Late payment

Where an amount is overdue, we may charge statutory interest, compensation and reasonable recovery costs where legally available.

12.5 Price changes

For standard 30-day Services, we may change charges by giving at least 30 days’ written notice. The Customer may cancel the affected Service before the increase takes effect by giving written notice during that period.

For Special-Term Services, charges may change:

We will give reasonable notice of a supplier-driven increase where the provider gives us sufficient notice.


13. Changes to Services

Either party may propose a change to a Service.

A material change must be recorded in an updated Order, Statement of Work, email approval or other written change record.

We may make non-material operational or technical changes without a formal change record where they:

Where a proposed change materially reduces a standard 30-day Service, the Customer may cancel the affected Service on written notice before the change takes effect.


14. Data protection

14.1 Compliance

Each party will comply with the data-protection laws applicable to it.

The Customer is normally the controller and we are normally the processor where we process personal data on the Customer’s behalf to provide the Services.

Each party may also act as an independent controller for personal data it uses for its own administration, billing, security, legal or regulatory purposes.

14.2 Processing details

The subject matter, duration, purpose and nature of processing, together with the types of personal data and categories of data subjects, are described in:

14.3 Our processor obligations

Where we act as processor, we will:

  1. process personal data only on the Customer’s documented instructions, unless the law requires otherwise;
  2. ensure that authorised personnel are subject to confidentiality obligations;
  3. apply appropriate technical and organisational security measures;
  4. provide reasonable assistance with data-subject requests;
  5. provide reasonable assistance with security, breach-notification and impact-assessment obligations;
  6. notify the Customer without undue delay after becoming aware of a personal-data breach affecting data processed on the Customer’s behalf;
  7. provide information reasonably necessary to demonstrate compliance;
  8. allow proportionate audits subject to reasonable notice, confidentiality and cost arrangements;
  9. return or delete personal data at the end of the Service where reasonably possible and legally permitted; and
  10. tell the Customer where we believe an instruction infringes applicable data-protection law.

14.4 Sub-processors

The Customer gives general authorisation for us to use sub-processors.

We will require a sub-processor handling Customer personal data to protect that data under obligations appropriate to the relevant processing.

We will make current sub-processor information available on request or through our published documentation.

Where practical, we will provide advance notice of a material new sub-processor. The Customer may raise a reasonable data-protection objection. The parties will work in good faith to resolve it, which may include adjusting or ending the affected Service where no reasonable alternative is available.

14.5 International transfers

Where personal data is transferred outside the United Kingdom, we will use a legally recognised transfer mechanism where one is required.

14.6 Customer instructions

The Customer confirms that:


15. Confidential information

Each party must protect the other party’s confidential information and use it only for the purposes of the Agreement.

A party may disclose confidential information:

These obligations do not apply to information that:

This section continues for three years after the Agreement ends. Trade secrets and personal data remain protected for as long as required by law or while they retain their confidential nature.

We will not use the Customer’s name or logo in public marketing without permission.


16. Intellectual property

Each party keeps ownership of the intellectual property it owned before the Agreement.

The Customer owns its data, documents, branding and materials.

We and our licensors retain ownership of:

Once the Customer has paid the relevant charges, it may use deliverables created specifically for it for its own internal business purposes.

Third-party products remain subject to the applicable provider’s licence terms.

The Customer gives us permission to use its materials, systems and data only as reasonably necessary to provide the Services, meet legal obligations and protect the security of the Services.


17. Responsibility and liability

17.1 Responsibilities that cannot be limited

Nothing in the Agreement excludes or limits liability for:

17.2 Types of loss we do not cover

Subject to section 17.1, neither party is liable to the other for:

This exclusion applies whether the loss is direct or indirect, except where an Order expressly provides a specific remedy.

17.3 Data loss and business interruption

We are not responsible for data loss, restoration costs or business interruption to the extent caused by:

This does not exclude responsibility for direct loss caused by our failure to use reasonable care and skill.

17.4 Overall liability cap

Subject to sections 17.1 and 17.5, each party’s total aggregate liability arising from the Agreement in any 12-month period will not exceed the total charges paid or payable by the Customer under the affected Order during that 12-month period.

Where the affected Service has been provided for less than 12 months, the cap will be the charges paid or payable for the period from the Service commencement date to the date of the event giving rise to the claim.

17.5 Matters outside the general cap

The general cap does not limit:

Any separate or increased liability cap must be stated in the applicable Order.

17.6 Third-party networks and services

We are not responsible for failure or delay caused by a communications network, electricity supply, internet provider, cloud platform or other third-party system outside our reasonable control.

Where appropriate, we will provide reasonable assistance to escalate the issue to the relevant provider.

17.7 Claims

A party must notify the other of a claim within a reasonable period after becoming aware of the circumstances giving rise to it and must take reasonable steps to reduce avoidable loss.


18. Suspension

We may suspend some or all of a Service where:

Where the issue is non-payment or another remediable breach, we will normally give the Customer a reasonable opportunity to put things right before suspension.

Advance notice may not be possible in an emergency or active security incident.

The Customer remains responsible for charges during a suspension caused by its breach, non-payment or misuse.

We will restore the Service within a reasonable period after the issue is resolved, subject to any applicable reconnection charges.


19. Ending the Agreement for breach

Either party may end an affected Service immediately by written notice where the other party:

We may use a shorter remedy period where the breach creates an urgent security, legal or operational risk.

Ending one Service does not automatically end the Customer’s other Services.


20. What happens when a Service ends

When a Service ends:

At the Customer’s request, we will provide reasonable transition assistance. Transition work may be charged at our standard rates and depends on the Customer and its replacement provider cooperating with us.

We may retain data where required by law, for legitimate record keeping or within routine backup cycles. Data remaining only in backups will be deleted in accordance with the normal backup-retention process.

The Customer is responsible for requesting any required data export before the Service ends.


21. Events outside reasonable control

Neither party is responsible for a delay or failure caused by an event outside its reasonable control.

This may include severe weather, fire, flood, epidemic, industrial action, war, civil disorder, government action, utility failure, widespread internet failure, supply-chain interruption or a major cyberattack that could not reasonably have been prevented.

The affected party must:

This section does not excuse the Customer from paying for products already supplied or Services already provided.

Where a material Service is unavailable for more than 30 consecutive days because of such an event, either party may end that affected Service by written notice.


22. Changes to these terms

We may update these terms to reflect changes in law, regulation, technology, security requirements or the way we operate.

We will give at least 30 days’ notice of a material change where reasonably practical.

A material change will not retrospectively alter an existing fixed commitment unless:

Where a material change disadvantages the Customer in relation to a standard 30-day Service, the Customer may end the affected Service before the change takes effect.


23. Notices

Formal notices under the Agreement must be sent by email or post to the contact details stated in the Order.

Notices to Discus should be sent to:

Email: [email protected]
Address: Discus Systems plc, Patrick Farm Barns, Meriden Road, Hampton-in-Arden, Solihull, West Midlands, B92 0LT.

An email is treated as received on the Working Day it is sent, provided the sender does not receive a delivery-failure message. An email sent outside normal business hours is treated as received on the next Working Day.

A Working Day is Monday to Friday, excluding public holidays in England.


24. General legal terms

24.1 Entire agreement

The Agreement records the entire agreement between the parties about its subject matter and replaces earlier discussions, proposals and understandings relating to the same Services.

This does not exclude liability for fraud.

24.2 No partnership

The parties are independent contractors. The Agreement does not create a partnership, joint venture, employment or agency relationship.

24.3 Assignment and subcontracting

We may subcontract parts of a Service, but remain responsible for our contractual obligations.

Neither party may transfer the whole Agreement without the other party’s written consent, which must not be unreasonably withheld or delayed.

We may transfer the Agreement as part of a genuine business sale, restructuring or transfer to an associated company, provided this does not materially reduce the Customer’s rights.

24.4 Third-party rights

A person who is not a party to the Agreement has no right to enforce it under the Contracts (Rights of Third Parties) Act 1999.

24.5 Waiver

A delay or failure to exercise a right does not waive that right.

24.6 Severability

If part of the Agreement is found to be invalid or unenforceable, the remaining provisions continue to apply. The parties will replace the affected provision with a lawful provision that most closely reflects its intended commercial effect.

24.7 Resolving disagreements

The parties will first try to resolve a disagreement through their usual account or service contacts.

If it cannot be resolved, either party may refer it to a director or senior manager of each party. The senior representatives will try in good faith to resolve the matter before court proceedings are started.

This does not prevent either party seeking urgent court protection where necessary.

24.8 Governing law

The Agreement and any non-contractual dispute connected with it are governed by the law of England and Wales.

The courts of England and Wales have exclusive jurisdiction.


25. Contacting us

Questions about these terms should be sent to:

Discus Systems plc
Patrick Farm Barns
Meriden Road
Hampton-in-Arden
Solihull
West Midlands
B92 0LT

Email: [email protected]
Telephone: 01675 430080
Website: www.discus.co.uk