Service Level Agreement.
1.Parties, status and contract documents
1.1 This Service Level Agreement (SLA) is between ACS-Apt Computer Systems Ltd., a company incorporated in England and Wales (ACS-APT or Supplier), and the business customer identified in the applicable Order Form (Customer). Each party warrants that it is acting wholly or mainly for purposes relating to its trade, business, craft or profession and not as a consumer.
1.2 The Contract consists of: (a) the Order Form; (b) any signed Country Addendum; (c) this SLA, including its schedules; (d) any statement of work (SOW); and (e) third-party terms expressly identified in the Order Form and made available to the Customer before signature.
1.3 If there is a conflict, the documents prevail in the order listed in clause 1.2, except that Schedule 2 prevails for the processing of personal data. A third party’s terms govern only that third party’s software or service and do not expand ACS-APT’s obligations.
1.4 Headings do not affect interpretation. “including” means including without limitation. A reference to legislation includes amendments and subordinate legislation in force from time to time.
2.Definitions
2.1 Business Day means a day other than Saturday, Sunday or a public holiday in England when banks in London are open for business. Business Hours means 09:00–17:00 UK time on a Business Day, unless the Order Form states otherwise.
2.2 Customer Data means all data supplied by or on behalf of the Customer or accessed by ACS-APT in providing the Services. Documentation means user and technical materials supplied with the Services. Incident means a reproducible failure of Supported Software to perform materially in accordance with its Documentation. Order Form means the ordering document signed by both parties. Services means the services described in the Order Form or SOW. Supported Software means the software expressly listed in the Order Form.
2.3 Service Request means a request for information, configuration, training, enhancement or other assistance that is not an Incident. Third-Party Services means software, hosting, telecommunications or services supplied by a person other than ACS-APT.
3.Scope of Services
3.1 During the Term and subject to payment, ACS-APT shall provide the Services with reasonable skill and care and in material accordance with the Contract.
3.2 Standard support includes telephone and remote troubleshooting for Supported Software during Business Hours. It does not include user training, customisation, report or screen changes, database programming, data correction, upgrades, installations, backup administration, infrastructure maintenance, or support for products not supplied or expressly supported by ACS-APT, unless included in an Order Form or SOW.
3.3 The first 30 minutes of initial diagnosis for an Incident is included in annual telephone support unless the Order Form states otherwise. Work that is out of scope, caused by a Customer dependency, or approved as chargeable is billed at the applicable rates after ACS-APT has notified the Customer and obtained approval, except for urgent protective action reasonably necessary to prevent material harm.
3.4 ACS-APT may contact relevant third-party providers on the Customer’s behalf. Their response, remediation, availability and platforms remain outside ACS-APT’s control. ACS-APT remains responsible for properly performing the coordination obligations it has expressly accepted.
4.Support process and service level
4.1 The Customer shall report Incidents through support@acs-apt.com or +44 (0)1923 244 444 and provide the affected system, users, business impact, error messages, steps to reproduce, recent changes and an authorised contact.
4.2 ACS-APT will assign the priority after reasonable consultation with the Customer. It may reclassify a ticket where the reported impact does not match the definitions below, giving reasons. Response means acknowledgement by a suitably qualified person who begins triage; it does not mean resolution.
| Priority | Definition | Initial response target | Update target | Restoration / resolution objective |
|---|---|---|---|---|
| P1 Critical | Production unavailable or severe security event; no reasonable workaround; material business-wide impact. | 4 Business Hours | Every 4 Business Hours | Continuous reasonable efforts during Business Hours; workaround or recovery plan within 1 Business Day. |
| P2 High | Major function materially impaired; multiple users affected; limited workaround. | 8 Business Hours | Each Business Day | Workaround or plan within 2 Business Days; target fix agreed after diagnosis. |
| P3 Normal | Non-critical defect; limited impact; reasonable workaround available. | 2 Business Days | Every 3 Business Days | Target fix in a maintenance release or mutually agreed plan. |
| P4 Request | Information, training, configuration, enhancement or cosmetic issue. | 5 Business Days | As agreed | Estimate and schedule by agreement; may be chargeable. |
Service-level measurement: targets run only during Business Hours, start when ACS-APT has received enough information and access to investigate, and pause while awaiting the Customer or a third-party dependency. Planned maintenance, Force Majeure Events and excluded causes do not count. Unless an Order Form expressly states service credits, these are performance objectives and not guaranteed resolution times; repeated material failure may constitute material breach under clause 15.
5.Customer responsibilities and remote accessing
5.1 The Customer shall maintain competent administrators, trained users, supported and lawfully licensed software, current backups tested for restoration, appropriate cyber-security controls, and compatible infrastructure. The Customer remains responsible for deciding whether the Services are suitable for its legal, tax, accounting and operational requirements.
5.2 The Customer shall provide timely, secure and least-privilege access reasonably required for support. Remote access must be approved and configured by the Customer or its IT provider using agreed tools and multi-factor authentication where available. ACS-APT shall use access only to provide the Services and shall apply its security obligations under Schedule 2.
5.3 ACS-APT is not responsible for delay caused by missing access, information, approvals, licences or backups. Any charge for wasted time must be reasonable, evidenced and notified before further chargeable work where practicable.
5.4 The Customer shall not submit unlawful, malicious or infringing content, circumvent licence controls, or permit unauthorised access to software or credentials.
6.Third-Party Services and cloud services
6.1 The Customer’s right to use Third-Party Services is subject to the applicable provider terms disclosed before purchase. The Customer authorises ACS-APT to accept those terms on its behalf only where the Order Form expressly says so.
6.2 ACS-APT does not warrant uninterrupted Third-Party Services and is not liable for a third party’s independent acts or omissions. This does not exclude ACS-APT’s liability for negligent selection, configuration or management of that third party where those activities form part of the Services.
6.3 Data hosted on a third-party platform is governed by the parties’ respective data-protection roles, Schedule 2, and the identified provider terms. Nothing in the Contract transfers ACS-APT’s own legal obligations to the Customer or provider.
7.Fees, invoicing, taxes and late payment
7.1 Fees and billing frequency are set out in the Order Form. Unless stated otherwise, third-party products and annual renewals are invoiced in advance; consultancy projects require 50% on signature and the balance by agreed milestones; and invoices are payable within 30 days (unless agreed otherwise) of invoice date in the invoiced currency without deduction or set-off, except as required by law.
7.2 Fees exclude VAT and similar sales, use, withholding or indirect taxes. The Customer shall pay applicable taxes, except taxes on ACS-APT’s net income. If law requires withholding, the Customer shall provide official evidence and, unless prohibited, gross up the payment so ACS-APT receives the amount it would have received without withholding.
7.3 A genuine invoice dispute must be notified promptly with reasonable particulars. The undisputed amount remains payable. The parties shall work in good faith to resolve the dispute; failure to dispute within seven Business Days does not waive a valid defence or make an incorrect invoice conclusive.
7.4 On overdue sums, ACS-APT may claim statutory interest, fixed compensation and reasonable recovery costs under the Late Payment of Commercial Debts (Interest) Act 1998, where applicable, or any equivalent mandatory local-law remedy. No double recovery is permitted.
7.5 Quoted day, half-day, hourly, premium and expense rates are those stated in the Order Form or then-current rate card supplied before work is authorised. ACS-APT may change recurring fees on renewal by at least 60 days’ written notice, except pass-through third-party increases, which may be applied on the notice reasonably available from the provider.
8.Term, renewal and suspension
8.1 The Contract starts on the date stated in the Order Form. Unless stated otherwise, the initial term is 12 months, and it renews for successive 12-month periods unless either party gives at least three calendar months’ written notice before the current term ends.
8.2 Third-party subscriptions may be non-cancellable for their committed period and renew under provider rules disclosed in the Order Form. Prepaid fees are non-refundable except where the Contract expressly provides or mandatory law requires.
8.3 ACS-APT may suspend affected Services on at least five Business Days’ notice if an undisputed amount remains unpaid after its due date, or immediately to address an urgent security, legal or licence risk. Suspension must be proportionate, limited where practicable, and lifted promptly when the cause is remedied. Where the customer repeatedly fails to pay on time or is in financial difficulty, ACS-APT may terminate the contract by giving 30 day notice. License/service suspension or contract termination does not waive payment obligations.
9.Intellectual property and licenses
9.1 Each party retains ownership of intellectual property owned or developed independently of the Contract. Third-party intellectual property remains subject to the provider’s licence.
9.2 Subject to payment, ACS-APT grants the Customer a non-exclusive, non-transferable (except under clause 18.3), worldwide licence during the relevant service term to use deliverables created specifically for the Customer for its internal business purposes. ACS-APT retains its tools, templates, methods, know-how, generic code and reusable components, including improvements.
9.3 Unless an SOW expressly transfers source code or ownership, bespoke development does not include a transfer of source code or intellectual-property rights. Any escrow, source-code access or broader licence must be stated in an SOW.
9.4 ACS-APT warrants that, to its knowledge, its original deliverables do not infringe UK intellectual-property rights. Its obligation is to obtain a right to continue use, modify or replace the affected item, or terminate it and refund prepaid unused fees. This does not apply to Customer materials, instructions, combinations not supplied by ACS-APT, or unauthorised changes.
10.Confidentiality
10.1 Each recipient shall protect the other party’s Confidential Information using at least reasonable care, use it only for the Contract, and disclose it only to personnel, professional advisers and approved subcontractors who need to know and are bound by confidentiality duties.
10.2 Confidential Information excludes information that is public without breach, already lawfully known, independently developed, or lawfully received without restriction. A recipient may disclose information where legally required after giving advance notice where lawful.
10.3 These duties continue for five years after termination, and indefinitely for trade secrets and personal data for so long as they remain protected by law.
11.Data protection and security
11.1 Each party shall comply with Data Protection Laws applicable to it. “Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and legislation amending or replacing them, including relevant provisions brought into force under the Data (Use and Access) Act 2025, plus mandatory data-protection law identified in a signed Country Addendum.
11.2 For business contacts and contract administration, each party normally acts as an independent controller and shall provide its own privacy information and lawful basis. The parties do not rely on contractual “consent” where consent is not the appropriate lawful basis.
11.3 Where ACS-APT processes personal data on the Customer’s behalf, Schedule 2 applies and forms a binding processor agreement. The Order Form must complete the processing particulars. If particulars are incomplete, ACS-APT shall process only what is reasonably necessary to provide support until they are documented.
11.4 Each party shall notify the other without undue delay of a material security incident relevant to the other party and cooperate as required by law. ACS-APT shall not access Customer Data except as necessary to provide the Services, comply with law, or protect the Services and users.
Where required by applicable data protection law, the Company will facilitate the exercise of individuals’ rights in relation to their personal data. These may include the rights to:
be informed about the processing of their personal data;
access their personal data;
have inaccurate personal data rectified and incomplete data completed;
have personal data erased in certain circumstances;
restrict the processing of personal data in certain circumstances;
receive and transmit personal data under the right to data portability, where applicable;
object to processing in certain circumstances;
withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
not be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects, except where permitted by law and subject to applicable safeguards; and
lodge a complaint with the Information Commissioner’s Office (ICO).
These rights are subject to the conditions, limitations and exemptions provided by applicable law.
All requests relating to individual rights must be forwarded immediately to the Data Protection Lead. The Company will verify the identity of the requester where necessary using measures that are reasonable and proportionate to the circumstances.
The Company will respond to valid requests without undue delay and, in accordance with the UK GDPR, normally within one month of receipt. Where permitted by law, this period may be extended by up to a further two months, taking into account the complexity and number of requests. The individual will be informed of any extension, and the reasons for it, within the initial one-month period.
Requests will normally be handled free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Company may, where permitted by law, charge a reasonable fee reflecting the administrative costs involved or refuse to act on the request.
The Company will maintain appropriate records of rights requests and their handling, including identity verification where applicable, searches undertaken, information reviewed or disclosed, redactions, exemptions relied upon, decisions made and communications with the individual.
Rights Request contact: contact@acs-apt.com
ACS-APT Computer Systems Ltd
Unit 22, Empire Centre,
Imperial Way
Watford
Hertfordshire
WD24 4YH
12.Use of Client Name, Logo and Brand As
12.1 ACS-APT may reference the Client in connection with case studies, presentations, marketing and promotional activities, corporate communications, blogs and media articles, including on its website and social media content.
ACS-APT may also, where appropriate, tag the Client on social media and share or repost promotional content that the Client has made publicly available.
Unless expressly agreed otherwise in writing, ACS-APT will obtain the Client’s prior written consent before publishing any case study or using the Client’s name, logo, trademarks, or other brand assets for marketing or promotional purposes.
Any such use will be in accordance with the Client’s applicable brand guidelines provided to ACS-APT and will not imply any endorsement by the Client beyond the scope of the parties’ commercial relationship.
13.Compliance in international business
13.1 Each party shall comply with laws applicable to its own performance, including the Bribery Act 2010 and applicable anti-bribery, anti-money-laundering, sanctions, export-control and trade laws. Neither party shall require the other to act unlawfully.
13.2 The Customer is responsible for local registration, sector, tax, employment, records, localisation, accessibility and content requirements arising from its use of the Services outside the United Kingdom. ACS-APT is responsible for laws applying to it as a UK supplier.
13.3 Before deployment in a country with mandatory local requirements including any relevant federal, state, free-zone or sector regime—the parties shall sign a Country Addendum allocating the required controls. References to regions or countries in sales materials do not constitute a warranty of universal legal compliance.
13.4 ACS-APT may refuse or suspend performance to the extent reasonably necessary to comply with sanctions, export controls or other law, after notice where lawful, and shall seek a lawful alternative where commercially reasonable.
14.Liability
14.1 Nothing in the Contract limits or excludes liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; breach of title implied by section 12 of the Sale of Goods Act 1979 or section 2 of the Supply of Goods and Services Act 1982 where applicable; deliberate default; or any liability that cannot lawfully be limited or excluded.
14.2 Subject to clause 14.1, neither party is liable for loss of profit, revenue, anticipated savings, goodwill, business opportunity, or for indirect or consequential loss. Loss of or corruption to data is excluded only to the extent it was avoidable by the Customer maintaining the backups required by clause 5.1.
14.3 Subject to clauses 14.1 and 14.4, each party’s aggregate liability arising from the Contract in any rolling 12-month period shall not exceed 100% of the fees paid or payable under the affected Order Form in that period. If the event occurs in the first 12 months, the cap is 100% of the fees paid or payable for that initial 12-month period.
14.4 The aggregate cap for breach of confidentiality, data-protection obligations, and infringement of the other party’s intellectual property is 150% of the amount calculated under clause 14.3. Payment obligations and the Customer’s liability for unlawful use or infringement of ACS-APT or third-party intellectual property are not reduced by clause 14.3.
14.5 The parties agree that these limitations allocate risk in a B2B contract and have been reflected in the fees and insurance available. Each limitation is separate and applies only to the extent it satisfies the reasonableness requirement under the Unfair Contract Terms Act 1977 where that Act applies.
15.Termination and exit
15.1 Either party may terminate an affected Order Form immediately by written notice if the other party commits a material breach that is not remedied within 30 days after written notice, or enters insolvency proceedings other than a solvent restructuring.
15.2 ACS-APT may terminate for persistent non-payment of undisputed sums after following clause 8.3. A termination notice must identify the affected contract and effective date.
15.3 On termination, accrued rights survive; licences end except to the extent perpetual; the Customer shall pay properly due fees; each party shall return or securely delete the other’s Confidential Information, subject to legal retention; and clauses intended to survive shall do so.
15.4 At the Customer’s written request made before termination or within 30 days after it, ACS-APT shall provide reasonable transition assistance and export Customer Data in a commonly used format, subject to third-party capabilities. Assistance beyond routine return or deletion may be charged at pre-agreed rates. ACS-APT shall not withhold Customer Data solely because an unrelated invoice is disputed.
16.Force majeure
16.1 Neither party is liable for delay caused by an event beyond its reasonable control that could not reasonably have been avoided or overcome, excluding lack of funds (Force Majeure Event). The affected party shall promptly notify the other, mitigate the effects, and resume performance as soon as reasonably practicable.
16.2 Payment obligations already accrued are not excused. If a Force Majeure Event materially prevents an affected Service for more than 30 consecutive days, either party may terminate that Service on written notice and ACS-APT shall refund prepaid fees for the unused period, excluding committed non-refundable third-party charges disclosed before purchase.
17.Disputes, governing law and jurisdiction
17.1 A party shall first give written details of a dispute to the other. An operational representative shall meet within 10 Business Days; if unresolved, a senior representative shall meet within a further 10 Business Days. The parties may then attempt mediation under the CEDR Model Mediation Procedure.
17.2 Nothing prevents urgent injunctive relief, debt proceedings for undisputed sums, preservation of limitation rights, or regulatory reporting.
17.3 The Contract and any non-contractual obligations are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, except that ACS-APT may seek interim or protective relief in any competent jurisdiction and mandatory local law may apply despite this clause.
18.General
18.1 Notices must be in writing and delivered by hand, prepaid tracked post/courier, or email to the legal notice contact in the Order Form. Email is received on the next Business Day if sent after 17:00 UK time or on a non-Business Day. This clause does not govern service of court proceedings.
18.2 Neither party may assign the Contract without the other’s prior written consent, not to be unreasonably withheld or delayed, except to an Affiliate or as part of a merger or sale of substantially all relevant business, provided the assignee is capable of performance and is not a sanctioned person or direct competitor of the non-assigning party.
18.3 ACS-APT may use subcontractors but remains responsible for their performance of its obligations. Data subprocessors are governed by Schedule 2.
18.4 No variation is effective unless in writing and signed by authorised representatives, except operational service procedures that do not reduce contractual rights. A failure or delay to enforce a right is not a waiver.
18.5 If a provision is invalid, it shall be modified to the minimum extent necessary or deleted, and the remainder continues. The Contract is the entire agreement and supersedes prior statements, but does not exclude liability for fraud or fraudulent misrepresentation.
18.6 No person other than a party has rights under the Contracts (Rights of Third Parties) Act 1999. The parties are independent contractors; nothing creates agency, partnership or employment.
18.7 The Contract may be signed in counterparts and electronically. Each signatory warrants authority to bind the relevant party.
Schedule 1 – Order Form and Service Particulars
This policy will be reviewed at least annually and sooner after significant legal guidance, business change, technology change, audit findings, material incidents or changes in processing risk. The document owner will retain approval and version records.
Exceptions require a documented business justification, risk assessment, compensating controls, time limit and written approval from the
| Item | Agreed particulars |
|---|---|
| Customer legal name / number / registered address | |
| Customer notice contact and email | |
| ACS-APT notice contact | |
| Effective date / initial term / renewal | |
| Supported Software and versions | |
| Services and exclusions | |
| Business Hours / time zone / holiday calendar | 09:00–17:00 UK time, England public holidays |
| Fees, currency, taxes and payment terms | |
| Service credits, if any | |
| Approved remote-access method | |
| Third-party terms and committed charges | |
| Country Addenda | |
| Liability cap variation / insurance requirement | |
| SOWs and special exit assistance |
Schedule Minimum implementation action
This Schedule applies where ACS-APT processes personal data on behalf of the Customer. The Customer is the controller and ACS-APT is the processor unless the processing particulars state otherwise.
S2-1. Processing particulars
S2-1.1 Subject matter and duration: remote support, implementation, maintenance, hosting coordination and related Services for the Term plus the limited return/deletion period.
S2-1.2 Nature and purpose: access, consultation, retrieval, testing, troubleshooting, transmission, backup where expressly ordered, and deletion as necessary to provide the Services.
S2-1.3 Categories of data subjects: Customer personnel, users, customers, suppliers and other individuals whose data is contained in systems presented for support. Types of personal data: identifiers, business contact data, account and usage data, support communications, device/network data, and application data identified below. Special-category or criminal-offence data is prohibited unless expressly identified and appropriate safeguards are agreed.
S2-1.4 Customer instructions, retention, approved locations and any additional categories must be completed in the table below.
The Parties shall provide the required details as listed in the below table
| Sr# | Required field | Agreed detail |
|---|---|---|
| 1 | Applications and datasets in scope | |
| 2 | Data-subject categories | |
| 3 | Personal-data types | |
| 4 | Processing locations | |
| 5 | Approved sub-processors (If applicable) | |
| 6 | International transfer mechanism (If applicable) |
S2-2. Processor obligations
S2-2.1 ACS-APT shall process personal data only on documented Customer instructions, including for international transfers, unless UK law requires otherwise; in that event it shall inform the Customer before processing unless prohibited. It shall immediately inform the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
S2-2.2 ACS-APT shall ensure authorised personnel are bound by confidentiality; implement appropriate technical and organisational measures under Article 32 having regard to risk; and not sell, monetise or use Customer personal data for its own marketing.
S2-2.3 Taking account of the nature of processing, ACS-APT shall assist the Customer by appropriate measures with data-subject requests and, taking account of information available, with security, breach notification, data-protection impact assessments and prior consultation. Reasonable assistance beyond ordinary Services may be chargeable where the need was not caused by ACS-APT’s breach.
S2-2.4 ACS-APT shall notify the Customer without undue delay after becoming aware of a personal-data breach and provide available information reasonably required for the Customer’s assessment and notifications. Notice is not an admission of fault.
S2-2.5 At the Customer’s choice and on termination, ACS-APT shall return or delete personal data and copies unless law requires retention. Routine support extracts will ordinarily be deleted within 30 days after ticket closure, subject to agreed backup cycles and legal holds.
S2-3. Subprocessors
S2-3.1 The Customer gives general written authorisation for the subprocessors identified in the processing particulars or current list. ACS-APT shall give at least 30 days’ prior notice of a new or replacement subprocessor where reasonably practicable.
S2-3.2 The Customer may object on reasonable data-protection grounds within 15 days. The parties shall seek a reasonable solution; if none is available, the Customer may terminate only the affected Service without penalty and receive a pro-rata refund of prepaid unused fees, excluding non-refundable third-party commitments disclosed before purchase.
S2-3.3 ACS-APT shall impose materially equivalent Article 28 obligations on each subprocessor and remains responsible to the Customer for that subprocessor’s performance of those obligations.
S2-4. International transfers
S2-4.1 Neither party shall make a restricted transfer of personal data unless a lawful transfer mechanism and required supplementary measures are in place. For transfers from the United Kingdom, the parties shall use applicable UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism.
S2-4.2 Where Customer personal data is subject to the EEA GDPR or another mandatory transfer regime, the relevant Country Addendum shall incorporate the required clauses and priority terms. Each party shall provide information reasonably required for a transfer-risk assessment and suspend an affected transfer if the mechanism becomes invalid and no lawful alternative is available.
S2-5. Audit and information rights
S2-5.1 ACS-APT shall make available information reasonably necessary to demonstrate compliance. The Customer may conduct one audit in any 12-month period on at least 20 Business Days’ notice, and additional audits after a material breach or regulator request.
S2-5.2 Audits shall occur during Business Hours, avoid unnecessary disruption, protect other customers’ information, and use independent reports or certifications where sufficient. The Customer bears its audit costs and ACS-APT may charge reasonable assistance costs, except where an audit identifies ACS-APT’s material non-compliance.
S2-5.3 Nothing requires disclosure that would compromise security, legal privilege, third-party confidentiality or another customer’s data; ACS-APT shall provide a reasonable alternative form of assurance.