Terms of service
These terms of service (the Terms) make a contract between The Curve Consulting Services Limited, a company registered in England and Wales under company number 11843070, with its registered office at 4 Joiner Street, Sheffield, S3 8GW (we, us, our), and the business that registers for Bitmap (the Customer, you, your).
Please read these Terms carefully.
1. Definitions
In these Terms:
Authorised User means a person whom you allow to use the Service through your Workspace, for example your employees and contractors.
Business Day means a day other than a Saturday, a Sunday or a public holiday in England.
Customer Data means the data that you or your Authorised Users put into the Service, or that the Service gets from a Third-Party Service for you. This includes the Personal Data in Schedule 1.
Data Protection Legislation means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and every law that changes or replaces them.
Documentation means the user guides and help pages for the Service that we publish.
Fees means the fees for your Plan, as shown at sign up or on the billing page of the Service.
Plan means the subscription plan that you choose, which sets the features, the number of Authorised Users and the Fees.
Service means Bitmap, the hosted business management software that we provide, with its applications, its APIs and its Documentation.
Subscription Period means the billing period of your Plan, for example one month or one year.
Third-Party Service means a product or a service that a third party provides, which you connect to the Service, for example Xero, Jira, Slack, HubSpot, Google Workspace or CharlieHR.
UK GDPR has the meaning given to it in section 3(10) of the Data Protection Act 2018.
Workspace means the separate instance of the Service that we make for you, at its own web address.
Words such as including and for example do not limit the words before them. A reference to a law includes that law as amended or replaced.
2. The contract
2.1 You accept these Terms when you tick the box to accept them during sign up, or when you first use the Service, whichever happens first.
2.2 The person who accepts these Terms for you promises that they have the authority to make this contract for the business.
2.3 These Terms, Schedule 1, and any order form that we both sign, make the whole contract between you and us (the Contract). If there is a conflict, a signed order form has priority, then Schedule 1 for data protection, then these Terms.
3. Business use only
3.1 The Service is for business use only. You promise that you make this Contract for your trade, business, craft or profession, and not as a consumer.
3.2 We do not make the Service available to consumers. If you are a consumer, you must not use the Service.
4. The Service
4.1 We give you, during the Contract, a non-exclusive, non-transferable right for your Authorised Users to use the Service for your internal business purposes. This right is subject to these Terms and to the limits of your Plan.
4.2 We can change the Service, including to add, change or remove features. If a change materially reduces the functionality of your Plan, we will tell you at least 30 days before it. You can then end the Contract under clause 20.3, and we will refund the Fees that you paid for the time after the end.
4.3 We can offer features that we mark as "beta", "preview" or "early access". We provide those features "as is". We can change or remove them at any time, and clause 16.1 does not apply to them.
4.4 We provide support by email at help@support.thecurve.io on Business Days, between 9:00 and 17:30 UK time. We will use reasonable efforts to reply promptly. We do not promise a response time unless an order form says so.
5. Accounts and Authorised Users
5.1 The person who registers becomes the first user of your Workspace. They can invite other Authorised Users and give them roles.
5.2 You are responsible for:
(a) the acts and the omissions of your Authorised Users, as if they were your own;
(b) making sure that each Authorised User keeps their password and their sign in details secret, and uses a separate account;
(c) the roles and the permissions that you give to your Authorised Users; and
(d) making sure that the number of Authorised Users does not exceed the limit of your Plan.
5.3 You must tell us promptly at help@support.thecurve.io if you know of, or suspect, unauthorised access to your Workspace.
5.4 You must give accurate details at sign up, and keep your contact and billing details up to date.
6. Acceptable use
6.1 You must not, and you must make sure that your Authorised Users do not:
(a) use the Service in a way that breaks a law or a regulation, or that infringes the rights of another person;
(b) upload a virus, malware or other harmful code;
(c) try to get unauthorised access to the Service, to another Workspace, or to the systems that host the Service;
(d) test the security of the Service, or scan it for weaknesses, without our written permission;
(e) put an unreasonable load on the Service, including with automated requests that exceed the published rate limits;
(f) copy, change, decompile or reverse engineer the Service, except as the law allows and cannot be excluded by contract;
(g) sell, rent, sublicense or otherwise make the Service available to a third party, other than to your Authorised Users;
(h) use the Service to build a competing product; or
(i) upload Customer Data that you do not have the right to upload.
6.2 If you break clause 6.1, we can suspend your access under clause 19.
7. Free trials
7.1 We can offer a free trial of the Service. The trial lasts for the period that we show at sign up.
7.2 At the end of the trial, the Service stops unless you choose a paid Plan and give valid payment details.
7.3 During a free trial, we provide the Service "as is". Clause 16.1 does not apply, and our total liability to you is limited as defined in clause 18.6.
8. Fees and payment
8.1 You must pay the Fees for your Plan in advance, at the start of each Subscription Period.
8.2 You pay by card or by another method that we accept, through our payment provider, Stripe Payments UK Ltd. You authorise us and our payment provider to charge your payment method for the Fees at the start of each Subscription Period, until you cancel.
8.3 Your subscription renews automatically at the end of each Subscription Period, for a new Subscription Period of the same length, until you cancel it under clause 20.2.
8.4 If you add Authorised Users or move to a higher Plan during a Subscription Period, we charge a pro rata amount for the rest of that period. If you remove Authorised Users or move to a lower Plan, the change starts at the next Subscription Period. We do not refund the difference.
8.5 The Fees do not include VAT. You must pay VAT, and any other applicable tax, at the rate in force at the time.
8.6 We can change the Fees. We will tell you at least 30 days before a change. The change starts at your next Subscription Period after the notice ends. If you do not accept the change, you can cancel before it starts.
8.7 If a payment fails, we will tell you and try the payment again. If you do not pay within 14 days after our notice, we can suspend your access under clause 19 until you pay.
8.8 We can charge interest on an overdue amount under the Late Payment of Commercial Debts (Interest) Act 1998.
8.9 The Fees are not refundable, except as these Terms say.
9. Customer Data
9.1 You own the Customer Data. We do not get any rights in it, except as these Terms say.
9.2 You give us a non-exclusive, worldwide, royalty-free licence to host, copy, process, transmit and display the Customer Data. This licence is only for us to provide the Service to you, to support you, to keep the Service secure, and to obey the law.
9.3 You are responsible for:
(a) the accuracy, the quality and the legality of the Customer Data;
(b) the way in which you got the Customer Data; and
(c) making sure that you have the rights, the consents and the lawful bases that the law requires for us to process the Customer Data under these Terms.
9.4 We can collect data about how people use the Service, for example the features that they use and the performance of the Service (Usage Data). We can use Usage Data to run, maintain and improve the Service. We will only share Usage Data with third parties in a form that does not identify you or any person.
9.5 We take regular backups of the Customer Data. If Customer Data is lost or damaged, our only obligation is to use reasonable efforts to restore it from our latest backup. This is your only remedy, and clause 18.4 applies. We do not promise that a backup will be complete or that a restore will succeed. You must keep your own copies of Customer Data that is important to you. The Service lets you export your data.
10. Third-Party Services
10.1 The Service can connect to Third-Party Services. You decide which Third-Party Services to connect.
10.2 When you connect a Third-Party Service, you authorise us to access it and to exchange data with it for you.
10.3 Your use of a Third-Party Service is subject to the terms of its provider. The contract for the Third-Party Service is between you and its provider. We are not a party to it.
10.4 We do not control Third-Party Services, and we are not responsible for:
(a) their availability, their accuracy, their security or their changes;
(b) the data that a Third-Party Service sends to the Service, or what a Third-Party Service does with the data that the Service sends to it; or
(c) a loss that a Third-Party Service causes, including a limit or a change to its API.
10.5 We can stop supporting a Third-Party Service. If possible, we will tell you in advance.
11. Not professional advice
11.1 The Service calculates and shows financial and operational information, for example budgets, invoices, deferred income, cash flow, profitability, utilisation and other reports and KPIs. That information depends on the Customer Data and on the data from Third-Party Services.
11.2 The Service is a tool. It does not give accounting, tax, legal, financial or employment advice. You are responsible for checking the information that the Service shows before you rely on it. You are responsible for your invoices, your accounts, your tax returns and your decisions.
12. Intellectual property
12.1 We, or our licensors, own all the intellectual property rights in the Service, including the software, the design, the Documentation and the Usage Data. You do not get any rights in the Service, except the right of use in clause 4.1.
12.2 Some parts of the Service use open source software. The licence of each open source component applies to that component.
12.3 If you or your Authorised Users give us suggestions or feedback about the Service, we can use them without restriction and without payment to you.
13. Confidentiality
13.1 Confidential Information means information that one party (the discloser) gives to the other party (the recipient) under the Contract, which is marked as confidential or which a reasonable person would understand to be confidential. Customer Data is your Confidential Information.
13.2 The recipient must:
(a) keep the Confidential Information of the discloser confidential;
(b) use it only to perform the Contract or to use the Service; and
(c) disclose it only to its employees, contractors, sub-processors and professional advisers who need to know it, and who have obligations of confidentiality no less strict than this clause.
13.3 Clause 13.2 does not apply to information that:
(a) is or becomes public, other than because the recipient broke this clause;
(b) the recipient had lawfully before the discloser gave it;
(c) the recipient gets lawfully from a third party without an obligation of confidentiality; or
(d) the recipient develops independently.
13.4 The recipient can disclose Confidential Information if a law, a court or a regulator requires it. If the law allows, the recipient must tell the discloser first.
13.5 This clause 13 continues for five years after the Contract ends.
14. Data protection
14.1 For the Personal Data in the Customer Data, you are the controller and we are your processor. Schedule 1 applies to that processing, and it is part of these Terms.
14.2 For the personal data that we collect to run our business, for example the name, the email address and the billing details of the people who manage your account, we are the controller. Our privacy policy at https://bitmap.app/privacy describes how we process that data.
15. Availability
15.1 We will use reasonable efforts to keep the Service available 24 hours a day, seven days a week.
15.2 We do not promise that the Service will be available at all times, or that it will be free from errors. The Service can be unavailable because of:
(a) planned maintenance, which we will try to do outside UK business hours, and tell you about in advance when it is reasonably practical;
(b) emergency maintenance or a security fix;
(c) a failure of a Third-Party Service, of the internet, or of a provider of hosting or networks; or
(d) an event under clause 23.
15.3 We do not give a service level agreement or service credits unless an order form that we both sign says so.
15.4 We have no liability for a period in which the Service is unavailable, interrupted or slow. Clause 18.4 applies.
16. Warranties
16.1 We promise that:
(a) the Service will perform materially as the Documentation describes; and
(b) we will provide the Service with reasonable skill and care.
16.2 Clause 16.1 does not apply to a defect that is caused by:
(a) a use of the Service that breaks these Terms or the Documentation;
(b) a change to the Service that a person other than us made;
(c) a Third-Party Service, or your systems, data or network; or
(d) a beta feature or a free trial.
16.3 If the Service does not obey clause 16.1, you must tell us in writing, with enough details for us to reproduce the problem. We will then, at our choice, correct the defect, give you a reasonable way to avoid it, or end the Contract and refund the Fees that you paid for the time after the end. This is your only remedy for a breach of clause 16.1.
16.4 You promise that:
(a) you have the rights in the Customer Data that clause 9.3 requires; and
(b) your use of the Service, and the Customer Data, will obey the law and these Terms.
16.5 Except as these Terms expressly say, we exclude all warranties, conditions and other terms, whether express or implied by statute, common law or otherwise, to the maximum extent that the law allows. This includes the terms implied by sections 13 to 15 of the Supply of Goods and Services Act 1982 about satisfactory quality and fitness for a purpose.
17. Indemnities
17.1 You must indemnify us against all losses, damages, costs (including reasonable legal fees) and expenses that we incur because of a claim by a third party that arises from:
(a) the Customer Data, including a claim that the Customer Data infringes the rights of a third party or breaks the Data Protection Legislation; or
(b) a breach of clause 6 (acceptable use) by you or by an Authorised User.
17.2 We must defend you against a claim by a third party that your use of the Service, as these Terms allow, infringes the copyright, the trade mark or the database right of that third party in the United Kingdom. We must pay the damages and the costs that a court awards against you, or that we agree in a settlement, for that claim. This clause 17.2 does not apply to a claim that comes from the Customer Data, from a Third-Party Service, or from a use of the Service that breaks these Terms.
17.3 If a claim under clause 17.2 occurs, or we think that it is likely, we can, at our choice and cost: get for you the right to continue to use the Service; change the Service so that it does not infringe; or end the Contract and refund the Fees that you paid for the time after the end.
17.4 A party that asks for an indemnity under this clause 17 must:
(a) tell the other party promptly about the claim;
(b) let the other party control the defence and the settlement of the claim;
(c) give reasonable help, at the cost of the other party; and
(d) not admit liability or settle the claim without the written agreement of the other party.
17.5 Clauses 17.2 and 17.3 give your only remedy for a claim that the Service infringes the rights of a third party.
18. Limitation of liability
18.1 Nothing in these Terms limits or excludes the liability of either party for:
(a) death or personal injury that its negligence causes;
(b) fraud or fraudulent misrepresentation;
(c) a breach of the terms implied by section 2 of the Supply of Goods and Services Act 1982 (title and quiet possession); or
(d) any other liability that the law does not allow a party to limit or exclude.
18.2 Nothing in these Terms limits your obligation to pay the Fees, or your liability under clause 17.1.
18.3 Subject to clauses 18.1 and 18.2, neither party is liable to the other party, whether in contract, in tort (including negligence), for breach of statutory duty, or otherwise, for:
(a) loss of profits;
(b) loss of revenue or of sales;
(c) loss of business, of contracts or of opportunity;
(d) loss of anticipated savings;
(e) loss of goodwill or damage to reputation;
(f) wasted expenditure or wasted management time; or
(g) any indirect or consequential loss.
18.4 Subject to clause 18.1, we have no liability to you, whether in contract, in tort (including negligence), for breach of statutory duty, or otherwise, for any loss that arises from:
(a) the loss, destruction, corruption or damage of Customer Data, or of any other data; or
(b) the Service being unavailable, interrupted, slow or inaccessible, for any reason and for any period.
Clause 9.5 gives your only remedy for the loss of Customer Data. This clause 18.4 is separate from clause 18.3, and each applies independently.
18.5 Subject to clauses 18.1, 18.2 and 18.6, the total liability of each party to the other party for all claims that arise under or in connection with the Contract, whether in contract, in tort (including negligence), for breach of statutory duty, or otherwise, is limited to the total Fees that you paid to us in the 12 months before the event that caused the first claim.
18.6 During a free trial, or while you use the Service without payment, our total liability to you is limited to £50.
18.7 You agree that the limits and the exclusions in this clause 18 are reasonable, because:
(a) the Fees reflect them;
(b) you can buy insurance for the losses that we exclude; and
(c) you are better able to judge the value of the Customer Data and the effect of a loss on your business; and
(d) the Service lets you export the Customer Data at any time, so you can keep your own copies.
18.8 You must bring any claim against us within 12 months after the date on which you became aware, or ought reasonably to have become aware, of the facts that give rise to the claim. After that time, the claim is barred.
19. Suspension
19.1 We can suspend the access of you or of any Authorised User to all or part of the Service, immediately and without liability, if:
(a) you do not pay the Fees as clause 8.7 says;
(b) you or an Authorised User break clause 6;
(c) we reasonably think that a use of the Service puts at risk the security, the integrity or the availability of the Service, or of the data of other customers; or
(d) a law, a court or a regulator requires it.
19.2 If possible, we will tell you before we suspend access, and give you a reasonable time to correct the cause. We will restore access when the cause is corrected.
19.3 The Fees continue during a suspension that clause 19.1(a) or 19.1(b) causes.
20. Term and termination
20.1 The Contract starts when you accept these Terms, and continues until you or we end it under this clause 20.
20.2 You can cancel your subscription at any time on the billing page of the Service, or by email to help@support.thecurve.io. The cancellation starts at the end of the current Subscription Period. We do not refund the Fees for the current Subscription Period.
20.3 You can end the Contract immediately by written notice if we make a change under clause 4.2 or clause 22.1 that you do not accept.
20.4 We can end the Contract for any reason with at least 30 days' written notice. We will then refund the Fees that you paid for the time after the end.
20.5 Either party can end the Contract immediately by written notice if the other party:
(a) commits a material breach of the Contract and, if the breach can be corrected, does not correct it within 30 days after a written notice that asks for it;
(b) cannot pay its debts as they fall due, enters into administration, liquidation, receivership or a voluntary arrangement with its creditors, or has a similar event in any jurisdiction; or
(c) stops, or threatens to stop, its business.
20.6 We can end the Contract immediately by written notice if you do not pay the Fees within 30 days after the due date.
21. What happens when the Contract ends
21.1 When the Contract ends:
(a) the right of use in clause 4.1 ends, and you and your Authorised Users must stop using the Service;
(b) you must pay all the Fees that are due; and
(c) each party must return or delete the Confidential Information of the other party, except as clause 21.2 and the law say.
21.2 For 30 days after the Contract ends, you can ask us to give you an export of the Customer Data in a common machine-readable format. After those 30 days, we will delete your Workspace and the Customer Data. Copies in our backups are deleted within 14 days after that, as our backup cycle continues. We can keep Customer Data for longer if the law requires it.
21.3 The end of the Contract does not affect the rights and the remedies that a party had at the time that it ended.
21.4 Clauses 9.4, 11, 12, 13, 16.5, 17, 18, 21 and 24, and any other clause that by its nature continues, continue after the Contract ends.
22. Changes to these Terms
22.1 We can change these Terms. If a change is material, we will tell you by email, or with a notice in the Service, at least 30 days before it starts. If you do not accept the change, you can end the Contract under clause 20.3 before the change starts. We will then refund the Fees that you paid for the time after the end.
22.2 We can make a change immediately if a law, a regulator or a security risk requires it, or if the change does not reduce your rights. We will tell you about it.
22.3 If you continue to use the Service after a change starts, you accept the changed Terms.
23. Events outside our control
23.1 Neither party is liable for a delay or a failure to perform the Contract that an event outside its reasonable control causes. Examples are a natural disaster, a fire, a flood, a pandemic, a war, terrorism, a riot, a strike of a third party, an act of a government, a failure of a public network or of a power supply, a failure of a hosting provider, or a cyber attack that reasonable security measures cannot prevent.
23.2 This clause does not apply to your obligation to pay the Fees.
23.3 If the event continues for more than 60 days, either party can end the Contract by written notice. We will then refund the Fees that you paid for the time after the end.
24. General
24.1 Assignment. You must not assign or transfer your rights or obligations under the Contract without our written agreement. We can assign or transfer the Contract to a company in our group, or to a buyer of all or part of our business, and we will tell you.
24.2 Subcontractors. We can use subcontractors to perform the Contract. We are responsible for their performance. Schedule 1 says how we use sub-processors.
24.3 Notices. A notice under the Contract must be in writing. We send notices to the email address of the owner of your Workspace. An email notice is received when it is sent, unless we get a message that it was not delivered. You send notices by post to The Curve Consulting Services Limited, 4 Joiner Street, Sheffield, S3 8GW. A notice by post is received on the second Business Day after it was posted. A notice of a claim must also go by post to the registered office of the other party.
24.4 Entire agreement. The Contract is the whole agreement between you and us about its subject. It replaces all earlier agreements, promises and statements. Each party agrees that it did not rely on a statement that the Contract does not include, and that it has no remedy for such a statement. This does not limit liability for fraud.
24.5 Your terms. Terms in a purchase order, or in any other document from you, do not apply, even if we accept or sign that document.
24.6 Waiver. If a party does not use, or delays the use of, a right or a remedy, that does not waive it.
24.7 Severance. If a court finds that a part of the Contract is invalid or cannot be enforced, the rest of the Contract continues. The parties will replace the invalid part with a valid part that has the nearest possible effect.
24.8 No partnership. The Contract does not make a partnership, a joint venture or an agency between you and us.
24.9 Third parties. A person who is not a party to the Contract has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.
24.10 Publicity. We can show your name and your logo in a list of our customers. You can tell us at any time to stop.
24.11 Governing law. The law of England and Wales governs the Contract, and any dispute or claim (including a non-contractual dispute or claim) that arises from it or in connection with it.
24.12 Jurisdiction. The courts of England and Wales have exclusive jurisdiction to settle any dispute or claim that arises from the Contract or in connection with it.
Schedule 1 — Data Processing Agreement
This schedule obeys Article 28(3) of the UK GDPR. In this schedule, controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings that the UK GDPR gives them. Personal Data means the personal data in the Customer Data. The Commissioner means the Information Commissioner.
1. Roles and instructions
1.1 You are the controller and we are the processor of the Personal Data. Annex A describes the processing.
1.2 We process the Personal Data only on your documented instructions, unless a law of the United Kingdom requires us to process it. If a law requires it, we will tell you before we process, unless that law prohibits it. These Terms, and the settings that you choose in the Service, are your instructions.
1.3 We will tell you immediately if we think that an instruction breaks the Data Protection Legislation.
1.4 You promise that you have a lawful basis for the processing, and that you gave the data subjects the information that the Data Protection Legislation requires.
2. Confidentiality of our personnel
2.1 We make sure that each person whom we authorise to process the Personal Data has an obligation of confidentiality.
3. Security
3.1 We use appropriate technical and organisational measures to protect the Personal Data, as Article 32 of the UK GDPR requires. Annex B summarises them.
3.2 If you ask, we will give you a more detailed description of our security measures. That description is our Confidential Information under clause 13 of these Terms.
3.3 We can change the measures, if the change does not reduce the general level of security.
4. Sub-processors
4.1 You give us a general authorisation to use sub-processors. Annex C lists our current sub-processors. We change Annex C under clause 4.2, and clause 22.1 of these Terms does not apply to that change.
4.2 We will tell you at least 7 days before we add or replace a sub-processor. You can object on reasonable grounds about data protection within that time. If we cannot resolve the objection, you can end the Contract by written notice, and we will refund the Fees that you paid for the time after the end.
4.3 We put obligations on each sub-processor, in a written contract, that are no less protective than this schedule. We are responsible to you for the performance of each sub-processor.
5. International transfers
5.1 We will not transfer Personal Data out of the United Kingdom, or let a sub-processor do so, unless the transfer obeys Chapter V of the UK GDPR. For example, the destination has UK adequacy regulations, or we use the International Data Transfer Agreement or the International Data Transfer Addendum that the Commissioner issued.
6. Help with the rights of data subjects
6.1 We will help you, with appropriate technical and organisational measures and as far as possible, to answer requests from data subjects who use their rights under Chapter III of the UK GDPR.
6.2 If we get a request directly from a data subject, we will send it to you promptly. We will not answer it ourselves, unless you tell us to.
7. Personal data breaches
7.1 We will tell you without undue delay, and in any event within 48 hours, after we become aware of a personal data breach that affects the Personal Data.
7.2 Our notice will give the information that you need to report the breach under Article 33 of the UK GDPR, as far as we know it. If we do not know all the information at first, we will give it in stages.
7.3 We will take reasonable steps to contain the breach and to reduce its effects.
8. Other help
8.1 We will give you reasonable help, with the information available to us, with your data protection impact assessments and your prior consultations with the Commissioner, under Articles 35 and 36 of the UK GDPR.
9. Deletion and return
9.1 When the Contract ends, we will return and delete the Personal Data as clause 21.2 of these Terms says, unless a law of the United Kingdom requires us to keep it.
10. Audits
10.1 We will make available to you the information that is necessary to show that we obey this schedule.
10.2 We will allow, and contribute to, audits and inspections by you or by an independent auditor whom you appoint. An audit:
(a) needs at least 30 days' written notice;
(b) happens during Business Days, not more than once in any 12 months, unless a supervisory authority requires it or a personal data breach occurred;
(c) must not damage our business or the security of other customers; and
(d) is at your cost, and the auditor must accept an obligation of confidentiality.
10.3 We can answer an audit request with a recent independent certificate or report about our security, if that report gives the information that you need.
11. Liability
11.1 Clause 18 of these Terms applies to this schedule.
Annex A — Details of the processing
Item | Details |
|---|---|
Subject matter | The hosting and the processing of the Customer Data to provide the Service. |
Duration | The term of the Contract, and the time after it until we delete the Personal Data under clause 21.2. |
Nature | Collection, storage, organisation, retrieval, calculation, display, transmission to the Third-Party Services that you connect, backup, and deletion. |
Purpose | To provide the Service to you, to support you, and to keep the Service secure. |
Data subjects | Your Authorised Users, employees and contractors; the contacts at your clients and your suppliers; and any other person whom you put in the Customer Data. |
Types of Personal Data | Names, work email addresses, job titles and roles; sign in data and IP addresses; timesheets and working hours; leave and absence records; resource plans and availability; cost rates and charge rates; skills and capabilities; contact details of clients and suppliers; and any other personal data that you put in the Customer Data. |
Special category data | The Service is not designed for special category data. Leave records can show that a person was absent because of sickness. You must not put the details of a medical condition, or other special category data, in the Service. |
Annex B — Security measures
Our measures include:
the separation of the data of each customer from the data of every other customer;
encryption of the data in transit and at rest;
control of access to the data, for your Authorised Users and for our staff;
regular backups, and the means to restore the data from them;
protection of the credentials and the secrets that the Service holds;
security updates to our software and our infrastructure; and
monitoring of the Service, and a process to respond to incidents.
Annex C — Sub-processors
Sub-processor | Purpose | Location |
|---|---|---|
OVH SAS | Hosting of the Service and its databases | [Location] |
ServerNet Internet Limited | Hosting of the Service and its databases | [Location] |
Amazon Web Services EMEA SARL | Storage of uploads and backups, and the secrets manager | United Kingdom (eu-west-2, London) |
Mailgun Technologies, Inc. | Sending of email from the Service | European Union |
Cloudflare, Inc. | Bot protection (Turnstile) on the sign up form | Global |
The Third-Party Services that you connect, for example Xero, Jira, Slack, HubSpot, Google Workspace and CharlieHR, are not our sub-processors. You choose them, and your contract with each provider covers them.