Back

Our Policies

Terms & Conditions

The Boring Stuff

This page (together with the documents referred to in it) tells you information about us and the legal terms and conditions ("Terms") on which we supply any services ("Services") listed on our website ("our site") to you.

Please read these Terms carefully and make sure that you understand them, before ordering any Services from our site. Please note that by ordering any of our Services, you agree to be bound by these Terms and the other documents expressly referred to in it.

If you refuse to accept these Terms, you will not be able to order any Services from our site.

You should print a copy of these Terms for future reference.

We amend these Terms from time to time as set out in clause 6. Every time you wish to order Services, please check these Terms to ensure you understand the terms which will apply at that time.

Information about us

We operate the website brightwork.uk. We are Brightwork Media Limited, a company registered in England and Wales under company number 12866475 and with our registered office at Unit 10, Victoria Hall, Barrow in Furness, CUMBRIA, LA141BX.
To contact us, please see our Contact Us page.

Use of our site

Your use of our site is governed by our Website Terms of Use. Please take the time to read these, as they include important terms which apply to you. When using our site, you must also comply with the provisions of our Acceptable Use Policy.

How we use your personal information

We only use your personal information in accordance our Privacy Policy. For details, please see our Privacy Policy. Please take the time to read these, as they include important terms which apply to you.

Our Contract with you

These Terms and any document expressly referred to in them constitute the entire agreement between you and us (the “Contract”). You acknowledge that you have not relied on any statement, promise or representation made or given by or on behalf of us which is not set out in these Terms or any document expressly referred to in them. Where you are a consumer, you have legal rights in relation to Services that are not as described. Advice about your legal rights is available from your local Citizens' Advice Bureau or Trading Standards office. Nothing in these Terms will affect these legal rights.

How the Contract is formed between you and us

  1. Our order process allows you to check and amend any errors before submitting your first order to us. Please take the time to read and check your order at each page of the order process. After you place an order for Services, you will receive an e-mail from us acknowledging that we have received your order. However, please note that this does not mean that your order has been accepted.
  2. If you are ordering Services with us we will confirm our acceptance to you by sending you an e-mail ("Order Confirmation"). If you are ordering domain registration Services with us we will confirm our acceptance to you by sending you an invoice. The Contract between us will only be formed when we send you the Order Confirmation or invoice as described above.
  3. The term of our contract for Services is as described in each invoice you receive from us. Once we have provided domain registration Services for you once on any given domain we will send you an invoice for domain registration Services when payment for that domain is next due unless you inform us otherwise.
  4. Unless the Contract is cancelled by either party in accordance with the Terms, or is amended by agreement between both parties, the Contract will renew automatically for the same term as the previous Contract at the Price as outlined in the Terms.
  5. If we are unable to supply you with the Services ordered, for example because of an error in the price on our site, we will inform you of this by e-mail and we will not process your order. If you have already paid for the Services, we will refund you the full amount as soon as possible.

Our right to vary these terms

We may revise these Terms from time to time, including but not limited to the following circumstances:

  1. Changes in how we accept payment from you; and
  2. Changes in relevant laws and regulatory requirements.
  3. Every time you order Services from us or the Contract between us is renewed, the Terms in force at that time will apply to the Contract between you and us.

Intellectual Property Rights

  1. For the purpose of this Contract, "Intellectual Property Rights" shall mean all patents, rights to inventions, utility models, copyright and related rights, trade marks, service marks, trade, business and domain names, rights in trade dress or get-up, rights in goodwill or to sue for passing off, rights in designs, rights in computer software, database rights, moral rights, rights in confidential information (including know-how and trade secrets) and any other intellectual property rights, whether registered or unregistered and including all applications for and renewals or extensions of such rights.
  2. You retain all Intellectual Property Rights in the software and materials that you provide to us and you grant us a licence to such Intellectual Property Rights to the extent required for us to perform our obligations pursuant to this Contract.
  3. All Intellectual Property Rights in any works arising in connection with the performance of the Services by us (the "Works") shall be our property, and we hereby grant to you a non-exclusive licence to such Intellectual Property Rights for the sole purpose of receiving the benefit of the Services.

If there is a problem with the Services

In the unlikely event that there is any defect with the Services, please;

    1. Contact us through the support ticketing system inside your client area or via email (inbox@brightwork.uk) and tell us as soon as reasonably possible (including details of your name, the respective domain name and/or server and any additional information you deem valuable)
    2. Give us a reasonable opportunity to repair or fix any defect
  1. We will use every effort to repair or fix the defect as soon as reasonably practicable and, in any event, within 1 working day.
  2. You will not have to pay for us to repair or fix a defect with the Services under this clause.
  3. If you are a consumer, you have legal rights in relation to Services not carried out with reasonable skill and care, or if the materials we use are faulty or not as described. Advice about your legal rights is available from your local Citizens' Advice Bureau or Trading Standards office. Nothing in these Terms will affect these legal rights.

Price of Services

  1. The prices for the Services will be as quoted on our site from time to time or as otherwise agreed between us.
  2. Prices for our Services may change from time to time, but changes will not affect any order which we have confirmed with an Order Confirmation (in the case of hosting Services) or with an invoice (in the case of domain registration Services) or during the period shown on subsequent invoices in the case of renewals.
  3. The price of the Services exclude VAT (where applicable) at the current rate chargeable in the UK at the time of publishing.
  4. Our site contains a number of Services. It is always possible that, despite our reasonable efforts, some of the Services on our site may be incorrectly priced. If we discover an error in the price of the Services you have ordered we will inform you of this error and we will give you the option of continuing to purchase the Services at the correct price, or cancelling your order. We will not process your order until we have your instructions. If we are unable to contact you using the contact details you provided during the order process, we will treat the order as cancelled and notify you in writing. Please note that if the pricing error is obvious and unmistakable and could have reasonably been recognised by you as a mispricing, we do not have to provide the Services to you at the incorrect (lower) price.
  5. Payments in respect of domain name registrations and domain name renewals are non-refundable.
  6. Reduced price trials are for new clients only.

How to pay

  1. You can only pay for the Services using a debit or credit card via Stripe or Bank Transfer. We accept the following cards: Visa, MasterCard, American Express.
  2. Payment for the Services is in advance and may be made (i) monthly or (ii) annually, as specified in the Order Confirmation. We will not charge your debit card or credit card until we send you an Order Confirmation.
  3. If you fail to make any payment due to us under this Contract by the due date (plus 7 days) then, without limiting our remedies under this clause, you shall pay a fixed late fee on the overdue amount at whichever is the greater of 5% or £10. You shall pay the penalty charge interest together with the overdue amount. If this is your first invoice, it will be deemed cancelled on the 7th day of non-payment.
  4. Adding your card to file authorises us to auto bill you on your due date. You can manage this via your client area, it is your responsibility to keep this updated.
  5. We use Stripe to process card payments. When you use our card payment system you confirm that you are permitting us to initiate a payment or series of payments on your behalf. You confirm that we may either take payments as a one-off or on a recurring basis as indicated on our payment page and/or your payment schedule. You confirm that the payment amount will be determined by reference to our charges at the time as described on your invoice, and any recurring fees will be determined by the conditions and terms laid out therein.

Termination

    Either party (the "Non-defaulting Party") shall be able to terminate this Contract immediately in the event that the other:
  1. Commits a material breach of any of its obligations under this Contract and has not remedied such breach (if capable of remedy) within 30 days of request from the Non-defaulting Party for remedy by serving written notice; or
  2. Is subject to any winding up order or resolution, has any provisional liquidator appointed to it, has a receiver appointed or is the subject of an application made to court for an administration order or if a notice of intention to appoint an administrator is filed or an administration order made in respect of it, is unable to pay its debts within the meaning of Section 123 of the Insolvency Act 1986, enters into any arrangement for the benefit of or other compounds with its creditors generally or ceases or threatens to cease carrying on its business, or (being an individual) is the subject of a bankruptcy petition or order, or any equivalent processes in any jurisdiction.
  3. Without prejudice to any rights that have accrued under a Contract or any of its rights or remedies, either party may terminate a Contract on giving not less than 30 days written notice to the other party. At our discretion we may accept requests to terminate Services in situations where you provide us with less than 30 days notice. You may be required to submit a cancellation request in the client area in order for us to process your cancellation. Notwithstanding the foregoing, if you have agreed and paid for Services on an annual or multi-year payment basis, we shall not be obliged to refund any pro rated payments if you cancel during the annual or multi-year term.
  4. In accordance with our Hosting Acceptable Use Policy, an account may be terminated by us unilaterally, without notice and at our discretion if we consider an account holder to be in breach of the stated prohibited uses contained within that Policy
  5. An account may be terminated with immediate effect if abusive behaviour is directed at our staff and/or company

Consequences of Termination

  1. Other than as set out in these Terms, neither party shall have any further obligation to the other under a Contract after its termination.
  2. Any provision of these Terms which expressly or by implication is intended to come into or continue in force on or after termination of a Contract shall remain in full force and effect.
  3. Termination of a Contract, for any reason, shall not affect the accrued rights, remedies, obligations or liabilities of the parties existing at termination.
  4. If a Contract is terminated, then:
    1. we will promptly provide to you an electronic copy of the Hosted Materials; and
    2. we will provide such assistance as is reasonably requested by you to transfer the hosting of the Hosted Materials to you or another service provider, subject to payment of our reasonable expenses.

Our liability if you are a business

This clause only applies if you are a business customer.

Nothing in these Terms limit or exclude our liability for:

  1. Death or personal injury caused by our negligence;
  2. Fraud or fraudulent misrepresentation; or
  3. Any other area where it would be unlawful or invalid to seek to exclude liability.

Subject to clause 14.1, we will under no circumstances be liable to you, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, arising under or in connection with the Contract for:

  1. Any loss of profits, sales, business, or revenue;
  2. Loss or corruption of data, information or software;
  3. Loss of business opportunity;
  4. Loss of anticipated savings;
  5. Loss of goodwill;
  6. Any indirect or consequential loss.

Subject to above clauses, our total liability to you in respect of all other losses arising under or in connection with the Contract, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall in no circumstances exceed the price of the Services in the previous 3 month period.

Except as expressly stated in these Terms, we do not give any representation, warranties or undertakings in relation to the Services. Any representation, condition or warranty which might be implied or incorporated into these Terms by statute, common law or otherwise is excluded to the fullest extent permitted by law. In particular, we will not be responsible for ensuring that the Services are suitable for your purposes.

 

Our liability if you are a consumer

This clause only applies if you are a consumer.

Nothing in these Terms limit or exclude our liability for:

  1. Death or personal injury caused by our negligence;
  2. Fraud or fraudulent misrepresentation; or
  3. Any other area where it would be unlawful or invalid to seek to exclude liability.

If we fail to comply with these Terms, we are responsible for loss or damage you suffer that is a foreseeable result of our breach of these Terms or our negligence, but subject to clause above, we are not responsible for any loss or damage that is not foreseeable.

Loss or damage is foreseeable if they were an obvious consequence of our breach or if they were contemplated by you and us at the time we entered into the Contract.

We only supply the Services for domestic and private use. You agree not to use the Services for any commercial, business or re-sale purposes, and subject to clause above, we have no liability to you for any:

  1. Any loss of profits, sales, business, or revenue;
  2. Loss or corruption of data, information or software;
  3. Loss of business opportunity;
  4. Loss of anticipated savings;
  5. Loss of goodwill;
  6. Any indirect or consequential loss.

Subject to the foregoing, our total liability to you in respect of all other losses arising under or in connection with the Contract, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall in no circumstances exceed the price of the Services in the previous 90 day period.

 

Indemnity

You shall indemnify us against all liabilities, costs, expenses, damages and losses (including any direct, indirect or consequential losses, loss of profit, loss of reputation and all interest, penalties and legal and other reasonable professional costs and expenses) suffered or incurred by us arising out of or in connection with:

  1. any breach by you of the warranties contained in clause 7; and
  2. any claim made against us for actual or alleged infringement of a third party's Intellectual Property Rights arising out of or in connection with the our use of software and/or other materials provided by you.

Events outside our control

  1. We will not be liable or responsible for any failure to perform, or delay in performance of, any of our obligations under a Contract that is caused by an Event Outside Our Control. An Event Outside Our Control is defined in below clause
  2. An "Event Outside Our Control" means any act or event beyond our reasonable control, including without limitation strikes, lock-outs or other industrial action by third parties, civil commotion, riot, invasion, terrorist attack or threat of terrorist attack, war (whether declared or not) or threat or preparation for war, fire, explosion, storm, flood, earthquake, subsidence, epidemic or other natural disaster, or failure of public or private telecommunications networks.

If an Event Outside Our Control takes place that affects the performance of our obligations under a Contract:

  1. we will contact you as soon as reasonably possible to notify you; and
  2. our obligations under a Contract will be suspended and the time for performance of our obligations will be extended for the duration of the Event Outside Our Control.

Providing Services

  1. We will supply the Services to you from the date set out in the Order Confirmation, in the case of hosting services, or invoice, in the case of domain registration services, until the completion or renewal date set out in the Order Confirmation. Where no completion date or renewal date is specified, we will supply the Services until the Contract is terminated in accordance with the Terms.
  2. Where the Order Confirmation sets out any milestones for the provision of Services, we will make every effort to complete the Services on time. However, there may be delays due to an Event Outside Our Control. See clause 17 for our responsibilities when an Event Outside Our Control happens.
  3. We will need certain information from you that is necessary for us to provide the Services, for example, name, address, contact details. We will contact you about this. If you do not, after being asked by us, provide us with this information, or you provide us with incomplete or incorrect information, we may make an additional charge of a reasonable sum to cover any extra work that is required, or we may suspend the Services by giving you written notice. We will not be liable for any delay or non-performance where you have not provided this information to us after we have asked. If we suspend the Services under this clause you do not have to pay for the Services while they are suspended, but this does not affect your obligation to pay for any invoices we have already sent you, or those of which may be raised after suspension.
  4. You are responsible for obtaining:
    1. Suitable licences of third party software; and
    2. Any third party cooperation and consents, which are required for the full use of the Services. We will not be liable for any delay or non-performance where you have not provided such licences and consents to us after we have asked, or where this is necessary.
  5. We may have to suspend the Services if we have to deal with technical problems. We will contact you to let you know in advance where this occurs, unless the problem is urgent or an emergency. This does not affect your obligation to pay for any invoices we have already sent you.
  6. Our distributed denial of service (“DDoS”) protection is a network wide solution that covers all of our infrastructure. It is capable of mitigating the majority of DDoS attacks, but if the attack is large enough then I.P. addresses, servers or websites may be black-holed or removed from the internet whilst the attack is in progress.
  7. If you do not pay us for the Services by the due date for payment, we may suspend the Services 7 days after the due date until you have paid us the outstanding amounts. We will contact you by email to tell you this. This does not affect our right to charge you interest
  8. Implementation and Transition
    1. We will make available the Services on or before the start date specified in the Order Confirmation.
    2. At your request and subject to our Free Migration offering, we will use reasonable endeavours to:
      1. Assist with the transfer of your website from your own development server; or
      2. Assist with the transition of any of your website(s) from any third party host
  9. Shared Hosting
    1. Where the Services we provide to you include shared hosting, we will make available to you:
      1. Hosting capacity on a shared server meeting the specification set out on the site which may vary from time to time;
      2. The ability to access, update or amend any websites, web applications, software, information, data, databases and other works and materials stored, transmitted, published or processed using the Services (the "Hosted Materials") by FTP or similar means.
      3. You warrant that any material that you display on the respective sites do not and will not infringe any applicable laws, regulations or display material which is obscene, indecent, pornographic, homophobic, seditious, offensive, defamatory, threatening, liable to incite racial hatred or acts of terrorism, menacing, blasphemous or in breach of any third party Intellectual Property Rights ("Inappropriate Content").
      4. For the avoidance of doubt, we will have administration rights in relation to any shared server, and we may refuse any request to change the configuration of a shared server at our sole discretion.
  10. Virtual Private Server "VPS" and Dedicated Servers
    1. Where the Services we provide to you include a dedicated server, we will make available a VPS/dedicated server meeting the specification set out on our site, and will grant to you administration rights with respect to that server except where the services are managed, in which case we may refuse any request to change the configuration of the VPS/dedicated server at our sole discretion.
    2. For unmanaged dedicated servers you acknowledge that we will not provide support in connection with the administration of such VPS/dedicated server, and you warrant that you have all necessary expertise to configure, manage and keep the VPS/dedicated server secure at all times.
    3. You will not configure, or allow any other person to configure, a VPS/dedicated server in any way contrary to the guidelines published on our site from time to time.
    4. We may from time to time require that you apply software and/or hardware upgrades to the VPS/dedicated server.
    5. Un-managed dedicated systems are provided with a guarantee of power availability 100% of the time in any calendar month, and network connectivity availability
    6. 99.99% of the time in any calendar month, except where it has been necessary to explicitly black-hole access to an IP directing to your system to mitigate a DDoS attack against it. A service credit equal to the service cost of any hours either resource is unavailable for greater than the time provided by this guarantee whenever this is not met will be provided to you on request.
    7. For the avoidance of doubt, dedicated servers made available under this Contract will remain our property at all times.
  11. Email Services
    1. Where the Services we provide to you include email transmission, storage and/or management services:
      1. We will provide POP3/IMAP/SMTP and webmail email services to you in accordance with the respective Services description.
      2. All shared hosting mailboxes will be protected by our anti-spam and anti-virus solution.
  12. Support
    1. The Company will use reasonable endeavours to respond to requests for support in relation to our support Services.
    2. For business web hosting services, managed VPS and managed dedicated servers, we will use reasonable endeavours to ensure that a member of our support staff can be reached by telephone during business hours in the case of an emergency.
  13. We may be limited in the Services we can offer by the rules and regulations set out by our suppliers. In particular this may limit or prevent us offering Services to customers in certain geographical areas. We have various suppliers who may apply such restrictions on us.

Domain Name Registration

  1. Where the Services we provide to you include domain name registration, we will attempt to register domain names that you order using the interface on our site but we do not warrant that we will be able to do so.
  2. You warrant that:
    1. The information submitted for the purposes of a domain name registration is current, accurate and complete.
    2. You have the legal right to apply for and use the domain name, and
    3. Your use of the domain name will not infringe any person's Intellectual Property Rights or other legal rights; and
    4. You will keep the information required for the purposes of a domain name registration up-to-date (which changes may be subject to additional payments as set out on our site).
  3. You acknowledge and accept that certain information submitted for the purposes of a domain name registration will be published on the internet via "WHOIS" or "RDAP" services.
  4. We may, in our sole discretion, reject any request to register a particular domain name without explanation.
  5. We do not offer any advice in relation to any actual or potential domain name dispute, and will have no liability in respect of the suspension or loss of a domain name by you as a result of any domain name arbitration procedure or court proceedings.
  6. Domain name registrations will be subject to periodic renewal fees and transfer fees as stated on our site from time to time. We have no responsibility for your use or retention of a domain name once registered, and it will be your responsibility to ensure that domain names are renewed and that applicable renewal charges are paid. The cost of registration, transfer and renewal of domain names can be found during the registration flow and on our site from time to time. You will be contacted 90 days in advance of these renewals, and will receive a reminder every 30 days thereafter, to your contact email address on file. If auto renewal is applied, charges will be made to payment method on file no less than 30 days before your expiry date.
  7. You acknowledge that domain names will be subject to the rules and policies from time to time of the relevant registry or registration authority, and you agree to abide by all such rules and policies.
  8. You agree to the terms of the applicable domain name registration agreement (as amended from time to time): www.nominet.uk - for .uk domains and www.icann.org for IDN domains. You can find Nominet's Terms of Registration here.
  9. Free domains
    1. The free domain offer on certain plans is only for the first year and is only valid on standard domains: e.g. .uk, .com, .org. This isn't applicable on premium TLDs. e.g. .london.
    2. Certain of our Services come with free life long domains. These are only for the life of the specific plan and will return to full price as and when the specific plan is cancelled or downgraded.
    3. The free domain should be chosen at checkout with your plan. This cannot be redeemed after your initial purchase.
    4. Free domains are only applicable to new accounts only, upgrading or switching from another Brightwork package will not qualify for another free domain.
    5. If the hosting is refunded the cost of the free domain will be deducted from this as the domain is yours to keep until expiry
  10. Premium domain names are priced individually. Registration, transfer & renewal of these domain names are on a case by case basis and will be discussed with the buyer at the time.

Domain Name Backorders

Our backordering service runs on Nominet EPP and only covers UK domain name backorders.

  1. Any backorder made for a domain name dropping the same day, will be deemed not refundable. If you have not yet paid for this backorder, and we are successful in catching it, you will be invoiced the cost of the catch.
  2. Where a domain has been backordered by several people and where we are successful in catching the domain, it is within our discretion to auction this domain on whichever platform we choose
  3. Where a domain has been backordered, but not paid for prior to chasing, it is within our sole discretion to release it to you.
    1. Customers on monthly plans are not subject to the above clause
  4. If we are successful in catching your backorder and you are not on a monthly plan, you will be charged the catch fee published on the website at the time of ordering.
After winning
  1. If we are successful in catching your domain name, payment is due the same day.
  2. Successful orders which haven't received payment after 7 days, with no reasonable excuse, will be deemed cancelled, however, you will still be charged.
  3. We will make every reasonable effort to release the domain to you the same day, providing you have given us the necessary release details

Communications between us

  1. When we refer, in these Terms, to "in writing", this will include e-mail.
  2. If you wish to contact us in writing, or if any clause in these Terms requires you to give us notice in writing, you can send this to us by email at inbox@brightwork.uk. We will confirm receipt of this by contacting you in writing by e-mail within 1 day.
  3. If we have to contact you or give you notice in writing, we will do so by e-mail or by pre-paid post to the address you provided to us within your account.
  4. If you are a business, please note that any notice given by you to us, or by us to you, will be deemed received and properly served 24 hours after an e-mail is sent or 24 hours after posting on our website. In proving the service of any notice, it will be sufficient to prove, in the case of an e-mail, that such e-mail was sent to the specified e-mail address of the addressee.
  5. If you have a complaint or want to file an abuse report, please email inbox@brightwork.uk with the relevant information,including domain name and any helpful additional information you wish to include.

Support

  1. The Company will use reasonable endeavours to respond to requests for support in relation to our Services.
  2. We will use reasonable endeavours to ensure that a member of our support staff can be reached by telephone during business hours in the case of an emergency.
  3. We may be limited in the Services we can offer by the rules and regulations set out by our suppliers. In particular this may limit or prevent us offering Services to customers in certain geographical areas. We have various suppliers who may apply such restrictions on us.

Other important terms

  1. This Contract constitutes the entire agreement between you and us and supersedes and extinguishes all previous drafts, agreements, arrangements and understandings between you and us, whether written or oral, relating to its subject matter.
  2. Each party agrees that it shall have no remedies in respect of any representation or warranty (whether made innocently or negligently) that is not set out in this Contract. Neither you nor we shall have any claim for innocent or negligent misrepresentation based upon any statement in this Contract.
  3. You may not assign or transfer any of your rights or obligations under this Contract, in whole or in part, without our prior written consent.
  4. A person who is not a party to this Contract shall not have any rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of these Terms.
  5. If any court or competent authority finds that any provision of this Contract (or part of any provision) is invalid, illegal or unenforceable, that provision or part-provision shall, to the extent required, be deemed to be deleted, and the validity and enforceability of the other provisions of this Contract shall not be affected.
  6. If any invalid, unenforceable or illegal provision of this Contract would be valid, enforceable and legal if some part of it were deleted, the provision shall apply with the minimum modification necessary to make it legal, valid and enforceable.
  7. If we fail to insist that you perform any of your obligations under these Terms, or if we do not enforce our rights against you, or if we delay in doing so, that will not mean that we have waived our rights against you and will not mean that you do not have to comply with those obligations. If we do waive a default by you, we will only do so in writing, and that will not mean that we will automatically waive any later default by you.
  8. These Terms and any disputes or claims arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) are governed by and construed in accordance with the law of England.
  9. The parties irrevocably agree that the courts of England have exclusive jurisdiction to settle any dispute or claim that arises out of or in connection with these Terms or their subject matter or formation (including non-contractual disputes or claims).
  10. Calls may be recorded for training or monitoring purposes.
Welcome to the Brightwork Media Limited (“Brightwork”) privacy notice.
 
Brightwork respects your privacy and is committed to protecting your personal data.
 
Our privacy notice will inform you as to how we look after your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you.
 

Important information and who we are

 

Purpose of this privacy notice

 
This privacy notice aims to give you information on how Brightwork Media Limited collects and processes your personal data through your use of this website, including any data you may provide through this website when you sign in to your client area or purchase a product / service. When we collect, use and are responsible for certain personal information about you, until 11pm on 31st December 2020 we are regulated under the General Data Protection Regulation ("GDPR or EU GDPR") which applies across the European Union (including in the United Kingdom). We are also regulated under the Retained General Data Protection Regulation (“GDPR” or “UK GDPR”) in the United Kingdom from the end of the Brexit implementation period. We are responsible as "controller" of that personal information for the purposes of those laws as described above.
 
This website is not intended for children and we do not knowingly collect data relating to children.
 
It is important that you read this privacy notice together with any other notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data.
 
This privacy notice supplements any other notices and is not intended to override them.
 

Controller & Data Processor

 
Brightwork is the controller and data processor and we are responsible for your personal data (collectively referred to as Brightwork Media Limited "we", "us" or "our" in this privacy notice).
 
We have appointed a data privacy manager who is responsible for overseeing questions in relation to this privacy notice.
 

If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the data privacy manager using the details set out below.

 
Brightwork Media Limited Data Controller

Ben Ravetta

Postal address:

Unit 10, Victoria Hall
CUMBRIA
LA141BX
 

Telephone number:

+44 01229 486772

Email:

ben@brightwork.uk

 
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
 

Changes to the privacy notice and your duty to inform us of changes

 
The data protection laws changed on 25th May 2018.
 
This version of our privacy policy was last updated on 22 Sept. 2022.
 
It is important that the personal data we hold about you is accurate and current.
 
Please keep us informed if your personal data changes during your relationship with us.
 

Third-party links

 
This website may include links to third-party websites, plug-ins and applications.
 
Clicking on those links or enabling those connections may allow third parties to collect or share data about you.
 
We do not control these third-party websites and are not responsible for their privacy statements.
 
When you leave our website, we encourage you to read the privacy notice of every website you visit.
 

The data we collect about you

 

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:

Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.

Contact Data includes billing address, delivery address, e-mail address and telephone numbers.

Financial Data includes bank account and payment card details.

Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.

Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.

Profile Data includes your username and password (if applicable), purchases or orders made by you, your interests, preferences, feedback and survey responses.
 

Usage Data includes information about how you use our website, products and services.

Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

If you fail to provide data:

 
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
 

How is your personal data collected?

 
We use different methods to collect data from and about you including through:
 

Direct interactions

 
You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, e-mail or otherwise. This includes personal data you provide when you:
 
  1. Apply for our products or services;
  2. create an account on our website;
  3. subscribe to our service or publications;
  4. communicate with us through social media platforms, professional network platforms or on video conferencing services;
  5. request marketing to be sent to you;
  6. enter a competition, promotion or survey; or
  7. give us some feedback.
  8. Automated technologies or interactions.
 
As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns.
 
We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our cookie policy for further details.
 

Third parties or publicly available sources.

 
We may receive personal data about you from various third parties and public sources as set out below:
 

Technical Data from the following parties:

  1. Analytics providers;
  2. Affiliate network providers;
  3. Advertising networks; and
  4. Search information providers.
  5. Contact, Financial and Transaction Data from providers of technical, payment and delivery services.
  6. Identity and Contact Data from data brokers or aggregators.
  7. Identity and Contact Data from publicly available sources.
 

How we use your personal data

 
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
 
  1. Where we need to perform the contract we are about to enter into or have entered into with you.
  2. Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  3. Where we need to comply with a legal or regulatory obligation.
 
Generally we do not rely on consent as a legal basis for processing your personal data other than to respond to an enquiry you make to us via our website where by making the enquiry you consent to us using any personal data provided for the purposes of dealing with and responding to that enquiry, or in relation to sending third party direct marketing communications to you via e-mail or text message.
 
You have the right to withdraw consent to marketing at any time by contacting us.
 

Purposes for which we will use your personal data

 

We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

 

Note that we may process your personal data for more than one lawful ground, depending on the specific purpose for which we are using your data.

 

Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.

 
Purpose/ActivityType of dataLawful basis for processing including basis of legitimate interest
To register you as a new customer

(a) Identity

(b) Contact

Performance of a contract with you
To process and deliver your order
including:

(a) Manage payments, fees and
charges

(b) Collect and recover money
owed to us

(a) Identity

(b) Contact

(c) Financial

(d) Transaction

(e) Marketing and
Communications

(a) Performance of a contract with you

(b) Necessary for our legitimate interests
(to recover debts due to us)

To manage our relationship with
you which will include:

(a) Notifying you about changes
to our terms or privacy policy

(b) Asking you to leave a review
or take a survey

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and
Communications

(a) Performance of a contract with you

(b) Necessary to comply with a legal
obligation

(c) Necessary for our legitimate interests
(to keep our records updated and to study
how customers use our products/services)

To enable you to partake in a
prize draw, competition or
complete a survey

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and
Communications

(a) Performance of a contract with you

(b) Necessary for our legitimate interests
(to study how customers use our
products/services, to develop them and
grow our business)

To administer and protect our
business and this website
(including troubleshooting, data
analysis, testing, system
maintenance, support, reporting
and hosting of data)

(a) Identity

(b) Contact

(c) Technical

(a) Necessary for our legitimate interests
(for running our business, provision of
administration and IT services, network
security, to prevent fraud and in the
context of a business reorganisation or
group restructuring exercise)

(b) Necessary to comply with a legal
obligation

To deliver relevant website
content and advertisements to
you and measure or understand
the effectiveness of the
advertising we serve to you

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and
Communications

(f) Technical

Necessary for our legitimate interests (to
study how customers use our
products/services, to develop them, to
grow our business and to inform our
marketing strategy)
To use data analytics to improve
our website, products/services,
marketing, customer relationships
and experiences

(a) Technical

(b) Usage

Necessary for our legitimate interests (to
define types of customers for our products
and services, to keep our website updated
and relevant, to develop our business and
to inform our marketing strategy)
To make suggestions and
recommendations to you about goods or services that may be of
interest to you

(a) Identity

(b) Contact

(c) Technical

(d) Usage

(e) Profile

Necessary for our legitimate interests (to
develop our products/services and grow our business)
To deal with a general enquiry or
careers enquiry

(a) Identity

(b) Contact

(a) Consent

(b) Necessary for our legitimate interests
(recruitment and to communicate with our
customers, partners and other third
parties)

 

Marketing

 
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising:
 
 

Promotional offers from us:

We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).
 

You will receive marketing communications from us if you have requested information from us or purchased goods or services from us or if you provided us with your details when you entered a competition or registered for a promotion and, in each case, you have not opted out of receiving that marketing.

 

Third-party marketing

We will get your express opt-in consent before we share your personal data with any company outside of Brightwork for marketing purposes.
 

Opting out

You can ask us or third parties to stop sending you marketing messages at any time by contacting us at any time.
 

Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase, warranty registration, product/service experience or other transactions.

 

Cookies

 

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy.

 

Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
 
If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
 
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
 
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
 

Disclosures of your personal data

We may have to share your personal data with the parties set out below for the purposes:
  1. Subsidiary companies within the Brightwork Media Limited group;
  2. External Third Parties we use to help deliver our services to you, eg payment service providers or domain name registration organisations;
  3. External Third Parties we use to help us run our business, eg accountants;
  4. External Third Parties to whom we may choose to sell, transfer, acquire, or merge parts of our business or our assets;
  5. Stripe for payment, analytics, and other business services. Stripe collects identifying information about the devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
  6. External auditors, eg in relation the audit of our accounts; and
  7. Law enforcement agencies, taxation authorities and regulatory bodies to comply with our legal, taxation and regulatory obligations;
 
We only allow our service providers to handle your personal data if we are satisfied they have appropriate technical and security measures to protect your personal data and treat it in accordance with the law. We also impose contractual obligations and/or risk assessments on service providers to ensure they only use your personal data to provide services to us and to you.
 

For a full list of the External Third Parties we share data with please follow this link.

International transfers

 

We share your data within Brightwork including any of our subsidiary companies and on occasion with third party suppliers where required and listed specifically within our Glossary. This might involve transferring your data outside the United Kingdom (UK) / European Economic Area (EEA).

Many of our external third parties are based outside the UK and/or European Economic Area (EEA) so their processing of your personal data will involve a transfer of data outside the UK / EEA. Whenever we transfer your personal data out of the UK / EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  1. We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  2. Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
 

We ensure your personal data is protected by requiring all our third parties to follow the same rules when processing your personal data. These rules are either the SCC, as described later in this clause 6, or are "binding corporate rules".

If, in the course of providing the Services, you are a Controller and we are your Processor in respect of any Personal Data, and the United Kingdom is or becomes a “third country” for the purpose of Chapter V of Regulation 2016/679, unless and until such time as the European Commission has decided that the United Kingdom ensures an adequate level of protection for the purposes of Chapter V of Regulation 2016/679, we and you shall, in respect of any transfer of Personal Data subject to Chapter V of Regulation 2016/679 which is neither on the basis of an adequacy decision nor subject to any of the permitted derogations set out in that Chapter V, enter automatically into the Standard Contractual Clauses for the transfer of personal data to processors established in third countries (controller to processor transfers) approved by the European Commission by Commission Decision 2010/87/EU, currently available at https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32010D0087

 

For the purposes of any Standard Contractual Clauses which we enter into with you by virtue of clause 6.3, we are the “data importer” and you are the “data exporter”. We will Process the Personal Data only for the purpose of providing the Services. The Data Subjects are anyone whose Personal Data you include in the data you upload to the Services, most probably your staff or your users, or people linked with your users. The Personal Data transferred, including any special categories of data, are decided solely by you. You confirm that you will inform us prior to any data transfer if you feel that the jurisdiction the data is being transferred to is a jurisdiction where the data subjects’ rights are not enforceable (where rights such as access, rectification and deletion are undermined) and effective legal remedies (particularly in case of access to data by public authorities in the recipient country) are not essentially equivalent. We will also keep this situation under regular review in order to ensure we only transfer data to countries where their laws that impose requirements to disclose personal data to public authorities are limited to what is necessary and proportionate in a democratic society.

 

If, in the course of providing the Services, you are a Controller and you transfer Personal Data to us as a Controller, and the United Kingdom is or becomes a “third country” for the purpose of Chapter V of Regulation 2016/679, unless and until such time as the European Commission has decided that the United Kingdom ensures an adequate level of protection for the purposes of Chapter V of Regulation 2016/679, we and you shall, in respect of any transfer of Personal Data subject to Chapter V of Regulation 2016/679 which is neither on the basis of an adequacy decision nor subject to any of the permitted derogations set out in that Chapter V, enter automatically into the Standard Contractual Clauses for the transfer of personal data from the Community to third countries (controller to controller transfers) annexed to the European Commission Decision 2004/915/EC (Set II), currently available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32004D0915

 
For the purposes of any Standard Contractual Clauses which we enter into with you by virtue of clause 6.4, we are the “data importer” and you are the “data exporter”, and we both elect option (iii) (the data processing principles set forth in Annex A) for the purpose of clause II(h). We will Process the Personal Data only for the purposes set out in this Privacy Policy. The Data Subjects are anyone whose Personal Data is provided to us during account registration, most probably your staff. The Personal Data transferred concerns basic personal details, contact information, data related to your staff’s internet connectivity (in the form of IP addresses) and, if you contract with us as an individual, your payment information. We do not collect any sensitive data. You confirm that you will inform us prior to any data transfer if you feel that the jurisdiction the data is being transferred to is a jurisdiction where the data subjects’ rights are not enforceable (where rights such as access, rectification and deletion are undermined) and effective legal remedies (particularly in case of access to data by public authorities in the recipient country) are not essentially equivalent. We will also keep this situation under regular review in order to ensure we only transfer data to countries where their laws that impose requirements to disclose personal data to public authorities are limited to what is necessary and proportionate in a democratic society.
 

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK or EEA, see contact details for the Data Privacy Manager at section 1 of this Privacy Policy.

Data security

 

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.

 

They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

 

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Data retention

 

How long will you use my personal data for?

 

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

 

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

 

By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for 6 years after they cease being customers for tax purposes. In some circumstances you can ask us to delete your data: see request erasure below for further information.

 

In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

 

Your legal rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data.

 
  1. Request access to your personal data.
  2. Request correction of your personal data.
  3. Request erasure of your personal data.
  4. Object to processing of your personal data.
  5. Request restriction of processing your personal data.
  6. Request transfer of your personal data.
  7. Right to withdraw consent.
 
If you wish to exercise any of the rights set out above, please contact us.
 
 

No fee usually required.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, excessive or likely to take a great deal of time. Alternatively, we may refuse to comply with your request in these circumstances.

 
 

What we may need from you

 

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

 

Time limit to respond

 

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

 

Glossary

 
LAWFUL BASIS
 

Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.

Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.

 

YOUR LEGAL RIGHTS

 

You have the right to:

Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

Data Processing Agreement

 

These terms set out the additional terms requirements and conditions on which we will process personal data when providing services to you.

 

This Agreement contains the mandatory clauses required by article 28(3) of the General Data Protection Regulation ((EU) 2016/679) for Agreements between data controllers.

 

We are Brightwork Media Limited a company incorporated and registered in England and Wales with company number 12866475 whose registered office is at Unit 10, Victoria Hall, Barrow in Furness, CUMBRIA, LA141BX.

By purchasing our services you confirm that you accept these terms of data processing and you agree to comply with them. If you do not agree with these terms, you must not purchase services from us.

We recommend that you print a copy of these terms for your future reference.

AGREED TERMS

 

Definitions and interpretation

 
The following definitions and rules of interpretation apply in this Agreement.
 
 
Definitions:
 
Data Subject:
An individual who is the subject of Personal Data.
 
 
Personal Data:

Means any information relating to an identified or identifiable natural person that is processed by the Data Processor as a result of, or in connection with, the provision of the services; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

 
Processing, processes and process:

Either any activity that involves the use of Personal Data or as the Data Protection Legislation may otherwise define processing, processes or process. It includes any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording. organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Processing also includes transferring Personal Data to third parties.

 
Data Protection Legislation:

All applicable privacy and data protection laws including the General Data Protection Regulation ((EU) 2016/679) and any applicable national implementing laws, regulations and secondary legislation in England and Wales relating to the processing of Personal Data and the privacy of electronic communications, as amended, replaced or updated from time to time, including the Privacy and Electronic Communications Directive (2002/58/EC) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426) and also the Retained General Data Protection Regulation (EU) 2016/679 and applicable UK laws from the end of the Brexit implementation period.

 

Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.

 
Standard Contractual Clauses (SCC): The European Commission's Standard Contractual Clauses for the transfer of Personal Data from the European Union to processors established in third countries as set out in Commission Decision 2010/87/EU.
 

This Agreement is subject to the terms of any separate agreement made between the parties for the supply of services (“Services Agreement”) and is incorporated into any such Agreement. Interpretations and defined terms set forth in the Services Agreement apply to the interpretation of this Agreement.

The Annexes form part of this Agreement and will have effect as if set out in full in the body of this Agreement. Any reference to this Agreement includes the Annexes.

A reference to writing or written excludes faxes and e-mail.

In the case of conflict or ambiguity between:
  1. Any provision contained in the body of this Agreement and any provision contained in the Annexes, the provision in the body of this Agreement will prevail;
  2. The terms of any accompanying invoice or other documents annexed to this Agreement and any provision contained in the Annexes, the provision contained in the Annexes will prevail; and
  3. Any of the provisions of this Agreement and the provisions of the Services Agreement, the provisions of the Services Agreement will prevail.
 

This agreement is in addition to and does not remove or replace a party’s obligations under the Data Protection Legislation.

In this agreement we are the Data Processor and you are the Data Controller.

2. Personal data types and processing purposes

 
The Data Controller retains control of the Personal Data and remains responsible for its compliance obligations under the applicable Data Protection Legislation, including providing any required notices and obtaining any required consents, and for the processing instructions it gives to the Data Processor.

ANNEX A describes the subject matter, duration, nature and purpose of processing and the Personal Data categories and Data Subject types in respect of which the Data Processor may process to provide services to the Data Controller under the terms of the Services Agreement or otherwise.

3. Data Processor's obligations

 

The Data Controller acknowledges that for the purposes of fulfilling its obligations under the Agreement the Data Processor may have access to and may be required to process Personal Data (as defined in the Data Protection Legislation) on behalf of the Data Controller and in accepting the Agreement the Data Controller authorises the Data Processor to process its Personal Data in accordance with the terms of this Clause 3.

Both parties will comply with all applicable requirements of the Data Protection Legislation. This clause 3 is in addition to, and does not relieve, remove or replace, a party's obligations under the Data Protection Legislation.

The parties acknowledge that for the purposes of the Data Protection Legislation, the Data Controller is the data controller and the Data Processor is the data processor (where Data Controller and Data Processor have the meanings as defined in the Data Protection Legislation).

Without prejudice to the generality of clause 3.2, the Data Controller will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of the Personal Data to the Data Processor for the duration and purposes of this agreement.

Without prejudice to the generality of clause 3.2, the Data Processor shall, in relation to any Personal Data processed in connection with the performance by the Data

Processor of its obligations under this agreement:

Process that Personal Data only on the written instructions of the Data Controller unless the Data Processor is required by the laws of any member of the European Union or by the laws of the European Union applicable to the Data Processor to process Personal Data (Applicable Laws). Where the Data Processor is relying on laws of a member of the European Union or European Union law as the basis for processing Personal Data, the Data Processor shall promptly notify the Data Controller of this before performing the processing required by the Applicable Laws unless those Applicable Laws prohibit the Data Processor from so notifying the Data Controller;
Ensure that it has in place appropriate technical and organisational measures, to protect against unauthorised or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, appropriate to the harm that might result from the unauthorised or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures (those measures may include, where appropriate, pseudonymising and encrypting Personal Data, ensuring confidentiality, integrity, availability and resilience of its systems and services, ensuring that availability of and access to Personal Data can be restored in a timely manner after an incident, and regularly assessing and evaluating the effectiveness of the technical and organisational measures adopted by it);
Ensure that all personnel who have access to and/or process Personal Data are obliged to keep the Personal Data confidential; and
Subject to clause 3.10 to not transfer any Personal Data outside of the UK / European Economic Area (“EEA”) unless the prior written consent of the Data Controller has been obtained and the following conditions are fulfilled:
The Data Controller or the Data Processor has provided appropriate safeguards in relation to the transfer;
The data subject has enforceable rights and effective legal remedies;
The Data Processor complies with its obligations under the Data Protection Legislation by providing an adequate level of protection to any Personal Data that is transferred; and
The Data Processor complies with reasonable instructions notified to it in advance by the Data Controller with respect to the processing of the Personal Data;
If so reasonably required, assist the Data Controller, at the Data Controller's cost, in responding to any request from a Data Subject and in ensuring compliance with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
Notify the Data Controller without undue delay on becoming aware of a Personal Data breach;
If so reasonably required, at the written direction of the Data Controller, delete or return Personal Data and copies thereof to the Data Controller on termination of the agreement unless required by Applicable Law to store the Personal Data; and
If so reasonably required, maintain complete and accurate records and information to demonstrate its compliance with this clause 3.
In accepting these Terms and Conditions the Data Controller consents to the Data Processor appointing third-party processors of Personal Data (“the Sub Processors”) under this agreement.
The Data Processor shall enter with the Sub Processors into a written agreement incorporating terms which are substantially similar to those set out in this clause 3 prior to any Sub Processor being appointed.
The Data Controller accepts that for the purposes of this Agreement part or all of its Personal Data may need to be processed outside of the UK or EEA and the Data Controller further consents to the Data Processor processing its Personal Data in appointing these third party processors referred to in section 5. Glossary who are located outside of the UK / EEA.
The Data Controller shall have the ability to withdraw its consent to the Data Processor’s use of Sub Processor for the purposes of fulfilling this Agreement by notifying the Data Processor in writing at its registered office. However the Data Controller acknowledges that the Data Processor may not be able to perform the Services or any part of the Services unless it is able to appoint an alternative Sub Processor and where an alternative Sub Processor cannot be appointed, the Data Processor shall not be obliged to provide any part of the Services which are so affected.
The Data Processor may, at any time on not less than 30 days’ notice, revise this clause 3 by replacing it with any applicable controller to processor standard clauses or similar terms forming part of an applicable certification scheme (which shall apply when replaced by attachment to this agreement).
4. Term and termination
 
This Agreement will remain in full force and effect so long as: (a) the Services Agreement remains in effect or the Data Processor provides the relevant services to the Data Controller, or (b) the Data Processor retains any Personal Data related to the Services Agreement and/or the services in its possession or control.
Any provision of this Agreement that expressly or by implication should come into or continue in force on or after termination of the Services Agreement or the provision of services by the Data Processor to the Data Controller (as may be applicable) in order to protect Personal Data will remain in full force and effect.
If a change in any Data Protection Legislation prevents either party from fulfilling all or part of its obligations to the other party, the parties will suspend the processing of Personal Data until that processing complies with the new requirements. If the parties are unable to bring the Personal Data processing into compliance with the Data Protection Legislation within 28 days, they may terminate the Services Agreement and/or the provision of services on written notice to the other party without prejudice to any right or remedy the parties may have under the Services Agreement or otherwise.
5. Notice
 

 1. Any notice or other communication given to a party under or in connection with the Agreement must be in writing and delivered to:

 
For the Data Controller: The address provided under the Services Agreement.
 
For the Data Processor: Ben Ravetta
Address: Brightwork Media Limited, Unit 10, Victoria Hall, Barrow in Furness, CUMBRIA, LA141BX.

E-mail: ben@brightwork.uk.

 
Clause 5.1 does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.

A notice given under this agreement is valid if sent by post or by e-mail.

General

 

If any provision or part-provision of this Agreement is or becomes invalid, illegal or unenforceable, it shall be deemed modified to the minimum extent necessary to make it valid, legal and enforceable. If such modification is not possible, the relevant provision or part-provision shall be deemed deleted. Any modification to or deletion of a provision or part-provision under this clause shall not affect the validity and enforceability of the rest of this Agreement.

 

If any provision or part-provision of this Agreement is invalid, illegal or unenforceable, the parties shall negotiate in good faith to amend such provision so that, as amended, it is legal, valid and enforceable, and, to the greatest extent possible, achieves the intended commercial result of the original provision.

 

Waiver.

A waiver of any right under this Agreement or law is only effective if it is in writing and shall not be deemed to be a waiver of any subsequent breach or default. No failure or delay by a party in exercising any right or remedy provided under this Agreement or by law shall constitute a waiver of that or any other right or remedy, nor shall it prevent or restrict its further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy shall prevent or restrict the further exercise of that or any other right or remedy.

 

No partnership or agency.

Nothing in this Agreement is intended to, or shall be deemed to, establish any partnership or joint venture between the parties, nor constitute either party the agent of the other for any purpose. Neither party shall have authority to act as agent for, or to bind, the other party in any way.

 

Third parties.

A person who is not a party to this Agreement shall not have any rights to enforce its terms. Variation. Except as set out in these Conditions, no variation of this Agreement, including the introduction of any additional terms and conditions, shall be effective unless it is agreed in writing and signed by the Data Processor.

 

Governing law.

This Agreement, and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims), shall be governed by, and construed in accordance with the law of England. Jurisdiction. Each party irrevocably agrees that the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Agreement or its subject matter or formation (including non-contractual disputes or claims).

 
ANNEX A Personal Data Processing Purposes and Details
 
Subject matter of processing: [Services]
 
Duration of Processing: The Term as set out at Clause 4.1
 
Nature of Processing: [Storage]
 
Business Purposes: Performance of our Services Agreement
 
Personal Data Categories: [Identity, Data, Financial Data, Transaction Data, Technical Data, Profile Data, Usage Data, Marketing & Communications Data and any other such date as collected by the Data Controller on its website]
 
Data Subject Types: [any user of the Data Controller’s website]
 
Located in a country with a current determination of adequacy.
Binding Corporate Rules.
Standard Processing Clauses between Customer as "data exporter" and Provider as "data importer".
Standard Processing Clauses between Provider as "data exporter" on behalf of Customer and Provider affiliate or Sub Processor as "data importer".
Content
Content