Services Contract Framework

Terms and Conditions

LEGAL · YZS-UK-TAC-2026

These Terms and Conditions govern professional technology and cybersecurity services supplied by YOUZSE LTD under statements of work and related agreements.

1. Parties, Definitions and Interpretation

These Terms and Conditions ("Conditions") govern the supply of professional technology services by YOUZSE LTD ("Supplier", "YOUZSE", "we", "us" or "our") to the client identified in the applicable proposal, statement of work, order or master services agreement ("Client", "you" or "your").

YOUZSE LTD operates from 66 Paul Street, LONDON, EC2A 4NA United Kingdom. Primary operational contacts include email tech@youzse.fit and telephone +44 7127 995133. Our public website is youzse.fit.

In these Conditions: "Agreement" means these Conditions together with the applicable Statement of Work ("SOW"), proposal, schedules and any data processing agreement; "Deliverables" means documents, software, configurations, designs, reports, code, scripts, architectures, runbooks and other materials to be supplied under an SOW; "Services" means the services described in an SOW, which may include cybersecurity services, computer systems design, cloud computing solutions, software development services, enterprise infrastructure services, web hosting services, API development, database management, data processing, content delivery network services, streaming platform solutions, artificial intelligence solutions, DevOps and automation, digital platform development and related consultancy; "Client Materials" means data, content, software, credentials, documentation and systems provided by or on behalf of the Client; "Business Day" means a day other than Saturday, Sunday or a public holiday in England; "Confidential Information" means non-public information disclosed by either party marked confidential or that ought reasonably to be considered confidential; "Personal Data", "Controller", "Processor", "Processing" and "Data Subject" have the meanings in UK GDPR; "Force Majeure Event" means an event beyond a party's reasonable control including act of God, epidemic, war, terrorism, riot, embargo, utility failure, widespread Internet backbone failure, industrial dispute affecting third parties, or failure of a critical upstream cloud or network provider not caused by the affected party.

Headings are for convenience only. References to statutes include amendments. "Including" means including without limitation. If there is conflict, the SOW prevails over these Conditions for the specific engagement, except that clauses on liability, governing law, intellectual property ownership defaults, and data protection may not be reduced below mandatory legal requirements by an SOW unless expressly and specifically negotiated in writing by authorised signatories.

2. Formation of Contract

A contract is formed when the Client accepts a written proposal or SOW issued by YOUZSE LTD, whether by signature, confirmed email acceptance from an authorised representative, issuance of a purchase order expressly referencing the proposal, or another method stated in the proposal.

Website enquiries, calls to +44 7127 995133, or messages to tech@youzse.fit do not themselves create a contract for Services. Estimates provided for discussion are indicative unless expressly stated as fixed and accepted.

These Conditions apply to the exclusion of any Client purchase terms unless YOUZSE LTD expressly agrees in writing to specific Client terms. Any commencement of work following Client instruction may be treated as acceptance of these Conditions and the relevant SOW.

Each SOW is a separate contract incorporating these Conditions, unless a master services agreement states otherwise.

3. Scope of Services and Change Control

YOUZSE LTD shall provide the Services with reasonable skill and care consistent with professional standards reasonably expected of a United Kingdom technology and cybersecurity services provider of similar size and specialisation.

The scope, assumptions, dependencies, timelines, fees and acceptance criteria are set out in the SOW. Services outside scope require a written change request. Either party may propose changes; YOUZSE LTD will assess impact on fee, schedule and risk and will not be obliged to perform out-of-scope work until the change is agreed in writing.

Client delays in providing Client Materials, access, decisions or approvals may result in schedule adjustment and additional charges for idle or remobilisation effort where reasonably incurred.

Unless an SOW states otherwise, Services are provided on a business-hours basis in the United Kingdom, excluding English public holidays. Critical support windows, if any, must be expressly purchased and described.

4. Cybersecurity Services

Cybersecurity Services may include security architecture reviews, control assessments, vulnerability assessment coordination, hardening guidance, identity and access reviews, security monitoring design, incident response preparedness, policy and standard drafting support, and verification of remediation status.

The Client authorises YOUZSE LTD to perform agreed testing and inspection only within the defined scope, assets, time windows and rules of engagement. The Client warrants it owns or is authorised to permit testing of all in-scope systems. Out-of-scope testing is prohibited.

Cybersecurity findings are point-in-time observations. They do not guarantee that systems are free of vulnerabilities or will remain secure. The Client remains responsible for implementing remediation unless the SOW expressly includes remediation services.

Reports are Confidential Information. The Client shall not represent YOUZSE LTD findings as a formal certification, regulated audit opinion or guarantee of compliance with any specific standard unless the SOW expressly provides such an opinion and identifies the standard and limitations.

If during Services we discover evidence of active compromise, we will notify the Client designated contact promptly and may suspend intrusive testing to avoid worsening impact, pending Client instruction.

For cybersecurity services, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

5. Computer Systems Design and Enterprise Infrastructure

Computer systems design and enterprise infrastructure Services may include capacity planning, network and compute architecture, high-availability design, disaster recovery planning, configuration standards, documentation of operating models and migration planning.

Designs are based on information provided by the Client and on discoveries made during engagement. Material inaccuracies in Client-provided inventories may require redesign and additional fees.

Unless the SOW includes build and operate responsibilities, YOUZSE LTD provides design and advisory Deliverables; implementation by Client or third parties is outside our responsibility.

Recommended architectures may depend on third-party cloud, hardware or software products. We do not warrant third-party products. Licensing and support contracts for third-party products remain the Client's responsibility unless we expressly resell or provision them under the SOW.

For computer systems design and enterprise infrastructure, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

6. Cloud Computing Solutions

Cloud computing Services may include landing zone design, account organisation, identity federation, networking, landing security baselines, cost visibility design, workload migration support and operational readiness.

The Client remains the cloud account owner unless otherwise agreed. The Client must maintain authoritative billing relationships with cloud providers. YOUZSE LTD shall not be liable for cloud consumption charges incurred in Client accounts, including charges arising from misconfiguration by Client personnel or from traffic following go-live, except to the extent caused by our proven negligence in performing in-scope configuration and not mitigated after notice.

Shared responsibility models of cloud providers apply. YOUZSE LTD responsibilities are limited to the SOW. The Client retains responsibility for data classification, lawful processing, endpoint security and user behaviour unless expressly included.

Access keys and privileged credentials provided to YOUZSE LTD must be rotated by the Client after the engagement or as otherwise agreed. We will handle credentials as Confidential Information and use least privilege where practicable.

For cloud computing solutions, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

7. Software Development Services

Software development Services may include custom application development, integration components, internal tools, scripts and related documentation. Development methodology, repositories, environments and acceptance tests shall be stated in the SOW or agreed project plan.

The Client shall provide timely feedback on iterations. Acceptance is deemed given if the Client does not provide written rejection specifying material non-conformities within the acceptance period stated in the SOW (or ten Business Days if none is stated).

Unless otherwise agreed, warranty for Deliverable software is limited to material conformity to agreed specifications for thirty (30) days after acceptance. Warranty excludes defects caused by Client modifications, third-party changes, unsuitable environment or misuse.

Open-source components may be included under their licences. The Client agrees to comply with applicable open-source licences for distribution. We will identify material copyleft components on request where reasonably identifiable from our dependency manifests.

For software development services, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

8. API Development and Integration

API Services may include design of interfaces, authentication patterns, rate limiting approaches, documentation, versioning strategy and integration with Client or third-party systems.

The Client is responsible for obtaining rights to integrate with third-party APIs and for complying with third-party developer terms. YOUZSE LTD is not liable for third-party API changes, deprecations or outages.

Security of API credentials, rotation policies and secret storage in Client environments remain Client responsibilities unless secret management implementation is in scope.

Performance benchmarks, if any, must be expressly defined. Absent defined benchmarks, APIs will be developed to meet reasonable professional standards for the stated use case without guaranteed throughput.

For api development and integration, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

9. Database Management and Data Processing

Database and data processing Services may include schema design, migration, performance tuning, backup strategy design, replication design, ETL or ELT pipeline development and data quality controls.

The Client warrants that it has lawful rights to provide datasets for processing and that datasets do not unlawfully include special category or criminal offence data unless expressly disclosed and agreed with appropriate safeguards.

Non-production environments should use anonymised or synthetic data where feasible. If production personal data must be used, a data processing agreement and heightened controls are required.

We do not guarantee discovery of all data quality defects. Migration cutover risks remain significant; rollback plans, if required, must be scoped. YOUZSE LTD is not responsible for business decisions made using Client data outputs.

For database management and data processing, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

10. Web Hosting Services

Where YOUZSE LTD provides hosting, the SOW will specify environment, resources, supported software stacks, backup frequency, restore objectives targets (if any), and support channels.

Hosting is subject to fair use and acceptable use. The Client must not host unlawful content, operate abusive mailers, mine cryptocurrency without written approval, or interfere with other tenants if on shared infrastructure.

Service credits, if offered, are the exclusive remedy for failure to meet stated availability targets, and are calculated as specified in the SOW. Absent an availability target, hosting is provided on a commercially reasonable efforts basis.

The Client must maintain its own application-level security, patching of Client-managed components, and content legality. We may suspend hosting for security, legal or non-payment reasons after notice where practicable.

For web hosting services, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

11. Content Delivery Networks and Streaming Platform Solutions

CDN and streaming Services may include architecture, configuration, caching policy design, origin shielding approaches, media workflow design, packaging guidance, access control design and performance troubleshooting support.

Delivery quality depends on end-user networks, device capabilities, licensed content media characteristics and third-party CDN or streaming vendor behaviour. We do not warrant uninterrupted global delivery or specific buffer-free playback metrics unless expressly committed in the SOW with measurement methodology.

The Client is responsible for content licensing, takedown compliance, age-gating where required, and for ensuring streaming of content does not infringe third-party rights.

Logs from CDN and streaming systems may contain Personal Data such as IP addresses. Roles as Controller or Processor shall be set out in the data processing schedule. Abuse mitigation (for example credential stuffing against video tokens) may require cooperative configuration changes.

For content delivery networks and streaming platform solutions, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

12. Artificial Intelligence Solutions

AI Services may include solution design, model selection advisory, prompt engineering support, evaluation harnesses, integration of AI APIs, governance documentation support and limited custom model work as scoped.

AI outputs may be inaccurate, biased or incomplete. The Client must implement human oversight appropriate to risk before relying on outputs for decisions that materially affect individuals or critical operations.

The Client shall not use AI Deliverables to unlawfully process Personal Data, to create deceptive deepfakes, to violate export controls, or to automate decisions in breach of UK GDPR Article 22 without required safeguards.

Unless expressly agreed, Client data will not be used by YOUZSE LTD to train generalised models for other customers. Third-party AI providers may have their own data use terms; the Client must approve use of such providers.

Intellectual property in prompts, evaluation sets and integration code shall follow Section 18 unless the SOW states otherwise. Model weights from third parties remain subject to third-party licences.

For artificial intelligence solutions, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

13. DevOps, Automation and Digital Platform Development

DevOps and digital platform Services may include CI/CD pipeline design, infrastructure as code, environment promotion strategies, observability design, platform engineering, developer portal components and operational runbooks.

Automation can cause rapid widespread change. The Client must ensure segregation of duties, approval gates and rollback strategies appropriate to risk. YOUZSE LTD is not liable for production incidents caused by Client approval of changes that bypass agreed controls.

Platform acceptance criteria should include security baseline checks. Continuous delivery does not eliminate the need for change records in regulated environments; the Client remains responsible for its regulatory change management obligations.

Access to deployment credentials must be controlled. Upon engagement end, Client shall revoke Supplier access promptly.

For devops, automation and digital platform development, the Client shall designate a technical product owner authorised to make decisions. Meetings, workshops and remote sessions may be recorded only with prior notice and agreement. Travel, if required beyond remote delivery from our London base, is chargeable at cost plus any agreed rate unless included in the SOW. YOUZSE LTD may use suitably qualified subcontractors, remaining responsible for their performance as if they were our own employees, subject to confidentiality and data protection terms.

14. Client Obligations

The Client shall: provide accurate information; obtain all consents and authorisations necessary for YOUZSE LTD to perform Services; maintain appropriate backups before invasive changes; ensure personnel cooperate reasonably; provide secure remote access methods; identify known hazardous conditions in scope environments; comply with applicable laws; and pay fees when due.

The Client shall not request Services that would require YOUZSE LTD to commit unlawful acts, including unauthorised access to third-party systems. If an instruction appears unlawful or unsafe, we may refuse or suspend performance and will explain our concerns.

The Client remains responsible for its own regulatory compliance, including sectoral regulations, except to the extent the SOW expressly transfers specific compliance tasks to YOUZSE LTD.

15. Fees, Invoicing and Taxes

Fees may be fixed price, time and materials, retainer, or consumption-based as stated in the SOW. Expenses reasonably incurred with prior approval are reimbursable. Rates may be adjusted on renewal or on thirty days' notice for ongoing retainers, not more than once per twelve months unless costs materially change due to Client-driven scope expansion.

Invoices are payable within thirty (30) days of invoice date unless otherwise stated, in pounds sterling, without set-off except as required by law. Late sums may accrue interest under the Late Payment of Commercial Debts (Interest) Act 1998.

Fees are exclusive of VAT and other taxes, which the Client shall pay at the applicable rate. If the Client is required to withhold tax, it shall gross up payments so that YOUZSE LTD receives the amount it would have received without withholding, except where treaty relief is properly applied and documented.

We may suspend Services for non-payment after providing at least seven days' written notice. Suspension does not constitute termination or waive sums due.

16. Non-Solicitation

During the term of an Agreement and for six (6) months thereafter, neither party shall, without prior written consent, solicit for employment any employee of the other who was materially involved in the Services, provided that general recruitment advertising not targeted at such individuals is permitted. This clause does not restrict hiring following unsolicited applications.

17. Confidentiality

Each party shall keep the other party's Confidential Information confidential and use it only to perform the Agreement. Disclosure is permitted to personnel and advisers with a need to know who are bound by confidentiality obligations no less protective, and where required by law, court order or regulation, provided the disclosing party gives prior notice where legally permitted.

Confidentiality obligations do not apply to information that is public other than by breach, independently developed, already known without duty, or rightfully received from a third party without duty.

Upon written request at termination, a party shall return or securely destroy the other party's Confidential Information, except for copies retained under bona fide backup policies or for legal retention, which remain subject to confidentiality.

Obligations survive for five (5) years after termination, and indefinitely for trade secrets for so long as they remain trade secrets under applicable law.

18. Intellectual Property

18.1 Pre-existing IP

Each party retains all right, title and interest in its pre-existing intellectual property. YOUZSE LTD retains its methodologies, frameworks, verification registers concepts, templates, tools, scripts libraries and know-how developed independently of the Client, including improvements thereto that are not Client-specific Deliverables ("Supplier IP").

18.2 Deliverables

Upon full payment of fees due for the relevant Deliverables, and except for Supplier IP and third-party materials, YOUZSE LTD assigns to the Client the intellectual property rights in bespoke Deliverables created specifically for the Client under the SOW. Until payment, YOUZSE LTD grants a limited licence to use Deliverables solely for evaluation.

18.3 Licence to Supplier IP

Where Deliverables incorporate Supplier IP, YOUZSE LTD grants the Client a non-exclusive, non-transferable, worldwide licence to use such Supplier IP solely as embedded in the Deliverables for the Client's internal business purposes, unless a broader licence is agreed in the SOW.

18.4 Client Materials

Client retains ownership of Client Materials. Client grants YOUZSE LTD a licence to use Client Materials solely to perform the Services. Client warrants it has rights to grant such licence.

18.5 Feedback

Suggestions provided by Client regarding Supplier IP may be used by YOUZSE LTD without obligation, provided Client Confidential Information is not disclosed.

18.6 Residual knowledge

Nothing prevents YOUZSE LTD personnel from using residual general knowledge, skills and experience retained in intangible form after performing Services, provided Confidential Information and Client Personal Data are not disclosed or reused unlawfully.

19. Data Protection

Each party shall comply with UK GDPR, the Data Protection Act 2018 and PECR where applicable. The roles of the parties (Controller, Processor or independent Controllers) shall be identified in the SOW or data processing schedule.

Where YOUZSE LTD acts as Processor, we shall: process Personal Data only on documented Client instructions; ensure personnel confidentiality; implement appropriate technical and organisational measures; not engage sub-processors without authorisation and flow-down obligations; assist with data subject rights and DPIAs reasonably, at Client cost if effort is material and not caused by our breach; delete or return Personal Data at the end of services subject to legal retention; and make available information necessary to demonstrate compliance, including allowing audits on reasonable notice no more than once annually unless required by a supervisory authority or breach.

International transfers by YOUZSE LTD as Processor shall use approved transfer mechanisms. Client instructions that require unlawful processing may be refused.

Where each party acts as independent Controller, each determines its own purposes and means and shall provide appropriate privacy notices to Data Subjects.

Details of processing (subject matter, duration, nature, purpose, types of Personal Data and categories of Data Subjects) shall be set out in a schedule. Our general privacy practices for data we control are described at privacy-policy.html.

Breach notification between parties shall occur without undue delay after becoming aware of a Personal Data Breach affecting the other party's data, with information reasonably available at the time and supplemented as known.

20. Security Standards in Delivery

YOUZSE LTD shall apply security practices appropriate to the Services, which may include secure configuration baselines, encrypted communications for remote administration, least-privilege access, logging of privileged actions where feasible, vulnerability management for systems we operate, and secure development practices for software we write.

The Client shall maintain complementary controls on systems it operates. Shared responsibility matrices in cloud and hosting engagements shall be documented where material.

Security questionnaires may be completed on reasonable request. On-site audits require mutual scheduling, confidentiality and limitation to relevant controls. Penetration testing against YOUZSE LTD corporate systems requires advance written authorisation.

Credentials issued to YOUZSE LTD must be unique, rotatable and preferably time-bound. The Client should enable multi-factor authentication on systems accessed by us.

21. Warranties and Disclaimers

YOUZSE LTD warrants that Services will be performed with reasonable skill and care and that it has the right to grant licences expressly granted herein.

Except as expressly stated, all other warranties, conditions and terms implied by statute or common law are excluded to the fullest extent permitted, including fitness for a particular purpose and satisfactory quality in relation to Deliverables that are digital services and professional advice.

Security, cloud, AI, CDN, streaming and DevOps outcomes depend on Client environment factors beyond our control. We do not warrant uninterrupted operation, absolute security, freedom from vulnerabilities, or that AI outputs will be error-free.

Third-party products and open-source software are provided "as is" as between YOUZSE LTD and the Client, without prejudice to licences from rights holders.

22. Indemnities

22.1 Supplier IP indemnity

Subject to the liability cap and exclusions, YOUZSE LTD shall indemnify the Client against third-party claims that paid bespoke Deliverables created by YOUZSE LTD infringe UK intellectual property rights, provided Client gives prompt notice, allows control of defence and settlement (not admitting liability without consent not to be unreasonably withheld), and provides reasonable cooperation. This indemnity does not apply to claims arising from Client Materials, Client modifications, combination with items not provided by us, or compliance with Client designs.

22.2 Client indemnity

Client shall indemnify YOUZSE LTD against claims arising from Client Materials, Client's failure to obtain authorisations for testing or access, content streamed or hosted by Client, Client's unlawful instructions, or Client's breach of third-party API or cloud terms.

22.3 Mitigation

If infringement is claimed against Deliverables, we may procure rights, modify Deliverables, or refund fees for the infringing portion upon return, as exclusive remedy for infringement claims under this clause beyond the indemnity defence obligations.

23. Limitation of Liability

Nothing excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot be limited under English law.

Subject to the foregoing, neither party shall be liable for indirect or consequential loss, loss of profits, loss of revenue, loss of business, loss of goodwill, loss of anticipated savings, or loss or corruption of data (except to the extent data recovery is an express paid Service and then only for the direct cost of re-performing that Service).

Subject to the foregoing, YOUZSE LTD's total aggregate liability under or in connection with each Agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise, shall not exceed the total fees paid by the Client to YOUZSE LTD under that Agreement in the twelve (12) months preceding the claim (or, if less than twelve months have elapsed, the fees paid to date under that Agreement).

The parties agree that the fees reflect this allocation of risk. Clients requiring higher liability caps must negotiate them expressly in writing before work begins, which may require adjusted fees and insurance.

24. Insurance

YOUZSE LTD shall maintain professional indemnity and public liability insurance at commercially reasonable levels for a firm of its nature while providing Services, and shall provide evidence of cover on reasonable request. Insurance does not increase liability caps except where mandatory law requires.

25. Term, Suspension and Termination

An Agreement commences on the effective date in the SOW and continues until Services are completed or until terminated under these Conditions.

Either party may terminate an Agreement for material breach if the breach is not cured within thirty (30) days after written notice specifying the breach (or immediately if the breach is not reasonably capable of cure).

Either party may terminate immediately if the other becomes insolvent, enters administration, liquidation or analogous proceedings, or ceases to trade.

YOUZSE LTD may suspend Services for non-payment, for unlawful or unsafe Client instructions, for security emergencies, or for Force Majeure Events affecting safe delivery.

Upon termination, Client shall pay for Services performed and authorised expenses incurred up to the effective date. Provisions intended to survive (including confidentiality, IP, liability, data protection, non-solicitation and governing law) shall survive.

Fixed-price projects terminated for convenience by Client (where permitted in the SOW) shall incur payment for work performed plus any committed non-cancellable third-party costs and a reasonable demobilisation fee stated in the SOW or otherwise agreed.

26. Force Majeure

Neither party is liable for delay or failure caused by a Force Majeure Event. The affected party shall give prompt notice and use reasonable efforts to mitigate. If Force Majeure continues for more than sixty (60) consecutive days, either party may terminate the affected SOW without liability for such termination, subject to payment for Services performed.

27. Export Control, Sanctions and Acceptable Use

Client represents that it is not subject to UK, EU, US or other applicable sanctions that would prohibit the Services, and that Services and Deliverables will not be used for prohibited end uses including unlawful surveillance, unauthorised intrusion into third-party systems, or development of prohibited weapons.

Client shall comply with export control laws applicable to software and technology transferred under the Agreement. YOUZSE LTD may refuse performance where sanctions or export laws would be breached.

28. Subcontracting and Personnel

YOUZSE LTD may subcontract elements of Services to carefully selected specialists, including for niche cybersecurity testing, cloud engineering, CDN configuration, streaming media workflows, AI engineering or DevOps automation. We remain responsible for subcontracted performance.

We may replace personnel with others of reasonably equivalent competence. Key person dependencies, if critical, must be expressly stated in the SOW and are subject to availability and events beyond reasonable control.

29. Non-Exclusive Relationship and Publicity

The relationship is non-exclusive. YOUZSE LTD may provide similar services to other clients, including clients in the same industry, without breaching confidentiality.

Neither party shall issue press releases naming the other without prior written consent, except that YOUZSE LTD may identify Client as a client in anonymised or logo form if expressly permitted in the SOW. Portfolio case summaries on portfolio.html will not disclose Client Confidential Information without permission.

30. Notices

Formal notices under an Agreement shall be in writing and delivered by hand, tracked post, or email with confirmed receipt to the addresses in the SOW, or if none, to YOUZSE LTD at 66 Paul Street, LONDON, EC2A 4NA United Kingdom and tech@youzse.fit, and to the Client at its registered office or primary billing email.

Notices are deemed received on delivery if by hand; two Business Days after posting if inland UK tracked post; or on Business Day of confirmed email receipt if sent before 17:00 UK time on a Business Day, otherwise the next Business Day.

31. Governing Law, Jurisdiction and Dispute Resolution

These Conditions and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with them or their subject matter shall be governed by and construed in accordance with the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction. Before commencing proceedings, the parties shall attempt in good faith to resolve disputes through escalation to senior management within fifteen (15) Business Days of written notice of dispute. This does not prevent either party seeking interim injunctive relief to protect intellectual property or Confidential Information.

32. General Boilerplate

These Conditions and the SOW constitute the entire agreement for their subject matter and supersede prior negotiations, without excluding liability for fraudulent misrepresentation. Variations must be in writing and signed or expressly confirmed by authorised representatives.

If any provision is held invalid, the remainder continues in force. Waiver must be express and in writing. Nothing creates a partnership, joint venture or employment relationship. Client may not assign without our consent, not to be unreasonably withheld; we may assign to a successor of our business.

The Contracts (Rights of Third Parties) Act 1999 is excluded except for permitted indemnified affiliates enforcing indemnities. Order of precedence: (1) SOW specific amendments that expressly override named clauses; (2) data processing schedule for data protection conflicts; (3) these Conditions; (4) proposal narrative.

These Conditions may be executed in counterparts, including electronic signature, each of which is deemed an original.

33. Service Initiation and Onboarding Procedures

Upon contract formation, YOUZSE LTD will open an engagement record with a serial reference for internal verification and delivery tracking. The Client will receive a request for onboarding information including technical contacts, escalation paths, inventory of in-scope assets, preferred communication channels, and change-approval authorities.

Onboarding may include a kickoff workshop to confirm scope boundaries, success criteria, risk assumptions, dependencies on third-party vendors, and the schedule for access provisioning. Delays in access provisioning are a common cause of timeline slippage and should be treated as a critical Client obligation.

Where Services involve production systems, a go-live readiness checklist will be agreed. The checklist may cover backup confirmation, rollback owners, communication plans, monitoring dashboards, and security review sign-off. YOUZSE LTD is entitled to postpone go-live if material checklist items remain incomplete and continuing would create unreasonable risk.

Documentation standards for the engagement will be confirmed early, including naming conventions, repository locations, diagram formats and the extent of runbook detail. The Client should not assume that undocumented tribal knowledge within its organisation is known to YOUZSE LTD.

If the Client requires specific compliance evidence packs for supplier assurance questionnaires or customer due diligence, such packs must be scoped. Substantial questionnaire programmes may be charged on a time and materials basis.

Training of Client personnel, if required, shall be scoped separately unless included. Knowledge transfer sessions are most effective when Client attendees have the prerequisite technical background identified in the SOW.

34. Access Management and Privileged Operations

Privileged access shall be granted using named accounts wherever practicable. Shared generic administrator accounts are discouraged. Where shared accounts cannot be avoided, the Client shall maintain compensating controls and acknowledge residual risk in writing.

YOUZSE LTD personnel will use privileged access only for in-scope tasks. Emergency break-glass access, if needed, shall be reported to the Client promptly with rationale and actions taken.

Remote access should prefer modern secure methods such as VPN with multi-factor authentication, just-in-time access brokers, or vendor privileged access workstations. Unencrypted protocols for administration are not acceptable except in isolated lab contexts expressly agreed.

The Client shall revoke access promptly when individuals leave the project. YOUZSE LTD will notify the Client when specific personnel leave the engagement so that revocation can occur.

Screen sharing during support may expose incidental Personal Data on Client desktops. Client participants should minimise such exposure. YOUZSE LTD will not record sessions without agreement.

Password exchange via insecure channels is prohibited. Secrets should be transferred using approved secret managers or encrypted channels.

35. Testing Environments and Release Management

Development, test, staging and production environments should be segregated. YOUZSE LTD will not promote changes to production without Client authorisation under the agreed change process.

Test data management remains a Client responsibility unless data synthesis or masking is in scope. Using unmasked production Personal Data in lower environments increases regulatory risk and should be avoided.

Automated pipelines created under DevOps Services will include stages appropriate to risk, which may include linting, unit tests, integration tests, security scanning and manual approval gates. The Client must not disable gates without understanding consequences.

Rollback plans should be tested where feasible. YOUZSE LTD is not responsible for irreversible data migrations where the Client declined a scoped rollback strategy.

Hotfix requests outside change windows may attract premium rates if supported, and may be refused where risk is unacceptable.

Release notes will summarise material changes. The Client should distribute release notes to affected internal stakeholders.

36. Incident Response Cooperation

If a security incident arises in systems related to the Services, the parties shall cooperate in good faith. YOUZSE LTD retains the right to take reasonable containment steps on systems we operate, and to recommend containment on Client-operated systems.

Incident classification severity levels should be agreed for managed services. Response times, if any, are service targets rather than warranties unless expressly stated as contractual commitments with credits.

Forensic imaging, chain of custody and law enforcement liaison are specialised activities and are included only if scoped. Preserving evidence may conflict with rapid restoration; the Client must prioritise objectives expressly.

Public statements about incidents shall be coordinated where both parties may be named. Neither party shall misrepresent the other's role.

Post-incident reviews may produce recommendations. Implementation remains optional unless contracted as follow-on work.

Personal Data Breaches shall additionally follow Section 19 notification duties.

37. Business Continuity and Backup Expectations

Unless backup and disaster recovery Services are expressly purchased, the Client remains responsible for backups of its data and for validating restore procedures.

Where YOUZSE LTD provides backup configuration, restore testing frequency shall be stated. Untested backups carry risk. Restore objectives are targets that depend on infrastructure and data volumes.

Georedundancy, multi-region failover and chaos testing are advanced capabilities requiring explicit scope. Default single-region deployments carry regional outage risk that the Client accepts unless mitigated in the SOW.

Force Majeure and upstream provider outages may prevent meeting continuity targets despite correct configuration.

Client should maintain offline contact methods for severe outages affecting primary communication tools.

Documentation of recovery procedures should be kept current by the party designated as operations owner in the shared responsibility matrix.

38. Detailed Cybersecurity Engagement Rules

Rules of engagement for cybersecurity assessments shall identify authorised IP ranges, application URLs, time windows, excluded systems, data handling constraints, and emergency stop contacts. Testing outside the rules of engagement is unauthorised.

Destructive testing, denial-of-service simulation, social engineering against individuals, or physical intrusion are excluded unless expressly authorised in writing with appropriate legal review.

Vulnerability severity ratings are based on professional judgement and may differ from automated scanner scores. The Client should triage findings using its risk appetite and business context.

Retesting of remediated findings, if required, must be scheduled and may be charged separately. Retesting does not extend to newly introduced systems outside the original scope.

YOUZSE LTD may decline to provide a clean bill of health statement. Absence of findings does not mean absence of risk. Continuous monitoring and patching remain Client operational duties unless managed services are purchased.

If Client publishes cybersecurity reports externally, Client shall not alter findings in a way that misleads, and shall include agreed limitations language.

Coordination with Client's existing MSSP, SOC or internal security team should be planned to avoid alert fatigue and duplicated incident tickets during testing.

Cloud metadata services, container escape testing and identity federation abuse tests require explicit inclusion due to elevated operational risk.

39. Detailed Cloud and Infrastructure Engagement Rules

Cloud landing zones should define account structure, network topology, identity boundaries, logging aggregation and baseline policies before workload migration. Skipping baselines increases remediation cost later.

Infrastructure as code is preferred for repeatability. Manual console changes by Client after handover may drift from documented state; drift remediation can be scoped as additional work.

Cost management tooling may be recommended. YOUZSE LTD does not guarantee cloud spend reductions; savings depend on Client usage patterns and willingness to implement recommendations.

Reserved capacity, savings plans and committed use discounts are commercial decisions for the Client and the cloud provider.

Network designs involving hybrid connectivity depend on Client circuit providers. Latency and packet loss on Client circuits are outside YOUZSE LTD control.

Tagging standards should be agreed for ownership and cost allocation. Untagged resources complicate operations and security reviews.

Decommissioning legacy infrastructure after migration should be planned to avoid dual-running cost and residual exposure.

40. Detailed Software, API and Platform Engagement Rules

Product backlogs prioritise features. Security and accessibility work should be scheduled rather than indefinitely deferred. YOUZSE LTD may flag critical security debt that blocks safe release.

Code repositories should enforce branch protection and peer review for production paths. Direct commits to main production branches are discouraged.

API contracts should be versioned. Breaking changes require migration plans for consumers. The Client is responsible for notifying external API consumers unless YOUZSE LTD is contracted to manage developer relations.

Digital platform multi-tenancy designs must address isolation, noisy neighbour controls and per-tenant configuration. Weak isolation is a material security risk.

Accessibility conformance to specific WCAG levels is included only if stated in acceptance criteria with test methodology.

Localisation and internationalisation support must be scoped if required. Default Deliverables may be English-language interfaces only.

Performance testing requires representative environments and datasets. Results from undersized test systems may not predict production behaviour.

41. Detailed Data, CDN, Streaming and AI Engagement Rules

Data retention schedules in pipelines should align with Client policy and UK GDPR storage limitation principles. Indefinite retention by default is discouraged.

CDN cache keys and purge strategies must be designed carefully to avoid serving stale private content. Misconfigured caching of authenticated pages is a serious risk the Client must help validate.

Streaming DRM, watermarking and tokenised URL schemes, if required, must be specified. YOUZSE LTD does not supply content licences.

AI evaluation should include task-specific metrics and human review samples. Accuracy claims without evaluation methodology will not be made in Deliverables.

Prompt injection, data exfiltration through model tools, and unsafe tool execution are known AI risks. Mitigations should be proportionate to deployment context.

Where AI systems process employee or customer Personal Data, transparency and lawful basis analysis are Client Controller responsibilities unless otherwise agreed.

Bandwidth and egress costs for CDN and streaming can be significant. The Client should monitor commercial thresholds with its vendors.

42. Managed Services, Retainers and Support Tiers

Managed services and retainers, if purchased, provide ongoing support within defined hours and caps on included effort. Work exceeding caps is charged at agreed rates or deferred to the next period by mutual agreement.

Support tiers may distinguish critical, high, medium and low priorities with corresponding response targets. Response is not the same as resolution. Resolution times depend on complexity, third parties and Client cooperation.

On-call rotas, if included, will specify contact methods and escalation. Abuse of emergency channels for non-emergencies may result in reclassification and charges.

Service reviews may be held monthly or quarterly to discuss tickets, risks, backlog and improvement opportunities.

Tools used for ticketing and monitoring may be YOUZSE LTD standard tools or Client tools as agreed. Dual logging should be avoided where possible.

Termination of managed services requires wind-down including access revocation, documentation handover and final invoice reconciliation.

43. Acceptance, Remedies and Re-performance

Where acceptance criteria are objective and documented, Client acceptance confirms material conformity. Subjective dissatisfaction without reference to criteria is not valid rejection.

If Deliverables fail acceptance due to YOUZSE LTD deficiency, our primary remedy is re-performance within a reasonable time. If re-performance fails after reasonable attempts, Client may terminate the affected portion and receive a refund of fees paid for the failed portion, subject to the liability clause.

Partial acceptance may be agreed for severable Deliverables. Payment schedules may align to accepted milestones.

Use of Deliverables in production before formal acceptance may constitute deemed acceptance of those Deliverables, except for latent defects not reasonably discoverable.

44. Ethics, Anti-Bribery and Modern Slavery

Each party shall comply with the Bribery Act 2010 and shall not offer or accept improper payments or advantages in connection with the Agreement.

YOUZSE LTD takes reasonable steps aligned to its size to avoid modern slavery in its supply chain and expects Clients and subcontractors to comply with applicable modern slavery laws.

Conflicts of interest that materially affect impartiality in cybersecurity assessments should be disclosed and managed.

45. Records, Audit Trails and Evidence Retention

Engagement records, change tickets, architecture decisions and verification evidence may be retained by YOUZSE LTD for quality, legal and insurance purposes under confidentiality duties.

Client may request copies of Deliverables and agreed project artefacts during the engagement and for a reasonable period thereafter while records remain available.

Audit trails in Client systems remain Client assets. YOUZSE LTD may retain extracts necessary to evidence work performed.

If Client requires specific evidence formats for regulated audits, requirements must be stated early.

46. TUPE and Employment Status

The parties intend that the Transfer of Undertakings Protection of Employment Regulations do not apply to these Services. Personnel of YOUZSE LTD remain our employees or contractors. If TUPE is alleged to apply contrary to intention, the parties shall cooperate in good faith and Client shall indemnify YOUZSE LTD against resulting employment liabilities to the extent caused by Client's acts or omissions, except where resulting from YOUZSE LTD breach.

Nothing in the Agreement makes YOUZSE LTD personnel employees of the Client.

47. Consumer Status and Business Clients

These Conditions are drafted for business Clients. If any mandatory consumer rights apply despite the business nature of Services, those rights remain unaffected to the extent they cannot be excluded.

Website terms for general visitors are set out in terms-of-service.html and do not reduce protections in a signed SOW for paying Clients.

48. Contact and Document Control

Questions about these Terms and Conditions may be directed to YOUZSE LTD at tech@youzse.fit, telephone +44 7127 995133, or by post to 66 Paul Street, LONDON, EC2A 4NA United Kingdom. Related policies are available at privacy-policy.html, cookie-policy.html and terms-of-service.html. Company and service information is available at about.html, services.html, portfolio.html and contact.html on youzse.fit.

Document serial reference: YZS-UK-TAC-2026. These Conditions may be updated for future engagements; the version incorporated into an SOW remains the version applicable to that SOW unless the parties agree to migrate to a newer version in writing.

49. Schedule A - Illustrative Shared Responsibility Matrix Themes

This Schedule describes illustrative shared responsibility themes commonly used in YOUZSE LTD cloud, hosting, cybersecurity and platform engagements. The actual matrix for an engagement is set out in the SOW and prevails over this illustrative text.

Identity and access management controls are typically shared: YOUZSE LTD may design and implement baseline identity patterns, while the Client remains responsible for joiner-mover-leaver processes, timely revocation, and business approval of access roles.

Data classification is a Client responsibility. YOUZSE LTD can recommend classification schemes and technical enforcement patterns, but only the Client can accurately classify its business records and Personal Data stores.

Physical security of Client offices and Client-owned data centres remains with the Client. Physical security of third-party cloud data centres remains with the cloud provider under its terms.

Endpoint security for Client employee devices remains with the Client unless YOUZSE LTD is contracted to manage endpoint tooling.

Application code written by Client developers remains subject to Client secure development lifecycle duties. YOUZSE LTD is responsible for code we author under the SOW to the warranty standard stated herein.

Logging pipelines may be built by YOUZSE LTD, but monitoring responses and twenty-four seven staffing are included only if purchased. Without a managed detection service, logs may exist without active continuous review.

Vulnerability remediation ownership should be explicit. Findings without owners accumulate risk. YOUZSE LTD can track findings if scoped, but patch execution on Client systems requires Client change control.

Backup configuration may be implemented by YOUZSE LTD, while restore testing frequency and business prioritisation of recovery order remain Client decisions unless managed recovery services are purchased.

Encryption key ownership should be clear. Client-managed keys require Client operational readiness. YOUZSE LTD-managed keys, if any, will be documented with escrow or handover arrangements on exit.

Compliance attestations to Client customers are Client representations. YOUZSE LTD may provide factual descriptions of controls we implemented, not blanket compliance certifications, unless a specific assurance engagement is contracted.

Incident communications to Client customers and regulators are Client responsibilities as Controller or service provider to those customers, with technical cooperation from YOUZSE LTD as scoped.

Third-party SaaS tools selected by Client remain under Client vendor management. YOUZSE LTD can advise on integration security but does not become the vendor contract party unless expressly agreed.

50. Schedule B - Illustrative Data Processing Description Themes

This Schedule describes illustrative themes for documenting processing activities when YOUZSE LTD acts as a Processor. The binding description is the data processing schedule attached to the SOW.

Subject matter of processing often includes Personal Data contained in Client business systems that YOUZSE LTD must access to deliver cybersecurity, cloud, software, data, CDN, streaming, AI, DevOps or hosting Services.

Duration of processing is typically the engagement term plus limited wind-down and legal retention periods for evidential copies.

Nature of processing may include access, storage, transmission, analysis, migration, transformation, deletion and logging as required to deliver the SOW.

Purpose of processing is limited to providing the contracted Services and related support, security and quality activities.

Types of Personal Data commonly include names, business contact details, authentication identifiers, IP addresses, usage logs, and content data stored by Client applications. Special category data is excluded unless expressly scheduled.

Categories of Data Subjects commonly include Client employees, contractors, customers, website users and other end users of Client systems.

Sub-processors may include cloud hosting providers, collaboration tools and specialist subcontractors. A current list can be provided on request for Processor engagements.

Transfer mechanisms for restricted transfers may include the UK IDTA or UK Addendum to standard contractual clauses, plus technical supplementary measures where appropriate.

Data Subject request assistance will be provided within reasonable timescales compatible with UK GDPR deadlines, recognising that YOUZSE LTD may need Client context to locate data.

Deletion methods may include cryptographic erasure, secure wipe, or logical deletion depending on system capabilities. Certificates of deletion can be provided if scoped.

Breach cooperation includes preserving relevant logs, providing timeline facts known to YOUZSE LTD, and implementing containment on systems under our operation.

Client instructions should be documented via tickets, email from authorised contacts, or SOW amendments. Oral emergency instructions should be confirmed in writing promptly.

51. Schedule C - Illustrative Service Level Theme Catalogue

This Schedule describes illustrative service level themes that may be selected in managed service SOWs. No service levels apply unless expressly incorporated.

Availability themes may include monthly uptime percentage measured at the external probe or load balancer, excluding planned maintenance notified in advance and Force Majeure Events.

Support response themes may include acknowledgement times for critical incidents within a defined number of business hours or on-call minutes.

Patch cadence themes may include applying critical security patches to YOUZSE LTD-managed infrastructure within agreed windows after vendor release and testing.

Backup success themes may include monitoring backup job success rates and alerting on failures.

Performance themes, if used, must define metrics, measurement points and exclusions for Client-caused load spikes.

Service credits, where offered, are typically a percentage of the monthly managed service fee for the affected service, capped monthly, and require Client to open a ticket within a claim window.

Reporting themes may include monthly service reports summarising incidents, changes, capacity and open risks.

Continuous improvement themes may include a backlog of hardening items reviewed each quarter within retainer capacity.

Exclusions commonly include Client application defects, third-party SaaS outages, Client network failures, and changes made by Client outside agreed process.

Measurement disputes should be escalated under the governance cadence before credits are finally determined.

52. Schedule D - Change Request Procedure Detail

This Schedule describes the standard change request procedure applicable unless the SOW specifies an alternative Client change process.

A change request should describe the proposed change, business rationale, urgency, affected systems, and any known constraints.

YOUZSE LTD will respond with impact analysis covering fee, timeline, risk, testing needs and dependencies.

Changes are approved when both parties confirm in writing. Work under unapproved changes is not required and may be invoiced if performed at Client insistence under emergency authority documented after the fact.

Emergency changes to restore service may proceed under verbal authorisation from the Client escalation contact, followed by written confirmation within two Business Days.

Change request records form part of the engagement audit trail and should be retained with project documentation.

Bundling multiple unrelated changes into one request is discouraged because it complicates impact analysis and acceptance.

Rejection of a change request does not itself terminate the Agreement. The original scope continues.

Material reductions in scope may require fee adjustment where fixed-price assumptions change.

53. Schedule E - Escalation and Governance Cadence

This Schedule describes recommended governance cadence for significant engagements.

Operational stand-ups may occur daily or several times weekly during intensive build phases.

Weekly progress reports may summarise accomplishments, risks, decisions needed and upcoming milestones.

Monthly steering committees for larger programmes may include commercial and technical stakeholders to address priorities and budget.

RAID logs tracking risks, assumptions, issues and dependencies should be reviewed regularly.

Decision logs prevent re-litigation of settled architecture choices. Reopening decisions may require change control.

Escalation paths should identify first-line project contacts, senior technical escalations and executive sponsors for each party.

Meeting minutes may be circulated after material workshops. Silence after a stated review period may be treated as agreement to factual minutes if so notified.

54. Schedule F - Exit and Transition Assistance

This Schedule describes exit assistance principles available if scoped or reasonably required on termination.

On termination or expiry, YOUZSE LTD will provide reasonable transition assistance if scoped or if Client requests assistance at then-current rates.

Transition assistance may include documentation handover, knowledge transfer sessions, export of configurations, revocation of access, and introduction to Client's successor supplier.

Source code for bespoke Deliverables already paid for will be provided from the repositories used in the engagement, excluding Supplier IP tools not licensed for standalone transfer.

Credentials and secrets under YOUZSE LTD control for Client systems will be handed over securely and then removed from our stores except evidential archives.

Transition periods should be long enough to avoid operational cliffs. Abrupt termination for non-payment may limit assistance to legally required minimums.

Client cooperation is essential; refusal to accept handover meetings may be noted and may limit later claims regarding incompleteness.

55. Schedule G - Security Control Domains Commonly Addressed

This Schedule lists security control domains frequently addressed in cybersecurity and infrastructure work.

Asset inventory and ownership clarity form a foundation for security and operations.

Identity lifecycle and privileged access management reduce account-based risk.

Network segmentation and secure remote access limit blast radius.

Vulnerability and patch management reduce exposure windows.

Secure configuration baselines reduce drift and weak defaults.

Logging, monitoring and alerting enable detection and investigation.

Backup, recovery and resilience planning support continuity.

Secure software development and dependency management reduce supply-chain risk.

Incident response preparedness improves coordination under pressure.

Vendor and supply-chain security reviews address third-party exposure.

Data protection and privacy engineering align processing with UK GDPR principles.

Physical and environmental controls remain relevant for hybrid estates.

Security awareness and phishing resilience address human-layer risk.

Cryptography and key management protect data confidentiality and integrity.

56. Schedule H - AI Governance Checklist Themes

This Schedule lists AI governance themes considered in artificial intelligence solution engagements.

Problem framing and intended use definition precede model selection.

Data source legitimacy and licence status must be verified for training or retrieval corpora.

Personal Data minimisation and purpose limitation apply to AI pipelines.

Evaluation metrics and human oversight thresholds should be documented.

Prompt and tool safety controls mitigate injection and exfiltration risks.

Bias and harmful output monitoring should be proportionate to impact.

User transparency notices may be required where individuals interact with AI.

Retention of prompts and outputs should follow policy and necessity.

Vendor AI terms must be reviewed for training-use and data residency clauses.

Rollback plans should exist if AI features behave unexpectedly in production.

Access control for AI administration interfaces must be strict.

Incident playbooks should include AI-specific failure modes such as model endpoint compromise.

57. Extended Provisions on Hosting Acceptable Use

Where hosting Services are supplied, the Client shall ensure that hosted content and applications comply with United Kingdom law, including intellectual property, defamation, data protection, and computer misuse laws. YOUZSE LTD may suspend content that is reasonably believed to be unlawful or to threaten platform stability, and will notify the Client where legally permitted.

The Client shall not use hosting resources to send unsolicited bulk email, to operate open relays, to distribute malware, or to participate in botnet activity. Detected abuse may result in immediate suspension.

Resource caps in the SOW are material. Persistent exceedance may be throttled or invoiced as overage if overage rates are stated, or may require an upgrade decision.

The Client is responsible for application licences installed on hosted environments unless YOUZSE LTD expressly provides licensed software as part of the service catalogue in the SOW.

Maintenance windows will be notified in advance where practicable. Emergency maintenance may occur without notice where delay would increase risk of data loss or security compromise.

IP address reputation, mail deliverability and third-party blocklists are influenced by Client sending behaviour. YOUZSE LTD does not guarantee mail inbox placement.

Domain DNS remains under Client control unless DNS management is scoped. Incorrect DNS changes by Client may cause outages outside YOUZSE LTD responsibility.

On termination of hosting, Client should migrate away before cancellation. After cancellation, data may be deleted following a short retention hold stated in the SOW or after seven days if none is stated, except where law requires longer retention of certain logs.

58. Extended Provisions on CDN and Streaming Operations

CDN configurations must distinguish public cacheable assets from private content. The Client shall identify which content classes exist. Misclassification risk sits primarily with Client content owners who understand business sensitivity.

Purge permissions should be limited to authorised operators. Unrestricted purge rights can cause widespread cache misses and origin overload.

Streaming platforms may involve origin servers, packagers, CDNs, players and DRM vendors. YOUZSE LTD responsibility is limited to components listed in the SOW. End-to-end viewer experience depends on many parties.

Live streaming introduces timing, redundancy and regional failover complexities. Single-region live origins carry higher outage risk during regional events.

Analytics for streaming and CDN may process IP addresses and device data. Privacy notices to end users are Client responsibilities as Controller of end-user relationships.

Rate limiting and bot management may be recommended to protect streaming tokens and origins. Overly aggressive blocking can affect legitimate users; tuning is iterative.

Contractual commitments from CDN vendors regarding throughput and POP coverage are between Client and vendor unless YOUZSE LTD is the contracting customer of record.

59. Extended Provisions on Artificial Intelligence Delivery

AI projects should begin with a clear statement of intended benefits, prohibited uses, and success metrics. Vague aspirations produce unmanageable scope.

Retrieval-augmented generation systems require careful corpus curation. Stale or confidential documents in retrieval indexes can cause leakage or incorrect answers.

Human-in-the-loop design is recommended for high-impact outputs. Fully autonomous operation in regulated decisions is discouraged unless legal analysis supports it.

Model upgrades by third-party providers can change behaviour. Clients should budget for re-evaluation after major model version changes.

Logging of prompts may create Personal Data stores. Access to prompt logs should be restricted and retained only as needed.

YOUZSE LTD does not guarantee that AI features will achieve any particular business ROI. Commercial outcomes depend on adoption, process change and data quality.

If Client insists on deploying AI features against written risk warnings from YOUZSE LTD, Client accepts residual risk associated with that decision.

60. Extended Provisions on DevOps and Automation Safety

Infrastructure as code pull requests should be reviewed before apply. Automated apply to production without review increases risk of widespread outage.

Secret scanning should be enabled in repositories where feasible. Secrets committed historically should be rotated, not merely deleted from HEAD.

Policy as code can enforce security baselines. Exceptions should be time-bound and approved.

Feature flags can reduce release risk but add operational complexity. Ownership of flag cleanup should be assigned.

Chaos engineering exercises require explicit authorisation and rollback readiness. They are excluded by default.

Toolchain choices (CI systems, artefact registries, orchestration platforms) should consider exit cost and lock-in. YOUZSE LTD will advise but Client decides.

Production credentials in CI must use short-lived tokens where available. Long-lived static keys in pipelines are discouraged.

61. Payment Disputes and Invoice Queries

Invoice queries must be raised within ten (10) Business Days of invoice date with reasonable detail. Undisputed amounts remain payable by the due date.

Time and materials invoices may be supported by time summaries on request. Detailed minute-by-minute logs are not required unless agreed for a regulated Client.

Purchase order numbers, if required by Client process, must be provided before invoice issuance; failure to provide a PO does not extinguish fees for authorised Services performed.

Currency conversion, if any, will use a commercially reasonable rate source stated on the invoice when billing in a currency other than pounds sterling, which is the default.

62. Staff Vetting and Location of Performance

YOUZSE LTD performs Services primarily from the United Kingdom. Remote delivery is standard. On-site work at Client premises in the United Kingdom may be arranged; overseas on-site work requires express agreement and may involve additional compliance checks.

Staff vetting levels beyond standard right-to-work and professional referencing, such as higher national security clearances, are not included unless expressly stated and feasible.

Client site rules, induction and health and safety requirements will be followed by attending personnel. Client shall provide a safe working environment.

63. Warranties by Client Regarding Systems and Authorisation

Client warrants that it has full power and authority to enter the Agreement and to permit the access and testing described in the SOW.

Client warrants that providing Client Materials does not knowingly infringe third-party rights.

Client warrants that production changes approved by its authorised contacts reflect Client's internal approvals.

Breach of these warranties is a material breach entitling YOUZSE LTD to suspend and to recover reasonably incurred losses subject to the liability clause.

64. Independent Legal Advice and Negotiation

Each party acknowledges it has had opportunity to seek independent legal advice on these Conditions. Negotiated SOW amendments prevail for that engagement when expressly stated.

Standard Conditions protect both parties by allocating risks predictably. Requests for unlimited liability, ownership of all Supplier IP, or unilateral audit rights without notice will be considered commercially and may be declined or priced differently.

65. Interpretative Expansion of Service Catalogue References

References in marketing materials on youzse.fit to layered verification, certificate framing, serial references such as YZS-UK-2026, and inspection fields describe methodology and brand language. They do not independently create regulated certifications.

Service catalogue items spanning cybersecurity services, computer systems design, cloud computing solutions, software development services, enterprise infrastructure, web hosting services, API development, database management, data processing, content delivery networks, streaming platform solutions, artificial intelligence solutions, DevOps and automation, and digital platform development may be combined in a single SOW or delivered as separate Agreements.

Where combined, dependencies between workstreams should be identified to avoid schedule conflict. YOUZSE LTD may recommend phasing for risk reduction.

Portfolio examples on portfolio.html are illustrative and may omit Client identifiers. They do not guarantee identical results.

66. Operational Reporting and KPI Interpretation

This section sets out additional contractual expectations regarding operational reporting and kpi interpretation in engagements with YOUZSE LTD. It applies where relevant to the Services described in the SOW and supplements, without replacing, the earlier operative clauses on scope, change control, acceptance, security and liability.

The Client and YOUZSE LTD shall cooperate in good faith to implement practical arrangements for operational reporting and kpi interpretation. Where the SOW already specifies detailed procedures on this topic, the SOW prevails. Where the SOW is silent, the following default expectations apply to professional delivery of cybersecurity, cloud, software, infrastructure, hosting, data processing, CDN, streaming, AI, DevOps and digital platform Services.

Communications should be clear, timely and directed to named contacts. Ambiguous instructions may be clarified before work proceeds. YOUZSE LTD may rely on written instructions from authorised Client contacts listed in the engagement record.

Records produced under this section, including reports, decisions, configuration notes and meeting outcomes, form part of the engagement documentation and are Confidential Information unless the SOW permits broader use.

Any tools introduced to support these practices remain subject to the intellectual property, data protection and security clauses of these Conditions. Client-preferred tools may be used if access is provided and security is acceptable.

Failure by either party to follow these operational expectations shall not automatically constitute material breach unless it causes material adverse impact and remains uncured after notice, but repeated non-cooperation may justify schedule adjustment, additional fees, or escalation under the governance provisions.

Nothing in this section expands YOUZSE LTD liability beyond Section 23 or creates service levels unless those service levels are expressly purchased. Targets and good-practice cadences described here are operational guidelines for working together effectively under the laws of England and Wales.

If you require tailored procedures beyond these defaults, request that they be written into the SOW before work begins. Contact YOUZSE LTD at tech@youzse.fit or +44 7127 995133 to discuss governance options for complex programmes.

67. Environment Naming and Configuration Hygiene

This section sets out additional contractual expectations regarding environment naming and configuration hygiene in engagements with YOUZSE LTD. It applies where relevant to the Services described in the SOW and supplements, without replacing, the earlier operative clauses on scope, change control, acceptance, security and liability.

The Client and YOUZSE LTD shall cooperate in good faith to implement practical arrangements for environment naming and configuration hygiene. Where the SOW already specifies detailed procedures on this topic, the SOW prevails. Where the SOW is silent, the following default expectations apply to professional delivery of cybersecurity, cloud, software, infrastructure, hosting, data processing, CDN, streaming, AI, DevOps and digital platform Services.

Communications should be clear, timely and directed to named contacts. Ambiguous instructions may be clarified before work proceeds. YOUZSE LTD may rely on written instructions from authorised Client contacts listed in the engagement record.

Records produced under this section, including reports, decisions, configuration notes and meeting outcomes, form part of the engagement documentation and are Confidential Information unless the SOW permits broader use.

Any tools introduced to support these practices remain subject to the intellectual property, data protection and security clauses of these Conditions. Client-preferred tools may be used if access is provided and security is acceptable.

Failure by either party to follow these operational expectations shall not automatically constitute material breach unless it causes material adverse impact and remains uncured after notice, but repeated non-cooperation may justify schedule adjustment, additional fees, or escalation under the governance provisions.

Nothing in this section expands YOUZSE LTD liability beyond Section 23 or creates service levels unless those service levels are expressly purchased. Targets and good-practice cadences described here are operational guidelines for working together effectively under the laws of England and Wales.

If you require tailored procedures beyond these defaults, request that they be written into the SOW before work begins. Contact YOUZSE LTD at tech@youzse.fit or +44 7127 995133 to discuss governance options for complex programmes.

68. Dependency and Third-Party Vendor Coordination

This section sets out additional contractual expectations regarding dependency and third-party vendor coordination in engagements with YOUZSE LTD. It applies where relevant to the Services described in the SOW and supplements, without replacing, the earlier operative clauses on scope, change control, acceptance, security and liability.

The Client and YOUZSE LTD shall cooperate in good faith to implement practical arrangements for dependency and third-party vendor coordination. Where the SOW already specifies detailed procedures on this topic, the SOW prevails. Where the SOW is silent, the following default expectations apply to professional delivery of cybersecurity, cloud, software, infrastructure, hosting, data processing, CDN, streaming, AI, DevOps and digital platform Services.

Communications should be clear, timely and directed to named contacts. Ambiguous instructions may be clarified before work proceeds. YOUZSE LTD may rely on written instructions from authorised Client contacts listed in the engagement record.

Records produced under this section, including reports, decisions, configuration notes and meeting outcomes, form part of the engagement documentation and are Confidential Information unless the SOW permits broader use.

Any tools introduced to support these practices remain subject to the intellectual property, data protection and security clauses of these Conditions. Client-preferred tools may be used if access is provided and security is acceptable.

Failure by either party to follow these operational expectations shall not automatically constitute material breach unless it causes material adverse impact and remains uncured after notice, but repeated non-cooperation may justify schedule adjustment, additional fees, or escalation under the governance provisions.

Nothing in this section expands YOUZSE LTD liability beyond Section 23 or creates service levels unless those service levels are expressly purchased. Targets and good-practice cadences described here are operational guidelines for working together effectively under the laws of England and Wales.

If you require tailored procedures beyond these defaults, request that they be written into the SOW before work begins. Contact YOUZSE LTD at tech@youzse.fit or +44 7127 995133 to discuss governance options for complex programmes.