Legal

Policies & Legal Information

Our master service terms, data processing agreement, privacy, cookie, complaints, abuse and acceptable use policies — everything in one place.

Master Services Terms

Version 1.0 - August 2026.  iTVerse Technology Services Ltd, registered in England and Wales, Company No. 14848571. Registered office: 162 Warren Lane, Bingley, West Yorkshire, BD16 3BU. VAT GB 445392481. The version of these terms in force on the date of your Order Form is the version that applies to your Agreement. Superseded versions are available on request.
These Master Services Terms apply to every service iTVerse provides. Your Agreement is made up of your signed Order Form, the Service Schedule for each service you take, these Master Terms, and any policy referenced in them. If they conflict, the Order Form wins, then the Service Schedule, then these terms. These are business to business terms; we do not contract with consumers under them.

1. Definitions

1.1In these terms: "Agreement" means the contract formed by the Order Form, the applicable Service Schedule, these Master Terms and any referenced policy; "Business Day" means a day other than a Saturday, Sunday or public holiday in England and Wales; "Charges" means the sums stated in the Order Form, as varied under clause 6; "Customer" means the party named as such on the Order Form; "Minimum Term" means the minimum term stated in the Order Form for a service, commencing on the Service Start Date; "Order Form" means the signed order document for the services; "Service Schedule" means the schedule describing a specific service, its inclusions, exclusions and service levels; "Service Start Date" means the date stated in, or determined in accordance with, the Service Schedule; "Supplier" means any carrier, network operator, vendor, distributor or other third party whose products or infrastructure we use to deliver a service.

2. The Agreement

2.1Each service ordered is a separate contract on these terms. A failure or delay affecting one service does not entitle the Customer to terminate, withhold payment for, or claim against any other service.
2.2These Master Terms are version-dated. The version in force on the date of the Order Form applies for that Agreement and is not changed by later published versions during the then current term, except where a change is required by law or is exclusively to the Customer's benefit. The version current at the start of any Extended Term applies from that Extended Term, provided iTVerse identified it in the end of term notice under clause 7.4.
2.3The Agreement is the entire agreement between the parties for the services and supersedes all prior proposals, discussions and representations, other than any fraudulent misrepresentation. No terms put forward by the Customer, including terms on a purchase order, apply.

3. Orders and acceptance

3.1Quotations are valid for 30 days unless stated otherwise and do not constitute an offer. An order is binding when iTVerse has accepted the signed Order Form in writing and any Supplier has accepted the corresponding wholesale or vendor order.
3.2Charges quoted before survey or discovery are based on the information available. Where a survey, audit or Supplier planning check shows materially different requirements, iTVerse will re-quote and the Customer may accept the revised terms or withdraw without early termination charge, paying only costs already incurred.
3.3The Customer consents to iTVerse carrying out credit reference searches in connection with the Agreement. iTVerse may require a deposit, guarantee or amended payment terms where a credit reference is unsatisfactory. Any deposit is payable within 7 days of signature, may be held against unpaid Charges, and any balance is returned within 30 days of the end of the Agreement.

4. Supplying the services

4.1iTVerse will supply the services with reasonable care and skill and in accordance with the Service Schedule in all material respects.
4.2Dates and lead times are estimates given in good faith. iTVerse will use reasonable endeavours to meet them, but they are not contractual commitments and time is not of the essence, except where a Service Schedule expressly states otherwise.
4.3iTVerse may make changes to a service that are required by law or by a Supplier, or that do not materially reduce its nature or quality, and will notify the Customer of any such change.
4.4No IT or telecommunications service is fault free and iTVerse does not warrant uninterrupted or error-free operation. Where a service is business critical, the Customer is responsible for appropriate resilience and continuity arrangements unless these are expressly included in a Service Schedule.
4.5Some services are regulated electronic communications services. Where statutory or regulatory protections, including Ofcom's General Conditions, apply to a service or to the Customer, those protections apply notwithstanding anything to the contrary in the Agreement, and the remainder of the Agreement continues in full force. iTVerse's complaints procedure is published at itverse.co.uk/legal; where the Customer is entitled under Ofcom's rules to alternative dispute resolution, an unresolved complaint may be referred, free of charge, to the Communications Ombudsman, the Ofcom-approved ADR scheme of which iTVerse is a member, six weeks after the complaint was first raised or on receipt of a deadlock letter.

5. Charges and payment

5.1All Charges exclude VAT, which is payable at the prevailing rate. Recurring Charges are invoiced in advance from the Service Start Date, pro rata for part periods, and become payable whether or not the Customer has begun to use the service.
5.2Invoices are payable within the period stated on the Order Form (14 days unless stated otherwise), by Direct Debit unless agreed otherwise, to the billing contact on the Order Form. Time for payment is of the essence.
5.3iTVerse may charge interest and recovery costs on overdue sums under the Late Payment of Commercial Debts (Interest) Act 1998, and may charge ancillary fees at its published tariff for paper billing, failed or non-Direct Debit payment, reconnection after suspension, missed or aborted appointments, and expedited work.
5.4The Customer must pay all sums in full without set-off, deduction, counterclaim or withholding, other than any deduction required by law. iTVerse may set off sums the Customer owes it against sums it owes the Customer. Invoice queries should be raised in writing within 14 days of the invoice date, as an administrative deadline so that queries can be investigated while records are current; undisputed portions remain payable on the due date, and this deadline does not affect either party's rights in respect of manifest errors. Delay in invoicing does not bar iTVerse from invoicing later.
5.5Charges based on usage, counts or consumption are determined from data recorded by iTVerse or its Suppliers.

6. Price changes

6.1Any annual price change mechanism is the one stated on the Order Form: either no scheduled increase, or a fixed pounds and pence increase stated on the Order Form, or, where expressly agreed with a Customer that is not a small business customer, an index-linked increase as stated on the Order Form. Where the Order Form is silent, there is no scheduled increase.
6.2In addition, iTVerse may pass through, at cost and without mark-up, any increase in Supplier charges, any new or increased tax, levy, regulatory fee or industry charge, and any increase arising from a change in law or regulation, on not less than 30 days' written notice with reasonable evidence.
6.3Where a pass-through increase under clause 6.2 is of material detriment to the Customer, the Customer may terminate the affected service without early termination charge by written notice within 30 days of iTVerse's notice, paying Charges accrued to the termination date and any unrecovered setup or third-party costs. An increase stated on the Order Form under clause 6.1, having been agreed in advance, does not give rise to a right of termination. Termination under this clause 6.3 does not relieve the Customer of liability for committed subscription costs under clause 11.3, which remain payable in full for the committed term.
6.4iTVerse may correct manifest pricing errors, and may re-price a service where the Customer changes its scope, volumes, locations or service level.

7. Term, renewal and notice

7.1Each service continues for its Minimum Term and then extends automatically for the renewal period stated on the Order Form for that service or, where the Order Form is silent, for a further period equal to the Minimum Term (each an "Extended Term"), and again at the end of each Extended Term, unless either party gives not less than 3 months' written notice expiring at the end of the then current term.
7.2If clause 7.1 is held unenforceable, the service instead extends for successive periods of 12 calendar months on the same notice.
7.3Each Extended Term is on the terms then in force for the Agreement, at the Charges applying at the end of the preceding term.
7.4iTVerse will write to the Customer not more than 6 months and not less than 4 months before the end of each term - so before the Customer's notice deadline under clause 7.1 - stating the end date, the notice required, the Charges, and the version of these terms that will apply if the service extends.
7.5Where the Customer employs 10 or fewer people, iTVerse will obtain the Customer's express consent before the start of each Extended Term, and the Customer may in any event terminate on 3 months' written notice expiring no earlier than the end of the Minimum Term.
7.6Notice under this clause 7 must be given in writing to iTVerse's registered office or the account email address notified to the Customer, quoting the Agreement reference. Notice given to an engineer, to the service desk or within a support ticket is not valid notice.

8. Cancelling before service start

8.1The Customer may cancel an accepted order before the Service Start Date by written notice, paying all survey, planning, design, licence and equipment costs incurred, all cancellation and abortive charges levied by Suppliers at cost, any third-party construction work already committed, and the administration charge stated on the Order Form.
8.2Where cancellation occurs after physical build, provisioning or licensing has begun, the full setup or installation charge also becomes payable.

9. Early termination

9.1If, after the Service Start Date, the Customer terminates a service before the end of the Minimum Term or the then current Extended Term, or iTVerse terminates for the Customer's material breach or non-payment, the Customer will pay within 30 days: all outstanding Charges and arrears; 100% of the recurring Charges for the unexpired balance of the term at the rate then applying; any setup, installation, equipment, licence or construction cost that was discounted, waived or spread and not recovered; any termination or cease charge levied by a Supplier, at cost; and the reasonable cost of recovering iTVerse equipment.
9.2These sums protect iTVerse's legitimate interest in performance of the agreed term, reflecting the committed and in many cases non-cancellable obligations to Suppliers that iTVerse enters into in reliance on that term, and are proportionate to that interest; they are not a penalty. No setup or installation charge is refundable on early termination.
9.3Notwithstanding clauses 9.1 and 9.2, iTVerse may, at the discretion of a director of iTVerse, agree to reduce or waive some or all of the early termination charges where it considers this reasonable in the circumstances. In reaching that decision, iTVerse may take into account any committed or non-cancellable Supplier costs, subscription or licence commitments, unrecovered setup, installation or equipment costs, and any other costs or liabilities arising from the early termination. Any reduction or waiver is effective only if agreed in writing by a director of iTVerse, applies only to the Agreement and circumstances for which it is given, and does not create any right, expectation or precedent for any other Customer or Agreement.
9.4Either party may terminate an Agreement immediately on written notice if the other commits a material breach not remedied within 30 days of written notice, or becomes insolvent, enters administration or liquidation, or has a receiver or administrator appointed.
9.5iTVerse may terminate a service on 30 days' written notice, without early termination charge to the Customer, where a Supplier withdraws the underlying product and no equivalent replacement is available on comparable commercial terms.

10. Suspension

10.1iTVerse may suspend a service in whole or in part where any sum is more than 14 days overdue, where the Customer is in material breach, where required by a Supplier or by law, where necessary to protect its network, systems or other customers, on an insolvency event or reasonably anticipated insolvency event, or for planned or emergency maintenance.
10.2Charges continue to accrue during any suspension other than one caused solely by iTVerse, and a reconnection charge at the published tariff applies on restoration following suspension for non-payment.

11. Third party services and software

11.1Many services are delivered using Supplier products and infrastructure. iTVerse's obligations for those elements are back-to-back with, and no greater than, the obligations owed to iTVerse by the relevant Supplier, and iTVerse is not liable for the acts or omissions of Suppliers, except to the extent the relevant loss is caused by iTVerse's own negligence or breach of this Agreement.
11.2Software and cloud services are supplied under the relevant licensor's terms, which are available on request and which the Customer agrees to comply with. The Customer indemnifies iTVerse against claims arising from the Customer's breach of any such licence.
11.3Subscription licences, including Microsoft 365 subscriptions, are subject to the vendor's subscription terms. A committed subscription term is not cancellable and cannot be reduced during that term; licence counts may be increased but not decreased until renewal; and the Customer remains liable for the full committed subscription cost regardless of usage or of the termination of any other service. Vendor price changes to subscriptions are passed through under clause 6.2.
11.4Where the Customer moves to or from another provider, the Customer is responsible for its contracts with that provider, including any early termination charges, unless the Order Form expressly states a capped amount that iTVerse will meet.

12. Equipment

12.1Title to equipment supplied by iTVerse passes only on payment in full; title to Supplier equipment (such as a carrier's network termination equipment) remains with the Supplier. Risk passes on delivery, and the Customer will keep equipment insured, safe, powered and undisturbed, and will not move or encumber it without written consent.
12.2Hired or loaned equipment must be returned within 7 days of the end of the relevant service, at the Customer's cost and cleared of the Customer's data, failing which iTVerse may charge its replacement value and may enter the site on reasonable notice to recover it.

13. Customer obligations

13.1The Customer will provide timely and safe access to its sites and systems, accurate and complete information, decisions and approvals when reasonably needed, suitable premises, power and environment for equipment, and the consents, licences, wayleaves and permissions required for the services, at its own cost.
13.2The Customer is responsible for all use of the services by anyone who obtains access through the Customer, including unauthorised or fraudulent use resulting from a compromise of the Customer's own network, credentials or equipment, and will pay all Charges arising from such use.
13.3The Customer will use the services lawfully and in accordance with iTVerse's acceptable use policy, and indemnifies iTVerse against claims arising from unlawful use or from content transmitted or stored by the Customer.
13.4Where iTVerse's performance is prevented or delayed by the Customer's act, omission or failure to meet these obligations, iTVerse is relieved of the affected obligations for the duration, is not liable for resulting costs, and may recover resulting costs from the Customer, including Supplier abortive charges at cost.

14. Service levels

14.1Service levels, where offered, are stated in the Service Schedule. Where they are passed through from a Supplier they are no greater than the levels that Supplier commits to iTVerse, and vary correspondingly if the Supplier varies them, on written notice.
14.2Service credits, where offered, are the Customer's sole and exclusive financial remedy for a service level failure, are capped at any amount iTVerse recovers from the relevant Supplier for the same failure, must be claimed in writing within 30 days, are applied against future invoices, and are not due while the account is in arrears.
14.3No service level applies to unavailability caused by planned or emergency maintenance, the Customer's own equipment, network, power or premises, denial of access, the Customer's acts or omissions, suspension under clause 10, or events under clause 19.

15. Liability

15.1Nothing in the Agreement limits or excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot lawfully be limited.
15.2Subject to clause 15.1, neither party is liable for loss of profit, revenue, business, contracts, anticipated savings or goodwill, loss or corruption of data or software, or any indirect or consequential loss.
15.3Subject to clause 15.1, iTVerse is not liable for loss arising from a security compromise of the Customer's own systems, network or credentials except to the extent caused by iTVerse's breach of the Agreement; nor for faults, interoperability or functionality issues in third-party software, products or equipment outside the scope of the services, including those caused by third-party updates or changes.
15.4Subject to clauses 15.1 to 15.3, iTVerse's total aggregate liability in any 12 month period is limited to the greater of £10,000 and the Charges paid for the affected service in the 12 months preceding the event giving rise to the claim, unless a higher amount is stated on the Order Form.
15.5Except as expressly stated in the Agreement, and to the extent permitted by law, all warranties, terms and conditions implied by statute or common law, including as to satisfactory quality and fitness for a particular purpose, are excluded.
15.6Other than claims for payment of sums due, for fraud, or under clause 15.1, neither party may bring a claim under the Agreement more than 12 months after the date on which it became aware, or ought reasonably to have become aware, of the event giving rise to the claim.

16. Confidentiality and intellectual property

16.1Each party will keep the other's commercial, technical and pricing information confidential and use it only for the purposes of the Agreement, except where disclosure is required by law, a regulator, or a Supplier for the purpose of delivering the services. This clause survives termination.
16.2Confidential information does not include information that is or becomes public other than through a breach of the Agreement, was already lawfully known to the recipient, is received in good faith from a third party entitled to disclose it, or is independently developed without use of the other party's information.
16.3iTVerse and its licensors own all intellectual property in the tools, scripts, reusable configuration templates and security baselines, documentation templates, processes, methods and know-how used or developed by iTVerse in delivering the services, and nothing in the Agreement transfers that ownership. Deliverables expressly identified as such in an Order Form are licensed or assigned as stated there. The Customer owns its own data at all times, together with the customer-specific configuration information applied within its own tenants, systems and equipment, which iTVerse will make available to the Customer as part of exit assistance; nothing in the Agreement transfers ownership of either to iTVerse, and iTVerse accesses them only as needed to deliver the services.

17. Data protection

17.1Each party will comply with UK data protection law, including the UK GDPR and the Data Protection Act 2018. Each party is an independent controller of the account and contact data it holds about the other.
17.2Where iTVerse processes personal data on the Customer's behalf in delivering a service, iTVerse acts as processor, the Customer as controller, and iTVerse's Data Processing Agreement (available at itverse.co.uk/legal) forms part of the Agreement, including its provisions on security measures, sub-processors, breach notification and international transfers.

18. Non-solicitation

18.1Neither party will, during the Agreement and for 12 months after it ends, employ, engage or solicit any person engaged by the other in delivering the services, without written consent. If the Customer does so, it will pay iTVerse an introduction fee equal to the greater of 25% of that person's annual remuneration and £10,000, which the parties agree is a genuine reflection of the recruitment, onboarding and training costs iTVerse would incur in replacing that person, and not a penalty.

19. Events beyond our control

19.1Neither party is liable for failure or delay caused by events beyond its reasonable control, including Supplier failure, utility or network failure, cable damage or theft, industrial action, fire, flood, storm, epidemic, war, civil unrest, or the act of any government or regulator. If such an event prevents iTVerse providing a service for more than 20 Business Days, either party may terminate that service on written notice without early termination charge.

20. General

20.1iTVerse may assign or novate the Agreement to a group company, a Supplier, or a purchaser of its business, and may perform its obligations using subcontractors of its choosing, remaining responsible to the Customer for their work. The Customer may not assign without iTVerse's written consent, not to be unreasonably withheld.
20.2Variations must be in writing and signed by both parties, except changes iTVerse may make under clauses 4.3, 6 and 14.1.
20.3Notices must be in writing to the recipient's registered office or the email addresses on the Order Form, and are deemed received the next Business Day. If any provision is held invalid, the remainder continues in force. No delay in enforcing a right waives it. Nothing creates a partnership or agency. No third party may enforce the Agreement under the Contracts (Rights of Third Parties) Act 1999.
20.4Before commencing proceedings in relation to any dispute (other than for urgent injunctive relief or debt recovery), each party will first give written notice of the dispute and the parties will attempt to resolve it through good faith discussion between nominated representatives with authority to settle, for a period of 30 days from the notice. If unresolved after that period, either party may pursue any remedy available to it.
20.5The Agreement is governed by the law of England and Wales and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

Data Processing Agreement

Version 1.0 - August 2026. iTVerse Technology Services Ltd, Company No. 14848571, 162 Warren Lane, Bingley, West Yorkshire, BD16 3BU ("iTVerse"). This Data Processing Agreement ("DPA") forms part of the Agreement between iTVerse and the Customer under clause 17.2 of the iTVerse Master Services Terms. The version in force on the date of the Order Form applies. Superseded versions are available on request.
This DPA applies wherever iTVerse processes personal data on the Customer's behalf in delivering the services - for example administering mailboxes and Microsoft 365 tenants, operating backup, monitoring and security tooling, or hosting portals. For that data the Customer is the controller and iTVerse the processor. It sits alongside the Master Services Terms and, on matters of data protection, prevails over them. Terms defined in the Master Terms have the same meaning here; "Data Protection Laws" means the UK GDPR, the Data Protection Act 2018 and applicable UK privacy legislation.

1. Processing on instructions

1.1iTVerse will process Customer personal data only on the Customer's documented instructions, which comprise the Agreement, the configuration of the services, and reasonable written instructions given from time to time, unless processing is required by law, in which case iTVerse will inform the Customer before processing where the law allows.
1.2iTVerse will inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Laws. iTVerse may suspend the affected processing until the instruction is confirmed or amended.
1.3The subject matter, duration, nature and purposes of processing, and the categories of data subjects and personal data, are set out in Annex 1.

2. Customer responsibilities

2.1The Customer is responsible for the lawfulness of the personal data and instructions it provides, including having a lawful basis, providing privacy information to data subjects, and the accuracy of the data.
2.2The Customer will notify iTVerse before requiring the processing of special category data or criminal offence data beyond what is incidental to the services, so that appropriate additional safeguards can be agreed.

3. Confidentiality and security

3.1iTVerse ensures that all personnel authorised to process Customer personal data are bound by contractual or statutory obligations of confidentiality and receive appropriate data protection and security training.
3.2iTVerse implements and maintains appropriate technical and organisational measures to protect Customer personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as described in Annex 2, and keeps those measures under review as risks and technology evolve.

4. Sub-processors

4.1The Customer gives general written authorisation for iTVerse to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex 3.
4.2iTVerse will give the Customer prior notice of any intended addition or replacement of a sub-processor, giving a reasonable opportunity to object on reasonable data protection grounds. Where an objection cannot be resolved in good faith, either party may terminate the affected service on 30 days' written notice without early termination charge for that service.
4.3iTVerse imposes on each sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains liable to the Customer for the performance of its sub-processors' obligations.

5. International transfers

5.1iTVerse will not transfer Customer personal data outside the United Kingdom unless an appropriate safeguard under Data Protection Laws is in place, including an adequacy regulation (such as for the EEA or the UK-US Data Bridge), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
5.2Where Customer personal data is processed within Microsoft cloud services supplied through iTVerse, Microsoft acts as sub-processor and the transfer mechanisms in the Microsoft Customer Agreement and Microsoft Products and Services Data Protection Addendum apply.

6. Assistance

6.1Taking into account the nature of the processing, iTVerse will assist the Customer by appropriate technical and organisational measures, so far as reasonably possible, in responding to data subject rights requests. iTVerse will notify the Customer without undue delay if it receives such a request directly and will not respond except on the Customer's instruction or where legally required.
6.2iTVerse will provide reasonable assistance with the Customer's obligations concerning security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner, taking into account the information available to iTVerse. Assistance that is material in scope may be chargeable at the day rate where the need does not arise from iTVerse's own breach of this DPA.

7. Personal data breach

7.1iTVerse will notify the Customer in writing of a confirmed personal data breach affecting Customer personal data without undue delay and in any event within 48 hours of becoming aware, including, so far as then known: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
7.2iTVerse will provide updates as further information becomes available and will cooperate in good faith with the Customer's investigation, notification and remediation. Notification to the Information Commissioner and to data subjects is the Customer's responsibility as controller; iTVerse will not make such notifications on the Customer's behalf unless instructed or legally required.

8. Deletion and return

8.1On termination or expiry of the relevant service, iTVerse will, at the Customer's choice, return or delete Customer personal data in its possession within 30 days, and delete remaining copies, except where law requires retention, in which case the data is isolated and protected until deletion is permitted. Certification of deletion is available on request.
8.2Data held within the Customer's own tenants and subscriptions (such as Microsoft 365) remains under the Customer's control throughout and is not deleted by iTVerse on exit; iTVerse's exit obligations for those services are the transfer of administrative control and documentation under the Service Schedule.

9. Audit

9.1iTVerse will make available the information reasonably necessary to demonstrate compliance with this DPA, will respond to a reasonable number of security and compliance questionnaires each year, and will provide copies of relevant certifications and reports where available, including its Cyber Essentials Plus certification and, for Microsoft services, Microsoft's published audit materials.
9.2The Customer may conduct or mandate one audit in any 12-month period, on not less than 30 days' written notice, during Business Hours and subject to reasonable confidentiality and safety requirements, at the Customer's cost. This limit does not apply following a confirmed material breach of this DPA by iTVerse or where required by a supervisory authority.

10. General

10.1This DPA takes effect from the date of the Order Form, continues for as long as iTVerse processes Customer personal data, and clauses 7 to 9 survive for so long as relevant. Liability under this DPA is subject to clause 15 of the Master Terms, save that nothing limits either party's liability to data subjects or supervisory authorities where the law does not permit it. This DPA is governed by the law of England and Wales.

Annex 1 - Processing details

ServiceNature and purposeData subjects and data categories
Managed IT support and Microsoft 365 administrationAccount, mailbox, device and tenant administration; service desk support; joiner and leaver processing; for the duration of the serviceCustomer staff, contractors and contacts: names, work contact details, credentials and identifiers, mailbox and file content incidentally accessed in support
Backup servicesBackup, storage and restoration of the agreed scopeAll data subjects and categories contained in the backed-up mailboxes, files, sites and servers
Security services (EDR, ITDR, filtering, training, dark web monitoring)Threat detection, containment, alerting and reporting; awareness training and simulation; monitoring for exposed credentialsCustomer staff: identifiers, device and usage telemetry, sign-in and security events, training results, exposed credential findings
Telephony (where taken)Operation of the telephone system; call routing and records; call recordings where enabledCallers and called parties: numbers, call records, and recording content where enabled
Email security and signaturesFiltering of inbound and outbound mail for spam and threats; application of signatures to outbound mail, in transitSenders and recipients of Customer mail: addresses, headers and message content in transit
Hosted portals and toolingOperation of Customer-facing portals and notifications built and hosted by iTVerseAs applicable to the portal: visitor, staff or customer names and contact details submitted to it

Annex 2 - Technical and organisational measures

 iTVerse is Cyber Essentials Plus certified and maintains, as a minimum: multi-factor authentication and role-based, least-privilege access to customer environments; unique named accounts with joiner and leaver controls; encryption of data in transit and, where supported, at rest; managed endpoint protection and 24x7 identity threat detection on its own estate; managed patching of its systems; segregated, access-controlled credential storage; logging and monitoring of administrative access; documented incident response with the 48-hour customer notification commitment in clause 7; staff confidentiality obligations and security training; supplier due diligence for the sub-processors in Annex 3; and backup of its own systems. Physical records are minimised; premises and devices are secured and encrypted.

Annex 3 - Sub-processors

Sub-processorPurposeLocation / transfer mechanism
Microsoft Ireland Operations Ltd / Microsoft CorporationMicrosoft 365, Azure and related cloud services supplied through iTVerse as CSPEEA / US - Microsoft DPA, adequacy and UK-US Data Bridge
Huntress Labs Inc.Endpoint and Microsoft 365 identity threat detection and responseUS - UK-US Data Bridge / IDTA
Atera Networks LtdRemote monitoring and management of supported devices; service desk toolingEEA / Israel (adequacy) / US - IDTA where applicable
Cloudflare, Inc.Hosting, content delivery and security for iTVerse-built portals and toolingUK / EEA / US - UK-US Data Bridge / IDTA
SMTP2GO (Pty) LtdTransactional email delivery for portals and service notificationsRegional routing incl. UK/EEA - IDTA where applicable
Acronis International GmbHServer and endpoint backup (ground-to-cloud) and backup storageUK data centre; Swiss parent - adequacy / IDTA
NinjaOne, LLCCloud-to-cloud Microsoft 365 backupEEA / US as configured - UK-US Data Bridge / IDTA
Hornetsecurity GmbHEmail security, spam and threat filtering of Customer mail flowGermany / EEA - adequacy
Exclaimer LtdEmail signature management applied to Customer mail flowUK / EEA (Microsoft Azure regions)
Voiceflex Ltd (where telephony is taken)SIP trunk call carriage, telephone numbers and call recordsUK
DigitalOcean, LLC (where telephony is taken)Cloud hosting of the Customer's 3CX telephone system, including call recordings where enabledUK (London region); US parent - UK-US Data Bridge / IDTA
3CX (where telephony is taken)Telephone system software vendor - licensing and update telemetryEEA
uSecure LtdSecurity awareness training, simulated phishing and dark web exposure monitoring (uLearn, uPhish, uBreach)UK / EEA
 This list is version-dated with this DPA. Additions and replacements are notified under clause 4.2, and the current list is always available at itverse.co.uk/legal or on request.

Acceptable Use Policy

Version 1.0 - August 2026. iTVerse Technology Services Ltd, Company No. 14848571. This Acceptable Use Policy ("AUP") is referenced by clause 13.3 of the iTVerse Master Services Terms and applies to every service iTVerse provides. The version in force on the date of your Order Form applies, together with any later version notified under the Master Terms.
This policy exists to protect our customers, our people, our network and the wider internet. The Customer is responsible for everyone who uses the services through it - staff, contractors, visitors and anyone else - and for making them aware of this policy. Breach of this AUP is a breach of the Agreement and may lead to suspension under clause 10 of the Master Terms.

1. Lawful use

1.1The services must be used lawfully. It is prohibited to use any service to create, store, send or make available material that is illegal; that infringes any person's intellectual property, privacy or confidentiality rights; that is defamatory, threatening or harassing; that constitutes or facilitates fraud or deception; or that relates to the abuse or exploitation of children, which iTVerse will report to the authorities without notice.

2. Network and systems abuse

2.1Users must not attempt to gain unauthorised access to any system, network, account or data; probe, scan or test the vulnerability of systems they are not authorised to test; intercept traffic not intended for them; mount or participate in denial of service attacks; forge headers, addresses or identifiers; distribute malware; or interfere with the service received by any other iTVerse customer or internet user.
2.2Users must not disable, bypass or interfere with security tooling, monitoring agents or configurations deployed by iTVerse as part of the services, and must not use the services to circumvent the security controls of any third party.

3. Email and messaging

3.1The services must not be used to send unsolicited bulk or marketing messages in breach of the Privacy and Electronic Communications Regulations, to send messages with forged or misleading origin information, to harvest addresses, or to operate open relays. Marketing carried out over the services must comply with applicable law and honour opt-outs. iTVerse and its Suppliers may apply sending limits and filtering to protect deliverability for all customers.

4. Connectivity

4.1Connectivity services are provided for the Customer's own business use and must not be resold or shared beyond the Customer's premises and organisation without iTVerse's written consent. Contended services are subject to reasonable and proportionate use so that shared capacity is fair to all users.

5. Telephony

5.1Voice services must not be used for artificially inflated traffic, auto-dialling or nuisance calling; outbound marketing calls must comply with the Telephone Preference Service and applicable law; and calling line identification must not be altered to misrepresent the caller's identity, in line with Ofcom's CLI guidelines. Premium rate and revenue-share abuse is prohibited.

6. Security responsibilities

6.1The Customer will keep credentials confidential and unique to named individuals, use multi-factor authentication where provided, keep its own systems and software within vendor support and updated, and notify iTVerse promptly of any suspected compromise of an account, device or service. Charges arising from unauthorised use are addressed by clause 13.2 of the Master Terms.

7. Hosted content and resources

7.1Content stored or published through iTVerse-hosted services must be lawful and must not place unreasonable or disproportionate load on shared infrastructure. iTVerse may remove or disable access to content that it reasonably believes breaches this policy or the law, notifying the Customer where practicable.

8. Treating our people with respect

8.1We help fastest when the conversation is civil. Abusive, threatening or discriminatory behaviour towards iTVerse staff will not be tolerated: iTVerse may end a call or interaction, require communication in writing, and, for repeated behaviour and after warning, treat it as a material breach of the Agreement.

9. Monitoring and enforcement

9.1iTVerse may monitor service and traffic data to operate, secure and improve the services; it does not routinely monitor the content of communications. Where iTVerse reasonably believes this policy has been breached, it may investigate, apply technical controls, suspend the affected service under clause 10 of the Master Terms, remove content, notify the Customer's nominated contact, recover costs reasonably incurred, and, where the law requires or permits, report the matter to Suppliers, regulators or law enforcement.

10. Reporting abuse

10.1Suspected abuse of iTVerse services should be reported to hello@itverse.co.uk with as much detail and evidence as possible. Domain-related abuse is handled under our separate Abuse Policy on this page.

Privacy Policy

Last updated: 27 March 2026

This privacy policy sets out how iTVerse uses and protects any information that you give iTVerse when you use this website. iTVerse is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement.

What We Collect

  • Name and job title
  • Contact information including email address
  • Demographic information such as postcode
  • Preferences and interests
  • Other information relevant to customer surveys and/or offers

What We Do With the Information We Gather

We require this information to understand your needs and provide you with a better service, and in particular for internal record keeping, improving our products and services, and occasionally sending promotional information about new products or offers using the email address you have provided.

Security

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.

How We Use Cookies

A cookie is a small file which asks permission to be placed on your computer's hard drive. We use traffic log cookies to identify which pages are being used and to help us analyse data about web page traffic and improve our website. We only use this information for statistical analysis purposes and then the data is removed from the system. You can choose to accept or decline cookies in your browser settings.

Analytics & Third-Party Tools

We use Google Analytics and Microsoft Clarity to understand how visitors interact with our website. Google Analytics collects anonymised data on page views, traffic sources, and user behaviour. Microsoft Clarity records anonymised session replays and heatmaps. Neither service is used to identify individual users. For full details, see our Cookie Policy.

Links to Other Websites

Our website may contain links to other websites of interest. However, once you have used these links to leave our site, we do not have any control over that other website and cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites.

Controlling Your Personal Information

We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so. You may request details of personal information which we hold about you. If you believe that any information we are holding on you is incorrect or incomplete, please write to or email us at hello@itverse.co.uk.

Registered address: iTVerse Technology Services Ltd, 162 Warren Lane, Bingley, Bradford, BD16 3BU

Cookie Policy

Last updated: 27 March 2026

iTVerse may use cookies, web beacons, tracking pixels, and other tracking technologies when you visit our website at itverse.co.uk to help customise the site and improve your experience. We reserve the right to make changes to this Cookie Policy at any time.

What Is a Cookie?

A "cookie" is a string of information which assigns you a unique identifier that we store on your computer. Your browser then provides that unique identifier to us each time you submit a query to the site. Cookies help us understand how the site is being used and improve your user experience.

Types of Cookies We Use

  • Analytics Cookies — monitor how users reached the site and how they interact with it.
  • Our Cookies (First-party) — necessary cookies without which the site won't work properly.
  • Personalisation Cookies — recognise repeat visitors and remember your settings and preferences.
  • Security Cookies — help identify and prevent security risks and authenticate users.
  • Third-Party Cookies — placed by companies that run certain services we offer.

Third-Party Analytics Tools

We use the following third-party analytics services on this website. Each provider has its own privacy policy governing how data is collected and processed.

ServiceProviderPurposePrivacy Policy
Google Analytics Google LLC Measures site traffic, page views, and user behaviour to help us understand how visitors use the site. Google Privacy Policy
Microsoft Clarity Microsoft Corporation Records anonymised session replays and heatmaps to help us identify usability issues and improve the site experience. Microsoft Privacy Statement

You can opt out of Google Analytics tracking at any time using the Google Analytics Opt-out Browser Add-on. Microsoft Clarity data is anonymised and does not include personally identifiable information.

Controlling Cookies

Most browsers accept cookies by default. You can remove or reject cookies in your browser settings, though this may affect the availability and functionality of the site. For guidance, visit your browser's help pages: Chrome, Firefox, Safari, or Edge.

Change Your Cookie Preferences

You can change or withdraw your cookie consent at any time.

Contact

If you have questions about this Cookie Policy, contact us at hello@itverse.co.uk.

Complaints Policy

Last updated: 27 March 2026

iTVerse Technology Services Ltd is committed to providing high-quality services and products to our customers. We recognise that, despite our best efforts, issues may arise that require prompt and effective resolution. This Complaints Policy outlines our commitment to addressing customer complaints in a fair, transparent and efficient manner.

How to Raise a Complaint

Complaints can be submitted by emailing hello@itverse.co.uk or calling 03300 56 88 33. All complaints will be logged with a unique reference number for tracking purposes.

What Happens Next

  • Acknowledgement — we will acknowledge your complaint within 3 working days.
  • Investigation — your complaint will be investigated promptly and impartially. We may request additional information if needed.
  • Resolution — we aim to resolve complaints within 10 working days from acknowledgement, keeping you informed throughout.
  • Final response — the outcome will be communicated to you in writing.

Escalation

If you are not satisfied with our final response, or six weeks have passed since you first raised your complaint with us, you may refer your complaint free of charge to the Communications Ombudsman, the independent alternative dispute resolution scheme, approved by Ofcom, of which iTVerse is a member. You can contact them at www.commsombudsman.org, by phone on 0330 440 1614, or by post at Communications Ombudsman, P.O. Box 730, Warrington, WA4 6WU. Where we have reached our final position on a complaint, we will issue a deadlock letter on request, which allows you to go to the Ombudsman without waiting six weeks. This applies to our communications services (broadband, connectivity and telephony) for consumers and small businesses; for all other services, you may request escalation to a director of iTVerse, and details of the escalation route will be included in our final resolution communication.

Switching provider

If you decide to move to another provider, we will not obstruct the transfer, and any telephone numbers you use with us remain available for you to port to your new provider once sums due have been paid. Where you switch or port during a minimum commitment period, early termination charges apply as set out in clause 9 of our Master Services Terms. Where a carrier or other supplier charges us for ceasing, transferring or porting your service, that charge is passed on to you at cost - we do not add a margin to exit costs. Your new provider will normally manage the transfer; please contact us before placing a transfer order so we can make the process as smooth as possible.

Continuous Improvement

All complaints are analysed to identify areas for improvement in our products, services and internal processes. Your feedback genuinely helps us do better.

Contact

For complaints or enquiries related to this policy, please contact us at hello@itverse.co.uk or call 03300 56 88 33.

Abuse Policy

Last updated: 27 March 2026

iTVerse Technology Services Ltd is dedicated to upholding the integrity and security of the .uk domain space. This Abuse Policy outlines our commitment to addressing instances of misuse or abuse within the .uk domain namespace.

Types of Abuse

Abuse within the .uk domain space may encompass, but is not limited to:

  • Malware Distribution — hosting or distributing malware or malicious software.
  • Phishing — hosting phishing websites or engaging in phishing activities.
  • Spam — sending unsolicited bulk email or engaging in spamming activities.
  • Intellectual Property Infringement — registering domain names that infringe on the IP rights of others.
  • Fraudulent Activities — using domain names to conduct fraudulent schemes or deceptive practices.
  • Child Exploitation — hosting or distributing child exploitation material.
  • Illegal Content — hosting content that is illegal or prohibited by law.

Reporting Abuse

If you become aware of abuse, please report it to us at hello@itverse.co.uk. Please provide as much relevant information and evidence as possible to assist our investigation.

Actions We May Take

  • Suspension or termination of the domain registration of abusive domain names.
  • Contacting registrants and requesting remedial action.
  • Cooperating with law enforcement authorities where illegal activity is involved.
  • Public disclosure of information about abusive domain names where appropriate.

Appeals

Registrants who believe their domain name has been unfairly targeted may appeal in writing to hello@itverse.co.uk. Appeals should include relevant evidence and arguments. iTVerse will review appeals fairly and may overturn or modify our initial decision if warranted.

Contact

iTVerse Technology Services Ltd, 162 Warren Lane, Bingley, BD16 3BU. Email: hello@itverse.co.uk

Independently reviewed by our customers