Skip to content
NexusReef
WorkCapabilitiesMethodAboutContact
๐Ÿ‡ฌ๐Ÿ‡งEN๐Ÿ‡ณ๐Ÿ‡ฑNL
Start a project
Navigate the ecosystem
01Work02Capabilities03Method04About05Contact
๐Ÿ‡ฌ๐Ÿ‡งEnglish๐Ÿ‡ณ๐Ÿ‡ฑNederlands
Send the signal

NexusReef legal

Business Terms and Conditions

The commercial framework for NexusReef business-to-business services, delivery, intellectual property, support, data processing and risk allocation.

Review draftVersion 1.0 ยท Effective 18 August 2026
DocumentBusiness Terms and Conditions
On this page
1. Definitions and interpretation2. Application, contracting and order of precedence3. Proposals and Statements of Work4. Performance of the Services5. Client responsibilities and dependencies6. Project timing and delivery7. Change control8. Testing and acceptance9. Fees, invoicing and payment10. Third-Party Services and open-source software11. AI-enabled Services12. Intellectual property rights13. Software licences and SaaS14. Hosting and infrastructure15. Maintenance and support16. Confidentiality17. Data protection18. Information security19. Warranties and remedies20. Intellectual property claims21. Liability22. Suspension23. Term and termination24. Exit assistance and data return25. Force majeure26. Compliance and acceptable conduct27. Publicity and portfolio use28. Notices29. Assignment and subcontracting30. General31. Dispute resolution, governing law and jurisdictionSchedule 1 - Data Processing ScheduleS1.1 Roles and scopeS1.2 Documented instructionsS1.3 Confidentiality and personnelS1.4 SecurityS1.5 SubprocessorsS1.6 International transfersS1.7 Data subject requests and regulatory assistanceS1.8 Personal data breachesS1.9 Audit and informationS1.10 Return and deletionS1.11 Liability and precedenceAnnex 1 - Processing detailsAnnex 2 - Baseline technical and organisational measuresAnnex 3 - Transfer mechanism hierarchySchedule 2 - Statement of Work checklist
Review draft

This page reflects the supplied v1.0 review draft. It is not yet intended for contractual reliance and remains excluded from search indexing until legal approval.

Legal entity
NexusReef Ltd ยท 17390669
Contact
info@nexusreef.com
Registered office
82A James Carter Road, Bury St. Edmunds, England, IP28 7DE

1. Definitions and interpretation

TermMeaning
AgreementThe binding contract between NexusReef and the Client comprising the applicable Proposal, Statement of Work, these Terms, any Data Processing Schedule, service schedule and any other document expressly incorporated by reference.
Applicable Data Protection LawAll data protection and privacy laws applicable to a party or the relevant processing, including the UK GDPR, the Data Protection Act 2018, PECR, the Data (Use and Access) Act 2025 and, where applicable, the EU GDPR and national implementing laws.
Background TechnologyAll software, source code, object code, libraries, frameworks, tools, templates, methods, know-how, designs, documentation, algorithms, models, prompts, workflows, systems and materials owned, developed or licensed by NexusReef independently of the Client-specific Services, including improvements and generic or reusable elements.
Business DayA day other than Saturday, Sunday or a public holiday in England on which banks in London are open for business.
Change RequestA written request to change the scope, assumptions, Deliverables, timetable, Fees, acceptance criteria, responsibilities or other part of a Statement of Work.
ClientThe business, organisation or public authority identified in the applicable Proposal or Statement of Work. References to the Client include its authorised users where the context requires.
Client DataPersonal data and other data, content or records supplied by or on behalf of the Client or processed through the Services for the Client.
Client MaterialsAll content, brands, trade marks, specifications, data, software, systems, documentation, instructions and other materials supplied or made available by or on behalf of the Client.
Confidential InformationInformation disclosed by or on behalf of a party that is marked confidential or that a reasonable business person would understand to be confidential, including business plans, pricing, security information, source code, credentials, Client Data, product roadmaps and trade secrets.
DeliverablesThe outputs expressly identified as deliverables in a Statement of Work, excluding Third-Party Services and NexusReef Background Technology except to the extent embedded in those outputs.
FeesThe charges, rates, subscriptions, licence fees, expenses and other amounts payable by the Client under the Agreement.
Intellectual Property RightsCopyright, database rights, patents, rights in inventions, trade marks, design rights, domain name rights, rights in confidential information and know-how, and all similar rights anywhere in the world, whether registered or unregistered.
ProposalA quotation, proposal, order form or commercial offer issued by NexusReef.
ServicesThe services specified in a Statement of Work, which may include software, website or application development, systems integration, AI solutions, consultancy, project management, licensing, SaaS, hosting, maintenance or support.
Statement of Work or SOWA document agreed by the parties that describes the Services, Deliverables, responsibilities, assumptions, timetable, Fees and any service-specific terms.
TermsThese Business Terms and Conditions, as incorporated into the Agreement.
Third-Party ServicesProducts, platforms, software, APIs, cloud services, hosting, payment services, app stores, plug-ins, models, data sources, licences or services supplied by a person other than NexusReef.

1.1 Headings do not affect interpretation. Words in the singular include the plural and vice versa. References to writing include email and electronic signature, but not informal messages where the Agreement requires a formal notice or Change Request.

1.2 The words "including", "includes" and similar expressions are illustrative and do not limit the words preceding them.

1.3 A reference to legislation includes amendments and replacement legislation in force from time to time, together with subordinate legislation, but no change in law expands a party's contractual liability retrospectively.

2. Application, contracting and order of precedence

2.1 These Terms apply only where they are referenced in or attached to a Proposal, SOW, order form, service agreement or other written acceptance. They apply to all Services supplied under that Agreement.

2.2 The Client confirms that it is entering into the Agreement wholly or mainly for business purposes and not as a consumer. If a consumer is to receive services directly from NexusReef, separate consumer terms must be agreed before supply.

2.3 If documents conflict, the following order applies, highest first: (a) a signed variation or Change Request; (b) the SOW; (c) any Data Processing Schedule or service-specific schedule; (d) the Proposal; (e) these Terms; and (f) any other incorporated document.

2.4 Terms in a Client purchase order, procurement portal, onboarding form or similar document do not apply unless NexusReef expressly accepts them in a document signed by a director. A purchase order may be used for administrative identification only.

2.5 An Agreement is formed when both parties sign or electronically accept the relevant document, or when NexusReef starts work following the Client's clear written instruction and the Client has been given these Terms before work starts.

2.6 Each person accepting an Agreement warrants that they are authorised to bind the party they represent.

3. Proposals and Statements of Work

3.1 A Proposal is open for acceptance for 30 days from its date unless it states another period. Before acceptance, NexusReef may withdraw or revise it.

3.2 A Proposal or estimate is based on the information, assumptions, dependencies and scope available when issued. Unless expressly labelled "fixed price", budgets and time estimates are good-faith estimates and are not guaranteed maximums.

3.3 Each SOW should identify, as applicable: the Services and Deliverables; exclusions; assumptions; Client dependencies; milestones; Fees and payment schedule; acceptance criteria; Third-Party Services; hosting and support; data processing; intellectual property treatment; and any special liability or exit terms.

3.4 Work outside the agreed scope is chargeable at the rates stated in the SOW or, if none are stated, NexusReef's then-current rates. NexusReef is not obliged to perform out-of-scope work until a Change Request is agreed.

3.5 Discovery, audit, migration assessment, technical investigation and prototype phases may identify risks or additional requirements that could not reasonably be priced beforehand. The parties will use change control to agree the resulting scope, timetable and Fees.

4. Performance of the Services

4.1 NexusReef will perform the Services with reasonable care and skill and materially in accordance with the applicable SOW.

4.2 Unless the SOW expressly creates a result obligation, NexusReef provides professional services on a reasonable-efforts basis. NexusReef does not guarantee revenue, rankings, conversion rates, user adoption, funding, regulatory approval or any other commercial outcome.

4.3 NexusReef may choose the personnel, tools, development methods and technical architecture used to perform the Services, subject to the SOW and Applicable Data Protection Law.

4.4 NexusReef may use suitably qualified employees, contractors and subprocessors. NexusReef remains responsible for their performance to the same extent as if NexusReef performed the relevant obligation itself, subject to the Agreement.

4.5 NexusReef does not provide legal, tax, accounting, financial, medical, employment or regulated professional advice. Any compliance-related functionality or guidance is technical support only; the Client must obtain specialist advice where appropriate.

4.6 NexusReef may make non-material changes to the Services where reasonably required for security, legal compliance, maintainability or technical efficiency, provided these do not materially reduce agreed functionality.

5. Client responsibilities and dependencies

5.1 The Client will provide complete, accurate and timely information, decisions, approvals, access, credentials, personnel, environments, content and other dependencies reasonably required for the Services.

5.2 The Client will appoint a suitably authorised project contact who can give instructions, consolidate feedback and approve decisions. NexusReef may rely on instructions from that contact until notified otherwise in writing.

5.3 The Client is responsible for the legality, accuracy, quality and completeness of Client Materials and Client Data, and for obtaining all licences, permissions, notices and consents necessary for NexusReef to use them as instructed.

5.4 Before NexusReef accesses or changes a Client production system, the Client must maintain a current recoverable backup unless backup responsibility is expressly allocated to NexusReef in the SOW.

5.5 The Client will not allow unauthorised persons to modify Deliverables or relevant environments during development, testing or incident investigation. NexusReef is not responsible for defects or delays caused by third-party or Client changes.

5.6 The Client must promptly review requests, prototypes, designs, test releases and decisions. Consolidated feedback must be provided through the agreed channel. Conflicting or fragmented feedback may be treated as a Change Request or chargeable project management.

5.7 The Client will use the Services lawfully, follow documentation and security instructions, protect credentials, maintain appropriate user permissions and promptly notify NexusReef of suspected compromise or misuse.

5.8 If the Client fails to meet a dependency, NexusReef may adjust the timetable, reallocate reserved capacity, invoice work completed and reasonable standby or re-planning costs, and submit a Change Request for resulting additional work.

6. Project timing and delivery

6.1 Milestones and delivery dates are target dates unless the SOW expressly states that a date is fixed. Time is not of the essence unless the SOW expressly says so for a specific obligation.

6.2 A delivery date is automatically extended to the extent delay is caused by the Client, a Change Request, a Third-Party Service, a force majeure event, inaccurate assumptions, unavailable access or a dependency outside NexusReef's reasonable control.

6.3 For agile or iterative projects, the backlog, priorities and sprint content may change by agreement. An agreed budget or target date does not guarantee completion of every backlog item; the parties will prioritise the highest-value items within available capacity.

6.4 NexusReef may deliver in stages. A stage may be invoiced and accepted independently where the SOW provides for staged delivery.

6.5 If a project is paused at the Client's request or because of Client delay for more than 20 Business Days, NexusReef may close the active delivery slot. Restart dates depend on capacity, and reasonable re-onboarding or re-planning Fees may apply.

7. Change control

7.1 Either party may propose a Change Request. The request should describe the proposed change and the reason for it.

7.2 NexusReef will assess the likely effect on scope, architecture, security, data protection, timetable, Fees and resources. Assessment work may be chargeable if substantial, provided NexusReef states this before starting the assessment.

7.3 A Change Request becomes binding only when accepted in writing by authorised representatives of both parties. Until then, the existing Agreement continues unchanged.

7.4 Where urgent action is reasonably required to contain a security incident, comply with law or prevent material service damage, NexusReef may take proportionate emergency action and notify the Client as soon as reasonably practicable. Reasonable associated Fees are payable where the cause is not attributable to NexusReef.

8. Testing and acceptance

8.1 Where acceptance criteria are stated in the SOW, the Client will test the Deliverables against those criteria within 10 Business Days after delivery or re-delivery, unless another period is stated.

8.2 A rejection notice must be in writing and identify reproducible, material non-conformities against the agreed acceptance criteria, with sufficient evidence to investigate. General dissatisfaction, new preferences or requirements not stated in the acceptance criteria do not constitute rejection.

8.3 NexusReef will use reasonable efforts to correct valid material non-conformities and re-submit the affected Deliverable. The acceptance process then repeats for that correction.

8.4 Minor defects that do not materially prevent the intended use do not delay acceptance. NexusReef will record and address them in a reasonable period or under the agreed support arrangement.

8.5 A Deliverable is deemed accepted on the earliest of: (a) written acceptance; (b) expiry of the acceptance period without a valid rejection notice; (c) productive or live use, other than controlled acceptance testing; or (d) the Client instructing NexusReef to proceed to a dependent stage.

8.6 If no acceptance criteria are stated, acceptance is based on whether the Deliverable materially conforms to the documented requirements in the SOW.

9. Fees, invoicing and payment

9.1 The Client will pay the Fees in the currency and on the schedule stated in the SOW. If no currency is stated, Fees are in pounds sterling. Fees exclude VAT and other applicable sales, withholding or transaction taxes, which are payable in addition where legally due.

9.2 Time-and-materials Services are charged for time reasonably spent, including agreed meetings, project management, investigation, documentation and deployment. Fixed Fees apply only to the expressly defined scope and assumptions.

9.3 The Client will reimburse reasonable pre-approved travel, accommodation and third-party expenses. Third-Party Services may be billed in advance and may be subject to exchange-rate changes or supplier price increases.

9.4 Unless the SOW states otherwise, invoices are due within 14 calendar days of the invoice date. Payment must be made without set-off, counterclaim, deduction or withholding, except where required by law.

9.5 The Client must notify NexusReef of a genuine invoice dispute within 7 Business Days of receipt, identifying the amount and detailed reason. The undisputed amount remains payable on time. The parties will work in good faith to resolve the disputed amount promptly.

9.6 For overdue commercial debts, NexusReef may charge statutory interest under the Late Payment of Commercial Debts (Interest) Act 1998, currently 8 percentage points above the Bank of England base rate, together with statutory fixed compensation and reasonable recovery costs.

9.7 If an undisputed amount remains overdue 7 days after written reminder, NexusReef may suspend affected Services or withhold release of Deliverables, credentials, licences or production deployment until payment. Suspension does not waive payment or extend any licence.

9.8 A deposit or advance payment secures capacity and may be applied to work, committed resources and non-cancellable costs. It is refundable only to the extent expressly stated in the SOW or required by law.

9.9 For recurring Services, NexusReef may revise Fees at renewal or after the first 12 months by giving at least 30 days' notice. If an increase exceeds the percentage change in the UK Consumer Prices Index plus three percentage points, the Client may terminate the affected recurring Service before the increase takes effect, unless the increase reflects a direct Third-Party Service cost or a Change Request.

10. Third-Party Services and open-source software

10.1 The Services may depend on Third-Party Services. Their availability, security, pricing, functionality, data location and terms are controlled by the relevant supplier and may change.

10.2 The Client is bound by the applicable third-party terms where it holds the account, licence or subscription. NexusReef may require the Client to accept those terms directly and maintain valid payment details.

10.3 Unless the SOW says otherwise, the Client owns and controls production domain registrations, cloud accounts, app-store accounts, analytics accounts and payment accounts. NexusReef may administer them as an authorised user for the Services.

10.4 NexusReef is not liable for Third-Party Service outages, deprecations, security incidents, model changes, policy decisions, account suspension or price increases except to the extent directly caused by NexusReef's breach of the Agreement.

10.5 Deliverables may contain open-source software subject to its own licence. Those components are licensed, not assigned, under the relevant open-source terms. NexusReef will not knowingly include a component that requires disclosure of proprietary Client code unless identified and approved in the SOW or otherwise agreed in writing.

10.6 A material third-party change may require a Change Request. If no reasonable technical alternative is available, either party may terminate the affected part of the Services on written notice, with the Client paying Fees and committed costs accrued to termination.

11. AI-enabled Services

11.1 This clause applies where the Services use machine learning, generative AI, a large language model, computer vision, automated recommendation, classification or another AI system.

11.2 AI outputs are probabilistic and may be incomplete, inaccurate, biased, outdated or unsuitable. The Client must apply appropriate human review before relying on an output, publishing it, communicating it to another person or using it to make a decision.

11.3 Unless expressly agreed in a compliance-specific SOW, AI outputs must not be used as the sole basis for decisions with legal or similarly significant effects, or in high-risk areas such as employment, credit, insurance, essential services, health, biometric identification, education, law enforcement or critical infrastructure.

11.4 The Client must disclose the intended purpose, users, territories, data categories, decision context and foreseeable misuse of an AI-enabled system. A change to the intended purpose or deployment context may change the legal classification and requires a Change Request and compliance review.

11.5 Each party will comply with obligations that apply to its role as provider, deployer, importer, distributor, controller or processor under applicable AI and data protection law. The Client is responsible for deployment controls, user instructions, human oversight, staff training, monitoring and lawful operational use unless the SOW allocates a task to NexusReef.

11.6 Where applicable, NexusReef will design or configure user-facing AI interactions so users are informed that they are interacting with AI. The parties will agree any machine-readable marking, labelling, logging, documentation or transparency measures required for generated content.

11.7 The Client must not submit personal data, special category data, confidential information, trade secrets or third-party protected content to an external AI provider unless that use is approved in the SOW and appropriate contractual, security, transparency and transfer safeguards are in place.

11.8 NexusReef will not intentionally use Client Confidential Information or Client Data to train a general-purpose model for NexusReef or a third party unless the Client expressly agrees in writing. This does not prevent processing needed to provide the agreed AI feature under approved provider terms.

11.9 Third-party AI models and APIs are Third-Party Services. Model behaviour, usage limits, content filters, pricing and availability may change, and equivalent outputs cannot be guaranteed after a model or version change.

11.10 The Client will not use AI-enabled Services for prohibited, deceptive, discriminatory, manipulative, infringing, unsafe or unlawful purposes, or to generate non-consensual intimate material, child sexual abuse material or content intended to impersonate a real person unlawfully.

12. Intellectual property rights

12.1 Each party retains ownership of Intellectual Property Rights it owned or developed independently before or outside the Agreement. The Client retains ownership of Client Materials and Client Data.

12.2 NexusReef and its licensors retain all Intellectual Property Rights in Background Technology, generic or reusable components, tools, templates, methods, know-how, architecture, development techniques, documentation frameworks, prompts, workflows, models and improvements, even where used in or developed while performing the Services.

12.3 Subject to full payment of all Fees due for the relevant SOW, NexusReef assigns to the Client, with full title guarantee, the Intellectual Property Rights owned by NexusReef in Deliverables created exclusively and specifically for the Client and expressly identified as bespoke Deliverables in the SOW. This assignment excludes Background Technology, Client Materials, Third-Party Services, open-source software and any item stated to be licensed.

12.4 To the extent Background Technology is embedded in an assigned Deliverable and is necessary to use, maintain or modify it, NexusReef grants the Client, on full payment, a perpetual, worldwide, royalty-free, non-exclusive licence to use, copy, modify and permit its professional advisers or replacement suppliers to use that embedded Background Technology solely as part of, or to support, the Deliverable. The Client may transfer this licence with the business or assets to which the Deliverable relates.

12.5 The assignment in clause 12.3 is a present assignment of existing rights and, to the extent permitted by law, an agreement to assign future rights as they arise. NexusReef will execute reasonable further documents needed to evidence the assignment, at the Client's cost, after full payment.

12.6 Source code, repository transfer, build pipelines, infrastructure-as-code, design source files, credentials and technical handover are included only to the extent stated in the SOW. Deployment of a website or application does not by itself require delivery of every internal tool, generic library or development environment.

12.7 The Client grants NexusReef a non-exclusive, worldwide, royalty-free licence during the Agreement to use, copy, adapt and process Client Materials and Client Data only as necessary to perform, secure and support the Services and meet legal obligations.

12.8 The Client warrants that NexusReef's authorised use of Client Materials and Client Data will not infringe third-party rights or law. The Client will indemnify NexusReef against third-party claims, losses and reasonable legal costs arising from a breach of this warranty, subject to clause 20.4.

12.9 No right in NexusReef-owned products, product brands, shared platforms or independent ventures - including Silent Run and Findex - transfers under a Client SOW unless expressly stated in a separate signed agreement.

12.10 To the extent permitted by law, NexusReef will procure waivers of moral rights in assigned bespoke Deliverables from personnel who created them. No waiver is required for Background Technology or third-party material.

13. Software licences and SaaS

13.1 Where NexusReef provides software or a hosted service that is not assigned under clause 12, NexusReef grants the Client a non-exclusive, non-transferable right during the agreed term to access and use it for the Client's internal business purposes and within agreed user, territory, environment and usage limits.

13.2 The Client must not, except where mandatory law permits: copy or distribute the software beyond agreed use; sell, sublicense or make it available as a service bureau; reverse engineer or attempt to discover source code; bypass security or usage limits; remove proprietary notices; or publish benchmark or security-test results without consent.

13.3 The Client is responsible for its users, account administration, access permissions and activity through its accounts. It must promptly disable access for persons who no longer require it.

13.4 NexusReef may introduce updates, patches and reasonable changes. A material reduction in core contracted functionality entitles the Client to notify NexusReef and, if not remedied within a reasonable period, terminate the affected recurring service at the end of the current paid period.

13.5 Usage above agreed limits may be restricted or charged at the rates stated in the SOW. NexusReef will use reasonable efforts to notify the Client before non-emergency restriction.

14. Hosting and infrastructure

14.1 Hosting, deployment, monitoring, backups, disaster recovery, domain management and infrastructure support are provided only where expressly stated in the SOW.

14.2 Unless an SLA states otherwise, NexusReef will use reasonable efforts to keep hosted Services available but does not guarantee uninterrupted or error-free operation. Planned maintenance, emergency maintenance, internet failures and Third-Party Service incidents may affect availability.

14.3 The SOW must specify any uptime commitment, support hours, recovery point objective, recovery time objective, backup frequency, retention, geographic location and service credit. If not specified, no contractual SLA or guaranteed restore point applies.

14.4 NexusReef may suspend or isolate systems where reasonably necessary to address a security risk, abuse, legal requirement, infrastructure threat or material impact on other customers. NexusReef will minimise disruption and notify the Client where lawful and practicable.

14.5 The Client is responsible for content, traffic, lawful use, user administration and capacity requirements. Excessive or abusive use may require a capacity upgrade or Change Request.

14.6 Unless the SOW says otherwise, the Client must retain independent copies of business-critical data and exported content. Backup is not an archive and may not permit recovery of every item or historical version.

15. Maintenance and support

15.1 Maintenance and support are included only if the SOW identifies the covered systems, term, support channel, support hours, severity definitions, response targets, update policy and Fees.

15.2 Maintenance normally covers diagnosis and correction of reproducible defects in the supported version that cause material non-conformity with agreed documentation. New features, redesigns, content work, migrations, regulatory changes and third-party changes are not maintenance unless stated.

15.3 Support targets are response targets, not guaranteed resolution times, unless an SLA expressly states otherwise. Resolution depends on severity, reproducibility, access, third parties and technical feasibility.

15.4 Maintenance does not cover issues caused by misuse, unsupported environments, unauthorised modification, Client or third-party code, failure to follow documentation, compromised credentials or a Third-Party Service, except as separately agreed.

15.5 NexusReef may require installation of supported versions, security patches or configuration changes before continuing support. Refusal may limit or suspend support for affected components.

16. Confidentiality

16.1 Each receiving party will keep the disclosing party's Confidential Information confidential, use it only for the Agreement and protect it with at least reasonable care.

16.2 A receiving party may disclose Confidential Information to its personnel, professional advisers, insurers, financiers, subcontractors and service providers who need it for the Agreement and are bound by confidentiality obligations no less protective in substance.

16.3 Confidential Information does not include information the receiving party can demonstrate: is public other than through breach; was lawfully known without restriction; was independently developed without use of the information; or was lawfully received from a third party without confidentiality duty.

16.4 A party may disclose information where required by law, court or regulator, provided it gives advance notice where lawful and reasonably assists the other party to seek protection.

16.5 These confidentiality obligations continue for five years after termination, and indefinitely for source code, credentials, security information, Client Data and trade secrets while they remain confidential.

16.6 On request or termination, each party will return or securely delete the other party's Confidential Information where reasonably practicable, except for legal records, secure backups and information required to establish or defend legal rights.

17. Data protection

17.1 Each party will comply with Applicable Data Protection Law for personal data it processes under or in connection with the Agreement.

17.2 For ordinary business contact, billing and relationship data, each party normally acts as an independent controller and is responsible for its own privacy information, lawful basis, retention and rights handling.

17.3 Where NexusReef processes personal data on the Client's documented instructions as a processor, Schedule 1 applies and forms part of the Agreement. The processing details must be completed in the SOW or Schedule 1 annex before production processing begins.

17.4 The Client warrants that its instructions and the collection and use of Client Data are lawful, transparent and limited to what is necessary. The Client remains responsible for determining the purposes and essential means of processing unless the parties agree another role in writing.

17.5 The Client must not provide special category data, criminal-offence data, children's data or high-risk datasets unless expressly identified in the SOW and appropriate legal, security and operational controls have been agreed.

17.6 If a party believes the agreed processing or instruction infringes Applicable Data Protection Law, it will promptly notify the other party and may suspend the affected processing while the parties resolve the issue.

18. Information security

18.1 Each party will implement appropriate technical and organisational measures proportionate to the nature, scope, context and risk of its processing and systems.

18.2 NexusReef will apply secure-development and access-control practices appropriate to the Services, which may include least privilege, multi-factor authentication, encryption in transit, patching, logging, environment separation, code review and incident management.

18.3 No internet-connected system can be guaranteed completely secure. NexusReef does not warrant that the Services will prevent every attack, error, malicious act or loss, but this does not reduce its obligation to use reasonable care and agreed security measures.

18.4 The Client is responsible for its endpoints, networks, identity systems, user conduct, passwords, access reviews, Client-controlled configurations, lawful content and security of systems outside NexusReef's agreed scope.

18.5 Each party will notify the other without undue delay of a confirmed security incident that materially affects the other party's systems, Confidential Information or personal data and will cooperate proportionately in containment, investigation and legally required notification.

18.6 The Client must not conduct penetration testing, vulnerability scanning or load testing against a NexusReef-managed environment without prior written approval of scope and timing. Good-faith vulnerability reports must be made privately and not publicly disclosed before remediation.

19. Warranties and remedies

19.1 Each party warrants that it has authority to enter into and perform the Agreement.

19.2 NexusReef warrants that the Services will be performed with reasonable care and skill and that, for 30 days after acceptance, bespoke Deliverables will materially conform to agreed acceptance criteria when used in the agreed environment.

19.3 If the Client reports a valid breach of clause 19.2 during the warranty period with sufficient detail, NexusReef will use reasonable efforts to re-perform the affected Service or correct the affected Deliverable. This is the Client's primary remedy for that breach.

19.4 The warranty does not apply to issues caused by Client or third-party changes, unsupported use, inaccurate Client Materials, a Third-Party Service, misuse, failure to follow instructions or matters outside the agreed scope.

19.5 Except as expressly stated and to the fullest extent permitted by law, all other warranties, conditions and terms are excluded, including implied terms as to satisfactory quality, fitness for a purpose not expressly agreed, uninterrupted availability and error-free operation. Nothing excludes the statutory duty to exercise reasonable care and skill where it cannot lawfully be excluded.

20. Intellectual property claims

20.1 NexusReef will defend the Client against a third-party claim that a bespoke Deliverable created solely by NexusReef and used as permitted infringes UK copyright, database right or registered trade mark, and will pay damages finally awarded or settlement amounts approved by NexusReef, subject to this clause and clause 21.

20.2 NexusReef has no responsibility for a claim arising from Client Materials, Client instructions, open-source or Third-Party Services, use outside the Agreement, combination with items not supplied by NexusReef, modification by another person or continued use after NexusReef offers a non-infringing alternative.

20.3 If a covered claim is likely, NexusReef may procure continued use, modify or replace the affected item, or terminate the affected part and refund prepaid Fees for the unused period. This clause states the Client's exclusive contractual remedy for covered infringement claims.

20.4 A party seeking an indemnity must promptly notify the indemnifying party, not admit liability without consent, give reasonable control of defence and settlement, and provide reasonable cooperation at the indemnifying party's cost. No settlement may impose an admission, non-monetary obligation or material reputational harm on the protected party without consent.

21. Liability

21.1 Nothing in the Agreement limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot lawfully be limited or excluded.

21.2 Subject to clause 21.1, neither party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business opportunity, contract or goodwill, whether direct or indirect, except that this exclusion does not prevent recovery of Fees properly payable to NexusReef.

21.3 Subject to clause 21.1, NexusReef is not liable for loss or corruption of data to the extent the loss could have been avoided by backups allocated to the Client, or for Third-Party Service failure, Client delay, Client Materials, unauthorised changes or use outside the Agreement.

21.4 Subject to clause 21.1, NexusReef's total aggregate liability arising from or in connection with a SOW in any rolling 12-month period, whether in contract, tort including negligence, misrepresentation, restitution or otherwise, will not exceed the total Fees paid or payable under that SOW during the 12 months immediately preceding the event giving rise to the first claim. If the event occurs during the first 12 months, the cap is the Fees paid or payable for that first 12-month period.

21.5 The cap in clause 21.4 also applies to NexusReef's obligations under clauses 20 and Schedule 1 unless the SOW expressly states a separate cap. The parties acknowledge that Fees and insurance are set in reliance on these limits.

21.6 Each party will take reasonable steps to mitigate loss. A party is not liable for a delay or failure caused by the other party's breach to the extent of that causation.

21.7 Nothing in this clause limits the Client's obligation to pay Fees, third-party costs or taxes properly due.

INSURANCE ALIGNMENT

This liability model is commercially important and fact-sensitive. Before use, confirm the cap and any separate data protection or IP cap against actual professional indemnity, cyber and public liability cover and the typical risk profile of NexusReef projects.

22. Suspension

22.1 NexusReef may suspend all or part of the Services where reasonably necessary because of: overdue undisputed payment; material breach; unlawful or abusive use; a security threat; risk to infrastructure or other customers; a regulator or court requirement; or suspension of a necessary Third-Party Service.

22.2 Except in an emergency or where prohibited, NexusReef will give reasonable notice and an opportunity to remedy. NexusReef will limit suspension to what is reasonably necessary and restore the Services after the cause is resolved.

22.3 The Client remains liable for recurring Fees during suspension where the cause is attributable to the Client. Suspension does not prevent termination or other remedies.

23. Term and termination

23.1 Each SOW starts on the date stated and continues for its agreed term or until completion. A recurring SOW renews only as stated in that SOW.

23.2 Either party may terminate an Agreement or affected SOW by written notice if the other party materially breaches it and, where the breach can be remedied, fails to remedy it within 14 days after written notice describing the breach.

23.3 A party may terminate immediately to the extent permitted by applicable insolvency law if the other party enters liquidation, administration or a comparable insolvency process, ceases business, or is unable to pay debts as they fall due, except for a solvent restructuring.

23.4 The Client may terminate a project for convenience on 30 days' written notice unless the SOW states otherwise. The Client must pay for work performed to the termination date, accepted or substantially completed milestones, reasonable handover work, and non-cancellable third-party or resource commitments. Any further cancellation charge applies only if expressly stated in the SOW.

23.5 NexusReef may terminate a recurring Service for convenience on at least 90 days' notice, or at the end of the current minimum term if later. This does not affect any agreed transition assistance.

23.6 Termination does not affect accrued rights, payment obligations or provisions intended to survive, including confidentiality, intellectual property, data protection, liability, dispute resolution and payment.

24. Exit assistance and data return

24.1 On termination, NexusReef will provide the Client with Deliverables, Client Materials and Client Data that the Client is entitled to receive and that are held in an exportable form, subject to full payment and the SOW.

24.2 Standard export, retention and deletion periods must be stated in the SOW. If none are stated, NexusReef may delete Client Data from active systems 30 days after termination and from routine backups in the ordinary backup cycle, normally within 90 days, except where law requires retention.

24.3 Migration, knowledge transfer, repository restructuring, documentation beyond the agreed Deliverables, data transformation, supplier coordination and other exit assistance are chargeable at then-current rates unless included in the SOW.

24.4 NexusReef may retain one secure archival copy of information where required for legal, tax, insurance or dispute purposes, subject to continued confidentiality and restricted access.

25. Force majeure

25.1 Neither party is liable for delay or failure caused by an event beyond its reasonable control, including natural disaster, fire, flood, epidemic, war, terrorism, civil disorder, labour dispute not limited to its own workforce, government action, utility or internet failure, cyberattack by a third party despite reasonable security, or major failure of a Third-Party Service.

25.2 The affected party will notify the other, use reasonable efforts to mitigate and resume performance. Payment obligations for Services already supplied are not excused.

25.3 If the event materially prevents an affected Service for more than 60 consecutive days, either party may terminate that affected Service on written notice without liability for future Fees, but accrued Fees and non-cancellable commitments remain payable.

26. Compliance and acceptable conduct

26.1 Each party will comply with laws applicable to its performance, including anti-bribery, sanctions, export control, employment, intellectual property, data protection and AI regulation.

26.2 The Client must not use the Services to infringe rights, distribute malware, gain unauthorised access, harass or exploit persons, facilitate fraud, unlawfully discriminate, process illegal content or materially interfere with systems or other users.

26.3 The Client is responsible for sector-specific compliance and regulatory approvals relating to its business, content, users and deployment. NexusReef will provide reasonable technical cooperation where agreed as chargeable Services.

26.4 Where a new law or regulatory interpretation materially changes the Services or cost of compliance, the parties will use change control. If no reasonable agreement is reached, either party may terminate the materially affected part on 30 days' notice.

27. Publicity and portfolio use

27.1 After a project is publicly launched, NexusReef may identify the Client by name and logo and display public-facing Deliverables in its portfolio and credentials, unless the Client opts out in writing before launch or the SOW states otherwise.

27.2 NexusReef will not disclose Confidential Information, private metrics, unreleased functionality or security-sensitive details in publicity without written approval.

27.3 A press release, testimonial or detailed case study requires prior approval of the other party, not to be unreasonably withheld or delayed.

28. Notices

28.1 Formal notices under the Agreement must be in writing and sent by email to the contract contact stated in the SOW, with a copy to info@nexusreef.com for notices to NexusReef, or by prepaid tracked post to the registered or principal office.

28.2 An email notice is deemed received at 09:00 on the next Business Day after transmission unless the sender receives a delivery failure. A posted notice is deemed received two Business Days after posting within the United Kingdom and five Business Days after international posting.

28.3 Routine project communications, support tickets and invoices are not formal termination or legal notices unless they clearly state that purpose and comply with this clause.

29. Assignment and subcontracting

29.1 The Client may not assign, transfer, charge or subcontract the Agreement without NexusReef's prior written consent, not to be unreasonably withheld for a bona fide group reorganisation or sale of substantially all relevant business assets, provided the assignee is financially and operationally capable.

29.2 NexusReef may assign the Agreement to an Affiliate or as part of a bona fide sale, merger, restructuring or transfer of its business or relevant assets, on written notice, provided this does not materially reduce the Client's contractual rights.

29.3 NexusReef may subcontract performance, subject to clause 4.4 and Schedule 1 where personal data is involved.

30. General

30.1 The Agreement constitutes the entire agreement concerning its subject matter and supersedes prior proposals, discussions and representations. Each party acknowledges it has not relied on a statement not set out in the Agreement, without limiting liability for fraud.

30.2 A variation is effective only if in writing and agreed by authorised representatives, except for non-material operational updates permitted by the Agreement.

30.3 Failure or delay in exercising a right is not a waiver. A waiver applies only to the specific circumstance stated in writing.

30.4 If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary to make it valid while preserving commercial intent, and the remaining provisions continue.

30.5 Nothing creates a partnership, joint venture, fiduciary relationship, employment relationship or agency. Neither party may bind the other except as expressly agreed.

30.6 No person other than the parties has a right to enforce the Agreement under the Contracts (Rights of Third Parties) Act 1999, except an assignee permitted under clause 29.

30.7 The Agreement may be executed in counterparts and by electronic signature, each of which is treated as an original and together form one instrument.

31. Dispute resolution, governing law and jurisdiction

31.1 A party raising a dispute will first give written details to the other party's project lead. If unresolved within 10 Business Days, the dispute will be escalated to a director of each party for good-faith negotiation.

31.2 Before starting court proceedings, the parties will consider mediation through an independent mediator. This does not prevent urgent injunctive relief, debt recovery or action required to preserve a limitation period.

31.3 The Agreement and any non-contractual obligations arising from it are governed by the law of England and Wales.

31.4 The courts of England and Wales have exclusive jurisdiction, except that NexusReef may bring proceedings for unpaid Fees or protection of Intellectual Property Rights or Confidential Information in any court of competent jurisdiction.

Schedule 1 - Data Processing Schedule

WHEN THIS SCHEDULE APPLIES

This Schedule applies only where NexusReef acts as processor of personal data for the Client. It is not a substitute for the Client's own privacy notice, records of processing, lawful basis, DPIA or controller obligations. Complete Annex 1 in each relevant SOW before production processing.

S1.1 Roles and scope

S1.1.1 The Client is the controller and NexusReef is the processor for the processing described in Annex 1, unless that Annex identifies a different lawful role. Each party may also be an independent controller for its own business administration, security, legal compliance and relationship records.

S1.1.2 This Schedule is intended to meet Article 28 UK GDPR and, where applicable, Article 28 EU GDPR requirements. If mandatory law requires additional terms, the parties will cooperate to implement them.

S1.1.3 The subject matter, duration, nature, purpose, data types and data subjects are set out in Annex 1 and the SOW. If incomplete, NexusReef may refuse or suspend production processing until completed.

S1.2 Documented instructions

S1.2.1 NexusReef will process personal data only on the Client's documented instructions, including the Agreement, SOW, support requests and configuration choices, unless law requires otherwise. Where legally permitted, NexusReef will notify the Client of that requirement before processing.

S1.2.2 If NexusReef reasonably believes an instruction infringes Applicable Data Protection Law, it will notify the Client and may suspend that instruction pending clarification or lawful amendment.

S1.2.3 The Client is responsible for the lawfulness, fairness, transparency, accuracy and minimisation of the personal data and instructions, and for providing required notices and obtaining any required consent.

S1.3 Confidentiality and personnel

S1.3.1 NexusReef will ensure persons authorised to process personal data are subject to confidentiality obligations and receive appropriate data protection and security awareness relevant to their role.

S1.3.2 Access will be limited to persons who require it for the Services, support, security, legal compliance or incident response.

S1.4 Security

S1.4.1 NexusReef will implement appropriate technical and organisational measures taking account of the state of the art, implementation cost, nature and risk of processing. The baseline measures are described in Annex 2 and may be supplemented by the SOW.

S1.4.2 The Client acknowledges that security is shared. Client-controlled identity, endpoints, networks, permissions, configurations and user behaviour remain the Client's responsibility unless expressly included in the Services.

S1.5 Subprocessors

S1.5.1 The Client gives general written authorisation for NexusReef to appoint subprocessors necessary for the Services. NexusReef will maintain a current list in the SOW, service documentation or another written record available to the Client.

S1.5.2 NexusReef will give at least 15 days' prior notice of a material new subprocessor where reasonably practicable. The Client may object on reasonable, documented data protection grounds within that period.

S1.5.3 The parties will work in good faith to address a valid objection. If no reasonable alternative is available without material cost or service impact, the Client may terminate the affected processing Service before the new subprocessor begins, paying accrued Fees and non-cancellable costs.

S1.5.4 NexusReef will impose written data protection obligations on subprocessors that are no less protective in substance than the relevant obligations in this Schedule and remains responsible for their performance to the extent required by law.

S1.6 International transfers

S1.6.1 NexusReef will not make a restricted international transfer of personal data unless a lawful transfer mechanism and any required assessment and supplementary measures are in place.

S1.6.2 Transfers from the EEA to the United Kingdom may rely on an applicable adequacy decision while valid. Other transfers may rely on adequacy regulations, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum, an approved certification or another lawful mechanism.

S1.6.3 The modules, parties and selections for any Standard Contractual Clauses or Addendum will follow the factual roles and processing described in Annex 1 and Annex 3. The parties authorise completion of administrative details needed to give effect to the chosen mechanism.

S1.7 Data subject requests and regulatory assistance

S1.7.1 Taking account of the nature of processing, NexusReef will provide reasonable technical and organisational assistance for the Client to respond to data subject requests. NexusReef will not respond directly except on Client instruction or where required by law.

S1.7.2 NexusReef will provide reasonable information and assistance relating to security, breach notification, DPIAs, prior consultation and regulator enquiries to the extent relevant to the Services. Assistance beyond standard functionality may be chargeable unless required because of NexusReef's breach.

S1.8 Personal data breaches

S1.8.1 NexusReef will notify the Client without undue delay after becoming aware of a personal data breach affecting Client personal data and will provide information reasonably available about the nature, likely consequences and mitigation.

S1.8.2 Notification is not an admission of fault or liability. The Client is responsible for deciding whether and how to notify individuals or regulators, unless law assigns that responsibility to NexusReef.

S1.8.3 The parties will coordinate external statements. Neither party will name the other in a notification or public statement unless required by law or reasonably necessary after consultation.

S1.9 Audit and information

S1.9.1 NexusReef will make available information reasonably necessary to demonstrate compliance with this Schedule, which may include policies, summaries, certifications, questionnaire responses and independent reports.

S1.9.2 Where that information is insufficient, the Client may conduct one audit per 12 months on at least 30 days' notice during normal business hours, subject to confidentiality, security, non-disruption and scope limitations. The Client bears its costs and NexusReef's reasonable assistance costs unless the audit identifies a material breach by NexusReef.

S1.9.3 Additional audits may be conducted following a material breach, regulator requirement or substantiated security concern. Audits must not expose another customer's data, source code, vulnerability details or privileged information.

S1.10 Return and deletion

S1.10.1 At the end of processing, NexusReef will, at the Client's choice and subject to the Agreement, return or delete Client personal data unless law requires retention.

S1.10.2 If no choice or period is specified, active copies may be deleted 30 days after termination and routine backup copies will expire through the normal backup cycle, normally within 90 days. During that period, data remains protected and is not restored except for recovery or legal need.

S1.11 Liability and precedence

S1.11.1 Liability under this Schedule is subject to clause 21 unless the SOW expressly states a separate cap. Nothing limits rights or obligations that cannot lawfully be limited.

S1.11.2 If this Schedule conflicts with the main Terms on personal data processing, this Schedule prevails. A valid mandatory transfer mechanism prevails for the restricted transfer it governs.

Annex 1 - Processing details

FieldDefault / to be completed in the SOW
Subject matterProvision, configuration, hosting, maintenance, support, migration or development of the Services described in the SOW.
DurationFor the SOW term plus the agreed return/deletion period.
Nature of processingCollection, access, recording, organisation, storage, retrieval, consultation, transmission, testing, troubleshooting, backup, deletion and other operations necessary for the Services.
PurposeTo deliver, secure, maintain and support the Services on the Client's documented instructions.
Data subjectsClient personnel and authorised users; the Client's customers, users, suppliers or contacts; and any other groups expressly listed in the SOW.
Personal data typesIdentity and contact data; account and authentication data; business records; service content; technical, device, usage and log data; support communications; and other types expressly listed in the SOW.
Special category / criminal dataNone unless expressly listed, justified and protected in the SOW.
Children's dataNone unless expressly listed and subject to a specific child-safety, age-assurance and privacy design assessment.
Frequency and volumeAs generated or supplied through the Services; estimated volume and peak usage to be stated where relevant to risk or capacity.
Data locationUnited Kingdom, EEA and approved subprocessor locations specified in the SOW or subprocessor record.
Return/deletionExport as stated in the SOW; active deletion after 30 days and backup expiry normally within 90 days if no other period is specified.

Annex 2 - Baseline technical and organisational measures

  • Governance and confidentiality: defined access responsibilities, confidentiality obligations and security awareness for authorised personnel.
  • Identity and access: least-privilege access, unique accounts, appropriate authentication controls and multi-factor authentication for privileged or administrative access where supported.
  • Encryption: encryption in transit using current secure protocols and encryption at rest where supported and proportionate to risk.
  • Environment separation: reasonable separation of development, test and production environments and segregation between customers where applicable.
  • Secure development: source control, peer or automated review appropriate to risk, dependency management, secrets management and testing before release.
  • Vulnerability and patch management: proportionate scanning, monitoring and remediation of relevant vulnerabilities and security updates.
  • Logging and monitoring: proportionate audit logs, operational monitoring and alerting for security-relevant events, subject to agreed retention.
  • Backups and resilience: backups, restoration tests and recovery arrangements only to the level stated in the SOW or hosting schedule.
  • Incident response: documented escalation, containment, investigation, evidence preservation and communication procedures.
  • Supplier management: due diligence, written contracts and review of subprocessors proportionate to processing risk.
  • Data minimisation and deletion: processing limited to documented purpose, controlled non-production data use and secure deletion or anonymisation when no longer needed.
  • Business continuity: reasonable continuity and recovery arrangements appropriate to the Services and agreed service levels.

Annex 3 - Transfer mechanism hierarchy

  • First: an applicable UK or EU adequacy decision or regulation.
  • Second: approved contractual safeguards, including the EU Standard Contractual Clauses for EU GDPR transfers and the UK IDTA or UK Addendum for UK GDPR transfers, with any required transfer assessment and supplementary measures.
  • Third: another lawful derogation or mechanism only where its legal conditions are met and use is documented.
  • The SOW or subprocessor record should identify relevant countries, suppliers and mechanisms. A supplier's participation in a recognised data bridge or framework may be used only while valid and applicable to the data and recipient.

Schedule 2 - Statement of Work checklist

Every material engagement should use a SOW that records the points below. Omitting an item means the default position in these Terms applies; it does not create an unstated obligation.

TopicWhat the SOW should state
Parties and contactsLegal names, company numbers, addresses, authorised commercial and project contacts.
ScopeServices, Deliverables, environments, territories, users, exclusions and assumptions.
Delivery modelFixed scope, time and materials, retainer, agile capacity or mixed model.
MilestonesTarget or fixed dates, dependencies, review windows and deployment responsibilities.
FeesCurrency, VAT, deposit, milestone invoices, recurring charges, rates, expenses and third-party costs.
AcceptanceAcceptance criteria, test data, test environment, review period and responsible approver.
Change controlAuthorised approvers and any expedited process.
Third partiesCloud, APIs, models, app stores, licences, account ownership, pass-through terms and cost allocation.
AIIntended purpose, role allocation, users, territories, data, human oversight, transparency, prohibited uses and monitoring.
Intellectual propertyBespoke Deliverables, Background Technology, source-code/repository handover, third-party/open-source items and any licence-only components.
Hosting / supportUptime, support hours, severity levels, response targets, maintenance, backups, RPO/RTO, retention and service credits.
Data protectionRoles, Annex 1 processing details, subprocessors, locations, transfer mechanism, special data, children and security measures.
SecurityRequired standards, access model, penetration testing, incident contacts and Client responsibilities.
ExitNotice, export format, handover, migration assistance, deletion timing and charges.
RiskAny project-specific warranties, indemnities, insurance requirements or alternative liability cap.
Related documentPrivacy and Cookie Notice
NexusReef

We build and operate digital ecosystems.

ยฉ 2026 NexusReef
LegalPrivacy & cookiesTerms
Designed to evolve.