Terms of Use
Provider: ExcelTTC Limited · Company number: NI740696
Registered office: 24 Phoenix Fields, Ballymena, BT42 2BF, United Kingdom
Effective date: 18 July 2026 · Website: workcura.com
Effective date: 18 July 2026
These Terms of Use (“Terms”) govern access to and use of the WorkCura website, web application and related services (together, the “Service”). The Service is provided by ExcelTTC Limited; a company registered in England, Wales and Northern Ireland under company number NI740696, whose registered office is at 24 Phoenix Fields, Ballymena, BT42 2BF, United Kingdom. (“ExcelTTC”, “WorkCura”, “we”, “us” or “our”).
By creating an account, accepting an invitation, selecting a subscription, clicking to accept these Terms or using the Service, you agree to these Terms. If you use the Service for an organisation, you confirm that you have authority to bind that organisation. If you do not agree, do not use the Service.
1. Scope and contract structure
1.1 These Terms apply to each organisation that buys or uses the Service (a “Customer”) and each person authorised to access it (an “Authorised User”). Customers may include healthcare staffing agencies and care or healthcare facilities. Authorised Users may include Customer administrators, agency staff, facility staff and healthcare workers.
1.2 An order form, online checkout, plan description, written quotation or other document that we accept and that identifies a subscription (an “Order”) forms part of the agreement. These Terms, the Order, the Privacy Notice, the Cookie Notice and any data processing terms expressly incorporated into the Order together form the “Agreement”.
1.3 If documents conflict, the following order applies unless an Order expressly says otherwise: the Order; any signed data processing addendum for data-protection matters; these Terms; then plan descriptions and other online materials.
1.4 The Service is intended primarily for business use. It is not intended for consumers acting wholly or mainly outside their trade, business, craft or profession.
2. About WorkCura and important limitations
2.1 WorkCura provides software for creating, offering, assigning, managing and recording agency healthcare-worker shifts and related operational information. Available functions may include worker records, compliance-document tracking, availability, shift scheduling, notifications, messaging, timesheets, electronic acknowledgements, reports, invoicing support and subscription management.
2.2 Unless an Order expressly states otherwise, ExcelTTC is a software provider only. We are not an employment business, employment agency, employer, payroll provider, recruitment consultant, care provider, healthcare provider or professional regulator. We do not employ, engage, supply, supervise or clinically direct healthcare workers through the Service.
2.3 The Service does not itself verify a person’s identity, right to work, qualifications, professional registration, training, criminal-record status, references, health, fitness, competence or suitability. A status, expiry date, upload or indicator in the Service is an administrative record, not a warranty or professional judgment by ExcelTTC.
2.4 We do not guarantee that shifts will be offered, accepted, completed or paid; that a worker will attend; that a facility will be suitable; or that any user-provided information is accurate. The relevant agency and facility remain responsible for their relationship, agreements and decisions.
3. Eligibility and authority
3.1 An individual may use the Service only if they are at least 18 years old, have legal capacity to enter into these Terms, and are authorised by the relevant Customer.
3.2 A person registering or administering a Customer account confirms that the Customer is lawfully established, all registration details are complete and accurate, and they have authority to administer users, data, subscriptions and settings for that Customer.
3.3 We may request information reasonably required to verify identity, authority, organisation details or lawful use. We may reject or delay registration where information is incomplete, inconsistent or reasonably raises security, fraud, sanctions or legal-compliance concerns.
4. Accounts and security
4.1 Each Authorised User must use their own account and must not share login credentials. Customers must promptly add, update, restrict or remove access when a person’s role changes or ends.
4.2 Users must use strong credentials, protect authentication methods, keep contact details current and notify us promptly at support@workcura.com of suspected unauthorised access, credential loss, data compromise or misuse.
4.3 The Customer is responsible for activity through its accounts unless caused by our breach of the Agreement. We may require password resets, additional verification or other proportionate security steps.
4.4 We may rely on instructions given through an authenticated account. Customer administrators control roles and permissions and are responsible for assigning the minimum access reasonably needed.
5. Customer responsibilities
5.1 Each Customer must:
use the Service lawfully, fairly and only for legitimate workforce and shift-management purposes;
provide accurate, current and complete information and correct errors promptly;
obtain all notices, consents, permissions and lawful bases needed to submit and use Customer Data;
maintain appropriate internal policies, supervision, continuity arrangements and records independent of the Service;
ensure Authorised Users understand and comply with the Agreement;
comply with employment, agency-worker, immigration, equality, health and safety, safeguarding, tax, pension, working-time, professional, care-sector and data-protection requirements that apply to it; and
cooperate reasonably with security, support and incident investigations.
5.2 Customers must not treat the Service as the sole record where law, regulation, professional practice or safe operations require an independent record, check, backup or human decision.
6. Agency responsibilities
6.1 An agency Customer is solely responsible for recruiting, engaging, vetting, supplying, paying and managing its workers, and for determining their employment or tax status.
6.2 Before offering or assigning a worker, the agency must complete and keep current every check required by law, contract and good professional practice, including as applicable: identity and right-to-work checks; qualifications and professional registration; references and employment history; Disclosure and Barring Service or equivalent checks; mandatory and role-specific training; occupational-health and fitness checks; vaccination or immunisation evidence where lawful and required; safeguarding checks; competency and experience; and appropriate insurance.
6.3 The agency must monitor expiries, restrictions and conditions, take prompt action when status changes, and never knowingly offer or assign an unsuitable or non-compliant worker. WorkCura reminders and dashboard indicators are supplementary aids only.
6.4 The agency is responsible for worker pay, holiday pay, tax, National Insurance, pension duties, expenses, working-time limits, rest, disciplinary matters and all other obligations arising from its relationship with a worker.
7. Facility responsibilities
7.1 A facility Customer must ensure each shift request is accurate and includes the location, times, role, required skills, rate or commercial information where applicable, reporting instructions, known risks and any lawful prerequisites.
7.2 The facility remains responsible for a safe working environment, induction, local policies, equipment, infection control, safeguarding procedures, clinical governance, appropriate supervision and escalation arrangements.
7.3 The facility must promptly report cancellations, changes, attendance issues, accidents, incidents, safeguarding concerns and performance concerns to the relevant agency and through any required external channel. Use of WorkCura does not replace statutory or contractual reporting.
7.4 A facility user who approves a timesheet or other record confirms that they are authorised to do so and that the record is accurate to the best of their knowledge.
8. Healthcare-worker responsibilities
8.1 A healthcare worker must keep profile, availability, contact, qualification and compliance information accurate and promptly tell the agency of any restriction, investigation, health or fitness issue, lapse, suspension or other circumstance relevant to safe and lawful work.
8.2 Accepting a shift is a commitment to attend on time, perform only work within the worker’s competence and authority, comply with facility and agency policies, maintain professional standards, record time honestly, and raise safety or safeguarding issues through the correct channels.
8.3 A worker must not use WorkCura as a substitute for clinical records, care plans, medication records, incident reporting systems or emergency communications.
9. Shifts, notifications and operational records
9.1 The Service may enable Customers to create shifts individually or by bulk upload, invite or assign workers, change or cancel shifts, record attendance and export reports. The Customer is responsible for reviewing bulk-uploaded data and resolving validation errors before relying on it.
9.2 A shift shown in the Service does not itself create an employment contract or guarantee work. The agency, facility and worker remain responsible for confirming the applicable engagement terms, rates, cancellation terms and instructions.
9.3 Email, SMS, in-app or push notifications may be delayed, blocked, misdirected or unavailable. Users must check the Service and maintain suitable alternative communications for urgent or safety-critical matters.
9.4 Statuses, audit trails, timesheets, electronic acknowledgements and signatures are operational evidence. They may be challenged or corrected where inaccurate and do not remove any legal requirement for other evidence, authorisation or records.
9.5 No user may falsify attendance, signatures, approvals, compliance documents, shift data or other records. Customers must investigate discrepancies promptly and preserve relevant evidence.
10. Acceptable use
10.1 No person may:
break any law, regulation, professional duty, court order or third-party right;
upload malicious code, probe or circumvent security, scan without permission, interfere with availability, or attempt unauthorised access;
share accounts, impersonate another person, misrepresent authority, or falsify records;
scrape, harvest, reverse engineer, decompile, copy or create derivative works from the Service except where applicable law cannot exclude that right;
use automated means that impose an unreasonable load or bypass usage limits;
upload unlawful, discriminatory, defamatory, abusive, threatening, obscene or infringing material;
use the Service to discriminate unlawfully, exploit workers, facilitate fraud, or make solely automated decisions that unlawfully produce legal or similarly significant effects;
upload patient, resident or service-user clinical information unless we have expressly enabled and agreed that use in writing; or
sell, sublicense, rent, time-share or provide the Service to an unauthorised third party.
10.2 We may investigate suspected misuse, preserve relevant information and cooperate with lawful requests. We will act proportionately and in accordance with applicable law.
11. Subscriptions, Trial, fees and payment
11.1 Available plans, features, add-ons, limits, billing periods and prices are described at checkout or in an Order. Prices exclude VAT and other applicable taxes unless stated otherwise.
11.2 Trial. An eligible newly registering agency may select a free Trial for 30 days. The Trial provides the package features and enabled add-on(s) stated at registration. It starts when activated, is available once per agency and related organisation, cannot be renewed, extended, paused, transferred or combined with another Trial, and may be refused where we reasonably identify duplicate, abusive or fraudulent registrations.
11.3 We may send reminders before Trial expiry, but failure to receive a reminder does not extend the Trial. To continue using the Service, the agency must select and successfully activate a paid Starter, Pro or other then-available plan before expiry.
11.4 At Trial expiry, if no paid plan is active, operational access will be disabled and users may be redirected after authentication to the package-selection page. We may retain limited access needed to choose a plan, manage billing, export available data or meet legal obligations. Reactivation requires an eligible paid plan; a further Trial is not available.
11.5 Paid subscriptions start on the date shown at checkout and renew automatically for successive billing periods unless cancelled before renewal, unless the Order says otherwise. Cancellation takes effect at the end of the current paid period; fees already paid are non-refundable except where the Order expressly provides a refund, we agree otherwise in writing, or applicable law requires it.
11.6 If a seven-day refund option is expressly displayed at checkout for a plan, the Customer may request it within seven days of the initial paid purchase. Approved refunds will be processed to the original payment method, ordinarily within 14 days, subject to payment-provider processing times. Renewals, add-ons and usage already materially consumed may be excluded if the checkout terms say so, to the extent lawful.
11.7 Payments may be processed by Stripe or another disclosed provider under its own terms and privacy information. We do not store full payment-card details. The Customer authorises recurring charges and must keep billing information current.
11.8 If payment is overdue, reversed or fails, we may retry collection, restrict paid features or suspend access after reasonable notice. The Customer remains liable for amounts due and reasonable recovery costs, subject to applicable law.
11.9 We may change prices for a future renewal period by giving reasonable advance notice. Continued use after the change takes effect constitutes acceptance; the Customer may cancel before renewal.
12. Customer Data and data protection
12.1 “Customer Data” means information, documents and other content submitted to or generated within the Service on a Customer’s behalf, excluding our software, service analytics and data irreversibly anonymised so that no person is identifiable.
12.2 As between the parties, the Customer retains its rights in Customer Data. The Customer grants us a non-exclusive, worldwide, royalty-free licence for the duration of the Agreement to host, copy, transmit, display, adapt and otherwise process Customer Data only as needed to provide, secure, support and improve the Service, comply with law and enforce the Agreement.
12.3 Each party will comply with applicable data-protection law, including the UK GDPR and Data Protection Act 2018. Our Privacy Notice explains how we act as an independent controller for matters such as account administration, billing, service security, support and our own legal obligations.
12.4 Where we process personal data on a Customer’s behalf, the Data Processing Schedule in Schedule 1 applies. Each Customer is responsible for deciding what personal data to submit, giving required privacy information, identifying a lawful basis and additional condition where needed, and handling data-subject requests unless the Schedule allocates assistance to us.
12.5 Criminal-offence information, health information, professional restrictions and similar records require heightened care. Customers must collect and disclose them only where lawful, necessary, proportionate, access-controlled and covered by suitable retention rules.
12.6 Patient or service-user clinical data must not be entered into free-text fields, messages, shift descriptions or uploads unless we expressly agree in writing that the relevant feature is designed and contracted for that purpose.
13. Confidentiality
13.1 Each party must keep the other’s non-public business, technical, security, pricing and personal information confidential and use it only to perform or exercise rights under the Agreement.
13.2 A receiving party may disclose confidential information to personnel and professional advisers who need it and are bound by confidentiality, or where required by law. Where lawful, it will give advance notice and reasonable assistance.
13.3 Confidentiality does not apply to information that is public without breach, already lawfully known, independently developed without use of the information, or lawfully received without restriction.
14. Intellectual property
14.1 We and our licensors own all intellectual-property rights in the Service, its software, design, documentation, branding, templates and improvements. No ownership transfers to the Customer or any user.
14.2 Subject to the Agreement and payment of applicable fees, we grant the Customer a limited, non-exclusive, non-transferable and revocable right during the subscription to permit its Authorised Users to access and use the Service for its internal business operations.
14.3 If a user provides feedback or suggestions, we may use them without restriction or payment, provided we do not identify the Customer publicly without permission.
14.4 “WorkCura”, our logos and related branding may not be used without prior written permission, except for accurate factual reference to the Service.
15. Third-party services and links
15.1 The Service may interoperate with third-party services, including payment, email, messaging, storage or analytics providers. Third-party services are governed by their own terms and may change or become unavailable.
15.2 We are not responsible for a third-party service, data it processes under the Customer’s direct relationship with it, or loss caused solely by that service. We remain responsible for our own obligations, including obligations concerning subprocessors under Schedule 1.
15.3 Links to third-party websites are provided for convenience and do not imply endorsement.
16. Availability, changes and support
16.1 We aim to provide a reliable Service but do not promise uninterrupted or error-free availability unless an Order includes a service-level commitment. Maintenance, security events, internet failures, third-party failures and events outside reasonable control may affect access.
16.2 We may update, modify or discontinue features to improve security, comply with law, address technical needs or develop the Service. We will give reasonable notice of a material reduction in core paid functionality where practicable.
16.3 Support is provided through support@workcura.com during the hours stated on our website or Order. Support does not include professional, legal, clinical, employment, tax or regulatory advice.
16.4 Customers must maintain appropriate continuity plans, including alternative contact methods and exports or backups of records they must retain independently.
17. Suspension
17.1 We may suspend all or part of access where reasonably necessary to address a security risk, suspected unlawful use, material breach, harm to another user, overdue payment, Trial expiry, a legal requirement or a threat to the Service.
17.2 Where appropriate and lawful, we will give notice and an opportunity to remedy. We may act immediately where delay would create material risk. We will restore access when the reason is resolved, subject to the Agreement.
17.3 Suspension does not remove payment or other obligations that accrued before suspension.
18. Term, cancellation and termination
18.1 The Agreement begins when the Customer accepts these Terms or first uses the Service and continues until all subscriptions and authorised access end.
18.2 Either party may terminate for material breach if the breach is not remedied within 14 days after written notice, or immediately if the breach cannot be remedied. Either party may terminate immediately if the other becomes insolvent or ceases business, subject to applicable insolvency law.
18.3 We may terminate immediately for serious or repeated security abuse, fraud, unlawful conduct or conduct likely to cause material harm, or where continuing the Service would breach law.
18.4 On termination or expiry, access ends and outstanding fees become due. The Customer must stop using the Service. Clauses intended by their nature to survive will survive, including payment, confidentiality, intellectual property, data protection, disclaimers, liability and general provisions.
18.5 During the subscription and for 30 days after termination, the Customer may request an export of Customer Data in an available standard format, unless law, security, account status or technical limitations prevent it. We may charge reasonable costs for a bespoke export. After the applicable period, we may delete or anonymise Customer Data in line with Schedule 1 and our retention obligations. Customers should export required records before access ends.
19. Warranties and disclaimers
19.1 Each party warrants that it has authority to enter into the Agreement. We warrant that we will provide the Service with reasonable skill and care.
19.2 Except as expressly stated and to the fullest extent permitted by law, the Service is provided “as is” and “as available”. We do not warrant that it will meet every requirement, be uninterrupted or error-free, prevent every cyber incident, or ensure compliance with laws applying to the Customer.
19.3 The Customer is responsible for decisions made using the Service and for professional, clinical, employment, safeguarding and regulatory judgment. Information in the Service is not legal, medical, clinical, tax, employment or other professional advice.
20. Liability
20.1 Nothing in the Agreement excludes or limits liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; breach of terms implied by law that cannot be excluded; or any other liability that cannot lawfully be excluded or limited.
20.2 Subject to clause 20.1, neither party is liable for loss of profit, revenue, business, contracts, anticipated savings, goodwill or reputation; loss or corruption of data where the loss could reasonably have been avoided by appropriate backup; or indirect or consequential loss.
20.3 Subject to clauses 20.1 and 20.4, each party’s total aggregate liability arising out of or relating to the Agreement in any 12-month period will not exceed the fees paid or payable by the Customer for the Service in that period. For a claim arising solely during a free Trial where no fees are paid, the cap is £100.
20.4 The cap in clause 20.3 does not apply to the Customer’s obligation to pay fees; either party’s breach of confidentiality; infringement or misuse of the other party’s intellectual-property rights; or liability arising from a party’s deliberate unlawful act. For liability under the Data Processing Schedule, the cap is two times the amount in clause 20.3, except where law does not permit limitation.
20.5 The limitations apply to all causes of action in aggregate, including contract, tort (including negligence), breach of statutory duty, misrepresentation and restitution, and reflect the allocation of risk and pricing of the Service.
21. Indemnity
21.1 The Customer will indemnify ExcelTTC against third-party claims, losses and reasonable costs arising directly from Customer Data or the Customer’s unlawful use of the Service, breach of clauses 5 to 10, or infringement of a third party’s rights, except to the extent caused by our breach or negligence.
21.2 We will promptly notify the Customer of an indemnified claim, allow reasonable control of the defence and settlement, and provide reasonable cooperation at the Customer’s cost. The Customer must not settle in a way that admits fault by or imposes non-monetary obligations on ExcelTTC without our consent, not to be unreasonably withheld.
22. Changes to these Terms
22.1 We may change these Terms to reflect changes in law, regulation, security, technology, functionality or business practice. We will post the updated Terms and update the effective date.
22.2 For a material change affecting an existing paid subscription, we will give reasonable advance notice by email, in-app message or another appropriate method. If the Customer does not agree, it may stop using the Service and cancel before the change takes effect. Continued use after that date constitutes acceptance.
22.3 Changes required urgently for law or security may take effect sooner. They will not apply retroactively unless required by law.
23. Notices
23.1 Operational notices may be sent in-app or to the account email. Legal notices to us must be sent to contactus@workcura.com and by prepaid post to our registered office, marked for the attention of the Legal Department.
23.2 We may send legal notices to the Customer’s registered email or postal address. Email notices are deemed received on the next business day after sending unless a delivery failure is received. Postal notices are deemed received two business days after posting within the UK.
24. General
24.1 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, except that this does not excuse payment obligations already due. The affected party must take reasonable steps to reduce the impact.
24.2 Assignment. The Customer may not assign or transfer the Agreement without our written consent, not to be unreasonably withheld. We may assign it as part of a corporate reorganisation, merger, financing or sale of all or substantially all of the relevant business, provided this does not materially reduce the Customer’s rights.
24.3 Subcontracting. We may use subcontractors but remain responsible for performance of our contractual obligations, subject to the Agreement.
24.4 No partnership or agency. The Agreement does not create a partnership, joint venture, fiduciary relationship, employment relationship or agency between ExcelTTC and any Customer, facility, agency or worker.
24.5 Entire agreement. The Agreement is the entire agreement about its subject matter and supersedes prior discussions and representations. Neither party relies on a statement not set out in the Agreement, without limiting liability for fraud.
24.6 Waiver and severance. A delay or failure to enforce a right is not a waiver. If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary or removed, and the remainder will continue.
24.7 Third-party rights. A person who is not a party to the Agreement has no right to enforce it under the Contracts (Rights of Third Parties) Act 1999.
24.8 Interpretation. “Including” means “including without limitation”. A reference to law includes amendments and replacements. Headings are for convenience only. Electronic acceptance and records may be used to evidence the Agreement.
25. Governing law and disputes
25.1 The parties will first try in good faith to resolve a dispute through their authorised representatives. This does not prevent either party seeking urgent interim relief.
25.2 The Agreement and any non-contractual obligations arising from it are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to any mandatory law that applies otherwise.
26. Contact
Questions about the Service or these Terms may be sent to support@workcura.com. Legal notices must be sent as stated in clause 23. ExcelTTC Limited’s registered office is 24 Phoenix Fields, Ballymena, BT42 2BF, United Kingdom.
Schedule 1 — Data Processing Schedule
This Schedule applies where ExcelTTC processes personal data on behalf of a Customer in providing WorkCura. Terms such as controller, processor, personal data, personal data breach, processing and data subject have the meanings given by applicable data-protection law.
1. Roles and instructions
1.1 The Customer is the controller and ExcelTTC is the processor for Customer Personal Data, except where the parties are independently controllers for their own purposes. The Customer instructs us to process Customer Personal Data to provide, secure, maintain, support and improve the Service; follow documented configuration and user actions; meet the Agreement; and comply with applicable law.
1.2 We will process Customer Personal Data only on documented instructions, including concerning international transfers, unless law requires otherwise. Where legally permitted, we will notify the Customer before processing required by law. If we believe an instruction infringes data-protection law, we will inform the Customer and may pause the affected processing.
2. Processing details
| Subject matter | Provision of the WorkCura workforce and shift-management Service. |
|---|---|
| Duration | For the Agreement and any limited retention or deletion period described in it. |
| Nature and purpose | Collection, storage, organisation, retrieval, transmission, display, support, security, backup, reporting, export, deletion and other processing necessary to provide the Service. |
| Data subjects | Healthcare workers; agency and facility staff; administrators; representatives, contacts and other individuals whose information the Customer lawfully submits. |
| Personal data | Identity and contact details; account and authentication data; work history, availability and shift records; timesheets and approvals; qualifications, registrations, training and compliance records; communications, support data, device and audit information; billing contacts; and other data configured by the Customer. |
| Sensitive data | Where the Customer submits it lawfully: health and occupational-health information, professional restrictions, criminal-offence/DBS information, equality-monitoring information and other special-category data. Patient clinical data is not permitted unless separately agreed in writing. |
3. Confidentiality and personnel
We will ensure that persons authorised to process Customer Personal Data are subject to a contractual or statutory duty of confidentiality, receive appropriate data-protection and security guidance, and access data only as needed for their role.
4. Security
4.1 Taking account of the state of the art, implementation costs, processing scope and risks, we will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
4.2 Measures will include, as appropriate: access controls and least privilege; authentication and credential protections; encryption in transit and appropriate protection at rest; logging and monitoring; vulnerability and patch management; backup and recovery; secure development and change control; supplier controls; incident response; personnel training; and periodic testing and review.
4.3 The Customer is responsible for secure configuration, user access, endpoint security, lawful data minimisation, retention settings and protecting exports or copies outside the Service.
5. Subprocessors
5.1 The Customer gives general written authorisation for us to appoint subprocessors needed to provide the Service. We will maintain an up-to-date list at www.workcura.com/subprocessors or make it available on request.
5.2 We will give reasonable advance notice of a new subprocessor that will process Customer Personal Data. The Customer may object on reasonable data-protection grounds within 10 business days. The parties will work in good faith on a solution; if none is reasonably available, either party may terminate the affected Service without penalty for the unused prepaid period.
5.3 We will impose data-protection obligations on each subprocessor that provide materially equivalent protection and remain responsible for the subprocessor’s performance of those obligations.
6. International transfers
We will not transfer Customer Personal Data outside the United Kingdom unless the transfer complies with applicable law through an adequacy regulation, the UK International Data Transfer Agreement or Addendum, binding corporate rules, a lawful derogation, or another valid mechanism, together with supplementary measures where required.
7. Data-subject rights and Customer assistance
Taking account of the nature of processing, we will provide reasonable assistance through Service functionality and appropriate technical or organisational measures so the Customer can respond to requests to exercise data-subject rights. If we receive a request concerning Customer Personal Data, we will refer it to the Customer and will not respond substantively unless authorised or legally required.
8. Breaches, assessments and consultations
8.1 We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available about the nature of the breach, likely consequences, affected data and individuals, measures taken or proposed, and a contact point. Information may be provided in phases.
8.2 Taking account of the processing and information available to us, we will provide reasonable assistance with breach notifications, data-protection impact assessments and prior consultations required of the Customer. We may charge reasonable costs where assistance is extensive and the need was not caused by our breach.
9. Deletion and return
At the Customer’s choice and subject to the Agreement, we will return or make available an export of Customer Personal Data and delete remaining copies after the Service ends, unless law requires retention. Data in backups may remain until overwritten under our normal cycle and will remain protected and unavailable for ordinary use. We may retain records needed to establish, exercise or defend legal claims or meet legal obligations.
10. Information and audits
10.1 We will make available information reasonably necessary to demonstrate compliance with this Schedule, including relevant independent assurance or summaries where available.
10.2 If that information is insufficient, the Customer may request an audit no more than once in any 12-month period, unless a breach or regulator requires more. Audits must be on reasonable notice, during business hours, minimise disruption, protect other customers and confidential information, and be conducted by an independent qualified auditor bound by confidentiality. The Customer bears its costs unless the audit identifies our material breach.
11. Priority
For personal-data processing matters, this Schedule prevails over conflicting provisions in the Terms, unless a signed data processing addendum expressly replaces it.