Legal
Terms of service
The terms on which we provide malware removal, monitoring and hardening.
1. Who these terms are between
These terms are between [REGISTERED COMPANY NAME], registered in England and Wales under company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS] ("we", "us"), and the person or organisation buying the service ("you").
These terms apply to business customers. If you are a consumer buying outside the course of a business, additional statutory rights apply which these terms do not limit.
2. What we provide
Depending on the plan you take, the service includes:
- Investigation and removal of malware from your website or server
- 24/7 monitoring of the sites and servers covered by your plan
- Hardening work — such as blocking script execution in upload directories, firewall and SSH lockdown, and administrator account audits
- Incident reporting
- White-label delivery and client-ready reporting on the Agency plan
What is covered depends on the plan: the Single Site plan covers one website, the Server / Multi-site plan covers one VPS or shared server and the sites hosted on it, and the Agency plan is scoped to your site count and server specification and agreed in writing before it starts.
3. Plans and prices
- Single Site — £99 per month
- Server / Multi-site — price on application, agreed in writing before it starts
- Agency (White-label) — from £299 per month, scoped per client
When you first sign up we carry out a security audit of the sites and servers your plan covers before any malware removal begins. This is a one-off setup charge of £129.99, payable at sign-up.
Prices are per month and are [INCLUSIVE / EXCLUSIVE] of VAT. [VAT NUMBER, IF REGISTERED.] We may change prices on [NOTICE PERIOD, e.g. 30 days'] written notice; a change will not affect the month you have already paid for.
4. Billing, and cancelling
The service is billed monthly in advance by [PAYMENT PROVIDER / METHOD]. There is no minimum term and no long-term contract.
You may cancel at any time. Cancellation takes effect at the end of the month you have paid for, and we do not refund part months. [STATE HOW TO CANCEL — e.g. by email to a named address.]
We may suspend or end the service if an invoice is unpaid after [NUMBER] days, if you ask us to do something unlawful, or if you use the service in a way that breaks clause 7.
5. "Unlimited" removals, and fair use
Malware removal is unlimited: if a site or server covered by your plan is infected, we will clean it as many times as it happens within your monthly fee, with no per-incident charges.
Fair use applies to full rebuilds. Where a server is so comprehensively compromised that a clean rebuild is the responsible course, or where the work amounts to migration or redevelopment rather than cleanup, we will tell you before we start and quote separately. Unlimited removal is not an unlimited development retainer.
We may also treat repeat infections as outside fair use where they are caused by your refusal to apply hardening we have recommended, or by software you have chosen to keep running unpatched after we have advised otherwise.
6. What we need from you
You are responsible for:
- Giving us the access we need — hosting, server, and site credentials — and having the authority to grant it
- Keeping your own backups. We take working copies during an engagement, but we are not a backup service
- Telling us promptly if you think you have been compromised
- Keeping the credentials you share with us secure, and rotating them when an engagement ends
You confirm that you own, or are authorised to instruct work on, every site and server you ask us to work on. We may ask for evidence of that authority.
7. Acceptable use
You may not use the service to gain access to systems you do not control, to test or attack third-party systems, or for any unlawful purpose. We will report and refuse work where we believe this is happening.
8. What we do not promise
This clause matters, so it is written plainly. Security is risk reduction, not certainty.
- We do not guarantee that a site or server will never be compromised. No provider honestly can. New vulnerabilities appear constantly, and some attacks succeed against well-maintained systems.
- We do not guarantee that all malware will be found. We apply professional skill and our own tooling, but detection is not absolute.
- We do not guarantee uninterrupted monitoring, which depends on third-party networks and your hosting remaining reachable.
- We do not guarantee search engine outcomes. Where a site has been blacklisted we will help you clean it and request a review, but the decision is the search engine's.
We will perform the service with reasonable care and skill, as required by section 13 of the Supply of Goods and Services Act 1982.
9. Liability
Nothing in these terms limits our liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited.
Subject to that, our total liability arising out of or in connection with the service, whether in contract, tort (including negligence) or otherwise, is limited in aggregate to [LIABILITY CAP — commonly the total fees paid by you in the 12 months before the claim]. We are not liable for loss of profit, loss of business, loss of goodwill, or loss of or damage to data, in each case whether direct or indirect.
[CONFIRM THIS CAP WITH YOUR INSURER AND YOUR SOLICITOR. A cap that is unreasonable under the Unfair Contract Terms Act 1977 may be unenforceable, which would leave you worse off than a realistic one.]
10. Confidentiality
Each of us will keep the other's confidential information confidential, and use it only to perform these terms. That includes anything we learn about your systems, and our own methods and reports. This survives the end of the contract.
We may describe the work in anonymised terms — for example the type of compromise and how it was resolved — but we will not identify you without your written permission.
11. Data protection
Where we process personal data on your behalf in the course of an engagement, we do so as your processor and on your documented instructions. Our privacy policy explains how we handle personal data as a controller. [ATTACH OR REFERENCE A DATA PROCESSING AGREEMENT — this is required by Article 28 UK GDPR where we process personal data for you.]
12. General
- Whole agreement. These terms, plus any written scope we agree, form the whole agreement between us.
- Changes. We may update these terms on [NOTICE PERIOD] written notice. If a change materially disadvantages you, you may cancel without penalty.
- Subcontracting. We may use subcontractors, and remain responsible for their work.
- No third-party rights. Nobody other than you and us may enforce these terms.
- Governing law. These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
13. Contact
[REGISTERED COMPANY NAME], [REGISTERED ADDRESS].
Email repair@patientzerosolutions.co.uk ·
Phone 01932 593642