`This Agreement is for the provision of the Melius Cyber Consultancy Limited, Cyber Safe software service herein referred to as Cyber Safe and associated Services as defined in the contract between the parties. By signing a Contract with Melius Cyber Consultancy Limited you are agreeing to abide by these Terms & Conditions.
This Agreement shall be governed by the laws of England and Wales and the parties hereby submit to the exclusive jurisdiction of the English court, except for enforcement proceeding where the English courts shall have non-exclusive jurisdiction.
In this Agreement “Melius Cyber” means Melius Cyber Consultancy Limited of Hadrian House, Beaminster Way East, Newcastle upon Tyne, NE3 2ER.
The Terms “you” and “customer” in this Agreement means your company and all of its employees (including any agents, support companies or third-party advisers which you request us to liaise with).
Definitions
The following definitions apply to this Contract:
Actual intrusions is the existence of a live unauthorised perpetrator, an individual or group of people, who have gained access to the Customer’s Information System.
Accredited partner a supplier (individual or body corporate), who has satisfied the procurement processes of Melius Cyber in accordance with ISO27001 and is subject to a valid confidentiality agreement.
Agreement of dates is defined as an acceptance (via email) by the Customer of an offer of a start and end date in which any security testing engagement will be carried out within.
Annual Fees or Monthly Fees means the recurring fees payable by Customer in order to continue to use the Services. Such Fees shall be exclusive of VAT or other sales taxes.
Approval to Test means Melius Cyber’s Scope Definition Form completed and signed by the Customer prior to execution of Security Testing.
Authorised User means each individual person or third-party agent/representative employed by the Customer as using and/or accessing the Software as authorised by the Customer to use the SaaS Service.
Charges means any or all charges payable under the signed Contract including any one-off charges, Annual Fees and ad-hoc fees owing by Customer to Melius Cyber Consultancy Limited as detailed in a Statement of Work.
Cloud means the on-demand availability of computer system resources, especially data storage and computing power, without direct active management by the user.
Conditions means the terms and conditions set out in this Agreement.
Confidential Information means all confidential information (however recorded or preserved) disclosed by a party or its employees, officers, representatives or advisers to the other party. including but not limited to all system configurations, user guidance, training handout, proprietary data whose disclosure to third parties may be damaging and other similar information, and any Software or materials which have been or will be supplied to the Customer by Melius Cyber in connection with this Contract.
Consultant means the individual(s) provided by Melius Cyber for the performance of the Security Testing. On occasion such a Consultant may be an accredited partner of Melius Cyber.
Contract means the signed Contract between the Customer and Melius Cyber. Within which are contained the details of the services to be provided to the Customer as part of the contract between you and Melius Cyber.
Customer means the entity shown on the signed Contract.
Customer Data means the personal data of which the Customer is data controller (“Customer Data”).
Cyber Safe means the software being provided by the Service.
Documentation means the standard user guides and manuals made available to the Customer by Melius Cyber, as updated from time to time.
End date means the date by which the Security Testing must cease as set out in the Authorisation to Test Scope Definition document. If “End Date” is omitted, then the time frame for the test will be six months after the “Start Date”.
Endpoint means any device that is physically an end point on a network i.e. Laptops, desktops, mobile phones, tablets, servers, and virtual environments.
GDPR means the EU General Data Protection Regulation being Regulation (EU) 2016/679.
ICO means the Information Commissioner’s Office or any replacement authority in the UK.
Information System means the entire infrastructure, organisation, personnel and components for the collection, processing, storage, transmission, display, dissemination and disposition of information, as defined and controlled by the Customer.
Intellectual Property Rights/IPR means all intellectual and industrial property rights including copyright, licence, patents, know-how, trademarks, trade names, inventions, registered designs, applications for and rights to apply for any of the foregoing, unregistered design rights, unregistered trademarks, database rights, and any other rights in any invention, discovery or process, and all similar or equivalent rights or forms of protection which subsist or will subsist, now or in the future, in any part of the world.
Interim Report a report made verbally or by other means to the Customer on the conduct of the Security Testing prior to the delivery of the Test Report.
Maintenance Release shall mean a new release of the Software that is substantially the same as the current Software, which is issued to remove known errors or otherwise improve or enhance the Software but does not constitute a New Version.
New Version shall mean a release of the Software that incorporates significant new or additional functionality and features which is not a Maintenance Release.
Melius Cyber means Melius Cyber Consultancy Limited, company number 11803541, who’s registered office is at Suite 2, Hadrian House Street, Beaminster Way East, Newcastle upon Tyne NE3 2ER.
Open-Source Software means software that is supplied on an “as is” basis and is supplied to Customer with all of the rights granted under the applicable licence.
Penetration Testing means the authorised access to carry out Security Testing to simulate a cyber attack and record the findings.
SaaS Service means the cloud-hosted Cyber Safe solution provided by Melius, comprising the Software and the Documentation, as updated by Melius Cyber from time to time.
SaaS Service Support means any services provided by Melius Cyber under this Subscription Agreement as detailed in the signed Contract or subsequent Statement of Work (SOW) documents.
Scope Definition means the breakdown of work documented within the Authorisation to Test Scope Definition which contains the details of what is included in the test scope.
Security Testing means an authorised penetration test or vulnerability assessment in which Melius Cyber attempts to circumvent the security measures and controls of an information system. The purpose being to identify vulnerabilities within an information system.
Software means the software, which may include Open-Source Software that is licensed to, or made available to the Customer under this Contract, as listed in the Contract, together with any updates or Maintenance Releases (but excludes New Versions).
Start Date means the date shown in the Contract when Cyber Safe is ready for use in a live environment by Customer and when Support Services start. For Penetration Testing services this means the date that Security Testing will start to be provided.
Statement of Work (SOW) means the document detailing the scope of works for services to be provided, deliverables and timetable and is governed by the terms and conditions set out in this Agreement.
Support Services means the management and maintenance services for the Software as described in the Contract.
Test Boundaries are the areas that require testing as agreed by the Customer in the Scope Definition documented in the Contract or whereby express permission has been given to Melius Cyber by the Customer, who have the authority to grant permission to the areas to be tested.
Test Report means the report produced by Melius Cyber detailing the results of the Security Testing.
Third Party Information Service Providers are entities that provide support to or implement the Customer’s information systems i.e. managed service providers.
Third Party Information Stakeholders are defined as any individuals, organisations or others, who have information concerning them or belonging to them held by or available to the Customer.
Working Day means 0900 – 1700 hours on a Monday to Friday excluding English public holidays.