WJDIGITAL LTD Route continuity active
Home About Services Portfolio Contact
Routing request
Home About Services Portfolio Contact Routing request

Terms and Conditions

Last updated: 17 July 2026 · Standard commercial terms for professional services engagements with WJDIGITAL LTD

1. Definitions and interpretation

In these Terms and Conditions ("Conditions"), unless the context otherwise requires, the following definitions apply. "WJDIGITAL LTD", "we", "us" and "our" mean WJDIGITAL LTD, whose principal place of business is 195-197 Wood Street, London, London, E17 3NU United Kingdom, contactable at service@wjdigital.codes and +44 20 7946 0192, and whose public website is wjdigital.codes.

"Client", "you" and "your" mean the company, partnership, public body or other legal person identified in the Statement of Work or other order document as the contracting customer. "Agreement" means the contract formed by these Conditions, the Statement of Work, any schedules (including a data processing schedule), and any documents expressly incorporated by written reference.

"Services" means the cloud infrastructure, media streaming, high-load web platform, content delivery network, application programming interface, DevOps, cybersecurity consulting, related advisory, implementation, managed support and other professional services described in the Statement of Work. "Deliverables" means documents, designs, configurations, code, runbooks, diagrams and other materials we are expressly required to supply under the Statement of Work.

"Statement of Work" or "SOW" means a written document signed or otherwise accepted by both parties describing scope, fees, timetable, assumptions and dependencies. "Background IP" means intellectual property owned or licensed by a party before the Agreement or developed independently outside the Services. "Foreground IP" means intellectual property created by us specifically for the Client in the course of the Services as identified in the SOW.

"Confidential Information" means non-public information disclosed by one party to the other in connection with the Agreement, including technical architectures, pricing, security controls, commercial terms and personal data. "Business Day" means a day other than Saturday, Sunday or a public holiday in England. Headings are for convenience only. References to statutes include amendments. Words in the singular include the plural and vice versa. "Including" means including without limitation.

2. Application of these Conditions

These Conditions apply to all quotations, proposals, SOWs and Agreements for Services supplied by WJDIGITAL LTD to business Clients, to the exclusion of any other terms the Client seeks to impose or incorporate, or which are implied by trade, custom, practice or course of dealing, except where we expressly agree otherwise in a signed writing.

A quotation does not constitute an offer. An Agreement is formed when the Client accepts a SOW in writing (including by email from an authorised address) or when we commence Services at the Client's written request, whichever occurs first. If there is a conflict between documents, the following order of precedence applies: (1) a specifically negotiated special condition in the SOW; (2) a data processing schedule; (3) these Conditions; (4) other schedules; (5) marketing materials or website content on wjdigital.codes.

Website Terms of Service govern use of wjdigital.codes only and do not vary these Conditions for contracted Services. The Client's purchase order terms are rejected unless we expressly accept them in writing signed by an authorised representative of WJDIGITAL LTD.

3. Company details and notices

Formal notices under the Agreement must be in writing and delivered by hand, pre-paid first-class post, or email with read acknowledgement or confirmed reply, to the addresses set out in the SOW or, if none, to 195-197 Wood Street, London, London, E17 3NU United Kingdom and service@wjdigital.codes for WJDIGITAL LTD, and to the Client addresses in the SOW. Notices are deemed received: if delivered by hand, on the Business Day of delivery; if posted, two Business Days after posting; if emailed, on the Business Day of transmission if sent before 17:00 London time on a Business Day, otherwise on the next Business Day, provided no delivery failure is received.

Operational communications about project delivery may use the named contacts in the SOW and telephone +44 20 7946 0192 but do not replace formal notice where these Conditions require notice.

4. Scope of Services

We shall provide the Services with reasonable skill and care in accordance with the SOW and these Conditions, consistent with good professional practice for United Kingdom technology consultancies operating in cloud infrastructure, media streaming distribution, high-load web platforms, CDN management, API integration, DevOps and cybersecurity consulting.

Unless expressly stated in the SOW, Services are professional services and advisory or implementation assistance; they are not a guarantee of specific third-party cloud credits, vendor certifications, uptime of third-party platforms, or outcomes dependent on Client systems we do not control.

We may use suitably qualified employees, contractors and subprocessors. We remain responsible for their performance as regards the Client, subject to the liability provisions below. Where the SOW identifies named personnel, we will use reasonable efforts to maintain continuity but may substitute personnel of equivalent skill with notice where reasonably required.

4.1 Cloud infrastructure services

Cloud infrastructure Services may include architecture design, landing zone foundations, identity and access baselines, network topology design, infrastructure as code, cost and tagging reviews, resilience patterns, and migration planning. The Client remains the account holder with cloud providers unless otherwise agreed. The Client must provide timely access, approvals and environment credentials necessary for performance.

4.2 Media streaming and CDN services

Media streaming and CDN Services may include distribution architecture, origin and edge path design, caching policy advice, packaging and protocol guidance, observability for streaming quality, and runbook preparation. Performance depends on ISP conditions, device ecosystems, content characteristics and third-party CDN behaviour. Targets in a SOW are objectives unless expressly labelled as service levels with credits.

4.3 High-load web platforms and APIs

High-load platform and API Services may include capacity modelling, caching strategies, asynchronous processing design, API gateway patterns, contract design, authentication flows, and load-testing support. Load-test results are indicative of conditions tested and are not warranties for production traffic of different shape or volume.

4.4 DevOps and delivery engineering

DevOps Services may include pipeline design, environment promotion routes, artefact management, infrastructure automation, release governance, and operational readiness reviews. The Client is responsible for approvals to promote changes into production unless managed-service responsibility is expressly transferred in the SOW.

4.5 Cybersecurity consulting

Cybersecurity consulting may include control gap assessments, secure architecture review, configuration hardening advice, incident response planning support, and tabletop exercises. Unless the SOW expressly includes offensive testing with defined rules of engagement, we will not perform intrusive testing. Findings are point-in-time and do not guarantee that systems are free from vulnerabilities.

5. Client obligations and dependencies

The Client shall: cooperate promptly with our reasonable requests; provide accurate information about systems, constraints and compliance needs; ensure authorised personnel are available for workshops and decisions; obtain licences for Client-provided software; secure all consents required for us to access environments; maintain appropriate backups unless backup operation is expressly in scope; and ensure that instructions given to us are lawful.

The Client warrants that it owns or is licensed to use materials it supplies and that our use of those materials in accordance with the Agreement will not infringe third-party rights. Delays caused by Client dependencies may result in timeline adjustment and additional charges at the rates in the SOW or our then-current rates if none are stated.

Where Services involve production changes, the Client remains responsible for business acceptance criteria, change-advisory approvals within its organisation, and communication to its end users, unless otherwise agreed in writing.

6. Change control

Either party may request a change to scope, Deliverables, timetable or fees. We will assess impact and provide a written change request setting out adjusted fees and timelines. No change is binding until both parties accept it in writing. We are not obliged to perform out-of-scope work. Urgent operational assistance requested by the Client without a completed change request may be charged on a time-and-materials basis at agreed rates and documented retrospectively.

7. Fees, expenses and payment

Fees are set out in the SOW and may be fixed price, time and materials, retainer, or a combination. Unless stated otherwise, fees are exclusive of VAT and other applicable taxes, which the Client shall pay at the prevailing rate. Reasonable pre-approved travel and subsistence expenses, and third-party costs incurred on the Client's behalf, are rechargeable at cost plus any handling fee stated in the SOW.

We invoice according to the SOW schedule, or monthly in arrears for time-and-materials work, or upon milestones. Invoices are payable within fourteen (14) days of the invoice date unless the SOW states a different period. Payment must be made in pounds sterling to the bank account nominated on the invoice, quoting the invoice number.

If the Client fails to pay any undisputed amount when due, we may charge interest under the Late Payment of Commercial Debts (Interest) Act 1998, suspend Services after providing at least seven (7) days' written notice, and recover reasonable debt collection costs. Disputed invoices must be notified in writing within ten (10) Business Days of receipt with reasonable detail; undisputed portions remain payable.

Fixed-price fees assume the accuracy of Client information and the dependencies listed in the SOW. Material inaccuracies may trigger change control. Retainers unused in a period do not roll over unless the SOW expressly provides. Estimates are not caps unless described as a fixed price or not-to-exceed amount.

8. Non-solicitation

During the Agreement and for six (6) months after its termination, neither party shall solicit for employment the other party's personnel who were materially involved in the Services, except through general recruitment advertising not targeted at such personnel. This does not restrict hiring where an individual responds to a genuine open advertisement. Breach may entitle the injured party to liquidated damages equal to three months' gross fees for the individual, as a genuine pre-estimate of loss, without prejudice to other remedies where the estimate is exceeded by proven loss.

9. Intellectual property ownership and licences

Background IP of each party remains vested in that party. The Client retains ownership of Client materials and Client data. Subject to payment of fees due, and except as otherwise stated in the SOW, Foreground IP in Deliverables created specifically for the Client will be assigned to the Client upon full payment, excluding our Background IP, tools, scripts, templates, know-how, methodologies and generic frameworks which remain ours.

We grant the Client a non-exclusive, non-transferable, perpetual licence to use our Background IP solely as embedded in the Deliverables for the Client's internal business purposes. The Client shall not reverse engineer our tools except where mandatory law permits, nor resell our Background IP on a standalone basis.

We may use anonymised, non-identifying know-how and residual skills gained during the engagement in future work for other clients, provided we do not disclose the Client's Confidential Information or copy proprietary Client materials.

Open-source components included in Deliverables remain subject to their applicable licences. We will identify material open-source licences on request where we introduce them. The Client is responsible for compliance with open-source obligations in its production use.

If a third party claims that a Deliverable we created infringes UK intellectual property rights, we may at our option procure a right of continued use, modify the Deliverable to be non-infringing, or terminate the affected portion and refund fees paid for that portion on a pro-rata basis. This obligation does not apply to infringement arising from Client materials, Client-required specifications, combinations not supplied by us, or modifications made by parties other than us.

Each party shall retain all rights in its trade marks. Neither party grants the other a licence to use trade marks except for limited references reasonably required to perform the Services or as agreed for case studies under Clause on publicity.

10. Confidentiality

Each party undertakes to keep the other party's Confidential Information confidential and not to disclose it to third parties except to employees, advisers and subcontractors who need to know it for the Agreement and who are bound by confidentiality obligations no less protective, or as required by law or a competent authority.

Confidentiality obligations do not apply to information that is public other than by breach, was already known without duty of confidence, is independently developed, or is disclosed with prior written consent. If disclosure is required by law, the disclosing party will give reasonable notice where legally permitted.

Confidentiality obligations survive for five (5) years after termination, except for trade secrets which remain protected while they qualify as trade secrets, and personal data which remains protected under data protection law.

Upon termination, each party shall return or securely destroy the other party's Confidential Information on request, except for copies retained under legal hold, backup systems, or professional record-keeping, which remain subject to confidentiality.

11. Data protection

Each party shall comply with its obligations under the UK GDPR and Data Protection Act 2018. Where we process personal data as a processor on behalf of the Client, the parties shall enter into a data processing schedule meeting Article 28 UK GDPR requirements, which is incorporated into the Agreement.

The Client warrants that it has a lawful basis to provide personal data to us and to instruct the processing described in the SOW. We shall process such personal data only on documented instructions, ensure confidentiality of authorised persons, implement appropriate security measures, assist with data subject rights and breach notification as reasonably required and scoped, and delete or return personal data at the end of services subject to legal retention.

Details of international transfers, subprocessors and retention for processor activities will be set out in the data processing schedule or SOW. Our role as controller for our own business contacts and website visitors is described in our Privacy Policy on wjdigital.codes and is separate from Client end-user data.

Cybersecurity consulting may include recommendations affecting personal data security. Implementation decisions and residual risk acceptance remain with the Client unless we have expressly accepted managed operation of a control in the SOW.

12. Security and access

We shall apply security measures appropriate to the nature of the Services, including least-privilege access to Client environments, secure handling of credentials, and prompt revocation of access when personnel leave an engagement. The Client shall provide access via approved channels and promptly revoke credentials we no longer need.

The Client must not provide production secrets through unsecured channels. If emergency access is granted, both parties shall document the reason and duration. We are not responsible for security incidents originating from Client-managed accounts, unmanaged shadow IT, or third-party providers outside our control, except to the extent caused by our proven failure to meet an express security obligation in the SOW.

Where the SOW requires specific certifications or control frameworks, our obligations are limited to those expressly stated. Generic references to industry good practice do not import the entirety of external frameworks unless scheduled.

13. Service levels, support and response

Unless a service level schedule is attached, Services are provided on a professional-services basis during ordinary Business Day hours in London, without uptime credits. Where managed support is included, response targets are objectives for prioritisation and are not warranties unless expressly described as committed service levels with defined remedies.

Severity definitions, escalation paths and maintenance windows will be documented in the SOW where support is in scope. Scheduled maintenance that we control will be notified in advance where reasonably practicable. Emergency security patches may be applied with shorter notice.

14. Warranties

We warrant that Services will be performed with reasonable skill and care and that we have the right to enter into the Agreement. Deliverables will materially conform to the acceptance criteria in the SOW for a period of thirty (30) days after acceptance, provided the Client notifies us of non-conformance promptly with reproducible detail. Our sole obligation for breach of this warranty is re-performance or, at our option, a refund of fees paid for the non-conforming portion.

Except as expressly stated, all other warranties, conditions and terms implied by statute or common law are excluded to the fullest extent permitted by the laws of England and Wales, including those regarding satisfactory quality and fitness for purpose.

The Client warrants that it has authority to contract, that information provided is accurate in all material respects, and that instructions will not require us to breach law.

15. Acceptance

Where the SOW provides for acceptance testing, the Client shall complete testing within the period stated (or ten Business Days if none) and either accept or provide a written list of material defects against agreed criteria. Minor defects that do not materially impair use shall not justify rejection and will be addressed within a reasonable remediation plan.

If the Client fails to notify rejection within the acceptance period, or uses the Deliverable in production for purposes beyond evaluation, the Deliverable is deemed accepted. Acceptance does not affect claims for latent defects notified within the warranty period that could not reasonably have been discovered during testing.

16. Limitation of liability

Nothing in the Agreement excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for wilful misconduct, or for any other liability that cannot be excluded or limited under the laws of England and Wales.

Subject to the preceding paragraph, neither party shall be liable to the other, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for any loss of profits, loss of revenue, loss of anticipated savings, loss of business, loss of goodwill, loss of or corruption of data (except to the extent we are expressly engaged to provide backup services and fail to meet an express backup obligation), or any indirect, consequential or special loss, even if advised of the possibility of such loss.

Subject to the first paragraph of this clause, our total aggregate liability arising out of or in connection with the Agreement shall not exceed the total fees paid or payable by the Client to WJDIGITAL LTD under the applicable SOW during the twelve (12) months immediately preceding the date of the event giving rise to the claim. Where the engagement has run for less than twelve months, the cap shall be the fees paid or payable for that engagement to date, or the fees scheduled for the first twelve months, whichever is higher.

The Client agrees that the fees reflect the allocation of risk in this clause. The Client is encouraged to purchase insurance appropriate to its risk profile. Multiple claims shall not enlarge the cap. Claims must be brought within twelve months of the date the claimant became aware, or ought reasonably to have become aware, of the circumstances giving rise to the claim, and in any event within two years of the act or omission complained of, except where a longer period is mandatory by law.

17. Indemnities

The Client shall indemnify WJDIGITAL LTD against claims, damages, losses and reasonable legal expenses arising from: Client materials and instructions; Client's breach of law or third-party rights; personal data processing where the Client is controller and the claim arises from Client instructions or Client's failure to comply with controller obligations; and use of Deliverables outside the licence scope.

We shall indemnify the Client against third-party claims that Foreground IP we assign or Deliverables we create (excluding Client materials, third-party products, and open-source components under their own licences) infringe UK intellectual property rights, subject to the options and exclusions in the intellectual property clause, and provided the Client gives prompt notice, reasonable cooperation, and sole control of defence and settlement (settlements requiring our prior consent where they impose obligations on us beyond payment of money we agree to pay).

An indemnified party must mitigate losses reasonably. Indemnity payments are subject to the liability cap except for IP infringement indemnity amounts we agree to pay to a third party to settle a covered claim, fraud, and liabilities that cannot be limited by law.

18. Insurance

We maintain professional indemnity and public liability insurance at levels we consider appropriate to our business. Evidence of cover will be provided on reasonable request. Maintaining insurance does not increase our liability beyond the contractual cap. The Client should maintain insurance appropriate to its operations, including cyber insurance where processing significant personal data or operating high-load public platforms.

19. Term and termination

The Agreement commences on the effective date in the SOW and continues until completion of the Services or until terminated in accordance with these Conditions. Either party may terminate for convenience where the SOW is on a monthly retainer, by giving thirty (30) days' written notice, unless the SOW states a different notice period or a fixed minimum term.

Either party may terminate immediately by written notice if the other party: commits a material breach and fails to remedy it within thirty (30) days of written notice specifying the breach (or immediately if the breach is not remediable); becomes insolvent, enters administration, liquidation, arrangement with creditors, or analogous process; or ceases to trade.

We may terminate or suspend immediately if the Client fails to pay undisputed sums within fourteen (14) days after a written overdue notice, or if continuing would breach export control, sanctions, or other mandatory law.

On termination: the Client shall pay for Services performed and recoverable commitments incurred up to the effective date; licences granted to the Client for unpaid Deliverables may be suspended until payment; each party shall return or destroy Confidential Information on request subject to permitted retention; and clauses which by nature should survive shall survive, including intellectual property, confidentiality, data protection, liability, indemnity, non-solicitation and governing law.

Termination does not affect accrued rights. Prepaid fees for Services not performed after termination for our material breach will be refunded on a pro-rata basis for the unused portion. Prepaid fees are otherwise non-refundable except as required by law or expressly stated.

20. Suspension

We may suspend Services on written notice if: continued performance presents a material security risk not caused by us; the Client's environment access is withdrawn; a third-party provider suspends underlying services; or the Client is in material breach including non-payment. We will resume when the cause is resolved. Suspension under this clause for Client cause does not relieve payment obligations for work performed and may extend timelines.

21. Force majeure

Neither party is liable for delay or failure to perform caused by events beyond its reasonable control, including act of God, natural disaster, war, terrorism, riot, embargo, act of government, epidemic, failure of utilities, failure of cloud or CDN providers not under that party's control, widespread internet backbone disruption, or industrial dispute affecting third parties. The affected party shall give prompt notice and use reasonable efforts to mitigate. If force majeure continues for more than sixty (60) days, either party may terminate the affected SOW without liability for such termination, subject to payment for Services performed.

22. Subcontracting and assignment

We may subcontract elements of the Services, remaining responsible for subcontracted performance to the Client. We may assign the Agreement to an affiliate or successor in connection with a corporate reorganisation or sale of business. The Client may not assign without our prior written consent, not to be unreasonably withheld for assignment to an affiliate capable of meeting Client obligations. Any attempted assignment in breach is void.

23. Non-exclusivity

The Agreement is non-exclusive. We may provide similar services to other clients, including those in adjacent markets, provided we do not misuse the Client's Confidential Information. The Client may engage other suppliers unless the SOW grants exclusivity for a defined scope and period.

24. Publicity and case studies

We may identify the Client by name and logo as a client on wjdigital.codes and in credentials materials unless the Client notifies us in writing that it objects. Detailed case studies, architecture diagrams or performance metrics require the Client's prior written approval. Either party may issue a press release about the relationship only with the other's prior written approval.

25. Compliance, anti-bribery and sanctions

Each party shall comply with applicable laws of England and Wales in connection with the Agreement, including anti-bribery laws such as the Bribery Act 2010, and shall not engage in corruption. Each party shall maintain adequate procedures designed to prevent bribery by associated persons as appropriate to its size and risk.

The Client warrants that it is not a sanctioned person and is not owned or controlled by a sanctioned person under UK sanctions regimes. We may refuse or terminate Services if performance would breach sanctions or export controls. The Client shall not request us to export technology in breach of applicable export laws.

26. Anti-slavery and ethical conduct

Each party shall take reasonable steps to ensure that slavery and human trafficking are not taking place in its business or supply chains in a manner consistent with the Modern Slavery Act 2015 expectations applicable to it. The Client shall not require us to use labour practices that breach UK employment law.

27. Export of technical data and access controls

Cloud, cybersecurity and streaming architectures may involve technical data subject to export or access-control considerations. The Client is responsible for classifying its content and for ensuring that region and access choices comply with its regulatory obligations. We will follow documented Client instructions regarding region placement where included in scope.

28. Third-party products and cloud providers

Where Services involve Amazon Web Services, Microsoft Azure, Google Cloud, CDN vendors, monitoring tools, CI platforms or other third-party products, those products are supplied under their own terms between the Client and the vendor unless we expressly resell under a separate schedule. We are not responsible for vendor outages, price changes, feature deprecations, or licence enforcement, except for our failure to implement configurations we expressly committed to deliver.

Advice about third-party products is based on information available at the time. Vendors change APIs and commercial terms frequently. We will use reasonable efforts to note known material risks during the engagement but cannot warrant permanence of third-party features.

29. Open-source software

If we introduce open-source software into Deliverables, we will do so under licences commonly accepted in enterprise environments where practicable and will disclose material licence obligations on request. Copyleft obligations that would require the Client to distribute proprietary source may be introduced only with the Client's prior written approval. The Client is responsible for its ongoing compliance and for scanning its wider estate beyond the Deliverables.

30. Testing, staging and production changes

Unless otherwise agreed, changes will be developed and tested in non-production environments before production promotion. The Client shall provide representative test data that is lawfully processed and, where possible, anonymised. Production changes require Client approval through the Client's change process unless we are expressly authorised to apply emergency fixes under a managed service SOW.

Rollback plans will be prepared where proportionate to risk and scoped in the SOW. Not every change can be instantly rolled back without data loss; residual risk will be identified where known.

31. Backup, disaster recovery and business continuity

Unless backup and disaster recovery operations are expressly included in the SOW, the Client remains solely responsible for backups, recovery testing and business continuity. Where we provide design advice only, implementation and verification remain Client responsibilities. Where we operate backups under a managed service, recovery time and recovery point objectives are as stated in the SOW and are subject to dependencies on underlying cloud provider capabilities.

32. Monitoring, logs and observability

Observability tooling may generate logs containing personal data or Confidential Information. Retention and access for such logs will follow the SOW and data protection schedule. The Client shall configure log redaction where required for its compliance programme. We are not liable for alerts the Client ignores or for thresholds the Client sets incorrectly after handover.

33. Incident response cooperation

If a security incident affects systems in scope, both parties shall cooperate reasonably. Notification timelines for personal data breaches where we are processor are set out in the data processing schedule. Public statements about incidents shall be coordinated where lawful and practical. Neither party shall admit liability on the other's behalf without prior written consent.

34. Media content and streaming rights

The Client warrants that it owns or is licensed to distribute all media content processed through architectures we design or operate, including music, video, images and live feeds. We do not clear rights with collecting societies or rights holders unless expressly engaged to provide such consultancy, and even then clearance remains a Client legal function.

Streaming quality depends on encoding ladder choices, CDN configuration, device capabilities, last-mile networks and player implementations. We will use reasonable skill and care in recommendations within scope, but we do not warrant uninterrupted viewing experiences for all end users globally.

Take-down requests, geo-blocking rules and parental control obligations are Client responsibilities unless the SOW expressly includes implementation of specified rules within systems we manage.

35. High-load and performance testing

Performance tests will be conducted within agreed windows and intensity limits to avoid unintended denial of service against production or third parties. The Client must obtain approvals from hosting and CDN providers where required by their acceptable use policies.

Test results are valid only for the tested build, dataset and environment. Extrapolation to future peak events involves uncertainty. Recommendations following tests are professional opinions, not guarantees of capacity.

The Client shall not publicly publish performance comparisons referencing WJDIGITAL LTD without our prior written consent.

36. API design and integrations

API Deliverables will follow the interface descriptions agreed in the SOW. Backward-incompatible changes after acceptance require change control. Third-party APIs integrated on Client instruction may change without notice; remediation of breaking third-party changes is chargeable unless caused by our error in implementing the originally agreed specification.

Authentication secrets, rate limits and abuse controls must be maintained by the party operating the API in production. We are not responsible for Client disclosure of API keys or for scrapers that overwhelm unprotected endpoints after handover.

37. DevOps pipelines and production access

Pipeline tooling may hold privileged credentials. The Client must ensure separation of duties appropriate to its risk appetite. We recommend least privilege and short-lived credentials. If the Client insists on long-lived shared credentials contrary to our written advice, the Client accepts the associated risk.

Promotion to production through pipelines we build still requires Client authorisation gates unless a managed continuous deployment authority is expressly granted. Audit trails of promotions should be retained by the Client in accordance with its policies.

38. Cybersecurity assessments and ethical boundaries

Vulnerability assessments and penetration tests, where included, will follow a written rules of engagement stating systems in scope, forbidden techniques, time windows and emergency contacts. Testing outside those rules is prohibited. Findings reports are Confidential Information.

We do not provide legal determinations of compliance with PCI DSS, ISO 27001, NHS DSPT, FCA expectations or other regimes unless a qualified specialist scope is expressly included. Our reports may support the Client's compliance programme but do not constitute certification.

If we discover evidence of ongoing criminal intrusion, we may recommend involving law enforcement. We will not destroy forensic evidence knowingly. The Client remains responsible for regulatory notifications required of it as controller or regulated firm.

39. Personnel, location and remote delivery

Services may be delivered remotely from the United Kingdom or, with Client approval, from other locations where our personnel or subcontractors are lawfully permitted to work. On-site attendance at Client premises or data centres will be agreed in the SOW, including access rules, induction requirements and working hours.

The Client shall provide a safe working environment for our personnel when on site, consistent with the Health and Safety at Work etc. Act 1974 and applicable regulations. We may withdraw personnel from unsafe conditions without liability for resulting delay.

We do not transfer employment of Client staff. Nothing in the Agreement creates a partnership, joint venture or employment relationship between our personnel and the Client. The Client shall not supervise our personnel as employees; direction is limited to contract outcomes and safety rules at Client sites.

If a named individual becomes unavailable due to illness, resignation or conflict, we will propose a replacement of suitable skill. The Client shall not unreasonably refuse replacements. Knowledge transfer will be arranged proportionately at our cost where the change is initiated by us other than for cause attributable to the Client.

40. Statements of Work content requirements

Each SOW should identify at minimum: parties and contacts; description of Services and Deliverables; assumptions and exclusions; Client dependencies; fees and payment schedule; target timetable; acceptance approach; and any special security or data protection requirements.

If the parties commence work based on an email confirmation before a formal SOW is signed, these Conditions still apply, and the email scope will be treated as the SOW until replaced. Ambiguities will be resolved by good-faith discussion; failing agreement, we may pause work pending clarification.

Optional items listed as "out of scope" in a SOW are excluded even if related to in-scope systems. Adjacent work requires change control. Discovery workshops may produce recommendations that exceed original budget; implementing those recommendations is a separate decision for the Client.

41. Estimates, forecasts and roadmaps

Any roadmap, forecast, cost projection or capacity estimate provided as part of advisory Services is a professional estimate based on information available at the time. It is not a fixed quote unless expressly labelled as such. Cloud consumption costs fluctuate with usage, vendor pricing and exchange rates.

We may assist the Client in configuring cost alerts and budgets in cloud consoles where scoped. Responsibility for approving spend and for unexpected viral traffic costs remains with the Client as account owner.

Where we provide total cost of ownership models, they include stated assumptions. Changing assumptions invalidates the model. The Client should seek independent financial advice for capital planning decisions of material size.

42. Documentation and knowledge transfer

Deliverable documentation will be provided in the format stated in the SOW, typically English-language documents suitable for technical operators. We are not obliged to provide training programme design, video production or multilingual translation unless included.

Knowledge transfer sessions, where scoped, will be scheduled during Business Days. Recording of sessions requires mutual agreement and will be treated as Confidential Information. The Client may create internal notes for employees bound by confidentiality.

Documentation reflects the system state at acceptance. Subsequent Client changes may obsolete documents. Update retainers can be agreed separately.

43. Tools, scripts and automation libraries

We may use internal accelerators, scripts and automation libraries to deliver efficiently. Unless the SOW states that source for such accelerators is a Deliverable to be assigned, only the configured outputs and agreed artefacts are Client Foreground IP, and accelerators remain our Background IP licensed for use as embedded.

The Client shall not extract our accelerators for resale as a competing consultancy toolkit. The Client may use embedded accelerators to operate the delivered system and to maintain it with its own staff or other suppliers.

If the Client requires escrow of certain tools, that must be negotiated in a separate escrow schedule with additional fees.

44. Governance, steering and reporting

For multi-phase engagements, the parties may establish a steering cadence with agenda, risk log and decision register. Decisions recorded in writing by authorised contacts are binding for scope interpretation.

Status reports will be provided at the frequency in the SOW. Reports are Confidential Information. Metrics included are those reasonably available; building new telemetry solely for reporting may require change control.

Escalation contacts will be named. Either party may escalate blockers that threaten critical path. Escalation does not itself vary fees or liability.

45. Multi-vendor environments

Many Clients operate multi-vendor stacks. We will coordinate reasonably with other suppliers where the SOW includes integration responsibilities, but we are not the prime contractor for other suppliers unless expressly appointed. Delays by other suppliers are Client dependencies.

Where another supplier's defect blocks our work, we will notify the Client and may stand down chargeable resources or redeploy subject to agreement. Waiting time caused by third parties may be chargeable if we have reserved capacity at Client request.

We do not supervise other suppliers' personnel and accept no responsibility for their negligence, except for our own interfaces as defined in the SOW.

46. Regulatory and sector-specific projects

If the Client operates in a regulated sector, the Client must identify material regulatory constraints in writing before architecture decisions are finalised. We will take identified constraints into account within scope. Undisclosed constraints discovered late may require rework at Client cost.

We are not the Client's compliance officer. Responsibility for regulatory submissions, attestations and licence conditions remains with the Client. Our Deliverables may be used as supporting evidence at the Client's discretion and risk.

Healthcare, financial services, education and public-sector engagements may require additional schedules covering data residency, clearance, or framework agreements. Those schedules prevail for their subject matter when executed.

47. Artificial intelligence and automated tooling

Where we use AI-assisted tooling in producing drafts of code, documentation or diagrams, we remain responsible for reviewing outputs before delivery as part of our reasonable skill and care obligation. Confidential Client data will not be submitted to consumer AI services that retain data for model training, unless the Client gives prior written approval for a named tool and configuration.

The Client must disclose if it requires prohibition on AI-assisted development. Additional effort arising from such prohibition may affect fees and timelines through change control.

AI-generated suggestions do not reduce the need for testing. Acceptance testing remains the Client's opportunity to verify fitness for purpose against agreed criteria.

48. Environmental systems access and credentials lifecycle

Credentials issued to WJDIGITAL LTD must be unique, revocable and preferably time-limited. The Client shall maintain an access register. Upon request at the end of an engagement, we will confirm destruction of local credential stores under our control.

Shared root passwords and unrestricted production access for all consultants are discouraged. If the Client mandates them, the Client accepts heightened risk. We may refuse access models that we reasonably consider reckless in a cybersecurity context.

Compromised credentials must be reported by either party to the other without undue delay after discovery. Reset procedures will be followed promptly.

49. Record keeping and audit

We shall keep reasonable records of time charged on time-and-materials engagements for twenty-four months and will provide summaries on request. Detailed individual timesheet disclosure may be limited to protect unrelated client confidentiality and personal data of our staff, but aggregate sufficiency for invoice verification will be provided.

The Client may audit our compliance with data protection and security obligations relevant to the engagement no more than once per twelve months, on thirty days' notice, during Business Days, at the Client's cost, and subject to confidentiality. Audits must not unreasonably disrupt operations or seek access to other clients' information. We may satisfy audit rights through third-party certifications and questionnaires where proportionate.

Regulatory audits requiring our cooperation will be supported reasonably; external costs and material time may be chargeable unless the audit arises from our material breach.

50. Dispute resolution

If a dispute arises, either party may escalate to senior named contacts for good-faith negotiation for fourteen (14) days. If unresolved, either party may pursue litigation in the courts of England and Wales. Nothing prevents either party seeking interim injunctive relief for breach of confidentiality, IP infringement or data protection urgency.

Mediation may be agreed voluntarily under a CEDR or similar model procedure. Mediation is without prejudice and does not suspend limitation periods unless agreed in writing.

Pending dispute resolution, both parties shall continue to perform undisputed obligations, including payment of undisputed invoices.

51. Governing law and jurisdiction

The Agreement and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it or its subject matter shall be governed by and construed in accordance with the law of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction to settle such disputes, and each party irrevocably submits to that jurisdiction. The Client that is established outside the United Kingdom still agrees to this jurisdiction for disputes concerning the Agreement.

The United Nations Convention on Contracts for the International Sale of Goods is excluded. The Contracts (Rights of Third Parties) Act 1999 is excluded except for indemnified affiliates expressly identified in writing as entitled to enforce an indemnity.

52. Entire agreement and variations

The Agreement constitutes the entire agreement between the parties relating to its subject matter and supersedes all prior negotiations, representations and understandings. Each party acknowledges it has not relied on any representation not set out in the Agreement, except for fraudulent misrepresentations.

Variations must be in writing and accepted by authorised representatives of both parties. Email may suffice if the authors are authorised contacts and the variation language is clear. Course of dealing does not vary these Conditions.

If any provision is held illegal, invalid or unenforceable, it shall be modified to the minimum extent necessary to make it valid, and the remaining provisions shall continue in full force.

53. Waiver and rights accumulation

A failure or delay in exercising a right under the Agreement does not constitute a waiver. A partial exercise does not preclude further exercise. Rights and remedies are cumulative and do not exclude rights under law except where expressly limited.

Any waiver must be specific and in writing to be effective, and applies only to the instance waived.

54. Severance and conflict with mandatory law

If a court finds a limitation of liability or other clause unenforceable as drafted, the parties intend that the clause be enforced to the maximum extent permitted. Mandatory consumer protections do not apply to business Clients contracting under these Conditions. If the Client is contracting as a consumer contrary to our business-to-business offering, we may cancel the engagement and refund fees for Services not performed.

55. Notices regarding website and policy documents

Our Privacy Policy, Cookie Policy and Terms of Service on wjdigital.codes provide transparency for website visitors and general privacy practices. They do not reduce obligations in a signed data processing schedule. In commercial engagements, the order of precedence in Clause 2 applies.

Contact channels published on the website — service@wjdigital.codes, +44 20 7946 0192, and 195-197 Wood Street, London, London, E17 3NU United Kingdom — remain valid for commercial notices unless the SOW specifies different addresses.

56. Detailed payment and invoicing mechanics

Invoices will state the SOW reference, period or milestone covered, fees due, VAT where applicable, and payment instructions. The Client shall provide a valid purchase order number if its internal processes require one; failure to issue a purchase order after Services have been requested in writing shall not be a valid reason for non-payment.

Billing disputes must identify line items and reasons with reasonable particularity. Silence after the dispute window constitutes acceptance of the invoice for payment purposes, without prejudice to later warranty claims regarding Deliverables.

We may issue electronic invoices by email to the billing contact. The Client is responsible for ensuring the billing contact mailbox is monitored. Currency conversion fees charged by the Client's bank are the Client's responsibility. Payment is considered made when funds clear our nominated account.

For multi-year engagements, fees may be indexed annually at the higher of three percent or the percentage increase in the UK Consumer Prices Index over the prior twelve months, unless the SOW freezes fees for a defined period. We will give at least thirty days' notice of indexation.

If the Client requires us to use a supplier portal, the Client shall arrange access promptly. Portal processing delays do not extend the due date once an invoice has been validly submitted according to the portal rules, unless the portal itself prevents submission for reasons attributable to us.

Set-off by the Client is not permitted against our invoices except for amounts finally awarded by a court or agreed in writing. We may set off amounts the Client owes us against amounts we owe the Client under any engagement.

57. TuPE and staff transfers

The parties do not intend that the Transfer of Undertakings (Protection of Employment) Regulations 2006 (TuPE) should apply to the commencement or termination of Services. If TuPE is alleged or found to apply, the Client shall indemnify us against employment liabilities arising from transferring employees that were not disclosed before contracting, and the parties shall discuss in good faith an appropriate adjustment to fees or scope.

We shall not knowingly structure Services to engineer an unfair TuPE transfer. The Client shall disclose any outgoing supplier staff who may be in scope before we begin, where the Client is aware of a potential transfer situation.

58. Warranties regarding malware and harmful code

We will use reasonable efforts consistent with good industry practice to avoid introducing known malware into Client systems through Deliverables we supply. The Client remains responsible for maintaining endpoint protection and for scanning artefacts according to its policies.

Supply of software received from third parties at Client direction is provided without additional malware warranty beyond passing through any vendor assurances we can reasonably obtain. Proof-of-concept code delivered for evaluation in non-production may lack hardening expected of production releases; the SOW should state the intended maturity level.

59. Beta features and experimental architectures

If the Client requests use of preview, beta or otherwise experimental cloud or CDN features, we will document known limitations. Such features are provided on an as-is advisory basis without warranty, and may be withdrawn by vendors without notice. Production reliance on beta features is at Client risk unless the SOW expressly accepts that risk profile with mitigation steps.

60. Exit assistance

Upon request before or within thirty days after termination, and subject to payment of our reasonable fees at then-current rates, we will provide proportionate exit assistance to transition Services to the Client or a replacement supplier, including handover of documentation and credentials under our control, and explanation sessions within an agreed time budget.

Exit assistance does not include building a complete re-implementation for a competitor or disclosing our proprietary accelerators beyond what is licensed. We may withhold exit assistance while undisputed fees remain overdue.

61. Schedule-style provisions on cloud landing zones

Where the SOW includes cloud landing zone design or build, the following supplementary terms apply unless varied. A landing zone comprises foundational accounts or subscriptions, identity integration, network skeletons, logging baselines, and guardrails agreed in workshops. The Client must nominate an executive sponsor and a technical owner with authority to approve deviations.

We will produce an architecture decision record for material choices, including region selection, connectivity model and secret management approach. The Client's approval of the decision record constitutes acceptance of those design choices for later implementation phases.

Implementation may proceed in waves. Each wave will have entry and exit criteria. Skipping a wave at Client request may increase risk; we will document residual risk and may require written acknowledgement before continuing.

Guardrails implemented as policy-as-code may block Client engineering teams from insecure actions. The Client is responsible for internal communication of those guardrails. Emergency break-glass procedures must be owned by the Client and tested periodically.

Cost of cloud resources consumed during build and test is borne by the Client as account owner. We will seek approval before enabling services expected to incur material ongoing spend beyond ordinary design work, except where the SOW pre-authorises a spend band.

Identity federation to Client directories may require Client identity team cooperation. Delays in federation are Client dependencies. Temporary local accounts used during bootstrap must be retired according to the runbook we provide.

62. Schedule-style provisions on CDN and edge configuration

Where CDN or edge configuration is in scope, we will document cache key design, time-to-live strategy, origin shielding choices, TLS certificate handling, and WAF or related controls if included. The Client must supply certificate materials or delegate certificate management via approved tooling.

Purge and invalidation rights will be limited to authorised Client personnel and our named operators. Misconfigured purges can increase origin load; the Client accepts operational risk of purge actions it initiates.

Geo-restriction rules and sanctioned territory blocking must be specified by the Client. We implement stated rules; we do not provide geopolitical legal advice on which territories to block.

Log delivery from CDN to Client storage may contain IP addresses and URLs. The Client must configure retention consistent with its privacy notices. We will assist with redaction options where the CDN product supports them and where scoped.

Performance objectives such as cache hit ratio targets are goals measured under agreed methods. Third-party outages, origin failure and sudden traffic spikes may prevent achievement without constituting breach if we have implemented the agreed configuration with reasonable skill and care.

63. Schedule-style provisions on streaming platforms

Streaming platform engagements may include contribution workflows, transcoding ladders, packaging, origin storage, CDN distribution, and player integration advice. Live streaming introduces additional risks around synchronisation, mid-event failures and sudden audience peaks.

The Client must provide accurate forecasts of concurrent viewers where capacity planning is requested. Material underestimation or overestimation may lead to overspend or buffering; change control will address capacity redesign.

Digital rights management systems, watermarking and forensic identifiers, if required, will be specified as third-party products. Integration effort depends on vendor documentation quality. Licence fees for DRM are Client costs unless we expressly resell.

User-generated content moderation tooling is out of scope unless listed. We do not monitor Client media for unlawful content as part of standard infrastructure Services.

Post-event reports, if scoped, will summarise technical metrics available from configured telemetry. Editorial or audience analytics beyond technical delivery metrics require a separate analytics scope.

64. Schedule-style provisions on API programmes

API programme Services may cover style guides, gateway selection, versioning strategy, developer portal fundamentals, authentication patterns and rate limiting. Publishing APIs to third-party developers creates ongoing support obligations for the Client.

We may provide OpenAPI or equivalent specifications as Deliverables. Consumer applications built by third parties against those specifications are outside our control. Breaking changes after public release require Client communication plans.

Load testing of APIs will respect agreed envelopes. The Client must ensure staging environments approximate production sufficiently for meaningful results. Material differences reduce predictive value of tests.

Where monetisation or API product packaging is discussed, our role is technical enablement unless commercial consulting is expressly included. Payment provider agreements remain between the Client and the provider.

65. Schedule-style provisions on DevOps transformation

DevOps transformation may include assessment of current delivery friction, pipeline modernisation, environment strategy, artefact promotion, quality gates and operational readiness. Cultural change within the Client organisation is outside our control; we provide technical enablement and recommended working practices.

Trunk-based or branching recommendations will be tailored to Client team size and risk. We do not mandate a single methodology for all Clients. Adoption depends on Client engineering management.

Quality gates such as mandatory test coverage thresholds can slow delivery if tests are brittle. The Client must invest in test maintenance. We can help design gates; we do not indefinitely maintain Client test suites unless a retainer is agreed.

Platform engineering efforts that create internal developer platforms will define self-service boundaries. Abuse of self-service leading to cost overruns remains a Client governance issue.

66. Schedule-style provisions on cybersecurity consulting retainers

Cybersecurity retainers may include a defined hours bank per month for advisory calls, policy reviews, architecture consultations and incident advisory. Unused hours expire at period end unless the SOW allows limited rollover.

Incident advisory under a retainer is not a full incident response retainer unless severity-based surge terms are included. On-site forensic seizure, law enforcement liaison beyond introductions, and twenty-four by seven SOC operations require separate scoping.

Advice is based on information the Client provides. Concealed systems and shadow IT reduce effectiveness. We may decline to provide written assurance for environments we have not assessed.

Tabletop exercises simulate scenarios. They do not replace technical controls. Participant performance in exercises is Confidential Information of the Client.

67. Client materials and feedback cycles

The Client shall supply materials, decisions and feedback within the periods specified in the project plan. If feedback is not received within ten Business Days of a request or other period in the SOW, we may treat delivered drafts as approved for the purpose of progressing subsequent dependent work, without prejudice to later defect notifications within warranty for latent issues.

Multiple rounds of aesthetic redesign beyond the number stated in the SOW are chargeable. Technical revisions required to meet agreed acceptance criteria within the original scope are included, subject to the Client providing timely, consolidated feedback rather than contradictory comments from multiple stakeholders.

The Client shall appoint a single product owner or equivalent with decision authority to resolve conflicting internal feedback. We are entitled to rely on that person's instructions.

68. Independent contractor status and taxes

WJDIGITAL LTD is an independent contractor. Nothing creates a partnership or agency except for limited agency expressly granted to order cloud resources in the Client's account where documented. Each party is responsible for its own taxes on its income.

The Client shall not deduct employment taxes from our fees. If a tax authority recharacterises the relationship contrary to the parties' intent, the parties shall cooperate in good faith, and the Client shall bear employment-related liabilities arising from its direction and control practices to the extent they caused recharacterisation, except where we misrepresented our status.

69. Conflicts of interest

We will notify the Client promptly if we become aware of a conflict of interest that materially affects our ability to perform objectively. We may propose ethical walls or decline a scope extension. Prior or concurrent work for a competitor in the same industry does not automatically constitute a conflict if Confidential Information is protected, but the Client may raise concerns for discussion.

The Client shall notify us of conflicts on its side, such as competing internal projects that may cancel the engagement, so that we can manage staffing.

70. Ethical hacking authorisation letter

Before any intrusive testing, the Client shall provide a written authorisation letter listing systems owned or controlled by the Client, confirming legal authority to test, and identifying blackout windows. Testing without such letter is not permitted. The Client shall obtain permission from relevant cloud providers where their policies require it.

We will stop testing if unexpected production impact occurs and will notify the Client. Emergency contacts must be reachable during test windows. Findings will be stored securely and transmitted via agreed channels only.

71. Insurance claims and cooperation

If either party seeks to claim under insurance in connection with the Agreement, the other party shall provide reasonable cooperation with factual information, subject to legal privilege and confidentiality owed to other clients. Cooperation time may be chargeable if extensive and the claim does not arise from the cooperating party's breach.

72. Records of processing and DPIA support

Where we act as processor, we will maintain records proportionate to Article 30 UK GDPR processor requirements. Support for Client data protection impact assessments will be provided where scoped, limited to technical descriptions of processing we perform. Legal risk acceptance in a DPIA remains the Client's decision as controller.

If a DPIA concludes that residual high risk requires ICO consultation, the Client leads that consultation. We will supply technical annexes reasonably required and scoped.

73. International Clients and local law overlays

These Conditions are drafted for contracting under English law. If the Client requires mandatory local law clauses for a specific jurisdiction, they must be negotiated as special conditions in the SOW. In the absence of such special conditions, English law and jurisdiction prevail.

The Client is responsible for local filing, language translation of consumer-facing notices, and sector registrations. We can provide English-language technical inputs for the Client's local counsel.

74. Language and interpretation aids

The Agreement is executed in English. Any translation is for convenience only; the English version prevails. Technical terms commonly used in cloud and cybersecurity industries shall be interpreted in their ordinary industry meaning unless defined.

Examples in SOWs are illustrative unless stated as exclusive lists. References to days mean calendar days unless Business Days are specified.

75. Counterparts and electronic signature

The Agreement may be executed in counterparts, including electronic copies, each of which is deemed an original. Electronic signatures and acceptance by authorised email shall be effective as original wet-ink signatures for the purposes of forming the Agreement under the laws of England and Wales, subject to any corporate formalities the Client must observe internally.

76. Further assurance

Each party shall execute documents and take steps reasonably required to give effect to the Agreement, including IP assignments for Foreground IP after payment, and access revocation confirmations at exit. Reasonable cooperation will be provided without additional charge where the step is a simple formality; complex registry filings may be chargeable.

77. Relationship with proposals and marketing materials

Proposals, slide decks, website copy on wjdigital.codes, and marketing case studies are not contractual warranties. Only the SOW and these Conditions define enforceable commitments. If a proposal is attached to a SOW, only the sections expressly incorporated apply, and commercial caveats in the proposal remain in effect.

78. Specific exclusions

Unless expressly included in the SOW, the following are excluded from Services: hardware procurement; software licence resale; physical cabling; carrier circuit contracts; legal opinions; financial audits; guaranteed penetration test scores; continuous twenty-four hour monitoring; content moderation; customer support for the Client's end users; and domain name registrar services.

Excluded items may be added by change control. Performing a small courtesy task does not expand scope permanently or waive the need for change control on subsequent requests.

79. Client reference environments and data quality

The quality of configuration outputs depends on accurate inventories of Client assets. The Client shall provide up-to-date diagrams, inventory exports and access lists. We may rely on them without independent verification beyond reasonable consistency checks unless verification is scoped.

Corrupted or incomplete data sets used in migration rehearsals may cause failed cutovers. The Client should allocate time for data cleansing. We can assist with cleansing strategy where scoped but do not guarantee perfect source data quality.

80. Continuous improvement and retrospectives

We may recommend retrospective sessions after major releases. Actions arising are Client decisions. We will incorporate agreed technical improvements into backlog only through change control if they affect fees or timelines.

Metrics for delivery performance will be shared candidly. Blame-oriented use of metrics against named junior personnel of either party is discouraged; escalation should focus on systemic fixes.

81. Capacity planning and viral events

Clients operating media streaming or high-load web platforms may experience sudden demand. Where capacity planning is in scope, we will model scenarios using Client-provided forecasts and historical telemetry. Models are inherently uncertain. The Client should maintain financial and technical contingency for demand exceeding planned envelopes.

Auto-scaling configurations, where implemented, can increase cloud spend rapidly. The Client must set budget alerts. We are not liable for bill shock arising from legitimate traffic, attacks, or misconfigured scrapers unless caused by our failure to implement an expressly agreed spend guardrail.

Pre-event war rooms, if requested for major launches, will be scoped with staffing hours and decision rights. Advice given under time pressure remains subject to the liability framework in these Conditions.

82. Migration cutover and rollback

Migration Services will include a cutover plan where scoped, identifying sequence, owners, communication points and rollback options. Some migrations cannot fully roll back without data loss once writes have switched; residual risk will be stated.

The Client shall freeze non-essential changes during cutover windows. Changes made by Client teams contrary to the freeze may invalidate the plan and are Client-caused delays.

Dress rehearsals reduce but do not eliminate cutover risk. The number of rehearsals is as stated in the SOW. Additional rehearsals are chargeable.

83. Domain, DNS and certificate operations

DNS changes can render services unavailable if misapplied. Where we perform DNS updates, the Client must confirm ownership of zones and provide registrar or DNS console access. Propagation delay is outside our control.

Certificate renewal automation, where configured, still requires Client monitoring of renewal alerts. Expired certificates caused by Client inaction after handover are not our breach.

CAA records, DMARC, DKIM and related email authentication controls will be implemented only if listed in scope. Email deliverability is influenced by many factors beyond DNS.

84. Logging retention versus storage costs

Extended log retention improves forensics but increases cost and privacy risk. We will present options; the Client selects retention. Implementing the Client's selection with reasonable skill and care discharges our duty even if a later incident suggests longer retention would have helped, provided we advised on the trade-off where scoped.

Immutable logging, where required for integrity, will be configured using product capabilities available in the Client's chosen cloud. Limitations of those products are inherited.

85. Privileged access workstations and supply chain

We may require use of hardened jump hosts or privileged access workstations for production changes. The Client shall not insist on unmanaged personal devices for privileged work if we reasonably object on security grounds.

Software supply chain controls such as artefact signing and dependency scanning will be implemented where scoped. Zero-day vulnerabilities in upstream packages may still appear; response will follow agreed incident processes.

86. Training and enablement beyond handover

Standard knowledge transfer is limited to the sessions in the SOW. Formal curriculum design, certification bootcamps, and ongoing coaching programmes are separate Services. Attendee attendance is the Client's responsibility; unused training seats do not automatically roll to later dates without agreement.

87. Warranties on third-party uptime and credits

Any uptime credits available from cloud or CDN vendors accrue to the Client under the vendor contract. We will assist in assembling claim evidence where scoped. We do not underwrite vendor SLAs and do not pay equivalent credits ourselves unless a managed service schedule expressly creates a pass-through credit mechanism.

88. Confidentiality of pricing and win themes

Our pricing, rate cards, proposals and win strategies are Confidential Information. The Client shall not share them with competing suppliers except under NDA for genuine evaluation of alternatives, and shall not use them to reverse engineer our commercial model for wide dissemination.

89. Step-in rights

If we fail to perform a material managed-service obligation and do not cure within the cure period, the Client may engage a third party to perform the failed obligation at our reasonable cost, limited to the direct incremental cost above our fees for that obligation and subject to the liability cap. Step-in is not available for advisory-only engagements.

90. Set of general commercial undertakings

Each party shall act in good faith in its commercial dealings under the Agreement, without creating a fiduciary relationship. Each party shall comply with lawful directions of regulators applicable to it. Each party shall ensure that its representatives behave professionally toward the other party's staff, without harassment or discrimination.

Abusive conduct toward our personnel may result in suspension of on-site or remote workshops until resolved. We will notify the Client's escalation contact promptly.

91. Extended definitions for technical artefacts

For clarity, "infrastructure as code" means machine-readable definitions used to provision cloud resources. "Runbook" means operational instructions for humans responding to events. "Playbook" may include automated response steps. "Blueprint" means a reusable architecture pattern. These artefacts are Deliverables only when listed as such in the SOW.

Source code Deliverables will be provided via agreed repositories. Commit history may include our engineer identities. The Client shall handle that personal data under its policies when forking repositories.

92. Security questionnaire fatigue and shared assessments

We will complete reasonable security questionnaires proportionate to engagement value. Excessively duplicative questionnaires may be answered by reference to prior responses or industry standard CAIQ-style materials where appropriate. On-site physical audits of our offices require advance scheduling and may be refused where disproportionate to risk.

93. Pandemic and civil contingency adjustments

If government measures restrict travel or on-site work, Services will shift to remote delivery where feasible without being a Client termination event. Additional costs for compliant travel when restrictions lift will be pre-approved. Force majeure still applies to true impossibility.

94. Ethical use and acceptable use of delivered systems

The Client shall not use Deliverables to operate unlawful services, to facilitate computer misuse contrary to the Computer Misuse Act 1990, to distribute malware, or to breach sanctions. We may suspend assistance if we reasonably believe the Client is using our work for unlawful purposes, and may terminate for cause.

95. Notices of claim procedure

Before issuing proceedings, other than for interim relief, the claimant shall send a letter before claim summarising the factual and legal basis and the remedy sought, and shall allow at least fourteen days for a substantive response, consistent with the spirit of the Practice Direction on Pre-Action Conduct where applicable. Failure to do so may be brought to the court's attention on costs.

96. Aggregation of SOWs

Multiple SOWs may exist concurrently under these Conditions. Each SOW is a separate engagement for fees and liability caps unless the parties expressly aggregate them in writing. Confidentiality and IP clauses apply across all SOWs between the same parties.

97. Survival matrix summary

Without limiting other survival language, the following survive termination: accrued payment obligations; intellectual property; confidentiality; data protection; liability and indemnity; non-solicitation; publicity restrictions; governing law; and any licence needed to use already paid Deliverables.

98. Contact for contract queries

Contractual queries about these Terms and Conditions may be directed to WJDIGITAL LTD at service@wjdigital.codes, by telephone on +44 20 7946 0192, or by post to 195-197 Wood Street, London, London, E17 3NU United Kingdom. Please include the SOW reference where applicable. Website visitors seeking only browsing terms should consult the Terms of Service on wjdigital.codes.

99. Acknowledgement of industry risk profile

The Client acknowledges that cloud infrastructure, media streaming, high-load platforms, CDN, APIs, DevOps automation and cybersecurity work involve inherent technical uncertainty, dependency on third-party providers, and residual security risk that cannot be eliminated. Fees and liability caps are set with that acknowledgement in mind. The Client remains responsible for business continuity decisions proportionate to the criticality of its services.

WJDIGITAL LTD will apply reasonable skill and care to reduce risk within the agreed scope, to document material known residual risks, and to recommend prioritised improvements. Ultimate risk acceptance for go-live decisions rests with the Client's authorised approvers.

100. Closing provisions and document control

These Terms and Conditions were last updated on 17 July 2026. We may publish updated standard Conditions on wjdigital.codes for future engagements. Existing signed Agreements remain governed by the Conditions version incorporated at the time of signing unless both parties agree to adopt a newer version.

Related transparency documents include the Privacy Policy, Cookie Policy and Terms of Service. For processor engagements, a data processing schedule should be executed alongside the SOW.

By signing a Statement of Work that references these Terms and Conditions, or by instructing us to commence Services after receiving them, the Client agrees to be bound by this document in full. WJDIGITAL LTD looks forward to delivering clear, reliable connection-oriented technology Services under a fair and comprehensive commercial framework governed by the laws of England and Wales.

If any clause number is reserved or cross-referenced incorrectly due to document editing, the substantive text shall prevail over numbering. The parties shall cooperate to correct clerical errors by written confirmation without reopening commercial negotiation.

101. Detailed change request workflow

A change request should describe the proposed change, reason, impact on scope, impact on fees, impact on timetable, impact on risks, and required Client decisions. We will respond within a reasonable period with acceptance, rejection, or a counter-proposal.

Work performed at Client written direction pending formal change documentation may be invoiced under time and materials. The Client cannot refuse payment for such directed work on the sole ground that a change form was incomplete if the direction was clear and authorised.

Rejected change requests do not themselves terminate the Agreement. If rejection leaves the original scope impossible, the parties shall discuss termination for convenience or a reduced scope amendment.

102. Invoicing examples and milestone logic

Milestone invoices become due on achievement of defined milestone criteria, not merely on calendar date, unless the SOW schedules time-based billing. If the Client delays acceptance unreasonably, milestone criteria may be deemed met after the acceptance window expires.

Retainers are invoiced in advance for each period. Time and materials invoices include a summary of activities. On request, we will map time to epic-level workstreams without disclosing irrelevant internal notes.

103. Subprocessor disclosure for managed services

For managed services involving continuous processing of Client personal data, we will disclose categories of subprocessors and update the Client through the mechanism in the data processing schedule. Objection rights and timelines follow that schedule. Emergency replacement of a failed subprocessor may occur with prompt notice thereafter where necessary to restore service.

104. Business continuity of WJDIGITAL LTD

We maintain internal arrangements to reduce single points of failure in delivery staffing for active engagements. No consultancy can eliminate all continuity risk. Critical Client systems should not rely on a single individual from any supplier, including us. We encourage paired knowledge on Client side.

105. Final interpretive note on service descriptions

Descriptions of Services in marketing language emphasise outcomes such as reliability, clarity and route continuity. In these Conditions, enforceable duties are those expressed as obligations to perform with reasonable skill and care against a defined scope, not metaphorical marketing phrases. The parties agree that technical schedules and acceptance criteria control over slogans.

Final test point: every critical path should remain readable under load.

Navigation index

Home About Services Portfolio Contact

Legal routes

Privacy Policy Cookie Policy Terms of Service Terms and Conditions

Contact data

service@wjdigital.codes

+44 20 7946 0192

195-197 Wood Street, London, E17 3NU United Kingdom

wjdigital.codes

WJDIGITAL LTD

© 2026 WJDIGITAL LTD. All rights reserved.