ITSM Ltd SaaS legal set — Service Schedule
Service Schedule — Martyn's Law Evidence Kit
Version 2.0 · In force from 24/09/2026
Supersedes Service Schedule — Martyn's Law Evidence Kit version 1.4; Refunds and cancellation version 1.1.
This Service Schedule forms part of the agreement between ITSM Ltd and the Client under our SaaS Terms and Conditions (the Terms). It sets out everything specific to the Martyn's Law Evidence Kit, the Service it is for. Under clause 2(c) of the Terms, the clauses of the Terms prevail over this Schedule: this Schedule governs only the matters that a clause of the Terms expressly leaves to it, and nothing in it disapplies or varies a clause of the Terms. Words defined in the Terms have the same meaning here. Because this Schedule follows the words on the Service's screens, it writes ‘organisation’, ‘owner’ and ‘subscription’ in lower case; each means the Organisation, Owner or Subscription the Terms define, whatever its case. This Schedule's divisions are called sections; “clause” always means a clause of the Terms.
The short version
This summary is here to help you read the rest. It is not part of this Schedule and does not change it — where the summary and the sections differ, the sections apply.
- What it is. A record-keeping tool. It is not legal advice, it does not make any premises compliant, and it certifies nothing — section 1.
- What it costs. £9 a month for one premises; £5 per premises a month on the estate plan, from 10 premises up to 150, and by written order above that; or £79 once for a procedure pack for one premises — section 2. Paying annually costs 10 times the monthly price. We are not registered for VAT and add none — section 2(c).
- What you can do without paying. Set up your organisation, its premises profiles and its people, with no time limit and nothing deleted for not paying — section 2(a).
- Is any of it required? Not at standard tier. There the Act asks you to notify the Security Industry Authority and to have public-protection procedures in place, so far as reasonably practicable; writing them down, drilling them and keeping the records this Service produces are good practice — not required at standard tier. The Service is not aimed at the enhanced tier, where you should seek professional advice — section 1(c).
- Refunds. An annual subscription carries a 30-day money-back guarantee. A procedure pack is refunded if you have not generated it or if it is defective, and a consumer has the further rights in section 3(e) — section 3.
- If you stop paying. Clause 8.4 of the Terms is the whole rule. Nothing pauses before the last day to pay in our notice, which is at least 10 Business Days after it — except that the number of premises on an estate plan cannot be changed meanwhile. After that day, recording evidence and generating packs pause until you pay; reading and exporting what you have never do — section 4.
- When it renews. About 30 days before an annual subscription renews, we email you the date and the amount, whether you pay by card or by invoice — section 2.1(v).
- Who can see your key holders' details. The people you invite, and ITSM Ltd's directors by the means listed in section 8(b). Our database and hosting providers hold them, and they appear in exports and in earlier pack versions — section 8(f).
- If you want it all deleted. An owner writes to us and we delete the organisation within 30 days — section 10(b). Export first, choosing the ZIP rather than the PDF on its own if you want your drill photographs too — section 10(a).
1. The Service and its purpose
(a) The Martyn's Law Evidence Kit is a record-keeping tool for premises within scope of the Terrorism (Protection of Premises) Act 2025. It produces public-protection procedure packs for adoption by the responsible person, and keeps the decisions, drills, refresher sessions, incident reviews and annual reviews recorded against them, so that an organisation can show what it did and when it did it.
(b) The Service is not legal advice and does not make any premises compliant. It does not decide which tier a premises falls into — the tier it shows is a guide, as section 1(c) explains — it does not notify the Security Industry Authority on the Client's behalf, and it certifies nothing. Responsibility under the Act rests with the responsible person for the premises and remains theirs. Every document the Service generates carries the words “Template for adoption by the responsible person — not certified advice.”, and clause 12.4 of the Terms says what that means.
(c) Nor is most of what this Service records required. At standard tier (premises where 200 to 799 people may be present) the Act asks two things: notify the Security Industry Authority, and have public-protection procedures in place so far as is reasonably practicable. Documenting those procedures, running drills, holding refresher sessions and keeping the records this Service produces are good practice — not required at standard tier. We sell record-keeping. We do not sell a legal requirement, and nothing in this Schedule should be read as saying you need it to meet your duties. Under the Act, places of worship, and early years, school and further-education premises, stay in the standard tier however many people may be present. The tier checker and every tier shown against a premises are a plain-English guide, not a legal determination. The Service is not aimed at premises in the enhanced tier, and organisations in that tier should seek professional advice.
(d) For this Service, four words used throughout these documents mean the following:
- the Brand is “Martyn's Law Evidence Kit”;
- the Website is this website, on which this Schedule is published;
- a premises is what the Service's screens call a venue; and
- your Records are everything you put in and everything the Service makes from it: your premises profiles (name, type, capacity, address, layout notes, exits, assembly points, key-holder contacts, the record of whether and when the Security Industry Authority was notified, the next review date and the group a premises is in); every version of the procedure packs generated for them; and the decision records, drill logs (walkthroughs, drills, refresher sessions, and incident and near-miss reviews), drill photographs and annual review records kept against them.
(e) The Purpose of this Service, as stated in section A1 of Annex A to the Acceptable Use Policy, is: to record and evidence a premises' public-protection procedures and the decisions, drills, refresher sessions, incident reviews and annual reviews that relate to them.
(f) The legal documents for this Service are published at the addresses below. The Terms, this Schedule and the Acceptable Use Policy are contractual. The Privacy Policy forms part of the agreement only so far as clause 2(b) of the Terms says, and the Cookie Policy not at all; both are otherwise notices. The Website Terms of Use govern the public pages of this website and are not part of the agreement.
| Document | Address | Status |
|---|---|---|
| SaaS Terms and Conditions | /legal/terms-and-conditions | Contractual, with the Client |
| This Service Schedule | /legal/service-schedule | Contractual, with the Client — including the refund terms in section 3 |
| Acceptable Use Policy, with its Annex A | /legal/acceptable-use-policy | Contractual, between us and each User |
| Privacy Policy, with its Annex A | /legal/privacy | A notice; the agreement relies on it only as clause 2(b) of the Terms says |
| Cookie Policy, with its Annex A | /legal/cookies | A notice; not part of the agreement |
| Website Terms of Use, with its Annex A | /legal/terms-of-use | Governs the public pages of this website |
Three things a buyer often asks for by name sit inside these documents. The refund terms are section 3 of this Schedule. Our contact and company details are section A2 of Annex A to the Website Terms of Use, which you can open directly at Contact and company details. The accessibility statement is section A3 of Annex A to the Website Terms of Use, at Accessibility statement.
(g) (Generated documents) For clause 9.2(e) of the Terms, the documents this Service generates are the procedure packs (PDF and Word), the evidence packs (PDF, which can also be downloaded in a ZIP file together with the premises' drill photographs) and the estate roll-ups (PDF). The licence in that clause lets the Client adopt, adapt, print, publish and share them for its own purposes — with its trustees, its insurer, a licensing authority or the regulator, for example. The template wording in them stays ours, and the words “Template for adoption by the responsible person — not certified advice.” must stay on every copy. They are templates for the responsible person to review and adopt, not advice and not a certificate (clause 12.4 of the Terms).
2. Plans, prices and how the Service is bought
(a) (Use without a Subscription) For clause 5.3 of the Terms, an organisation that has bought nothing can, for as long as it exists here:
- create its organisation, which also creates the support-portal account described in section 5(b);
- add, edit and archive premises profiles — with no numerical limit for an organisation set up for one premises, and up to 10 live premises for one set up as an estate (section 2.2(a));
- record that it has notified the Security Industry Authority; and
- invite people and set up groups of premises.
There is no time limit on this, and nothing is deleted because an organisation has not paid or has not been used. Everything else the Service offers comes with a purchase: generating procedure packs (a one-off pack for one premises, or included in a subscription as section 2.2(c) describes); recording decisions, drills, refresher sessions, incident reviews and annual reviews, and the evidence-pack export (an evidence log or estate subscription); the estate roll-up (an estate subscription); and the reminders in section 6(b), which go only to an organisation that holds a live purchase (section 6(c)). Section 2.1(iv) says which of these an unpaid purchase order already gives. The tier checker on this website needs no account at all; section A1.3 of Annex A to the Website Terms of Use describes it.
(b) The Plans for this Service, and its one-off purchase — the things you can buy, which have nothing to do with the standard and enhanced tiers in the Act or with the tier checker — are set out below. An evidence log covers one premises, so an organisation that keeps several premises on evidence logs holds one for each.
| Plan | Covers | Price |
|---|---|---|
| Procedure pack (one-off) | One premises: generating its procedure pack (section 2(d)) | £79, paid once |
| Evidence log — one venue | One premises: decision records, the drill and refresher log, incident and annual reviews, reminders, the evidence-pack export, and procedure-pack generation for that premises once section 2.2(c) allows | £9 a month, or £90 a year |
| Estate | Every premises in the organisation, from 10 up to 150: everything in the evidence log for each of them, the estate roll-up, and procedure-pack generation for each once section 2.2(c) allows | £5 per premises a month, or £50 per premises a year |
(c) These are the whole prices. As clause 8.1(a) of the Terms says, ITSM Ltd is not registered for VAT and adds none: our invoices carry no VAT line and no registration number, and each says so on its face. The price is the same whether you pay by card or by invoice against a purchase order. The estate plan has one rate per premises, with no bands and no thresholds, from 10 premises to 150; above that, section 2(e) applies. Paying annually costs exactly 10 times the monthly price, for every plan that has an annual price. A VAT registration would be a change to the Fees under clause 8.3 of the Terms, as clause 8.1(a) of the Terms says.
(d) (The one-off procedure pack) The procedure pack is a one-off purchase under clause 4(d) of the Terms: paid for once, by card only, never renewed, and working as soon as the payment is complete. It covers generating that premises' pack, and generating it again — after the premises profile changes, for example — as often as needed, for as long as the Term lasts, with no other end date. The current version is always downloadable as a PDF and as a Word document. So is any earlier version that was in force at some point in the last 2 years — one replaced by a later version less than 2 years ago — from the version history on the premises' Procedures page, so that a decision can be read against the pack in force when it was made. An earlier version replaced longer ago than that stays in the record (section 9) but is no longer offered for download. While an organisation holds one, its owners also receive the reminders in section 6(b) (section 6(c)).
(e) (Estates above 150 premises) An estate of more than 150 premises is not bought in the Service. Ask through the enquiry form on the home page or by email. If we go ahead, it is contracted by a written order signed by both parties, stating the number of premises, the price and the Subscription Period. The order is made under the Terms and this Schedule; section 2(b) does not price it, because the order does. Its number of premises is changed by agreement between us. Settings does not stop an owner reducing it to 150 or fewer (though never below the number of live premises), but a change made there moves the whole subscription onto the rate in section 2(b), from the moment it is made, so write to us instead of using it.
2.1 How it is paid for, and who sells it to you
(i) You can pay by card, or — for an annual subscription only — by invoice against a purchase order on 30-day terms, which is how most councils, dioceses and charities need to buy. The one-off procedure pack is paid by card only.
(ii) (Who you buy from, and who we write to) We are the seller however you pay (clause 8.5 of the Terms). Every invoice is made out to your organisation at the billing address held in the Service and, where you give one, quotes your purchase-order reference. The Billing Contact is set when your organisation first buys: the billing email entered on the invoice form or, if none was entered, the email address of the person buying. After that it changes only when a new billing email is entered on the invoice form in Settings, or when an owner writes to us to change it. A card purchase never changes it, and nor does the billing portal.
(iii) (How payment is taken) A card is charged when you buy and at each renewal. An invoice is emailed to the Billing Contact by Stripe on our behalf, with bank-transfer details, and is due 30 days after its date. Refunds are made by us, under section 3.
(iv) (Purchase orders) Either way, what you have bought starts working when we are paid: at once by card, and against a purchase order when its first invoice is paid. On an invoiced subscription the Subscription Period — and so the year you are paying for — starts on the date of that first invoice, not on the day it is paid. The first invoice on a purchase order is governed by clause 8.4(h) of the Terms, which says what happens until it is paid and how you or we may call the order off. While that first invoice is unpaid, an evidence log or estate subscription ordered this way unlocks nothing except two exports, which the Service gives as soon as the order is placed: the evidence-pack export for each premises the order covers and, for an estate subscription, the estate roll-up. They remain available if the order is then called off unpaid, as they do for any subscription an organisation has held (section 10(d)). Every later invoice — a renewal, or more premises — leaves the Service running, and its due date is when Fees fall due for clauses 8.1(c) and 8.4(a) of the Terms.
(v) (Renewing an annual subscription) About 30 days before an annual subscription renews, whether it is paid by card or by invoice — or, where a first period under section 2.1(vi) is shorter than that, within a day of the purchase — we email every owner and the Billing Contact with the renewal date and the amount. It is sent even to an address on the stop list in section 6(b). No notice is sent for a monthly subscription, for one already set to be cancelled, or for one whose last day to pay under clause 8.4(a) of the Terms has passed. A card subscription is then charged to the card on file on the renewal date. On an invoiced subscription, a purchase-order reference entered in Settings before the renewal date is printed on the renewal invoice; if yours arrives after the invoice has gone out, write to us and we will reissue it quoting the reference, with the same due date. If you cancel before the renewal date, it does not renew and nothing is charged or invoiced. On an invoiced subscription, if an owner or the Billing Contact tells us before a renewal invoice's due date that the organisation will not renew, and nothing has been created in the Service since the renewal date, we void that invoice, the subscription ends on the renewal date, and nothing is owed for the Renewal Period — one of the ways clause 4(c) of the Terms lets a Subscription end.
(vi) (Renewing at a financial year end) An estate subscription bought annually, by card or by invoice, and an evidence log bought by invoice, may be set when bought to renew on 31 March or 31 December. An evidence log bought annually by card is not offered this. The first Subscription Period then runs to the next such date and is charged pro rata to it — unless that date is fewer than 14 days, or more than 364 days, after the purchase (the first card payment or, on a purchase order, the date of the first invoice), in which case the first Subscription Period is an ordinary twelve months and renews on its anniversary. Each Renewal Period after it is twelve months (clause 4(b) of the Terms).
(vii) (United Kingdom only) For clause 3(g) of the Terms, this Service is sold only to a Client whose billing address is in the United Kingdom. The Service will not take a purchase until a billing address, with its country set to the United Kingdom, has been entered in Settings.
(viii) (Who may commit the Client) For clause 5.2(b) of the Terms, every owner, and every member with access to the whole organisation, may in the Service buy a Subscription or a one-off pack, change the number of premises, open the billing portal and cancel there, enter a renewal purchase-order reference, and set the billing address — and the Client is bound by what they do. Settings offers none of these to a member scoped to part of the estate, and the Service refuses such a member's request to buy, change the number of premises, open the billing portal or enter a renewal purchase-order reference. The billing address is the exception: it is held on the organisation's own record, which the database lets any member of the organisation change by a request made directly rather than through Settings. An address changed that way is what the check in section 2.1(vii) reads at the next purchase, and from that purchase it is the address the organisation's invoices are made out to.
2.2 Allowances, changing the number of premises, and bundled packs
(a) (Premises allowance) This paragraph applies only to an organisation set up as an estate. The Service will not let you add a premises, or bring one back from the archive, beyond the number of premises your estate subscription covers or — without a live estate subscription — beyond 10 live premises. Archived premises do not count. Nothing extra is charged and nothing is deleted: to go further, increase the number under section 2.2(b).
(b) (Changing the number of premises) Under clause 14 of the Terms, the number of premises on an estate subscription is changed in the Service, from Settings, and not through the billing portal — and only while the subscription is active, so not while a payment is overdue (clause 8.4(a) of the Terms) or before the first invoice on a purchase order has been paid. An increase takes effect immediately and is charged pro rata for the rest of the period already paid for; a decrease takes effect at the next renewal, so the Client keeps the number of premises it has paid for until then, and nothing is deleted. A change re-prices the whole Subscription at the Fees current at the time of the change, as clause 8.3 of the Terms provides — for a decrease, from the moment it is asked for, including the rest of the current period, so that if the Fees have risen since that period was paid for, the difference for the rest of it is charged on the next invoice. The number cannot be set below the number of live premises the organisation already has, or outside the range in section 2(b). From when a decrease is scheduled until the end of the period after it takes effect, the billing portal may not be able to cancel the subscription: write to us and we will cancel it for you.
(c) (When included pack generation starts) An estate subscription includes procedure-pack generation for every premises, and an evidence log includes it for its own premises. It starts at the end of the 30th day after the London date on which we are first paid for an annual subscription — when the money-back window in section 3(a) closes — and at the end of the 90th day for a monthly one. On a purchase order, the days count from when the first invoice is paid. Before then, packs can be bought individually as the one-off purchase in section 2(d). This is so that a subscription cannot be bought for one month, or paid for annually and refunded, just to take the packs — and it is why the money-back guarantee in section 3(a) can be unconditional.
(d) (The business-use confirmation) For clauses 3(b) and 3(c) of the Terms, this Service does not ask for a separate declaration on a separate screen. The confirmation is part of the single tick on the acceptance screen, where the wording says so, and it is stored only as that person's record of accepting the Terms (section 9). We do not ask for a company registration number or a VAT number. That confirmation is a record of what you told us, not a decision about your status: if you were in fact dealing as a consumer, your statutory rights apply in full, as clause 3(c) of the Terms says.
(e) (Changing plan) The Service has no way to move an organisation from one plan to another — between the evidence log and the estate plan, between monthly and annual payment, or from a one-off pack to a subscription — and the billing portal does not offer it. To change plan, buy the new one and cancel the old, as clause 14 of the Terms provides. The Service also offers no way to change an organisation's type, from one premises to an estate or back.
3. Refunds and cancellation
These are the refund terms clause 8.1(b) of the Terms leaves to this Schedule. They change only under section 12. They are written to be read on their own: someone approving a spend should be able to read this section and know what happens if it does not work out.
(a) (The money-back guarantee) An annual Subscription carries a 30-day money-back guarantee, running from the day we are first paid for it: the day of a card payment, or the day an invoice against a purchase order is paid. It covers everything paid for that Subscription within those 30 days — so on a Subscription set to renew at a financial year end under section 2.1(vi), whose first payment covers only the weeks up to that date, it also covers the first full year if that is paid within them. Tell us within the 30 days and we refund it in full. There are no conditions: we will not refuse a refund because of anything done in the Service, because section 2.2(c) holds back included pack generation until the window has closed. When we refund it, the Subscription ends at once — recording and pack generation under it stop — and export continues under section 10(d). A renewal is not covered; it can instead be cancelled before it renews (section 2.1(v)). Monthly Subscriptions and one-off packs do not carry the guarantee.
(b) (No other refund for a change of mind) After the guarantee period, an annual Subscription you cancel continues to the end of the period paid for and then stops; we do not refund part of it. A monthly Subscription can be cancelled at any time, with no notice period and no cancellation fee; it runs to the end of the month already paid for, and we do not refund part of a month. This is subject to section 3(e) and section 3(f), and nothing in this section limits your rights where we are in breach.
(c) (A procedure pack you have not yet generated) If you have paid for a one-off procedure pack and not yet generated it, tell us and we refund it in full. Once it has been generated it is not refundable for a change of mind, because generating it is the delivery — the checkout says so before you pay. Section 3(d) and section 3(e) still apply.
(d) (A defective pack) If a generated pack is wrong — it does not reflect the premises details entered, or it fails to produce a usable document — that is a defect, not a change of mind. Tell us and we will fix it or refund it.
(e) (If you are a consumer) This Service is sold for business and organisational use, and almost everyone who buys it is buying for a village hall committee, a parochial church council, a charity, a council or a business. If you are in fact dealing as a consumer, nothing in this Schedule affects your statutory rights, including any right to cancel a distance contract within 14 days under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013, which sits alongside the 30-day guarantee rather than being replaced by it. A procedure pack you cancel within those 14 days is refunded even if it has been generated, because the checkout does not ask you to request that it be generated straight away or to acknowledge that you would lose the right to cancel. If you cancel a subscription within those 14 days, we refund what you paid in full, because the checkout does not ask you to request that the subscription start straight away.
(f) (Refunds the agreement keeps) In each of these cases the agreement gives you a refund of what you have paid for the unused part of a period, counted pro rata by day, and nothing in section 3(b) takes it away:
- we cancel your Subscription on notice (clause 15.1(c) of the Terms);
- we stop providing the Service (clause 15.1(d) of the Terms);
- you end the agreement because we are in breach of it (clause 15.3(b) of the Terms);
- a change to these documents materially reduces what you receive, and you cancel because of it (clause 19(b) of the Terms);
- you end the affected part of the Service after objecting to a new sub-processor (clause 11.5(c) of the Terms), or to a change to section 11 of this Schedule (clause 11.5(e) of the Terms, and section 12);
- we end the agreement or a Subscription for unpaid Fees, and you have paid more than clause 8.4(g) of the Terms says is owed; and
- we end a Subscription because of a claim that the Service infringes someone else's intellectual property that we cannot otherwise resolve (clause 9.2(c) of the Terms).
(g) (A purchase order you do not go ahead with) An invoiced subscription can end with nothing owed in two further ways:
- before the first invoice on a purchase order is paid, tell us you will not go ahead: we cancel the order and void its invoices, and nothing is owed (clause 8.4(h) of the Terms); and
- if an owner or the Billing Contact tells us before a renewal invoice's due date that the organisation will not renew, and nothing has been created in the Service since the renewal date, we void that invoice and the subscription ends on the renewal date (section 2.1(v)).
(h) (How to claim, who may, how refunds are paid, and how to cancel)
- To claim a refund, write to support@itsm-ltd.com within the period that applies, from the address on the Account of an owner or of a member with access to the whole organisation — the people who may commit the Client under section 2.1(viii). You do not have to give a reason for the money-back guarantee, though we would like to know one.
- Refunds are made by us, by hand, to the method you paid by: to the card through Stripe, which processes our card payments, or by bank transfer for an invoice. We issue a credit note against the invoice. A card refund usually appears within 5 to 10 Business Days; that is the card issuer's timing, not a commitment of ours.
- To cancel a Subscription, an owner or a member with access to the whole organisation uses Manage billing, invoices and cancellation in Settings — shown once the organisation has bought something, and, while a decrease is scheduled, subject to section 2.2(b) — which cancels at the end of the period paid for; or writes to us from the address on their Account, as clause 15.1(a) of the Terms describes. A cancellation by email takes effect when it reaches us, and if it reaches us before the renewal date the Subscription does not renew.
- Changing the number of premises on an estate subscription is not cancelling; it is done under section 2.2(b).
- Questions and complaints about a refund are handled as section A2.4 of Annex A to the Website Terms of Use describes.
4. If you stop paying, or you cancel: what you keep
(a) (Late payment) Clause 8.4 of the Terms is the whole rule for Fees paid late; this paragraph only names what it covers for this Service. The last day to pay in our notice is at least 10 Business Days after the notice (clause 8.4(a) of the Terms), and from the notice the number of premises on an estate subscription cannot be changed. After the last day to pay, what clause 8.4(b) of the Terms allows to pause is: recording decisions, drills, refresher sessions, incident reviews and annual reviews; generating procedure packs under the subscription; the reminders in section 6(b), unless another purchase keeps them going (section 6(c)); and, for an estate, the premises allowance, which falls back to 10 live premises (section 2.2(a)). Never paused: reading your Records; the evidence-pack export and the estate roll-up for what you have paid for; and downloading procedure packs as PDF and Word. A one-off pack bought separately for a premises is not affected, and keeps generating.
(b) The same applies after cancellation or lapse, and nothing is deleted. Creating new evidence is a paid feature; taking out evidence already created is a right. The evidence-pack export and the estate roll-up remain available to an organisation whose Subscription has been cancelled or has lapsed, for as long as its organisation exists here (clause 15.4 of the Terms, and section 10(d)). Section 10(a) says what the export does and does not contain.
5. Support
(a) Support is requested by writing to support@itsm-ltd.com, or through ITSM Ltd's support portal at `support.itsm-ltd.com`, which ITSM Ltd runs in the United Kingdom. The portal is a separate system from this Service.
(b) (The account we create for you) When an organisation is created in this Service, we ask the support portal to create an account for it for one person — the owner who created the organisation or, if that first attempt fails and our daily job has to retry it, the organisation's longest-standing owner at the time of the retry — and the portal sends that person an invitation to set a password there. An organisation created before we began doing this is given an account in the same way by our daily job, for its longest-standing owner at the time. To do that we send the portal only an identifier for the organisation, its name, and that person's email address. No Records are sent, then or ever. What ends up in an enquiry is whatever the person writing it includes, which is why section 5(f) asks you not to paste Records into one. If that email address already belongs to an organisation in the portal — because the same person has set up another organisation here, for example, or already uses the portal for another ITSM Ltd product — the portal cannot create the account automatically, and we set it up by hand.
(c) The Client acknowledges and agrees that, in relation to support enquiries and the support portal:
- (i) enquiries and their contents are held by us as controller under the Privacy Policy. Those in the support portal, and email that has become part of one, are kept for 6 years after the Client's organisation is closed, so that we can deal with a query or a claim about the support we gave, and are then deleted in a yearly review; other email to the support address is deleted 24 months after it arrives, as the Privacy Policy says;
- (ii) an enquiry remains readable to our support staff after the person who sent it is removed from the Client's organisation in this Service;
- (iii) a person holding an account in the support portal for the Client's organisation may be able to see every enquiry raised by that organisation, with the messages and attachments in it, so a portal account should be held only by someone who may see all of them;
- (iv) removing a person from the Client's organisation in this Service does not by itself close their account in the support portal — see the note below;
- (v) a support-portal account is deactivated on the request of an owner of the Client's organisation, which may be made at any time by writing to us. The portal gives this Service no way to do that automatically, so a member of ITSM Ltd's staff does it by hand in the portal; and
- (vi) deleting the Client's organisation in this Service does not delete its support-portal organisation or its support history, which are kept under section 5(c)(i). An owner may ask for them to be deactivated at the same time.
(d) Only one portal account is created automatically. Further people are added to the portal by ITSM Ltd's staff on request; there is no self-service route, and adding a colleague to this Service does not add them to the portal.
(e) Signing in to the support portal is by email address and password, which is a different arrangement from this Service — where there is no password at all. The two accounts are separate: changing one does not change the other.
(f) Please do not paste Records into a support enquiry. Tell us the premises and roughly when something happened and we will find it. Anything you do include is held under section 5(c)(i) rather than under the measures in section A6 of Annex A to the Privacy Policy, and may be readable by anyone in your organisation who holds a portal account.
(g) (No response target and no service level) Support has no response time and no resolution time, and there is no service level agreement: clause 5.6(b)(i) of the Terms applies. Support is the same for every plan, and for an organisation that has not bought anything.
(h) Every email the Service sends itself — reminders, invitations, notices and acknowledgements — carries a reply-to address that reaches the support inbox, so a reply is read by a person. Three kinds of email are not sent by the Service: the sign-in link, which our authentication provider sends; any invoice or receipt emailed to you, which Stripe sends on our behalf; and the support portal's invitation, which the portal sends. To reach us about any of them, write to the support address.
6. Reminders and other email
(a) Sign-in to this Service is by emailed link only. There is no password. Email delivery is therefore the availability of the Service, and an address that cannot receive our mail is an address that cannot sign in. If your organisation filters mail, ask whoever looks after it — before you need to sign in, not after — to allow two senders: our authentication provider, which sends the sign-in links (section 5(h)), and our own sending address, which sends reminders, invitations, notices and acknowledgements.
(b) Besides sign-in links, invitations, the emails in section 6(d) and the notices in section 6(f), the Service sends three kinds of reminder, and only these three:
| What | When | How to stop it |
|---|---|---|
| Annual procedure review reminder | Once for each review date, when the review falls due within 30 days or is already overdue | Use the link at the foot of the reminder, and press the button on the page it opens; or use your mail app's own unsubscribe button, where it shows one; or write to us and we stop it for you. Either way your address goes on the stop list. Other owners still receive it |
| Post-incident prompt | Once, on a daily run within 7 days after an incident or near-miss review is logged | The same: the link at the foot of the prompt, or write to us. Other owners are unaffected |
| Commencement countdown digest | Monthly, on the first day of the month, until the expected commencement date the Service is configured with. A month whose daily run does not happen on the first is not caught up | It is one switch for the whole organisation, in Settings, which any member of the organisation can turn on or off. It goes only to owners. The link in the digest, or a message to us, stops it for you personally |
The stop list is read by the daily job each time it sends these reminders. An address goes on it in one of four ways: from the link in a reminder, which stops that kind of reminder for the address it was sent to once the button on the page it opens is pressed — opening the link on its own changes nothing, so a mail scanner that follows it stops nothing; from a mail app's own unsubscribe button, which these three reminders support through the standard one-click header, and which stops that kind of reminder for that address as soon as it is pressed; by us, by hand, when you reply or write to us; or automatically, for all three reminders, when our email provider reports that a message the Service sent to that address was permanently rejected by the receiving mail server or was marked as spam by its recipient. It stops only these three reminders, never the emails in section 6(d) or the notices in section 6(f). The basis on which each reminder is sent is in section A7 of Annex A to the Privacy Policy.
(c) All three go only to owners of an organisation that holds a live purchase: an active subscription, a one-off procedure pack, or a subscription whose payment is overdue but whose last day to pay under clause 8.4(a) of the Terms has not passed. A colleague who logs the drills does not receive the prompt about them. Because a one-off pack does not expire during the Term, an organisation that has bought one goes on receiving the reminders after any subscription ends; the link in each one stops it for that address, or write to us and we stop them.
(d) The Service also sends two things to people who are not Users: an email repeating the headline of a tier-checker result, where one is asked for, and an acknowledgement of a waitlist registration. A larger-estate enquiry is emailed to us and is not acknowledged automatically — a person replies to it. Beyond those, it sends — or we send — the notices this agreement requires, and these are sent even to an address on the stop list:
- the notice of unpaid Fees that clause 8.4(a) of the Terms requires, sent to every owner and to the Billing Contact and stating the last day to pay, and our written confirmation of any extension under clause 8.4(e) of the Terms;
- the reminders about an unpaid first invoice on a purchase order (clause 8.4(h) of the Terms);
- the renewal notice section 2.1(v) describes;
- any notice under clauses 8.4(f), 15.1(c), 15.1(d) and 15.2 of the Terms;
- the 30 days' notice that clauses 8.3 and 19 of the Terms require; and
- a deletion confirmation under section 10(b).
Receipts and invoices that Stripe sends on our behalf are in the same category.
(e) We do not send product marketing to Users of this Service (clause 11.1(c) of the Terms). The one promotional email we send is the single email telling someone who joined the waitlist, on their consent, that this Service has opened (section A7 of Annex A to the Privacy Policy). We do not pass anyone's details to a third party for their own marketing.
(f) (Changes to someone's access) When an owner saves a change to a person's role or access in Settings, the Service emails that person, naming the organisation, their role and what they can now see — the whole organisation, or the names of the groups and premises granted to them. When an owner removes a person from the organisation, the Service emails them to say that their access has been removed. The email is sent each time a change is saved, even one that alters nothing; a person's first access is announced by their invitation instead. It does not say which owner made the change. It is not a reminder, so the stop list does not apply to it and it carries no link to stop it. If it cannot be sent, the change still takes effect, and the failure is reported to us (section A1 of Annex A to the Privacy Policy).
7. Hosting, data location, backups and sub-processors
(a) Client Data for this Service is stored in the United Kingdom: with Supabase, in London (eu-west-2), for the database, for authentication and for the private store holding drill photographs; and the servers that run the application are Vercel's, in London (lhr1). Two qualifications: the emails described in section 6 carry Client Data through our email provider, namely organisation, group and premises names, a premises' next review date, the date on an incident or near-miss review, the email addresses of the people they are sent to and, in an invitation, of the person who sent it, and a purchase-order reference entered for a renewal; and the recipients listed in section A3 of Annex A to the Privacy Policy process data as that section states, including where they process it.
(b) The complete list of the recipients of personal data for this Service is section A3 of Annex A to the [Privacy Policy](/legal/privacy). It says what each receives, where it processes it, and the legal mechanism relied on for anything that leaves the UK. It is the sub-processor list for clause 11.5 of the Terms — a sub-processor being a company we use to help run the Service, which handles your data on our instructions and not for itself.
(c) Stripe is on that list but is not a sub-processor of Records. It processes card payments for us and raises and sends our invoices, and receives only the billing details needed to do that — never Records. It processes that billing data, which we control under clause 11.1(c) of the Terms, as our processor, and as a controller in its own right for its own purposes, such as preventing fraud and meeting its own legal and regulatory obligations as a regulated financial services provider. The Stripe account is shared with ITSM Ltd's other products. It is described in full in section A3 of Annex A to the Privacy Policy.
(d) (Backups) For clause 5.5(d) of the Terms: our database provider takes a backup of the database every day, and keeps each backup for 7 days before it is overwritten. Whether those backups include the private store holding drill photographs is set by our database provider, so treat the photographs as not backed up. We do not test restoring them. Recovery of any particular item is not guaranteed, so keep your own copies using the exports in section 10(a).
8. Security, staff access and authentication
(a) The security measures for this Service are those in section A6 of Annex A to the Privacy Policy.
(b) (Access by our personnel — clause 11.7 of the Terms) This Service has no staff console inside the application and no feature for signing in as a customer. Our people reach the contents of a Client's organisation held in the Service only through our database provider's administrative console and an administrative database key, both held only by ITSM Ltd's directors. Copies of some Client Data also sit with the other recipients in section A3 of Annex A to the Privacy Policy, and ITSM Ltd's directors, and no one else of ours, can see them through each provider's own account console:
- premises and organisation names, and the dates, in the emails described in section 6, through our email provider's console;
- the error messages and identifiers in error reports and in the application's logs, through our error-reporting and hosting providers' consoles; and
- the organisation's name and billing address, and purchase-order references, through Stripe's dashboard.
Anything a Client or User sends to our support mailbox or support portal, including a reply that quotes one of our emails, is read there. The key could technically be used to create a sign-in link for any Account; it is used only for the purposes listed in this paragraph. The application also uses that key automatically, in its server code, for: the daily reminder job; the payment webhook; setting up the support-portal account when an organisation is created; the three public forms; recording page visits, and the start of a card payment, as section A2 of Annex A to the Privacy Policy describes; stopping a reminder from the link in it; acting on our email provider's reports of rejected mail and spam complaints; finding a person's email address to send the notice in section 6(f); generating a procedure pack, or recording a decision, drill or review, when the Service runs without payments configured; and showing an invitation to the person it was sent to. Our people use the console or the key by hand only to operate the Service, to provide Support at the Client's request, to carry out a deletion or an erasure the Client or a data subject is entitled to, or to investigate a security or availability incident; neither is used to read Records for any other purpose. The same purposes apply to every one of the means listed in this paragraph. Each such use is an instruction to us for clause 11.3(a) of the Terms.
(c) The key is not issued to one individual, and neither the key nor the console is logged by the application: the application does not record its own uses of the key, and the console sits outside it. Our database provider keeps its own platform logs, for 7 days.
(d) What we do record is what we do by hand: every erasure or deletion we carry out by hand under section 9 or section 10 is written down and confirmed to the Client in writing. That is narrower than an access log, and we name the difference so that one is not read as the other.
(e) (Two-step verification — clause 6(c) of the AUP) No customer role in this Service requires two-step verification, because there is no password. Sign-in is by a single-use link sent to the address on the Account, which expires, is spent when it is used, and is cancelled if a newer one is requested. The security of an Account is therefore the security of its mailbox, which is why clause 6 of the AUP asks Users to keep their own mail secure. There is no MFA for customer sign-in.
(f) (Who can see what you record) Four answers, because it is the question we are asked most:
- People you invite. Someone with access to the whole organisation sees every premises; someone you scope to particular premises or groups of premises sees only those. The check is written in the database rather than in the application, so it holds even if the application asks the wrong question.
- Every member's email address is visible to the rest of the organisation, whatever they are scoped to — section A6 of Annex A to the Acceptable Use Policy.
- ITSM Ltd's directors, by the means listed in section 8(b), and only for the reasons listed there.
- The recipients in section A3 of Annex A to the [Privacy Policy](/legal/privacy), each for the purpose stated against it. Key-holder names and numbers are held by our database provider, pass through our hosting provider, and appear in evidence-pack exports and in every version of a procedure pack generated while they were in the premises profile. They are not sent to our email or error-reporting providers, to Stripe, or to the support portal.
9. What the Service will not let you delete — and what we will still remove for you
For clause 11.6 of the Terms and clause 7(c) of the AUP, the records in this Service that cannot be edited or deleted one at a time from inside the Service are:
- decision records, drill and refresher logs, incident and near-miss reviews, and annual review records — the database lets a signed-in person read and add them, and grants nobody a right to change or delete one through the application, ourselves included. A log that can be tidied afterwards is not evidence of anything;
- drill photographs — the store they sit in has no rule allowing one to be changed or deleted. That includes a photograph stored when it was chosen but never attached to a saved entry (section A4 of Annex A to the Acceptable Use Policy);
- each version of a generated procedure pack, which is fixed when it is produced, so that a decision recorded on a given date can be read against the pack in force then (section 2(d) says which versions can be downloaded). A new version is added rather than an old one rewritten, and key-holder details stay in earlier versions after they are edited out of the premises profile. Each version records the Account that generated it, and that link is cleared if the Account is deleted;
- a pack or an export somebody has already downloaded, which has left the Service entirely;
- the record of which legal documents each person accepted, and at which version, which is deleted with that person's Account; and
- an email already sent.
None of this binds us as controller. It describes what the Service will not let a signed-in person do. Where clause 11.6 of the Terms applies, we restrict our processing to what the law requires. If something should never have been recorded — a photograph showing a person who did not agree to be in it, or a name that does not belong in a log — tell your organisation, and tell us. We remove it by hand on the organisation's instruction, or where the law requires, record that we did, and confirm when it is done (section 8(d)). Each entry above is explained in section A5 of Annex A to the Privacy Policy.
10. Exporting, and deleting
(a) (Export, and what it contains) At any time, including after cancellation, an organisation can export as PDFs an evidence pack for each premises covered by an evidence log or estate subscription it has held and, where it has held an estate subscription, a roll-up across its estate. Procedure packs, once generated, download as PDF and Word — the current version of each, and the earlier versions section 2(d) describes — whatever the organisation's payment position. An evidence pack can be downloaded in two ways: as a PDF on its own, which notes that a drill has a photograph but does not contain it; or as a ZIP file holding the same PDF and, in a folder beside it, every photograph attached to a drill log for that premises, each named by the date of its drill and an identifier for the drill, with the PDF naming the file that belongs to each drill. A photograph that was stored but never attached to a saved log is not included. Both include the premises' key-holder list. If a photograph cannot be read from our store when the ZIP is made, it is left out, the failure is reported to us, and the PDF inside says against that drill that its photograph could not be included — download the ZIP again, or write to us. On an owner's request we will also send the Client its Records as CSV files, and its drill photographs, free of charge, within 30 days — which is how to get a copy another system can read.
(b) (Deletion) For clause 15.1(b) of the Terms: this Service has no self-service way to delete an organisation. An owner asks us in writing, from the address on their Account, and we delete the organisation and everything in it — including the photographs — using the administrative access in section 8(b), within 30 days, and confirm in writing when it is done. Where no owner remains, anyone who can show they are authorised to act for the Client may ask, and we verify that authority before acting. Deletion is permanent, so export first. This is also how we meet clause 11.3(g) of the Terms at the end of the agreement.
(c) (What deletion does not reach) Deleting an organisation does not delete:
- (i) its support enquiries and support-portal organisation (section 5(c)(i) and section 5(c)(vi)), and the billing records we must keep, each kept for the period in section 11.4 and then dealt with as that section describes;
- (ii) the sign-in Accounts of its people, and each person's record of which legal documents they accepted, which belong to the person rather than the organisation, because one person can be in more than one organisation — they are deleted when that person's Account is deleted, which we do on request;
- (iii) the stop list in section 6(b), kept as section A4 of Annex A to the Privacy Policy describes; and
- (iv) the sent-reminders record, which stops a reminder or notice going twice, holds identifiers and dates only, has no database link to the organisation, and is kept as section A4 of Annex A to the Privacy Policy describes.
Nor does it reach: submissions through the public forms on this website — the tier checker, the larger-estate enquiry and the waitlist — which we hold as controller and delete after 24 months, with the IP address cleared after 7 days (section A4 of Annex A to the Privacy Policy); emails already sent; the emails in our support mailbox, including the copies of enquiries and waitlist registrations forwarded to it; or copies held in our email, error-reporting and hosting providers' logs, which they keep for their own periods. Backups taken before the deletion are overwritten within 7 days (section 7(d)). From the moment of deletion that data is put beyond use — it is not restored, searched or used for any purpose, and if a backup were ever restored the deletion would be reapplied to it immediately.
(d) (How long export lasts) An organisation that has ever held an evidence log or estate subscription can sign in and export its own evidence for as long as its organisation exists here, however long ago it cancelled (clause 15.4(a) of the Terms). Only deletion under section 10(b), or the end of the Service under clause 15.1(d) of the Terms, ends it.
11. Data processing particulars (Article 28(3) UK GDPR)
This section sets out the particulars Article 28(3) of the UK GDPR requires — the list the law says a contract like this must contain. It is the Client's documented instruction to us for clause 11.3(a) of the Terms. Most of it is here for your insurer, your auditor or a funder who asks for it; section 11.5 and section 11.8 are the two parts that describe what is held and what you are responsible for.
11.1 Subject matter
Our provision of the Service to the Client under the agreement: a record of the Client's premises and their public-protection procedures, together with the decisions, drills, refresher sessions, incident and near-miss reviews and annual reviews recorded against them, the documents generated from them, and the reminder and export functions that go with them.
11.2 Nature of the processing
In ordinary words: we store what you type, make documents out of it, email you about it, and let you export it. In the words Article 28(3) asks for: collection, recording, organisation, structuring, storage, retrieval, use, generation of documents (PDF and Word), transmission by email, production of exports, restriction, erasure and destruction — carried out electronically and, other than where a person at the Client acts through the Service, automatically.
11.3 Purpose of the processing
The Client's purpose: to record and evidence a premises' public-protection procedures and the decisions, drills, refresher sessions, incident reviews and annual reviews that relate to them, so that the Client can show what it did and when — to its trustees, its insurer, a licensing authority or the Security Industry Authority. We process Client Data for that purpose and no other. We process it for no purposes of our own, except the limited controller purposes in clause 11.1(c) of the Terms, as section 10(c) and section 11.7 describe; we do not use it to train any model; we do not derive statistics, benchmarks or product insight from the contents of Records; and we do not disclose it other than as clause 11 of the Terms permits.
11.4 Duration of the processing
For the Term, and afterwards only as follows:
- the Client's Records are kept for as long as the Client's organisation exists here — including after a Subscription is cancelled or lapses, because the export right in section 10(d) depends on them — and deletion under section 10(b) ends our keeping of them, except for the copies section 10(c) says deletion does not reach: backups, which are overwritten within 7 days (section 7(d)) and are never restored without the deletion being reapplied; emails already sent; our support mailbox; and our providers' logs, each kept as that section describes. Nothing deletes them on a timer. Clause 11.3(g) of the Terms gives the Client the choice of deletion or return at the end of the agreement, and section 10(b) is how it makes that choice — at any time, in one email, carried out within 30 days;
- support enquiries are kept for 6 years after the Client's organisation closes, and are then deleted in a yearly review (our data as controller, stated here for completeness);
- the record of which legal documents a person accepted, and at which version, is kept for as long as that person's Account exists and is deleted with it (our data as controller); and
- billing records are kept for 6 years after the last invoice, to meet accounting and tax obligations, and then removed from our billing account in a yearly review, as far as our payment provider allows (our data as controller).
11.5 Categories of personal data
- (a) the names, roles and contact details of the Client's Personnel and Users where the Client records them in a premises profile or in its Records;
- (b) key-holder and responsible-person contact details recorded against a premises — role, name and telephone number, entered by the Client — including the copies of them in procedure-pack versions and exports;
- (c) the contents of the Client's Records — decision records (including who decided, who took part and what was weighed), drill and refresher logs (including who took part and what was practised), incident and near-miss reviews, and annual review records, all of which are free text, including the names typed into them, and may name or describe any individual; and
- (d) drill photographs, which may show identifiable people and the interior of premises.
11.6 Categories of data subject
- (a) the Client's Personnel and Users;
- (b) key holders, trustees, wardens, volunteers and others named in a premises' contacts or in the contents of its Records — who may include the Client's Personnel, its volunteers, its contractors and members of the public; and
- (c) individuals appearing in a drill photograph.
11.7 What this section does not cover
These particulars describe only the personal data we process on the Client's behalf. We are the controller, and not the Client's processor, of: each person's sign-in Account and session; each person's membership of an organisation and the invitations sent to them — the email address, role and access held for each; billing data, including the Billing Contact, the billing address and any purchase-order reference; the support-portal account, including the details sent to set it up (section 5(b)), and support enquiries; the records of which legal documents each person accepted; and submissions through the public forms on this website — the tier checker, the larger-estate enquiry and the waitlist — with the IP address kept for 7 days for rate limits; the stop list in section 6(b); the sent-reminders record in section 10(c); and the count of visits to the Website's public pages described in section A2 of Annex A to the Privacy Policy. Our purposes and lawful bases for that data are in section 7 of the Privacy Policy, and nothing in this section is an instruction from the Client about it. Where a person's data appears in both places, each of us answers for the processing it carries out in its own role.
11.8 Obligations and rights of the Client
Clause 11 of the Terms sets out what the Client is responsible for as controller. If the Client buys the Service for premises that another body runs — a diocese for its parishes, or a council for halls run by their own committees — the Client is still the controller whose instructions we follow under this agreement; whether that other body is also a controller of what is recorded about its premises is for the two of them to settle, and where they are joint controllers the Client is responsible for the arrangement between them that Article 26 of the UK GDPR requires. In plain terms, the Client is responsible for five things:
- Telling us what to do with the data. Accepting these documents is that instruction; the Client can give us others in writing.
- Having a lawful reason for what it records. Most of it is straightforward. Two things are not: an incident or near-miss review describing someone's health or conduct, and a photograph showing an identifiable person. Those may need a condition under Article 9(2) of the UK GDPR and, where that condition requires it, a condition in Schedule 1 to the Data Protection Act 2018, with an appropriate policy document meeting Part 4 of that Schedule where the condition requires one; and for anything about a criminal offence or alleged offence that is not processed under the control of official authority, a condition in Part 1, 2 or 3 of Schedule 1 to that Act, because section 10(5) requires it. Clause 11.2(f)(i) of the Terms sets the whole list out. If in doubt, the simplest answer is usually to photograph the room rather than the people in it, and to write up what happened without describing anyone's health or naming anyone as suspected of an offence.
- Answering people who ask about its records. If somebody asks why they appear in a decision record or a drill log, that question is for the Client, not for us. We will help it answer.
- Telling people it has recorded them, as Articles 13 and 14 require — in particular key holders, whose names and numbers the Client enters and we never see anyone enter, and people who appear in a drill photograph. Article 14 is usually the operative one, because those details come from the organisation rather than from the person. A line in committee minutes saying whose contact details are held, and why, usually covers it. The recipients list such a notice needs is section A3 of Annex A to the Privacy Policy.
- Carrying out a data protection impact assessment where Article 35 requires one — likely for a large estate, for premises used by children, or where incident reviews describe health or conduct — and keeping its own record of processing under Article 30(1), for which sections 11.1 to 11.6 may be used directly.
The Client's rights under clause 11 of the Terms include: giving and varying its instructions; requiring us to delete or return personal data at the end of the agreement (clause 11.3(g) of the Terms, and section 10(b)); our assistance with data subject requests, security, breach notification and impact assessments (clause 11.3(e) of the Terms); objecting to a new sub-processor, or to a change to section 11, and, if the objection cannot be resolved, terminating with a refund (clauses 11.5(c) and 11.5(e) of the Terms); having personal data transferred out of the United Kingdom only as clause 11.3(d) of the Terms allows; and auditing our compliance with clause 11 (clause 11.3(h) of the Terms).
Assistance that is needed only because of how this Service is built is free. Removing or amending a record the Service does not let the Client remove itself, and deleting the organisation, are the obvious cases. Clause 11.3(e) of the Terms leaves this to this Schedule: we will not charge for those, and we will tell the Client before charging for anything else.
11.9 Our records, and audits
We make available to the Client the information necessary to show that we meet our obligations under clause 11 of the Terms, and allow for and contribute to audits, as clause 11.3(h) of the Terms provides. For this Service most of that information is in this Schedule and in section A6 of Annex A to the Privacy Policy; a request for anything more is dealt with under that clause.
12. Changes to this Schedule
We may change this Schedule. The current version is always the one published at this address, and it shows its version number and the date it came into force. We give at least 30 days' notice of any change, in the same way as clause 19 of the Terms. A change to the price of an existing Subscription is governed by clause 8.3 of the Terms.
Under clause 11.5(e) of the Terms, a change to section 11 is treated as a change of sub-processor, because section 11 is the Client's own documented instruction to us and a processor should not be able to rewrite its controller's instructions by notice: we give at least 30 days' notice of it by email, the Client may object on reasonable data protection grounds within that period, and if we cannot resolve the objection it may terminate the affected part of the Service without penalty and with a refund of Fees paid for its unexpired part (clause 11.5(c) of the Terms).
The refund terms are section 3 of this Schedule, and they change only under this section. A change to this Schedule cannot change a clause of the Terms: this Schedule governs only the matters that a clause of the Terms expressly leaves to it.