Last updated: 23 July 2026. View change log.
This Master Services Agreement (“Agreement”) sets out the general terms on which Cultrix Limited (“Cultrix”, “we”, “us”) provides IT services to you, the customer named in the relevant order, quotation or statement of work (“you”, “your”).
The details of each service – what it covers, what it does not, the service levels and how it works in practice – are set out in the relevant Service Schedules. Those Schedules form part of this Agreement.
1. Structure of this Agreement
- This Agreement is made up of:
- this Master Services Agreement – IT;
- the Service Schedules that apply to the services you buy, which may include:
- Schedule 1 – IT Support;
- Schedule 2 – Patch Management;
- Schedule 3 – Monitoring & Alerting;
- Schedule 4 – Cloud Productivity Platform Administration and Licensing;
- Schedule 5 – Backup and Recovery;
- Schedule 6 – Endpoint Protection and Security Services;
- Annexes, which may include:
- Annex A – Service Level Agreement (SLA);
- Annex B – Acceptable Use Policy (AUP);
- Annex C – Shared Responsibility Model;
- Annex D – Fair Use Policy (FUP);
- any order form, online checkout confirmation, quotation or statement of work we agree with you (each an “Order”).
- If any part of this Agreement conflicts with another, the order of priority is:
- the applicable Order;
- the relevant Service Schedule;
- Annexes A–D;
- this Master Services Agreement.
Not every service described in a Service Schedule will apply to you. You only receive the Services included in your Order.
The Cultrix Common Terms (published at cultrix.co.uk/legal/common-terms) form part of this Agreement. They cover confidentiality, liability, governing law, notices, events beyond our control, changes and subcontracting. Where the Common Terms conflict with this Agreement, a Schedule or an Order, the more specific document prevails.
2. Definitions
In this Agreement:
- “Business Day”
- Monday to Friday, excluding English bank holidays.
- “Business Hours”
- 08:30–17:30 UK time on a Business Day, unless we say otherwise.
- “Devices”
- Desktops, laptops, servers and endpoints recorded in our asset records for a Service.
- “Endpoint Protection”
- Our collective term for the security and continuity services that relate to physical devices, including (but not limited to) antivirus, EDR, ransomware protection, DNS filtering, SOC monitoring, and endpoint backup and continuity services.
- “Guardian”
- A support package that includes Support + Shield plus RocketCyber Security Operations Centre (SOC) services.
- “Managed Services”
- The ongoing, recurring services we provide under this Agreement.
- “Modular Activation”
- Your ability to switch individual security components on or off within Shield, Support + Shield, Guardian or User Protection, whether you buy them as a package or on their own.
- “Service Desk”
- Our support team and ticketing system.
- “Services”
- Any services we provide under the relevant Schedule(s) and Order(s).
- “Shield”
- Our managed security stack, made up of Antivirus, Endpoint Detection and Response, Ransomware Protection and DNS Filtering. You can buy Shield on its own or as part of a Support package.
- “Support + Shield”
- A support package that includes Shield and enhanced Service Desk cover, including Security Policy Management, Out-of-Hours Urgent Support at no extra charge, and management of VOIP phones, mobiles and tablets.
- “Third-Party Services”
- Software, platforms or infrastructure provided by third parties (for example Microsoft 365 or other external software, hosting, monitoring or security services).
- “User Protection”
- A suite of cloud-security services (including Cloud Backup, Cloud Threat Detection & Response, Dark Web Monitoring, Email Security, and Phishing Awareness Training) that you can buy as a package or as standalone components.
3. Term, renewal and termination
- A Service starts on the start date in the Order, or when we begin providing it.
- Unless we say otherwise, each Service has a minimum initial term of 12 months.
- After the initial term, a Service continues on a rolling monthly basis until it is cancelled.
- You may cancel by giving us at least 30 days’ written notice, subject to any minimum terms.
- We may end the Agreement if you materially breach it, become insolvent, or fail to pay on time.
- When a Service ends:
- you must pay all outstanding charges;
- we will stop providing the affected Services;
- we will help with a reasonable, orderly handover on a time-and-materials basis.
4. Our responsibilities
- We will provide the Services with reasonable skill and care.
- We will run our systems in line with our internal Information Security Management System.
- We will use reasonable efforts to meet the targets in Annex A (SLA).
- We will keep you informed of any material issues that affect your Services.
4A. Platform support & limitations
The Services depend on installing and running our management, monitoring and security tools, including remote monitoring and management (RMM) agents and related software. The details of platform support, what our software can manage, and any limitations (including supported Windows, macOS and Linux versions, limits on Linux desktop support, compatibility notes for Windows-on-ARM/Prism emulation, and constraints that affect third-party application patching) are set out in the relevant Service Schedule. These details may change as platform vendors and tool providers update their requirements. Where a platform or version falls outside supported parameters, we may limit support for the affected device or system until you put things right.
5. Your responsibilities
- Give us the access, information and approvals we reasonably need.
- Make sure your staff cooperate with us and follow reasonable instructions.
- Maintain suitable power, connectivity and licensed software.
- Follow the Acceptable Use Policy, Fair Use Policy and Shared Responsibility Model.
- Meet your obligations around user management, licensing and backups where they apply.
5A. Services not purchased and residual risk
We are not responsible for preventing, reducing or recovering from security incidents, data loss or downtime where the relevant security, backup or business continuity service is not in your Order. Where you choose not to buy a service we recommend, you accept the risks that go with it for the affected systems and data.
5B. Customer-caused incidents
We are not responsible for service interruptions, faults, system behaviour or data loss caused by your actions, including (but not limited to):
- changes you make using administrative or elevated permissions;
- installing, removing or changing software;
- altering configuration or security settings;
- replacing or reconfiguring routers, firewalls or network equipment;
- using unsupported hardware, operating systems or services.
Any investigation or remediation needed because of an incident you or your users cause is treated as chargeable consultancy and is not subject to SLA response or resolution times. Giving staff administrative access means you accept the risks that come with it.
6. Access, tools and changes to your environment
- You allow us to install our remote access, monitoring, security and backup tools on in-scope devices.
- Remote sessions may be logged or recorded.
- You must not remove or disable our tools without our agreement.
- Where configuration changes (for example policies, security baselines or firewall rules) are needed to deliver a Service, we will apply them carefully and plan them with you where practical.
6A. Out of scope and project-only work
The following work is always delivered as a project. It is not included in any support package unless we say so expressly in a separate Statement of Work:
- network segmentation;
- firewall configuration and logging;
- Zero Trust architecture;
- Privileged Access Management setup;
- device encryption rollout;
- MDM or BYOD setup and policy creation;
- Microsoft Secure Score improvement (“Fortify”);
- security hardening or compliance alignment (CE/CREST/PCI/DORA/ISO);
- any migration activities;
- office moves, new office setups or relocations.
7. Third-Party Services
- You must comply with the terms of any relevant third party (for example platform, hosting, software or infrastructure providers).
- We are not responsible for the design or availability of Third-Party Services, but we will help you manage issues where this is in scope.
- Changes made by third parties may affect how we deliver the Services. We will act reasonably to adapt, and we will discuss any material impact with you.
8. Data protection
- Each of us will comply with applicable data protection laws.
- Whether we act as controller or processor depends on the situation, as set out in our Privacy Policy and Shared Responsibility Model.
- Where we process personal data as your processor, our Data Processing Agreement applies.
- We will put in place appropriate technical and organisational measures to protect personal data.
9. Security
- We run an information security framework aligned with recognised standards such as ISO 27001 and Cyber Essentials.
- Security-related Services (for example EDR, SIEM, vulnerability scanning or SaaS threat detection) are set out in the relevant Schedule.
- No system can be perfectly secure. We will take proportionate steps to manage security and respond promptly to incidents.
10. Charges, invoicing and payment
- Charges are set out in the Order and/or the relevant Schedule.
- Recurring fees are invoiced monthly in advance unless we agree otherwise.
- Time-and-materials work is invoiced in arrears.
- Payment terms are 30 days from the invoice date.
- If you dispute an invoice, you must tell us before the due date. You must still pay any amounts that are not in dispute.
- If you fail to pay and there is no genuine dispute, we may charge interest and/or suspend the Services.
11. Suspension
- We may suspend the Services if:
- you fail to pay after a reminder;
- you breach this Agreement or the AUP;
- your environment poses an immediate security risk;
- a third-party supplier requires suspension.
- We will act reasonably and will normally contact you before we suspend, unless the risk is urgent.