Client Service Agreement 

Client Service Agreement

Project Terms

By accepting a quotation from Ross & Sons Digital, the client agrees to the following terms.

Quotations

All quotations remain valid for 30 days unless otherwise stated.

Deposits

Projects may require a deposit before work commences.

Typical payment structure:

  • 50% Deposit

  • 50% Upon Completion

For larger projects, staged payments may apply.

Scope of Work

The agreed quotation defines the project scope.

Any additional work requested outside the agreed scope may incur additional charges.

Client Responsibilities

The client agrees to provide:

  • Content

  • Images

  • Branding materials

  • Access credentials

  • Feedback and approvals

Delays in providing required information may impact project timelines.

Ownership

Upon full payment, ownership of completed website or application assets created specifically for the client will transfer to the client unless otherwise agreed.

Ross & Sons Digital retains ownership of:

  • Proprietary tools

  • Development frameworks

  • Reusable code libraries

  • Internal processes and methodologies

Maintenance

Unless covered by a maintenance agreement, ongoing updates and support are not included following project completion.

Hosting and Domains

Hosting, domains, software subscriptions, third-party integrations, and cloud services may incur separate recurring charges.

Limitation of Liability

Ross & Sons Digital shall not be liable for indirect, consequential, or financial losses resulting from the use of delivered services.

Cancellation

If a project is cancelled after work has commenced, Ross & Sons Digital reserves the right to invoice for work completed up to the cancellation date.

Governing Law

This agreement shall be governed by the laws of England and Wales.

Website Maintenance Agreement

Website Maintenance Agreement

Last Updated: June 2026

1. Agreement Overview

This Website Maintenance Agreement ("Agreement") sets out the terms under which Ross & Sons Digital provides ongoing website maintenance, support, monitoring, and related services to its clients.

This Agreement applies to all clients who subscribe to a website maintenance or support plan provided by Ross & Sons Digital.

2. Purpose of Maintenance Services

The purpose of website maintenance is to ensure that your website remains secure, functional, up-to-date, and operating efficiently.

Maintenance services are designed to minimise downtime, improve security, and help maintain optimal website performance.

3. Services Included

Depending on the selected maintenance package, services may include:

Website Updates

  • Content Management System (CMS) updates

  • Plugin and extension updates

  • Theme updates

  • Compatibility checks

Security Monitoring

  • Security scans

  • Malware monitoring

  • Vulnerability assessments

  • Security patch implementation

Website Backups

  • Scheduled backups

  • Backup retention management

  • Restoration assistance where applicable

Performance Monitoring

  • Website uptime monitoring

  • Speed and performance checks

  • Error identification and reporting

Technical Support

  • Troubleshooting website issues

  • Technical advice

  • Minor content updates (where included within the selected package)

4. Exclusions

Unless specifically included within the selected support package, maintenance services do not include:

  • Website redesigns

  • New page creation

  • New functionality development

  • E-commerce product uploads

  • Copywriting services

  • SEO campaigns

  • Branding services

  • Photography or graphic design

  • Third-party software licensing costs

  • Recovery from client-caused damage or unauthorised modifications

Additional work outside the scope of the maintenance plan may be charged at our standard hourly rates.

5. Client Responsibilities

The client agrees to:

  • Provide accurate information when reporting issues.

  • Maintain secure access credentials.

  • Notify Ross & Sons Digital of any suspected security incidents.

  • Avoid making unauthorised modifications that may affect website functionality.

  • Maintain valid licences for any third-party software or services where required.

6. Response Times

Ross & Sons Digital will make reasonable efforts to respond to support requests within the following target times:

Priority Target Response Time Critical Website Outage Within 4 Business Hours High Priority Issue Within 1 Business Day Standard Support Request Within 2 Business Days General Enquiry Within 3 Business Days

Response times are targets and not guaranteed service-level commitments unless otherwise agreed in writing.

7. Emergency Support

Emergency support outside normal business hours may be available and may incur additional charges unless included within a premium support package.

8. Third-Party Services

Ross & Sons Digital is not responsible for delays, outages, or failures caused by third-party providers, including:

  • Hosting providers

  • Domain registrars

  • Cloud service providers

  • Payment gateways

  • API providers

  • Email service providers

We will, where possible, assist in liaising with third-party providers to resolve issues.

9. Backups and Data Recovery

Whilst backups may be performed as part of the maintenance service, Ross & Sons Digital cannot guarantee recovery of all data in every circumstance.

Clients remain responsible for maintaining independent copies of critical business data where appropriate.

10. Security

Ross & Sons Digital will implement reasonable security measures and best practices. However, no website can be guaranteed to be completely secure.

We shall not be liable for breaches resulting from:

  • Weak passwords

  • Compromised client devices

  • Third-party vulnerabilities

  • Social engineering attacks

  • Actions taken by unauthorised users

11. Fees and Payments

Maintenance services are provided on a monthly or annual subscription basis.

Fees must be paid in accordance with the selected package and payment schedule.

Failure to make payment may result in suspension of maintenance services.

12. Cancellation

Either party may terminate this Agreement by providing at least 30 days' written notice.

Any fees due up to the termination date remain payable.

No refunds will be provided for partially used billing periods unless required by law.

13. Limitation of Liability

Ross & Sons Digital shall not be liable for:

  • Loss of profits

  • Loss of revenue

  • Loss of business opportunities

  • Loss of data

  • Indirect or consequential losses

Our liability shall be limited to the fees paid by the client for maintenance services during the preceding 12 months.

14. Amendments

Ross & Sons Digital reserves the right to amend this Agreement from time to time. Updated versions will be published on our website and become effective upon publication.

15. Governing Law

This Agreement shall be governed by and interpreted in accordance with the laws of England and Wales.

Any disputes arising under this Agreement shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Contact Information

For support requests, account enquiries, or questions regarding this Agreement, please contact Ross & Sons Digital using the contact details available on our website.


By subscribing to a maintenance plan or requesting website maintenance services from Ross & Sons Digital, you acknowledge and agree to the terms of this Website Maintenance Agreement.

Refund & Cancellation Policy

Refund & Cancellation Policy

Last Updated: June 2026

1. Introduction

This Refund & Cancellation Policy outlines the terms governing project cancellations, refunds, recurring services, and support agreements provided by Ross & Sons Digital.

By engaging our services, you agree to the terms set out in this policy.

2. Project Deposits

To secure project commencement, Ross & Sons Digital may require a deposit before any work begins.

Unless otherwise agreed in writing:

  • All deposits are non-refundable.

  • Deposits secure project scheduling, resource allocation, planning, and initial development work.

  • Work will not commence until the required deposit has been received.

3. Project Cancellations

Cancellation Before Work Begins

If a project is cancelled before any work has commenced, Ross & Sons Digital may, at its sole discretion, offer a partial refund of any payments received, less any administrative or planning costs already incurred.

Cancellation After Work Has Commenced

If a project is cancelled after work has begun:

  • The client will be invoiced for all work completed up to the cancellation date.

  • Any outstanding balances become immediately payable.

  • Deposits already paid will not be refunded.

  • Any completed work remains the property of Ross & Sons Digital until all outstanding invoices have been paid in full.

4. Website Development Projects

Website development projects involve planning, design, development, testing, and consultation.

As these services are bespoke and created specifically for the client:

  • Refunds are generally not available once development work has commenced.

  • Any refund requests will be considered on a case-by-case basis.

  • Project milestones already completed remain chargeable.

5. Mobile Application Development

Mobile application development services are customised and involve substantial time and technical resources.

Once development has commenced:

  • Payments made are non-refundable.

  • Completed development stages remain chargeable.

  • Any intellectual property rights remain with Ross & Sons Digital until full payment has been received.

6. AI, Automation, and Consultancy Services

Consultancy, AI implementation, automation design, strategy sessions, and advisory services are delivered based on professional expertise and time invested.

As such:

  • Fees for completed consultancy services are non-refundable.

  • Scheduled workshops or consultations cancelled with less than 48 hours' notice may be charged in full.

7. Hosting Services

Website hosting, cloud hosting, email hosting, and infrastructure services are billed in advance.

Unless otherwise stated:

  • Hosting fees are non-refundable once a service period has commenced.

  • Clients may cancel hosting services by providing at least 30 days' written notice.

  • Services will remain active until the end of the paid billing period.

8. Maintenance & Support Plans

Maintenance and support agreements may be cancelled at any time by providing 30 days' written notice.

Where a monthly support agreement exists:

  • Charges already invoiced remain payable.

  • No partial refunds will be provided for unused portions of a billing cycle.

  • Support services will continue until the cancellation date.

9. Domain Names and Third-Party Services

Domain registrations, SSL certificates, software licences, cloud subscriptions, API services, and third-party products purchased on behalf of a client are generally non-refundable.

Any refunds are subject to the terms and policies of the respective third-party provider.

10. Exceptional Circumstances

Ross & Sons Digital may, at its sole discretion, offer goodwill refunds or credits in exceptional circumstances.

Any such refund does not create an obligation to provide refunds in future cases.

11. Service Suspension

Ross & Sons Digital reserves the right to suspend services where:

  • Invoices remain unpaid.

  • The client breaches contractual obligations.

  • The client violates our Terms and Conditions or Acceptable Use Policy.

Any suspension does not entitle the client to a refund.

12. Consumer Rights

Nothing in this policy affects any statutory rights available to consumers under applicable UK consumer protection legislation.

13. Changes to this Policy

Ross & Sons Digital reserves the right to amend this Refund & Cancellation Policy at any time. Any updates will be published on our website and take effect immediately upon publication.

14. Contact Information

For questions regarding cancellations, refunds, or billing matters, please contact Ross & Sons Digital using the contact details provided on our website.


By purchasing or engaging any services from Ross & Sons Digital, you acknowledge that you have read, understood, and agree to this Refund & Cancellation Policy.

Acceptable Use Policy

Acceptable Use Policy

Last Updated: June 2026

1. Introduction

This Acceptable Use Policy ("Policy") sets out the rules governing the use of Ross & Sons Digital's website, services, software, applications, hosting environments, cloud platforms, AI solutions, and any related digital services.

By accessing or using our services, you agree to comply with this Policy.

2. Lawful Use

You must use our website and services only for lawful purposes and in accordance with all applicable laws and regulations.

You agree not to use our services in any way that may harm Ross & Sons Digital, its clients, partners, systems, reputation, or other users.

3. Prohibited Activities

Users must not:

  • Engage in any unlawful, fraudulent, or deceptive activity.

  • Upload, transmit, or distribute malicious software, viruses, ransomware, spyware, or harmful code.

  • Attempt to gain unauthorised access to systems, servers, networks, databases, or user accounts.

  • Circumvent security measures or authentication controls.

  • Interfere with the operation, performance, or security of our services.

  • Conduct denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks.

  • Use our services to distribute spam, unsolicited marketing communications, or phishing messages.

  • Impersonate another individual, organisation, or business.

  • Harvest, collect, or process personal data unlawfully.

  • Infringe the intellectual property rights of others.

4. Content Standards

Any content submitted, uploaded, published, or transmitted through our services must not:

  • Be unlawful, abusive, threatening, defamatory, or discriminatory.

  • Promote violence, hatred, harassment, or illegal activity.

  • Contain obscene, offensive, or harmful material.

  • Violate the rights of any individual or organisation.

  • Breach confidentiality obligations.

  • Infringe copyright, trademarks, patents, or other intellectual property rights.

Users remain solely responsible for any content they provide or publish.

5. AI and Automation Services

When using AI-powered solutions provided by Ross & Sons Digital, users must not:

  • Generate content intended to deceive, defraud, or mislead others.

  • Use AI systems for unlawful surveillance or monitoring.

  • Generate harmful, abusive, discriminatory, or illegal content.

  • Attempt to manipulate or abuse AI systems in a manner that could cause harm to others.

  • Rely solely on AI-generated outputs for critical legal, financial, medical, or regulatory decisions without appropriate human review.

6. Hosting and Cloud Services

Where Ross & Sons Digital provides hosting, cloud infrastructure, or managed services, users must not:

  • Host illegal content.

  • Operate malware, botnets, or malicious software.

  • Engage in cryptocurrency mining without prior written consent.

  • Use excessive resources in a manner that negatively impacts other users or services.

  • Store or distribute content that breaches applicable laws or regulations.

7. Cyber Security

Users are responsible for maintaining appropriate security measures, including:

  • Using strong passwords.

  • Protecting account credentials.

  • Keeping devices and software updated.

  • Reporting suspected security incidents promptly.

Any suspected security vulnerabilities affecting Ross & Sons Digital systems should be reported immediately.

8. Monitoring and Enforcement

Ross & Sons Digital reserves the right to monitor the use of its services where necessary to:

  • Protect systems and infrastructure.

  • Investigate suspected breaches of this Policy.

  • Comply with legal obligations.

  • Maintain service integrity and security.

9. Breach of Policy

Where we reasonably believe that this Policy has been breached, we may:

  • Issue warnings.

  • Suspend access to services.

  • Remove content.

  • Terminate service agreements.

  • Report unlawful activity to relevant authorities.

  • Pursue legal remedies where appropriate.

10. Limitation of Liability

Ross & Sons Digital accepts no responsibility for losses arising from a user's failure to comply with this Policy.

Users remain responsible for all actions undertaken through their accounts, systems, and authorised access credentials.

11. Changes to this Policy

We reserve the right to amend this Acceptable Use Policy at any time. Updated versions will be published on our website and will take effect immediately upon publication.

12. Contact Information

If you have any questions regarding this Acceptable Use Policy or wish to report a suspected breach, please contact Ross & Sons Digital using the contact details provided on our website.


By accessing our website or using our services, you confirm that you have read, understood, and agree to comply with this Acceptable Use Policy.

Website Disclaimer

Website Disclaimer

Last Updated: June 2026

General Information

The information contained on this website is provided by Ross & Sons Digital for general informational purposes only. Whilst we endeavour to keep the information accurate, current, and complete, we make no representations or warranties of any kind, express or implied, regarding the accuracy, reliability, suitability, or availability of the website or the information, products, services, or related content contained on the website.

Any reliance you place on such information is strictly at your own risk.

Professional Advice

The content provided on this website does not constitute legal, financial, accounting, cybersecurity, business, or professional advice.

Visitors should seek appropriate professional advice before making decisions based on information obtained from this website.

Service Information

Descriptions of services, pricing, features, and availability are provided for guidance only and may be subject to change without notice.

Any quotations provided by Ross & Sons Digital shall take precedence over information displayed on this website.

Website Availability

Ross & Sons Digital makes every effort to keep the website operational and accessible. However, we do not guarantee uninterrupted access and accept no responsibility for temporary unavailability caused by maintenance, technical issues, third-party providers, or circumstances beyond our control.

External Links

This website may contain links to external websites operated by third parties.

These links are provided for convenience only and do not imply endorsement of the content, services, or views expressed on those websites.

Ross & Sons Digital has no control over external websites and accepts no responsibility for their content, availability, privacy practices, or security.

Technology and Security

Whilst we implement reasonable security measures to protect this website, we cannot guarantee that the website, servers, downloads, or communications will be free from viruses, malware, or other harmful components.

Users are responsible for implementing their own security measures and ensuring that any downloads or interactions with the website are conducted safely.

Limitation of Liability

To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for any loss or damage, including but not limited to:

  • Direct or indirect financial loss

  • Loss of profits

  • Loss of business opportunities

  • Loss of data

  • Business interruption

  • Reputational damage

  • Any consequential or incidental losses

arising from the use of, or inability to use, this website or any information contained within it.

Intellectual Property

All website content, including text, graphics, logos, branding, designs, images, and software, is the property of Ross & Sons Digital unless otherwise stated.

Unauthorised copying, reproduction, distribution, modification, or use of website content is prohibited without prior written permission.

Testimonials and Case Studies

Any testimonials, reviews, case studies, or examples displayed on this website are intended to illustrate typical experiences and outcomes. Individual results may vary depending on circumstances, business requirements, market conditions, and implementation.

Ross & Sons Digital does not guarantee specific results or business outcomes.

Changes to This Disclaimer

Ross & Sons Digital reserves the right to update or amend this Website Disclaimer at any time without prior notice. Changes will become effective upon publication on this website.

Governing Law

This Disclaimer shall be governed by and interpreted in accordance with the laws of England and Wales.

Any disputes arising from the use of this website shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Contact Us

If you have any questions regarding this Website Disclaimer, please contact Ross & Sons Digital using the contact details provided on our website.

AI Services Disclaimer

AI Services Disclaimer

Last Updated: June 2026

Introduction

Ross & Sons Digital provides Artificial Intelligence (AI), automation, machine learning, chatbot, content generation, and related technology solutions to assist businesses in improving efficiency, productivity, and decision-making.

By using our AI-related services, you acknowledge and agree to the terms outlined in this disclaimer.

No Guarantee of Accuracy

Whilst we strive to implement reliable and effective AI solutions, AI-generated content, recommendations, responses, reports, and analyses may contain inaccuracies, omissions, outdated information, or unintended outputs.

Clients should independently review and verify all AI-generated content before relying upon, publishing, distributing, or implementing it.

Human Oversight Required

AI systems are designed to assist and support business operations and should not replace professional judgement, human review, or expert advice.

Ross & Sons Digital recommends that all AI-generated outputs are reviewed by an appropriately qualified individual before being used in business-critical decisions.

Business Decisions

Any decisions made based on AI-generated information remain the sole responsibility of the client.

Ross & Sons Digital shall not be liable for any losses, damages, costs, or business impacts arising from decisions made using AI-generated outputs, recommendations, forecasts, or automated processes.

Third-Party AI Platforms

Some AI services may utilise third-party technologies, platforms, APIs, or software providers.

Ross & Sons Digital is not responsible for:

  • Service interruptions or outages

  • Changes to third-party functionality

  • Pricing changes imposed by third-party providers

  • Errors originating from third-party AI systems

  • Data processing practices of third-party platforms

Clients may also be subject to the terms and conditions of those third-party providers.

AI Content Generation

Where AI is used to generate content, including but not limited to text, images, code, marketing materials, reports, or customer communications:

  • The client is responsible for reviewing all content before publication or use.

  • Ross & Sons Digital does not guarantee originality, accuracy, completeness, or suitability for a particular purpose.

  • Clients remain responsible for ensuring compliance with copyright, intellectual property, advertising, and regulatory requirements.

Data Privacy and Security

Ross & Sons Digital takes reasonable measures to protect data used within AI-powered solutions. However, clients should avoid submitting highly sensitive, confidential, or regulated information into AI systems unless appropriate safeguards and agreements are in place.

Clients are responsible for ensuring that their use of AI services complies with applicable data protection laws, including UK GDPR and the Data Protection Act 2018.

Availability of AI Services

AI technologies are constantly evolving. Ross & Sons Digital reserves the right to modify, replace, suspend, or discontinue AI-related services where necessary due to technological, commercial, legal, or operational reasons.

Limitation of Liability

To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for any direct, indirect, incidental, consequential, or financial losses arising from:

  • AI-generated content or recommendations

  • Automated decisions or actions

  • Errors, inaccuracies, or omissions in AI outputs

  • Service interruptions or failures

  • Reliance on AI-generated information

The client accepts full responsibility for the review, validation, and implementation of any AI-generated output.

Acceptance

By engaging Ross & Sons Digital for AI-related services, you acknowledge that AI technologies have inherent limitations and agree to use such services at your own discretion and risk.

For any questions regarding our AI services, please contact Ross & Sons Digital using the contact details provided on our website.

Mobile Application Acceptable Use & User Policy

Mobile Application Acceptable Use & User Policy

Last Updated: June 2026

1. Introduction

This Mobile Application Acceptable Use & User Policy ("Policy") governs the use of mobile applications, web applications, software platforms, and digital solutions developed, operated, or managed by Ross & Sons Digital.

By downloading, accessing, registering for, or using any application provided by Ross & Sons Digital, you agree to comply with this Policy.

2. Acceptance of Terms

By using our applications, you confirm that:

  • You have read and understood this Policy.

  • You agree to comply with all applicable laws and regulations.

  • You accept responsibility for your use of the application.

  • You are at least 18 years old or have permission from a parent or legal guardian where applicable.

3. Permitted Use

Our applications are intended for legitimate personal, business, or organisational use in accordance with their intended purpose.

Users may:

  • Access authorised features and services.

  • Store and manage permitted information.

  • Use communication and collaboration tools where available.

  • Access support services provided within the application.

4. Prohibited Use

Users must not:

  • Use the application for unlawful purposes.

  • Attempt to gain unauthorised access to systems, databases, servers, or user accounts.

  • Reverse engineer, decompile, modify, or copy the application without permission.

  • Introduce malware, viruses, spyware, or malicious code.

  • Upload harmful, offensive, defamatory, discriminatory, or illegal content.

  • Use automated tools, bots, or scripts to access the application without authorisation.

  • Interfere with the security, performance, or functionality of the application.

  • Circumvent licensing, subscription, or authentication mechanisms.

5. User Accounts

Where user accounts are required:

  • Users are responsible for maintaining the confidentiality of login credentials.

  • Passwords must not be shared with unauthorised individuals.

  • Users must notify Ross & Sons Digital immediately if they suspect unauthorised access.

  • Users are responsible for activities carried out under their account.

Ross & Sons Digital reserves the right to suspend or terminate accounts where misuse is suspected.

6. Data Protection and Privacy

Ross & Sons Digital is committed to protecting user privacy and handling personal information in accordance with applicable data protection laws, including the UK GDPR and Data Protection Act 2018.

Information collected through our applications will be processed in accordance with our Privacy Policy.

7. Intellectual Property Rights

All application content, source code, designs, logos, trademarks, features, functionality, and intellectual property remain the property of Ross & Sons Digital or its licensors unless otherwise agreed in writing.

Users are granted a limited, non-exclusive, non-transferable licence to use the application for its intended purpose.

No ownership rights are transferred through use of the application.

8. AI and Automated Features

Where applications include Artificial Intelligence (AI), machine learning, automation, or automated decision-making features:

  • Outputs should be reviewed before being relied upon.

  • AI-generated information may not always be accurate or complete.

  • Users remain responsible for decisions made based on AI-generated outputs.

  • Ross & Sons Digital accepts no liability for decisions made solely on AI-generated content.

Users must not use AI features to generate unlawful, misleading, harmful, discriminatory, or fraudulent content.

9. Availability of Services

Ross & Sons Digital will make reasonable efforts to maintain application availability but does not guarantee uninterrupted access.

We may temporarily suspend services for:

  • Maintenance

  • Security updates

  • Infrastructure upgrades

  • Emergency repairs

  • Regulatory compliance

10. Third-Party Services

Applications may integrate with third-party services, APIs, payment processors, cloud platforms, or external providers.

Ross & Sons Digital is not responsible for:

  • Service interruptions caused by third parties.

  • Third-party content or services.

  • Changes to third-party pricing or functionality.

  • Data handling practices of external providers.

Users may also be subject to additional third-party terms and conditions.

11. Security

Users agree to:

  • Use strong passwords.

  • Protect devices used to access the application.

  • Keep software and operating systems updated.

  • Report suspected security vulnerabilities promptly.

Ross & Sons Digital reserves the right to investigate security incidents and take appropriate action to protect users and systems.

12. Suspension and Termination

Ross & Sons Digital may suspend or terminate access where:

  • This Policy is breached.

  • Illegal activity is suspected.

  • Security risks are identified.

  • Subscription fees remain unpaid.

  • Continued access may negatively impact other users or systems.

13. Limitation of Liability

To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for:

  • Loss of profits

  • Loss of revenue

  • Loss of data

  • Business interruption

  • Indirect or consequential losses

  • Decisions made based on information provided within the application

Our total liability shall not exceed the fees paid by the user during the preceding 12 months, where applicable.

14. Updates and Changes

Ross & Sons Digital reserves the right to modify, update, enhance, or discontinue application features and services at any time.

We may also amend this Policy from time to time. Continued use of the application constitutes acceptance of any updated terms.

15. Governing Law

This Policy shall be governed by and interpreted in accordance with (UK GDPR) data protection act 2018 laws of England and Wales.

Any disputes arising from the use of our applications shall be subject to the exclusive jurisdiction of (UK GDPR) data protection act 2018 laws the courts of England and Wales.

Contact Information

For support, privacy enquiries, or questions regarding this Policy, please contact Ross & Sons Digital using the contact information available on our website.


By downloading, accessing, registering for, or using any application developed, operated, or managed by Ross & Sons Digital, you acknowledge that you have read, understood, and agree to comply with this Mobile Application Acceptable Use & User Policy.

Mobile Application Acceptable Use & User Policy

Mobile Application Acceptable Use & User Policy

Last Updated: June 2026

1. Introduction

This Mobile Application Acceptable Use & User Policy ("Policy") governs the use of mobile applications, web applications, software platforms, and digital solutions developed, operated, or managed by Ross & Sons Digital.

By downloading, accessing, registering for, or using any application provided by Ross & Sons Digital, you agree to comply with this Policy.

2. Acceptance of Terms

By using our applications, you confirm that:

  • You have read and understood this Policy.

  • You agree to comply with all applicable laws and regulations.

  • You accept responsibility for your use of the application.

  • You are at least 18 years old or have permission from a parent or legal guardian where applicable.

3. Permitted Use

Our applications are intended for legitimate personal, business, or organisational use in accordance with their intended purpose.

Users may:

  • Access authorised features and services.

  • Store and manage permitted information.

  • Use communication and collaboration tools where available.

  • Access support services provided within the application.

4. Prohibited Use

Users must not:

  • Use the application for unlawful purposes.

  • Attempt to gain unauthorised access to systems, databases, servers, or user accounts.

  • Reverse engineer, decompile, modify, or copy the application without permission.

  • Introduce malware, viruses, spyware, or malicious code.

  • Upload harmful, offensive, defamatory, discriminatory, or illegal content.

  • Use automated tools, bots, or scripts to access the application without authorisation.

  • Interfere with the security, performance, or functionality of the application.

  • Circumvent licensing, subscription, or authentication mechanisms.

5. User Accounts

Where user accounts are required:

  • Users are responsible for maintaining the confidentiality of login credentials.

  • Passwords must not be shared with unauthorised individuals.

  • Users must notify Ross & Sons Digital immediately if they suspect unauthorised access.

  • Users are responsible for activities carried out under their account.

Ross & Sons Digital reserves the right to suspend or terminate accounts where misuse is suspected.

6. Data Protection and Privacy

Ross & Sons Digital is committed to protecting user privacy and handling personal information in accordance with applicable data protection laws, including the UK GDPR and Data Protection Act 2018.

Information collected through our applications will be processed in accordance with our Privacy Policy.

7. Intellectual Property Rights

All application content, source code, designs, logos, trademarks, features, functionality, and intellectual property remain the property of Ross & Sons Digital or its licensors unless otherwise agreed in writing.

Users are granted a limited, non-exclusive, non-transferable licence to use the application for its intended purpose.

No ownership rights are transferred through use of the application.

8. AI and Automated Features

Where applications include Artificial Intelligence (AI), machine learning, automation, or automated decision-making features:

  • Outputs should be reviewed before being relied upon.

  • AI-generated information may not always be accurate or complete.

  • Users remain responsible for decisions made based on AI-generated outputs.

  • Ross & Sons Digital accepts no liability for decisions made solely on AI-generated content.

Users must not use AI features to generate unlawful, misleading, harmful, discriminatory, or fraudulent content.

9. Availability of Services

Ross & Sons Digital will make reasonable efforts to maintain application availability but does not guarantee uninterrupted access.

We may temporarily suspend services for:

  • Maintenance

  • Security updates

  • Infrastructure upgrades

  • Emergency repairs

  • Regulatory compliance

10. Third-Party Services

Applications may integrate with third-party services, APIs, payment processors, cloud platforms, or external providers.

Ross & Sons Digital is not responsible for:

  • Service interruptions caused by third parties.

  • Third-party content or services.

  • Changes to third-party pricing or functionality.

  • Data handling practices of external providers.

Users may also be subject to additional third-party terms and conditions.

11. Security

Users agree to:

  • Use strong passwords.

  • Protect devices used to access the application.

  • Keep software and operating systems updated.

  • Report suspected security vulnerabilities promptly.

Ross & Sons Digital reserves the right to investigate security incidents and take appropriate action to protect users and systems.

12. Suspension and Termination

Ross & Sons Digital may suspend or terminate access where:

  • This Policy is breached.

  • Illegal activity is suspected.

  • Security risks are identified.

  • Subscription fees remain unpaid.

  • Continued access may negatively impact other users or systems.

13. Limitation of Liability

To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for:

  • Loss of profits

  • Loss of revenue

  • Loss of data

  • Business interruption

  • Indirect or consequential losses

  • Decisions made based on information provided within the application

Our total liability shall not exceed the fees paid by the user during the preceding 12 months, where applicable.

14. Updates and Changes

Ross & Sons Digital reserves the right to modify, update, enhance, or discontinue application features and services at any time.

We may also amend this Policy from time to time. Continued use of the application constitutes acceptance of any updated terms.

15. Governing Law

This Policy shall be governed by and interpreted in accordance with (UK GDPR) data protection act 2018 laws of England and Wales.

Any disputes arising from the use of our applications shall be subject to the exclusive jurisdiction of (UK GDPR) data protection act 2018 laws the courts of England and Wales.

Contact Information

For support, privacy enquiries, or questions regarding this Policy, please contact Ross & Sons Digital using the contact information available on our website.


By downloading, accessing, registering for, or using any application developed, operated, or managed by Ross & Sons Digital, you acknowledge that you have read, understood, and agree to comply with this Mobile Application Acceptable Use & User Policy.

Data Flow Diagram (DFD)

Data Flow Diagram (DFD)

System: Incident Management System
Version: 1.0

Data Flow Overview

  •  ┌──────────────────────────────┐
    │ End Users │
    │------------------------------│
    │ • Officers │
    │ • Managers │
    │ • Administrators │
    └──────────────┬───────────────┘

    Personal Data Entry (HTTPS/TLS)


    ┌────────────────────────────────┐
    │ Incident Management System │
    │ │
    │ • Authentication │
    │ • Incident Processing │
    │ • User Management │
    │ • Audit Logging │
    │ • Senior Reviews │
    └──────────────┬─────────────────┘

    ┌───────────────────────┼────────────────────────┐
    │ │ │
    ▼ ▼ ▼
    Microsoft Entra ID Secure Database Audit Log Service
    (Microsoft Login) (Application Data) (Edit History)
    │ │ │
    └───────────────────────┼────────────────────────┘


    Encrypted Backups


    Disaster Recovery Storage

Personal Data Flow

1. Data Collection

Personal information is collected from authorised users when they:

  • Sign in using Microsoft 

  • Create an incident

  • Edit an incident

  • Create a Senior Review

  • Manage user accounts

  • Update records

Typical data includes:

  • Name

  • Email address

  • Job title

  • Department

  • Incident details

  • Persons involved

  • Dates and times

  • Locations

  • Investigation notes

  • Attachments (if enabled)


2. Authentication

Multi-Factor Authentication (MFA) through the customer's chosen identity provider.

The application receives:

  • User name

  • Email address

  • Unique user identifier

  • Authentication token

  • Assigned role (Officer or Manager)

Passwords are never stored by Ross & Sons Digital.


3. Data Processing

Once authenticated, the application processes personal data to:

  • Create incident records

  • Update incidents

  • Assign investigations

  • Record Senior Reviews

  • Manage permissions

  • Generate reports

  • Record audit history

Processing is limited to authorised users based on role-based access controls.


4. Data Storage

Personal information is securely stored within the application's cloud-hosted database.

Stored information may include:

  • User accounts

  • Incident records

  • Investigation notes

  • Senior Reviews

  • Audit logs

  • User permissions

  • System configuration

All communication with the database is encrypted using HTTPS/TLS.


5. Audit Logging

Every significant action is automatically recorded.

Audit records include:

  • User identity

  • Date and time

  • Action performed

  • Record affected

  • Fields changed

Audit records are generated server-side and cannot be modified by users.


6. Data Sharing

The application shares information only where necessary to provide the service.

Examples include:

  • Microsoft Entra ID (authentication)

  • Cloud hosting provider (secure storage)

  • Authorised administrators

  • Customer organisations

No personal data is sold or shared for marketing purposes.


7. Data Retention

Information is retained in accordance with:

  • Customer retention policies

  • NHS records management requirements (where applicable)

  • UK GDPR

  • Legal obligations

Data is securely deleted when no longer required.


8. Data Disposal

When records reach the end of their retention period, they are securely removed using appropriate deletion procedures to reduce the risk of unauthorised recovery.


Data Categories

Data Category Purpose Name User identification Email address Authentication and communication Job title User roleDepartment Organisational reporting Incident details Incident management Locations Investigation Dates and times Incident chronology Investigation notes Case management Audit history Accountability User permissions Access control


Lawful Processing

The system processes information to support:

  • Incident reporting

  • Investigation management

  • Organisational governance

  • Health and safety

  • Security management

  • Compliance and audit

Processing is undertaken by the customer organisation in accordance with the UK GDPR and the Data Protection Act 2018.


Security Controls Protecting Data

  • Microsoft Entra ID authentication

  • HTTPS/TLS encryption

  • Role-Based Access Control (RBAC)

  • Server-side session management

  • Comprehensive audit logging

  • Secure cloud hosting

  • Regular security updates

  • Encrypted backups


Data Flow Summary

Source Processing Storage Output User Microsoft Entra ID authentication Cloud database Secure access User Incident creation and updates Incident records Reports and investigations Manager Senior Reviews Review records Governance oversight System Audit logging Audit database Compliance and accountability Database Encrypted backups Backup storage Disaster recovery


Data Protection Principles

The Incident Management System has been designed to support the core principles of the UK GDPR:

  • Lawfulness, fairness, and transparency

  • Purpose limitation

  • Data minimisation

  • Accuracy

  • Storage limitation

  • Integrity and confidentiality

  • Accountability

This Data Flow Diagram demonstrates how personal data is collected, processed, stored, protected, and retained within the system, supporting secure and compliant incident management.

Technical Architecture Diagram

Ross & Sons Digital

Technical Architecture Diagram

System: Incident Management System
Version: 1.0


High-Level Architecture

┌──────────────────────────────┐ │ End Users │ │------------------------------│ │ • Officers │ │ • Managers │ │ • System Administrators │ └──────────────┬───────────────┘ │ │ HTTPS / TLS 1.2+ ▼ ┌────────────────────────────────────┐ │ Microsoft Authentication │ │ (Microsoft Entra ID) │ └──────────────┬─────────────────────┘ │ Secure OAuth Authentication │ ▼ ┌───────────────────────────────────────────────┐ │ Ross & Sons Digital Cloud Application │ │ │ │ • Incident Management Portal │ │ • User Management │ │ • Senior Reviews │ │ • Audit Logging │ │ • Role-Based Access Control │ │ • Session Management │ └──────────────┬────────────────────────────────┘ │ ┌────────────────┼────────────────┐ │ │ │ ▼ ▼ ▼ ┌────────────────┐ ┌────────────────┐ ┌─────────────────┐ │ Incident API │ │ User API │ │ Audit API │ │ │ │ │ │ │ │ Incident CRUD │ │ Authentication │ │ Edit History │ │ Search │ │ Permissions │ │ Activity Logs │ └────────┬───────┘ └────────┬───────┘ └────────┬────────┘ │ │ │ └──────────────────┼──────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Secure Cloud Database │ │-------------------------------------│ │ • Incident Records │ │ • User Accounts │ │ • Roles & Permissions │ │ • Senior Reviews │ │ • Audit History │ │ • Configuration Data │ └─────────────────────────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Backup & Recovery Services │ │-------------------------------------│ │ • Encrypted Backups │ │ • Disaster Recovery │ │ • Restore Procedures │ └─────────────────────────────────────┘


Authentication Flow

  1. User opens the Incident Management System.

  2. The application redirects the user to Microsoft Entra ID (Microsoft).

  3. Microsoft authenticates the user.

  4. A secure authentication token is returned.

  5. The application validates the token.

  6. The user's role (Officer or Manager) is retrieved.

  7. Access is granted according to role-based permissions.

No Microsoft passwords are stored by Ross & Sons Digital.


Network Flow

User Device │ HTTPS / TLS │ ▼ Microsoft Entra ID │ OAuth Authentication │ ▼ Incident Management Application │ Secure API Requests │ ▼ Cloud Database │ Encrypted Storage │ ▼ Backup Services


Core Components

User Interface

  • Responsive web application

  • Secure login

  • Incident dashboard

  • User management

  • Senior reviews

  • Audit history

Authentication

  • Microsoft Sign-In

  • OAuth 2.0

  • Microsoft Entra ID

  • Optional Multi-Factor Authentication (controlled by the customer)

Application Services

  • Incident Management

  • User Management

  • Audit Logging

  • Senior Reviews

  • Session Management

  • Role-Based Access Control (RBAC)

APIs

  • Incident API

  • Authentication API

  • User Management API

  • Audit Logging API

Database

  • Incident Records

  • User Profiles

  • Roles & Permissions

  • Audit Logs

  • Senior Reviews

  • System Configuration


Security Controls

  • HTTPS/TLS encrypted communications

  • Microsoft Entra ID authentication

  • OAuth 2.0 token validation

  • Server-side session management

  • Role-Based Access Control (RBAC)

  • Comprehensive audit logging

  • Immediate session termination when access is revoked

  • Secure cloud-hosted infrastructure

  • Regular software updates and security patching


Data Flow Summary

Source Destination Data User Microsoft Entra ID Authentication request Microsoft Entra ID Application Authentication token Application Database Incident records Database Application Incident information Application Audit Service User activity logs Database Backup Service Encrypted backups


Hosting Architecture

  • Cloud-hosted application

  • Secure HTTPS endpoint

  • Managed database service

  • Encrypted storage

  • Secure backup services

  • High-availability infrastructure (where supported by the hosting provider)


Disaster Recovery

  • Encrypted backups

  • Documented restore procedures

  • Regular backup verification

  • Recovery Time Objective (RTO): 4 hours

  • Recovery Point Objective (RPO): 1 hour


Architecture Principles

The Incident Management System has been designed around the principles of security, availability, integrity, confidentiality, and accountability. It uses trusted Microsoft identity services for authentication, role-based authorisation for access control, server-side audit logging for accountability, and secure cloud infrastructure to support resilience and business continuity.

Business Continuity & Disaster Recovery Plan (BCP/DRP)

Ross & Sons Digital

Business Continuity & Disaster Recovery Plan (BCP/DRP)

Document Title: Business Continuity & Disaster Recovery Plan
System: Incident Management System
Version: 1.0
Document Owner: Ross & Sons Digital
Approved By: Director – Ross & Sons Digital
Review Date: Annually or following any major system change

  1. Purpose

This Business Continuity and Disaster Recovery (BCDR) Plan outlines the procedures Ross & Sons Digital will follow to maintain or restore the Incident Management System following an unexpected disruption.

The objective of this plan is to minimise downtime, protect customer data, maintain service availability, and ensure business operations can continue following a technical failure, cyber incident, or disaster.

  1. Scope

This plan applies to:

  • Incident Management System
  • Web application
  • Cloud-hosted infrastructure
  • Application database
  • Authentication services
  • Supporting APIs
  • Administrative portal
  • Customer support services
  1. Business Objectives

The objectives of this plan are to:

  • Protect confidential information.
  • Maintain system availability.
  • Minimise operational disruption.
  • Restore services as quickly as possible.
  • Meet contractual obligations.
  • Support NHS and UK GDPR requirements.
  • Ensure business resilience.
  1. Recovery Objectives

Objective

Target

Recovery Time Objective (RTO)

Within 4 hours

Recovery Point Objective (RPO)

Maximum 1 hour of data loss

Critical Incident Response

Immediate

Customer Notification

Within 2 hours where appropriate

  1. Critical Services

The following services are considered critical: 

  • User (MFA) authentication
  • Incident Database
  • Cloud Hosting Platform
  • Secure API Services
  • User Management
  • Audit Logging
  • Incident Reporting
  • Senior Review Functions
  1. Roles and Responsibilities

Director

Responsible for:

  • Activating the Business Continuity Plan
  • Customer communications
  • Supplier management
  • Incident escalation
  • Final approval of recovery

Technical Lead

Responsible for:

  • Technical investigation
  • System restoration
  • Security patching
  • Database recovery
  • Infrastructure monitoring

Cyber Security Lead

Responsible for:

  • Security incident response
  • Threat analysis
  • Vulnerability management
  • Security reporting
  • Liaison with customer cyber teams

Customers

Customers should:

  • Report incidents promptly
  • Follow local business continuity procedures
  • Notify Ross & Sons Digital of suspected security incidents
  1. Risk Assessment

Potential disruption may include:

  • Cloud service outage
  • Internet connectivity failure
  • Cyber attack
  • Ransomware
  • Hardware failure
  • Database corruption
  • Human error
  • Software defects
  • Power outage
  • Third-party service failure
  1. Preventative Measures

Ross & Sons Digital implements the following controls:

  • Secure cloud hosting
  • HTTPS encryption
  • Microsoft User (MFA) authentication
  • Role-Based Access Control
  • Audit logging
  • Server-side session management
  • Software version control
  • Change management
  • Security monitoring
  • Regular software updates
  1. Backup Strategy

Application data is backed up regularly.

Backups include:

  • Incident database
  • User configuration
  • Application configuration
  • Audit logs

Backups are:

  • Encrypted
  • Securely stored
  • Tested periodically
  • Protected from unauthorised access

Backup restoration procedures are documented and tested.

  1. Disaster Recovery Procedures

Step 1

Identify the incident.

Determine:

  • Nature of the issue
  • Impact
  • Systems affected
  • Severity

Step 2

Contain the incident.

Actions may include:

  • Disabling affected services
  • Restricting access
  • Isolating compromised systems
  • Blocking malicious activity

Step 3

Notify stakeholders.

Where appropriate notify:

  • Customers
  • ICT Teams
  • Cyber Security Teams
  • Senior Management

Step 4

Recover services.

Recovery may include:

  • Restore database
  • Deploy latest application version
  • Restore backups
  • Verify authentication services
  • Test functionality

Step 5

Validate system.

Checks include:

  • User (MFA) authentication
  • Incident creation
  • Incident editing
  • Audit history
  • User permissions
  • Senior Reviews
  • Reporting functionality

Step 6

Return to service.

The system will only return to production once testing confirms services are operating correctly.

  1. Cyber Incident Response

Where a cyber incident is suspected:

Immediate actions include:

  • Preserve evidence.
  • Isolate affected systems.
  • Investigate activity.
  • Review audit logs.
  • Notify customers where appropriate.
  • Apply security patches.
  • Restore secure services.

Where legally required, appropriate regulatory reporting procedures will be followed.

  1. Data Recovery

Recovery priority:

  1. User (MFA) authentication
  2. Database restoration
  3. Incident records
  4. Audit logs
  5. User accounts
  6. Reporting functions
  7. Administrative services
  1. Communication Plan

During a major incident Ross & Sons Digital will:

  • Provide regular customer updates.
  • Confirm estimated recovery times.
  • Notify customers of completed recovery.
  • Provide a post-incident summary where appropriate.
  1. Testing

This plan will be tested:

  • At least annually.
  • Following significant infrastructure changes.
  • Following major software releases.
  • After significant incidents.

Testing may include:

  • Backup restoration
  • Disaster recovery exercises
  • Authentication testing
  • Security testing
  • Infrastructure failover testing
  1. Review

This document will be reviewed:

  • Every 12 months
  • Following major incidents
  • Following infrastructure changes
  • Following security incidents
  • Following customer feedback
  1. Document Control

Version

Date

Author

Description

1.0

June 2026

Leroy Ross

Initial Release

  1. Approval

Prepared by:
Leroy Ross
Director
Ross & Sons Digital

Approved by:

Signature: __Leroy Ross______

Date: _____  18/06/2026_____ 

Appendix A – System Security Summary

The Incident Management System includes:

  • User (MFA) authentication
  • Role-Based Access Control (RBAC)
  • Server-side session management
  • Secure HTTPS/TLS encryption
  • Comprehensive audit logging
  • User account management
  • Immediate session revocation on account removal
  • Cloud-hosted infrastructure
  • Secure application updates
  • Regular maintenance and security patching

Appendix B – Recovery Targets

Service

Priority

Target Recovery

Authentication

Critical

1 Hour

Database

Critical

2 Hours

Incident Recording

Critical

2 Hours

Audit Logging

Critical

2 Hours

User Management

High

4 Hours

Reporting Functions

Medium

4 Hours

Commitment

Ross & Sons Digital is committed to maintaining the confidentiality, integrity, and availability of customer information. This Business Continuity and Disaster Recovery Plan supports our commitment to delivering secure, reliable, and resilient digital services and aligns with recognised information security and business continuity best practices.

Security Controls

Security Controls

Information Security Controls

The Incident Management System has been designed using a security-by-design approach to protect confidential information and maintain the integrity and availability of data.

Security measures include:

  • Microsoft Multi-Factor Authentication (MFA) for verified user access.
  • Role-based access controls (RBAC).
  • Server-side session management.
  • Comprehensive audit logging.
  • Secure password handling by the identity provider.
  • Automatic session validation.
  • Principle of least privilege for user permissions.
  • Secure cloud hosting.
  • Encrypted communications using HTTPS/TLS.
  • Regular application updates and maintenance.

Encryption

Data in Transit

All communications between users and the application are encrypted using HTTPS with TLS.

Data at Rest

Application data is stored within secure cloud-hosted databases. Encryption at rest should be enabled through the hosting provider where available.

Sensitive credentials are never stored in plain text.


Authentication & Multi-Factor Authentication (MFA)

User authentication is performed using Microsoft 365 authentication services.

This provides:

  • Secure sign-in
  • Centralised identity management
  • Password policy enforcement
  • Support for Multi-Factor Authentication where enabled by the organisation
  • Conditional Access policies managed by Microsoft Entra ID

The application does not manage user passwords directly.


Access Control

Access is controlled using role-based permissions.

Officer

  • Create incidents
  • Edit incidents
  • View authorised records

Manager

  • Delete incidents
  • Create Senior Reviews
  • View complete audit history
  • Manage user accounts
  • Promote users
  • Remove user access

All permissions are managed server-side.


Audit Logging

Every significant action is recorded, including:

  • User authentication
  • Incident creation
  • Incident edits
  • User account changes
  • Permission changes
  • Senior Reviews
  • Administrative actions

Audit logs record:

  • Verified user identity
  • Date and time
  • Action performed
  • Record affected

Audit information cannot be altered by end users.


Cyber Security

The application has been developed in accordance with recognised secure development principles.

Security measures include:

  • Server-side validation
  • Input validation
  • Authentication controls
  • Role-based authorisation
  • Secure session management
  • Secure API access
  • Audit logging
  • HTTPS encryption

Security updates will be applied promptly following the identification of vulnerabilities.


Security Patching

Ross & Sons Digital will:

  • Monitor security vulnerabilities.
  • Apply security patches promptly.
  • Update application dependencies regularly.
  • Review third-party libraries for known vulnerabilities.
  • Maintain software versions supported by vendors.

Critical security patches will be prioritised.


Penetration Testing

Prior to production deployment, independent penetration testing should be completed.

Testing should include:

  • Authentication testing
  • Authorisation testing
  • API security
  • OWASP Top 10 assessment
  • Session management
  • Injection testing
  • Cross-site scripting testing
  • Business logic testing

Any identified vulnerabilities should be remediated before deployment.


Business Continuity

The application has been designed to minimise service disruption.

Business continuity measures include:

  • Secure cloud hosting
  • Database backups
  • Disaster recovery procedures
  • Controlled software deployment
  • Monitoring of system availability
  • Secure user authentication

Document your Recovery Time Objective (RTO) and Recovery Point Objective (RPO) if these have been defined.


Data Protection

The application has been developed in accordance with UK GDPR principles, including:

  • Lawfulness
  • Fairness
  • Transparency
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity
  • Confidentiality
  • Accountability

Only information necessary for incident management is processed.


Lawful Basis (UK GDPR)

Personal Data

Article 6(1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Special Category Data

Where special category data is processed:

Article 9(2)(h) – Management of health or social care systems.

or

Article 9(2)(g) – Substantial public interest.

The Trust's Information Governance Team should confirm the appropriate lawful basis.


Risk Assessment

 

Risk Mitigation Unauthorised access Microsoft authentication, RBAC, server-side session management Weak passwords Password policies and MFA managed through Microsoft Data interception HTTPS/TLS encryption Data loss Regular backups and disaster recovery procedures Privilege misuse Role-based permissions and audit logging User error Training, user guides, and least-privilege access Software vulnerabilities Regular patching and vulnerability monitoring Session hijacking Secure server-side session management Insider threats Comprehensive audit trails and user accountability Unauthorised changes Server-authoritative audit logging and restricted permissions.

Data Flow Diagram (DFD)

Data Flow Diagram (DFD)

System: Incident Management System
Version: 1.0

Data Flow Overview

  •  ┌──────────────────────────────┐
    │ End Users │
    │------------------------------│
    │ • Officers │
    │ • Managers │
    │ • Administrators │
    └──────────────┬───────────────┘

    Personal Data Entry (HTTPS/TLS)


    ┌────────────────────────────────┐
    │ Incident Management System │
    │ │
    │ • Authentication │
    │ • Incident Processing │
    │ • User Management │
    │ • Audit Logging │
    │ • Senior Reviews │
    └──────────────┬─────────────────┘

    ┌───────────────────────┼────────────────────────┐
    │ │ │
    ▼ ▼ ▼
    Microsoft Entra ID Secure Database Audit Log Service
    (Microsoft Login) (Application Data) (Edit History)
    │ │ │
    └───────────────────────┼────────────────────────┘


    Encrypted Backups


    Disaster Recovery Storage

Personal Data Flow

1. Data Collection

Personal information is collected from authorised users when they:

  • Sign in using Microsoft 

  • Create an incident

  • Edit an incident

  • Create a Senior Review

  • Manage user accounts

  • Update records

Typical data includes:

  • Name

  • Email address

  • Job title

  • Department

  • Incident details

  • Persons involved

  • Dates and times

  • Locations

  • Investigation notes

  • Attachments (if enabled)


2. Authentication

Multi-Factor Authentication (MFA) through the customer's chosen identity provider.

The application receives:

  • User name

  • Email address

  • Unique user identifier

  • Authentication token

  • Assigned role (Officer or Manager)

Passwords are never stored by Ross & Sons Digital.

Technical Architecture Diagram

Ross & Sons Digital

Technical Architecture Diagram

System: Incident Management System
Version: 1.0


High-Level Architecture

┌──────────────────────────────┐ │ End Users │ │------------------------------│ │ • Officers │ │ • Managers │ │ • System Administrators │ └──────────────┬───────────────┘ │ │ HTTPS / TLS 1.2+ ▼ ┌────────────────────────────────────┐ │ Microsoft Authentication │ │ (Microsoft Entra ID) │ └──────────────┬─────────────────────┘ │ Secure OAuth Authentication │ ▼ ┌───────────────────────────────────────────────┐ │ Ross & Sons Digital Cloud Application │ │ │ │ • Incident Management Portal │ │ • User Management │ │ • Senior Reviews │ │ • Audit Logging │ │ • Role-Based Access Control │ │ • Session Management │ └──────────────┬────────────────────────────────┘ │ ┌────────────────┼────────────────┐ │ │ │ ▼ ▼ ▼ ┌────────────────┐ ┌────────────────┐ ┌─────────────────┐ │ Incident API │ │ User API │ │ Audit API │ │ │ │ │ │ │ │ Incident CRUD │ │ Authentication │ │ Edit History │ │ Search │ │ Permissions │ │ Activity Logs │ └────────┬───────┘ └────────┬───────┘ └────────┬────────┘ │ │ │ └──────────────────┼──────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Secure Cloud Database │ │-------------------------------------│ │ • Incident Records │ │ • User Accounts │ │ • Roles & Permissions │ │ • Senior Reviews │ │ • Audit History │ │ • Configuration Data │ └─────────────────────────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Backup & Recovery Services │ │-------------------------------------│ │ • Encrypted Backups │ │ • Disaster Recovery │ │ • Restore Procedures │ └─────────────────────────────────────┘


Authentication Flow

  1. User opens the Incident Management System.

  2. The application redirects the user to Microsoft Entra ID (Microsoft).

  3. Microsoft authenticates the user.

  4. A secure authentication token is returned.

  5. The application validates the token.

  6. The user's role (Officer or Manager) is retrieved.

  7. Access is granted according to role-based permissions.

No Microsoft passwords are stored by Ross & Sons Digital.


Network Flow

User Device │ HTTPS / TLS │ ▼ Microsoft Entra ID │ OAuth Authentication │ ▼ Incident Management Application │ Secure API Requests │ ▼ Cloud Database │ Encrypted Storage │ ▼ Backup Services


Core Components

User Interface

  • Responsive web application

  • Secure login

  • Incident dashboard

  • User management

  • Senior reviews

  • Audit history

Authentication

  • Microsoft Sign-In

  • OAuth 2.0

  • Microsoft Entra ID

  • Optional Multi-Factor Authentication (controlled by the customer)

Application Services

  • Incident Management

  • User Management

  • Audit Logging

  • Senior Reviews

  • Session Management

  • Role-Based Access Control (RBAC)

APIs

  • Incident API

  • Authentication API

  • User Management API

  • Audit Logging API

Database

  • Incident Records

  • User Profiles

  • Roles & Permissions

  • Audit Logs

  • Senior Reviews

  • System Configuration


Security Controls

  • HTTPS/TLS encrypted communications

  • Microsoft Entra ID authentication

  • OAuth 2.0 token validation

  • Server-side session management

  • Role-Based Access Control (RBAC)

  • Comprehensive audit logging

  • Immediate session termination when access is revoked

  • Secure cloud-hosted infrastructure

  • Regular software updates and security patching


Data Flow Summary

Source Destination Data User Microsoft Entra ID Authentication request Microsoft Entra ID Application Authentication token Application Database Incident records Database Application Incident information Application Audit Service User activity logs Database Backup Service Encrypted backups


Hosting Architecture

  • Cloud-hosted application

  • Secure HTTPS endpoint

  • Managed database service

  • Encrypted storage

  • Secure backup services

  • High-availability infrastructure (where supported by the hosting provider)


Disaster Recovery

  • Encrypted backups

  • Documented restore procedures

  • Regular backup verification

  • Recovery Time Objective (RTO): 4 hours

  • Recovery Point Objective (RPO): 1 hour


Architecture Principles

The Incident Management System has been designed around the principles of security, availability, integrity, confidentiality, and accountability. It uses trusted Microsoft identity services for authentication, role-based authorisation for access control, server-side audit logging for accountability, and secure cloud infrastructure to support resilience and business continuity.

Business Continuity & Disaster Recovery Plan (BCP/DRP)

Ross & Sons Digital

Business Continuity & Disaster Recovery Plan (BCP/DRP)

Document Title: Business Continuity & Disaster Recovery Plan
System: Incident Management System
Version: 1.0
Document Owner: Ross & Sons Digital
Approved By: Director – Ross & Sons Digital
Review Date: Annually or following any major system change

  1. Purpose

This Business Continuity and Disaster Recovery (BCDR) Plan outlines the procedures Ross & Sons Digital will follow to maintain or restore the Incident Management System following an unexpected disruption.

The objective of this plan is to minimise downtime, protect customer data, maintain service availability, and ensure business operations can continue following a technical failure, cyber incident, or disaster.

  1. Scope

This plan applies to:

  • Incident Management System
  • Web application
  • Cloud-hosted infrastructure
  • Application database
  • Authentication services
  • Supporting APIs
  • Administrative portal
  • Customer support services
  1. Business Objectives

The objectives of this plan are to:

  • Protect confidential information.
  • Maintain system availability.
  • Minimise operational disruption.
  • Restore services as quickly as possible.
  • Meet contractual obligations.
  • Support NHS and UK GDPR requirements.
  • Ensure business resilience.
  1. Recovery Objectives

Objective

Target

Recovery Time Objective (RTO)

Within 4 hours

Recovery Point Objective (RPO)

Maximum 1 hour of data loss

Critical Incident Response

Immediate

Customer Notification

Within 2 hours where appropriate

  1. Critical Services

The following services are considered critical: 

  • User (MFA) authentication
  • Incident Database
  • Cloud Hosting Platform
  • Secure API Services
  • User Management
  • Audit Logging
  • Incident Reporting
  • Senior Review Functions
  1. Roles and Responsibilities

Director

Responsible for:

  • Activating the Business Continuity Plan
  • Customer communications
  • Supplier management
  • Incident escalation
  • Final approval of recovery

Technical Lead

Responsible for:

  • Technical investigation
  • System restoration
  • Security patching
  • Database recovery
  • Infrastructure monitoring

Cyber Security Lead

Responsible for:

  • Security incident response
  • Threat analysis
  • Vulnerability management
  • Security reporting
  • Liaison with customer cyber teams

Customers

Customers should:

  • Report incidents promptly
  • Follow local business continuity procedures
  • Notify Ross & Sons Digital of suspected security incidents
  1. Risk Assessment

Potential disruption may include:

  • Cloud service outage
  • Internet connectivity failure
  • Cyber attack
  • Ransomware
  • Hardware failure
  • Database corruption
  • Human error
  • Software defects
  • Power outage
  • Third-party service failure
  1. Preventative Measures

Ross & Sons Digital implements the following controls:

  • Secure cloud hosting
  • HTTPS encryption
  • Microsoft User (MFA) authentication
  • Role-Based Access Control
  • Audit logging
  • Server-side session management
  • Software version control
  • Change management
  • Security monitoring
  • Regular software updates
  1. Backup Strategy

Application data is backed up regularly.

Backups include:

  • Incident database
  • User configuration
  • Application configuration
  • Audit logs

Backups are:

  • Encrypted
  • Securely stored
  • Tested periodically
  • Protected from unauthorised access

Backup restoration procedures are documented and tested.

  1. Disaster Recovery Procedures

Step 1

Identify the incident.

Determine:

  • Nature of the issue
  • Impact
  • Systems affected
  • Severity

Step 2

Contain the incident.

Actions may include:

  • Disabling affected services
  • Restricting access
  • Isolating compromised systems
  • Blocking malicious activity

Step 3

Notify stakeholders.

Where appropriate notify:

  • Customers
  • ICT Teams
  • Cyber Security Teams
  • Senior Management

Step 4

Recover services.

Recovery may include:

  • Restore database
  • Deploy latest application version
  • Restore backups
  • Verify authentication services
  • Test functionality

Step 5

Validate system.

Checks include:

  • User (MFA) authentication
  • Incident creation
  • Incident editing
  • Audit history
  • User permissions
  • Senior Reviews
  • Reporting functionality

Step 6

Return to service.

The system will only return to production once testing confirms services are operating correctly.

  1. Cyber Incident Response

Where a cyber incident is suspected:

Immediate actions include:

  • Preserve evidence.
  • Isolate affected systems.
  • Investigate activity.
  • Review audit logs.
  • Notify customers where appropriate.
  • Apply security patches.
  • Restore secure services.

Where legally required, appropriate regulatory reporting procedures will be followed.

  1. Data Recovery

Recovery priority:

  1. User (MFA) authentication
  2. Database restoration
  3. Incident records
  4. Audit logs
  5. User accounts
  6. Reporting functions
  7. Administrative services
  1. Communication Plan

During a major incident Ross & Sons Digital will:

  • Provide regular customer updates.
  • Confirm estimated recovery times.
  • Notify customers of completed recovery.
  • Provide a post-incident summary where appropriate.
  1. Testing

This plan will be tested:

  • At least annually.
  • Following significant infrastructure changes.
  • Following major software releases.
  • After significant incidents.

Testing may include:

  • Backup restoration
  • Disaster recovery exercises
  • Authentication testing
  • Security testing
  • Infrastructure failover testing
  1. Review

This document will be reviewed:

  • Every 12 months
  • Following major incidents
  • Following infrastructure changes
  • Following security incidents
  • Following customer feedback
  1. Document Control

Version

Date

Author

Description

1.0

June 2026

Leroy Ross

Initial Release

  1. Approval

Prepared by:
Leroy Ross
Director
Ross & Sons Digital

Approved by:

Signature: __Leroy Ross______

Date: _____  18/06/2026_____ 

Appendix A – System Security Summary

The Incident Management System includes:

  • User (MFA) authentication
  • Role-Based Access Control (RBAC)
  • Server-side session management
  • Secure HTTPS/TLS encryption
  • Comprehensive audit logging
  • User account management
  • Immediate session revocation on account removal
  • Cloud-hosted infrastructure
  • Secure application updates
  • Regular maintenance and security patching

Appendix B – Recovery Targets

Service

Priority

Target Recovery

Authentication

Critical

1 Hour

Database

Critical

2 Hours

Incident Recording

Critical

2 Hours

Audit Logging

Critical

2 Hours

User Management

High

4 Hours

Reporting Functions

Medium

4 Hours

Commitment

Ross & Sons Digital is committed to maintaining the confidentiality, integrity, and availability of customer information. This Business Continuity and Disaster Recovery Plan supports our commitment to delivering secure, reliable, and resilient digital services and aligns with recognised information security and business continuity best practices.

Security Controls

Security Controls

Information Security Controls

The Incident Management System has been designed using a security-by-design approach to protect confidential information and maintain the integrity and availability of data.

Security measures include:

  • Microsoft Multi-Factor Authentication (MFA) for verified user access.
  • Role-based access controls (RBAC).
  • Server-side session management.
  • Comprehensive audit logging.
  • Secure password handling by the identity provider.
  • Automatic session validation.
  • Principle of least privilege for user permissions.
  • Secure cloud hosting.
  • Encrypted communications using HTTPS/TLS.
  • Regular application updates and maintenance.

Encryption

Data in Transit

All communications between users and the application are encrypted using HTTPS with TLS.

Data at Rest

Application data is stored within secure cloud-hosted databases. Encryption at rest should be enabled through the hosting provider where available.

Sensitive credentials are never stored in plain text.


Authentication & Multi-Factor Authentication (MFA)

User authentication is performed using Microsoft or Google authentication services.

This provides:

  • Secure sign-in
  • Centralised identity management
  • Password policy enforcement
  • Support for Multi-Factor Authentication where enabled by the organisation
  • Conditional Access policies managed by Microsoft Entra ID

The application does not manage user passwords directly.


Access Control

Access is controlled using role-based permissions.

Officer

  • Create incidents
  • Edit incidents
  • View authorised records

Manager

  • Delete incidents
  • Create Senior Reviews
  • View complete audit history
  • Manage user accounts
  • Promote users
  • Remove user access

All permissions are managed server-side.


Audit Logging

Every significant action is recorded, including:

  • User authentication
  • Incident creation
  • Incident edits
  • User account changes
  • Permission changes
  • Senior Reviews
  • Administrative actions

Audit logs record:

  • Verified user identity
  • Date and time
  • Action performed
  • Record affected

Audit information cannot be altered by end users.


Cyber Security

The application has been developed in accordance with recognised secure development principles.

Security measures include:

  • Server-side validation
  • Input validation
  • Authentication controls
  • Role-based authorisation
  • Secure session management
  • Secure API access
  • Audit logging
  • HTTPS encryption

Security updates will be applied promptly following the identification of vulnerabilities.


Security Patching

Ross & Sons Digital will:

  • Monitor security vulnerabilities.
  • Apply security patches promptly.
  • Update application dependencies regularly.
  • Review third-party libraries for known vulnerabilities.
  • Maintain software versions supported by vendors.

Critical security patches will be prioritised.


Penetration Testing

Prior to production deployment, independent penetration testing should be completed.

Testing should include:

  • Authentication testing
  • Authorisation testing
  • API security
  • OWASP Top 10 assessment
  • Session management
  • Injection testing
  • Cross-site scripting testing
  • Business logic testing

Any identified vulnerabilities should be remediated before deployment.


Business Continuity

The application has been designed to minimise service disruption.

Business continuity measures include:

  • Secure cloud hosting
  • Database backups
  • Disaster recovery procedures
  • Controlled software deployment
  • Monitoring of system availability
  • Secure user authentication

Document your Recovery Time Objective (RTO) and Recovery Point Objective (RPO) if these have been defined.


Data Protection

The application has been developed in accordance with UK ICO and GDPR principles, including:

  • Lawfulness
  • Fairness
  • Transparency
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity
  • Confidentiality
  • Accountability

Only information necessary for incident management is processed.


Lawful Basis (UK ICO and GDPR)

Personal Data

Article 6(1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Special Category Data

Where special category data is processed:

Article 9(2)(h) – Management of health or social care systems.

or

Article 9(2)(g) – Substantial public interest.

The Trust's Information Governance Team should confirm the appropriate lawful basis.


Risk Assessment

 

Risk Mitigation Unauthorised access with Microsoft or Google authentication, RBAC, server-side session management Weak passwords Password policies and MFA managed through Microsoft Data interception HTTPS/TLS encryption Data loss Regular backups and disaster recovery procedures Privilege misuse Role-based permissions and audit logging User error Training, user guides, and least-privilege access Software vulnerabilities Regular patching and vulnerability monitoring Session hijacking Secure server-side session management Insider threats Comprehensive audit trails and user accountability Unauthorised changes Server-authoritative audit logging and restricted permissions.