Client Service Agreement
Client Service Agreement
Project Terms
By accepting a quotation from Ross & Sons Digital, the client agrees to the following terms.
Quotations
All quotations remain valid for 30 days unless otherwise stated.
Deposits
Projects may require a deposit before work commences.
Typical payment structure:
-
50% Deposit
-
50% Upon Completion
For larger projects, staged payments may apply.
Scope of Work
The agreed quotation defines the project scope.
Any additional work requested outside the agreed scope may incur additional charges.
Client Responsibilities
The client agrees to provide:
-
Content
-
Images
-
Branding materials
-
Access credentials
-
Feedback and approvals
Delays in providing required information may impact project timelines.
Ownership
Upon full payment, ownership of completed website or application assets created specifically for the client will transfer to the client unless otherwise agreed.
Ross & Sons Digital retains ownership of:
-
Proprietary tools
-
Development frameworks
-
Reusable code libraries
-
Internal processes and methodologies
Maintenance
Unless covered by a maintenance agreement, ongoing updates and support are not included following project completion.
Hosting and Domains
Hosting, domains, software subscriptions, third-party integrations, and cloud services may incur separate recurring charges.
Limitation of Liability
Ross & Sons Digital shall not be liable for indirect, consequential, or financial losses resulting from the use of delivered services.
Cancellation
If a project is cancelled after work has commenced, Ross & Sons Digital reserves the right to invoice for work completed up to the cancellation date.
Governing Law
This agreement shall be governed by the laws of England and Wales.
Website Maintenance Agreement
Website Maintenance Agreement
Last Updated: June 2026
1. Agreement Overview
This Website Maintenance Agreement ("Agreement") sets out the terms under which Ross & Sons Digital provides ongoing website maintenance, support, monitoring, and related services to its clients.
This Agreement applies to all clients who subscribe to a website maintenance or support plan provided by Ross & Sons Digital.
2. Purpose of Maintenance Services
The purpose of website maintenance is to ensure that your website remains secure, functional, up-to-date, and operating efficiently.
Maintenance services are designed to minimise downtime, improve security, and help maintain optimal website performance.
3. Services Included
Depending on the selected maintenance package, services may include:
Website Updates
-
Content Management System (CMS) updates
-
Plugin and extension updates
-
Theme updates
-
Compatibility checks
Security Monitoring
-
Security scans
-
Malware monitoring
-
Vulnerability assessments
-
Security patch implementation
Website Backups
-
Scheduled backups
-
Backup retention management
-
Restoration assistance where applicable
Performance Monitoring
-
Website uptime monitoring
-
Speed and performance checks
-
Error identification and reporting
Technical Support
-
Troubleshooting website issues
-
Technical advice
-
Minor content updates (where included within the selected package)
4. Exclusions
Unless specifically included within the selected support package, maintenance services do not include:
-
Website redesigns
-
New page creation
-
New functionality development
-
E-commerce product uploads
-
Copywriting services
-
SEO campaigns
-
Branding services
-
Photography or graphic design
-
Third-party software licensing costs
-
Recovery from client-caused damage or unauthorised modifications
Additional work outside the scope of the maintenance plan may be charged at our standard hourly rates.
5. Client Responsibilities
The client agrees to:
-
Provide accurate information when reporting issues.
-
Maintain secure access credentials.
-
Notify Ross & Sons Digital of any suspected security incidents.
-
Avoid making unauthorised modifications that may affect website functionality.
-
Maintain valid licences for any third-party software or services where required.
6. Response Times
Ross & Sons Digital will make reasonable efforts to respond to support requests within the following target times:
Priority Target Response Time Critical Website Outage Within 4 Business Hours High Priority Issue Within 1 Business Day Standard Support Request Within 2 Business Days General Enquiry Within 3 Business Days
Response times are targets and not guaranteed service-level commitments unless otherwise agreed in writing.
7. Emergency Support
Emergency support outside normal business hours may be available and may incur additional charges unless included within a premium support package.
8. Third-Party Services
Ross & Sons Digital is not responsible for delays, outages, or failures caused by third-party providers, including:
-
Hosting providers
-
Domain registrars
-
Cloud service providers
-
Payment gateways
-
API providers
-
Email service providers
We will, where possible, assist in liaising with third-party providers to resolve issues.
9. Backups and Data Recovery
Whilst backups may be performed as part of the maintenance service, Ross & Sons Digital cannot guarantee recovery of all data in every circumstance.
Clients remain responsible for maintaining independent copies of critical business data where appropriate.
10. Security
Ross & Sons Digital will implement reasonable security measures and best practices. However, no website can be guaranteed to be completely secure.
We shall not be liable for breaches resulting from:
-
Weak passwords
-
Compromised client devices
-
Third-party vulnerabilities
-
Social engineering attacks
-
Actions taken by unauthorised users
11. Fees and Payments
Maintenance services are provided on a monthly or annual subscription basis.
Fees must be paid in accordance with the selected package and payment schedule.
Failure to make payment may result in suspension of maintenance services.
12. Cancellation
Either party may terminate this Agreement by providing at least 30 days' written notice.
Any fees due up to the termination date remain payable.
No refunds will be provided for partially used billing periods unless required by law.
13. Limitation of Liability
Ross & Sons Digital shall not be liable for:
-
Loss of profits
-
Loss of revenue
-
Loss of business opportunities
-
Loss of data
-
Indirect or consequential losses
Our liability shall be limited to the fees paid by the client for maintenance services during the preceding 12 months.
14. Amendments
Ross & Sons Digital reserves the right to amend this Agreement from time to time. Updated versions will be published on our website and become effective upon publication.
15. Governing Law
This Agreement shall be governed by and interpreted in accordance with the laws of England and Wales.
Any disputes arising under this Agreement shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Contact Information
For support requests, account enquiries, or questions regarding this Agreement, please contact Ross & Sons Digital using the contact details available on our website.
By subscribing to a maintenance plan or requesting website maintenance services from Ross & Sons Digital, you acknowledge and agree to the terms of this Website Maintenance Agreement.
Refund & Cancellation Policy
Refund & Cancellation Policy
Last Updated: June 2026
1. Introduction
This Refund & Cancellation Policy outlines the terms governing project cancellations, refunds, recurring services, and support agreements provided by Ross & Sons Digital.
By engaging our services, you agree to the terms set out in this policy.
2. Project Deposits
To secure project commencement, Ross & Sons Digital may require a deposit before any work begins.
Unless otherwise agreed in writing:
-
All deposits are non-refundable.
-
Deposits secure project scheduling, resource allocation, planning, and initial development work.
-
Work will not commence until the required deposit has been received.
3. Project Cancellations
Cancellation Before Work Begins
If a project is cancelled before any work has commenced, Ross & Sons Digital may, at its sole discretion, offer a partial refund of any payments received, less any administrative or planning costs already incurred.
Cancellation After Work Has Commenced
If a project is cancelled after work has begun:
-
The client will be invoiced for all work completed up to the cancellation date.
-
Any outstanding balances become immediately payable.
-
Deposits already paid will not be refunded.
-
Any completed work remains the property of Ross & Sons Digital until all outstanding invoices have been paid in full.
4. Website Development Projects
Website development projects involve planning, design, development, testing, and consultation.
As these services are bespoke and created specifically for the client:
-
Refunds are generally not available once development work has commenced.
-
Any refund requests will be considered on a case-by-case basis.
-
Project milestones already completed remain chargeable.
5. Mobile Application Development
Mobile application development services are customised and involve substantial time and technical resources.
Once development has commenced:
-
Payments made are non-refundable.
-
Completed development stages remain chargeable.
-
Any intellectual property rights remain with Ross & Sons Digital until full payment has been received.
6. AI, Automation, and Consultancy Services
Consultancy, AI implementation, automation design, strategy sessions, and advisory services are delivered based on professional expertise and time invested.
As such:
-
Fees for completed consultancy services are non-refundable.
-
Scheduled workshops or consultations cancelled with less than 48 hours' notice may be charged in full.
7. Hosting Services
Website hosting, cloud hosting, email hosting, and infrastructure services are billed in advance.
Unless otherwise stated:
-
Hosting fees are non-refundable once a service period has commenced.
-
Clients may cancel hosting services by providing at least 30 days' written notice.
-
Services will remain active until the end of the paid billing period.
8. Maintenance & Support Plans
Maintenance and support agreements may be cancelled at any time by providing 30 days' written notice.
Where a monthly support agreement exists:
-
Charges already invoiced remain payable.
-
No partial refunds will be provided for unused portions of a billing cycle.
-
Support services will continue until the cancellation date.
9. Domain Names and Third-Party Services
Domain registrations, SSL certificates, software licences, cloud subscriptions, API services, and third-party products purchased on behalf of a client are generally non-refundable.
Any refunds are subject to the terms and policies of the respective third-party provider.
10. Exceptional Circumstances
Ross & Sons Digital may, at its sole discretion, offer goodwill refunds or credits in exceptional circumstances.
Any such refund does not create an obligation to provide refunds in future cases.
11. Service Suspension
Ross & Sons Digital reserves the right to suspend services where:
-
Invoices remain unpaid.
-
The client breaches contractual obligations.
-
The client violates our Terms and Conditions or Acceptable Use Policy.
Any suspension does not entitle the client to a refund.
12. Consumer Rights
Nothing in this policy affects any statutory rights available to consumers under applicable UK consumer protection legislation.
13. Changes to this Policy
Ross & Sons Digital reserves the right to amend this Refund & Cancellation Policy at any time. Any updates will be published on our website and take effect immediately upon publication.
14. Contact Information
For questions regarding cancellations, refunds, or billing matters, please contact Ross & Sons Digital using the contact details provided on our website.
By purchasing or engaging any services from Ross & Sons Digital, you acknowledge that you have read, understood, and agree to this Refund & Cancellation Policy.
Acceptable Use Policy
Acceptable Use Policy
Last Updated: June 2026
1. Introduction
This Acceptable Use Policy ("Policy") sets out the rules governing the use of Ross & Sons Digital's website, services, software, applications, hosting environments, cloud platforms, AI solutions, and any related digital services.
By accessing or using our services, you agree to comply with this Policy.
2. Lawful Use
You must use our website and services only for lawful purposes and in accordance with all applicable laws and regulations.
You agree not to use our services in any way that may harm Ross & Sons Digital, its clients, partners, systems, reputation, or other users.
3. Prohibited Activities
Users must not:
-
Engage in any unlawful, fraudulent, or deceptive activity.
-
Upload, transmit, or distribute malicious software, viruses, ransomware, spyware, or harmful code.
-
Attempt to gain unauthorised access to systems, servers, networks, databases, or user accounts.
-
Circumvent security measures or authentication controls.
-
Interfere with the operation, performance, or security of our services.
-
Conduct denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks.
-
Use our services to distribute spam, unsolicited marketing communications, or phishing messages.
-
Impersonate another individual, organisation, or business.
-
Harvest, collect, or process personal data unlawfully.
-
Infringe the intellectual property rights of others.
4. Content Standards
Any content submitted, uploaded, published, or transmitted through our services must not:
-
Be unlawful, abusive, threatening, defamatory, or discriminatory.
-
Promote violence, hatred, harassment, or illegal activity.
-
Contain obscene, offensive, or harmful material.
-
Violate the rights of any individual or organisation.
-
Breach confidentiality obligations.
-
Infringe copyright, trademarks, patents, or other intellectual property rights.
Users remain solely responsible for any content they provide or publish.
5. AI and Automation Services
When using AI-powered solutions provided by Ross & Sons Digital, users must not:
-
Generate content intended to deceive, defraud, or mislead others.
-
Use AI systems for unlawful surveillance or monitoring.
-
Generate harmful, abusive, discriminatory, or illegal content.
-
Attempt to manipulate or abuse AI systems in a manner that could cause harm to others.
-
Rely solely on AI-generated outputs for critical legal, financial, medical, or regulatory decisions without appropriate human review.
6. Hosting and Cloud Services
Where Ross & Sons Digital provides hosting, cloud infrastructure, or managed services, users must not:
-
Host illegal content.
-
Operate malware, botnets, or malicious software.
-
Engage in cryptocurrency mining without prior written consent.
-
Use excessive resources in a manner that negatively impacts other users or services.
-
Store or distribute content that breaches applicable laws or regulations.
7. Cyber Security
Users are responsible for maintaining appropriate security measures, including:
-
Using strong passwords.
-
Protecting account credentials.
-
Keeping devices and software updated.
-
Reporting suspected security incidents promptly.
Any suspected security vulnerabilities affecting Ross & Sons Digital systems should be reported immediately.
8. Monitoring and Enforcement
Ross & Sons Digital reserves the right to monitor the use of its services where necessary to:
-
Protect systems and infrastructure.
-
Investigate suspected breaches of this Policy.
-
Comply with legal obligations.
-
Maintain service integrity and security.
9. Breach of Policy
Where we reasonably believe that this Policy has been breached, we may:
-
Issue warnings.
-
Suspend access to services.
-
Remove content.
-
Terminate service agreements.
-
Report unlawful activity to relevant authorities.
-
Pursue legal remedies where appropriate.
10. Limitation of Liability
Ross & Sons Digital accepts no responsibility for losses arising from a user's failure to comply with this Policy.
Users remain responsible for all actions undertaken through their accounts, systems, and authorised access credentials.
11. Changes to this Policy
We reserve the right to amend this Acceptable Use Policy at any time. Updated versions will be published on our website and will take effect immediately upon publication.
12. Contact Information
If you have any questions regarding this Acceptable Use Policy or wish to report a suspected breach, please contact Ross & Sons Digital using the contact details provided on our website.
By accessing our website or using our services, you confirm that you have read, understood, and agree to comply with this Acceptable Use Policy.
Website Disclaimer
Website Disclaimer
Last Updated: June 2026
General Information
The information contained on this website is provided by Ross & Sons Digital for general informational purposes only. Whilst we endeavour to keep the information accurate, current, and complete, we make no representations or warranties of any kind, express or implied, regarding the accuracy, reliability, suitability, or availability of the website or the information, products, services, or related content contained on the website.
Any reliance you place on such information is strictly at your own risk.
Professional Advice
The content provided on this website does not constitute legal, financial, accounting, cybersecurity, business, or professional advice.
Visitors should seek appropriate professional advice before making decisions based on information obtained from this website.
Service Information
Descriptions of services, pricing, features, and availability are provided for guidance only and may be subject to change without notice.
Any quotations provided by Ross & Sons Digital shall take precedence over information displayed on this website.
Website Availability
Ross & Sons Digital makes every effort to keep the website operational and accessible. However, we do not guarantee uninterrupted access and accept no responsibility for temporary unavailability caused by maintenance, technical issues, third-party providers, or circumstances beyond our control.
External Links
This website may contain links to external websites operated by third parties.
These links are provided for convenience only and do not imply endorsement of the content, services, or views expressed on those websites.
Ross & Sons Digital has no control over external websites and accepts no responsibility for their content, availability, privacy practices, or security.
Technology and Security
Whilst we implement reasonable security measures to protect this website, we cannot guarantee that the website, servers, downloads, or communications will be free from viruses, malware, or other harmful components.
Users are responsible for implementing their own security measures and ensuring that any downloads or interactions with the website are conducted safely.
Limitation of Liability
To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for any loss or damage, including but not limited to:
-
Direct or indirect financial loss
-
Loss of profits
-
Loss of business opportunities
-
Loss of data
-
Business interruption
-
Reputational damage
-
Any consequential or incidental losses
arising from the use of, or inability to use, this website or any information contained within it.
Intellectual Property
All website content, including text, graphics, logos, branding, designs, images, and software, is the property of Ross & Sons Digital unless otherwise stated.
Unauthorised copying, reproduction, distribution, modification, or use of website content is prohibited without prior written permission.
Testimonials and Case Studies
Any testimonials, reviews, case studies, or examples displayed on this website are intended to illustrate typical experiences and outcomes. Individual results may vary depending on circumstances, business requirements, market conditions, and implementation.
Ross & Sons Digital does not guarantee specific results or business outcomes.
Changes to This Disclaimer
Ross & Sons Digital reserves the right to update or amend this Website Disclaimer at any time without prior notice. Changes will become effective upon publication on this website.
Governing Law
This Disclaimer shall be governed by and interpreted in accordance with the laws of England and Wales.
Any disputes arising from the use of this website shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Contact Us
If you have any questions regarding this Website Disclaimer, please contact Ross & Sons Digital using the contact details provided on our website.
AI Services Disclaimer
AI Services Disclaimer
Last Updated: June 2026
Introduction
Ross & Sons Digital provides Artificial Intelligence (AI), automation, machine learning, chatbot, content generation, and related technology solutions to assist businesses in improving efficiency, productivity, and decision-making.
By using our AI-related services, you acknowledge and agree to the terms outlined in this disclaimer.
No Guarantee of Accuracy
Whilst we strive to implement reliable and effective AI solutions, AI-generated content, recommendations, responses, reports, and analyses may contain inaccuracies, omissions, outdated information, or unintended outputs.
Clients should independently review and verify all AI-generated content before relying upon, publishing, distributing, or implementing it.
Human Oversight Required
AI systems are designed to assist and support business operations and should not replace professional judgement, human review, or expert advice.
Ross & Sons Digital recommends that all AI-generated outputs are reviewed by an appropriately qualified individual before being used in business-critical decisions.
Business Decisions
Any decisions made based on AI-generated information remain the sole responsibility of the client.
Ross & Sons Digital shall not be liable for any losses, damages, costs, or business impacts arising from decisions made using AI-generated outputs, recommendations, forecasts, or automated processes.
Third-Party AI Platforms
Some AI services may utilise third-party technologies, platforms, APIs, or software providers.
Ross & Sons Digital is not responsible for:
-
Service interruptions or outages
-
Changes to third-party functionality
-
Pricing changes imposed by third-party providers
-
Errors originating from third-party AI systems
-
Data processing practices of third-party platforms
Clients may also be subject to the terms and conditions of those third-party providers.
AI Content Generation
Where AI is used to generate content, including but not limited to text, images, code, marketing materials, reports, or customer communications:
-
The client is responsible for reviewing all content before publication or use.
-
Ross & Sons Digital does not guarantee originality, accuracy, completeness, or suitability for a particular purpose.
-
Clients remain responsible for ensuring compliance with copyright, intellectual property, advertising, and regulatory requirements.
Data Privacy and Security
Ross & Sons Digital takes reasonable measures to protect data used within AI-powered solutions. However, clients should avoid submitting highly sensitive, confidential, or regulated information into AI systems unless appropriate safeguards and agreements are in place.
Clients are responsible for ensuring that their use of AI services complies with applicable data protection laws, including UK GDPR and the Data Protection Act 2018.
Availability of AI Services
AI technologies are constantly evolving. Ross & Sons Digital reserves the right to modify, replace, suspend, or discontinue AI-related services where necessary due to technological, commercial, legal, or operational reasons.
Limitation of Liability
To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for any direct, indirect, incidental, consequential, or financial losses arising from:
-
AI-generated content or recommendations
-
Automated decisions or actions
-
Errors, inaccuracies, or omissions in AI outputs
-
Service interruptions or failures
-
Reliance on AI-generated information
The client accepts full responsibility for the review, validation, and implementation of any AI-generated output.
Acceptance
By engaging Ross & Sons Digital for AI-related services, you acknowledge that AI technologies have inherent limitations and agree to use such services at your own discretion and risk.
For any questions regarding our AI services, please contact Ross & Sons Digital using the contact details provided on our website.
Mobile Application Acceptable Use & User Policy
Mobile Application Acceptable Use & User Policy
Last Updated: June 2026
1. Introduction
This Mobile Application Acceptable Use & User Policy ("Policy") governs the use of mobile applications, web applications, software platforms, and digital solutions developed, operated, or managed by Ross & Sons Digital.
By downloading, accessing, registering for, or using any application provided by Ross & Sons Digital, you agree to comply with this Policy.
2. Acceptance of Terms
By using our applications, you confirm that:
-
You have read and understood this Policy.
-
You agree to comply with all applicable laws and regulations.
-
You accept responsibility for your use of the application.
-
You are at least 18 years old or have permission from a parent or legal guardian where applicable.
3. Permitted Use
Our applications are intended for legitimate personal, business, or organisational use in accordance with their intended purpose.
Users may:
-
Access authorised features and services.
-
Store and manage permitted information.
-
Use communication and collaboration tools where available.
-
Access support services provided within the application.
4. Prohibited Use
Users must not:
-
Use the application for unlawful purposes.
-
Attempt to gain unauthorised access to systems, databases, servers, or user accounts.
-
Reverse engineer, decompile, modify, or copy the application without permission.
-
Introduce malware, viruses, spyware, or malicious code.
-
Upload harmful, offensive, defamatory, discriminatory, or illegal content.
-
Use automated tools, bots, or scripts to access the application without authorisation.
-
Interfere with the security, performance, or functionality of the application.
-
Circumvent licensing, subscription, or authentication mechanisms.
5. User Accounts
Where user accounts are required:
-
Users are responsible for maintaining the confidentiality of login credentials.
-
Passwords must not be shared with unauthorised individuals.
-
Users must notify Ross & Sons Digital immediately if they suspect unauthorised access.
-
Users are responsible for activities carried out under their account.
Ross & Sons Digital reserves the right to suspend or terminate accounts where misuse is suspected.
6. Data Protection and Privacy
Ross & Sons Digital is committed to protecting user privacy and handling personal information in accordance with applicable data protection laws, including the UK GDPR and Data Protection Act 2018.
Information collected through our applications will be processed in accordance with our Privacy Policy.
7. Intellectual Property Rights
All application content, source code, designs, logos, trademarks, features, functionality, and intellectual property remain the property of Ross & Sons Digital or its licensors unless otherwise agreed in writing.
Users are granted a limited, non-exclusive, non-transferable licence to use the application for its intended purpose.
No ownership rights are transferred through use of the application.
8. AI and Automated Features
Where applications include Artificial Intelligence (AI), machine learning, automation, or automated decision-making features:
-
Outputs should be reviewed before being relied upon.
-
AI-generated information may not always be accurate or complete.
-
Users remain responsible for decisions made based on AI-generated outputs.
-
Ross & Sons Digital accepts no liability for decisions made solely on AI-generated content.
Users must not use AI features to generate unlawful, misleading, harmful, discriminatory, or fraudulent content.
9. Availability of Services
Ross & Sons Digital will make reasonable efforts to maintain application availability but does not guarantee uninterrupted access.
We may temporarily suspend services for:
-
Maintenance
-
Security updates
-
Infrastructure upgrades
-
Emergency repairs
-
Regulatory compliance
10. Third-Party Services
Applications may integrate with third-party services, APIs, payment processors, cloud platforms, or external providers.
Ross & Sons Digital is not responsible for:
-
Service interruptions caused by third parties.
-
Third-party content or services.
-
Changes to third-party pricing or functionality.
-
Data handling practices of external providers.
Users may also be subject to additional third-party terms and conditions.
11. Security
Users agree to:
-
Use strong passwords.
-
Protect devices used to access the application.
-
Keep software and operating systems updated.
-
Report suspected security vulnerabilities promptly.
Ross & Sons Digital reserves the right to investigate security incidents and take appropriate action to protect users and systems.
12. Suspension and Termination
Ross & Sons Digital may suspend or terminate access where:
-
This Policy is breached.
-
Illegal activity is suspected.
-
Security risks are identified.
-
Subscription fees remain unpaid.
-
Continued access may negatively impact other users or systems.
13. Limitation of Liability
To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for:
-
Loss of profits
-
Loss of revenue
-
Loss of data
-
Business interruption
-
Indirect or consequential losses
-
Decisions made based on information provided within the application
Our total liability shall not exceed the fees paid by the user during the preceding 12 months, where applicable.
14. Updates and Changes
Ross & Sons Digital reserves the right to modify, update, enhance, or discontinue application features and services at any time.
We may also amend this Policy from time to time. Continued use of the application constitutes acceptance of any updated terms.
15. Governing Law
This Policy shall be governed by and interpreted in accordance with (UK GDPR) data protection act 2018 laws of England and Wales.
Any disputes arising from the use of our applications shall be subject to the exclusive jurisdiction of (UK GDPR) data protection act 2018 laws the courts of England and Wales.
Contact Information
For support, privacy enquiries, or questions regarding this Policy, please contact Ross & Sons Digital using the contact information available on our website.
By downloading, accessing, registering for, or using any application developed, operated, or managed by Ross & Sons Digital, you acknowledge that you have read, understood, and agree to comply with this Mobile Application Acceptable Use & User Policy.
Mobile Application Acceptable Use & User Policy
Mobile Application Acceptable Use & User Policy
Last Updated: June 2026
1. Introduction
This Mobile Application Acceptable Use & User Policy ("Policy") governs the use of mobile applications, web applications, software platforms, and digital solutions developed, operated, or managed by Ross & Sons Digital.
By downloading, accessing, registering for, or using any application provided by Ross & Sons Digital, you agree to comply with this Policy.
2. Acceptance of Terms
By using our applications, you confirm that:
-
You have read and understood this Policy.
-
You agree to comply with all applicable laws and regulations.
-
You accept responsibility for your use of the application.
-
You are at least 18 years old or have permission from a parent or legal guardian where applicable.
3. Permitted Use
Our applications are intended for legitimate personal, business, or organisational use in accordance with their intended purpose.
Users may:
-
Access authorised features and services.
-
Store and manage permitted information.
-
Use communication and collaboration tools where available.
-
Access support services provided within the application.
4. Prohibited Use
Users must not:
-
Use the application for unlawful purposes.
-
Attempt to gain unauthorised access to systems, databases, servers, or user accounts.
-
Reverse engineer, decompile, modify, or copy the application without permission.
-
Introduce malware, viruses, spyware, or malicious code.
-
Upload harmful, offensive, defamatory, discriminatory, or illegal content.
-
Use automated tools, bots, or scripts to access the application without authorisation.
-
Interfere with the security, performance, or functionality of the application.
-
Circumvent licensing, subscription, or authentication mechanisms.
5. User Accounts
Where user accounts are required:
-
Users are responsible for maintaining the confidentiality of login credentials.
-
Passwords must not be shared with unauthorised individuals.
-
Users must notify Ross & Sons Digital immediately if they suspect unauthorised access.
-
Users are responsible for activities carried out under their account.
Ross & Sons Digital reserves the right to suspend or terminate accounts where misuse is suspected.
6. Data Protection and Privacy
Ross & Sons Digital is committed to protecting user privacy and handling personal information in accordance with applicable data protection laws, including the UK GDPR and Data Protection Act 2018.
Information collected through our applications will be processed in accordance with our Privacy Policy.
7. Intellectual Property Rights
All application content, source code, designs, logos, trademarks, features, functionality, and intellectual property remain the property of Ross & Sons Digital or its licensors unless otherwise agreed in writing.
Users are granted a limited, non-exclusive, non-transferable licence to use the application for its intended purpose.
No ownership rights are transferred through use of the application.
8. AI and Automated Features
Where applications include Artificial Intelligence (AI), machine learning, automation, or automated decision-making features:
-
Outputs should be reviewed before being relied upon.
-
AI-generated information may not always be accurate or complete.
-
Users remain responsible for decisions made based on AI-generated outputs.
-
Ross & Sons Digital accepts no liability for decisions made solely on AI-generated content.
Users must not use AI features to generate unlawful, misleading, harmful, discriminatory, or fraudulent content.
9. Availability of Services
Ross & Sons Digital will make reasonable efforts to maintain application availability but does not guarantee uninterrupted access.
We may temporarily suspend services for:
-
Maintenance
-
Security updates
-
Infrastructure upgrades
-
Emergency repairs
-
Regulatory compliance
10. Third-Party Services
Applications may integrate with third-party services, APIs, payment processors, cloud platforms, or external providers.
Ross & Sons Digital is not responsible for:
-
Service interruptions caused by third parties.
-
Third-party content or services.
-
Changes to third-party pricing or functionality.
-
Data handling practices of external providers.
Users may also be subject to additional third-party terms and conditions.
11. Security
Users agree to:
-
Use strong passwords.
-
Protect devices used to access the application.
-
Keep software and operating systems updated.
-
Report suspected security vulnerabilities promptly.
Ross & Sons Digital reserves the right to investigate security incidents and take appropriate action to protect users and systems.
12. Suspension and Termination
Ross & Sons Digital may suspend or terminate access where:
-
This Policy is breached.
-
Illegal activity is suspected.
-
Security risks are identified.
-
Subscription fees remain unpaid.
-
Continued access may negatively impact other users or systems.
13. Limitation of Liability
To the fullest extent permitted by law, Ross & Sons Digital shall not be liable for:
-
Loss of profits
-
Loss of revenue
-
Loss of data
-
Business interruption
-
Indirect or consequential losses
-
Decisions made based on information provided within the application
Our total liability shall not exceed the fees paid by the user during the preceding 12 months, where applicable.
14. Updates and Changes
Ross & Sons Digital reserves the right to modify, update, enhance, or discontinue application features and services at any time.
We may also amend this Policy from time to time. Continued use of the application constitutes acceptance of any updated terms.
15. Governing Law
This Policy shall be governed by and interpreted in accordance with (UK GDPR) data protection act 2018 laws of England and Wales.
Any disputes arising from the use of our applications shall be subject to the exclusive jurisdiction of (UK GDPR) data protection act 2018 laws the courts of England and Wales.
Contact Information
For support, privacy enquiries, or questions regarding this Policy, please contact Ross & Sons Digital using the contact information available on our website.
By downloading, accessing, registering for, or using any application developed, operated, or managed by Ross & Sons Digital, you acknowledge that you have read, understood, and agree to comply with this Mobile Application Acceptable Use & User Policy.
Data Flow Diagram (DFD)
Data Flow Diagram (DFD)
System: Incident Management System
Version: 1.0
Data Flow Overview
- ┌──────────────────────────────┐
│ End Users │
│------------------------------│
│ • Officers │
│ • Managers │
│ • Administrators │
└──────────────┬───────────────┘
│
Personal Data Entry (HTTPS/TLS)
│
▼
┌────────────────────────────────┐
│ Incident Management System │
│ │
│ • Authentication │
│ • Incident Processing │
│ • User Management │
│ • Audit Logging │
│ • Senior Reviews │
└──────────────┬─────────────────┘
│
┌───────────────────────┼────────────────────────┐
│ │ │
▼ ▼ ▼
Microsoft Entra ID Secure Database Audit Log Service
(Microsoft Login) (Application Data) (Edit History)
│ │ │
└───────────────────────┼────────────────────────┘
│
▼
Encrypted Backups
│
▼
Disaster Recovery Storage
Personal Data Flow
1. Data Collection
Personal information is collected from authorised users when they:
-
Sign in using Microsoft
-
Create an incident
-
Edit an incident
-
Create a Senior Review
-
Manage user accounts
-
Update records
Typical data includes:
-
Name
-
Email address
-
Job title
-
Department
-
Incident details
-
Persons involved
-
Dates and times
-
Locations
-
Investigation notes
-
Attachments (if enabled)
2. Authentication
Multi-Factor Authentication (MFA) through the customer's chosen identity provider.
The application receives:
-
User name
-
Email address
-
Unique user identifier
-
Authentication token
-
Assigned role (Officer or Manager)
Passwords are never stored by Ross & Sons Digital.
3. Data Processing
Once authenticated, the application processes personal data to:
-
Create incident records
-
Update incidents
-
Assign investigations
-
Record Senior Reviews
-
Manage permissions
-
Generate reports
-
Record audit history
Processing is limited to authorised users based on role-based access controls.
4. Data Storage
Personal information is securely stored within the application's cloud-hosted database.
Stored information may include:
-
User accounts
-
Incident records
-
Investigation notes
-
Senior Reviews
-
Audit logs
-
User permissions
-
System configuration
All communication with the database is encrypted using HTTPS/TLS.
5. Audit Logging
Every significant action is automatically recorded.
Audit records include:
-
User identity
-
Date and time
-
Action performed
-
Record affected
-
Fields changed
Audit records are generated server-side and cannot be modified by users.
6. Data Sharing
The application shares information only where necessary to provide the service.
Examples include:
-
Microsoft Entra ID (authentication)
-
Cloud hosting provider (secure storage)
-
Authorised administrators
-
Customer organisations
No personal data is sold or shared for marketing purposes.
7. Data Retention
Information is retained in accordance with:
-
Customer retention policies
-
NHS records management requirements (where applicable)
-
UK GDPR
-
Legal obligations
Data is securely deleted when no longer required.
8. Data Disposal
When records reach the end of their retention period, they are securely removed using appropriate deletion procedures to reduce the risk of unauthorised recovery.
Data Categories
Data Category Purpose Name User identification Email address Authentication and communication Job title User roleDepartment Organisational reporting Incident details Incident management Locations Investigation Dates and times Incident chronology Investigation notes Case management Audit history Accountability User permissions Access control
Lawful Processing
The system processes information to support:
-
Incident reporting
-
Investigation management
-
Organisational governance
-
Health and safety
-
Security management
-
Compliance and audit
Processing is undertaken by the customer organisation in accordance with the UK GDPR and the Data Protection Act 2018.
Security Controls Protecting Data
-
Microsoft Entra ID authentication
-
HTTPS/TLS encryption
-
Role-Based Access Control (RBAC)
-
Server-side session management
-
Comprehensive audit logging
-
Secure cloud hosting
-
Regular security updates
-
Encrypted backups
Data Flow Summary
Source Processing Storage Output User Microsoft Entra ID authentication Cloud database Secure access User Incident creation and updates Incident records Reports and investigations Manager Senior Reviews Review records Governance oversight System Audit logging Audit database Compliance and accountability Database Encrypted backups Backup storage Disaster recovery
Data Protection Principles
The Incident Management System has been designed to support the core principles of the UK GDPR:
-
Lawfulness, fairness, and transparency
-
Purpose limitation
-
Data minimisation
-
Accuracy
-
Storage limitation
-
Integrity and confidentiality
-
Accountability
This Data Flow Diagram demonstrates how personal data is collected, processed, stored, protected, and retained within the system, supporting secure and compliant incident management.
Technical Architecture Diagram
Ross & Sons Digital
Technical Architecture Diagram
System: Incident Management System
Version: 1.0
High-Level Architecture
┌──────────────────────────────┐ │ End Users │ │------------------------------│ │ • Officers │ │ • Managers │ │ • System Administrators │ └──────────────┬───────────────┘ │ │ HTTPS / TLS 1.2+ ▼ ┌────────────────────────────────────┐ │ Microsoft Authentication │ │ (Microsoft Entra ID) │ └──────────────┬─────────────────────┘ │ Secure OAuth Authentication │ ▼ ┌───────────────────────────────────────────────┐ │ Ross & Sons Digital Cloud Application │ │ │ │ • Incident Management Portal │ │ • User Management │ │ • Senior Reviews │ │ • Audit Logging │ │ • Role-Based Access Control │ │ • Session Management │ └──────────────┬────────────────────────────────┘ │ ┌────────────────┼────────────────┐ │ │ │ ▼ ▼ ▼ ┌────────────────┐ ┌────────────────┐ ┌─────────────────┐ │ Incident API │ │ User API │ │ Audit API │ │ │ │ │ │ │ │ Incident CRUD │ │ Authentication │ │ Edit History │ │ Search │ │ Permissions │ │ Activity Logs │ └────────┬───────┘ └────────┬───────┘ └────────┬────────┘ │ │ │ └──────────────────┼──────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Secure Cloud Database │ │-------------------------------------│ │ • Incident Records │ │ • User Accounts │ │ • Roles & Permissions │ │ • Senior Reviews │ │ • Audit History │ │ • Configuration Data │ └─────────────────────────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Backup & Recovery Services │ │-------------------------------------│ │ • Encrypted Backups │ │ • Disaster Recovery │ │ • Restore Procedures │ └─────────────────────────────────────┘
Authentication Flow
-
User opens the Incident Management System.
-
The application redirects the user to Microsoft Entra ID (Microsoft).
-
Microsoft authenticates the user.
-
A secure authentication token is returned.
-
The application validates the token.
-
The user's role (Officer or Manager) is retrieved.
-
Access is granted according to role-based permissions.
No Microsoft passwords are stored by Ross & Sons Digital.
Network Flow
User Device │ HTTPS / TLS │ ▼ Microsoft Entra ID │ OAuth Authentication │ ▼ Incident Management Application │ Secure API Requests │ ▼ Cloud Database │ Encrypted Storage │ ▼ Backup Services
Core Components
User Interface
-
Responsive web application
-
Secure login
-
Incident dashboard
-
User management
-
Senior reviews
-
Audit history
Authentication
-
Microsoft Sign-In
-
OAuth 2.0
-
Microsoft Entra ID
-
Optional Multi-Factor Authentication (controlled by the customer)
Application Services
-
Incident Management
-
User Management
-
Audit Logging
-
Senior Reviews
-
Session Management
-
Role-Based Access Control (RBAC)
APIs
-
Incident API
-
Authentication API
-
User Management API
-
Audit Logging API
Database
-
Incident Records
-
User Profiles
-
Roles & Permissions
-
Audit Logs
-
Senior Reviews
-
System Configuration
Security Controls
-
HTTPS/TLS encrypted communications
-
Microsoft Entra ID authentication
-
OAuth 2.0 token validation
-
Server-side session management
-
Role-Based Access Control (RBAC)
-
Comprehensive audit logging
-
Immediate session termination when access is revoked
-
Secure cloud-hosted infrastructure
-
Regular software updates and security patching
Data Flow Summary
Source Destination Data User Microsoft Entra ID Authentication request Microsoft Entra ID Application Authentication token Application Database Incident records Database Application Incident information Application Audit Service User activity logs Database Backup Service Encrypted backups
Hosting Architecture
-
Cloud-hosted application
-
Secure HTTPS endpoint
-
Managed database service
-
Encrypted storage
-
Secure backup services
-
High-availability infrastructure (where supported by the hosting provider)
Disaster Recovery
-
Encrypted backups
-
Documented restore procedures
-
Regular backup verification
-
Recovery Time Objective (RTO): 4 hours
-
Recovery Point Objective (RPO): 1 hour
Architecture Principles
The Incident Management System has been designed around the principles of security, availability, integrity, confidentiality, and accountability. It uses trusted Microsoft identity services for authentication, role-based authorisation for access control, server-side audit logging for accountability, and secure cloud infrastructure to support resilience and business continuity.
Business Continuity & Disaster Recovery Plan (BCP/DRP)
Ross & Sons Digital
Business Continuity & Disaster Recovery Plan (BCP/DRP)
Document Title: Business Continuity & Disaster Recovery Plan
System: Incident Management System
Version: 1.0
Document Owner: Ross & Sons Digital
Approved By: Director – Ross & Sons Digital
Review Date: Annually or following any major system change
- Purpose
This Business Continuity and Disaster Recovery (BCDR) Plan outlines the procedures Ross & Sons Digital will follow to maintain or restore the Incident Management System following an unexpected disruption.
The objective of this plan is to minimise downtime, protect customer data, maintain service availability, and ensure business operations can continue following a technical failure, cyber incident, or disaster.
- Scope
This plan applies to:
- Incident Management System
- Web application
- Cloud-hosted infrastructure
- Application database
- Authentication services
- Supporting APIs
- Administrative portal
- Customer support services
- Business Objectives
The objectives of this plan are to:
- Protect confidential information.
- Maintain system availability.
- Minimise operational disruption.
- Restore services as quickly as possible.
- Meet contractual obligations.
- Support NHS and UK GDPR requirements.
- Ensure business resilience.
- Recovery Objectives
Objective
Target
Recovery Time Objective (RTO)
Within 4 hours
Recovery Point Objective (RPO)
Maximum 1 hour of data loss
Critical Incident Response
Immediate
Customer Notification
Within 2 hours where appropriate
- Critical Services
The following services are considered critical:
- User (MFA) authentication
- Incident Database
- Cloud Hosting Platform
- Secure API Services
- User Management
- Audit Logging
- Incident Reporting
- Senior Review Functions
- Roles and Responsibilities
Director
Responsible for:
- Activating the Business Continuity Plan
- Customer communications
- Supplier management
- Incident escalation
- Final approval of recovery
Technical Lead
Responsible for:
- Technical investigation
- System restoration
- Security patching
- Database recovery
- Infrastructure monitoring
Cyber Security Lead
Responsible for:
- Security incident response
- Threat analysis
- Vulnerability management
- Security reporting
- Liaison with customer cyber teams
Customers
Customers should:
- Report incidents promptly
- Follow local business continuity procedures
- Notify Ross & Sons Digital of suspected security incidents
- Risk Assessment
Potential disruption may include:
- Cloud service outage
- Internet connectivity failure
- Cyber attack
- Ransomware
- Hardware failure
- Database corruption
- Human error
- Software defects
- Power outage
- Third-party service failure
- Preventative Measures
Ross & Sons Digital implements the following controls:
- Secure cloud hosting
- HTTPS encryption
- Microsoft User (MFA) authentication
- Role-Based Access Control
- Audit logging
- Server-side session management
- Software version control
- Change management
- Security monitoring
- Regular software updates
- Backup Strategy
Application data is backed up regularly.
Backups include:
- Incident database
- User configuration
- Application configuration
- Audit logs
Backups are:
- Encrypted
- Securely stored
- Tested periodically
- Protected from unauthorised access
Backup restoration procedures are documented and tested.
- Disaster Recovery Procedures
Step 1
Identify the incident.
Determine:
- Nature of the issue
- Impact
- Systems affected
- Severity
Step 2
Contain the incident.
Actions may include:
- Disabling affected services
- Restricting access
- Isolating compromised systems
- Blocking malicious activity
Step 3
Notify stakeholders.
Where appropriate notify:
- Customers
- ICT Teams
- Cyber Security Teams
- Senior Management
Step 4
Recover services.
Recovery may include:
- Restore database
- Deploy latest application version
- Restore backups
- Verify authentication services
- Test functionality
Step 5
Validate system.
Checks include:
- User (MFA) authentication
- Incident creation
- Incident editing
- Audit history
- User permissions
- Senior Reviews
- Reporting functionality
Step 6
Return to service.
The system will only return to production once testing confirms services are operating correctly.
- Cyber Incident Response
Where a cyber incident is suspected:
Immediate actions include:
- Preserve evidence.
- Isolate affected systems.
- Investigate activity.
- Review audit logs.
- Notify customers where appropriate.
- Apply security patches.
- Restore secure services.
Where legally required, appropriate regulatory reporting procedures will be followed.
- Data Recovery
Recovery priority:
- User (MFA) authentication
- Database restoration
- Incident records
- Audit logs
- User accounts
- Reporting functions
- Administrative services
- Communication Plan
During a major incident Ross & Sons Digital will:
- Provide regular customer updates.
- Confirm estimated recovery times.
- Notify customers of completed recovery.
- Provide a post-incident summary where appropriate.
- Testing
This plan will be tested:
- At least annually.
- Following significant infrastructure changes.
- Following major software releases.
- After significant incidents.
Testing may include:
- Backup restoration
- Disaster recovery exercises
- Authentication testing
- Security testing
- Infrastructure failover testing
- Review
This document will be reviewed:
- Every 12 months
- Following major incidents
- Following infrastructure changes
- Following security incidents
- Following customer feedback
- Document Control
Version
Date
Author
Description
1.0
June 2026
Leroy Ross
Initial Release
- Approval
Prepared by:
Leroy Ross
Director
Ross & Sons Digital
Approved by:
Signature: __Leroy Ross______
Date: _____ 18/06/2026_____
Appendix A – System Security Summary
The Incident Management System includes:
- User (MFA) authentication
- Role-Based Access Control (RBAC)
- Server-side session management
- Secure HTTPS/TLS encryption
- Comprehensive audit logging
- User account management
- Immediate session revocation on account removal
- Cloud-hosted infrastructure
- Secure application updates
- Regular maintenance and security patching
Appendix B – Recovery Targets
Service
Priority
Target Recovery
Authentication
Critical
1 Hour
Database
Critical
2 Hours
Incident Recording
Critical
2 Hours
Audit Logging
Critical
2 Hours
User Management
High
4 Hours
Reporting Functions
Medium
4 Hours
Commitment
Ross & Sons Digital is committed to maintaining the confidentiality, integrity, and availability of customer information. This Business Continuity and Disaster Recovery Plan supports our commitment to delivering secure, reliable, and resilient digital services and aligns with recognised information security and business continuity best practices.
Security Controls
Security Controls
Information Security Controls
The Incident Management System has been designed using a security-by-design approach to protect confidential information and maintain the integrity and availability of data.
Security measures include:
- Microsoft Multi-Factor Authentication (MFA) for verified user access.
- Role-based access controls (RBAC).
- Server-side session management.
- Comprehensive audit logging.
- Secure password handling by the identity provider.
- Automatic session validation.
- Principle of least privilege for user permissions.
- Secure cloud hosting.
- Encrypted communications using HTTPS/TLS.
- Regular application updates and maintenance.
Encryption
Data in Transit
All communications between users and the application are encrypted using HTTPS with TLS.
Data at Rest
Application data is stored within secure cloud-hosted databases. Encryption at rest should be enabled through the hosting provider where available.
Sensitive credentials are never stored in plain text.
Authentication & Multi-Factor Authentication (MFA)
User authentication is performed using Microsoft 365 authentication services.
This provides:
- Secure sign-in
- Centralised identity management
- Password policy enforcement
- Support for Multi-Factor Authentication where enabled by the organisation
- Conditional Access policies managed by Microsoft Entra ID
The application does not manage user passwords directly.
Access Control
Access is controlled using role-based permissions.
Officer
- Create incidents
- Edit incidents
- View authorised records
Manager
- Delete incidents
- Create Senior Reviews
- View complete audit history
- Manage user accounts
- Promote users
- Remove user access
All permissions are managed server-side.
Audit Logging
Every significant action is recorded, including:
- User authentication
- Incident creation
- Incident edits
- User account changes
- Permission changes
- Senior Reviews
- Administrative actions
Audit logs record:
- Verified user identity
- Date and time
- Action performed
- Record affected
Audit information cannot be altered by end users.
Cyber Security
The application has been developed in accordance with recognised secure development principles.
Security measures include:
- Server-side validation
- Input validation
- Authentication controls
- Role-based authorisation
- Secure session management
- Secure API access
- Audit logging
- HTTPS encryption
Security updates will be applied promptly following the identification of vulnerabilities.
Security Patching
Ross & Sons Digital will:
- Monitor security vulnerabilities.
- Apply security patches promptly.
- Update application dependencies regularly.
- Review third-party libraries for known vulnerabilities.
- Maintain software versions supported by vendors.
Critical security patches will be prioritised.
Penetration Testing
Prior to production deployment, independent penetration testing should be completed.
Testing should include:
- Authentication testing
- Authorisation testing
- API security
- OWASP Top 10 assessment
- Session management
- Injection testing
- Cross-site scripting testing
- Business logic testing
Any identified vulnerabilities should be remediated before deployment.
Business Continuity
The application has been designed to minimise service disruption.
Business continuity measures include:
- Secure cloud hosting
- Database backups
- Disaster recovery procedures
- Controlled software deployment
- Monitoring of system availability
- Secure user authentication
Document your Recovery Time Objective (RTO) and Recovery Point Objective (RPO) if these have been defined.
Data Protection
The application has been developed in accordance with UK GDPR principles, including:
- Lawfulness
- Fairness
- Transparency
- Data minimisation
- Accuracy
- Storage limitation
- Integrity
- Confidentiality
- Accountability
Only information necessary for incident management is processed.
Lawful Basis (UK GDPR)
Personal Data
Article 6(1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Special Category Data
Where special category data is processed:
Article 9(2)(h) – Management of health or social care systems.
or
Article 9(2)(g) – Substantial public interest.
The Trust's Information Governance Team should confirm the appropriate lawful basis.
Risk Assessment
Risk Mitigation Unauthorised access Microsoft authentication, RBAC, server-side session management Weak passwords Password policies and MFA managed through Microsoft Data interception HTTPS/TLS encryption Data loss Regular backups and disaster recovery procedures Privilege misuse Role-based permissions and audit logging User error Training, user guides, and least-privilege access Software vulnerabilities Regular patching and vulnerability monitoring Session hijacking Secure server-side session management Insider threats Comprehensive audit trails and user accountability Unauthorised changes Server-authoritative audit logging and restricted permissions.
Data Flow Diagram (DFD)
Data Flow Diagram (DFD)
System: Incident Management System
Version: 1.0
Data Flow Overview
- ┌──────────────────────────────┐
│ End Users │
│------------------------------│
│ • Officers │
│ • Managers │
│ • Administrators │
└──────────────┬───────────────┘
│
Personal Data Entry (HTTPS/TLS)
│
▼
┌────────────────────────────────┐
│ Incident Management System │
│ │
│ • Authentication │
│ • Incident Processing │
│ • User Management │
│ • Audit Logging │
│ • Senior Reviews │
└──────────────┬─────────────────┘
│
┌───────────────────────┼────────────────────────┐
│ │ │
▼ ▼ ▼
Microsoft Entra ID Secure Database Audit Log Service
(Microsoft Login) (Application Data) (Edit History)
│ │ │
└───────────────────────┼────────────────────────┘
│
▼
Encrypted Backups
│
▼
Disaster Recovery Storage
Personal Data Flow
1. Data Collection
Personal information is collected from authorised users when they:
-
Sign in using Microsoft
-
Create an incident
-
Edit an incident
-
Create a Senior Review
-
Manage user accounts
-
Update records
Typical data includes:
-
Name
-
Email address
-
Job title
-
Department
-
Incident details
-
Persons involved
-
Dates and times
-
Locations
-
Investigation notes
-
Attachments (if enabled)
2. Authentication
Multi-Factor Authentication (MFA) through the customer's chosen identity provider.
The application receives:
-
User name
-
Email address
-
Unique user identifier
-
Authentication token
-
Assigned role (Officer or Manager)
Passwords are never stored by Ross & Sons Digital.
Technical Architecture Diagram
Ross & Sons Digital
Technical Architecture Diagram
System: Incident Management System
Version: 1.0
High-Level Architecture
┌──────────────────────────────┐ │ End Users │ │------------------------------│ │ • Officers │ │ • Managers │ │ • System Administrators │ └──────────────┬───────────────┘ │ │ HTTPS / TLS 1.2+ ▼ ┌────────────────────────────────────┐ │ Microsoft Authentication │ │ (Microsoft Entra ID) │ └──────────────┬─────────────────────┘ │ Secure OAuth Authentication │ ▼ ┌───────────────────────────────────────────────┐ │ Ross & Sons Digital Cloud Application │ │ │ │ • Incident Management Portal │ │ • User Management │ │ • Senior Reviews │ │ • Audit Logging │ │ • Role-Based Access Control │ │ • Session Management │ └──────────────┬────────────────────────────────┘ │ ┌────────────────┼────────────────┐ │ │ │ ▼ ▼ ▼ ┌────────────────┐ ┌────────────────┐ ┌─────────────────┐ │ Incident API │ │ User API │ │ Audit API │ │ │ │ │ │ │ │ Incident CRUD │ │ Authentication │ │ Edit History │ │ Search │ │ Permissions │ │ Activity Logs │ └────────┬───────┘ └────────┬───────┘ └────────┬────────┘ │ │ │ └──────────────────┼──────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Secure Cloud Database │ │-------------------------------------│ │ • Incident Records │ │ • User Accounts │ │ • Roles & Permissions │ │ • Senior Reviews │ │ • Audit History │ │ • Configuration Data │ └─────────────────────────────────────┘ │ ▼ ┌─────────────────────────────────────┐ │ Backup & Recovery Services │ │-------------------------------------│ │ • Encrypted Backups │ │ • Disaster Recovery │ │ • Restore Procedures │ └─────────────────────────────────────┘
Authentication Flow
-
User opens the Incident Management System.
-
The application redirects the user to Microsoft Entra ID (Microsoft).
-
Microsoft authenticates the user.
-
A secure authentication token is returned.
-
The application validates the token.
-
The user's role (Officer or Manager) is retrieved.
-
Access is granted according to role-based permissions.
No Microsoft passwords are stored by Ross & Sons Digital.
Network Flow
User Device │ HTTPS / TLS │ ▼ Microsoft Entra ID │ OAuth Authentication │ ▼ Incident Management Application │ Secure API Requests │ ▼ Cloud Database │ Encrypted Storage │ ▼ Backup Services
Core Components
User Interface
-
Responsive web application
-
Secure login
-
Incident dashboard
-
User management
-
Senior reviews
-
Audit history
Authentication
-
Microsoft Sign-In
-
OAuth 2.0
-
Microsoft Entra ID
-
Optional Multi-Factor Authentication (controlled by the customer)
Application Services
-
Incident Management
-
User Management
-
Audit Logging
-
Senior Reviews
-
Session Management
-
Role-Based Access Control (RBAC)
APIs
-
Incident API
-
Authentication API
-
User Management API
-
Audit Logging API
Database
-
Incident Records
-
User Profiles
-
Roles & Permissions
-
Audit Logs
-
Senior Reviews
-
System Configuration
Security Controls
-
HTTPS/TLS encrypted communications
-
Microsoft Entra ID authentication
-
OAuth 2.0 token validation
-
Server-side session management
-
Role-Based Access Control (RBAC)
-
Comprehensive audit logging
-
Immediate session termination when access is revoked
-
Secure cloud-hosted infrastructure
-
Regular software updates and security patching
Data Flow Summary
Source Destination Data User Microsoft Entra ID Authentication request Microsoft Entra ID Application Authentication token Application Database Incident records Database Application Incident information Application Audit Service User activity logs Database Backup Service Encrypted backups
Hosting Architecture
-
Cloud-hosted application
-
Secure HTTPS endpoint
-
Managed database service
-
Encrypted storage
-
Secure backup services
-
High-availability infrastructure (where supported by the hosting provider)
Disaster Recovery
-
Encrypted backups
-
Documented restore procedures
-
Regular backup verification
-
Recovery Time Objective (RTO): 4 hours
-
Recovery Point Objective (RPO): 1 hour
Architecture Principles
The Incident Management System has been designed around the principles of security, availability, integrity, confidentiality, and accountability. It uses trusted Microsoft identity services for authentication, role-based authorisation for access control, server-side audit logging for accountability, and secure cloud infrastructure to support resilience and business continuity.
Business Continuity & Disaster Recovery Plan (BCP/DRP)
Ross & Sons Digital
Business Continuity & Disaster Recovery Plan (BCP/DRP)
Document Title: Business Continuity & Disaster Recovery Plan
System: Incident Management System
Version: 1.0
Document Owner: Ross & Sons Digital
Approved By: Director – Ross & Sons Digital
Review Date: Annually or following any major system change
- Purpose
This Business Continuity and Disaster Recovery (BCDR) Plan outlines the procedures Ross & Sons Digital will follow to maintain or restore the Incident Management System following an unexpected disruption.
The objective of this plan is to minimise downtime, protect customer data, maintain service availability, and ensure business operations can continue following a technical failure, cyber incident, or disaster.
- Scope
This plan applies to:
- Incident Management System
- Web application
- Cloud-hosted infrastructure
- Application database
- Authentication services
- Supporting APIs
- Administrative portal
- Customer support services
- Business Objectives
The objectives of this plan are to:
- Protect confidential information.
- Maintain system availability.
- Minimise operational disruption.
- Restore services as quickly as possible.
- Meet contractual obligations.
- Support NHS and UK GDPR requirements.
- Ensure business resilience.
- Recovery Objectives
Objective
Target
Recovery Time Objective (RTO)
Within 4 hours
Recovery Point Objective (RPO)
Maximum 1 hour of data loss
Critical Incident Response
Immediate
Customer Notification
Within 2 hours where appropriate
- Critical Services
The following services are considered critical:
- User (MFA) authentication
- Incident Database
- Cloud Hosting Platform
- Secure API Services
- User Management
- Audit Logging
- Incident Reporting
- Senior Review Functions
- Roles and Responsibilities
Director
Responsible for:
- Activating the Business Continuity Plan
- Customer communications
- Supplier management
- Incident escalation
- Final approval of recovery
Technical Lead
Responsible for:
- Technical investigation
- System restoration
- Security patching
- Database recovery
- Infrastructure monitoring
Cyber Security Lead
Responsible for:
- Security incident response
- Threat analysis
- Vulnerability management
- Security reporting
- Liaison with customer cyber teams
Customers
Customers should:
- Report incidents promptly
- Follow local business continuity procedures
- Notify Ross & Sons Digital of suspected security incidents
- Risk Assessment
Potential disruption may include:
- Cloud service outage
- Internet connectivity failure
- Cyber attack
- Ransomware
- Hardware failure
- Database corruption
- Human error
- Software defects
- Power outage
- Third-party service failure
- Preventative Measures
Ross & Sons Digital implements the following controls:
- Secure cloud hosting
- HTTPS encryption
- Microsoft User (MFA) authentication
- Role-Based Access Control
- Audit logging
- Server-side session management
- Software version control
- Change management
- Security monitoring
- Regular software updates
- Backup Strategy
Application data is backed up regularly.
Backups include:
- Incident database
- User configuration
- Application configuration
- Audit logs
Backups are:
- Encrypted
- Securely stored
- Tested periodically
- Protected from unauthorised access
Backup restoration procedures are documented and tested.
- Disaster Recovery Procedures
Step 1
Identify the incident.
Determine:
- Nature of the issue
- Impact
- Systems affected
- Severity
Step 2
Contain the incident.
Actions may include:
- Disabling affected services
- Restricting access
- Isolating compromised systems
- Blocking malicious activity
Step 3
Notify stakeholders.
Where appropriate notify:
- Customers
- ICT Teams
- Cyber Security Teams
- Senior Management
Step 4
Recover services.
Recovery may include:
- Restore database
- Deploy latest application version
- Restore backups
- Verify authentication services
- Test functionality
Step 5
Validate system.
Checks include:
- User (MFA) authentication
- Incident creation
- Incident editing
- Audit history
- User permissions
- Senior Reviews
- Reporting functionality
Step 6
Return to service.
The system will only return to production once testing confirms services are operating correctly.
- Cyber Incident Response
Where a cyber incident is suspected:
Immediate actions include:
- Preserve evidence.
- Isolate affected systems.
- Investigate activity.
- Review audit logs.
- Notify customers where appropriate.
- Apply security patches.
- Restore secure services.
Where legally required, appropriate regulatory reporting procedures will be followed.
- Data Recovery
Recovery priority:
- User (MFA) authentication
- Database restoration
- Incident records
- Audit logs
- User accounts
- Reporting functions
- Administrative services
- Communication Plan
During a major incident Ross & Sons Digital will:
- Provide regular customer updates.
- Confirm estimated recovery times.
- Notify customers of completed recovery.
- Provide a post-incident summary where appropriate.
- Testing
This plan will be tested:
- At least annually.
- Following significant infrastructure changes.
- Following major software releases.
- After significant incidents.
Testing may include:
- Backup restoration
- Disaster recovery exercises
- Authentication testing
- Security testing
- Infrastructure failover testing
- Review
This document will be reviewed:
- Every 12 months
- Following major incidents
- Following infrastructure changes
- Following security incidents
- Following customer feedback
- Document Control
Version
Date
Author
Description
1.0
June 2026
Leroy Ross
Initial Release
- Approval
Prepared by:
Leroy Ross
Director
Ross & Sons Digital
Approved by:
Signature: __Leroy Ross______
Date: _____ 18/06/2026_____
Appendix A – System Security Summary
The Incident Management System includes:
- User (MFA) authentication
- Role-Based Access Control (RBAC)
- Server-side session management
- Secure HTTPS/TLS encryption
- Comprehensive audit logging
- User account management
- Immediate session revocation on account removal
- Cloud-hosted infrastructure
- Secure application updates
- Regular maintenance and security patching
Appendix B – Recovery Targets
Service
Priority
Target Recovery
Authentication
Critical
1 Hour
Database
Critical
2 Hours
Incident Recording
Critical
2 Hours
Audit Logging
Critical
2 Hours
User Management
High
4 Hours
Reporting Functions
Medium
4 Hours
Commitment
Ross & Sons Digital is committed to maintaining the confidentiality, integrity, and availability of customer information. This Business Continuity and Disaster Recovery Plan supports our commitment to delivering secure, reliable, and resilient digital services and aligns with recognised information security and business continuity best practices.
Security Controls
Security Controls
Information Security Controls
The Incident Management System has been designed using a security-by-design approach to protect confidential information and maintain the integrity and availability of data.
Security measures include:
- Microsoft Multi-Factor Authentication (MFA) for verified user access.
- Role-based access controls (RBAC).
- Server-side session management.
- Comprehensive audit logging.
- Secure password handling by the identity provider.
- Automatic session validation.
- Principle of least privilege for user permissions.
- Secure cloud hosting.
- Encrypted communications using HTTPS/TLS.
- Regular application updates and maintenance.
Encryption
Data in Transit
All communications between users and the application are encrypted using HTTPS with TLS.
Data at Rest
Application data is stored within secure cloud-hosted databases. Encryption at rest should be enabled through the hosting provider where available.
Sensitive credentials are never stored in plain text.
Authentication & Multi-Factor Authentication (MFA)
User authentication is performed using Microsoft or Google authentication services.
This provides:
- Secure sign-in
- Centralised identity management
- Password policy enforcement
- Support for Multi-Factor Authentication where enabled by the organisation
- Conditional Access policies managed by Microsoft Entra ID
The application does not manage user passwords directly.
Access Control
Access is controlled using role-based permissions.
Officer
- Create incidents
- Edit incidents
- View authorised records
Manager
- Delete incidents
- Create Senior Reviews
- View complete audit history
- Manage user accounts
- Promote users
- Remove user access
All permissions are managed server-side.
Audit Logging
Every significant action is recorded, including:
- User authentication
- Incident creation
- Incident edits
- User account changes
- Permission changes
- Senior Reviews
- Administrative actions
Audit logs record:
- Verified user identity
- Date and time
- Action performed
- Record affected
Audit information cannot be altered by end users.
Cyber Security
The application has been developed in accordance with recognised secure development principles.
Security measures include:
- Server-side validation
- Input validation
- Authentication controls
- Role-based authorisation
- Secure session management
- Secure API access
- Audit logging
- HTTPS encryption
Security updates will be applied promptly following the identification of vulnerabilities.
Security Patching
Ross & Sons Digital will:
- Monitor security vulnerabilities.
- Apply security patches promptly.
- Update application dependencies regularly.
- Review third-party libraries for known vulnerabilities.
- Maintain software versions supported by vendors.
Critical security patches will be prioritised.
Penetration Testing
Prior to production deployment, independent penetration testing should be completed.
Testing should include:
- Authentication testing
- Authorisation testing
- API security
- OWASP Top 10 assessment
- Session management
- Injection testing
- Cross-site scripting testing
- Business logic testing
Any identified vulnerabilities should be remediated before deployment.
Business Continuity
The application has been designed to minimise service disruption.
Business continuity measures include:
- Secure cloud hosting
- Database backups
- Disaster recovery procedures
- Controlled software deployment
- Monitoring of system availability
- Secure user authentication
Document your Recovery Time Objective (RTO) and Recovery Point Objective (RPO) if these have been defined.
Data Protection
The application has been developed in accordance with UK ICO and GDPR principles, including:
- Lawfulness
- Fairness
- Transparency
- Data minimisation
- Accuracy
- Storage limitation
- Integrity
- Confidentiality
- Accountability
Only information necessary for incident management is processed.
Lawful Basis (UK ICO and GDPR)
Personal Data
Article 6(1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Special Category Data
Where special category data is processed:
Article 9(2)(h) – Management of health or social care systems.
or
Article 9(2)(g) – Substantial public interest.
The Trust's Information Governance Team should confirm the appropriate lawful basis.
Risk Assessment
Risk Mitigation Unauthorised access with Microsoft or Google authentication, RBAC, server-side session management Weak passwords Password policies and MFA managed through Microsoft Data interception HTTPS/TLS encryption Data loss Regular backups and disaster recovery procedures Privilege misuse Role-based permissions and audit logging User error Training, user guides, and least-privilege access Software vulnerabilities Regular patching and vulnerability monitoring Session hijacking Secure server-side session management Insider threats Comprehensive audit trails and user accountability Unauthorised changes Server-authoritative audit logging and restricted permissions.