Terms of Business

Last updated: August 2026

These Terms of Business govern engagements between Erryn.io Ltd (the Consultant) and the client named in the associated proposal, statement of work, or other written engagement agreement (the Client).

These terms are intended for business-to-business engagements only. By entering into an engagement, the Client confirms that it is acting in the course of its business, trade, profession, or commercial activities and not as a consumer.

By accepting a proposal, statement of work, or other engagement in writing, including by email or electronic acceptance, the Client agrees to these terms.

Where a signed or expressly accepted proposal, statement of work, data processing agreement, non-disclosure agreement, performance share agreement, or other written agreement contains a term that conflicts with these terms, the more specific agreement will take precedence to the extent of that conflict.

1. The parties

Consultant: Erryn.io Ltd, a company registered in England and Wales under company number 17407419. Registered office: The Old Granary, Hampton-on-the-Hill, Warwick, United Kingdom, CV35 8HB. Trading as erryn.io. Contact: hello@erryn.io.

Unless expressly stated otherwise, all fees are exclusive of VAT. Erryn.io Ltd is not currently VAT registered and VAT will therefore not be charged unless and until it becomes legally applicable. If VAT becomes chargeable during an engagement, it will be added to invoices from the date required by law.

Client: The business, company, organisation, sole trader, partnership, or other commercial entity named in the relevant proposal or statement of work.

For these terms, a Working Day means Monday to Friday excluding public holidays in England.

2. Engagement types

erryn.io operates under two primary engagement structures. The applicable structure will be confirmed in the proposal or statement of work.

2.1 Project engagements

A project engagement covers a defined scope of work for a fixed or estimated fee. Work begins once the proposal or statement of work has been accepted in writing and any required deposit has been received.

The scope, deliverables, anticipated timeline, assumptions, dependencies, and price will be set out in the relevant proposal or statement of work. Changes to scope are handled under clause 8.

2.2 Retainer engagements

A retainer engagement provides ongoing consultancy or support services on a monthly basis. The scope of services, monthly fee, any included time or service allocation, minimum term, and notice period will be confirmed in writing at the outset.

Retainers are invoiced monthly in advance unless otherwise agreed. After any stated minimum term, a retainer runs on a rolling monthly basis and either party may terminate it on 30 days’ written notice, or the alternative notice period stated in the engagement agreement.

3. Proposals and acceptance

A proposal is valid for 30 days from its issue date unless otherwise stated. Acceptance in writing, including by email or electronic acceptance, constitutes a binding agreement incorporating these terms.

Work will not begin until acceptance has been confirmed and, where applicable, the required deposit has been received.

The Consultant may decline or withdraw a proposal at any time before acceptance without obligation.

4. Fees and payment

4.1 Project fees

Project fees are set out in the relevant proposal or statement of work. Unless otherwise agreed:

  • A deposit of 50% is required before work begins.
  • The deposit is credited against the total project fee and reserves capacity for the engagement.
  • The remaining balance is due on completion or at the milestone specified in the proposal.
  • For larger projects, staged payment arrangements may be agreed and will be set out in the proposal or statement of work.

4.2 Retainer fees

Retainer fees are invoiced monthly in advance unless otherwise agreed. The first invoice is raised on or around the agreed start date and subsequent invoices are normally raised on the corresponding date each month.

4.3 Payment terms

Payment is due within 14 days of the invoice date unless alternative terms have been agreed in writing.

If an undisputed invoice remains overdue, the Consultant may:

  • Pause work where payment is more than 7 days overdue.
  • Charge statutory interest under the Late Payment of Commercial Debts (Interest) Act 1998 where applicable.
  • Claim any fixed compensation and reasonable recovery costs permitted by applicable late-payment legislation.
  • Withhold delivery of final files, transferable credentials, or other final handover materials until outstanding balances have been cleared, provided doing so does not unlawfully interfere with Client property or access.

A pause caused by overdue payment may affect previously estimated delivery dates, and the Consultant will not be responsible for delays arising from that pause.

4.4 Expenses and third-party costs

Third-party costs reasonably required to deliver an engagement, including software licences, hosting services, stock assets, specialist services, or other external costs, will be agreed with the Client before commitment wherever reasonably practicable.

Such costs will be invoiced at cost with no markup unless the proposal or another written agreement states otherwise.

5. Performance share engagements

Where a performance share model is agreed, this clause applies in addition to the general terms. The revenue share percentage, eligible revenue, baseline, exclusions, attribution method, measurement source, reporting process, payment schedule, minimum term, and any other commercial rules will be stated in a separate performance share agreement.

5.1 Eligibility

Performance share engagements are offered at the sole discretion of the Consultant and are not available to all clients. Before an agreement is entered into, the Consultant may withdraw a performance share offer where the commercial opportunity, available data, existing business position, or required level of transparency does not support the arrangement.

5.2 Baseline and measurement

Revenue share will be calculated against the baseline and measurement method specified in the performance share agreement. The Client must provide complete, accurate, and reasonably verifiable revenue information on the agreed schedule.

Intentional concealment or material misrepresentation of revenue or other information used to calculate the performance share constitutes a material breach of contract.

5.3 Payment of revenue share

Unless the performance share agreement states otherwise, payments are calculated monthly against the previous month’s verified eligible revenue. The Client will provide the required revenue report within 7 days after the end of each calendar month and payment will be due within 14 days after the report has been received and verified.

5.4 Verification and audit rights

The Consultant may request reasonable supporting evidence for figures used to calculate performance share payments, including relevant platform exports, payment processor reports, analytics data, or accounting records. This right will be exercised reasonably and only to the extent required to verify amounts payable.

5.5 Duration

The arrangement runs for the term stated in the performance share agreement. Unless a minimum term or different notice period applies, either party may terminate it with 60 days’ written notice.

Any performance share accrued before or during the notice period remains payable after termination, and reasonable verification rights continue to apply to those amounts.

6. Outcome guarantees

On eligible engagements, the Consultant may offer a specific outcome guarantee with an agreed remedy where a defined metric is not achieved.

Any such guarantee applies only where the proposal or another written agreement expressly identifies the guaranteed outcome, measurement method, measurement period, Client dependencies, exclusions, and remedy.

General references to guarantees, target outcomes, typical results, case studies, or performance claims on the erryn.io website or in marketing material do not create a contractual guarantee unless expressly incorporated into the relevant engagement agreement.

7. Compliance and security engagements

This clause applies to engagements involving cyber security, information security, technical security, or compliance advisory work, including Cyber Essentials, Cyber Essentials Plus, ISO 27001, SOC 2, PCI DSS, security remediation, security reviews, and related services.

7.1 Nature of the service

The Consultant may provide readiness assessments, technical review, documentation support, remediation, implementation guidance, and audit preparation within the scope agreed for the engagement.

The Consultant is not an accredited certification body and does not issue certifications unless a particular service expressly states otherwise. Any certification body, auditor, assessor, or other independent third party acts independently, whether engaged directly by the Client or introduced by the Consultant. The Consultant has no control over and accepts no responsibility for that party’s independent findings or decisions.

7.2 No guaranteed certification or security outcome

Unless expressly covered by a written outcome guarantee under clause 6, the Consultant does not warrant that an engagement will result in certification, accreditation, a successful audit, elimination of all vulnerabilities, prevention of every security incident, or any other particular security outcome.

Any readiness opinion or assessment reflects the Client environment, evidence, systems, and information made available to the Consultant at the relevant time.

7.3 Client environment and disclosure

The Client must disclose known material security weaknesses, unsupported or end-of-life systems, unmanaged devices, bring-your-own-device practices, unusual infrastructure, relevant third-party dependencies, and other material matters that could reasonably affect the engagement.

The Consultant will advise on risks identified within the agreed scope but is not responsible for pre-existing vulnerabilities, infrastructure, systems, or practices that are outside that scope or were materially misrepresented or withheld.

Where the Client operates across multiple jurisdictions, the Client is responsible for determining which laws and regulatory regimes apply to its operations. The Consultant may provide technical and compliance guidance within the agreed scope but does not provide legal advice unless expressly stated otherwise.

7.4 Continuing responsibility

Responsibility for the Client’s security posture, governance, risk decisions, and maintenance of controls remains with the Client.

The Consultant’s role is limited to the agreed engagement period and scope unless ongoing monitoring, support, or management has been separately agreed.

7.5 Authority to access and test systems

The Client warrants that it owns, controls, or has obtained sufficient authority over every system, account, application, network, device, dataset, or other resource that it instructs the Consultant to access, configure, scan, assess, test, or modify.

The Client is responsible for obtaining any necessary permission from hosting providers, software providers, infrastructure owners, employers, customers, or other third parties before authorising work on systems that it does not exclusively own or control.

The Consultant will operate within the technical and operational boundaries agreed for the engagement. Penetration testing, exploitation, destructive testing, or other intrusive security testing will not be undertaken unless expressly included within a written scope or rules of engagement.

8. Scope changes

Requests to materially change the agreed scope should be made in writing. The Consultant will assess any likely impact on cost, timing, resources, risk, and deliverables before additional work is undertaken.

A change may be approved through a revised proposal, change request, statement of work, or clear written agreement by email.

The Consultant is not required to perform work outside the agreed scope. Where the Client expressly instructs the Consultant in writing to proceed with additional work before a formal change document is issued, that work may be charged at the Consultant’s then-current day or hourly rate, provided that rate or charging basis has been notified to the Client.

If material issues are discovered that could not reasonably have been anticipated when the engagement was scoped, the Consultant will raise them promptly and provide a recommendation before undertaking material additional work.

9. Client responsibilities

The quality and timing of an engagement depend on reasonable Client cooperation. The Client agrees to:

  • Provide accurate and complete information, evidence, content, and materials reasonably required for the engagement.
  • Respond to questions, reviews, and approval requests within agreed timescales or, where none are agreed, within 5 Working Days where reasonably practicable.
  • Provide access to systems, platforms, accounts, personnel, and documentation reasonably required to perform the work.
  • Ensure that materials supplied to the Consultant may lawfully be used and do not infringe third-party intellectual property rights.
  • Maintain appropriate licences and permissions for systems and third-party services used in the engagement.
  • Maintain reasonable backups of important systems and data unless backup responsibility is expressly included within the Consultant’s scope.
  • Notify the Consultant promptly of material changes to the Client’s systems or circumstances that could affect the work.

The Consultant is not responsible for resulting timeline overruns where delays are caused by the Client’s failure to meet these responsibilities.

If Client inaction prevents meaningful progress for more than 30 days, the Consultant may invoice work completed and committed costs to date, pause the engagement, and agree a revised delivery schedule before work resumes.

10. Intellectual property

10.1 Bespoke deliverables

Subject to clauses 10.2 and 10.3, once all amounts due for the relevant engagement have been paid in full, the Client will own the intellectual property rights in final bespoke deliverables created specifically and exclusively for the Client and identified as deliverables under the engagement.

Until full payment has been received, ownership of those deliverables remains with the Consultant and any use by the Client is provisional and limited to review and approval unless otherwise agreed.

Where a separate written assignment or other document is reasonably required to give legal effect to the transfer of a copyright or other right intended to pass to the Client under this clause, the Consultant will execute that document following receipt of full payment.

10.2 Consultant materials, reusable technology and know-how

The Consultant retains ownership of all methodologies, concepts, know-how, frameworks, templates, processes, utilities, software tools, code libraries, modules, routines, reusable components, development techniques, systems, and other background intellectual property used in or arising from the performance of the engagement that are not uniquely created for the Client.

This includes improvements, extensions, generic functionality, technical knowledge, reusable code, methods, or tools developed during an engagement where they are capable of use independently of the Client’s confidential information or uniquely commissioned deliverables.

Where Consultant materials are incorporated into a Client deliverable, the Client receives a perpetual, worldwide, royalty-free licence to use, maintain, modify, and operate those materials as part of that deliverable for its own business purposes. The Client may not extract and independently resell, sublicense, or commercially distribute the Consultant materials unless expressly agreed in writing.

10.3 Third-party materials

Third-party assets, software, fonts, plugins, libraries, APIs, platforms, open-source components, or other third-party materials remain subject to their respective licence terms.

The Client is responsible for maintaining any licences required for continued use after handover. The Consultant will identify material known dependencies at handover where reasonably practicable.

11. Data protection

11.1 Compliance

Each party will comply with applicable data protection law, including the UK GDPR and Data Protection Act 2018, in relation to personal data processed in connection with an engagement.

Each party acts as an independent controller in relation to ordinary business contact, account administration, invoicing, and contractual information that it processes for its own purposes.

11.2 Processing on behalf of the Client

Where the Consultant processes personal data on behalf of the Client in providing the services, the Client acts as controller and the Consultant acts as processor unless the circumstances require another legal classification.

The subject matter, nature, purpose, and duration of processing are the activities reasonably required to provide the services described in the relevant engagement. Personal data and categories of data subjects will be limited to those reasonably necessary to perform that work.

In that capacity, the Consultant will:

  • Process personal data only on the Client’s documented instructions unless required otherwise by law.
  • Ensure that persons authorised to process the data are subject to appropriate confidentiality obligations.
  • Apply appropriate technical and organisational measures proportionate to the processing and risk.
  • Provide reasonable assistance with data subject rights, security obligations, breach response, and data protection impact assessments where relevant to the processing performed by the Consultant.
  • Notify the Client without undue delay after becoming aware of a personal data breach affecting personal data processed on the Client’s behalf.
  • On termination of the relevant services, return or delete Client personal data as reasonably requested, except where retention is required by law or is contained within ordinary secure backups pending scheduled deletion.
  • Provide information reasonably necessary to demonstrate compliance with these obligations and cooperate with reasonable audits where legally required.
  • Inform the Client if, in the Consultant’s reasonable opinion, an instruction would breach applicable data protection law.

11.3 Sub-processors and international transfers

The Client gives general authorisation for the Consultant to use reputable third-party service providers and sub-processors where reasonably necessary to deliver the services, provided that appropriate contractual and data protection safeguards are applied.

The Consultant will not knowingly make a restricted international transfer of Client personal data unless an appropriate lawful transfer mechanism or other permitted basis is in place.

Where the parties enter into a separate data processing agreement for an engagement, that agreement takes precedence over this clause in relation to the processing it covers.

12. Confidentiality

Each party will keep confidential non-public information disclosed by the other party in connection with an engagement and will use it only for purposes reasonably connected with the engagement.

This obligation continues for three years after termination, except that obligations relating to personal data, authentication credentials, security-sensitive information, and genuine trade secrets continue for as long as the information remains protected by law or retains its confidential character.

These obligations do not apply to information that is already lawfully public, was lawfully known to the receiving party without confidentiality restriction, is independently developed without use of the confidential information, or must be disclosed by law or a competent authority.

Unless the Client requests otherwise in writing, the Consultant may state that the Client is or has been a client and may describe the general, non-confidential nature of the services provided. Client logos, confidential results, security findings, sensitive performance information, or identifying details of security incidents will not be published without appropriate permission.

The Consultant will not publicly identify a Client’s security weaknesses or confidential security findings without the Client’s written consent unless disclosure is required by law.

13. Liability

13.1 General limitation

Subject to clause 13.4, for engagements other than those falling within clause 7, the Consultant’s total aggregate liability arising out of or in connection with a project engagement, whether in contract, tort including negligence, misrepresentation, or otherwise, is limited to the total fees paid or payable for that engagement.

For a rolling retainer, the Consultant’s total aggregate liability is limited to the fees paid or payable under that retainer during the 12 months immediately preceding the event giving rise to the claim.

13.2 Compliance and security engagements

Subject to clause 13.4, for engagements falling within clause 7, the Consultant’s total aggregate liability arising out of or in connection with the relevant engagement, whether in contract, tort including negligence, misrepresentation, or otherwise, is limited to £250,000.

Claims arising from the same act, omission, event, series of related events, or substantially the same underlying cause will be treated as a single claim for the purpose of this aggregate limit.

13.3 Excluded losses and circumstances

Subject to clause 13.4 and to the fullest extent permitted by law, the Consultant is not liable for:

  • Indirect or consequential loss.
  • Loss of profit, revenue, anticipated savings, goodwill, business opportunity, or anticipated business, whether direct or indirect, except where expressly included within a written outcome guarantee.
  • Loss arising from the Client’s failure to meet its responsibilities under clause 9.
  • Loss arising from third-party platforms, providers, outages, algorithm changes, software changes, infrastructure failures, or security incidents outside the Consultant’s reasonable control.
  • Loss resulting from changes made to deliverables, systems, configurations, or recommendations by the Client or another third party after the Consultant’s work without the Consultant’s involvement.
  • Loss arising from pre-existing vulnerabilities, undisclosed systems, inaccurate information, or third-party infrastructure outside the agreed scope.
  • Loss or corruption of data to the extent that it could reasonably have been avoided or restored through backups which the Client was responsible for maintaining under clause 9.

13.4 Liability that cannot be excluded

Nothing in these terms excludes or limits liability for:

  • Death or personal injury caused by negligence.
  • Fraud or fraudulent misrepresentation.
  • Any other liability which cannot lawfully be excluded or limited.

13.5 Insurance and contractual liability

The existence or amount of any insurance maintained by the Consultant does not increase, replace, or waive the contractual limitations of liability set out in this clause.

14. Termination

14.1 Material breach

Either party may terminate an engagement by written notice where the other party is in material breach and, where the breach is capable of remedy, has failed to remedy it within 14 days after written notice requiring it to do so.

14.2 Project cancellation by the Client

The Client may terminate a project engagement for convenience by written notice. In that event, the Client must pay for work properly completed up to the termination date together with any non-recoverable third-party costs or commitments already incurred for the project.

Any deposit already paid will be applied against the amounts due. To the extent that the deposit represents capacity reserved for the project and the Consultant cannot reasonably reallocate that capacity, it is non-refundable, subject always to applicable law.

14.3 Termination by the Consultant

Where the Consultant terminates because of Client breach, the Client remains responsible for work properly completed and non-recoverable commitments incurred up to termination.

If the Consultant terminates a project without Client breach before completing the agreed services, the Consultant will refund any prepaid fees relating to work that will not be performed and provide reasonable handover of completed work for which payment has been made.

14.4 Retainer engagements

Either party may terminate a retainer by giving 30 days’ written notice or the alternative notice period stated in the engagement agreement. Notice does not affect rights or obligations already accrued.

14.5 Immediate termination

The Consultant may terminate or suspend an engagement immediately if the Client or its representatives behave in a seriously abusive, threatening, fraudulent, or unlawful manner, or instruct the Consultant to undertake work that would reasonably require the Consultant to act unlawfully, dishonestly, or materially outside an agreed authorised security scope.

15. Warranties and insurance

The Consultant warrants that:

  • Services will be performed with reasonable skill and care.
  • The Consultant has authority to enter into the engagement and to grant the rights and licences described in these terms.
  • The Consultant maintains professional indemnity insurance of not less than £2,000,000 and will provide reasonable evidence of current cover on request.

Except where expressly stated in a written outcome guarantee, the Consultant does not warrant any particular commercial result, revenue increase, search ranking, conversion rate, certification, security outcome, or other specific metric.

16. Subcontractors and third-party specialists

The Consultant may use suitably qualified subcontractors, specialists, or third-party service providers where reasonably necessary to deliver an engagement. The Consultant remains responsible to the Client for the performance of subcontracted services that form part of the Consultant’s contractual scope, subject to the other provisions of these terms.

Any subcontractor given access to Client confidential information or personal data will be subject to appropriate confidentiality and, where applicable, data protection obligations.

17. Force majeure

Neither party is liable for delay or failure to perform an obligation where that failure results from circumstances beyond its reasonable control, including widespread infrastructure or communications failure, natural disaster, serious civil disruption, government action, war, or comparable events.

The affected party must notify the other as soon as reasonably practicable and take reasonable steps to reduce the effect of the event.

This clause does not excuse payment of sums already due for services performed or costs already incurred.

18. Notices

Any formal notice under these terms must be given in writing and may be sent by email to the principal contact address stated in the engagement or, in the case of the Consultant, to hello@erryn.io.

An email notice will be treated as received on the Working Day on which it is sent, provided it is sent before 5:00pm UK time and no delivery failure notification is received. An email sent after that time or on a non-Working Day will be treated as received on the next Working Day.

19. Governing law and disputes

These terms and every engagement governed by them are subject to the laws of England and Wales.

If a dispute arises, the parties will first attempt in good faith to resolve it through direct discussion. If the dispute remains unresolved 30 days after written notice of the dispute, either party may pursue any remedy available to it through the courts of England and Wales, which will have exclusive jurisdiction.

20. General

20.1 Independent parties

Nothing in these terms creates a partnership, joint venture, employment relationship, fiduciary relationship, or agency between the parties. Neither party may bind the other except where expressly authorised in writing.

20.2 Assignment

Neither party may transfer an engagement to another party without the other’s prior written consent, such consent not to be unreasonably withheld, except that the Consultant may assign the engagement as part of a genuine restructuring, merger, or transfer of substantially all of its business provided this does not materially reduce the Client’s contractual protections.

20.3 Severability

If any provision of these terms is found to be invalid or unenforceable, the remaining provisions will continue in effect. The affected provision will, so far as legally possible, be interpreted or modified only to the minimum extent necessary to make it valid and enforceable.

20.4 Waiver

A failure or delay by either party to exercise a contractual right does not waive that right.

20.5 Third-party rights

Unless expressly stated otherwise, a person who is not a party to an engagement has no right to enforce its terms under the Contracts (Rights of Third Parties) Act 1999.

21. Amendments

The Consultant may update these Terms of Business from time to time. The version in force when a proposal or engagement is accepted will govern that engagement.

Material changes to these terms will not apply retrospectively to an active engagement unless agreed in writing by both parties.

22. Entire agreement

These terms, together with the relevant accepted proposal, statement of work, and any other agreement expressly incorporated into the engagement, constitute the entire agreement between the parties concerning that engagement and supersede prior discussions, proposals, representations, and understandings relating to the same subject matter.

Nothing in this clause excludes liability for fraud or fraudulent misrepresentation.


Contact

Erryn.io Ltd
Trading as erryn.io
The Old Granary
Hampton-on-the-Hill
Warwick
United Kingdom
CV35 8HB

Company number: 17407419
Email: hello@erryn.io