Connect Frontline

Terms of Service


 

Group 15795

 

Version 1.0 · Effective from 27/08/2026

Cocentric Group Limited, registered in England and Wales with company number 09087499, registered office 86-90 Paul Street, London, EC2A 4NE.

These Terms govern use of the Connect Frontline platform. They apply to a customer when that customer signs an Order Form referencing them. The version in force at the date of last signature on an Order Form governs that Order Form for its duration, regardless of any later version published here.

Every version of these Terms is archived. A dated PDF of any version is available on request from support@cocentric.com.

 

Part A: Terms of Service

1. Definitions

  • “Agreement” means these Terms together with any Order Form referencing them.
  • “Authorised User” means an employee, contractor or agent of the Client authorised to access and use Connect in accordance with the Agreement and the Order Form.
  • “Client Data” means any electronic data or information submitted, stored or transmitted by the Client or Authorised Users through Connect.
  • “Confidential Information” means all non-public information disclosed by one party to the other in connection with the Agreement, whether oral, written or digital, and whether or not marked confidential.
  • “Connect” means the Connect Frontline platform and related services.
  • “Data Processing Terms” means Part B of these Terms.
  • “Documentation” means user guides, release notes and other materials describing the features and operation of Connect.
  • “Effective Date” means the date stated in the Order Form, or where none is stated, the date of last signature on that Order Form.
  • “Go-Live” means the date on which Cocentric confirms in writing to the Client that the Modules and integrations marked in scope in the Order Form are available for use by Authorised Users in the Client’s production environment.
  • “Licensed User” means an Authorised User with an active identity provisioned in Connect, measured on the last business day of each month.
  • “Order Form” means a written order executed by both parties that references these Terms and sets out the commercial details, including fees, users, term and scope.
  • “Pilot” means a time-limited, no-fee evaluation deployment described as a pilot, proof of concept or trial in an Order Form.
  • “Pilot Period” means the period stated in the applicable Order Form during which a Pilot runs.
  • “Processing Schedule” means the processing schedule set out in an Order Form.
  • “Subprocessor” means a third party engaged by Cocentric to process Client Data in connection with the provision of Connect.
  • “Term” means the initial and renewal subscription periods specified in the applicable Order Form.

 

2. Provision of services

2.1 Cocentric will provide Connect to the Client for the Term, in accordance with these Terms and limited to the Modules and integrations marked in scope in the applicable Order Form. Modules not marked in scope are not licensed, and any use of them requires a further Order Form. Cocentric may make a Module available for evaluation without charge, in which case clause 2.2 applies to that Module.

2.2 Pilots. Where an Order Form describes a Pilot, the following apply and prevail over any conflicting provision of these Terms: (i) no licence fees are payable for the Pilot Period; (ii) the Order Form expires automatically at the end of the Pilot Period with no notice, fee or termination payment due from either party; (iii) no minimum term, auto-renewal or notice period applies; (iv) either party may terminate the Pilot at any time on fourteen days’ written notice without cause and without charge; (v) the parties will hold a pilot review meeting not later than ten working days before the end of the Pilot Period to assess performance against the success criteria in the Order Form; (vi) any continuation beyond the Pilot Period requires a separate Order Form signed by both parties; and (vii) on expiry or termination Cocentric will delete all Client Data in accordance with clause 12 and confirm deletion in writing.

  • 2.2.1 Where an Order Form states an implementation fee for a Pilot, that fee is payable notwithstanding clause 2.2(i), and is credited against licence fees as stated in that Order Form.

2.3 Scope and change control. Only the services, modules and integrations listed in an Order Form are in scope. Anything else, including custom development, data migration and data cleansing, is out of scope. Changes must be documented in a written change request, priced at the rates in clause 2.3.1 or as varied by the Order Form, and signed by both parties before work begins. No change takes effect on a verbal instruction. Change requests are charged in minimum increments of half a day. Pre-approved expenses are charged at cost against receipts.

  • 2.3.1 Published change control rates. Unless the Order Form states otherwise, out-of-scope work is charged at £1,500 per person-day of eight hours, excluding VAT, with a 50% uplift for work carried out outside the coverage window in clause 8.6 or at weekends. An Order Form may vary these rates.

2.4 Deemed Go-Live. Where Go-Live is delayed by more than twenty working days beyond the date stated in the Order Form and the delay is attributable to the Client, including a failure to meet a dependency in clause 3.1, Go-Live is deemed to have occurred on the twenty-first working day after the date stated in the Order Form.

 

3. Client obligations

Connect is provided for the Client’s internal business purposes only. The Client will ensure that only Authorised Users access the service and is responsible for all use by those users. The Client shall:

  • provide accurate and lawful Client Data;
  • comply with all applicable laws, including data protection, export control and anti-bribery laws;
  • not introduce unlawful or harmful data;
  • assign Authorised Support Contacts, who shall be named in the applicable Order Form;
  • remain responsible for the acts and omissions of all Authorised Users; and
  • ensure login credentials are issued only to Authorised Users, are not shared between users, and are kept secure.

The Client is responsible for any unauthorised access to or use of Connect resulting from its failure to safeguard credentials, save to the extent the unauthorised access results from Cocentric’s negligent act or omission or its breach of the Agreement.

3.1 Dependencies. The Client will:

  • provide accurate and complete user data, including identifiers and attributes, in the agreed format and to the agreed timetable;
  • nominate project contacts and administrators and ensure their availability for workshops, testing and sign-off, including a weekly progress call during build and twice weekly during UAT and hypercare;
  • ensure its third-party vendors, including any HRIS, identity provider and endpoint platforms, provide the access, APIs and support required;
  • provide Cocentric with access to the systems, environments and test accounts needed to configure and test the integrations in scope;
  • configure its own environments to support those integrations, including network, authentication and device management settings;
  • notify Cocentric of any system limitation, change or upgrade that may affect Connect; and
  • give or refuse milestone sign-off, with written reasons where refused, within five working days of request.

3.2 Effect of unmet dependencies. Where the Client does not meet a dependency in clause 3.1, Cocentric is not in breach of any milestone or service level to the extent the failure is attributable to that, and affected dates move day for day. Cocentric will notify the Client promptly where it considers a dependency unmet.

  • Dates stated in an Order Form, including the milestone dates in its Schedule 1, are subject to this clause.

3.3 Third-party approvals. Apple App Store and Google Play review timescales are outside the control of both parties. Go-live dates move day for day where a submission is delayed in review, and this is not a breach by either party.

3.4 Chat and Calling. Where Chat and Calling is in scope, the Client will inform Authorised Users that Connect cannot be used to call emergency services or any public telephone network number, and that Authorised Users must retain an alternative means of making emergency calls. Where the Client enables content filtering or moderation, the Client is responsible for determining its lawful basis for that monitoring, for carrying out any required data protection impact assessment, for informing Authorised Users of the monitoring, and for any consultation required with employee representatives.

3.5 Compliance. Each party will comply with all applicable anti-bribery and anti-corruption laws, including the Bribery Act 2010, and with all applicable modern slavery laws, including the Modern Slavery Act 2015, and will maintain policies and procedures appropriate to its size and business to ensure compliance.

 

4. Fees and payment

4.1 Fees are set out in the applicable Order Form. Unless the Order Form states otherwise, fees are invoiced annually in advance. No licence fees are payable during a Pilot Period. The first licence invoice is issued on the Effective Date unless the Order Form states otherwise, and subsequent licence invoices are issued on each anniversary of the Effective Date. Where an implementation fee is stated, it is invoiced as set out in the Order Form.

4.2 Annual adjustment. Unless the Order Form states otherwise, licence fees increase by five percent on each anniversary of the Effective Date, beginning with the first anniversary. Cocentric will give at least sixty days’ written notice of the adjusted fees. No adjustment applies during a Pilot Period.

4.3 Overage. Where the number of Licensed Users exceeds the volume stated in the applicable Order Form by more than ten percent at any monthly measurement, all Licensed Users above the stated volume are billed at the per-user rate stated as a cash figure in that Order Form, pro rata for the remainder of the then-current annual period. Where no rate is stated, no overage is payable. Overage is billed in arrears and Cocentric will notify the Client within ten working days of the licensed volume being exceeded.

4.4 Taxes. Fees exclude taxes, levies, duties and similar governmental assessments, for which the Client is responsible. Where the Client is established outside the United Kingdom, fees are stated without UK VAT and any applicable reverse charge is the Client’s responsibility.

4.5 Payment. Unless the Order Form states otherwise, invoices are payable within thirty days of invoice date. Late payments accrue interest at eight percent above the Bank of England base rate from the due date until payment, accruing daily.

4.6 Suspension and termination for non-payment. Cocentric may suspend the service on thirty days’ written notice if undisputed invoices remain unpaid or in cases of material misuse, and may suspend immediately in cases of security threat, unlawful use or urgent risk to the service or other customers. Where Cocentric suspends immediately it will notify the Client as soon as reasonably practicable, limit the suspension to the affected part of the service so far as practicable, and restore the service promptly once the cause is resolved. If undisputed fees remain unpaid for more than sixty days after the due date, Cocentric may terminate the Agreement and the applicable Order Form with immediate effect on written notice. The notice and cure periods in this clause apply unless the Order Form states otherwise.

 

5. Service usage

Cocentric will provide Connect in accordance with these Terms, the Documentation and the applicable Order Form. The Client shall not:

  • reverse engineer or disassemble Connect, save to the extent such acts cannot be prohibited under section 50B or 50BA of the Copyright, Designs and Patents Act 1988;
  • use Connect to build a competing service;
  • sublicense, resell or transfer the service;
  • remove proprietary notices; or
  • interfere with the service’s operation.

 

6. Intellectual property

All intellectual property rights in Connect remain with Cocentric and its licensors. The Client retains ownership of Client Data.

The Client grants Cocentric a non-exclusive, royalty-free licence to use Client intellectual property and Client Data solely to the extent necessary to provide the services as detailed in the applicable Order Form. The licence terminates automatically on expiry or termination of that Order Form.

Cocentric grants the Client a limited, non-transferable, non-exclusive licence for Authorised Users to access and use Connect during the Term.

Cocentric may use aggregated and anonymised usage statistics derived from the Client’s use of Connect to improve and administer the service, provided such data does not identify the Client or any individual, is not capable of re-identification, contains no Client Data content, and is not disclosed to any third party in a form attributable to the Client.

 

7. Data protection

The Client is the data controller and Cocentric is the data processor. The Data Processing Terms in Part B apply, together with the Processing Schedule in the applicable Order Form. Where Part A conflicts with Part B, Part B prevails in respect of the processing of personal data. Part B also prevails over an Order Form in respect of the processing of personal data, other than as to the particulars set out in that Order Form’s Processing Schedule.

 

8. Support and service levels

Cocentric will provide support at the tier stated in the applicable Order Form, including access to a help centre, ticketing system and troubleshooting. Target service availability is 99.9%, measured monthly in accordance with clause 8.8. Support response times apply only where tickets have been raised at https://support.cocentric.com/ by an Authorised Support Contact named in the applicable Order Form, with sufficient information to enable Cocentric to investigate and reproduce the issue. A Client may name up to five Authorised Support Contacts. Changes take effect on written notice from the Client project lead to Cocentric’s project lead.

8.1 Planned maintenance. Cocentric will give at least five working days’ notice of planned maintenance and will schedule it outside 08:00-20:00 UK time where reasonably practicable. Emergency maintenance may be carried out at any time with notice as soon as reasonably practicable. Planned maintenance will not exceed eight hours in any calendar month, save with the Client’s prior written agreement.

8.2 Service credits. No service credits apply unless an Order Form expressly provides for them. Where an Order Form provides for service credits, they are the Client’s sole financial remedy for failure to meet the availability target. Where it does not, the Client’s remedies for failure to meet the availability target are the escalation process in clause 16 and the termination right in this clause. Failure to meet the availability target in three consecutive months is a material breach entitling the Client to terminate under clause 12. No service credits apply during a Pilot Period.

8.3 Response times. The following are targets for first reply and for the frequency of subsequent updates. They are not resolution times, and they run only during the applicable coverage window in clause 8.6.

Severity

First reply

Periodic updates

Urgent

2 hours

3 hours

High

8 hours

6 hours

Minor

24 hours

24 hours

Low

48 hours

48 hours

 

8.4 Severity definitions.

Severity

Definition

Example

Urgent

Connect is unavailable to all or substantially all Authorised Users, or a security or data incident is suspected. No workaround available.

Authentication failing for the whole user group.

High

A core function is unavailable or materially degraded for multiple users. Workaround unavailable or impractical.

HRIS sync failing, so new joiners are not provisioned.

Minor

A function is impaired for a small number of users, or a defect exists with a practical workaround.

One endpoint tile not launching for a single user.

Low

Cosmetic issues, questions, documentation gaps, or non-urgent change requests.

Branding or label correction.

 

8.5 Hypercare. Following Go-Live Cocentric will provide a hypercare period of ten working days for the resolution of initial issues, during which Cocentric will prioritise the Client’s tickets ahead of its general queue, unless the Order Form states otherwise. No separate response targets apply during hypercare.

8.6 Support coverage. Support is provided during United Kingdom business hours, being 09:00 to 17:30 UK time, Monday to Friday, excluding English public holidays. The targets in clause 8.3 run only during that window, and a ticket raised outside it is treated as raised at the start of the next window. Cocentric does not provide out-of-hours or weekend support except where an Order Form expressly states otherwise.

8.7 Support tiers. The tier licensed to a Client is the tier stated in that Client’s Order Form.

Tier

What is included

Essential

Help centre, ticketing system and troubleshooting. All severities. Response targets in clause 8.3. Coverage as clause 8.6. Hypercare of ten working days following Go-Live.

Priority

Everything in Essential, plus a named customer success contact, a quarterly service review, priority placement in the support queue ahead of Essential tickets of the same severity, and hypercare extended to twenty working days.

 

8.8 Availability. Connect is Available where an Authorised User can authenticate to the Admin Console and the Access Hub. Availability is measured monthly as a percentage of total minutes in the calendar month, excluding: planned and emergency maintenance under clause 8.1; unavailability of the Client’s own systems, network, identity provider or connected endpoint platforms; unavailability caused by a third-party platform, app store or telecommunications carrier outside Cocentric’s control; the Client’s breach or misconfiguration; and force majeure. Chat and Calling availability is measured separately and excludes carrier and third-party media routing failures.

 

9. Warranties

Cocentric warrants that: (i) Connect will materially conform to its Documentation; (ii) the functionality of the in-scope Modules will not be materially reduced during a subscription term, save where Cocentric exercises its right to discontinue the service under clause 12(iv); and (iii) services will be provided with reasonable skill and care.

9.1 Warranty remedy. If Cocentric breaches a warranty above it will use reasonable endeavours to correct the non-conformity at no charge. If it has not done so within thirty days of written notice, the Client may terminate the affected Order Form and receive a pro-rata refund of fees paid in advance for the unexpired term.

Except as expressly stated, the service is provided “as is” without additional warranties. Cocentric does not warrant the performance, accuracy or reliability of any third-party intellectual property, including open source software, incorporated into or used with Connect, save that where an Order Form expressly lists a third-party integration within scope, Cocentric warrants that it will configure and maintain that integration with reasonable skill and care and will use reasonable endeavours to resolve faults in it.

 

10. Indemnities

10.1 Cocentric indemnity. Cocentric shall indemnify the Client against any claim that Connect, when used in accordance with the Agreement, infringes third-party intellectual property rights, provided the Client promptly notifies Cocentric, grants Cocentric control of the defence and settlement, and provides reasonable cooperation. Cocentric shall not settle any claim in a way that requires the Client to admit liability, make a payment or accept an injunction without the Client’s prior written consent, not to be unreasonably withheld. If Connect becomes, or in Cocentric’s reasonable opinion is likely to become, the subject of an infringement claim, Cocentric will at its own cost either procure the right for the Client to continue using Connect, or modify or replace it so that it is non-infringing and materially equivalent in function, or, if neither is achievable on commercially reasonable terms, terminate the affected Order Form and refund fees paid in advance for the unexpired term.

10.2 Client indemnity. The Client shall indemnify Cocentric against any claim, loss, liability, cost or expense arising from: (i) Client Data; (ii) misuse of the services by the Client or its Authorised Users; (iii) the Client’s breach of the Agreement; (iv) the Client’s infringement of Cocentric’s intellectual property rights; or (v) any claim alleging infringement of third-party intellectual property rights caused by the Client’s misuse of Connect. The Client’s liability under this clause is subject to the same notification, control and cooperation conditions as apply to Cocentric under clause 10.1, and is not subject to the caps in clause 11.

 

11. Liability

Neither party limits or excludes its liability for death or personal injury caused by negligence, for fraud, or for any other liability that cannot lawfully be limited or excluded.

11.1 General cap. Subject to the paragraph above and to clause 11.4, and other than for the matters in clause 11.2, each party’s total aggregate liability under the Agreement, including under the indemnity in clause 10.1, shall not exceed 100% of the fees paid or payable by the Client in the twelve months preceding the event giving rise to the claim. Neither party is liable for indirect, special or consequential losses, or for loss of profits, revenue or anticipated savings.

11.2 Data protection and confidentiality cap. Liability for breach of clause 7, breach of clause 13, or breach of the Data Processing Terms, including any fine or claim arising from a personal data breach, shall not exceed in aggregate the sum stated in the applicable Order Form or, where no sum is stated, two hundred and fifty thousand pounds (£250,000).

11.3 Overall ceiling. Each party’s total aggregate liability under the Agreement, across all heads of claim and however arising, shall not exceed the sum in clause 11.2.

11.4 Exclusions from the caps. Nothing in this clause limits the Client’s obligation to pay fees properly due, or the Client’s liability under clause 10.2.

 

12. Term and termination

The Agreement commences on the Effective Date and remains in force until there are no current Order Forms between the parties. The Term for each Order Form is as set out in that Order Form.

Either party may terminate the Agreement or any Order Form: (i) on thirty days’ written notice if the other materially breaches and fails to remedy within that period; (ii) immediately if the other becomes insolvent, enters administration, or is subject to bankruptcy or similar proceedings; (iii) immediately if a regulator or applicable law prevents provision of the services; (iv) by Cocentric, on not less than ninety days’ written notice, or twelve months’ written notice where the Order Form is within its Initial Term, in respect of Connect only, where Cocentric elects to discontinue the service; or (v) by the Client, on not less than ninety days’ written notice, where Cocentric gives notice of a licence fee increase exceeding the annual adjustment stated in the applicable Order Form, appoints a Subprocessor to which the Client has objected under Part B and the objection is not resolved, or gives notice of a change to these Terms that the Client does not accept. Application of the annual adjustment under clause 4.2 at the rate stated in the Order Form does not give rise to a right of termination. There is no right to terminate for convenience during an Initial Term.

Where Cocentric terminates under (iv), it will refund fees paid in advance for the unexpired term on a pro-rata basis.

12.1 Renewal volume. On renewal the Client may state the number of Licensed Users required for the renewal period in its renewal notice, and the licence fee for that period is calculated on that number at the then-current per-user rate. Licensed User volumes may not be reduced during an Initial Term or a renewal period once it has commenced.

On expiry or termination of an Order Form, the Client may request data export within thirty days. Cocentric will provide data in CSV or JSON, with a data dictionary describing the fields, unless otherwise agreed, and will then delete Client Data, including from backups within its normal backup cycle, except as required by law, confirming deletion in writing on request.

 

13. Confidentiality

13.1 Obligations. Each party will treat as confidential all Confidential Information received from the other. The receiving party shall not disclose it to any third party except to employees, contractors or professional advisers who need to know it for the purposes of the Agreement and are bound by confidentiality obligations no less restrictive than these.

13.2 Exclusions. Confidential Information does not include information the receiving party can demonstrate: (i) was already in its lawful possession before disclosure; (ii) is or becomes publicly available without breach of the Agreement; (iii) is lawfully disclosed by a third party without restriction; or (iv) is independently developed without use of the other party’s Confidential Information.

13.3 Compelled disclosure. A party may disclose Confidential Information if required by law, regulation or court order, provided that, where legally permissible, it gives prompt written notice and cooperates with reasonable efforts to challenge or limit the disclosure.

13.4 Survival. These obligations survive termination for three years, save that obligations in respect of personal data and trade secrets survive indefinitely.

 

14. Publicity

Neither party may use the other’s name or logo, or refer to the existence or subject matter of the Agreement, in marketing materials, case studies, press releases or on its website without the other’s prior written consent, not to be unreasonably withheld or delayed. Consent given for one use is not consent for any other use, and may be withdrawn on thirty days’ written notice.

 

15. Insurance

Cocentric maintains, for the duration of the Agreement and for two years afterwards, insurance with limits of indemnity of not less than: professional indemnity £5,000,000 in the aggregate including all costs; public and products liability £5,000,000 each and every claim; employers’ liability £10,000,000 in the aggregate; and cyber and data £1,000,000 in the aggregate. Cover is limited to the United Kingdom and the European Union; claims brought in the USA or Canada are not covered. Cocentric will provide certificates on reasonable written request, and will notify the Client without undue delay if any policy lapses or is cancelled or if any limit is reduced. The Client shall not do, or fail to do, anything which would reasonably be expected to invalidate or prejudice the benefit of such insurance.

 

16. Dispute resolution

In the event of a dispute the parties will first attempt resolution at operational level, then escalate to senior executives. If unresolved, the parties will attempt mediation before commencing court proceedings. Nothing in this clause prevents either party from seeking interim or injunctive relief, from bringing proceedings to protect its intellectual property or Confidential Information, or from recovering undisputed sums due.

 

17. General

These Terms and any Order Form together constitute the entire agreement between the parties and supersede all prior agreements. Each party acknowledges that in entering the Agreement it has not relied on any statement, representation, assurance or warranty that is not set out in the Agreement. Nothing in this clause limits or excludes liability for fraud or fraudulent misrepresentation. In the event of any conflict or inconsistency between these Terms and an Order Form, the Order Form takes precedence, save that Part B prevails over the Order Form in respect of the processing of personal data, other than as to the particulars set out in the Processing Schedule.

Neither party may assign the Agreement without written consent, except in the case of merger or acquisition, and save that neither party may assign to a direct competitor of the other without prior written consent.

Neither party is liable for delays caused by force majeure events beyond reasonable control. If a force majeure event continues for more than thirty days, either party may terminate the affected Order Form on written notice.

If any provision is held invalid, unlawful or unenforceable, the remaining provisions remain in full force and effect.

No third party has any rights under the Agreement pursuant to the Contracts (Rights of Third Parties) Act 1999.

Execution of Order Forms. An Order Form may be signed in counterparts and by electronic signature, each of which is an original. An Order Form takes effect only when signed by both parties and is not binding on Cocentric until countersigned.

Changes to these Terms. These Terms are version-controlled. The version in force at the date of signature of an Order Form governs that Order Form for its duration. Cocentric may publish updated versions, but no change takes effect in relation to an existing Order Form unless (a) Cocentric gives the Client at least thirty days’ written notice and the Client does not object, or (b) the parties sign a written variation. Where the Client gives notice of termination under clause 12(v) in response to a change, the version of these Terms in force before that change continues to govern the affected Order Form until termination takes effect.

Notices. Notices must be in writing and sent by email to the contacts named in the applicable Order Form, copied in the case of Cocentric to support@cocentric.com and in the case of the Client to the generic address stated in the Order Form. A notice is deemed received at 09:00 on the next business day after sending, provided no delivery failure notification is received. Notices of termination must also be sent by post to the recipient’s registered office.

 

18. Governing law and jurisdiction

The Agreement is governed by the laws of England and Wales. The courts of England and Wales have non-exclusive jurisdiction.

 

 

Part B: Data Processing Terms

These terms record the terms required by Article 28(3) UK GDPR. “UK GDPR”, “personal data”, “processing”, “data subject”, “personal data breach”, “controller” and “processor” have the meanings given in the UK GDPR and the Data Protection Act 2018.

B1. Roles and scope

B1.1 The Client is the controller and Cocentric is the processor in respect of the personal data described in the standing particulars at clause B1.4 and any variations recorded in the Processing Schedule in an Order Form.

B1.2 Each party will comply with its obligations under applicable data protection law. The Client warrants that it has a lawful basis for the processing it instructs and has provided the necessary information to data subjects.

B1.3 These terms apply for as long as Cocentric processes personal data on behalf of the Client, and survive termination of the Order Form until all personal data has been returned or deleted under clause B9.

B1.4 Standing particulars. The following particulars are the complete record required by Article 28(3) UK GDPR and apply to all processing under these terms. The Processing Schedule in an Order Form records only variations agreed for that Order Form, and where it records none these particulars apply in full.

Particular

Detail

Subject matter

Provision of the Modules and integrations marked in scope in the applicable Order Form.

Duration

From the Effective Date until expiry or termination of the applicable Order Form, plus the export and deletion periods in clause B9.

Nature

Collection, storage, structuring, retrieval, use, transmission to connected endpoint systems, and erasure. Processing is automated, by synchronisation from the Client’s HRIS to Connect and onward to connected endpoints. Where Chat and Calling is in scope, processing also includes the transmission, storage and, where the Client configures it, the filtering and moderation of content created by Authorised Users.

Purpose

To create, maintain and deprovision digital identities for the Client’s workforce so that those individuals can authenticate to and access the Client’s connected workplace systems and, where Chat and Calling is in scope, communicate with each other.

Data location

Primary storage in the United Kingdom or European Economic Area. Certain Subprocessors listed in Part D process personal data outside the UK and EEA, in each case under the transfer mechanism stated in Part D. See clause B11.

Categories of personal data

Identity and contact data; employment and role data; and system and authentication data generated by Connect. Where Chat and Calling is in scope, content created by Authorised Users, including messages, images, video, voice notes and call metadata. The agreed field mapping is recorded in the configuration document under clause B2.2.

Special category and high-risk data

The Client will not configure the HRIS field mapping to include special category data, criminal offence data, financial account details, payment card data, or government identity document numbers, and will exclude any such field before Go-Live. Cocentric does not require such data. Where Chat and Calling is in scope, content created by Authorised Users may incidentally contain special category data; the Client remains the controller of that content and its inclusion is not an instruction to Cocentric to process special category data.

Categories of data subject

Employees and contractors of the Client enrolled as Authorised Users.

Frequency of transfer

Configurable. Default twice daily for scheduled synchronisation from the Client’s HRIS. Changes and additions made directly in Connect take effect in real time.

Retention

Deprovisioned user records deleted within twelve months of the leaver date, or within a shorter period configured by the Client, minimum thirty days. Authentication and access logs retained for ninety days. Where Chat and Calling is in scope, content created by Authorised Users is retained for twenty-four months from creation by default, configurable by the Client between three and thirty-six months, and is then deleted.

 

B2. Processing on documented instructions

B2.1 Cocentric will process personal data only on the Client’s documented instructions, including as to international transfers, unless required to do otherwise by law. Where required by law to process otherwise, Cocentric will inform the Client before processing unless the law prohibits it.

B2.2 Each Order Form, these terms, the Processing Schedule in that Order Form, and the configuration document produced during the discovery workshops and signed off by both parties, together constitute the Client’s complete documented instructions. The configuration document records the agreed field mapping between the Client’s HRIS and Connect, and may be updated by written agreement between the parties without varying the Order Form. Further instructions must be given in writing to Cocentric’s project contact named in the Order Form.

B2.3 Cocentric will inform the Client if, in its opinion, an instruction infringes applicable data protection law, and is not obliged to carry out such an instruction.

B2.4 Cocentric will not sell personal data, and will not use personal data to train, develop or improve any machine learning or artificial intelligence model, or for any purpose other than providing the services.

 

B3. Confidentiality of personnel

B3.1 Cocentric will ensure every person authorised to process the personal data is subject to a binding duty of confidentiality, has received data protection training appropriate to their role, and is granted access only to the extent necessary to perform their duties.

B3.2 Access is restricted to named personnel on a least-privilege basis. The list of roles with access is maintained by Cocentric and available to the Client on request. Where Chat and Calling is in scope, Cocentric personnel do not access content created by Authorised Users in the ordinary course. Access to such content is by break-glass procedure only, is logged, and is notified to the Client without undue delay.

 

B4. Security

B4.1 Cocentric will implement and maintain the technical and organisational measures in Part C, which are appropriate to the risk in accordance with Article 32 UK GDPR.

B4.2 Cocentric may update Part C provided the level of protection is not reduced.

 

B5. Subprocessors

B5.1 The Client gives general written authorisation to Cocentric to engage the Subprocessors listed in Part D.

B5.2 Cocentric will give the Client at least thirty days’ written notice before appointing any new or replacement Subprocessor. The Client may object on reasonable data protection grounds within that period. Where the Client objects within the notice period, Cocentric will not permit the proposed Subprocessor to process the Client’s personal data until the objection is resolved or the Order Form terminates under this clause. If the objection cannot be resolved within thirty days, the Client may terminate the Order Form without penalty and receive a pro-rata refund of any fees paid in advance.

B5.3 Cocentric will impose on each Subprocessor data protection obligations no less protective than these terms, and remains fully liable to the Client for the acts and omissions of its Subprocessors.

 

B6. Data subject rights

B6.1 Taking into account the nature of the processing, Cocentric will assist the Client by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights under Chapter III UK GDPR.

B6.2 Cocentric will notify the Client without undue delay, and in any event within three working days, if it receives a request from a data subject relating to personal data processed under these terms. Cocentric will not respond to the request itself except to acknowledge receipt and direct the data subject to the Client, unless the Client instructs otherwise in writing.

 

B7. Assistance with compliance

B7.1 Cocentric will provide reasonable assistance with data protection impact assessments and any prior consultation with the supervisory authority, taking into account the nature of the processing and the information available to Cocentric.

B7.2 Assistance under clauses B6 and B7 is provided at no additional charge during any Pilot Period. Otherwise Cocentric may charge at the day rate in clause 2.3.1, or as varied by the applicable Order Form, for assistance that is materially disproportionate to the routine operation of the services.

 

B8. Personal data breach

B8.1 Cocentric will notify the Client without undue delay, and in any event within seventy-two hours, of becoming aware of a personal data breach affecting personal data processed under these terms. Cocentric is aware of a personal data breach when its information security lead or incident response lead has confirmed that a personal data breach has occurred. A report or suspicion that has not been confirmed does not start that period.

B8.2 The notification will describe, to the extent known: the nature of the breach including the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and the name and contact details of Cocentric’s point of contact. Where the information cannot be provided at once it will be provided in phases without further undue delay.

B8.3 Cocentric will not notify any regulator or data subject about a breach affecting the Client’s personal data without the Client’s prior written consent, unless required by law.

B8.4 Cocentric will cooperate with the Client and take the steps the Client reasonably requests to assist in the investigation, mitigation and remediation of the breach.

 

B9. Return and deletion

B9.1 On expiry or termination of an Order Form, the Client may request export of the personal data within thirty days, in a standard machine-readable format, being CSV or JSON.

B9.2 After that period Cocentric will delete all personal data, including from backups within its normal backup cycle and in any event within ninety days, and will confirm deletion in writing. This does not apply to the extent Cocentric is required by law to retain a copy, in which case it will inform the Client of the requirement and continue to protect the data.

 

B10. Audit and information

B10.1 Cocentric will make available all information necessary to demonstrate compliance with Article 28 UK GDPR.

B10.2 On not less than thirty days’ written notice and no more than once in any twelve-month period, Cocentric will provide its current ISO/IEC 27001 certificate and statement of applicability, its most recent penetration test summary, its Cyber Essentials certificate, and a completed security questionnaire, and will respond to reasonable follow-up questions.

B10.3 Cocentric will allow for and contribute to audits, including inspections, by the Client or an auditor mandated by the Client. In the first instance the audit obligation is satisfied by the material provided under clause B10.2. Where that material is not sufficient to demonstrate compliance, or where a regulator requires it, or following a personal data breach affecting the Client’s personal data, the Client may carry out an on-site inspection.

B10.4 On-site inspections are subject to the following. The auditor must not be a competitor of Cocentric and must be bound by confidentiality obligations directly to Cocentric. The Client will give at least thirty days’ written notice, except following a personal data breach, where ten working days’ notice applies. Inspections take place during business hours and no more than once in any twelve-month period, except following a personal data breach or where a regulator requires otherwise. Scope is limited to the systems, premises and records used to process the Client’s personal data. The auditor may not access the personal data or Confidential Information of other Cocentric customers, may not connect any device to Cocentric’s network, and may not copy or remove data. Cocentric’s hosting infrastructure is operated by a subprocessor and is not available for on-site inspection; the certifications provided under clause B10.2 stand in respect of that infrastructure. The Client bears its own costs and Cocentric’s reasonable costs of supporting an inspection, charged at the day rate in clause 2.3.1, or as varied by the applicable Order Form, save where the inspection identifies a material breach by Cocentric of these Data Processing Terms, in which case Cocentric bears its own costs.

 

B11. International transfers

B11.1 Cocentric will process and store personal data in the United Kingdom or the European Economic Area, except where a Subprocessor listed in Part D operates outside the UK and EEA. Part D states the processing location and the transfer mechanism relied on for each such Subprocessor.

B11.2 Cocentric will not transfer personal data outside the UK or EEA other than as disclosed in Part D without first giving the Client thirty days’ written notice, and will in every case rely on a valid transfer mechanism, being an adequacy decision, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum. Clause B5.2 applies to any such change. Where a transfer mechanism relied on in Part D ceases to be valid, Cocentric will rely on the EU Standard Contractual Clauses together with the UK Addendum, or another valid mechanism, without the need to vary these Terms, and will notify the Client of the change.

B11.3 Where support is provided from outside the UK or EEA, or where a Subprocessor operates from outside the UK or EEA, this is disclosed in Part D.

 

B12. Liability

B12.1 Liability arising under or in connection with these terms is subject to clause 11, including the cap in clause 11.2 and the ceiling in clause 11.3.

 

B13. Clients established in the EEA

B13.1 Where the Client is established in the European Economic Area, or the processing is otherwise subject to Regulation (EU) 2016/679, these terms apply with the following modifications: references to the UK GDPR are to Regulation (EU) 2016/679; references to the Data Protection Act 2018 are to the applicable national implementing law; references to the Information Commissioner’s Office and to the supervisory authority are to the competent supervisory authority for the Client; and the transfer mechanism in clause B11.2 is the EU Standard Contractual Clauses. Where the processing is subject to both regimes, both apply.

 

Part C: Technical and organisational measures

Reviewed annually. Last reviewed 27/08/2026.

Area

Measure

Certification

ISO/IEC 27001:2022 certified. Cyber Essentials certified.

Hosting

Microsoft Azure datacentres, North Europe and UK South, holding ISO 27001 and SOC 2 certification.

Encryption

Personal data encrypted in transit using TLS 1.2 or higher and at rest using AES-256.

Access control

Role-based access on a least-privilege basis. Multi-factor authentication enforced for all users with administrator or remote access, including cloud-based email. Access reviewed quarterly and revoked on departure.

Content access

Where Chat and Calling is in scope, content created by Authorised Users is not accessed by Cocentric personnel in the ordinary course. Access is by break-glass procedure only, is logged, and is notified to the Client.

Network and endpoint security

WAF-protected ingress via App Gateway, private VNet segmentation with NSGs, private endpoints for data services.

Vulnerability management

Vulnerabilities are remediated by severity, measured from the date Cocentric becomes aware: CVSS 9.0 and above within 14 days; CVSS 7.0 to 8.9 within 30 days; CVSS 4.0 to 6.9 within 90 days.

Logging and monitoring

Authentication and administrative actions logged. Logs retained for 90 days. Alerts monitored each business day.

Business continuity

Documented disaster recovery plan tested annually. Recovery time objective 8 hours. Recovery point objective 4 hours. Backups taken daily, retained 35 days, encrypted at rest, and restore-tested quarterly.

Personnel

Confidentiality obligations in contracts of employment. Data protection training on induction, and annually thereafter. Pre-employment screening including identity and right-to-work checks.

Testing

Penetration testing carried out annually by an independent provider, with a summary available under clause B10.2.

Segregation

Client data logically segregated from that of other Cocentric clients. Partitioned at database level.

 

Part D: Approved subprocessors

Changes to this list require thirty days’ notice under clause B5.2.

Subprocessor

Service provided

Processing location

Microsoft Ireland Operations Limited

Cloud hosting and infrastructure (Azure)

UK and Ireland (Azure UK South and North Europe regions)

Twilio Ireland Limited

SMS delivery for one-time passcodes and notifications

US (EU-US Data Privacy Framework including UK Extension; SCCs and UK Addendum as fallback under clause B11.2)

Twilio Ireland Limited (Twilio SendGrid)

Transactional email delivery. Service and account notifications.

US (EU-US Data Privacy Framework including UK Extension; SCCs and UK Addendum as fallback under clause B11.2)

Zendesk, Inc.

Customer support ticketing and helpdesk

EU (Germany)

Amazon Web Services EMEA SARL

Cloud hosting and infrastructure (AWS) for Connect Frontline mobile application

Primarily UK (AWS eu-west-2); limited processing in other AWS regions including US and Canada (SCCs / UK Addendum)

Stream.io, Inc. (GetStream)

In-app voice calling

EU (Ireland) or US, per application region (SCCs / UK Addendum). 

 

Part E: Module catalogue

Descriptions only. The Modules licensed to a Client are those marked in scope in that Client’s Order Form. Cocentric may add Modules to this catalogue; adding a Module does not license it to any existing Client.

Module

Description

Admin Console

Identity and access core: user provisioning and deprovisioning, authentication, and access management. Required for all other Modules.

Access Hub (mobile and web app)

The Connect Frontline application for iOS, Android and web, giving Authorised Users single-tap access to the connected endpoint systems in scope.

Chat and Calling

A chargeable additional Module. Secure messaging and app-to-app voice calling between Authorised Users on iOS, Android and web. Groups derive from the Client’s HRIS and update automatically for joiners, movers and leavers. Personal telephone numbers are not used or displayed. Administrators may set word filters and moderate content. Content is encrypted in transit. No public telephone network, external numbers, emergency calls or call recording. Web excludes calling. Clause 3.4 applies.