# IT MANAGED SERVICES AGREEMENT
Date: 21 October 2029
Parties: Northstar Managed IT Limited and Fenwick Architects Limited
## 1. Parties and purpose
Northstar Managed IT Limited (Company No. 08776655), 5 Innovation Drive, Cambridge CB4 0WS, will provide Fenwick Architects Limited (Company No. 06622119), 30 Station Road, Cambridge CB1 2JH, with managed Microsoft 365, endpoint monitoring, patching, helpdesk and backup services for up to 65 users and 80 devices.
## 2. Scope, price and subject
The monthly fee is £4,200 plus VAT, including the listed services, and additional projects require a written change order. Priority 1 means a material outage or suspected ransomware and is acknowledged within 30 minutes 24/7; Priority 2 within four business hours; Priority 3 within one business day. Targets are service levels, not a warranty that an incident cannot happen.
## 3. Operating duties
Northstar will maintain an escalation rota, patch supported systems, test monthly backups and give a quarterly service report. Fenwick will nominate administrators, apply reasonable user security instructions, keep licences paid, approve maintenance windows and promptly report suspected compromise. Northstar may suspend a compromised account to protect the environment, notifying Fenwick as soon as safe.
## 4. Compliance, records and controls
Fenwick is controller and Northstar processor for documented support processing of user and client data. The parties will sign and follow a UK GDPR Article 28 data-processing schedule, use appropriate technical and organisational measures, restrict sub-processors, assist with rights requests and notify a personal-data breach without undue delay. Data must remain in approved UK or adequate locations unless an approved transfer safeguard applies.
## 5. Term, ending and remedies
Fenwick owns its data, configurations and bespoke documentation; Northstar owns tools, scripts and pre-existing IP and grants a licence necessary for use during and after the term where paid. Northstar must not use Fenwick confidential data for advertising, model training or unrelated analytics. Fenwick authorises remote administration only through named accounts with multi-factor authentication.
## 6. Liability and reservations
The initial term is 24 months from 1 November 2029, then monthly rolling with 90 days' notice. A party may terminate for an uncured material breach, insolvency or a serious security failure; Fenwick may terminate on 30 days' notice after a repeated Priority 1 service-level failure. Exit includes an encrypted data export and 20 hours' reasonable transition support, with deletion certified after retention ends.
## 7. Governing law and signatures
Neither party excludes liability for fraud, death or personal injury caused by negligence, deliberate data misuse or IP infringement. Other aggregate liability is capped at 12 months' fees, with a separate £500,000 cap for a data-protection breach caused by Northstar. England and Wales law governs; the directors sign on 21 October 2029.