top of page

Terms and Conditions of Service

These Terms & Conditions govern the use of the Endpoint Works website and the services provided by Endpoint Works.

By requesting, booking, purchasing or using our services, you agree to these Terms & Conditions. If you do not agree, please do not use our services.

1. About Endpoint Works

Endpoint Works provides business technology and asset-management services, including:

​

  • IT equipment collection and transportation

  • Secure data destruction and media sanitisation

  • IT asset disposal

  • IT equipment recycling

  • Equipment refurbishment and remarketing

  • Office clearance

  • Office moves and IT relocation

  • Asset collection and logistics

  • Equipment resale

  • Secure handling of IT assets

  • Other related technology and business services

​

The specific services provided will be detailed in the customer's quotation, order confirmation or service agreement.

2. Customer Responsibilities

Customers must provide accurate and complete information regarding the equipment and services required.

​

  • This may include:

  • Number and type of devices

  • Make and model

  • Serial numbers or asset numbers where available

  • Equipment condition

  • Collection and delivery locations

  • Access requirements

  • Collection dates and times

  • Security requirements

  • Data destruction requirements

  • Any special handling requirements

​

Customers must have the legal authority to provide equipment to Endpoint Works and to instruct Endpoint Works to perform the agreed services.

 

Customers are responsible for ensuring that any data they require for business, legal, regulatory, financial or operational purposes has been appropriately backed up or retained before equipment is submitted for destruction or sanitisation.

3. Data Protection and UK GDPR

Endpoint Works recognises the importance of protecting personal data, confidential information and commercially sensitive information contained on IT equipment.

Endpoint Works will process personal data in accordance with applicable UK data protection legislation, including the UK GDPR and Data Protection Act 2018, as applicable to the services being provided.

​

Endpoint Works will apply the relevant data protection principles, including:

​

  • Lawfulness, fairness and transparency

  • Purpose limitation

  • Data minimisation

  • Accuracy

  • Storage limitation

  • Integrity and confidentiality

  • Accountability

​

These principles form the basis of the UK data protection regime.

4. Controller and Processor Responsibilities

The role of Endpoint Works in relation to personal data will depend on the particular service and processing activity.

​

Where the customer determines the purposes and means of processing personal data and Endpoint Works processes that data solely on the customer's instructions, Endpoint Works may act as a data processor.

​

Where Endpoint Works determines its own purposes and means for processing personal data, Endpoint Works may act as a data controller.

​

The parties will determine their respective roles based on the actual processing activities rather than simply the terminology used in the contract.

​

Where Endpoint Works acts as a processor, the parties will enter into a Data Processing Agreement (DPA) where required.

​

The DPA may address:

​

  • Processing instructions

  • Confidentiality

  • Security measures

  • Sub-processors

  • Personal data breaches

  • Data subject rights

  • Data retention

  • Data deletion or return

  • Assistance with regulatory obligations

  • Auditing and compliance

  • International data transfers where applicable

​

The ICO states that processor contracts should contain appropriate contractual requirements and that processors must implement appropriate technical and organisational measures to protect personal data.

5. Lawful Basis for Processing

Where Endpoint Works acts as a data controller, it will identify an appropriate lawful basis for each relevant processing activity.

​

Depending on the circumstances, this may include:

​

  • Performance of a contract

  • Legal obligation

  • Legitimate interests

  • Consent

  • Other lawful bases available under applicable data protection legislation

​

Endpoint Works will not rely on consent where another lawful basis is more appropriate.

​

Where legitimate interests are relied upon, Endpoint Works will identify and document the relevant legitimate interest and consider the impact on individuals as required.

​

The ICO requires organisations to determine their lawful basis before processing personal data and to explain the applicable lawful basis within their privacy information.

6. Privacy Notice

These Terms & Conditions should be read together with the Endpoint Works Privacy Notice.

​

The Privacy Notice explains how Endpoint Works collects, uses, stores and protects personal information.

​

The Privacy Notice will provide information including, where applicable:

​

  • What personal information Endpoint Works collects

  • How the information is obtained

  • Why the information is processed

  • The lawful basis for processing

  • Who information may be shared with

  • How long information is retained

  • Individual data protection rights

  • How individuals can contact Endpoint Works

  • How individuals can raise a complaint

  • Details of international transfers where applicable

  • Information about automated decision-making or profiling where applicable

​

The ICO's current guidance requires privacy information to explain matters such as purposes, lawful bases, recipients, retention and individual rights.

7. ICO Registration

Endpoint Works will comply with applicable ICO registration and data protection fee requirements.

​

Where Endpoint Works is required to register with the Information Commissioner's Office and pay the applicable data protection fee, Endpoint Works will maintain the appropriate registration.

​

Endpoint Works will not state or imply that ICO registration constitutes a certification of its security or data-destruction services.

8. Information Security

Endpoint Works will implement appropriate technical and organisational measures appropriate to the risks associated with the personal data and services being provided.

​

Depending on the service, these measures may include:

​

  • Access controls

  • Staff confidentiality requirements

  • Secure handling procedures

  • Asset identification and tracking

  • Controlled access to equipment

  • Secure transportation

  • Chain-of-custody records

  • Secure storage where applicable

  • Data sanitisation

  • Physical destruction

  • Secure disposal

  • Incident management procedures

​

Security measures will be proportionate to the nature of the equipment, information and risks involved.

9. Secure Data Destruction and Media Sanitisation

Where Endpoint Works is instructed to destroy or sanitise data, an appropriate method will be selected based on factors including:

​

  • Storage media type

  • Device condition

  • Data sensitivity

  • Customer requirements

  • Intended equipment disposition

  • Whether the equipment is being reused, resold, recycled or destroyed

  • Technical limitations of the storage technology

​

Endpoint Works may use recognised industry guidance including NIST Special Publication 800-88 Revision 2 — Guidelines for Media Sanitization, where applicable.

​

NIST SP 800-88 Rev. 2 provides guidance for establishing media sanitisation programmes and selecting appropriate sanitisation methods based on information sensitivity and media characteristics.

10. Clear, Purge and Destroy

Where applicable, Endpoint Works may use sanitisation approaches corresponding to the NIST SP 800-88 framework, including:

​

Clear

​

Logical sanitisation methods intended to protect against straightforward recovery attempts using appropriate interfaces and normal user-access methods.

​

Purge

​

Sanitisation methods intended to make recovery of the data infeasible using a level of effort appropriate to the applicable requirements.

​

Destroy

​

Physical destruction of the storage media where reuse is not appropriate or where the customer requires permanent destruction.

​

The appropriate method will depend on the technology and circumstances.

​

NIST SP 800-88 is recognised technical guidance and is not itself a certification of Endpoint Works.

11. Validation and Verification

Where applicable to the agreed service, Endpoint Works may maintain records or perform appropriate verification to confirm that the agreed sanitisation or destruction process has been completed.

​

The level of verification will depend on the service purchased and the applicable equipment and sanitisation method.

​

Where a customer requires a particular verification standard, this must be agreed before the service is undertaken.

12. Data Destruction Certificates

Where included within the agreed service, Endpoint Works may provide a Certificate of Data Destruction or equivalent documentation.

​

Records may include:

​

  • Customer name

  • Collection date

  • Processing date

  • Asset number

  • Serial number where available

  • Manufacturer

  • Model

  • Storage media type

  • Sanitisation or destruction method

  • Processing result

  • Certificate reference

  • Date of completion

​

Certificates will only confirm the services actually performed.

14. Personal Data Breaches and Security Incidents

Endpoint Works will maintain procedures for identifying, assessing and responding to suspected personal data breaches and security incidents.

​

Where Endpoint Works acts as a processor and becomes aware of a personal data breach affecting information processed on behalf of a customer, Endpoint Works will notify the relevant customer without undue delay and provide reasonable assistance in accordance with the applicable agreement and law.

​

Where Endpoint Works is acting as a controller, Endpoint Works will assess any suspected personal data breach and determine whether notification to the ICO or affected individuals is required.

​

Where a breach is notifiable, the ICO states that the controller must generally notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

​

The 72-hour regulatory requirement should not be confused with Endpoint Works' customer notification obligations. A customer contract or DPA may require Endpoint Works to notify the customer considerably sooner.

15. Data Retention and Secure Disposal

Endpoint Works will retain personal information and operational records only for as long as reasonably necessary for the relevant purpose, unless a longer retention period is required or permitted by law.

​

Where information is no longer required, it will be securely deleted, anonymised or otherwise disposed of as appropriate.

​

Specific retention periods may vary depending on:

​

  • Legal requirements

  • Accounting requirements

  • Contractual requirements

  • Regulatory requirements

  • Dispute resolution

  • Insurance requirements

  • Asset and destruction records

  • Legitimate business requirements

  • ​

The Endpoint Works Privacy Notice will provide further information regarding applicable retention periods or the criteria used to determine them.

16. Customer Authorisation for Data Destruction

The customer is responsible for confirming that Endpoint Works has authority to destroy or sanitise the data stored on equipment supplied.

​

Once a data destruction or physical destruction process has been completed, the process may be irreversible.

​

Customers must ensure that all information they need has been retained before authorising destruction.

​

Endpoint Works will not be responsible for information destroyed in accordance with the customer's instructions.

17. Physical Destruction

Where physical destruction is selected or required, storage media may be physically destroyed so that the original storage medium cannot reasonably be reused.

​

Physical destruction may be appropriate where:

​

  • The storage device is damaged.

  • The device cannot be reliably sanitised.

  • The customer specifically requires physical destruction.

  • The information requires a higher level of protection.

  • The device is being permanently disposed of.

​

Once physical destruction has taken place, the equipment or storage media cannot normally be returned in its original functional form.

18. Third-Party Processors and Disposal Partners

Where Endpoint Works uses third-party service providers, processors, transport providers, recycling partners or disposal facilities, Endpoint Works will take reasonable steps to ensure that appropriate contractual and security arrangements are in place where required.

​

Where Endpoint Works acts as a processor, any sub-processor arrangements will be managed in accordance with the applicable customer agreement and data protection requirements.

​

Where required, sub-processors will be subject to appropriate contractual protections.

19. Collection and Transportation

Customers must ensure that equipment is available and reasonably accessible at the agreed collection time.

Additional charges may apply where delays or additional requirements occur, including:

​

  • Waiting time

  • Restricted access

  • Incorrect collection information

  • Additional equipment

  • Additional locations

  • Failed collection attempts

  • Parking or access charges

  • Additional labour requirements

​

Any additional charges will be communicated where reasonably possible.

21. Equipment Resale and Asset Value

Where Endpoint Works purchases, resells or remarkets equipment, the value may depend on:

​

  • Make and model

  • Age

  • Specification

  • Condition

  • Functionality

  • Market demand

  • Quantity

  • Accessories

  • Battery condition

  • Data-security requirements

​

Any valuation provided before inspection is indicative unless expressly confirmed as a final agreed value.

22. Equipment Condition

Endpoint Works may inspect equipment before confirming its final resale value.

Equipment may be classified as suitable for:

​

  • Resale

  • Refurbishment

  • Parts recovery

  • Recycling

  • Responsible disposal

​

Equipment that is damaged, incomplete, faulty or materially different from the information provided may be subject to a revised valuation.

24. Damage and Loss

Endpoint Works will take reasonable care when handling customer equipment.

However, we will not be responsible for damage or loss resulting from:

​

  • Pre-existing damage

  • Incorrect information supplied by the customer

  • Hidden defects

  • Equipment that was already faulty

  • Inadequate packaging where packaging is the customer's responsibility

  • Circumstances outside our reasonable control

​

Nothing in these Terms excludes or limits liability that cannot legally be excluded or limited.

25. Payment

Payment terms will be stated on the relevant quotation or invoice.

​

Unless otherwise agreed, invoices must be paid within the payment period stated on the invoice.

​

Endpoint Works reserves the right to suspend further services where invoices remain unpaid.

26. Cancellation

Customers must provide at least 72 hours' notice before the scheduled collection time if they wish to cancel or rearrange a collection, office move or other booked service.

 

Where less than 72 hours' notice is provided, Endpoint Works reserves the right to apply a cancellation or rearrangement charge where staff, vehicles, equipment or other resources have already been allocated to the booking.

​

Any applicable charge will be communicated to the customer.

27. Recycling and Responsible Disposal

Where equipment is unsuitable for resale or refurbishment, Endpoint Works may arrange appropriate recycling or disposal.

​

Endpoint Works may use appropriate third-party recycling or disposal partners where required.

​

Customers must notify Endpoint Works before collection if they require specific equipment to be returned or retained.

28. Confidentiality

Endpoint Works will take reasonable steps to protect confidential business information encountered while providing services.

​

Customers should identify any specific confidentiality, security or regulatory requirements before work begins.

29. Intellectual Property

All intellectual property relating to the Endpoint Works brand, website, software, designs, logos and original content belongs to Endpoint Works or its relevant licensors unless otherwise stated.

​

Nothing in these Terms grants ownership of Endpoint Works' intellectual property.

30. Events Outside Our Control

Endpoint Works will not be liable for delays or failure to perform services where caused by circumstances outside our reasonable control.

​

This may include severe weather, road closures, industrial action, vehicle breakdowns, government restrictions, emergencies, security incidents or other unforeseen circumstances.

bottom of page