Legal
The terms on which we provide our services.
These terms apply when you buy services from us. Your use of this website is covered separately by our Terms of Use.
Who you are contracting with. Tea Powered Projects Limited, company number 10542712, registered in England and Wales, registered office C/O XNM Accountancy Limited, Creative Suite 1, Mill 3, Pleasley Vale Business Park, Mansfield, NG19 8RL. VAT number GB 469621165. Contact us at hello@teapowered.pro or +44 (0) 115 647 1900. "We", "us" and "our" mean that company. "You" means the business buying the services.
These terms apply to every service we provide, unless we have signed something else with you that says otherwise.
They apply in full where there is no signed Statement of Work - for example a platform subscription taken on its own, standalone hosting, support tickets, or hourly work.
Where there is a signed Statement of Work, these terms fill the gaps in it rather than replacing it.
Five documents can apply at once. If they disagree, this is the order:
2.1 The signed Scope and Authorisation wins outright, for security testing work, on what may be tested, how, and when. Nothing in any other document authorises testing.
2.2 The signed Statement of Work wins on scope, deliverables, timescales and price.
2.3 The CMS Service Terms win on platform ownership, subscription term and what happens when the service ends.
2.4 These Terms and Conditions apply to anything the others do not cover.
2.5 The Data Processing Agreement wins outright on any question about personal data, over all four of the above.
A contract starts when the earliest of these happens:
3.1 You accept a quotation or Statement of Work in writing (email is enough).
3.2 You place an order for a plan, add-on or service.
3.3 You start using a service we have set up for you.
3.4 You pay an invoice for the service.
We provide the services described in your quotation, Statement of Work, or the plan you subscribed to. Our current plans, add-ons and rates are in our price list.
We may improve or change the platform. We will not remove a feature you actively use without reasonable notice and either a replacement or a way to move off it.
5.1 VAT. All prices exclude VAT, which we add at the prevailing UK rate.
5.2 Invoices are due on receipt unless we have agreed otherwise in writing.
5.3 How to pay. Direct debit, card via Stripe, or BACS. Annual plans may be paid by BACS.
5.4 Subscriptions are billed monthly in advance unless you have agreed annual billing.
5.5 Late payment. We may charge interest and reasonable recovery costs under the Late Payment of Commercial Debts (Interest) Act 1998.
5.6 Price changes. We may change our prices on 30 days' written notice. If a change increases what you pay, you may end the affected service on notice before it takes effect, without an early termination sum.
5.7 Discounts given for a minimum term are conditional on completing that term. See clause 6.4.
5.8 Third-party licences on a fixed term. Some licences we supply, such as Microsoft 365, are bought from the vendor for a fixed term, usually 12 months, even when billed monthly. These renew automatically for another term unless you tell us before the renewal date. Once a term has renewed, the licences are payable for the whole of it, and clause 6.2 does not apply to them. We will remind you at least 14 days before each renewal.
6.1 Ongoing services run for the initial term stated in your quotation, Statement of Work or plan. For platform subscriptions that is 12 months unless stated otherwise.
6.2 After the initial term the service continues monthly until either of us ends it on 30 days' written notice.
6.3 One-off work ends when the work is delivered and paid for.
6.4 Ending early. If you end an ongoing service before the initial term completes, the balance of that term becomes payable, calculated at the standard undiscounted rate, less amounts already paid. Prepayments are not refundable. This is a single charge - we do not also claim the discount back separately. The CMS Service Terms work this through with examples.
6.5 We may end an ongoing service on 90 days' written notice. If we do, clause 6.4 does not apply, and we refund anything you have prepaid for the period after you leave.
6.6 Either of us may end the agreement immediately if the other commits a material breach that is not put right within 30 days of being told about it in writing, or becomes insolvent.
6.7 What happens to your data when a platform service ends is set out in the CMS Service Terms. There is no charge for getting your content and data back.
If an invoice is more than 30 days overdue we may suspend access to the administration interface, after giving you 7 days' written warning.
We will not take a live website offline before an invoice is 60 days overdue, and we will never withhold your data or your offboarding export because of an unpaid invoice.
We may also suspend a service immediately where continuing would break the law, or where the service is being used in breach of clause 9.
8.1 Give us the information, content, access and approvals we need, when we need them.
8.2 Nominate one person who can approve work and respond within 3 working days. If delay on your side affects timescales, we may extend deadlines accordingly.
8.3 Make sure you have the rights to any content, images or materials you give us.
8.4 Keep your login credentials secure, and tell us promptly if an account is compromised.
8.5 Meet your own obligations as data controller, including your privacy notice and cookie notice.
8.6 Make sure everything you publish through our platform is lawful and accurate.
While your subscription is active we grant you a non-exclusive, non-transferable right to use the platform to run your own website. You may not:
9.1 Resell, sublicense or share access with anyone outside your organisation.
9.2 Use the platform to operate a website for a third party.
9.3 Copy, decompile, reverse engineer or attempt to extract the source of the platform.
9.4 Publish unlawful, defamatory, obscene or infringing content.
9.5 Probe, scan or test the security of the platform, or attempt to access another customer's data. This does not stop you commissioning a test of your own site from us, or from someone else, where we have agreed the scope in writing first under clause 19.
9.6 Use the platform to send unsolicited marketing in breach of PECR or UK GDPR.
9.7 Deliberately overload the platform or interfere with its operation.
Breaching this clause is a material breach and may lead to immediate suspension under clause 7.
10.1 Your materials. You keep ownership of your brand, content, photography and anything else you supply to us.
10.2 Work built for you. On payment in full, we assign to you the intellectual property in any website, copy, design and content created specifically for you.
10.3 Our platform. We keep ownership of the TPP content management platform, our shared code packages, our standard page blocks, and our design system. These are licensed to you for the term, not sold.
10.4 Detail. For platform work, the full ownership and offboarding position is in the CMS Service Terms.
Each of us will keep the other's non-public information confidential and use it only to perform the agreement. This obligation continues for 3 years after the agreement ends.
It does not apply to information that is public through no fault of the receiving party, was already known, or must be disclosed by law.
Where we process personal data on your behalf, you are the controller and we are the processor. That relationship is governed by our Data Processing Agreement, which takes precedence over these terms on any data protection question.
13.1 We warrant that we will provide the services with reasonable care and skill, and that we have the right to provide them.
13.2 We do not warrant any specific search engine ranking, traffic level, lead volume, conversion rate or commercial outcome. Search engines are not within either party's control.
13.3 We do not warrant that the platform will be uninterrupted or error free. We maintain it, back it up daily and fix faults as part of the managed service, but we do not commit to an uptime figure unless we have agreed one in writing.
13.4 Third-party services we integrate - payment processing, email delivery, SMS, social platforms, search engines - are outside our control. We are not liable for their failures, though we will help you work around them.
14.1 Cap. Each party's total liability under the agreement will not exceed the fees paid or due in the 12 months before the event giving rise to the claim.
14.2 Excluded losses. Neither of us is liable for indirect or consequential loss, pure economic loss, loss of profits, anticipated savings, business or goodwill, however arising.
14.3 Your data. We do not exclude our liability for losing your data. We back your data up daily and keep offsite copies. If we lose it through our fault, our liability is limited by the cap in clause 14.1 but it is not excluded.
14.4 Carve-outs. Nothing limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be limited by law.
14.5 Your indemnity. You will cover us against claims arising from content you supply or publish through our services, where that content infringes someone's rights or breaks the law.
15.1 We maintain professional indemnity, public liability and employers' liability insurance appropriate to the services we provide, with reputable insurers.
15.2 We will provide evidence of cover on request.
15.3 Holding insurance does not increase the liability cap in clause 14. Cover is there to help us meet a liability, not to create one.
Neither of us is liable for failing to perform because of something outside our reasonable control, including outages at hosting or connectivity providers, cyber attack, power failure, industrial action, or government action. If it lasts more than 30 days, either of us may end the affected service without penalty.
17.1 Tell us first. If something has gone wrong, email hello@teapowered.pro or call us. We would rather hear it early than read it in a solicitor's letter.
17.2 What we will do. We acknowledge a complaint within 5 working days and give you either an answer or a plan with a date within 15 working days.
17.3 Escalation. If you are not satisfied with the answer, ask for it to go to a director, who will review it and respond within a further 10 working days.
17.4 Before court. Both of us will try in good faith to settle a dispute through the steps above before starting proceedings. This does not stop either of us from applying to court for an urgent remedy, or from recovering a debt that is not in dispute.
17.5 Personal data complaints are handled under our Privacy Policy, which also explains your right to complain to the Information Commissioner's Office.
We may update these terms on 30 days' written notice. If a change materially reduces your rights, you may end the affected service on notice without an early termination sum, even during an initial term.
This section applies to penetration testing, security audits, pre-takeover application audits and incident response. It applies only to that work, not to every engagement.
19.1 Authorisation comes first. We do not test, scan, or read the source of any system until a Scope and Authorisation document is signed by both of us. It names the systems, what may and may not be done to them, the testing window, and who to call to stop the work. No signature, no testing.
19.2 That document wins. On any question of what may be tested and how, the Scope and Authorisation overrides these terms and any Statement of Work. See clause 2.
19.3 Your authority. You confirm that you own, or are otherwise entitled to authorise testing of, every system in scope, and that any third party hosting part of it has given its own consent. We rely on that confirmation and are not required to verify it.
19.4 Testing carries inherent risk. Even careful, rate-limited work can disturb a system that is already unstable. You are responsible for having a verified, restorable backup before testing starts. We are not liable for faults exposed rather than caused by testing carried out within the agreed rules, nor for weaknesses that already existed.
19.5 A test is not a certificate. A report says what we found, in the scope and time agreed. We do not warrant that every weakness has been found, or that a system is secure. Anyone telling you otherwise is selling something.
19.6 Findings are confidential, both ways. We treat findings as your confidential information and will not publish them, or name you as a client, without your written consent. You may share the report inside your organisation and with your insurers, auditors and professional advisers.
19.7 Evidence handling. Evidence and scan output are held encrypted on our own systems, restricted to the people working on the engagement, and destroyed 12 months after the report unless you ask for it sooner. We keep the report itself, and the authorisation, as business records.
19.8 No subcontracting without your consent. We will not pass any part of a security engagement to anyone outside TPP without your written agreement. This overrides the general position on subcontractors.
19.9 Fixing is separate work. Remediation and retesting are quoted separately unless your Statement of Work says otherwise.
19.10 If we find you are already compromised, we stop, tell you the same day, and treat incident response as separate work under its own agreement. It is not covered by a testing fee.
19.11 We will decline unlawful work. We will not test a system you are not entitled to authorise, and we will stop immediately if that turns out to be the position, without refund of work already done.
20.1 We use AI tools. We use AI assistance across content, design, development and research. We do not present this work as unassisted, and we do not charge differently for it. What you are buying is the finished, checked deliverable and our responsibility for it.
20.2 A person is responsible for everything we deliver. AI output is a draft. Every deliverable that reaches you has been reviewed and approved by a named person at TPP, who holds editorial responsibility for it. No AI system publishes, sends or commits to anything on our behalf without that approval.
20.3 Our warranty is unchanged. Clause 13.1 applies in full to AI-assisted work. We are as liable for a claim in an AI-assisted deliverable as for one we typed ourselves.
20.4 Your data. We do not put your personal data, customer records, credentials, or confidential material into an AI tool unless that tool is on our approved list, is covered by our Data Processing Agreement, and its provider is contractually barred from training on the data. Our internal standard is set out in our AI Use Policy, available on request.
20.5 Security engagements are excluded. Findings, evidence and scan output from work under clause 19 are not processed by third-party AI tools at all. Clause 19.7 governs how they are held.
20.6 Watermarking. Output from current AI models carries a machine-readable watermark, applied by the model providers under EU AI Act Article 50. It indicates that content may have been processed by a model. It is not a search ranking signal and search engines cannot read it. We mention it so that it is not a surprise to you later.
20.7 If you need work produced without AI assistance, tell us before the engagement starts. We can agree it in the Statement of Work, and it will be priced accordingly. We will not accept a no-AI requirement introduced after delivery.
20.8 Your material. If you supply us with AI-generated content to publish, clause 14.5 applies to it as it does to any other content you supply.
21.1 Assignment. You may not transfer the agreement without our written consent. We may transfer it to a company that acquires our business.
21.2 Subcontracting. We may use subcontractors, and we stay responsible for their work.
21.3 Third parties. Nobody other than you and us has rights under the agreement.
21.4 Entire agreement. The documents in clause 2 are the whole agreement between us and replace anything said or written beforehand. This does not limit liability for fraud.
21.5 Severability. If a clause is unenforceable, the rest continues to apply.
21.6 Waiver. Not enforcing a term once does not mean we give up the right to enforce it later.
21.7 Notices. Written notice may be given by email - to you at your account email address, and to us at hello@teapowered.pro.
21.8 Governing law. These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Last updated: 1 October 2026 - Version 1.2