Legal
These terms and the Data Processing Agreement together form the agreement for an Assessment. Both are shown in full when you buy, and the version you accepted is recorded against your order.
TERMS OF SUPPLY
Microsoft 365 Health Assessment (Vitals)
Version 2.0 · Effective 20 August 2026
1. Who these terms are between
1.1 Innova. Innova Technologies Group Ltd, registered in England and Wales under company number 17205930, registered office 7 Stromberg Street, Anlaby, Hull, HU10 7ER, trading as Innova Group, VAT number 519893442 (“Innova”, “we”, “us”).
1.2 Client. The organisation identified when the order is placed (“you”, “your”, the “Client”).
1.3 These Terms of Supply and the Data Processing Agreement (“DPA”) together form the agreement for the Assessment (the “Agreement”). They are accepted online before customer processing begins. We record the version accepted and provide a copy electronically.
1.4 If these Terms conflict with the DPA on a data-protection matter, the DPA prevails to the extent of that conflict.
2. Business customers only
2.1 The Assessment is supplied only for business purposes and is not offered to consumers.
2.2 By accepting the Agreement, you confirm that you are acting wholly or mainly for purposes relating to your trade, business, craft or profession and that you have authority to bind the organisation identified in the order.
2.3 If you are a sole trader, you may purchase only where the Assessment is acquired wholly or mainly for your business. Nothing in these Terms excludes any right that cannot lawfully be excluded.
3. What you are buying
3.1 Vitals is a read-only, point-in-time assessment of the Microsoft 365 tenant identified in the order. It analyses the areas described in clause 4 and produces a written Report.
3.2 Scan — £99 plus VAT. The Report provides scores, findings, affected-item counts and prioritised recommendations. Identifying examples such as individual file paths, user names and guest email addresses are removed before the Scan Report is rendered.
3.3 Worklist — £295 plus VAT. The Worklist includes the Scan output plus specific remediation evidence, which may include file and folder paths, sharing links and account identifiers, together with a remediation review call of up to one hour to be taken within 30 days after release.
3.4 A Scan Report is released through a token-protected report link sent to the purchasing/delivery email address. The link expires no later than 30 days after delivery.
3.5 A completed Worklist is generated but not delivered by email when processing finishes. We withhold it until the scheduled Worklist review has taken place and an authorised Innova administrator expressly releases it to the authorised recipient. Before authorised release, the Worklist is inaccessible through its report token even if that token is known or possessed. On release, the report link is issued and the 30-day retention period begins.
3.6 Report-access links are bearer links and remain usable until they expire no later than 30 days after delivery (Scan) or release (Worklist). You should retain any copy you need before expiry. After the applicable retention period, we cannot promise to reproduce the original Report without running a new Assessment.
4. Scope and limitations of the Assessment
4.1 Read-only. The Microsoft Graph permissions used by Vitals are read-only. Vitals cannot create, alter or delete tenant content or configuration. It does not open, read or copy the contents or bodies of documents, email messages or Teams chats.
4.2 Included areas. The Assessment may examine SharePoint and Teams content metadata; users, guests, groups and administrators; Microsoft subscriptions; Intune-managed devices and compliance state; Conditional Access and tenant identity settings; Microsoft 365 activity over the relevant Microsoft reporting period; tenant sharing defaults; Microsoft Secure Score and controls; third-party application consent; MFA registration/capability; sensitivity labels; site/page hygiene; and Copilot readiness derived from those areas.
4.3 Public DNS. Vitals also checks published SPF, DKIM and DMARC records for domains associated with the Assessment. These are public DNS records. Domain names may be sent to a public DNS resolver operated by Cloudflare or Google for the lookup. No Microsoft 365 tenant permission is used for this step.
4.4 Mailbox rules. Mailbox-rule analysis is included in the standard Assessment. Vitals uses the read-only MailboxSettings.Read permission to assess mailbox settings, including forwarding and inbox rules. It may read rule names, conditions and forwarding addresses, but it does not read the contents or bodies of email messages.
4.5 Sampling — important. The Assessment examines up to 15 site collections, up to 500 items within each sampled site, and detailed sharing permissions on up to 200 items per sampled site. On larger tenants, the Report is therefore a representative sample rather than an exhaustive examination of every item. The Assessment is not a certification, penetration test, statutory audit or guarantee that every issue has been identified.
4.6 Point in time. The Report describes the tenant as it appeared when the Assessment ran. Changes before or after that time are outside the Report.
4.7 Advisory. Findings and recommendations are advisory professional opinions based on the information sampled and the checks performed. They are not legal, regulatory, accounting or compliance advice and do not certify compliance with any law, standard or framework.
4.8 The Report itself will state that the Assessment is a point-in-time sample and not an exhaustive audit.
5. Size limit
5.1 Published Scan and Worklist prices apply to organisations with up to 100 staff and a single Microsoft 365 tenant.
5.2 If the organisation is larger or requires more than one tenant to be assessed, we may pause before processing and offer a separate quotation. If you do not accept it, we will refund the affected order in full.
6. What we need from you
6.1 Before the Assessment can run, the Agreement must be accepted and a Global Administrator of the tenant must approve the requested read-only application permissions through Microsoft Entra.
6.2 The payer and the administrator approving tenant access may be different people. You are responsible for providing accurate recipient and approver details and ensuring that the person granting consent is authorised to do so.
6.3 If access has not been approved 30 days after payment, we may close the order and refund the price paid in full. No tenant Assessment will have been run.
6.4 You must not provide us with instructions, access or data that you are not authorised to provide.
7. Turnaround, price, payment and refunds
7.1 We aim to make the Report available within three working days after the required tenant access has been approved. This is a service target, not a guaranteed deadline.
7.2 Prices are in pounds sterling and exclude VAT, which is added where applicable.
7.3 Payment is taken in advance through Stripe. We do not receive or store full payment-card details.
7.4 We will refund the affected Assessment in full if we cannot complete it because of a technical failure for which we are responsible. If a Report has not been made available within 14 days after the required access was approved, you may request a full refund.
7.5 Except where these Terms expressly provide otherwise or the law requires otherwise, no refund is due after the Report has been delivered or, for Worklist, released.
8. Confidentiality and data protection
8.1 Each party shall keep confidential information received from the other in connection with the Assessment confidential and use it only for the Agreement, except where disclosure is required by law or made to professional advisers or service providers who are bound by appropriate confidentiality obligations.
8.2 We treat tenant information and the Report as confidential. The Worklist should be treated as particularly sensitive because it may identify exact files, links and accounts requiring remediation.
8.3 The DPA governs our processing of Personal Data on your behalf. Assessment Personal Data is subject to the retention and deletion controls in the DPA.
8.4 We may retain and use genuinely anonymous information in accordance with the DPA for service improvement, repeat-assessment comparison and aggregate benchmarking. We will not publish a benchmark that identifies you without your prior written consent.
9. Ownership and permitted use
9.1 You may retain, reproduce and share your Report within your organisation and with your professional advisers and IT provider.
9.2 Vitals software, assessment logic, scoring methodology, report layout, branding and other underlying intellectual property remain owned by Innova or its licensors. No ownership of those materials transfers to you.
9.3 You must not remove Innova attribution from a Report, represent the Report as having been produced by another provider, reverse engineer Vitals, or resell access to the Vitals software.
10. IT providers and purchases for another organisation
10.1 An IT provider or other intermediary may purchase an Assessment for a client only where it is authorised to do so by the organisation whose tenant will be assessed.
10.2 Where the purchaser is acting as a processor for its client and Innova would process the end client’s Personal Data as a sub-processor, the direct-customer DPA does not by itself govern that chain. The purchaser must enter into Innova’s applicable IT-provider/sub-processor terms before the Assessment is run.
10.3 The organisation whose tenant is assessed must be correctly identified in the order and the required Microsoft Entra administrator consent must be granted for that tenant.
10.4 An IT provider may provide the Report to its client and add its own commentary, but must not remove Innova attribution or present Innova’s Assessment as its own product. Nothing in this clause permits resale or sublicensing of the Vitals software.
11. Removing access and end of service
11.1 Tenant access can be revoked by the tenant administrator through Microsoft Entra at any time. Revocation prevents further use of that authorisation.
11.2 We do not use the tenant authorisation after completion of the Assessment unless you give a further documented instruction, for example to run a new Assessment.
11.3 Retention and deletion of Assessment Personal Data after completion are governed by the DPA.
12. Liability
12.1 Nothing in the Agreement excludes or limits either party’s liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be excluded or limited.
12.2 Subject to clause 12.1, neither party is liable to the other for any indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business opportunity or goodwill, arising out of or in connection with the Assessment.
12.3 Subject to clauses 12.1 and 12.4, Innova’s total aggregate liability arising out of or in connection with a single Assessment and the Agreement governing it, whether in contract, tort (including negligence), breach of statutory duty or otherwise, shall not exceed £10,000.
12.4 The cap in clause 12.3 does not operate to exclude or limit any liability to the extent that applicable law prohibits that exclusion or limitation. Nothing in the Agreement changes any responsibility or liability imposed directly on either party by Data Protection Legislation.
12.5 The Assessment is a sampled, point-in-time advisory service. Subject to clause 12.1, Innova is not responsible for an issue that falls outside the stated scope or sampling limits, arises after the Assessment, results from inaccurate/incomplete information or access supplied by the Client, or results from a Client decision to implement, not implement or modify a recommendation except to the extent the loss was caused by Innova’s breach of the Agreement or negligence.
12.6 Nothing in this clause requires the Client to waive a right of a Data Subject or regulator that cannot lawfully be waived.
13. General
13.1 The version of the Agreement accepted for an order is the version that governs that order. We may update future versions, but an update does not retrospectively alter an existing order unless both parties agree or the change is required by law.
13.2 Neither party is liable for delay or failure caused by circumstances beyond its reasonable control, but this does not excuse obligations concerning confidentiality, security or Personal Data to the extent they remain capable of performance.
13.3 No person other than the parties has any right under the Contracts (Rights of Third Parties) Act 1999 to enforce the Agreement.
13.4 If any provision is invalid or unenforceable, the remaining provisions continue in effect and the invalid provision is treated as modified to the minimum extent necessary to make it valid where legally possible.
13.5 A failure or delay in exercising a right is not a waiver of that right.
13.6 The Agreement is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction, subject to any mandatory law that applies.
14. Acceptance record
14.1 Acceptance is recorded electronically against the order. We may record the accepting person’s name and job title, organisation, date and time, IP address and the version of the Agreement accepted, and provide a copy electronically.
14.2 We retain contractual, tax, payment and accounting records where necessary for our own legal and business obligations. These records are distinct from Assessment Personal Data processed on your behalf under the DPA.