1. Terms and conditions
Ocerli customer terms and conditions
Effective date 1 September 2026
Version: 2.0
These terms are intended for business customers only. They govern access to and use of the Ocerli payroll platform and related services.
1. Who we are and how these terms work
1.1 In these terms, Ocerli, we, us and our means Ocerli Limited trading as Ocerli, a company registered in Jersey with registered number 112188 and registered office at 9 Hope Street, St Helier, Jersey, JE2 3NS
1.2 You and Customer mean the business, firm, organisation, employer, bureau, accountant or other entity that creates or accepts a subscription, signs an Order Form, uses the Services, or authorises users to access the Services. If an individual accepts these terms on behalf of a Customer, that individual confirms they have authority to bind the Customer.
1.3 These terms apply together with any Order Form, Pricing Plan, Rate Card, Support Policy, Data Processing Agreement, Privacy Policy, Security Statement, Sub-processor List the Retention Policy and any other document expressly incorporated by reference. If there is a conflict, the order of priority is: (a) Order Form; (b) Data Processing Agreement for data processing matters; (c) these terms; (d) Support Policy, Rate Card, Retention Policy and other incorporated policies.
1.4 We may offer different products, plan tiers, modules, integrations, APIs and support packages. The specific Services you have purchased, the plan limits, the fees and any special terms will be set out in your Order Form, Pricing Plan or online checkout.
1.5 These terms are designed for business-to-business use. If a customer may be treated as a consumer or micro-business under applicable law, qualified legal advice is required before using these terms.
2. Definitions
2.1 Account means the Customer account, tenant, subscription or workspace created for use of the Services.
2.2 Administrator means a user with authority to manage the Account, billing, users, permissions, payroll entities, settings or other administrative functions.
2.3 Ancillary Services means services outside the standard subscription, including onboarding, data migration, bulk imports, customer-caused error remediation, custom reports, custom development, integration work, training, historical document re-issues, account reactivation, data restoration, out-of-hours support and other professional services.
2.4 Authorised User means any employee, officer, contractor, agent, adviser, client user, bureau user or other person authorised by the Customer or an Administrator to access the Services.
2.5 Customer Data means all data, content, files, payroll information, employee information, tax information, pension information, pay data, returns, reports, configuration settings and other materials submitted to, generated through, stored in or processed by the Services for or on behalf of the Customer.
2.6 Data Protection Laws means all data protection, privacy and electronic communications laws applicable to the relevant processing, including where applicable the Data Protection (Jersey) Law 2018, the Data Protection Authority (Jersey) Law 2018, the UK GDPR, the UK Data Protection Act 2018, the EU GDPR and equivalent laws in other relevant jurisdictions.
2.7 Fees means subscription fees, usage fees, module fees, implementation fees, Ancillary Services fees, reactivation fees, data retrieval fees and any other amounts payable under these terms, an Order Form, a Pricing Plan or the Rate Card.
2.8 Order Form means an order form, proposal, statement of work, online plan selection, checkout page, renewal notice or other document accepted by the parties that identifies the Services purchased, fees, plan limits, subscription term and any special terms.
2.9 Rate Card means Ocerli’s then-current fee schedule for Ancillary Services, professional services, out-of-scope support, data retrieval, reactivation, custom work and related services, as updated from time to time.
2.10 Services means the Ocerli cloud payroll software, web application, APIs, integrations, modules, support services, documentation, updates and any related services made available by Ocerli.
2.11 Subscription Term means the initial term and each renewal term for which the Customer subscribes to the Services.
2.12 Retention Policy means the Ocerli Data Retention, Export and Deletion Policy referred to in Schedule 4, as approved and updated by Ocerli from time to time.
3. Access to the Services
3.1 Subject to payment of the Fees and compliance with these terms, Ocerli grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to access and use the Services for the Customer’s internal business purposes or, where expressly permitted by the applicable plan, to provide payroll services to the Customer’s own clients.
3.2 The Customer is responsible for choosing the correct subscription plan and modules for its use case, including the number of payroll entities, employers, employees, payslips, pay runs, jurisdictions, users, API calls, integrations, storage and support levels.
3.3 The Customer must ensure that each Authorised User accepts or complies with these terms and uses the Services only within the access rights granted to them.
3.4 The Customer is responsible for all activity on the Account, including activity by Authorised Users, Administrators, invited users and anyone using login credentials issued to the Customer.
3.5 The Customer is responsible for managing user roles, permissions and access rights. Ocerli is not responsible for losses caused by the Customer granting excessive access, failing to remove users, failing to review user permissions or failing to use available security controls.
3.6 Ocerli may add, remove or change user roles, permissions and security features from time to time where reasonably necessary to improve security, functionality or compliance.
4. Subscription plans, usage limits and plan tiers
4.1 The Services are provided on a subscription basis. Your plan tier and usage limits will be set out in the applicable Order Form, Pricing Plan or online account settings.
4.2 Plan tiers may vary by jurisdiction, customer type or package. A plan may include or exclude features such as multi-employer processing, bureau functionality, client portals, payroll approvals, statutory filing functionality, API access, integrations, custom reports, advanced permissions, single sign-on, audit logs, priority support, implementation support or dedicated account management.
4.3 Unless expressly included in your plan or Order Form, a subscription does not include bespoke configuration, custom development, data migration, bulk cleansing, training, customer-caused error remediation, post-termination restoration, out-of-hours support or other Ancillary Services.
4.4 If the Customer exceeds its plan limits, Ocerli may charge the applicable additional usage fees, require the Customer to upgrade to an appropriate plan, restrict further use until the plan is upgraded, or agree a bespoke package.
4.5 Ocerli may provide guidance on the appropriate plan, but the Customer remains responsible for selecting and maintaining a plan that matches its business, payroll volumes and compliance needs.
5. Fees, billing and payment
5.1 The Customer must pay the Fees specified in the Order Form, Pricing Plan, invoice or Rate Card.
5.2 Fees may be calculated by reference to one or more pricing metrics, including active employees, payslips, pay runs, payroll entities, users, seats, client accounts, modules, jurisdictions, API usage, integrations, storage, support package, implementation scope or any other basis stated in the Order Form.
5.3 Fees may be billed monthly, annually or on another billing cycle stated in the Order Form. Unless the Order Form says otherwise, recurring subscription Fees are payable in advance and usage-based Fees are payable in arrears or on the next invoice.
5.4 Unless expressly stated otherwise, Fees are exclusive of GST, VAT, withholding taxes, duties, levies, bank charges and other taxes or charges. The Customer is responsible for all such amounts except taxes based on Ocerli’s net income.
5.5 The Customer must provide accurate billing, contact and payment information and keep it up to date. Ocerli may invoice the Customer electronically.
5.6 Invoices are payable within 30 days of the invoice date unless the Order Form states a different period.
5.7 If payment is overdue, Ocerli may, without limiting any other rights: (a) charge interest at the rate permitted by applicable law or, if lawful, 4% above the Bank of England base rate; (b) recover reasonable collection costs; (c) suspend access to the Services; (d) withhold new work, Ancillary Services, data restoration or reactivation services; and (e) terminate the subscription in accordance with these terms.
5.8 Ocerli will normally give at least 7 days’ notice before suspending for non-payment, unless there is fraud, repeated non-payment, payment reversal, insolvency risk or legal/regulatory risk.
5.9 The Customer must not withhold or set off payment unless required by law or agreed in writing by Ocerli.
6. Auto-renewal, cancellation and price changes
6.1 Unless the Order Form says otherwise, each subscription automatically renews at the end of the then-current Subscription Term for a further period of the same length.
6.2 The Customer may cancel a subscription by giving at least one month’s written notice before the end of the current billing period, unless the Order Form states a different notice period.
6.3 Cancellation takes effect at the end of the notice period or the current paid Subscription Term, whichever is later. The Customer remains responsible for Fees during the notice period.
6.4 Ocerli may increase subscription Fees: (a) on renewal; (b) annually on or after 1 August by at least the percentage increase in the Jersey Retail Price Index or another index stated in the Order Form; (c) where the Customer changes plan, adds modules or exceeds usage limits; or (d) on at least 30 days’ notice for other pricing changes. Payslip fees will be renewed annually and made effective 1 Aug of each year irrespective of subscription renewal date.
6.5 Ocerli may update the Rate Card from time to time. Updated Rate Card fees apply to Ancillary Services ordered after the effective date of the update, unless otherwise agreed in writing.
6.6 If a material price increase is not acceptable, the Customer may cancel the affected subscription before the increase takes effect. Cancellation does not entitle the Customer to a refund of prepaid Fees except where required by law or expressly agreed in writing.
7. Free trials, pilots and beta services
7.1 Ocerli may offer free trials, pilot accounts, sandbox accounts, beta services or no-charge services. These are provided for evaluation only and may be subject to separate fees and terms, usage limits, reduced support, limited security assurances and shorter data-retention periods.
7.2 At the end of a trial or pilot, access will end unless the Customer enters into a paid subscription. Ocerli may delete or archive trial data unless otherwise agreed.
7.3 Beta services are provided as-is, may contain errors, may be changed or withdrawn at any time, and should not be used for live payroll unless Ocerli expressly confirms in writing that live use is permitted.
8. Standard support
8.1 Standard support is included only to the extent stated in the Customer’s plan, Order Form or Support Policy.
8.2 Standard support is provided to assist trained Authorised Users with technical issues, platform functionality, and reasonable questions arising from normal use of the Services. Standard support is not a substitute for onboarding, training, re-training, payroll process consultancy, or general user education.
8.3 The Customer is responsible for ensuring that each Owner, administrator, payroll user, manager, approver or other Authorised User who uses the Services has completed the training or onboarding reasonably required for their role. Where the Customer appoints a new Owner, administrator or payroll user, or where an existing user changes role or responsibilities, the Customer must ensure that the relevant user completes appropriate training before relying on standard support.
8.4 Ocerli may decline to provide standard support or may reclassify a support request as a Chargeable Ancillary Service, in accordance with clause 9, where Ocerli reasonably considers that the request arises wholly or mainly because an Authorised User has not completed appropriate training, is unfamiliar with the Services, requires re-training, or requires step-by-step operational assistance rather than support with a technical issue.
8.5 Any training, re-training, user familiarisation, payroll process guidance, bulk correction work, or support required as a result of a change in the Customer’s Owner, administrator, payroll team or other Authorised Users may be charged at Ocerli’s then-current training or professional-services rates. Ocerli will, where reasonably practicable, notify the Customer before carrying out chargeable work.
8.6 Unless otherwise agreed, standard support includes reasonable help with general platform use, access issues, basic configuration questions, suspected platform defects, and guidance on using published self-service features.
8.7 Standard support does not include Ancillary Services, professional services, payroll consultancy, tax advice, employment law advice, accounting advice, customer-caused error remediation, bespoke configuration, custom development, data migration, bulk data changes, historical reconstruction, third-party system troubleshooting, or out-of-hours work.
8.8 Ocerli may require the Customer to provide access to their account, screenshots, examples, payroll IDs, error messages, steps to reproduce and other information reasonably needed to investigate a support request.
8.9 Ocerli may refuse or delay support where the Customer is overdue on Fees, has breached these terms, refuses to provide necessary information, or asks Ocerli to take action that would be unlawful, insecure or outside the scope of the Services.
9. Ancillary Services and chargeable work
9.1 Ancillary Services are chargeable at Ocerli’s then-current Rate Card rates unless included in an Order Form or expressly agreed in writing.
9.2 Ancillary Services include, without limitation:
- onboarding, implementation, configuration workshops and project management;
- data migration, data mapping, data cleansing, bulk import and bulk amendment;
- customer training, bureau training, administrator training and bespoke consultancy;
- custom reports, custom fields, custom workflows, custom development and API/integration work;
- bespoke payroll configuration or jurisdiction-specific configuration not included in the subscription;
- year-end, tax-year, quarter-end, parallel-run or filing assistance beyond standard platform support;
- expedited support, priority support not included in the plan, and out-of-hours support;
- account reactivation, account reinstatement and re-granting access after termination or suspension;
- restoring data from archive, backups or legacy systems;
- post-termination data retrieval, bespoke exports and additional one-off exports beyond standard self-service tools;
- re-issuing historical payslips, reports, returns, statements, audit logs or other historical documents;
- support requests that are, in Ocerli’s reasonable opinion, primarily training, re-training, payroll process guidance or remediation caused by an untrained or insufficiently trained user;
- remediation work caused by inaccurate, incomplete or late Customer Data or Customer instructions;
- work required because the Customer, an Authorised User or a third-party integration made incorrect changes; and
- any other work that Ocerli reasonably identifies as outside standard support.
9.3 Before starting chargeable work, Ocerli will normally provide a written estimate, rate, scope or cap for approval. The Customer’s written approval, email confirmation, ticket confirmation or continued instruction to proceed will be treated as approval.
9.4 For urgent payroll or compliance work, Ocerli may start chargeable work without a formal signed statement of work where an Administrator or authorised contact asks Ocerli to proceed urgently. Ocerli will notify the Customer as soon as reasonably practicable of the applicable rates and estimated scope.
9.5 Estimates are not fixed quotes unless expressly stated. If work is likely to exceed an estimate, Ocerli will seek further approval where reasonably practicable.
9.6 Ocerli may require payment in advance, a deposit, settlement of overdue Fees or a signed statement of work before performing Ancillary Services.
9.7 Nothing in this clause prevents the Customer from reporting suspected platform defects, security incidents, data breaches, service availability issues or other urgent technical issues. Ocerli may investigate such matters regardless of whether the reporting user has completed training,but may charge for any resulting work that is determined not to relate to a fault in the Services.
10. Customer-caused errors and remediation
10.1 The Customer is responsible for the accuracy, completeness, timeliness and legality of all Customer Data, instructions, payroll settings, rates, deductions, employee records, tax codes, contribution settings, bank details, pension details, leave records and other information entered into or used with the Services.
10.2 The Customer must review payroll outputs, calculations, reports, submissions, payslips and export files before relying on them or sending them to employees, tax authorities, pension providers, banks or other third parties.
10.3 Where an error arises from inaccurate, incomplete, late or incorrectly entered Customer Data, Customer instructions, Customer configuration, Customer approval, Customer use of the Services, or a third-party system under the Customer’s control, the Customer remains responsible for the consequences of that error.
10.4 If correcting such an error requires support-team time, payroll specialist time, data work, developer time, database work, reprocessing, historical reconstruction, custom export, manual correction, emergency support or other out-of-scope assistance, Ocerli may charge for that remediation as an Ancillary Service.
10.5 Chargeable remediation may be billed by time spent, minimum charge, fixed fee, agreed estimate, support package, project fee or another method stated in the Rate Card or approved in writing.
10.6 Ocerli may decline to perform remediation work where it would create regulatory risk, data protection risk, security risk, audit integrity issues, system instability or disproportionate operational burden.
10.7 If a suspected error is caused by an Ocerli platform defect, Ocerli will investigate under standard support. If the investigation shows the issue was customer-caused, third-party-caused, or outside the subscription scope, Ocerli may charge for further investigation or remediation after notifying the Customer.
11. Payroll responsibilities and regulatory obligations
11.1 Ocerli provides software tools to support payroll processing. The Customer remains responsible for its employer, payroll, tax, social security, pension, employment, accounting, audit and recordkeeping obligations unless an Order Form expressly states that Ocerli is taking on a specific obligation.
11.2 The Customer is responsible for determining: (a) who is an employee, worker, director, contractor or other payee; (b) applicable pay, deductions, allowances, benefits, contributions and tax treatment; (c) applicable payroll frequency; (d) applicable jurisdiction; (e) filing deadlines; (f) payment deadlines; and (g) whether any legal or professional advice is needed.
11.3 Ocerli may provide payroll logic, templates, workflows, automated calculations, reports, reminders or submission functionality. These features do not remove the Customer’s responsibility to verify outputs and comply with applicable law.
11.4 The Customer is responsible for approving payroll before finalisation, submission, payment or release of payslips.
11.5 Unless expressly agreed in an Order Form, Ocerli is not responsible for making payments to employees, tax authorities, social security authorities, pension providers or other recipients.
11.6 Ocerli is not responsible for submitting filings to tax authorities, social security authorities, pension providers or other regulators. Where the Services enable or automate a filing, the Customer remains responsible for checking that the filing is complete, accurate, authorised and submitted on time.
11.7 The Customer must maintain its own records for the statutory periods applicable to the Customer and its employees. Ocerli’s retention of archived data is not a substitute for the Customer’s own statutory recordkeeping obligations.
11.8 Ocerli may update payroll logic and compliance functionality from time to time. The Customer must provide information reasonably requested by Ocerli to configure or update the Services for the Customer’s jurisdiction and use case.
11.9 Ocerli is not liable for penalties, interest, surcharges, fines, employee claims, tax liabilities, pension liabilities or other losses arising from inaccurate Customer Data, late Customer approvals, incorrect Customer instructions, Customer failure to review outputs, third-party failures or changes in law not reasonably reflected in the Services at the relevant time.
12. Customer Data ownership and licence
12.1 As between Ocerli and the Customer, the Customer owns all Customer Data.
12.2 The Customer grants Ocerli a worldwide, non-exclusive, royalty-free licence to host, copy, transmit, display, process, store, back up, analyse and otherwise use Customer Data to: (a) provide, secure, support and improve the Services; (b) perform Ocerli’s obligations; (c) troubleshoot, maintain and develop the platform; (d) comply with law; and (e) create anonymised or aggregated data in accordance with these terms.
12.3 The Customer warrants that it has all rights, permissions, notices, lawful bases and consents required for Ocerli to process Customer Data in accordance with these terms and the Data Processing Agreement.
12.4 Ocerli may create aggregated, anonymised or de-identified data from Customer Data and usage data, provided it does not identify the Customer, Authorised Users, employees or other individuals. Ocerli may use such data for analytics, benchmarking, product development, security, service improvement and lawful business purposes.
12.5 Ocerli will not sell Customer Data or use identifiable payroll data for marketing unrelated third-party products without appropriate legal basis and consent where required.
13. Data protection and privacy
13.1 The parties will comply with applicable Data Protection Laws.
13.2 For Customer Data processed through the Services, the Customer will usually act as controller and Ocerli will usually act as processor. Ocerli may act as controller for limited data relating to its own business operations, including account administration, billing, marketing, security monitoring, product analytics and legal compliance, as described in Ocerli’s Privacy Policy.
13.3 The Data Processing Agreement (Schedule 1) forms part of these terms
13.4 The Customer must provide privacy notices to employees, workers, Authorised Users and other data subjects and must ensure it has a lawful basis for Ocerli and any sub-processors to process their personal data.
13.5 The Customer must not input personal data into free-text fields unless the field is intended for that type of data. The Customer must not input payment card data, bank data, tax identifiers, health data, special category data or criminal offence data into fields not designed for that information.
13.6 Ocerli may use sub-processors to provide the Services. Ocerli will maintain a Sub-processor List and will require sub-processors to protect personal data under written terms that are materially consistent with Ocerli’s data protection obligations.
13.7 International transfers of personal data will be handled in accordance with applicable Data Protection Laws and, where required, appropriate safeguards such as adequacy decisions, standard contractual clauses, UK international data transfer agreements/addenda, Jersey-approved mechanisms or equivalent safeguards.
13.8 Each party must notify the other without undue delay if it becomes aware of a personal data breach affecting Customer Data. Ocerli will provide reasonable information to assist the Customer in meeting breach assessment and notification obligations.
13.9 Where Ocerli is required by law to notify a regulator directly, it may do so. Where the Customer is controller, the Customer remains responsible for assessing and making controller notifications unless law requires otherwise.
14. Security
14.1 Ocerli will maintain appropriate technical and organisational measures designed to protect Customer Data against unauthorised or unlawful processing and accidental loss, destruction, damage, alteration or disclosure.
14.2 Security measures may include encryption in transit, access controls, role-based permissions, audit logging, backup procedures, vulnerability management, secure development practices, monitoring, incident response processes and use of reputable cloud infrastructure.
14.3 The Customer is responsible for maintaining appropriate security on its own systems, devices, networks, email accounts and user accounts.
14.4 The Customer must ensure that Authorised Users use strong passwords, multi-factor authentication where required or available, secure devices, appropriate access rights and secure email practices.
14.5 The Customer must notify Ocerli immediately if it suspects unauthorised access to the Account, compromised credentials, incorrect user access, accidental disclosure or any other security issue affecting the Services.
14.6 Ocerli may require use of multi-factor authentication, password rules, account verification or other security controls. Ocerli may suspend access where reasonably necessary to protect the Services, Customer Data, other customers or Ocerli.
14.7 No online service is completely secure. Ocerli does not guarantee that the Services will be immune from all security incidents, but it will take reasonable steps appropriate to the nature of the Services and the risks involved.
15. Availability, maintenance and support targets
15.1 Ocerli will use reasonable endeavours to make the production Services available in accordance with the Support Policy and any applicable service level agreed in an Order Form.
15.2 Unless an Order Form states otherwise, any availability target is a target only and does not entitle the Customer to service credits, refunds or compensation.
15.3 Availability targets exclude scheduled maintenance, emergency maintenance, customer-side issues, third-party services, integrations, internet failures, force majeure events, beta services, trial services, suspension for breach or non-payment, and downtime caused by the Customer or its Authorised Users.
15.4 Ocerli may perform scheduled maintenance and will use reasonable endeavours to schedule planned maintenance outside normal business hours and to give advance notice where reasonably practicable.
15.5 Ocerli may perform emergency maintenance without notice where necessary for security, stability, compliance or urgent operational reasons.
15.6 Unless the Order Form says otherwise, support is available during 9:00 am to 5:00 pm Jersey/UK time on business days, excluding public holidays in Jersey and/or the UK.
15.7 Ocerli will prioritise support requests based on severity and business impact. Indicative initial response targets are set out in Schedule 2. Response targets are not guaranteed resolution times.
16. Third-party services and integrations
16.1 The Services may integrate with or depend on third-party services, including accounting software, HR systems, payment providers, banking systems, government portals, identity providers, communications tools, hosting providers and other software or infrastructure.
16.2 Third-party services are provided by independent third parties and may be subject to their own terms, fees, availability, security, support and privacy practices.
16.3 The Customer authorises Ocerli to exchange Customer Data with third-party services connected by the Customer or reasonably required to provide the Services.
16.4 Ocerli is not responsible for third-party services, third-party outages, third-party API changes, third-party errors, third-party data loss or the Customer’s use of third-party services.
16.5 Ocerli may add, remove, suspend or change integrations where reasonably necessary, including where a third-party provider changes its service, terms, security requirements, API, fees or availability.
17. Intellectual property
17.1 Ocerli and its licensors own all intellectual property rights in the Services, software, platform, APIs, workflows, interfaces, documentation, designs, templates, reports, product logic, know-how, code, databases, analytics, improvements and related materials.
17.2 The Customer receives only the limited right to access and use the Services under these terms. No intellectual property rights are transferred to the Customer.
17.3 The Customer must not copy, modify, adapt, translate, reverse engineer, decompile, disassemble, scrape, frame, resell, sublicense or create derivative works from the Services except as expressly permitted by law or agreed in writing.
17.4 If the Customer provides feedback, suggestions, ideas or improvement requests, Ocerli may use them without restriction or compensation, provided Ocerli does not disclose the Customer’s confidential information.
17.5 Ocerli may use the Customer’s name and logo in customer lists and sales materials only with the Customer’s prior written consent, unless otherwise agreed in an Order Form.
18. Confidentiality
18.1 Each party may receive confidential information from the other. Confidential information includes business, technical, financial, pricing, security, payroll, employee, product and commercial information that is identified as confidential or should reasonably be understood to be confidential.
18.2 The receiving party must protect confidential information using at least reasonable care, use it only for purposes connected with these terms, and disclose it only to people who need to know it and are bound by appropriate confidentiality obligations.
18.3 Confidentiality obligations do not apply to information that is public, already known without restriction, independently developed, lawfully received from a third party, or required to be disclosed by law, regulator or court order.
18.4 If disclosure is legally required, the receiving party will, where lawful and practicable, give advance notice and cooperate to limit disclosure.
19. Acceptable use
19.1 The Customer must use the Services only for lawful business purposes and in accordance with these terms, documentation and reasonable instructions from Ocerli.
19.2 The Customer must not, and must ensure Authorised Users do not:
- undermine or attempt to bypass the security or integrity of the Services;
- access systems, data or accounts without permission;
- introduce malware, harmful code or automated attacks;
- overload, interfere with or disrupt the Services;
- use the Services for unlawful, fraudulent, abusive, offensive or discriminatory purposes;
- upload content that infringes third-party rights or breaches law;
- reverse engineer, copy or extract the source code, logic or structure of the Services;
- scrape or harvest data except through permitted export or API functionality;
- resell, lease, lend, sublicense or provide the Services to third parties except as expressly permitted by the plan;
- perform penetration testing or security testing without Ocerli’s prior written approval;
- use the Services to build, benchmark or train a competing product without Ocerli’s written consent;
- share user credentials or allow unauthorised access; or
- behave abusively or disrespectfully towards Ocerli staff, contractors, partners or customers.
19.3 Ocerli may suspend or restrict access where it reasonably believes the Customer has breached this clause or where continued access could harm the Services, Ocerli, other customers, individuals or third parties.
20. Changes to Services and terms
20.1 Ocerli may update, improve, modify, replace or discontinue features from time to time. Ocerli will use reasonable endeavours to avoid materially reducing core paid functionality during a paid Subscription Term without notice.
20.2 Ocerli may make changes required for security, compliance, legal, regulatory, infrastructure, third-party or operational reasons without advance notice where necessary.
20.3 Ocerli may update these terms from time to time. Material changes will normally be notified at least 30 days before taking effect, unless a shorter period is required for legal, security or urgent operational reasons.
20.4 Continued use of the Services after changes take effect constitutes acceptance of the updated terms. If a material change is unacceptable, the Customer may terminate the affected Services before the change takes effect.
21. Suspension
21.1 Ocerli may suspend the Services, an Account or any Authorised User immediately if: (a) Fees are overdue; (b) the Customer breaches these terms; (c) there is a security risk; (d) there is suspected fraud, misuse or unlawful activity; (e) required by law, regulator, court order or sanctions rules; (f) a third-party service requires suspension; (g) the Customer becomes insolvent; or (h) continued access could create risk to Ocerli, the Services, other customers or individuals.
21.2 Suspension does not relieve the Customer from paying Fees unless Ocerli agrees otherwise.
21.3 Ocerli will restore access when the reason for suspension has been resolved to Ocerli’s reasonable satisfaction and any applicable reactivation or handling fee has been paid.
22. Termination
22.1 Either party may terminate a subscription at the end of the current Subscription Term by giving the required notice.
22.2 Either party may terminate immediately if the other party commits a material breach and fails to remedy it within 14 days of written notice, or if the breach cannot be remedied.
22.3 Ocerli may terminate immediately if the Customer fails to pay Fees, becomes insolvent, breaches acceptable use or security obligations, infringes Ocerli intellectual property, creates legal or regulatory risk, or repeatedly makes unsupported or abusive support requests.
22.4 On termination or expiry: (a) the Customer’s right to access and use the Services ends; (b) the Customer must stop using the Services; (c) unpaid Fees become immediately due; (d) Ocerli may archive the Account; and (e) clauses intended to survive will continue.
22.5 Fees are non-refundable except where required by law or expressly stated in an Order Form.
23. Post-termination data access, export and retrieval
23.1 The Customer should export and download all Customer Data needed for statutory, tax, payroll, employee, audit and business recordkeeping before termination or expiry.
23.2 After termination or expiry, Ocerli will provide a free self-service access window of 30 days, during which the Customer may access the Account for read-only export or download purposes, provided all undisputed Fees have been paid and access is technically available.
23.3 During the free access window, the Customer may use standard self-service export functionality available in the Services. Ocerli is not required to provide bespoke exports, manual assistance, data cleansing, historical reconstruction, database extracts, custom reports or developer support free of charge.
23.4 After the free access window, the Account may be archived, restricted, deleted or deactivated in accordance with the Retention Policy and applicable law. Any request to retrieve, export, restore, re-open, re-grant access to or reactivate Customer Data after that period is a chargeable Ancillary Service.
23.5 Chargeable post-termination services may include a reactivation fee, handling fee, professional-services time, data retrieval fee, storage/archival fee, subscription reinstatement fee and any third-party costs.
23.6 A former customer returning after termination to request historical payroll data, payslips, reports, returns, audit logs or exports must pay the applicable Rate Card fees before Ocerli is required to perform retrieval, restoration or reactivation work.
23.7 Ocerli may provide exported data in standard formats reasonably selected by Ocerli, such as CSV, XLSX, PDF or other commonly available export formats. Ocerli is not required to provide proprietary database backups, source code, database schemas, custom formats or direct database access.
23.8 Ocerli may withhold chargeable retrieval, restoration, bespoke export or reactivation services until all overdue Fees and applicable Ancillary Services fees are paid, except to the extent prohibited by law or Data Protection Laws.
23.9 Ocerli may retain Customer Data after termination where required or permitted by law, regulation, audit, tax, accounting, dispute, backup, security or legitimate business retention requirements. Statutory retention obligations may override deletion requests.
23.10 Once Customer Data has been deleted or irreversibly anonymised in accordance with the Retention Policy, Ocerli will not be able to restore it.
23.11 Ocerli’s retention of archived Customer Data does not make Ocerli responsible for the Customer’s statutory recordkeeping obligations.
24. Warranties and disclaimers
24.1 Each party warrants that it has authority to enter into and perform these terms.
24.2 Ocerli warrants that it will provide the Services with reasonable skill and care.
24.3 The Customer acknowledges that payroll outcomes depend on accurate Customer Data, correct configuration, timely approvals, current legal requirements, third-party services and proper Customer review.
24.4 Except as expressly stated in these terms and to the extent permitted by law, the Services are provided as-is and as-available. Ocerli does not warrant that the Services will be uninterrupted, error-free, immune from security incidents, or suitable for every jurisdiction, customer structure, payroll scenario or tax outcome.
24.5 Ocerli does not provide legal, tax, employment, accounting, pension, financial or payroll bureau advice unless expressly agreed in a separate written professional-services agreement. Information provided through the Services or support is general platform guidance and is not a substitute for professional advice.
24.6 The Customer is responsible for obtaining professional advice where needed.
25. Limitation of liability
25.1 Nothing in these terms excludes or limits liability that cannot be excluded or limited by law, including liability for fraud, fraudulent misrepresentation, willful misconduct, death or personal injury caused by negligence, or any other liability that cannot legally be excluded.
25.2 Subject to clause 25.1, Ocerli is not liable for: (a) loss of profit, revenue, goodwill, business, anticipated savings, opportunity or reputation; (b) indirect, consequential, special, exemplary or punitive loss; (c) tax, payroll, pension, social security, employee or regulatory penalties caused by inaccurate Customer Data, Customer instructions, Customer approval or Customer failure to review outputs; (d) losses caused by third-party services, integrations, banks, payment providers, government portals or tax authority systems; (e) loss caused by unauthorised access resulting from Customer security failures; or (f) loss of data, except that Ocerli will use reasonable endeavours to restore data from available backups where the loss is caused by Ocerli.
25.3 Subject to clauses 25.1 and 25.4, Ocerli’s total aggregate liability arising out of or in connection with the Services and these terms is limited to the Fees paid or payable by the Customer for the affected Services in the 12 months immediately before the event giving rise to the claim.
25.4 The Customer must notify Ocerli of any claim within 12 months of becoming aware of the circumstances giving rise to it, unless a longer period is required by law.
25.6 Each party must take reasonable steps to mitigate losses.
26. Indemnities
26.1 The Customer indemnifies Ocerli against losses, liabilities, damages, costs and expenses arising from third-party claims related to: (a) Customer Data; (b) Customer breach of law or these terms; (c) payroll, employment, tax, pension or social security obligations of the Customer; (d) Customer-caused errors; (e) Customer use of third-party services; (f) Customer instructions; or (g) claims by employees, workers, clients or other data subjects arising from Customer acts or omissions, except to the extent caused by Ocerli’s breach of these terms.
26.2 Ocerli indemnifies the Customer against third-party claims alleging that the Services, when used in accordance with these terms, infringe that third party’s intellectual property rights, except where the claim arises from Customer Data, Customer instructions, modifications not made by Ocerli, combination with third-party services, use outside the permitted scope, or continued use after Ocerli provided a non-infringing alternative.
26.3 If the Services are alleged to infringe, Ocerli may procure the right to continue use, modify the Services, replace the Services, or terminate the affected Services and refund any prepaid unused Fees.
26.4 The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation and allow the indemnifying party to control the defence and settlement, provided no settlement may admit liability or impose obligations on the indemnified party without consent.
27. Insurance
27.1 Ocerli will maintain insurance cover that it reasonably considers appropriate for a SaaS payroll provider of its size, nature and risk profile.
28. Compliance, sanctions and export controls
28.1 The Customer must comply with all laws applicable to its use of the Services, including employment, payroll, tax, social security, pension, anti-bribery, anti-money laundering, sanctions, export control and data protection laws.
28.2 Ocerli may refuse, block, suspend or terminate access or payments where it reasonably believes there is a sanctions, fraud, regulatory, legal, financial crime or security risk.
28.3 The Customer confirms that it and its Authorised Users are not subject to sanctions and are not located in a country or territory where Ocerli is prohibited from providing the Services.
29. Non-solicitation
29.1 During the Subscription Term and for six months after it ends, the Customer must not knowingly solicit for employment or engagement any Ocerli employee, Director or contractor who was materially involved in providing the Services to the Customer.
29.2 This does not prevent general recruitment advertising not targeted at Ocerli personnel.
29.3 If the Customer breaches this clause, Ocerli may claim its reasonable recruitment and replacement costs or a pre-agreed amount if legally enforceable. Lawyer sign-off is required on any fixed amount.
30. Force majeure
30.1 Neither party is liable for failure or delay caused by events beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, pandemic, epidemic, labour disputes, failure of utilities or internet services, cloud provider failure, cyberattack, government action, legal changes, sanctions, fire, flood or other events outside reasonable control.
30.2 The affected party must take reasonable steps to reduce the impact and resume performance.
31. Notices
31.1 Notices to Ocerli must be sent to info@ocerli.com and, if required by the Order Form, to 9 Hope Street, St Helier, Jersey, JE2 3NS
31.2 Notices to the Customer may be sent to the Account owner, billing contact, Administrator, legal contact or email address provided through the Services.
31.3 Operational notices may be given by email, in-product notice, CRM system, support ticket, website notice or other reasonable electronic method.
32. Assignment and subcontracting
32.1 The Customer may not assign, transfer or novate these terms without Ocerli’s prior written consent, except as part of a genuine corporate reorganisation, merger or sale of substantially all assets where the assignee is not a competitor and is able to perform the Customer’s obligations.
32.2 Ocerli may assign, transfer, novate or subcontract its rights and obligations to an affiliate, successor, purchaser or service provider, provided this does not materially reduce the Customer’s rights under these terms.
32.3 Ocerli remains responsible for subcontractors to the extent required by these terms and applicable law.
33. Governing law, jurisdiction and disputes
33.1 These Terms, and any dispute or claim arising out of or in connection with them, their subject matter or formation, including any non-contractual dispute or claim, shall be governed by and construed in accordance with the laws of Jersey.
33.2 The parties submit to the exclusive jurisdiction of the courts of Jersey in respect of any dispute or claim arising out of or in connection with these Terms, unless mandatory law requires otherwise.
33.3 Nothing in these Terms shall limit either party’s obligation to comply with any applicable mandatory laws or regulatory requirements, including, where relevant, UK payroll, tax, employment, data protection or other laws that apply to the Customer’s use of the Services.
33.4 Nothing in this clause shall prevent Ocerli from bringing proceedings in any other jurisdiction where reasonably necessary to recover unpaid Fees, protect its intellectual property, enforce its rights, or seek urgent injunctive, interim or protective relief.
33.5 Before starting court proceedings, each party will use reasonable endeavours to resolve disputes through good-faith escalation between senior representatives. Either party may seek urgent injunctive, interim or protective relief at any time.
33.6 Where the Customer is an Enterprise Customer, or where the relevant Order Form, Statement of Work or subscription agreement expressly states that this clause applies, either party may require that any dispute arising out of or in connection with these Terms is first referred to confidential mediation before an independent mediator agreed by the parties. If the parties cannot agree a mediator within 10 Business Days, either party may request that a mediator be appointed by the President for the time being of the Law Society of Jersey or such other independent appointing body as the parties may agree.
33.7 The mediation shall take place in Jersey, unless the parties agree otherwise, and each party shall participate in good faith. Unless otherwise agreed, the costs of the mediator shall be shared equally, but each party shall bear its own legal and other costs of participating in the mediation.
33.8 If the dispute is not resolved within 30 days after the mediator is appointed, or such longer period as the parties may agree, either party may commence court proceedings in accordance with clause 33.2, unless the relevant Order Form, Statement of Work or subscription agreement provides that the dispute is to be finally resolved by arbitration.
33.9 Where arbitration is expressly agreed, the dispute shall be referred to and finally resolved by arbitration seated in Jersey, conducted in English, by a single arbitrator appointed by agreement between the parties or, failing agreement within 10 Business Days, by an independent appointing body agreed by the parties or determined by the Royal Court of Jersey. The arbitration shall be conducted in accordance with the Arbitration (Jersey) Law 1998 and any arbitration rules specified in the relevant Order Form, Statement of Work or subscription agreement.
33.10 Nothing in this clause prevents either party from applying to a court of competent jurisdiction for urgent interim, injunctive or protective relief, including in relation to confidentiality, intellectual property, data protection, security, non-payment, suspension of Services, or misuse of the Services.
34. General
34.1 These terms and the incorporated documents form the entire agreement between the parties about the Services and replace prior discussions, proposals and understandings.
34.2 If any provision is invalid or unenforceable, it will be modified or removed to the minimum extent necessary and the remaining provisions will continue.
34.3 No failure or delay in enforcing rights is a waiver.
34.4 Nothing in these terms creates a partnership, joint venture, employment, agency, fiduciary or trust relationship.
34.5 A person who is not a party has no right to enforce these terms unless applicable law says otherwise.
34.6 Clauses relating to Fees, Customer Data, confidentiality, intellectual property, data protection, post-termination data access, liability, indemnities, governing law, disputes and any other clauses intended to survive will survive termination.
Schedule 1 – Data Processing Agreement
DATA PROCESSOR AGREEMENT
- Introduction
1.1 This Data Processing Agreement (“DPA”) is entered into between the Client (the “Controller”) and Ocerli (the “Processor”) and governs the Processor’s processing of personal data on behalf of the Controller. This DPA is intended to satisfy the requirements of Article 19(3) of the Data Protection (Jersey) Law 2018 (“DPJL”), Article 28(3) of the UK GDPR, the Data Protection (Bailiwick of Guernsey) Law, 2017 (“Guernsey Law”), and equivalent provisions under another Applicable Law where relevant.
1.2 Article 19(1) DPJL / Article 28(1) of the UK GDPR lays down the responsibility of the data controller to ensure the data processor provides sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of the law (DPJL) and ensure the protection of the rights of the data subjects.
1.3 For the purposes of this DPA, “the Agreement” means, together, the Letter of Engagement/Contract, the Terms and Conditions, any Order Form, this DPA, and the Ocerli Data Retention, Export and Deletion Policy as incorporated and updated from time to time. Where this DPA refers to matters being “as provided in the Agreement”, that reference includes the retention, archive and deletion terms set out in that Policy.
- Legislation
2.1 The Processor shall comply with all applicable data protection and privacy legislation (“Applicable Law”) in force from time to time, which may include, without limitation, the Data Protection (Jersey) Law 2018 (“DPJL”), the Data Protection (Bailiwick of Guernsey) Law, 2017 (“Guernsey Law”), the UK General Data Protection Regulation and the Data Protection Act 2018 (together, “UK GDPR”), the Cayman Islands Data Protection Act (2021 Revision), the Isle of Man Data Protection Act 2018, and equivalent legislation in other jurisdictions, together with any replacement or successor legislation, to the extent applicable to the Processor’s actual processing activities under this DPA. The Processor shall comply with the data protection laws applicable to its actual processing activities under this DPA. The Processor does not warrant compliance with any specific regime beyond those applicable to its actual processing activities.
- Processing of personal data
3.1 Purpose: The purpose of the processing under the Contract is the provision of the Processors services by the Processor as specified in the Letter of Engagement/Contract.
3.2 In connection with the Processor’s delivery of services to the Controller, the Processor will process certain categories and types of the Controller’s and his customer’s personal data on behalf of the Data Controller.
3.3 ” Personal data” includes “any information relating to an identified or identifiable natural person” as defined in Article 2 DPJL / Article 4(1) of the UK GDPR (“Personal Data”). The categories and types of Personal Data processed by the Processor on behalf of the Controller are listed in sub-Appendix A. The Processor only performs processing activities that are necessary and relevant to perform the agreed services. The parties shall update sub-appendix A whenever changes that necessitate an update occur.
3.4 In accordance with Article 8 DPJL / Article 5(1)(e) of the UK GDPR (storage limitation), the Processor shall not retain Personal Data processed under this DPA in identifiable form for longer than is necessary for the purposes set out in this DPA, except to the extent a longer period is required or permitted by Applicable Law, is subject to a legal hold, or is provided for in the Ocerli Data Retention, Export and Deletion Policy referred to at clause 1.3.
3.5 The obligation in clause 3.3 to process only Personal Data that is necessary and relevant to the agreed services is an ongoing obligation and is not limited to the point at which the services are first provided. The Processor shall periodically review, and shall delete, restrict or anonymise, Personal Data that is no longer necessary for those purposes, subject always to clause 3.4 and any retention required or permitted by Applicable Law.
- Instruction
4.1 The Processor may only act and process the Personal Data in accordance with its function as Data Processor according to Article 19 DPJL / Article 28 of the UK GDPR and with the documented instructions from the Controller (“Instruction”) unless required by law to act without such instructions. The Instruction at the time of entering into this DPA is that the Processor may only process the Personal Data with the purpose of delivering the agreed services as described in the Letter of Engagement/Contract.
4.2 The Controller guarantees the processing of Personal Data in accordance with the requirements of Data Protection Laws and Regulations. The Controller’s instructions for the processing of Personal Data shall comply with Applicable Law. The Controller will have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which it was obtained.
4.3 The Processor will inform the Controller of any instruction that it deems to be in violation of applicable laws and will only execute the instructions once they have been confirmed or modified.
4.4 The Controller acknowledges that it retains sole responsibility as data controller for: (a) ensuring that the legal basis for its payroll processing is established and maintained, including any applicable lawful basis under Applicable Law; (b) the accuracy, completeness and legality of all payroll instructions and Personal Data provided to the Processor; (c) providing appropriate privacy notices to its employees and workers in connection with the payroll processing described in this DPA; (d) compliance with all obligations as employer, including employment law, payroll and tax obligations, and obligations to relevant authorities, except to the extent the Processor has expressly agreed to discharge such obligations on the Controller’s behalf; and (e) making any required notifications to supervisory authorities or data subjects in connection with a Personal Data Breach, with the Processor providing reasonable support as described in clause 5.6. Nothing in this DPA shall be construed as transferring to the Processor any obligation that properly rests with the Controller as data controller or employer.
- The Processor’s obligations
5.1 Confidentiality
5.1.1 The Processor shall treat all the Personal Data as strictly confidential information. The Personal Data may not be copied, transferred or otherwise processed in conflict with the Instruction unless the Controller has agreed in writing.
5.1.2 The Processor’s employees shall be subject to an obligation of confidentiality that ensures they shall treat all the Personal Data under this DPA with strict confidentiality.
5.1.3 Personal Data will only be made available to personnel who require access to it for the delivery of the agreed services and this DPA.
5.1.4 The Processor shall also ensure that employees processing the Personal Data only process the Personal Data in accordance with the Instruction.
5.2 Security
5.2.1 The Processor shall implement the appropriate technical and organisational measures in accordance with Article 21 DPJL / Article 32 of the UK GDPR. The security measures are subject to technical progress and development. The Processor may update or modify the security measures from time to time, provided that such updates and modifications do not degrade overall security.
5.3 The Processor shall provide documentation in writing for the Processor’s security measures if requested by the Controller.
5.4 Data protection impact assessments and prior consultation
5.4.1 If the Processor’s assistance is necessary and relevant upon the Controller’s prior written consent, the Processor shall assist the Controller in preparing data protection impact assessments in accordance with Article 19 & 21 DPJL / Articles 28, 32, 35 and 36 of the UK GDPR along with any prior consultation in accordance with Article 19 & 21 DPJL / Articles 28, 32, 35 and 36 of the UK GDPR.
5.5 Rights of the Data Subjects
5.5.1 If the Controller receives a request from a data subject for the exercise of the data subject’s rights under the applicable law and the correct and legitimate reply to such a request necessitates the Processor’s assistance upon the Controller’s prior written consent, the Processor shall assist the Controller by providing the necessary information and documentation. The Processor shall be given reasonable time to assist the Controller with such requests in accordance with the applicable law.
5.5.2 If the Processor receives a request from a data subject for the exercise of the data subject’s rights under the applicable law and such request is related to the Personal Data of the Controller, the Processor must immediately forward the request to the Data Controller and must refrain from responding to the person directly.
5.6 Personal Data Breaches
5.6.1 Where the Processor becomes aware of a confirmed or reasonably suspected security incident that affects Personal Data processed on behalf of the Controller under this DPA (a “Personal Data Breach”), the Processor shall notify the Controller without undue delay and, where feasible, within 48 hours of becoming aware. Initial notification may be made based on the information available at the time and shall be updated as further information becomes available. Nothing in this clause shall be construed as an admission of liability by the Processor, and notifications shall be made without prejudice to any investigation that may follow. For the avoidance of doubt, a “Personal Data Breach” for the purposes of this DPA means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by the Processor on behalf of the Controller. The Processor’s notification obligations under this clause are limited to breaches affecting Controller personal data processed under this DPA; the Processor’s obligations as a controller in respect of its own business data are governed by its own data protection policies.
5.6.2 The Processor shall make reasonable efforts to identify the cause of the Personal Data Breach and take such steps as it deems reasonably necessary to investigate, contain, and prevent recurrence, and shall keep the Controller reasonably informed of material developments. The Controller, as data controller, shall remain solely responsible for determining whether and when to notify any supervisory authority or affected data subjects, and the Processor shall provide reasonable cooperation and assistance to the Controller in connection with any such notifications.
5.7 Documentation of Compliance and Audit Rights
5.7.1 Upon request, the Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, which may include security policy summaries, relevant certifications, third-party assurance materials, and written responses to reasonable security questionnaires. Where the Controller requires further assurance that cannot be satisfied by the foregoing, the Processor shall provide reasonable cooperation to facilitate a limited, focused audit of the Processor’s processing activities under this DPA, subject to: (a) reasonable advance written notice of not less than 30 days; (b) agreement on the scope, timing, and conduct of the audit, which shall be limited to matters directly relevant to this DPA; (c) any audit being carried out at the Controller’s expense and during normal business hours in a manner that minimises disruption to the Processor’s operations; and (d) the auditor being subject to appropriate confidentiality obligations. The Processor shall not be required to provide access to data or systems relating to other clients. The parties shall agree in writing the basis on which any such audit is to be conducted before it commences.
5.8 Data Transfers
5.8.1 The Processor shall not transfer Personal Data processed under this DPA to any country outside the jurisdiction in which the services are delivered except where: (a) such transfer is to a country or territory that has been recognised as providing an adequate level of protection under Applicable Law; (b) appropriate safeguards are in place as required by Applicable Law (such as standard contractual clauses or equivalent binding protections); or (c) the Controller has given its prior written consent to such transfer. The Processor shall use only storage and processing solutions that employ appropriate technical and organisational security measures and shall ensure that any approved sub-processors offering cloud storage services maintain equivalent standards.
- Sub-Processors
6.1 The Data Processor is given general authorisation to engage third parties to process the Personal Data (“Sub-Processors”) without obtaining any further written, specific authorisation from the Controller, provided that the Processor notifies the Controller in writing about the identity and role of a potential Sub-Processor (and its processors, if any). If the Controller wishes to object to the relevant Sub-Processor, the Controller shall give notice hereof in writing within ten (10) business days of receiving the notification from the Processor. Absence of any objections from the Controller shall be deemed a consent to the relevant Sub-Processor.
6.2 In the event the Controller objects to a new Sub-Processor on reasonable data protection grounds and the Processor cannot resolve the objection, either party may terminate the affected services on reasonable written notice. The Processor may continue to use the relevant Sub-Processor where necessary to provide the services to other clients or to wind down the affected services until termination takes effect.
6.3 The Processor shall complete a written Sub-processor agreement with any Sub processors. Such an agreement shall, at minimum, provide the same data protection obligations as the ones applicable to the Processor, including the obligations under this DPA. The Processor shall monitor and control its Sub-processors’ compliance with the applicable law on an ongoing basis. Documentation of such monitoring and control shall be provided to the Controller if requested in writing.
6.4 The Processor is accountable to the Controller for any Sub-Processor in the same way as it is accountable for its own actions and omissions.
6.5 The Processor is at the time of entering into this DPA using the Sub-Processors listed in sub-Appendix B. If the Processor initiates sub-processing with a new Sub-Processor, such new Sub-Processor shall be added to the list in sub-appendix B under paragraph 2.
- Limitation of Liability
7.1 The total aggregate liability to the Client, of whatever nature, whether in contract, tort or otherwise, of the Processor for any losses whatsoever and howsoever caused arising from or in any way connected with this engagement shall be subject to the (“Limitation of Liability”) clause set out in the Terms and Conditions.
7.2 Nothing in this DPA shall create any liability on the part of the Processor that is separate from, or greater than, the limitations set out in the Limitation of Liability clause in the Terms and Conditions, except to the extent that Applicable Law prohibits such limitation in relation to a specific head of liability. For the avoidance of doubt, this DPA does not create any uncapped or separate exposure for the Processor in respect of data breach or data protection claims. Nothing in this clause shall relieve the Processor of its own direct responsibilities under Applicable Law as they apply to its role as Processor under this DPA.
- Termination
8.1 Following expiration or termination of the Agreement, the Processor will delete or return to the Controller all Personal Data in its possession as provided in the Agreement except to the extent the Processor is required by Applicable law to retain some or all of the Data (in which case the Processor will archive the data and implement reasonable measures to prevent the Personal Data from any further processing). The terms of this DPA will continue to apply to such Personal Data.
8.2 For the purposes of clause 8.1, the Controller instructs the Processor to retain, restrict, archive, return, delete, anonymise and, where applicable, restore Customer Data in accordance with the Agreement, including the Ocerli Data Retention, Export and Deletion Policy referred to at clause 1.3. Unless the Controller gives a valid written instruction requiring earlier deletion or return, and subject always to Applicable Law, legal holds and clause 3.4, the Processor may retain terminated Personal Data in a restricted archive for the period stated in that Policy.
- Governing Law and Jurisdiction
9.1 This Agreement is governed by and construed in accordance with the laws of Jersey.
9.2 Any dispute arising in connection with this Agreement which the parties are unable to resolve amicably shall be subject to the exclusive jurisdiction of the courts of Jersey, subject to possible appeal to the Royal Court of Jersey.
- Counterparts and Signatures
10.1 The Effective Date of this Agreement is the date the Terms and Conditions were accepted. This Agreement shall be binding on the Parties from the Effective Date.
10.2 This Agreement may be signed in any number of counterparts, each of which constitutes a single instrument.
10.3 The Parties may sign this Agreement electronically, and each party waives the right to challenge its validity or enforceability because it may have been signed electronically.
10.4 Executed in Jersey, Channel Islands with two original copies, each Party acknowledging receipt of one.
Sub-Appendix A
- Personal Data
The personal data processed under this engagement includes employee identification data (names, dates of birth, National Insurance numbers, Social Security numbers, employee reference numbers and equivalent identifiers); contact details (residential addresses, telephone numbers and email addresses); employment details (job titles, start and end dates, employment status, working hours and location); financial details (bank account details, salary, bonuses, commissions, allowances, benefits in kind, expense reimbursements, pension contributions, student loan deductions, court orders and attachment of earnings orders); tax information (tax codes, P45 and P46 data, year-to-date earnings and deductions, and equivalent tax information in other jurisdictions); and any other personal data necessary for the proper calculation, payment and reporting of payroll.
- Special Category Data
Sickness absence records and certifications, including data relating to short-term and long-term illness; maternity, paternity, adoption and shared parental leave details; and data concerning disabilities relevant to reasonable adjustments and tax exemptions.
Condition for processing (Schedule 2 Part 2 DPJL / Article 9(2) GDPR):
The condition relied upon for this special category data is processing necessary for carrying out the obligations of the controller in the field of employment, social security and social protection law under Schedule 2 Part 2 paragraph 2 of the DPJL (Article 9(2)(b) of the UK GDPR and EU GDPR; Schedule 2 Part II of the Guernsey Law).
- Categories of Data Subjects
The data subjects are the employees and workers of the Client (and, where the engagement includes their payment, contractors paid through the payroll), together with their dependants, beneficiaries and emergency contacts where required for benefits administration or attachment of earnings orders.
- Purpose of the Processing
To enable the Controller, using the Ocerli platform and related services, to calculate, administer and report on payroll to meet its related obligations to HM Revenue & Customs, the Jersey Comptroller of Revenue or the equivalent tax authority, pension providers, courts (in respect of attachment of earnings orders), and other relevant third parties. For the avoidance of doubt, Ocerli does not make payments to employees or submit returns on behalf of the Controller, and nothing in this DPA shall be construed as Ocerli assuming any employer, payroll, tax or filing obligation of the Controller.
Sub-Appendix B
APPROVED SUB-PROCESSORS
- Amazon Web Services EMEA SARL (Republic of Ireland) — cloud hosting, backup and storage
- Microsoft Corporation (via Microsoft Ireland Operations Limited) — Microsoft 365 (email and Teams) and Azure Blob Storage (backup and replicated storage)
- Atlassian Corporation (Trello) — project management (may process client and project data depending on use)
- Zendesk Inc. (United States) — client support and support ticket management
- Tango (process documentation and support tracking)
- HubSpot Inc. (United States) — CRM and client communications
Schedule 2 – Support and service level targets
- Standard support hours. 9:00 am to 5:00 pm Jersey/UK time on business days, excluding public holidays, unless the Order Form says otherwise.
- Support channel. Support requests should be submitted through support@ocerli.com
- Severity 1 – Critical. Production Service unavailable for all or substantially all users, or a critical payroll run cannot be accessed because of a suspected Ocerli platform failure. Target initial response: 3 business hours.
- Severity 2 – High. Major function materially impaired, material calculation/reporting issue suspected, or significant user group affected. Target initial response: 1 business day.
- Severity 3 – Normal. General product question, configuration query, non-critical defect or individual user issue. Target initial response: 2 business days.
- Severity 4 – Low. How-to request, enhancement request, cosmetic issue or non-urgent query. Target initial response: 3 business days
- Enterprise Customers – Target initial response: 3 business hours.
- Resolution targets. Response targets are not resolution guarantees. Resolution depends on severity, complexity, Customer cooperation, third-party systems and whether the issue is in scope.
- Out-of-hours and expedited support. Out-of-hours, emergency, priority or expedited support is chargeable unless included in the Customer’s plan.
Schedule 3 – Ancillary Services and Rate Card
- The subscription includes access to the Services and standard support for in-scope use. It does not include professional services unless expressly included in the Order Form.
- The following are chargeable unless included in an Order Form:
- onboarding and implementation packages;
- data migration and bulk data import;
- data cleansing and data mapping;
- training and bespoke consultancy;
- custom reports, dashboards and exports (Enterprise only);
- custom development and integration work (Enterprise only);
- API support outside standard documentation;
- customer-caused error remediation;
- year-end or tax-year processing assistance beyond standard support;
- expedited, emergency or out-of-hours support;
- account reactivation or reinstatement;
- post-termination data retrieval or restoration;
- re-issuing historical documents; and
- additional one-off exports beyond self-service functionality.
- Ocerli may charge by hourly rate, daily rate, minimum charge, fixed fee, package fee, usage fee, third-party cost pass-through, or a combination.
- Ocerli may update the Rate Card on notice or by publishing an updated version. Updated rates apply to new work, not work already agreed at a fixed price.
- Work starts only after approval unless urgent action is requested by an Administrator or authorised contact.
Schedule 4 – Data export, retention and deletion
- Standard self-service exports. The Customer may export available data using standard platform tools during the Subscription Term and free access window.
- Free Access Window 30 days after termination or expiry, subject to payment of undisputed Fees and technical availability.
- Standard formats. CSV, XLSX, PDF or other standard formats Ocerli reasonably selects.
- Chargeable retrieval after free window. Any retrieval, restoration, export, reactivation or re-granting of access after the free window is chargeable.
- Statutory records. The Customer must keep its own statutory payroll, tax, employee and accounting records for applicable legal periods. Ocerli’s archived data is not the Customer’s statutory archive.
- Retention policy. The Ocerli Data Retention, Export and Deletion Policy (Retention Policy, defined at clause 2.12 and referred to at clause 23.4) sets out the default retention periods for Customer Data and other categories of data, the Restricted Archive model applying after the free access window, and the circumstances in which data will be deleted, anonymised or retained for longer. The current version of the Retention Policy is available on request and will be referenced by name and version once approved.
- Ocerli may delete or anonymise data after the retention period unless retention is required or permitted by law, dispute, audit, security, backup or legitimate business purposes.