Terms of Service
Effective date: 6 April 2026 · Last updated: 6 April 2026
These Terms of Service (“Terms”) govern your use of the RotationGrid platform (“Service”) provided by RotationGrid, a trading name of Ben Sharif Limited, a company registered in England and Wales (company number 17060795) with its registered office at 32 Denison Way, Cardiff, CF5 4SF (“we”, “us”, “our”). By creating an account or using the Service, you agree to these Terms.
1. Definitions
- “Customer” means the NHS organisation, deanery, or other entity that subscribes to the Service.
- “User” means any individual authorised by a Customer to access the Service.
- “Customer Data” means all data uploaded to or created within the Service by a Customer or its Users, including trainee records, placement data, ARCP events, and configuration.
- “Platform” means the RotationGrid web application and associated APIs.
2. Account and access
You must provide accurate information when creating an account. You are responsible for maintaining the confidentiality of your login credentials and for all activity under your account. Notify us immediately at [email protected] if you suspect unauthorised access.
We may suspend or terminate accounts that violate these Terms, pose a security risk, or remain inactive for more than 12 months.
3. Licence and permitted use
We grant you a limited, non-exclusive, non-transferable licence to access and use the Service for the purpose of managing postgraduate medical training programmes. You may not:
- Sublicense, resell, or redistribute access to the Service
- Reverse-engineer, decompile, or attempt to extract source code
- Use the Service for any unlawful purpose or in violation of applicable regulations
- Attempt to circumvent access controls, rate limits, or security measures
- Upload malicious code, perform automated scraping, or overload the Service
4. Data ownership and processing
Customer Data belongs to the Customer. We do not claim ownership of any data you enter into the Service. We process Customer Data solely to provide and improve the Service, in accordance with our Privacy Policy and any Data Processing Agreement in place.
You are responsible for ensuring that your use of the Service complies with applicable data protection laws, including UK GDPR and the Data Protection Act 2018. Where trainee data is processed, the Customer is the data controller and RotationGrid is the data processor.
5. Data Processing Agreement
Customers processing personal data through the Service should enter into a Data Processing Agreement (DPA) with us, as required by Article 28 UK GDPR. We provide a standard DPA on request. Contact [email protected] to arrange this.
6. Service availability and support
We aim to maintain high availability of the Service but do not guarantee uninterrupted access. Planned maintenance will be communicated in advance where possible.
We provide support via email at [email protected] during UK business hours (Monday–Friday, 09:00–17:00 GMT/BST). We aim to respond to support requests within 1 working day.
7. Security
We implement appropriate technical and organisational measures to protect the Service and Customer Data, including encryption, access controls, audit logging, and regular backups. Details are set out in our Privacy Policy.
You are responsible for the security of your own devices, network, and credentials when accessing the Service.
8. Backups and data recovery
We perform automated daily backups of all Customer Data. Backups are encrypted and stored in the UK (AWS S3, eu-west-2). In the event of data loss, we will make reasonable efforts to restore data from the most recent backup.
9. Intellectual property
The Service, including its design, code, features, documentation, and branding, is the intellectual property of RotationGrid. These Terms do not transfer any intellectual property rights to you.
Feedback, feature requests, and suggestions you provide may be used by us to improve the Service without obligation to you.
10. Limitation of liability
To the maximum extent permitted by law:
- Our total aggregate liability to you for any claims arising from or related to the Service shall not exceed the fees paid by you in the 12 months preceding the claim.
- We are not liable for indirect, incidental, special, consequential, or punitive damages, including loss of data, revenue, or business opportunities.
- We are not liable for losses arising from circumstances beyond our reasonable control, including third-party service outages, network failures, or force majeure events.
Nothing in these Terms excludes or limits liability for fraud, death or personal injury caused by negligence, or any other liability that cannot be excluded by law.
11. Termination
Either party may terminate the Service by providing 30 days’ written notice. Upon termination:
- We will provide a full export of Customer Data in a standard format (JSON and/or CSV) within 30 days of the termination date.
- After the export period, Customer Data will be securely deleted from our systems, including backups, within 90 days.
- Account data (email, name) will be retained for 12 months for audit and compliance purposes, then deleted.
We may terminate your access immediately if you materially breach these Terms and fail to remedy the breach within 14 days of notice.
12. Changes to these Terms
We may update these Terms from time to time. Material changes will be communicated via the platform and to registered administrators by email at least 30 days before taking effect. Continued use of the Service after the effective date constitutes acceptance of the updated Terms.
13. Governing law and disputes
These Terms are governed by the laws of England and Wales. Any disputes arising from these Terms or the Service shall be subject to the exclusive jurisdiction of the courts of England and Wales.
14. Contact
For questions about these Terms, contact us at:
- General: [email protected]
- Legal: [email protected]
- Privacy: [email protected]