Last Updated: September 2026
These Standard Terms and Conditions of Service (“Terms”) apply to services supplied by E Price and N.B Price, a partnership, ABN 18 588 788 695, trading as Digital Discovery Group (“Digital Discovery Group”, “DDG”, “we”, “us” or “our”).
These Terms apply to any person or organisation engaging DDG for information technology, networking, hardware, software, cyber security, artificial intelligence, consulting, managed services, support or related technical services (“Client”, “you” or “your”).
1. When These Terms Apply
These Terms apply whenever a Client requests, authorises or receives Services from DDG and there is no separately executed Master Services Agreement (“MSA”) governing those Services.
You accept these Terms when you accept a DDG quotation or proposal, submit or authorise a support ticket, request work by email, telephone or another agreed communication method, provide DDG with access to systems or equipment, instruct DDG to commence work, or otherwise receive Services from DDG.
Where DDG and the Client have signed an MSA, the MSA applies in preference to these Terms to the extent of any inconsistency.
A quotation, Statement of Work, Service Schedule or other written proposal may contain additional or specific terms. Where there is a conflict, the specific commercial terms in the accepted quotation or Statement of Work apply to that engagement, and these Terms otherwise continue to apply.
2. Services
DDG may provide IT support, end-user support, remote support, onsite support, endpoint administration, Windows and macOS support, server administration, networking, wireless networking, firewalls, VPNs, switches, routers, system configuration, troubleshooting, hardware installation, software installation, software licensing assistance, cloud services, cyber security, artificial intelligence solutions, automation, endpoint security, vulnerability remediation, technical consulting, project services and related information technology services.
The precise scope of an engagement is limited to the work reasonably described in the Client’s request, accepted quotation, ticket, proposal or Statement of Work.
Having access to a system, administrative credentials, visibility of a device, or having previously assisted with a system does not make DDG responsible for the ongoing operation, security, licensing, availability, capacity, patching, backup or maintenance of that system unless DDG has expressly agreed to provide those Services.
3. Support Tickets and Service Requests
DDG may record Client requests as support tickets.
A support ticket may contain the Client’s request, technician notes, communications, time records, technical findings, work performed, recommendations, parts or software used and the status or resolution of the issue.
The person submitting or approving a ticket warrants that they are authorised by the Client to request the relevant work.
A ticket authorises DDG to undertake reasonable diagnostic, support and remediation activities falling within the scope of the request.
Where DDG identifies work that is materially outside the original request, involves substantial additional cost or represents a separate project, DDG may seek additional approval before proceeding.
Email, support-ticket approval or another recorded written communication is sufficient approval.
DDG may undertake reasonable emergency action without obtaining prior approval where immediate action is reasonably required to contain a security incident, prevent material data loss, restore a critical service, prevent further system damage or address an immediate material security risk.
4. Contact Reports
DDG may provide a Contact Report following onsite attendance, significant support work, project activities or other technical engagements.
A Contact Report may record the date of attendance, location, Client contact, support-ticket number, work performed, systems or equipment affected, technical observations, actions taken, recommendations, unresolved issues and billable time.
Contact Reports are intended to provide the Client with a clear record of the Services performed.
A Contact Report is not a warranty that every defect, configuration issue, security weakness or other problem within the Client’s environment has been identified.
Unless expressly stated otherwise, reports and findings represent the condition of the relevant systems at the time the work was undertaken.
5. Time Recording and Billing
DDG may charge Services on an hourly, fixed-price, project, per-device, recurring-service, subscription or other agreed basis.
Applicable pricing will ordinarily be stated in a quotation, proposal, Service Schedule or other written communication.
Where Services are charged by time, DDG may record billable professional time in 6-minute increments unless otherwise agreed.
Billable time may include reasonable time spent diagnosing, researching, configuring, troubleshooting, communicating about, documenting and resolving the Client’s request.
Where applicable, onsite attendance, travel, after-hours work, specialist services, hardware, software, licensing, subscriptions and third-party charges may be charged separately.
Support tickets, technician records and Contact Reports may be used as supporting records for invoicing.
6. Quotations and Cost Control
Quotations are based on the information reasonably available to DDG at the time they are prepared.
Technical work can reveal additional problems that could not reasonably have been identified before work commenced.
Where a quotation states a fixed price or not-to-exceed amount, DDG will not knowingly materially exceed that amount without Client approval, except where emergency action is authorised under these Terms.
Where an estimate is likely to be materially exceeded, DDG will make reasonable efforts to notify the Client before undertaking significant additional work.
Hardware, software and third-party supplier pricing may change before an order is accepted by the supplier.
7. Invoices and Payment
Unless otherwise agreed in writing, invoices are payable within 14 days of the invoice date.
The Client must raise any good-faith invoice dispute within 7 days of receiving the invoice and identify the amount disputed and the reason for the dispute.
Any undisputed amount remains payable by the due date.
Where an invoice remains materially overdue, DDG may suspend non-critical Services after providing reasonable written notice.
Where lawful, overdue amounts may attract interest at the Reserve Bank of Australia cash rate plus 4% per annum, calculated from the due date.
DDG will not intentionally destroy or withhold Client-owned credentials or Client-owned data solely as leverage in a payment dispute.
8. Client Responsibilities
The Client must provide DDG with reasonable access, information, equipment, credentials and assistance required to perform the Services.
The Client must provide information that is accurate and complete to the best of its knowledge, notify DDG of relevant known faults or risks, promptly report suspected security incidents, maintain appropriate licences and support entitlements, maintain suitable physical security, and ensure that people requesting Services on its behalf are properly authorised.
The Client must tell DDG where a system is unusually sensitive, business-critical, subject to specific regulatory obligations or requires special change-control procedures before DDG commences relevant work.
9. Hardware and Software Licensing
The Client is responsible for maintaining valid and sufficient licences, subscriptions, warranties, support entitlements and usage rights for hardware, software and services where those rights are required.
DDG is not required to install, activate, configure or support software that DDG reasonably believes is unlicensed, pirated, improperly activated, being used contrary to applicable licence conditions or otherwise unlawful.
DDG may assist with licensing administration but does not assume responsibility for pre-existing or historical licensing deficiencies unless expressly agreed.
Where DDG identifies an apparent licensing deficiency, the Client must obtain appropriate licensing or provide reasonable evidence of its entitlement.
10. Unsupported and End-of-Life Systems
DDG may designate a product, device, operating system, application or service as unsupported where vendor support has ended, security updates are unavailable, hardware has reached end-of-life, required replacement parts are unavailable, the system is materially obsolete, or continued operation creates an unreasonable security or reliability risk.
DDG may provide reasonable-efforts assistance for unsupported technology but does not guarantee that faults can be resolved.
Where DDG recommends replacement, upgrading or remediation and the Client elects not to proceed, DDG may record the issue as an Accepted Client Risk.
11. Backups, Data Loss and System Configuration
The Client is responsible for maintaining appropriate, current and recoverable backups of important business data unless DDG has expressly agreed in writing to provide managed backup or disaster-recovery Services.
Before material changes to a production system, DDG may request that the Client confirm an appropriate backup or recovery mechanism exists.
No backup, storage or disaster-recovery system can guarantee successful recovery in every circumstance.
Pre-existing Systems and Misconfiguration
DDG is not responsible for loss, corruption, unavailability or damage arising from pre-existing system defects, undocumented configurations, incorrect configurations existing before DDG’s involvement, unsupported software or hardware, latent hardware failure, storage-media failure, software corruption, malware, cyber attack, third-party changes, vendor failures, previous work performed by another provider, Client or user changes, or any other condition that DDG did not create and was not contracted to remediate.
DDG is also not responsible merely because a fault, configuration issue or vulnerability existed in a system to which DDG had access.
Changes Made During Support
Technical support and system administration inherently involve making changes to hardware, software and configuration, and those changes carry risks including interruption, incompatibility and data loss.
DDG will exercise reasonable care and skill when performing authorised work.
To the maximum extent permitted by law, DDG is not responsible for data loss or loss of availability that would reasonably have been prevented by a current and recoverable backup which the Client was responsible for maintaining.
DDG is not responsible for consequential loss resulting from an underlying system failure, pre-existing misconfiguration, third-party system failure or data corruption except to the extent that the loss is directly caused by DDG’s failure to exercise the care and skill required by law.
Nothing in these Terms excludes any liability or consumer guarantee that cannot lawfully be excluded.
12. Change Management
Where DDG knowingly proposes a change carrying a material risk of disruption or data loss, DDG will, where reasonably practicable, consider the proposed outcome, backup or recovery position, appropriate timing and rollback options.
Routine administration, updates, security remediation and support activities within an authorised scope do not require separate approval for every individual technical action.
Emergency changes may be undertaken where reasonably necessary to protect systems, data, security or business operations.
13. Remote Access and Management Tools
DDG may use remote-support, monitoring, endpoint-management and administration tools to provide Services.
Where the Client requests or authorises remote support, the Client authorises DDG to remotely access the relevant system to the extent reasonably necessary to perform the requested Services.
Where ongoing endpoint-management Services are separately agreed, DDG may install and operate appropriate management agents, including ManageEngine Endpoint Central Enterprise or replacement or supplementary management tools.
Remote-administration technology carries inherent risks including compromise of administrator credentials, vulnerabilities in remote-management software, inadvertent access to confidential information, unintended system changes and increased impact if a privileged management platform is compromised.
DDG will use reasonable security controls appropriate to the Services provided.
Remote access is intended for legitimate IT administration, troubleshooting, maintenance, security and support and does not, by itself, authorise DDG to conduct unrelated or covert employee surveillance.
The Client is responsible for ensuring that it has the legal authority to permit remote access and for providing any employee or user notices required by applicable law.
14. Authority to Access Systems
The Client warrants that it owns, controls or otherwise has sufficient authority over every system, machine, account, network or dataset it instructs DDG to access.
DDG is entitled to rely on an instruction from an authorised Client representative as confirmation of that authority.
DDG may refuse or suspend work where it reasonably believes the necessary authority is absent, unclear or withdrawn.
15. Cyber Security
Cyber security is a shared responsibility.
DDG may provide cyber security services including advisory, hardening, endpoint protection, vulnerability remediation, monitoring, incident response assistance, security assessments, secure configuration, identity and access management, log review and related specialist services where agreed.
No security service, product or control can guarantee prevention or detection of all malware, ransomware, phishing, social engineering, credential theft, software vulnerabilities, insider threats, unauthorised access, business email compromise, third-party compromise, zero-day vulnerabilities or cyber attacks.
The Client remains responsible for employee conduct, user credential handling, physical security, internal policies, business continuity planning, approving recommended expenditure, maintaining required licences and subscriptions, promptly reporting suspected incidents and complying with its own legal and regulatory obligations.
Where DDG identifies and documents a material security risk and the Client elects not to remediate it, DDG may record that risk as an Accepted Client Risk.
DDG is not responsible for loss to the extent caused by the Client’s failure to implement a documented security recommendation, failure to maintain security tooling, disabling or bypassing security controls, using unsupported systems, sharing credentials insecurely, failing to notify DDG of a known incident or permitting unauthorised changes.
Security assessments and reports are point-in-time assessments based on the systems, evidence and information reasonably available at the time and are not guarantees of ongoing security or compliance.
Where specialist cyber security services are required, DDG may engage suitably qualified subcontractors or specialist service providers in accordance with these Terms.
16. Artificial Intelligence and Automated Services
DDG may use, configure, integrate or recommend artificial intelligence, machine learning, automation, generative AI, AI agents, language models, decision-support systems and related technologies (“AI Services”) where appropriate to the engagement.
AI Services may be provided directly by DDG or may rely on third-party platforms, APIs, cloud services, models or vendors.
AI Output Limitations
AI-generated output may be incomplete, inaccurate, outdated, misleading, non-unique or unsuitable for a particular purpose.
The Client must not treat AI-generated output as a substitute for professional legal, financial, medical, regulatory, compliance or other specialist advice unless it has been independently reviewed by a suitably qualified person.
Where AI output is used in business-critical, customer-facing, financial, legal, security, operational or regulatory decisions, the Client is responsible for implementing appropriate human review and approval.
Client Data and AI Systems
The Client must not knowingly provide DDG with personal information, confidential information, trade secrets, regulated information or third-party data for use in an AI Service unless the Client has authority to do so.
Where DDG configures an AI Service to process Client information, the relevant quotation, proposal or scope may identify applicable data-handling, hosting, vendor and retention arrangements.
Third-party AI providers may process information under their own terms, privacy policies, data-location arrangements and service conditions.
DDG does not guarantee that a third-party AI provider will retain a particular model, feature, pricing structure, output quality, data location or availability.
AI Security and Prompt Risks
AI systems may be exposed to risks including prompt injection, data leakage, hallucination, insecure integrations, excessive permissions, malicious input, model or vendor vulnerabilities, inaccurate automation and unintended actions.
Where DDG deploys AI agents or automated workflows, the Client acknowledges that automation may act on information without continuous human supervision and may produce unintended results if instructions, permissions, integrations or source data are incorrect.
The Client must ensure that appropriate access controls, approval processes and human oversight are maintained for AI Services that can access systems, send communications, modify records, initiate transactions or perform other consequential actions.
AI Intellectual Property and Third-Party Rights
DDG does not warrant that AI-generated content is unique or that equivalent or similar output will not be generated for another person.
The Client is responsible for reviewing AI-generated content before publication or commercial use where copyright, trademark, confidentiality, privacy, defamation, licensing or other third-party rights may be relevant.
AI Service Changes
AI platforms and models may change rapidly.
DDG may reasonably replace or modify an AI platform, model, integration or provider where required by security, availability, pricing, functionality, vendor changes or service quality, provided any material change to an agreed Client-facing Service is communicated where reasonably practicable.
17. Subcontractors and Specialist Providers
DDG may use suitably qualified employees, contractors, consultants and specialist service providers to perform Services.
This may include specialist cyber security, networking, firewall, infrastructure, cloud, telecommunications, digital forensics, incident response, artificial intelligence, data engineering, automation and advanced engineering services.
Unless otherwise agreed, the Client’s contractual relationship remains with DDG.
DDG may provide an authorised specialist with access reasonably necessary to perform the relevant work and will require persons accessing Client confidential information to be subject to appropriate confidentiality obligations.
Separately chargeable specialist work will ordinarily be quoted or approved before commencement unless emergency work has been authorised.
18. Third-Party Products and Services
DDG may recommend, procure, configure or support products and services supplied by third parties.
Third-party products remain subject to the relevant supplier’s licence terms, warranty conditions, support arrangements, pricing, privacy terms and availability.
DDG is not responsible for outages, vulnerabilities, defects, price changes, discontinuation, data-handling practices or failures originating within a third-party product or service except to the extent caused by DDG’s own negligent configuration or administration.
19. Hardware and Procurement
DDG may procure hardware, software, subscriptions and licences for the Client.
Supplier pricing and availability may change before an order is accepted.
Special-order, configured, activated or licensed products may be non-refundable subject to applicable law.
Unless otherwise agreed, title to hardware supplied by DDG passes after payment in full.
20. Confidentiality
DDG and the Client must keep each other’s confidential information confidential and use that information only for legitimate purposes connected with the Services.
Confidential information includes passwords and credentials, network configurations, security information, customer information, employee information, financial information, technical information and other commercially sensitive material.
The obligation does not apply to information that is lawfully public, independently developed, lawfully obtained from another source or required to be disclosed by law.
21. Privacy and Data Security
DDG will take reasonable technical and organisational measures to protect Client information in DDG’s custody or control.
DDG will access Client information only to the extent reasonably necessary to provide the Services.
Where DDG becomes aware of material unauthorised access to, disclosure of or loss of Client information in DDG’s custody or control, DDG will notify the Client without unreasonable delay.
Each party remains responsible for its own obligations under applicable privacy and workplace laws.
22. Intellectual Property
The Client retains ownership of Client data.
DDG retains ownership of its pre-existing and reusable intellectual property, including methodologies, scripts, templates, automation, tooling, management systems, deployment methods, documentation frameworks, prompts, workflows, technical methods and know-how.
Following full payment, the Client may use Client-specific documentation and deliverables created for it for its internal business purposes, subject to applicable third-party licence terms.
23. Reports and Recommendations
Technical reports, Contact Reports, assessments and recommendations are based on the information and systems reasonably available to DDG at the relevant time.
Technology environments change continuously.
A report or assessment is a point-in-time finding and is not a continuing warranty of system security, availability, compliance or reliability.
24. Limitation of Liability
Nothing in these Terms excludes, restricts or modifies any liability, guarantee, right or remedy that cannot lawfully be excluded.
Subject to those rights, neither party is liable to the other for indirect or consequential loss, including loss of anticipated profit, revenue, savings, goodwill or business opportunity.
DDG’s liability will be reduced proportionately to the extent a loss is caused or contributed to by the Client, a Client employee or user, another IT provider, unsupported technology, inaccurate or incomplete information, licensing deficiencies, a third-party product or service, failure of a Client-managed backup, interference with DDG management tools or failure to follow a documented material recommendation.
To the maximum extent permitted by law, DDG’s total aggregate liability arising from Services governed by these Terms is limited to the fees paid to DDG for the Services giving rise to the claim during the preceding 12 months.
This limitation does not apply where liability cannot lawfully be limited.
25. Suspension and Termination
Either party may stop an individual engagement subject to payment for work already performed and non-cancellable commitments already incurred.
DDG may suspend or decline Services where amounts remain materially overdue, continuing the work would be unlawful, the Client lacks authority to permit the work, a serious safety or security issue exists, or the Client requires DDG to work with unlawfully licensed systems.
On completion or termination, reasonable handover or transition assistance may be separately billable.
26. Cost Reduction and Technology Optimisation
Where appropriate, DDG may review the Client’s environment for opportunities to reduce unnecessary technology expenditure and operational complexity.
This may include reviewing software subscriptions, duplicated licences, hardware lifecycle, vendor costs, recurring support issues, unused systems, automation opportunities and opportunities to standardise technology.
Any projected saving, cost avoidance or return on investment is an estimate based on available information and is not guaranteed.
No material expenditure, migration, cancellation or system change arising from such a review will be undertaken without appropriate Client approval.
27. Disputes
Before commencing legal proceedings, the parties should attempt in good faith to resolve the dispute between senior representatives.
Nothing prevents either party seeking urgent legal relief where necessary.
28. General
These Terms are governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of its courts.
Changes to a specific engagement may be agreed in writing, including by email.
If any provision of these Terms is unenforceable, it will be read down or severed to the minimum extent necessary without affecting the remainder.
Electronic communications and electronic acceptance may be relied upon as evidence of instructions, approvals and acceptance of Services.
29. Clients With a Master Services Agreement
Where DDG and the Client have entered into a separately executed Master Services Agreement, that MSA governs the relationship.
These website Terms may supplement the MSA only where they do not conflict with it.
Where no MSA exists, these Terms form the standard terms governing all Services supplied by Digital Discovery Group to the Client.
Website Acceptance Wording
By requesting or authorising services from Digital Discovery Group, you agree to our Standard Terms and Conditions of Service. If your organisation has a separately signed Master Services Agreement with Digital Discovery Group, that agreement applies in preference to the Standard Terms where there is any inconsistency.
Legal Review Notice
These Terms are a commercial draft and are not legal advice. Digital Discovery Group should obtain appropriate Australian legal review before publication, particularly in relation to limitation of liability, Australian Consumer Law, privacy, cyber security, artificial intelligence, remote access, workplace surveillance, data loss and third-party services.
