Legal

Legal documentation, definitions and abbreviations

Terms and conditions, SLA, privacy statement and the terms and abbreviations used in B/Focused documents, in one central place.

Need support? +31 45 303 0003 Advice or a quote? +31 45 303 0232

This translation is provided for convenience. The Dutch version is legally binding.

On this page you will find legal documents, commonly used abbreviations, glossaries and additional information about B/Focused services.

This gives you one central location for practical information, definitions and documentation that regularly recur within Managed IT, Co-Managed IT, Microsoft 365, cybersecurity and other services.

Documents

Definitions

In ICT, many abbreviations and definitions are used. We also sometimes tend to use them, even though this can be unclear terminology for end users or clients. That is why all the terms and abbreviations you come across in our documents and procedures are published in one place, so you can look them up at any time and we don’t have to keep adding them to separate documents. We reserve the right to add or amend terms and abbreviations at our own discretion.

Processing agreement

A processing agreement is an agreement that sets out how personal data is processed, secured and protected when an organisation has personal data processed by an external party.

At B/Focused, a separate processing agreement is in most cases not necessary, because the agreements regarding data processing, confidentiality, security and service provision are included within our Service Level Agreement (SLA).

As a result, agreements on:

  • processing of personal data;
  • confidentiality;
  • security measures;
  • responsibilities of both parties;
  • obligation to report data breaches;
  • service provision and service agreements;

are laid down within one integral document.

This way, clients have one central document in which both the service provision and the agreements regarding data protection and confidentiality are laid down.

Data Protection Officer

A Data Protection Officer (DPO), also known as Functionaris Gegevensbescherming (FG), is responsible for overseeing the processing and protection of personal data within an organisation.

The DPO advises on privacy legislation, supports compliance with the GDPR, oversees internal processes relating to data protection and acts as a point of contact for both supervisory authorities and data subjects.

Not every organisation is required to appoint a Data Protection Officer. This depends on the nature of the organisation, the scale of data processing and the legal obligations that apply.

(ICT) production environment

In our documents and everyday language, we regularly refer to the production environment. By this we mean the ICT production environment needed to carry out your business processes: the workstations, internet access, the network and the server and cloud infrastructure you actively use to carry out digital work.

The production environment does not include any machines, production lines and the like, unless these are explicitly mentioned in our documents or included in an additional maintenance contract.

Start time

The time at which the Contractor begins restoring the Incident, after the Response Time has elapsed, as determined by the Contractor.

General Terms and Conditions

The General Terms and Conditions of B/Focused Managed ICT Services B.V. (version October 2026), found at: General Terms and Conditions (pdf).

Autotask PSA

Autotask PSA (Professional Services Automation) is essential software in which our ticketing system, project management, planning, workflow automation and other processes take place.

The Contractor’s aim is to link all connected management systems where possible to Autotask PSA as a central storage location for data, in order to deliver excellent service and reporting.

Availability

The percentage of total time, measured over a full month, during which there is no disruption.

Cyber(security) incident

A cyber(security) incident refers to any event or action that compromises the confidentiality, integrity or availability of information systems, networks or data.

Actual Availability

The number of minutes during a given period that the Service was actually available, as described in the SLA.

Data retention

With data retention we indicate how far back in time we can go to restore data. By default we apply a data retention policy of 1 year, which is sufficient for most businesses to recover data after a calamity.

In some cases a different or even unlimited data retention is required. This adjusted policy is agreed and applied in mutual consultation.

It is also important to know that legislation in the Netherlands expects you to retain data for 7 years, and for personnel data a retention obligation of 30 years applies.

Services

The services provided by B/Focused Managed ICT Services to the client.

Emergency Change Request (emergency repair)

Occasional, unforeseen emergency repair to prevent a disruption, also known as an Emergency Change Request. The Contractor has carried out a risk assessment, from which it has become clear that not carrying out the repair work poses a significant risk to the service and/or the client.

FFF

Full Fixed Fee.

Desired Availability

The level of availability of the Service pursued by the Contractor.

Helpdesk or Servicedesk

The Contractor’s service point where the Client can go with complaints, questions and/or remarks regarding the Service.

Recovery time

The time between (i) the moment the Contractor detected an Incident or the Client reported the Incident and (ii) the moment the Incident is resolved, (the Incident in) the Service is replaced, or a workaround has been created, as determined by the Contractor.

Immutable backup service

A backup service or solution that is unerasable and therefore can never be deleted by cybercriminals in the event of a cyber incident. This allows the Contractor to always carry out an infrastructure recovery in the event of a cyber incident or other disaster at the Client.

Incident

An event that leads to one or more services being unavailable.

ISO 27001

ISO 27001 is a globally recognised standard in the field of information security. The standard describes how information security should be handled in a structured way, with the aim of ensuring the confidentiality, availability and integrity of information within the organisations of both the Contractor and the Client.

Local building infrastructure

By the Client’s local building infrastructure we mean facilities that we rely on for our ICT service provision, such as correct cabling infrastructure and adequate, maintained cooling facilities. Problems in this infrastructure and any resulting downtime fall outside the normal SLA agreements, because we have no influence over them.

Malware

Malicious software used to disrupt services, hijack or steal data, or for other criminal activities that can cause damage.

Environmental conditions

By this we mean events that occur, such as a lightning strike, flooding or storm damage, over which we have no influence.

Subcontractors

Companies that supply hardware, software and/or services to parties.

Maintenance

Carrying out repairs, taking precautionary measures and regular checks of the Services, as well as planned maintenance.

Support

Providing verbal (telephone) and written (including email) advice regarding the use and operation of the Service.

Agreement

An agreement concluded between the Contractor and the Client regarding the provision of a service on the platform of one of B/Focused ICT Services’ subcontractors.

PFF

Partial Fixed Fee.

Problem

One or more incidents for which the solution is not known.

Problem coordinator

The point of contact for ongoing problems, recorded in the ticket.

Response time

The time between (i) the moment the Client reported an Incident and (ii) the moment the Contractor sends the Client confirmation of receipt of the report, as determined by the Contractor.

Also used as: the time between a fault report and the first contact with the Client about the progress of resolving the fault.

Site, website B/Focused Managed ICT Services

The website: www.b-focused.eu.

Spam

Collective term for unwanted emails.

Ticketing system

The software used by B/Focused Managed ICT Services (Autotask PSA) in which all client reports, RMM software and AI processes used are recorded.

Change request

A change to one of the services or the infrastructure.

Virus

A form of malware that can embed itself in software.

Working day, office hours and operational hours B/Focused Managed ICT Services

From 8:00 to 17:30 Monday to Friday, with the exception of recognised and official public holidays in the Netherlands.

Workaround

A (temporary) solution used to reduce or resolve the impact of an incident or problem for which no full solution exists.

Workflows

Process automations that we can apply to a ticket, AI or RMM event.

Abbreviations

AISP

All-in Seat Price.

HaaS (Hardware as a Service)

Hardware as a Service (abbreviated HaaS) or Device as a Service (abbreviated DaaS) is a service in which you use hardware for a fixed price per month. This can be, for example, a laptop, tablet, smartphone or PC.

In addition to the use, various services are also included in the price via our all-you-can-ICT subscriptions.

AI (Artificial Intelligence)

Artificial Intelligence is a technology that B/Focused Managed ICT Services uses in its software to improve and automate management and monitoring processes.

AVG (Algemene Verordening Gegevensbescherming) or GDPR (General Data Protection Regulation)

Governments, businesses and associations must comply with the GDPR. The GDPR gives people more privacy rights. Organisations must organise their systems and processes accordingly.

This can be checked. In any case, it is important that this process is in order, so that in the event of a cyber incident you have no culpable shortcomings in your processes and cannot be held jointly and severally liable for data breaches.

CAB (Change Advisory Board)

A Change Advisory Board is a group of people responsible for assessing changes in a client’s IT environment, recorded in an email distribution list or, more strictly, in the form of a meeting led by a chairperson.

CMDB (Configuration Management Database)

CMDB stands for Configuration Management Database. For us as a service provider, this database may well be the most important part of your ICT infrastructure. A CMDB is a repository that serves as documentation and contains all relevant information about your IT environment and the components used for delivering IT services.

DAP (Dossier Afspraken en Procedures)

Dossier of Agreements and Procedures: a document relating to the way of working regarding the services and/or products to be delivered.

EDR (Endpoint Detection & Response)

Endpoint Detection & Response: software that can detect and isolate anomalies in processes based on data statistics. As a result, this software recognises cyber threats faster that are not (yet) recognised by traditional virus scanners.

HA (High Availability)

High Availability (HA) concerns ICT infrastructure with a high expected uptime. The uptime is laid down in the SLA agreement, which states what percentage of uptime the Client may expect.

The uptime percentage can be translated into days, hours or even milliseconds of downtime per year.

The higher the desired uptime and the associated high-availability infrastructure, the more exponentially the costs rise to achieve this.

IP (Internet Protocol)

IP stands for ‘Internet Protocol’: the set of rules for the arrangement of data sent via the internet or the local network. In essence, IP addresses are the identification method that makes it possible to send information between devices on a network.

KPI (Key Performance Indicator)

Key Performance Indicator. KPIs measure how far along you are in achieving a certain goal.

NIS2

The NIS2 directive (Network and Information Security) is a European directive that improves the digital and economic resilience of member states. In the Netherlands, the directive is implemented through the Cyberbeveiligingswet (Cbw). As a result, cybersecurity becomes a legal obligation for many more organisations and institutions, including SMEs.

SaaS (Software as a Service)

Software as a Service allows users to connect to and use applications in the cloud via the internet, such as Microsoft 365, online backup or online security.

SLA (Service Level Agreement)

A Service Level Agreement is an agreement between a supplier and a recipient of one or more services, in which it is made clear to both parties what can be expected from the services.

SPOC (Single Point of Contact)

Single Point of Contact: the first point of contact for all reports. This is our Servicedesk department for questions from the client and its employees, and our Managed Services department for incidents generated by our RMM software.

VoIP (Voice over IP)

VoIP stands for ‘Voice over Internet Protocol’. Other terms often used for VoIP telephony are ‘calling via the internet’ and ‘internet telephony’.

Looking for a specific explanation or document?

Our knowledge base is regularly expanded with new definitions, abbreviations and documentation. Is the information you are looking for not there? Ask your question.

Getting acquainted · which step suits your organisation?

You will be speaking with Ralph Dykstra

Founder and owner of B/Focused

A conversation of about 30 minutes in which we get to know your organisation and look at the challenges, risks and opportunities in your IT environment.

Advice or a quote? Sales
+31 45 303 0232
Need support? Service desk
+31 45 303 0003