futr
Procurement pack

The answers before you have to ask for them.

The creative conversation goes well, and then it meets legal, finance and IT. This page is what they ask for, published in advance — entity and contracting, intellectual property, data protection, security posture, accessibility and continuity.

Print this page for your supplier file. Nothing here is asserted unless it has been confirmed; where something is still outstanding it says so, along with what is needed. The binding documents are our Terms & Conditions and Privacy Policy — where this summary and those differ, those govern.

How to read this

6 items are marked To confirm. They are administrative facts — registration numbers, insurance schedules, a jurisdiction clause — that belong to the company record rather than to a web page, and we would rather show the gap than fill it with something plausible. Ask and they are supplied same-day, under NDA if you need them to be.

Supplier identity
Legal entityFUTR Technology Group (Pty) Ltd
Trading asFUTR Agency
Company registration number2023/534929/07
Country of incorporationRepublic of South Africa
Trading since2016
Entity registered2023
Director and office bearerTyler Brown
Address for legal service158 Jan Smuts Avenue, Rosebank, Johannesburg, 2196, South AfricaNominated for receipt of legal documents unless a project agreement states another address.
General contactinfo@futragency.com · +27 71 604 3335
Markets servedWorldwide
Professional or accreditation bodyNone claimedStated plainly. Any membership relevant to a specific engagement is named in the proposal.
VAT registration numberTo confirmIf VAT registered, the number. If not, the page should say “not VAT registered” — either answer is fine, silence is not.
B-BBEE statusTo confirmLevel and certificate or sworn affidavit. Asked for by South African clients and by multinationals with SA operations.
Contracting and commercial

We contract in whatever form your procurement function requires. Where you have a standard agreement we work to it; where you do not, we supply ours.

Contracting modelMaster services agreement with a statement of work per engagementScope, deliverables, acceptance criteria and payment schedule live in the SOW, so a change of scope is a new SOW rather than a renegotiated contract.
Pricing modelFixed price against a defined scope; retained monthly for ongoing workWe do not price open-ended time and materials for delivery work — it puts the risk of our own estimating error on you.
Quoting currenciesZAR, GBP, EUR, USD
Change controlWritten variation to the SOW, priced before work begins
Governing lawSouth African lawSubject to mandatory consumer jurisdiction, the parties consent to the jurisdiction of the courts of South Africa.
Dispute routeComplaint to info@futragency.com, then confidential mediation in Johannesburg before litigationSenior representatives attempt resolution in good faith within 10 Business Days first.
Quotation validity14 calendar days unless the quotation states otherwise
Payment termsDue on the date stated on the invoice, or within 7 calendar days if no date is statedInvoice disputes must be specific and raised within 5 Business Days; undisputed amounts remain payable.
Late paymentPrime lending rate of our principal South African bank plus 5% per year, calculated daily and capped at the maximum lawful rate
Revision rounds includedTwo per expressly reviewable milestone, unless the statement of work says otherwise
Liability capFees paid for the specific services in the six months before the event, or total project fees if the project ran under six monthsDoes not apply to liability that cannot lawfully be limited, or to fraud or wilful misconduct.
Non-solicitation12 months after the project ends; 20% of first-year gross remuneration if breachedDoes not restrict hiring through a genuinely general public recruitment process.
Banking and remittance detailsSupplied on your supplier onboarding form, never publishedDeliberately absent from this page. Published bank details are how invoice-redirection fraud starts.
Intellectual property

Each party keeps what it already owned. You grant us a licence to use your materials as needed to do the work; nothing about your brand, content or data becomes ours.

Subject to full and cleared payment of everything due on the project, we assign or license the final bespoke deliverables to you to the extent set out in the statement of work. That last phrase matters and we would rather draw attention to it than let it be discovered later: the scope of the transfer is defined per engagement, so if you need outright assignment of specific items — source code, design files, a name — say so during contracting and it is written into the statement of work. Before full payment you hold a revocable licence to review the work only.

What stays with us by default: our pre-existing and reusable tools, methods, code modules, libraries, design systems and automation components. Where those are embedded in something you have paid for, you get a perpetual, non-exclusive, non-transferable licence to use them as part of that deliverable. Concepts not selected, drafts and working production files also stay with us unless the statement of work transfers a named item.

Third-party and open-source materials — typefaces, stock, plugins — remain under their own licences, and any ongoing fees are yours. We identify those before they are used rather than after.

On domains, hosting and platform accounts, you nominate the legal owner. We will administer them for convenience, but we do not become the beneficial owner and you should not want us to be. Renewals, credential custody and independent backups sit with the account owner.

We may show your name, logo and publicly launched work in our portfolio and pitches, without disclosing confidential performance data. A confidentiality restriction agreed in writing before launch overrides that, which is the normal arrangement for marine and other sensitive clients.

Data protection

For personal data belonging to your customers, you are the controller and we act as processor on your documented instructions. For the contact details of your own staff working with us, we are controller for the limited purpose of running the engagement.

Applicable regimesPOPIA (South Africa); GDPR and UK GDPR where you or your customers are in scope
Data processing agreementA data-processing schedule is used whenever we handle your customer, lead, employee or special personal information — signed before any personal data is shared
Information OfficerTyler Brown, registered with the Information Regulator (South Africa)
RegulatorInformation Regulator (South Africa) — inforegulator.org.za
TransfersProcessing takes place in South Africa and in the regions of the subprocessors listed belowFor EU and UK clients this is a third-country transfer and is covered by the standard contractual clauses in the DPA.
RetentionUnsuccessful enquiries up to 24 months; project and client records generally five years after the engagement; recruitment records up to 12 months; statutory accounting records for the legally required periodFull schedule in the Privacy Policy. Backup deletion runs on a rolling cycle rather than immediately.
AccessLeast privilege. Named individuals only, removed at the end of an engagement.
Breach notificationYou are notified without undue delay and in any case within 72 hours of us becoming aware
Subprocessors

Third parties that may process personal data on your behalf as part of delivery. You are notified before any addition to this list.

SubprocessorPurposeRegion
VercelApplication hosting and content deliveryGlobal edge, primary region configurable
GooglePageSpeed Insights measurement; analytics where enabledGlobal

Project-specific subprocessors — a payment gateway, an email platform, a CRM — are the ones you already use, and are named in the statement of work rather than assumed here.

Security posture

We are a small senior team, not an enterprise with a security department. What follows is what we actually do, stated plainly, rather than a policy library written for the questionnaire.

AuthenticationMulti-factor on every account with access to client systems
Credential handlingManaged password vault; credentials never sent by email or chat
TransportHTTPS enforced, HSTS enabled, modern TLS only
DependenciesAutomated vulnerability alerts on repositories, patched on a defined cadence
BackupsClient production systems backed up on a schedule agreed in the SOW, with restores tested rather than assumed
Environment separationDevelopment, staging and production separated; no production data in development
OffboardingAccess revoked at the end of an engagement, confirmed in writing
Incident responseNamed contact, defined escalation path, written post-incident reportWe have run real recoveries, including a WordPress compromise documented in our technical writing.
Penetration testingTo confirmState the position honestly: whether independent testing is commissioned per project, offered as an option, or not currently performed.
ISO 27001 or SOC 2Not certifiedStated plainly rather than omitted. If certification is a hard requirement for your procurement process, we are not the right supplier and would rather you knew now.
Accessibility

We target WCAG 2.2 Level AA on core journeys as standard, not as an upsell. Automated tooling runs in the build; the remainder is a manual pass with a keyboard and a screen reader, because automated testing catches roughly a third of the criteria and the third it catches is the easy third.

Our own site publishes its accessibility position on its specification page, including the parts not yet measured. If you require a formal conformance report or a VPAT for a specific deliverable, that is a defined piece of work we will quote rather than a claim we will assert.

Business continuity and key-person risk

The honest position: we are a small team, and concentration of knowledge in a small number of people is the principal risk of engaging us. We would rather set that out here than have it discovered during a due-diligence call.

What we do about it. Two technical owners hold overlapping knowledge of every engagement, so no project has a single point of understanding. Decisions are recorded in a written log rather than held in someone’s memory. Everything is built on mainstream, widely supported technology — Next.js, React, WordPress, Shopify, Supabase — specifically so that another competent team could take it over. Domains, hosting and platform accounts are registered in your name from the start, so the assets are not stranded with us at any point. And a documented handover is a defined deliverable in the statement of work rather than a favour at the end of one.

One thing to be clear about, because it is in our terms and buyers should see it here rather than find it in clause 21: on termination we release paid-for final deliverables, and we are not obliged to release unpaid work, working files or credentials to systems we own. That is a payment-protection mechanism, not a hostage mechanism — it is why the handover deliverable and the ownership-of-accounts arrangement above matter, and why they are agreed at the start.

What we do not have: a bench deep enough to absorb both owners being unavailable simultaneously. If your risk assessment requires that, a larger supplier is the correct answer and we will say so during procurement rather than after.

Insurance
Professional indemnityTo confirmInsurer, policy number, limit of indemnity and renewal date, from the schedule.
Public liabilityTo confirmInsurer, policy number and limit, if held.
Cyber liabilityTo confirmIncreasingly asked for by enterprise buyers. Confirm whether held, and at what limit.

Need this on your own form?

Most procurement teams have a supplier questionnaire they would rather we completed than read a page. Send it over — we will complete it and return it, and if there is a question we have to answer “no” to, the answer will be no.

Four ways in

However you prefer.

Marine and yacht enquiries go straight to a named senior contact, and nothing is published without permission.