Policies

Windows Information Protection Terms of Use

This device is subject to Windows Information Protection (WIP) policies managed by Daffodil IT on behalf of your company as part of your support & maintenance contract, which are in place to protect sensitive business data and reduce the risk of accidental data leakage.

This device uses WIP to separate work and personal data. Company data is encrypted and may only be accessed by approved apps.

You agree to use company data only within approved apps and services. Attempting to transfer work content to unapproved or personal apps (e.g., personal email or social media) may be blocked or audited.

Devices enrolled in Intune may be monitored for compliance, including app usage, encryption status, and policy adherence. No personal data outside the work container is accessed or reviewed.

In the event of device loss or theft, WIP allows for remote wipe of company data only. You agree to notify Daffodil IT on behalf of your company immediately if the device is lost or compromised.

Violations of these terms may result in restricted access to company data or escalation to company leadership or IT security.

For client-owned devices, WIP applies only to work data associated with services delivered by Daffodil IT on behalf of your company. No personal or third-party data will be accessed or modified.

These terms may be updated from time to time. You will be notified of any material changes and continued use of the device indicates your agreement to the updated terms.

By continuing to use this device, you acknowledge and accept the above Windows Information Protection Terms of Use. If you do not accept, please contact support@daffodil-it.co.uk and relevant, nominated persons at your company for alternative arrangements.

Windows Information Protection Compliance Statement

Purpose

To mitigate the risk of data leakage on Windows-based endpoints, Daffodil IT implements Windows Information Protection (WIP) policies via Microsoft Intune for applicable devices. This ensures business data is isolated, encrypted, and controllable, even when devices are used for personal tasks.

Scope

This policy applies to:

  • All corporate-owned and BYOD Windows 10/11 devices enrolled in Intune.
  • All users with access to Microsoft 365 business data.
  • Devices used by internal staff or client users operating under support contracts.

Controls Enforced

WIP is configured to:

  • Enforce data separation between corporate and personal apps.
  • Apply automatic encryption to work-related files and email attachments.
  • Restrict cut, copy, paste, and save-as actions to only approved apps.
  • Support remote selective wipe of corporate data in case of offboarding or device loss.

User Consent & Awareness

  • All users are required to review and accept the Windows Information Protection Terms of Use.
  • Users are made aware that personal apps will not have access to corporate data, and vice versa.
  • Users understand that corporate data is monitored and protected, while personal data is not accessed.

Exceptions

  • Devices that are corporate-owned and fully managed may operate without WIP.

Compliance & Audit

  • WIP policy configuration is reviewed quarterly or in response to material changes.
  • Compliance reports are generated through Microsoft Intune.
  • Violations are escalated to the IT Security Lead and may result in access suspension or disciplinary measures.

All client data accessed via Daffodil systems is protected using Microsoft Intune’s Windows Information Protection, which enforces encryption, data access control, and selective wipe capabilities. This is part of our ongoing commitment to cyber hygiene and compliance with best practices under frameworks such as Cyber Essentials and GDPR.

  • Microsoft Defender for Endpoint, BitLocker, Conditional Access, and Data Loss Prevention (DLP) are in place.
  • No personal app use is permitted on the device.
  • A risk assessment has been documented and approved.