Skip to main content

Help us improve the Digital Marketplace - send your feedback

RYDAL COMMUNICATIONS LTD

Curo IP Hosted Telephony

Curo IP Hosted Telephony is a secure, cloud-based unified communications platform delivering voice, video, messaging and conferencing. Designed for hybrid working, it includes call routing, voicemail, analytics and CRM integration. Hosted in UK ISO 27001-certified data centres, it’s fully managed with SLA-backed support, scalable from SME to enterprise.

Features

  • Cloud-based hosted telephony with unified communications platform integration
  • HD voice, video calling, and conferencing via softphones or handsets
  • CRM and Microsoft Teams integration with click-to-dial functionality
  • SLA-backed UK support desk and technical engineering assistance
  • Auto-attendant, call routing, voicemail-to-email, and hunt group features
  • Real-time reporting dashboard with analytics and call statistics
  • Secure call recording with configurable retention and access controls
  • Presence status indicators and internal messaging functionality
  • Mobile and desktop app for remote and hybrid working
  • Hosted in UK ISO27001-certified data centres with redundancy

Benefits

  • Enables flexible, remote working from any location or device
  • Reduces telephony costs by eliminating on-premises PBX hardware
  • Improves customer contact with intelligent call routing and analytics
  • Simplifies management with centralised admin and user control panel
  • Enhances staff productivity through presence, chat and integration tools
  • Improves uptime with resilient cloud infrastructure and failover
  • Scales easily from small teams to multi-site organisations
  • Supports business continuity with cloud-hosted disaster recovery options
  • Speeds up deployment with expert site installation and onboarding
  • Meets compliance with ISO, GDPR and Cyber Essentials certification

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at n.nania@rydal-group.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 4 0 3 5 3 1 4 2 4 6 7 3 5 5

Contact

RYDAL COMMUNICATIONS LTD Neville Nania
Telephone: 01733511116
Email: n.nania@rydal-group.co.uk

About your service

Service categories

Applications

Collaborative

  • Team collaboration

Conferencing and virtual event

  • Web Conferencing Applications
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Integrates with Microsoft Teams, CRM systems (e.g. Salesforce, HubSpot), and third-party contact centre platforms. Enhances existing collaboration and customer service tools with cloud-based telephony, call control, and analytics features. Also connects with SIP trunks and UC platforms for extended communication capabilities.
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
Service availability depends on reliable internet connectivity and sufficient bandwidth. Features may vary based on user licence type or handset model. Some call management functions are unavailable on mobile apps. Planned maintenance is performed outside core business hours with advance notice. Number porting is subject to lead times and carrier acceptance. PoE or local power is required for IP handsets. Advanced features such as call recording or analytics may require additional configuration. Service support is limited to approved devices and compatible operating systems. VPNs or firewalls must allow required VoIP ports and protocols.
System requirements
  • Stable broadband or leased line internet connection is required
  • Compatible IP handset or VoIP-enabled device is needed
  • Softphone users need headset with microphone and speakers
  • Supported operating systems: Windows, macOS, iOS, Android
  • Web access requires Chrome, Edge, or Firefox browser
  • Mobile app requires iOS 12+ or Android 9+
  • VoIP traffic must be allowed through firewalls and routers
  • Power over Ethernet (PoE) or power adaptor for handsets
  • Admin access requires secure login credentials with multi-factor authentication
  • Minimum 1Mbps per concurrent call recommended for HD voice

User support

Email or online ticketing support
Yes
Support response times
We respond to all support tickets within 1 hour during core business hours (08:00–17:00, Monday to Friday). High-priority issues (e.g. service outage) receive immediate triage and escalation. Outside these hours, emergency support is available for priority cases via our out-of-hours contact process. Standard response times may be extended during weekends and public holidays. Users receive real-time updates and can track ticket progress via our support portal.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We conduct internal testing to ensure compatibility with common screen readers and keyboard navigation. Our support portal’s chat function adheres to WCAG 2.2 AA standards, providing accessible colour contrast, focus indicators, and text scaling. Feedback is periodically gathered from users with accessibility needs for ongoing improvements.
Onsite support
Yes, at extra cost
Support levels
We provide a single-tier SLA-backed support model included as standard, covering technical, service, and account-related queries. Support is available via phone, email, and online ticketing. Working hours are Mon-Fri 8.00 am-5.00pm & exclude UK public holidays. Out of hours pricing available upon request. Response times range from 1 hour for high-priority incidents to 8 working hours for standard requests. Users can track and prioritise tickets through our portal.

All customers are assigned a named Service Delivery Manager (SDM) who acts as a technical point of contact and escalation path. For larger or more complex deployments, a Technical Account Manager (TAM) or Cloud Support Engineer may be assigned at no additional cost.

Optional premium support services — including enhanced response times, weekend cover, or onsite engineer call-outs — are available at extra cost. Charges are agreed per contract and based on the scope and SLA requirements.

We proactively monitor system performance and notify customers of any incidents or maintenance windows. Our support team is based in the UK and fully trained in delivering telecoms and unified communications services in line with ISO 9001 and ISO 27001 standards.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We provide a structured onboarding process to ensure a smooth transition to Curo IP. This includes project management, technical planning, and pre-deployment support. A dedicated Service Delivery Manager oversees onboarding and acts as the primary point of contact.

Initial setup includes system configuration, user provisioning, number porting (if applicable), and handset or softphone setup. We offer remote onboarding sessions as standard, and onsite installation is available where required (at extra cost).

Users are supported with comprehensive documentation, including quick-start guides, admin manuals, and FAQs. Online training webinars are provided to both administrators and end users during rollout. Tailored one-to-one or group training can also be arranged.

Our support team is available throughout onboarding to resolve any technical or operational queries. Access to the customer portal, support ticketing system, and user training materials is provided from day one.

We also perform system validation checks, test call routing, and confirm service readiness prior to go-live. Post-deployment reviews ensure the system is functioning as expected and users are confident in operating the service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, customers can extract their data via the secure web portal or request a formal data export through our support team. This includes call detail records (CDRs), voicemail files, call recordings (if enabled), and user configuration data.

Customers are advised to export or request their data within 30 days of contract termination. Data exports can be provided in standard formats such as CSV (for logs and CDRs) and MP3/WAV (for recordings). Secure file transfer methods are used for delivery, including encrypted downloads or SFTP.

We provide guidance and support throughout the data extraction process, including verification steps to ensure correct and authorised handover. Additional data extraction services or custom formats may be arranged upon request, subject to a charge depending on scope.

After the 30-day grace period, all remaining customer data is securely deleted in accordance with GDPR and our ISO 27001-certified data handling policy. We confirm deletion with the customer and retain logs of the process for compliance purposes.
End-of-contract process
At the end of the contract, services are scheduled for deactivation based on the agreed termination date. We provide a minimum of 30 days’ notice to coordinate the transition and ensure continuity of service. During this period, we support the customer in extracting all required data (e.g. call logs, recordings, voicemails), and provide assistance with number porting or migration to alternative providers if applicable.

Included in the contract price is access to the support team for data extraction, configuration handover, and administrative offboarding. We also provide a written summary of the termination steps and confirm when the data has been fully and securely deleted.

Optional additional-cost services at contract end may include bespoke data formatting, large-scale data transfers, onsite engineering visits, or consultancy to assist with migration planning. Charges for these services are based on the agreed rate card or scoped per requirement.

All customer data is securely deleted 30 days after service termination unless an extension is agreed in writing. Deletion is carried out in compliance with GDPR and ISO 27001 protocols, with evidence available upon request.

We aim to ensure a smooth and fully supported offboarding process to protect business continuity.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile app provides core telephony functions including calling, voicemail, chat, presence, and call history. Users can make and receive calls using their business number, access contacts, and manage basic settings. Some advanced features—such as call recording configuration, detailed analytics, and admin controls—are only available via the desktop or browser interface. The mobile interface is optimised for iOS and Android devices, ensuring ease of use on smaller screens. Push notifications and background call handling are supported for seamless communication. Mobile performance is dependent on network connectivity (Wi-Fi or 4G/5G).
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface includes a secure web portal for administrators and users, providing access to call routing, voicemail, presence, user management, and reporting. It is designed to be intuitive and user-friendly, with role-based access. Mobile and desktop apps offer a simplified interface for daily communication needs. Real-time status indicators and click-to-call functions are available. The interface meets WCAG 2.2 AA accessibility standards, supporting keyboard navigation and screen readers. Users can customise preferences, manage devices, and access help resources. The interface is regularly updated for security and usability improvements.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We conduct internal accessibility testing on our service interface to ensure compatibility with assistive technologies, including screen readers (such as NVDA and JAWS), keyboard-only navigation, and high-contrast modes. Testing is done on both the web portal and softphone applications across supported browsers and operating systems. Feedback is gathered from users with accessibility needs during onboarding and periodically through service reviews. The interface design follows WCAG 2.2 AA guidelines, including appropriate contrast ratios, focus indicators, resizable text, and consistent navigation structure. Updates to the interface are tested for regressions in accessibility compliance. While we have not formally engaged with third-party disability user groups, internal user experience evaluations focus on inclusivity and usability. We continue to monitor accessibility developments and aim to align with EN 301 549 in future enhancements.
API
Yes
What users can and can't do using the API
Our API allows users to integrate Curo IP with third-party systems such as CRM platforms (e.g. Salesforce, HubSpot), helpdesk tools, and productivity suites. Through the API, users can enable click-to-dial functionality, retrieve call data and analytics, automate call logging, and display live call statistics on wallboards.

API endpoints support user provisioning, call routing updates, and voicemail configuration depending on licence type and user permissions. Setup requires API key authentication and endpoint access, typically provided via our technical team during onboarding. Changes through the API are logged and audited.

Limitations include restricted access to core system controls, which are reserved for admin portal users. Some API functions require specific user roles or licence types. Real-time call manipulation (e.g. mid-call transfer) is not supported via API.

Our documentation is provided in HTML and PDF format, covering authentication, endpoints, parameters, and sample requests. While a sandbox environment is not currently available, test support can be arranged upon request.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Users can customise a wide range of features within the Curo IP platform. This includes call routing plans, auto-attendants, voicemail messages, hunt groups, call recording rules, and user permissions. Individual users can personalise their voicemail settings, ringtones, presence status, and call forwarding rules.

Authorised administrators can configure company-wide settings via the secure web portal, including group features, contact directories, and integration settings with third-party platforms such as Microsoft Teams or CRMs. Branding elements such as logos and welcome messages can be applied to certain interfaces.

Customisation is carried out through the browser-based admin portal or by request via our support team. API access also allows customers to automate some configuration tasks and integrate the service into their broader IT ecosystem.

Only users with admin privileges can customise organisation-wide settings. Standard users can manage their own profiles and device-level features. Customisation changes are logged for auditing and compliance purposes. Technical support is available during onboarding and throughout the contract term to assist with complex configuration or service tailoring.

Scaling

Independence of resources
Our cloud infrastructure uses virtualised, multi-tenant architecture with strict resource allocation to ensure users are not impacted by others' demand. CPU, bandwidth, and memory resources are monitored and scaled dynamically to maintain consistent performance. Quality of Service (QoS) rules prioritise real-time voice traffic, preventing degradation during peak loads. Services are hosted in resilient UK data centres with high availability and failover. Each customer environment is logically separated, and traffic is isolated via secure VLANs and firewalls. Usage thresholds are actively monitored, and additional capacity is provisioned proactively to ensure performance remains unaffected by other users.

Analytics

Service usage metrics
Yes
Metrics types
We provide service metrics including call volumes, durations, missed and answered calls, call queues, and voicemail usage. Metrics are available by user, group, extension, or site. Real-time dashboards display live call activity, while scheduled reports provide historical analysis. System health and uptime data are also available. Call quality data (e.g. jitter, latency) can be viewed per session. Metrics support capacity planning and SLA tracking. APIs allow for integration with external BI tools or wallboards. Reports can be downloaded in CSV or viewed within the admin portal. Alerts and thresholds can be configured for key performance indicators.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data through the secure web portal or request an export via the support team. Call logs, voicemail files, user details, and call recordings (if enabled) are available. Data can be downloaded directly in standard formats or securely transferred via encrypted links or SFTP. Access to exports is controlled by user permissions. Assistance is available from our support team to guide users through the export process. Customers are advised to extract data before contract termination, although a 30-day post-contract window is provided for final exports.
Data export formats
  • CSV
  • Other
Other data export formats
  • MP3 – for call recordings and voicemails
  • WAV – for call recordings and voicemails
Data import formats
  • CSV
  • Other
Other data import formats
  • MP3 – for voicemail greetings and auto-attendant prompts
  • WAV – for call recordings and IVR messages
  • CSV – for bulk user data, contacts, call plans

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We guarantee 99.99% service availability for our Curo IP Hosted Telephony platform, excluding planned maintenance and force majeure events. This equates to less than 53 minutes of downtime per year. Availability is monitored continuously across all critical service components including call routing, portals, and APIs.

Our Service Level Agreement (SLA) includes response and resolution targets aligned with incident severity. Priority 1 incidents (e.g. total service outage) are responded to within 15 minutes and resolved within 4 hours. Lower priority issues follow agreed timelines detailed in our support policy.

If availability falls below the guaranteed threshold in a calendar month, service credits can be applied. These are calculated as a percentage of the monthly service charge, scaled to the level of disruption experienced and agreed by both parties. Customers must submit a claim within 30 days of the incident to be eligible.

Scheduled maintenance is communicated with at least 48 hours’ notice and is typically performed outside core business hours to minimise impact. Maintenance windows are excluded from availability calculations.

Our service resilience is supported by geographically diverse infrastructure, automatic failover, and live monitoring, ensuring continuity even during unexpected events.
Approach to resilience
Curo IP is hosted in UK data centres ensuring high service availability and fault tolerance. All critical components—including call control, database clusters, and session border controllers—are configured for high availability (HA) with automatic failover between nodes.

Redundant hardware, power supplies, and connectivity links ensure no single point of failure exists. Load balancing and intelligent traffic routing enable real-time adjustment to hardware or network issues without service disruption.

Data is replicated across environments in near real-time to protect against data loss. We conduct regular failover testing, disaster recovery simulations, and infrastructure monitoring to validate service resilience.

Data centres are Tier 3 equivalent or higher and certified to ISO 27001, ISO 22301, and ISO 9001 standards, with N+1 power and cooling.

In the event of a critical failure, failover mechanisms automatically redirect traffic to healthy infrastructure. Recovery time objectives (RTO) and recovery point objectives (RPO) are contractually defined and monitored.

If further detail is required, resilience architecture documentation is available to buyers on request under a non-disclosure agreement.
Outage reporting
We provide multiple channels for communicating service outages and disruptions. Customers are notified via email alerts for both planned maintenance and unplanned incidents. Notifications include service impact, expected resolution time, and status updates.

Customers may also subscribe to RSS feeds or webhook-based notifications for integration with internal monitoring tools. Where required, outage notifications can be escalated via direct contact with our support team or technical account manager.

Post-incident, we provide a formal incident report detailing root cause analysis, remediation actions, and measures to prevent recurrence.

Our proactive monitoring and automated alerting systems allow us to detect and respond to issues rapidly, often before they impact end users.

An API for service status is available on request for customers requiring integration into their own dashboards or operational toolsets.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted by role-based access controls (RBAC) and enforced using unique user credentials. Multi-Factor Authentication (MFA) is required for all admin and privileged accounts. Support channels such as the ticketing system and phone support require customer identity verification before any account or configuration changes are actioned. All access is logged and monitored. Only authorised technical staff have administrative access, which is granted on a least-privilege basis and reviewed regularly. Changes made via support channels are recorded with timestamps and technician IDs for audit purposes.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
We operate an ISO/IEC 27001:2022 certified Information Security Management System (ISMS) which governs all security policies and procedures. Our security framework covers areas including access control, data protection, change management, incident response, physical security, and user awareness training.

All employees and contractors receive mandatory security training on induction and annually thereafter. Policies are published internally, reviewed regularly, and updates are communicated to all staff. Compliance with security policies is enforced through management oversight, internal audits, and automated access controls.

The Head of Operations holds overall responsibility for information security governance, supported by a dedicated Information Security Officer. Security incidents or policy breaches are reported through an internal escalation process, with incidents reviewed by the management team and root cause analysis conducted where necessary.

Risk assessments are conducted regularly and aligned with business objectives. Security controls are monitored continuously, and we undergo external audits to validate compliance.

Customers may request copies of our security policies and audit summaries under NDA.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We follow an ISO 27001-aligned change management process. All service components are tracked through asset registers and configuration management databases (CMDB). Changes are formally raised, risk-assessed for security, impact, and business continuity, and reviewed by a change advisory board (CAB). High-risk changes require senior approval and customer notification. Implementation is planned with rollback procedures and tested in staging environments where appropriate. Post-deployment, changes are audited and reviewed. All activity is logged, version-controlled, and retained for audit. Emergency changes follow an expedited but logged and reviewed path. Change logs and documentation are available to customers on request.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We operate a formal vulnerability management programme aligned with ISO 27001 and Cyber Essentials. Threat intelligence is sourced from NCSC advisories, vendor alerts, CVE databases, and security mailing lists. Vulnerabilities are risk-assessed based on CVSS scores and impact on service. Critical patches are deployed within 24 hours, high-risk within 72 hours, and medium/low-risk as part of scheduled maintenance. Automated scanning tools are used alongside manual checks. Systems are monitored continuously for known exploits, and regular penetration tests validate our controls. Patch deployments follow our change control process and are tested in staging before production rollout.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We use automated monitoring tools to detect anomalies, intrusion attempts, and unauthorised access across our infrastructure. Logs from firewalls, servers, and applications are centralised and analysed in real-time. Alerts are triaged based on severity and investigated by our security team. High-priority incidents (e.g. suspected compromise) trigger an immediate response within 30 minutes, following our ISO 27001-aligned incident management process. Root cause analysis is conducted, and remedial action is implemented swiftly. Customers are notified if their data or service is affected. All incidents are logged, reviewed, and used to enhance future threat detection and response.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We maintain predefined processes for handling common incidents such as service outages, DDoS attacks, unauthorised access attempts. All incidents follow our ISO 27001 aligned incident response plan. Reporting via support portal, email. Working hours are Mon-Fri 8.00 - 5.00pm. Exclude UK public holidays. OOH pricing available upon request. Incidents are logged, prioritised, and investigated immediately based on severity. Customer updates throughout the process. For high-impact incidents, we provide a post-incident report within 5 business days, detailing root cause, impact, and corrective actions. All incidents are reviewed as part of our continual improvement process and used to strengthen our security posture.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Free trial available on a case-by-case basis. Includes maximum of 2 user licences. Excludes softphone, handsets, broadband or leased line connectivity. Trial duration and scope agreed during pre-sales discussions, typically up to 30 days. Designed to evaluate suitability before full deployment.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
CQS (Certified Quality Systems) Ltd for ISO27001:2022 until 19/02/2028
ISO/IEC 27001 accreditation date
Thursday 20 February 2025
What the ISO/IEC 27001 doesn’t cover
The certification does not extend to third-party environments outside of Rydal Group’s direct operational control, such as customer-managed on-premise hardware or customer-side integrations beyond our defined service scope.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
CQS (Certified Quality Systems) Ltd Until 25/01/2027
ISO 9001 accreditation date
Friday 26 January 2024
What the ISO 9001 doesn’t cover
The certification does not apply to third-party reseller activities or services delivered outside Rydal Group’s managed operations. It is focused on our own provision of telecoms, IT, and cloud communication solutions.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2c5a8a82-8188-4c3f-9d49-2e457d2e86e5
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at n.nania@rydal-group.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.