Legal
Data Processing Addendum.
This page is provided as a reference. The version that applies to your contract is the one signed in your order form or DPA, contact [email protected] for the contract-specific version.
Last updated: May 2026
Clauses
What the addendum covers
| 1. Scope | This DPA forms part of the customer agreement between you and GuardianGaze Limited governing the Guardian Gaze platform. It applies to processing of personal data on your behalf in connection with the service. |
| 2. Role and responsibilities | You are the controller. GuardianGaze Limited is the processor. We process personal data only on your documented instructions, which are deemed to be: operating the platform, providing support, and complying with applicable law. |
| 3. Sub-processors | You authorise GuardianGaze Limited to engage sub-processors. The current list is maintained as an appendix to the customer DPA, with advance written notice of any addition or replacement. You may object to a new sub-processor on reasonable grounds. |
| 4. International transfers | Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Agreement and EU Standard Contractual Clauses as appropriate. |
| 5. Security measures | We maintain technical and organisational security measures appropriate to the risk, aligned with GDPR Article 32. The current security profile is documented in the customer agreement. |
| 6. Personal data breach | We will notify you of any personal data breach affecting your data without undue delay. Notification will include the categories of data, approximate volumes, likely consequences, and remediation measures. |
| 7. Data subject rights | We will assist you, taking into account the nature of processing, in fulfilling your obligations to respond to data-subject requests. |
| 8. Audit rights | You may audit our compliance with this DPA per the terms set out in the customer DPA, subject to confidentiality undertakings. |
| 9. Return and deletion | On termination of the agreement, personal data is returned or deleted within the period stated in the order form, except where applicable law requires further retention. |
| 10. Liability and indemnity | Liability under this DPA is subject to the limitations in the main customer agreement. |
Procurement or security review?
The trust centre covers platform security, data handling and residency in the terms a reviewer works in.
Contract and DPA questions: [email protected]