This page is provided as a reference. The version that applies to your contract is the one signed in your order form or DPA. Contact [email protected] for the contract-specific version.
This DPA forms part of the customer agreement between you and Guardian Gaze Limited governing the Guardian Gaze platform. It applies to processing of personal data on your behalf in connection with the service.
You are the controller. Guardian Gaze Limited is the processor. We process personal data only on your documented instructions, which are deemed to be: operating the platform, providing support, and complying with applicable law.
You authorise Guardian Gaze Limited to engage sub-processors. The current list is maintained as an appendix to the customer DPA, with advance written notice of any addition or replacement. You may object to a new sub-processor on reasonable grounds.
Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Agreement and EU Standard Contractual Clauses as appropriate.
We maintain technical and organisational security measures appropriate to the risk, aligned with GDPR Article 32. The current security profile is documented in the customer agreement.
We will notify you of any personal data breach affecting your data without undue delay. Notification will include the categories of data, approximate volumes, likely consequences, and remediation measures.
We will assist you, taking into account the nature of processing, in fulfilling your obligations to respond to data-subject requests.
You may audit our compliance with this DPA per the terms set out in the customer DPA, subject to confidentiality undertakings.
On termination of the agreement, personal data is returned or deleted within the period stated in the order form, except where applicable law requires further retention.
Liability under this DPA is subject to the limitations in the main customer agreement.