Data Processing Agreement

GuardTour Pro Limited | Company number 17316266

This Data Processing Agreement explains how GuardTour Pro Limited handles personal information on behalf of the security company using our platform. It sets out each party’s responsibilities for protecting that information, including security, confidentiality, assistance with individual rights, and the return or deletion of data.

It applies throughout the 14-day free trial and any subsequent paid subscription and forms part of the applicable terms agreed between the parties.

1. Parties and start date

GuardTour Pro Ltd, company number 17316266, registered office 1st Floor, 30 North Street, Ashford, Kent, United Kingdom, TN24 8JR (Processor), and the business identified in the accepted setup schedule (Customer or Controller) agree this DPA. It forms part of the trial terms and, when accepted, the paid Service Agreement. It starts on recorded acceptance before processing begins and continues until all Customer Personal Data is returned or deleted as required. It does not itself commit the Customer to a paid subscription.

2. Scope and customer responsibilities

Customer Personal Data means personal information handled on the Customer’s behalf through the platform and related support. The Customer decides the purposes and essential means of processing and is responsible for lawful grounds, privacy notices, accuracy, minimisation, retention instructions and appropriate permissions. It must establish any additional conditions for health, other special-category or criminal-offence information. Employment, monitoring and vetting decisions remain its responsibility. Its obligations do not reduce ours. This DPA assumes the Customer is a controller; other arrangements must be agreed before processing. Our separate business administration and billing activities are covered by our Privacy Notice.

3. Instructions and permitted use

We shall comply with the UK GDPR, Data Protection Act 2018 and other applicable data protection law. We shall process Customer Personal Data only on documented instructions, including this DPA, the setup schedule, agreed settings and lawful written instructions, including for international transfers. Where UK law requires other processing, we shall notify the Customer first unless legally prohibited. We shall immediately flag an instruction we believe infringes data protection law and seek clarification, suspending affected processing where necessary. We shall not sell the data, use it for our advertising, train general-purpose AI models on it or repurpose it for unrelated development. AI processing requires express documented instructions and approved supplier arrangements.

4. Confidentiality and security

We shall limit access to authorised persons who need it for the service and are bound by confidentiality. We shall maintain measures appropriate to risk under Article 32, including tenant separation, least-privilege access, strong authentication, appropriate encryption and credential protection, security logging, secure development and vulnerability management, protected backups and tested recovery, staff training and secure deletion. We shall regularly assess effectiveness and shall not materially reduce agreed protection. Implementation evidence is identified in the setup schedule. These duties cover our personnel and supplier arrangements.

5. Subprocessors and international transfers

The Customer authorises the named subprocessors in the agreed register identified in the setup schedule. We shall give at least 30 days’ written notice of intended additions or replacements, allowing reasonable data protection objections. A disputed provider shall not process affected data until the objection is resolved. If no reasonable solution exists, either party may terminate the affected service without an early termination charge, with unused prepaid fees refunded. We shall assess suppliers, impose equivalent Article 28 obligations by written contract and remain responsible for their compliance.

Approved storage, backup and support-access locations and transfer arrangements must be recorded in the register. Restricted transfers require documented Customer authorisation and a valid UK transfer mechanism, with required assessments and supplementary measures. Authorisation alone is not a transfer safeguard. We shall suspend non-compliant transfers, assist with a lawful alternative, and notify the Customer of legally binding disclosure demands unless prohibited, limiting disclosures to lawful requirements.

6. Rights requests and compliance assistance

Taking account of the processing and information available, we shall provide appropriate technical and organisational assistance, insofar as possible, with individual rights requests, security, breach reporting, impact assessments and prior regulatory consultation under Articles 32–36. We shall promptly forward rights requests and respond substantively only on instructions or where legally required. We shall provide information necessary to demonstrate Article 28 compliance and allow and contribute to Customer or mandated-auditor audits, including inspections. Reasonable notice, confidentiality and operational arrangements must not obstruct necessary audits or regulatory access.

7. Personal data breaches

We shall notify the Customer without undue delay after becoming aware of a personal data breach affecting its data, without waiting for a completed investigation. We shall provide available details of affected people and records, likely consequences, mitigation and a contact, supplying further information promptly as it becomes available. We shall contain and investigate the breach, preserve evidence and assist with remediation and notifications. The Customer determines notifications for which it is responsible; we shall not identify it publicly without instruction unless legally required.

8. Return and deletion

At the Customer’s choice, we shall securely return or delete its data at the end of processing and delete existing copies unless UK law requires retention. Lawful deletion instructions during the service also apply. The setup schedule fixes export, live deletion and backup deadlines. We shall require equivalent action from subprocessors. Pending expiry, backup copies shall be protected and put beyond ordinary use; restored data remains subject to deletion instructions. Legally retained records shall be restricted to the required purpose and deleted when that requirement ends. We shall confirm completion on request. Relevant confidentiality, security and assistance duties continue until deletion is complete.

9. Contract arrangements

This DPA prevails over conflicting processing terms; mandatory transfer clauses take priority. Routine assistance is included in service fees; exceptional charges require advance agreement and shall not delay legal duties. Remediation of our own breach is not chargeable. Lawful Service Agreement liability terms apply, without restricting individual or regulatory rights, non-excludable liability or subprocessor responsibility. This DPA creates no separate liability cap. Other changes require written agreement; publishing new wording alone does not amend an accepted DPA. The Service Agreement governs law and courts; otherwise, England and Wales law and courts apply, subject to mandatory law.