Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of, and is governed by, the Terms of Service between you (the “Customer”) and Wardenfox Ltd (company number pending), a company registered in England and Wales whose registered office is to be updated before public launch (“WardenFox”, “we”, “us”). It sets out the terms on which we process personal data on your behalf, as required by Article 28 of the UK GDPR. Where this DPA conflicts with the Terms of Service on data-protection matters, this DPA prevails.

1. Roles of the parties

For personal data about your own customers and contacts that you enter into or generate within the Service, you are the controller and we are your processor. We process that data only to provide the Service and only on your instructions. (Separately, for the personal data of you and your staff as account holders, we are the controller — that is covered by our Privacy Policy, not this DPA.) “Personal data”, “controller”, “processor”, “data subject”, “processing” and “personal data breach” have the meanings given in the UK GDPR.

2. Your instructions

We will process the personal data only on your documented instructions, including on international transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless the law prohibits it. Your use of the Service, together with the Terms of Service and this DPA, are your complete and documented instructions. If we believe an instruction breaches the UK GDPR or other data-protection law, we will tell you.

3. Confidentiality

We ensure that the people we authorise to process the personal data are subject to a duty of confidentiality and process it only as needed to provide the Service.

4. Security

Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with Article 32 of the UK GDPR. A summary of those measures is in Annex C.

5. Sub-processors

You give us general authorisation to engage sub-processors to help provide the Service. Our current sub-processors are listed in Annex B. We impose data-protection terms on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. If we add or replace a sub-processor we will give you reasonable notice (for example by updating Annex B and/or our Privacy Policy), and you may object on reasonable data-protection grounds, in which case we will work with you in good faith to find a solution.

6. Assisting you

Taking into account the nature of the processing, we will assist you with appropriate measures, so far as possible, to:

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own breach-reporting obligations. You are responsible for notifying the ICO and affected data subjects where the law requires you to.

8. International transfers

Where providing the Service involves a transfer of personal data outside the UK (for example to a sub-processor in Annex B), we will ensure an appropriate safeguard is in place — such as the UK adequacy regulations, the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum — and will only transfer what is necessary.

9. Deletion or return

At the end of the Service, you can export your inventory from the Service and request a copy of your other data from us before deletion. If you use the account-deletion flow or ask us to delete the data when the Service ends, we will delete the live personal data from the primary database promptly, unless the law requires us to keep some of it. Residual copies in routine backups are deleted in line with our backup-rotation cycle.

10. Audits and information

We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To respect the confidentiality and security of our other customers, audits are on reasonable prior notice, no more than once a year (unless required by a regulator or following a breach), at your cost, and we may satisfy an audit request by providing relevant documentation or third-party reports where available.

11. General

This DPA is governed by the laws of England and Wales. If any part of it is invalid or unenforceable, the rest stays in effect. This DPA does not give either party any greater liability than is set out in the Terms of Service.


Annex A — Details of the processing

Annex B — Sub-processors

Annex C — Security measures