Legal
Data Processing Addendum
Last updated September 9, 2026. Applies whenever we process personal data on a customer's behalf.
Scope and roles
This addendum forms part of the agreement between GuardResourceOne ("processor") and the customer ("controller") and applies whenever we process personal data on the customer's behalf through GuardSource. Where UK or EU GDPR applies, this addendum satisfies Article 28.
Subject matter and duration
- Subject matter: provision of the GuardSource security workforce management platform.
- Duration: for the term of the subscription, plus the 30-day post-termination export window.
- Nature and purpose: hosting, storage, transmission, scheduling, reporting and analysis of workforce records.
- Categories of data subject: the customer's officers, supervisors, administrators, visitors and client contacts.
- Categories of personal data: identity and contact details, employment and licence details, shift and attendance records, location recorded during shifts, incident report content, photographs and media.
Processor obligations
- Process personal data only on the controller's documented instructions, including for international transfers, unless required otherwise by law.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement the technical and organisational measures described on our Security page.
- Assist the controller with data subject requests, impact assessments and regulator consultations, taking into account the nature of processing.
- Notify the controller without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach.
- Delete or return all personal data at the end of the service, and delete existing copies unless law requires retention.
- Make available the information needed to demonstrate compliance and allow audits once per year, or after a breach, on reasonable notice.
Sub-processors
The controller gives general authorisation for the sub-processors listed on our sub-processors page. We will give at least 30 days' notice before adding or replacing one, and the controller may object on reasonable data-protection grounds, in which case we will work to find a solution or the controller may terminate the affected service.
Transfers
Where processing involves a transfer out of the UK or EEA, the parties adopt the Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum, which are incorporated here by reference.
Signing this addendum
Customers who need a countersigned copy can request one at privacy@guardresourceone.com. We return signed addenda within five business days.
See the current sub-processor list and our security measures.
