Legal
Data processing addendum — not yet written.
The Article 28 terms this addendum will have to cover, and nothing that binds anybody yet.
This addendum has not been written yet. What follows is an outline: the Article 28 terms a UserGuard DPA has to contain, and what each section will have to establish. It commits to no notification windows, no security measures, no transfer mechanism and no sub-processor list, because none of that has been settled. Nothing on this page is binding on you or on us until the real text is published in its place. Until then, write to hello@userguard.io.
When this addendum applies
States that the addendum forms part of the terms of service, and which customers it takes effect for — those whose use of UserGuard involves processing personal data under the GDPR, the UK GDPR, or a comparable law.
States whether it applies automatically on accepting the terms or has to be requested and executed separately, and what happens when a procurement process needs a countersigned copy or asks for bespoke wording.
Roles of the parties
Establishes the customer as controller of the personal data processed through the service — they decide which sites carry the script, which categories exist, what the banner asks, how long records are kept, and what happens when a visitor exercises a right — and UserGuard as processor, acting on their behalf and on their instructions.
Establishes that UserGuard is a separate, independent controller for its own account, billing and support data, which the privacy policy governs rather than this addendum, and states plainly that the two are not merged.
Subject matter, duration, nature and purpose
Records the four things Article 28(3) requires to be set down in writing. The subject matter is the provision of the service as described in the terms. The duration is the subscription term plus whatever deletion window the deletion section sets.
The nature and purpose is the processing the product actually performs: collecting a visitor’s consent decision and storing it as a durable record, blocking or permitting tags accordingly, scanning pages to identify cookies and third-party requests, generating policy and statement drafts from those findings, producing reports, and providing access, search and export over all of it.
Categories of data subjects and personal data
Data subjects to be listed: visitors to the websites the customer registers, and the users they invite into their UserGuard account.
Personal data to be listed, field by field, so a controller can map it without guessing. The final text must enumerate exactly what a consent record contains, exactly what is held about account users, and how scan data is treated where it incidentally captures personal data in a cookie value or a URL parameter. It should also state the position on special categories under Article 9 and what customers are instructed not to configure.
Processing on documented instructions
Commits UserGuard to processing personal data only on the controller’s documented instructions, including as to international transfers, unless required otherwise by law, and states what happens when the law requires something else. Identifies what counts as the instructions: this addendum, the terms, and the configuration choices made in the application.
States what UserGuard does with an instruction it considers to infringe data protection law, and sets out the prohibitions that are absolute rather than settings — no processing for other purposes, no sale, no sharing for advertising, no training of machine-learning models on customer data.
Security and confidentiality
Sets out the technical and organisational measures relied on under Article 32, at the level of detail a security reviewer can check, and says how changes to them are communicated. This section cannot be written from the outline: it has to describe measures that are actually in place and verifiable.
Confidentiality of personnel
Establishes that everyone with any possibility of access to customer data is bound by written confidentiality obligations that survive the end of their engagement, receives data-protection training, holds only the access their role requires, and loses it when the engagement ends. States how often access is reviewed.
Assistance with data-subject requests and DPIAs
Describes the tools the application gives a controller to answer most requests without contacting UserGuard — finding a consent record and exporting it — and states the assistance available where those tools are not enough, including how quickly.
States what happens when a data subject contacts UserGuard directly about data processed for a customer: that the response is to refer them to the controller and notify the controller, and how quickly. Also states the assistance provided with data protection impact assessments and prior consultations under Articles 35 and 36.
Personal data breaches
States the window within which UserGuard notifies a customer of a personal data breach affecting personal data it processes for them, measured from becoming aware, and by what channels the notification is delivered.
States what the first notification must contain — the nature of the breach, the categories and approximate numbers concerned, the likely consequences, the measures taken, and a named contact — how follow-up works as more is learned, and what post-incident reporting is provided. Confirms that the decision to notify a supervisory authority or affected individuals under Articles 33 and 34 rests with the controller.
Sub-processor terms and your right to object
Records the customer’s general written authorisation for sub-processors, and commits that each is engaged under a written contract with data protection obligations no less protective than those here, with UserGuard remaining liable for their performance.
States how much advance notice is given before a sub-processor is added or replaced, how that notice is delivered, how a customer objects on reasonable data protection grounds, and what happens if no alternative can be found — including any termination and refund right. It should also say that an objection is not treated as a breach of contract.
Current sub-processors
The list of sub-processors will be published in this section and kept current, updated before a new sub-processor begins processing rather than after. It is not written yet, and no sub-processors are named anywhere on this page.
Changes to this list
Describes how customers are told when the list changes: how to subscribe to notifications, how far ahead an addition or replacement is announced, what the notice contains, and how removals are recorded.
International transfers
Names the transfer mechanism relied on for personal data leaving the EEA, the UK or Switzerland for a country without an adequacy decision, and incorporates it properly — including which modules apply, and each of the optional selections the clauses require the parties to make.
States the equivalent position for UK and Swiss transfers, and what transfer impact assessment work has been done and can be shared on request. Where a data-residency option exists, this section says what it covers.
Audits and information rights
States what information UserGuard makes available to demonstrate compliance with Article 28, how it is requested, how quickly it arrives, and whether it is charged for.
Sets the terms of an on-site or third-party audit where documentation is genuinely insufficient: frequency, notice, timing, who may conduct it, confidentiality, and who bears the cost in each outcome. Confirms that a supervisory authority exercising statutory powers is not subject to those limits.
Deletion and return on termination
States what happens to personal data on termination or expiry, and the controller’s choice between deletion and return. States what can be exported, in what formats, and how long the export stays available.
States the deletion timeline through to backups, so “deleted” has a date attached rather than an intention. States what is retained where law requires it, and confirms that anything retained stays subject to this addendum for as long as it is held.
Precedence, changes and contact
Sets the order of precedence between this addendum, the terms of service and the transfer clauses, and confirms which parts of the terms — including the limitation of liability — carry across to processing under this addendum.
States how this addendum is updated, how much notice material changes carry, and where prior versions live. Names the contact point for questions, signature requests, transfer impact assessments and sub-processor objections. Until the real text is published, that contact point is hello@userguard.io.