Legal
Data Processing Agreement
Template version · Last updated: August 20, 2026
This is a working template for facility customers. It is not executed until countersigned. Email support@seniorguard.care for a PDF with company details filled in for your agreement file.
1. Parties and roles
The Customer (facility / agency) is the Controller of resident and staff personal data entered into SeniorGuardCare. SeniorGuardCare Ltd (or the contracting entity named on the Order Form) is the Processor for that Customer Data, except where SeniorGuardCare determines purposes for its own account administration (billing, security logs), in which case it acts as an independent controller.
2. Subject matter and duration
Processing covers care coordination: resident demographics, medications, MAR/visit logs, incidents, risk assessments, documents, messaging, and related audit trails, for the term of the subscription and any agreed retention/deletion period after termination.
3. Nature and purpose
Hosting, storage, retrieval, transmission, and display of Customer Data to authorised users; optional AI features only when enabled and consented; support, security monitoring, and backups.
4. Types of data and data subjects
Residents / service users, family members, and staff. May include special category health data (UK GDPR Art. 9) such as medications, allergies, incidents, and clinical documents uploaded by the Customer.
5. Customer instructions
The Processor processes Customer Data only on documented instructions from the Customer (including configuration of the Service and support tickets), unless required by UK/EU law. The Customer is responsible for the lawfulness of instructions and for obtaining any required consents or Art. 9 conditions for health data.
6. Confidentiality and security
Personnel with access are bound by confidentiality. Technical and organisational measures include TLS in transit, access control and Row Level Security, encrypted storage for uploaded documents, logging, and account deletion tooling. See the Trust centre for the current security posture summary.
7. Subprocessors
Customer authorises engagement of subprocessors listed on the Trust centre (including Supabase, Vercel, Stripe, Resend, Twilio when SMS is enabled, and the AI model provider when AI features are used). Material changes will be notified with a reasonable objection window where contractually required.
8. International transfers
Where Customer Data is transferred outside the UK/EEA, the Processor uses appropriate safeguards (e.g. UK IDTA / SCCs) with the relevant subprocessor.
9. Assistance
Taking into account the nature of processing, the Processor assists with data subject requests, DPIAs, and consultations with the ICO, insofar as possible via product features (export, access controls, deletion) and reasonable support.
10. Breach notification
The Processor will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with information reasonably available to support the Customer's own notification duties.
11. Deletion and return
On termination, Customer may export data via product tools. Thereafter the Processor deletes or returns Customer Data within the timeframe stated in the Order Form or Privacy Policy, except where retention is required by law or needed for dispute resolution / billing records.
12. Audits
Upon reasonable written notice, the Processor will make available information necessary to demonstrate compliance with this DPA (security summaries, questionnaire responses). On-site audits require mutual agreement on scope, timing, and cost.
13. Governing law
This DPA is governed by the law specified in the Master Terms / Order Form (typically England and Wales for UK facility customers).