Legal

Data Processing Agreement

Template version · Last updated: August 20, 2026

This is a working template for facility customers. It is not executed until countersigned. Email support@seniorguard.care for a PDF with company details filled in for your agreement file.

1. Parties and roles

The Customer (facility / agency) is the Controller of resident and staff personal data entered into SeniorGuardCare. SeniorGuardCare Ltd (or the contracting entity named on the Order Form) is the Processor for that Customer Data, except where SeniorGuardCare determines purposes for its own account administration (billing, security logs), in which case it acts as an independent controller.

2. Subject matter and duration

Processing covers care coordination: resident demographics, medications, MAR/visit logs, incidents, risk assessments, documents, messaging, and related audit trails, for the term of the subscription and any agreed retention/deletion period after termination.

3. Nature and purpose

Hosting, storage, retrieval, transmission, and display of Customer Data to authorised users; optional AI features only when enabled and consented; support, security monitoring, and backups.

4. Types of data and data subjects

Residents / service users, family members, and staff. May include special category health data (UK GDPR Art. 9) such as medications, allergies, incidents, and clinical documents uploaded by the Customer.

5. Customer instructions

The Processor processes Customer Data only on documented instructions from the Customer (including configuration of the Service and support tickets), unless required by UK/EU law. The Customer is responsible for the lawfulness of instructions and for obtaining any required consents or Art. 9 conditions for health data.

6. Confidentiality and security

Personnel with access are bound by confidentiality. Technical and organisational measures include TLS in transit, access control and Row Level Security, encrypted storage for uploaded documents, logging, and account deletion tooling. See the Trust centre for the current security posture summary.

7. Subprocessors

Customer authorises engagement of subprocessors listed on the Trust centre (including Supabase, Vercel, Stripe, Resend, Twilio when SMS is enabled, and the AI model provider when AI features are used). Material changes will be notified with a reasonable objection window where contractually required.

8. International transfers

Where Customer Data is transferred outside the UK/EEA, the Processor uses appropriate safeguards (e.g. UK IDTA / SCCs) with the relevant subprocessor.

9. Assistance

Taking into account the nature of processing, the Processor assists with data subject requests, DPIAs, and consultations with the ICO, insofar as possible via product features (export, access controls, deletion) and reasonable support.

10. Breach notification

The Processor will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with information reasonably available to support the Customer's own notification duties.

11. Deletion and return

On termination, Customer may export data via product tools. Thereafter the Processor deletes or returns Customer Data within the timeframe stated in the Order Form or Privacy Policy, except where retention is required by law or needed for dispute resolution / billing records.

12. Audits

Upon reasonable written notice, the Processor will make available information necessary to demonstrate compliance with this DPA (security summaries, questionnaire responses). On-site audits require mutual agreement on scope, timing, and cost.

13. Governing law

This DPA is governed by the law specified in the Master Terms / Order Form (typically England and Wales for UK facility customers).

Request signed DPA