Data Processing Agreement

Template version v2026.04.22

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer identified on the applicable Order Form (the “Customer”) and Guard Core (the “Processor”) and governs the Processor’s processing of Personal Data on behalf of the Customer in connection with the Service.

1. Definitions

Terms used in this DPA have the meanings given in the GDPR (Regulation (EU) 2016/679). “Personal Data” means personal data processed by Guard Core on the Customer’s behalf under the Agreement.

2. Subject matter, duration, nature and purpose

Guard Core processes Personal Data on the Customer’s behalf solely to provide the Service as described in the Agreement. Processing begins on the Effective Date and continues for the term of the Agreement plus any retention period required by law.

3. Categories of data subjects and Personal Data

  • Data subjects: end users of the Customer’s applications protected by the Guard Core agent (guard-agent).
  • Personal Data: IP addresses, user agents, request paths, threat indicators, and any identifiers sent by the Customer’s applications via the agent.

4. Obligations of the Processor

4.1 Processing instructions

Guard Core processes Personal Data only on the Customer’s documented instructions (including with respect to international transfers), unless required otherwise by Union or Member State law.

4.2 Confidentiality

Persons authorised to process Personal Data are under appropriate confidentiality obligations.

4.3 Security (Article 32)

Appropriate TOMs: AES-256-GCM encryption at rest for sensitive fields, TLS 1.2+ in transit, role-based access control with MFA, append-only audit logging retained for 6 years, vulnerability management, periodic penetration testing. Full TOMs are described in Annex II.

4.4 Sub-processors (Article 28(2))

The Customer provides general authorisation for Guard Core to engage the sub-processors listed at /subprocessors. Guard Core gives 30 days’ notice of additions or replacements; the Customer may object on reasonable grounds.

4.5 Assistance with data subject rights

Guard Core assists the Customer in fulfilling its obligation to respond to requests from data subjects (access, rectification, erasure, restriction, portability, objection).

4.6 Breach notification

Guard Core notifies the Customer without undue delay after becoming aware of a Personal Data Breach, in any case within 72 hours, including the information required under Article 33(3).

4.7 DPIA assistance

Guard Core assists the Customer in conducting DPIAs and prior consultations (Articles 35-36).

4.8 Return or deletion

On termination, at the Customer’s choice, Guard Core deletes or returns Personal Data within 90 days, except where Union or Member State law requires continued storage.

4.9 Audits

Guard Core makes available information necessary to demonstrate compliance and contributes to audits, no more than once per year (more frequently after a material incident), on 30 days’ notice, during business hours, subject to confidentiality.

5. International transfers

Where Guard Core or a sub-processor is located outside the EEA, transfers rely on the EU Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated by reference as Annex III, and on Commission adequacy decisions where applicable (e.g. Switzerland).

6. Liability

Liability is subject to the limits set out in the Agreement. Nothing in this DPA limits either party’s direct obligations or liability to data subjects under Article 82 GDPR.

7. Governing law and jurisdiction

This DPA is governed by the law specified in the Agreement. In the absence of such specification, the law of Ireland applies.

Annexes

  • Annex I - Details of processing (see sections 2 and 3 above)
  • Annex II - Technical and organisational security measures (published separately)
  • Annex III - EU Commission Standard Contractual Clauses (incorporated by reference; executed copies on request)
  • Annex IV - Sub-processors (maintained at /subprocessors)

Execution

To sign a countersigned copy, email [email protected] with your company details. For the Processor, Renzo Franceschini (Founder) will countersign.