Data Processing Agreement
When you upload data about your employees and contractors to Guardiso, you remain its controller and we act as the processor. This agreement sets out what we may do with that data, how we protect it, and what you may require of us.
Data Processing Agreement
Document version: 2.1 In force from: 1 September 2026 Previous version: 1.0 of 16 August 2026 Legal basis: Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the GDPR)
Date of conclusion: ………………………
Agreement concluded between:
the data controller — ……………………………………………, tax identification number ………………………, with its registered office at ……………………………………………, hereinafter referred to as the Controller,
and
the data processor — Guardiso Michał Lewandowski, ul. Święty Marcin 29/8, 61-806 Poznań, Poland, tax identification number (NIP) 6060011996, trading under the Guardiso brand, email address kontakt@guardiso.com, hereinafter referred to as the Processor.
This Agreement sets out the rules governing the entrustment of the processing of personal data in connection with the Controller's use of the Guardiso platform available at https://guardiso.com.
Throughout this document, the Platform means the Guardiso software made available to the Controller through a web browser on a subscription basis, and the Entrusted Data means the personal data that the Controller enters or uploads into the Platform and in respect of which it is the controller.
§ 1. Subject matter, nature and purpose of the processing
-
The Controller entrusts the Processor with the processing of the Entrusted Data solely for the purpose of providing the Platform service — that is, storing, organising and making available to the Controller its own documentation of its information security management system and of its compliance with the selected standards.
-
The nature of the processing comprises: collection, recording, storage, organisation, consultation, use within the scope of the Platform's functions, disclosure to persons authorised by the Controller, and erasure.
-
The Processor does not process the Entrusted Data for its own purposes, and in particular does not use it to train artificial intelligence models, for marketing purposes, or to build profiles of natural persons.
-
The Parties acknowledge the content of Article 28(10) GDPR, under which a processor that infringes the Regulation by determining the purposes and means of the processing is considered to be a controller in respect of that processing.
§ 2. Type of data and categories of data subjects
-
Categories of data subjects: the Controller's employees and associates, persons appointed to roles within the information security management system, persons reporting incidents, representatives of the Controller's counterparties and suppliers, and external auditors to whom the Controller has granted access.
-
Types of ordinary data: first name and surname, business email address, position and role within the organisation, department, business telephone number, data contained in documents and evidence uploaded by the Controller, and records of activity in the Platform together with the internet protocol address and time stamp.
-
Special categories of data referred to in Article 9(1) GDPR, and data relating to criminal convictions and offences referred to in Article 10 GDPR, are not required in order to use the Platform, and the Platform is not intended for such data. If the Controller enters such data in the content of documents, it does so at its own responsibility and is obliged to inform the Processor beforehand in writing or in documentary form (forma dokumentowa), so that the Parties may determine additional protective measures.
-
Duration of the processing: for the term of the service agreement and for the period indicated in § 11.
§ 3. Obligations of the Controller as data controller
-
The Controller declares that it has a legal basis for the processing of the Entrusted Data within the meaning of Article 6(1) GDPR and, in the case of special categories of data, also a condition under Article 9(2) GDPR, and that that basis covers the entrustment of such data to the Processor on the terms of this Agreement.
-
The Controller declares that it has fulfilled the information obligation towards the data subjects arising from Article 13 or Article 14 GDPR, including that it has informed those persons about the use of the Platform and about the categories of recipients of the data. This applies in particular to the Controller's employees and associates, to persons reporting incidents, and to contact persons at its suppliers and counterparties.
-
The Controller declares that the instructions it issues are lawful and fall within the scope and purpose set out in § 1. The Controller is responsible for the compliance of its instructions with the GDPR and with the other personal data protection provisions to which it is subject.
-
The Controller is responsible for the content, scope, accuracy and currency of the data that it enters or uploads into the Platform. In particular, the Controller:
- applies the data minimisation principle under Article 5(1)(c) GDPR and does not enter into the Platform data that is unnecessary for the purpose set out in § 1;
- ensures the accuracy of the data in accordance with Article 5(1)(d) GDPR, using the rectification and erasure functions available in the Platform;
- is responsible for the selection and scope of the documents and evidence that it places in the Platform, including for what personal data their content contains.
-
The Controller manages access to its organisation in the Platform: it designates authorised persons, grants and withdraws their permissions, oversees the currency of the user list, and promptly withdraws access from persons who have ceased to have grounds to use the Platform. The Processor does not assess whether the permissions granted by the Controller are justified.
-
The Controller implements its own security measures on its side to the extent required by Article 32 GDPR, and in particular secures the devices and accounts of the persons to whom it has granted access and protects the login links sent to the email addresses it has indicated.
-
The Controller promptly informs the Processor of any change relevant to the entrustment, in particular of a change to the contact details of the person designated for data protection matters and of any intention to enter into the Platform categories of data other than those described in § 2.
-
The provisions of this section do not release the Processor from its own obligations arising from the GDPR and from this Agreement, in particular from the obligation to inform the Controller referred to in § 4(4).
§ 4. Instructions of the Controller — Article 28(3)(a) GDPR
-
The Processor processes the Entrusted Data solely on documented instructions from the Controller. Actions performed by the Controller and by persons authorised by it in the Platform interface, as well as the configuration of the Platform's functions made by the Controller, are also deemed to be documented instructions.
-
The conclusion of this Agreement and of the service agreement constitutes an instruction to process within the scope and for the purpose described in § 1 and § 2.
-
Transfer of the Entrusted Data to a third country or to an international organisation takes place solely on the terms described in § 8 and in accordance with the rules described in § 10.
-
The Processor promptly informs the Controller if, in its opinion, an instruction issued infringes the GDPR or other European Union or Member State data protection provisions. Pending clarification of the matter, the Processor may suspend the execution of such an instruction.
-
If European Union law or Member State law imposes on the Processor an obligation to process that is inconsistent with the Controller's instruction, the Processor informs the Controller of this before the processing begins, unless such information is prohibited by that law on important grounds of public interest.
§ 5. Confidentiality — Article 28(3)(b) GDPR
-
The Processor ensures that the persons authorised to process the Entrusted Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. That commitment remains in force after the end of their cooperation with the Processor.
-
Persons acting under the authority of the Processor process the Entrusted Data only on its instructions, in accordance with Article 29 GDPR.
-
Access to the Entrusted Data is available solely to persons for whom it is necessary in order to perform their duties, and solely to the extent necessary for that purpose.
-
The owner of the Platform has no standing access to the Controller's data. Every access by the Processor's personnel to the data of a given Controller requires a request with a justification and approval by the Controller, is limited in time and is logged. The Controller may revoke such access at any time.
-
Emergency access, without the Controller's prior consent, is permissible only in the event of an actual security incident where delay would risk a breach of the rights or freedoms of natural persons. The Processor notifies the Controller of every such access promptly and no later than within seven days, indicating the reason for, the scope of and the duration of the access and the actions taken.
§ 6. Security of processing — Article 28(3)(c) and Article 32 GDPR
-
The Processor implements the technical and organisational measures described in Annex 1 to this Agreement, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, as well as the risk to the rights or freedoms of natural persons.
-
The Processor may change the measures described in Annex 1, provided that the level of protection is not reduced. The Processor informs the Controller of any change that materially alters the description in Annex 1 in accordance with the rules described in § 14(2).
-
Annex 1 also contains expressly marked limitations on the Processor's present capabilities. The Controller takes them into account in its own risk assessment and in its own data protection impact assessment.
-
The Processor maintains a record of the categories of processing activities carried out on behalf of the Controller in accordance with Article 30(2) GDPR and makes it available to the Controller on request.
§ 7. Sub-processors — Article 28(2) and (4) GDPR
-
The Controller grants the Processor general written authorisation to use the sub-processors listed in Annex 2.
-
The Processor informs the Controller of any intention to add a new sub-processor or to replace an existing one at least 30 days in advance. It sends that information to the email address indicated by the Controller and publishes it in the Platform. Within that period the Controller may raise a reasoned objection.
-
If an objection is raised, the Parties enter into good-faith discussions on a solution. If no solution is found within 30 days, the Controller may terminate the service agreement with effect as at the end of the paid period, and the Processor refunds the fee for the unused period.
-
The Processor imposes on every sub-processor the same data protection obligations as those resting on the Processor itself under this Agreement, by way of a contract or another legal act, and is liable to the Controller for the acts and omissions of those entities as for its own.
-
The list in Annex 2 is maintained in a single place in the Platform's code and feeds both this Agreement and the information published by the Processor, so that the documents do not diverge from the actual state of affairs.
§ 8. Transfers of data outside the European Economic Area
-
The Entrusted Data is stored in Poland, in a data centre in Warsaw.
-
Some sub-processors operate outside the European Economic Area. The legal basis for each such transfer is indicated in Annex 2 — it is either a European Commission adequacy decision issued on the basis of Article 45 GDPR or the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on the basis of Article 46(2)(c) GDPR.
-
The Processor does not transfer the Entrusted Data to a third country without a basis under Chapter V GDPR.
-
The Processor verifies that the indicated basis is current before commencing cooperation with a sub-processor. If the basis ceases to apply, the Processor suspends the transfer or replaces the basis with another basis permitted under Chapter V GDPR, and informs the Controller accordingly.
§ 9. Assistance to the Controller — Article 28(3)(e) and (f) GDPR
9.1. Rights of data subjects
-
The Processor assists the Controller in fulfilling its obligation to respond to requests from data subjects in respect of the rights set out in Chapter III GDPR, by making available in the Platform tools for searching for, producing, rectifying and erasing data.
-
If a data subject approaches the Processor directly with a request concerning the Entrusted Data, the Processor does not respond to it on the merits, but promptly, and no later than within three business days, forwards the request to the Controller and informs the requesting person that the controller of their data is the Controller.
-
If the tools available in the Platform are not sufficient to carry out the request, the Processor provides the Controller with additional technical assistance within seven business days of receiving the application.
9.2. Notification of breaches to the Controller
-
The Processor notifies the Controller of every breach of the protection of the Entrusted Data without undue delay and no later than within 48 hours of the Processor becoming aware of the breach.
-
The period referred to in paragraph 4 runs from the moment the Processor becomes aware of the breach, and not from the moment it occurs. The Processor does not maintain round-the-clock on-call cover, which it states expressly in the "Limitations" part of Annex 1.
-
The notification contains the information required for the Controller to fulfil the obligation under Article 33 GDPR, to the extent that such information is known to the Processor at the time of notification, that is: a description of the nature of the breach, the categories and approximate number of data subjects concerned, the categories and approximate number of data records concerned, a description of the possible consequences of the breach, and a description of the remedial and mitigating measures taken or proposed.
-
The absence of complete information does not justify delaying the notification. The Processor sends the notification with the information at its disposal and supplements it in stages as further circumstances are established, in accordance with Article 33(4) GDPR.
-
The notification is sent to the email address indicated by the Controller for data protection matters or, in the absence of such an address, to the email address of the person who created the Controller's account in the Platform. The Controller is responsible for keeping that address current.
-
The Processor documents every breach of the protection of the Entrusted Data and makes the documentation available to the Controller on request.
9.3. Communication to data subjects
-
If a breach is likely to result in a high risk to the rights or freedoms of natural persons, the obligation to communicate the breach to those persons rests on the Controller under Article 34 GDPR. The Processor assists the Controller in fulfilling that obligation to the extent arising from Article 28(3)(f) GDPR.
-
The assistance referred to in paragraph 10 comprises:
- identifying which persons are affected by the breach and making available their contact details held in the Platform, to the extent necessary for the communication;
- providing a description of the nature of the breach and the information referred to in Article 34(2) GDPR, formulated in clear and plain language;
- providing information about the remedial measures taken and about the measures that the data subjects may take themselves;
- providing the information the Controller needs in order to assess whether any of the conditions exempting it from the obligation to communicate, referred to in Article 34(3) GDPR, applies, and in particular information as to whether the data affected by the breach was encrypted and whether the encryption key remained beyond the reach of an unauthorised person;
- on the express and documented instruction of the Controller and at its cost — the technical dispatch of the communication prepared by the Controller, using the communication channels available in the Platform.
- The Processor provides the assistance referred to in paragraph 11 without undue delay, within the deadlines agreed with the Controller according to the urgency of the matter. The content of the communication and the decision whether and whom to notify rest solely with the Controller. The Processor does not communicate with data subjects on its own initiative or in its own name, unless a provision of law expressly imposes such an obligation on it.
9.4. Impact assessment and prior consultation
-
The Processor provides the Controller with the information necessary to carry out the data protection impact assessment referred to in Article 35 GDPR and the prior consultation with the supervisory authority referred to in Article 36 GDPR. That information comprises a description of the technical and organisational measures, a description of the flow of data to sub-processors, and the limitations set out in Annex 1.
-
The Processor provides the assistance referred to in paragraphs 1–13 without additional remuneration, unless its scope goes beyond ordinary support and requires substantial effort — in which case the Parties agree the remuneration before work commences, and the absence of such agreement does not release the Processor from providing assistance to the extent required by the GDPR.
§ 10. Requests from public authorities and state services
-
If a public authority, a court, a public prosecutor's office or a state service approaches the Processor for disclosure of the Entrusted Data, the Processor does not disclose it automatically. Before any disclosure the Processor:
- checks whether the request comes from a body authorised to make it and whether it was properly served;
- checks whether the request indicates a legal basis and the scope of the data requested;
- limits any disclosure solely to the data covered by the request, refusing to disclose a wider scope.
-
The Processor notifies the Controller of a request received promptly and no later than within 48 hours of receiving it, and before disclosing the data, so that the Controller may pursue legal remedies. The notification indicates the authority, the scope of the request and the deadline stated in it.
-
If a provision of law prohibits the Processor from informing the Controller about the request, in particular for the benefit of ongoing criminal proceedings, the Processor:
- refrains from notifying solely to the extent and for the time covered by the prohibition;
- makes reasonable efforts to have the prohibition lifted or limited, including to obtain the authority's consent to inform the Controller;
- notifies the Controller promptly once the prohibition ceases to apply;
- documents the course of the matter and makes the documentation available to the Controller once the prohibition ceases to apply.
-
If the request is binding and no prohibition on informing applies, and the Controller does not take a position within the deadline arising from the request, the Processor discloses the data to the minimum extent arising from the request and promptly informs the Controller of this.
-
Requests from third-country authorities. A judgment of a court of a third country and a decision of an administrative authority of a third country requiring the transfer or disclosure of personal data may be executed only where they are based on an international agreement in force, in accordance with Article 48 GDPR. The Processor does not execute such requests outside that procedure and informs the Controller about them in accordance with paragraphs 2 and 3.
-
The Processor contractually obliges sub-processors to apply rules corresponding to paragraphs 1–5 and to notify the Processor of requests concerning the Entrusted Data, unless the law prohibits this.
-
The Processor has not provided and does not provide any authority or state service with standing, direct or automated access to the Entrusted Data.
§ 11. End of the processing — return or erasure of data, Article 28(3)(g) GDPR
-
The choice rests with the Controller. After the end of the provision of the service the Processor, depending on the Controller's decision, returns the Entrusted Data to it or erases it, and then deletes all existing copies of it, unless European Union law or Member State law requires its further storage.
-
Manner of making the declaration. The Controller makes its declaration of choice within 30 days of the end of the provision of the service, to kontakt@guardiso.com or using the function available in the Platform. The Processor reminds the Controller of the right of choice and of the deadline no later than on the day the provision of the service ends, to the email address of the person managing the account.
-
Self-service download of data. During the 30 days referred to in paragraph 2, the Controller retains the ability to download the Entrusted Data from the Platform itself, within the scope of the export functions made available in the Platform. Use of that ability does not replace the declaration referred to in paragraph 2 and does not deprive the Controller of the right of choice.
-
Return of data on request. If the Controller chooses return, the Processor prepares and issues the complete set of the Entrusted Data in a structured, commonly used, machine-readable format — register data in CSV or JSON format, and documents and evidence in the formats in which they were uploaded — within 14 days of receiving the declaration. The complete set is transmitted through a secure channel agreed with the Controller.
-
Charges. One preparation of the complete set of data after the end of the service is free of charge. For each subsequent preparation in the same matter, and for an export in an individually agreed format, the Processor may request remuneration corresponding to the effort involved, agreed before work commences.
-
Erasure. If the Controller chooses erasure or does not make a declaration within the period referred to in paragraph 2, the Processor erases the Entrusted Data within 14 days after the expiry of that period. The absence of a declaration from the Controller is treated as a choice of erasure; the Processor does not erase the data before the expiry of the period for making the declaration.
-
Backups. Database backups are created automatically once every 24 hours and are retained for seven days, after which they are overwritten in the normal cycle. This means that the Entrusted Data disappears from the backups no later than seven days after its erasure from the Platform. Until they are overwritten, the backups remain covered by this Agreement and by the same protective measures.
-
If, outside the cycle described in paragraph 7, any other copy of the Entrusted Data exists, made for a specific documented purpose, the Processor identifies it to the Controller on request and states its purpose and the date of its erasure. Until it is erased, such a copy remains covered by this Agreement.
-
Confirmation. At the Controller's request, the Processor issues confirmation of the erasure of the Entrusted Data, in writing or in documentary form, stating the date and scope of the erasure.
-
The provisions of this section apply accordingly to the end of the service in respect of a single organisation managed within the Controller's account.
§ 12. Demonstrating compliance and audit — Article 28(3)(h) GDPR
-
The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, including the current ISO/IEC 27001 certificate and the summary of implemented safeguards constituting Annex 1.
-
The Controller has the right to conduct an audit, including an inspection, itself or through an authorised auditor. An audit requires 30 days' advance notice, takes place during the Processor's working hours, and may not disrupt the continuity of the service provided to other customers or breach the confidentiality of their data.
-
The Controller bears its own costs of the audit. The costs on the Processor's side are borne by the Controller, unless the audit reveals a breach of this Agreement — in which case they are borne by the Processor.
-
In place of an inspection, the Processor may present a current certificate or an independent auditor's report, if it covers the scope of the Controller's request. If such a document does not cover the entire scope of the request, the Controller retains the right of inspection in respect of the scope not covered.
-
An auditor authorised by the Controller may not be a competitor of the Processor and, before commencing the audit, undertakes to maintain confidentiality.
-
The Processor contributes to the audit, including by answering the auditor's questions and making documentation available within the scope covered by the audit.
§ 13. Liability
-
The Parties are liable on the terms set out in Article 82 GDPR. The Processor is liable for damage caused by processing to the extent that it has not complied with the obligations imposed by the GDPR specifically on processors, or has acted outside or contrary to the lawful instructions of the Controller, in accordance with Article 82(2) GDPR.
-
The Processor's liability towards the Controller under this Agreement is limited to the amount of the fees paid by the Controller in the twelve months preceding the event giving rise to the claim.
-
The limitation in paragraph 2 does not apply to damage caused intentionally, to gross negligence, or to administrative fines imposed on the Controller, where these result solely from a breach of this Agreement by the Processor.
-
The Controller is liable towards the Processor for the consequences of any untruthfulness of the declarations made in § 3, in particular for the absence of a legal basis for the processing and for failure to fulfil the information obligation towards data subjects.
-
Delimitation of roles. Guardiso is a tool that supports compliance management. The compliance assessment, decisions concerning risk and the content of the documentation remain the responsibility of the Controller. Indicators, suggestions and content generated by the Platform, including content generated by artificial intelligence, are of an auxiliary nature and require verification by the Controller. The Processor does not provide legal assistance or legal advice within the meaning of the regulations governing the legal professions, and is not liable for the consequences of decisions taken by the Controller, including for the outcome of any inspection or certification procedure.
§ 14. Final provisions
-
The Agreement enters into force upon its acceptance in the Platform and remains in force for the term of the service agreement. The provisions of § 5, § 9(9), § 11, § 12 and § 13 remain in force after its end, to the extent indicated therein.
-
Any amendment to the Agreement requires documentary form. The Processor informs the Controller of an amendment 30 days in advance; the absence of an objection within that period means acceptance of the amendment. An amendment that lowers the level of data protection entitles the Controller to terminate the service agreement with a refund of the fee for the unused period.
-
Annex 1 and Annex 2 form an integral part of this Agreement.
-
In the event of a conflict between this Agreement and the service agreement, in matters of personal data protection this Agreement prevails.
-
In matters not regulated herein, the GDPR, the Polish Personal Data Protection Act of 10 May 2018 (ustawa o ochronie danych osobowych) and the Polish Civil Code of 23 April 1964 (Kodeks cywilny) apply.
-
Disputes are resolved by the court having jurisdiction over the Processor's registered office. This provision does not limit the rights available to a Controller who is a natural person conducting business activity, where mandatory provisions of law provide for different jurisdiction.
-
Acceptance of the Agreement is recorded in the Platform together with the date, the document version and the accepting person, which constitutes evidence of its conclusion.
Annex 1 — Technical and organisational measures (Article 32 GDPR)
Part A. Measures implemented
| Area | Measures applied |
|---|---|
| Encryption in transit | Connections to the Platform are encrypted only. Traffic to the database is carried over the infrastructure provider's private network, without exposure to the public internet. |
| Encryption at rest | Personal data subject to pseudonymisation is encrypted with the AES-256-GCM algorithm. Each customer organisation has its own encryption key — compromise of one customer's key does not expose another customer's data. |
| Key management | Keys are stored in a dedicated vault at the cloud provider, with version history, an access log and permission control. Keys are not stored on workstations. The Controller may itself order the replacement of its key from within the Platform. |
| Cryptographic erasure of data | Deletion of an organisation's key renders that organisation's encrypted data permanently unreadable, which makes it possible to carry out an erasure request without compromising the integrity of the backups. |
| Access control | Role-based permissions, checked on the server side with every request. Authentication through an external identity provider or through a one-time link sent to an email address. Passwords are not stored. |
| Separation of customer data | Every write and read is filtered by organisation identifier on the server side. The organisation identifier is determined from the user's session, never from data sent by the browser. Entitlement to the organisation is verified with every request, including for sessions established earlier. |
| Access by the Processor's personnel | No standing access to customer data. Access solely upon a request with a justification, following the customer's approval, limited in time and logged. Personal data is masked by default and its revealing is recorded. The customer may revoke access at any time. |
| Separation of environments | The production environment and the development environment have separate databases, separate keys and separate secrets. Non-production environments contain no real customer data — only synthetic data. The environment for security testing is created separately for the duration of such a test, on anonymised data, and is decommissioned once the test is complete. |
| Network | The database is accessible solely from a private network, without a public address. An allow-list of addresses for administrative access. Protection against denial-of-service attacks and a web application firewall at the network edge. |
| Data location | Platform data is stored in a data centre in Warsaw, Poland. |
| Backups | Automatic database backups performed once every 24 hours, retained for seven days. |
| Event logging | An activity log in the Platform containing the time, the user, the action and the internet protocol address. Accesses by the Processor's personnel to customer data are logged separately and are visible to the customer in the Platform. The Processor makes the remaining log records available to the customer on request. |
| Software development | Quality and security gates are run before every deployment. Automated scanning of libraries and of the application image for known vulnerabilities; detection of a vulnerability of medium or higher severity blocks the deployment until it is removed or a documented, named exemption is granted. |
| Vulnerability management | Publicly known vulnerabilities are removed by updating dependencies at the next deployment. Security reports are accepted at security@guardiso.com. |
| Personnel | The business is run single-handedly by the owner. A confidentiality commitment and the maintenance of information security competence within a certified management system. Any person admitted to processing in the future is subject to authorisation and to a confidentiality commitment before obtaining access. |
| Business continuity | A business continuity and recovery plan is maintained within the certified information security management system. The application runs in multiple instances; the database is operated as a managed service of the infrastructure provider. The scope of recovery is determined by the copies described in the "Backups" row — the Processor does not declare point-in-time recovery, because it has not confirmed that capability by a test. See also Part B. |
| Certification | The information security management system is certified as conforming to the ISO/IEC 27001 standard by TÜV NORD. The certificate is valid from 17 July 2026 to 16 July 2029. |
Part B. Limitations which the Processor states expressly
The Processor provides the information below so that the Controller can reliably assess the risk on its side and take it into account in its own data protection impact assessment. A commitment that the Processor is not able to keep today would be worse for the Controller than no commitment at all.
| Area | Actual state |
|---|---|
| Measurement of service availability | The Processor does not currently measure the availability of its own service and does not produce availability reports. Until such measurement is implemented, the Processor does not declare an availability figure in this Annex. |
| Recovery time from backup | The Processor has not so far carried out a documented test of restoring data from a backup and, for that reason, does not declare a guaranteed recovery time. Should recovery be needed, the Processor commences it promptly and informs the Controller of the progress. The result of the first restoration test carried out will be made available to the Controller on request. |
| Round-the-clock on-call cover | The Processor does not maintain round-the-clock on-call cover and does not maintain an incident response team. Matters are handled on business days. This has a direct bearing on the time taken to detect a breach and has been taken into account in the notification deadline in § 9(4). |
| Automatic failure alerting | The Processor does not currently maintain an alert collection system or automatic notification of an on-call person about a failure. Detection of an event occurs through the Processor's own observation or through a customer report. |
| Penetration tests | Penetration tests are carried out on request and before significant changes. The Processor does not commit to a regular cycle of such tests and does not declare their frequency. |
| Scale of operations | The business is run single-handedly. This means that there is no segregation of duties in the classic internal control sense. The compensating measures are the logging of actions, the restriction of access to customer data through a request-based procedure, and supervision by the certification body. |
The Processor undertakes to update Part B and to inform the Controller in accordance with the rules in § 14(2) once any of the above limitations ceases to apply.
Annex 2 — Sub-processors
The list is complete as at the date indicated in the heading of the Agreement. The "Entrusted Data" column indicates whether data covered by this Agreement is transferred to the entity in question, or only data in respect of which Guardiso is the controller — the latter are listed for the sake of full transparency.
| Entity | Role | Scope of data | Country of processing | Basis for transfer outside the EEA | Entrusted Data |
|---|---|---|---|---|---|
| Scaleway, S.A.S. | Application hosting, database, file storage | All data entrusted by the Controller: user accounts, documents, evidence, registers | Poland (Warsaw region) | The data does not leave the European Economic Area | Yes |
| Cloudflare, Inc. | Name server, protection against attacks, web application firewall, traffic statistics | Internet protocol addresses and headers of requests passing through the edge network. The content of requests is not stored | United States (edge network nodes also in the European Union) | Commission Implementing Decision (EU) 2023/1795 — EU–US Data Privacy Framework | Yes |
| Anthropic Ireland, Limited | Language model — Asystent Guardiso, generating draft documents and analyses | The content of the user's query and the organisation context submitted for analysis. Full registers and attachments are not transmitted | United States: the provider processes data on its servers in the United States. The party to the agreement for a customer in the European Economic Area is the company established in Dublin, Ireland | Standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, Modules Two and Three, incorporated by reference into the data processing agreement concluded with that entity | Yes |
| OpenAI Ireland Ltd. | Conversion of text into vectors for the purposes of searching the knowledge base | Fragments of document text converted into numerical vectors. The vectors do not allow the original to be reconstructed | United States: the provider processes data outside the European Economic Area. The party to the agreement for a customer in that area is the Irish company | Standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated into the data processing agreement concluded with that entity | Yes |
| Google Ireland Ltd. and Google LLC | Login with a Google account (identity provider) | The email address and first name from the Google account of the person logging in — only where the user selects that login method. We do not receive passwords | Ireland (the Google group also in the United States) | Commission Implementing Decision (EU) 2023/1795 — EU–US Data Privacy Framework | Yes |
| Plus Five Five, Inc. (the Resend service) | System email — login links, invitations, notifications | The recipient's email address, first name and surname, the content of the system message | United States: the provider states that its primary processing operations take place there and that stored data is held there. The eu-west-1 region we selected governs only where email is sent from, not where it is stored | Standard contractual clauses (Commission Implementing Decision (EU) 2021/914), Module Two, incorporated into the provider's data processing agreement. The provider additionally declares compliance with the EU–US Data Privacy Framework | Yes |
| Superlative Enterprises Pty Ltd (the Have I Been Pwned service) | Checking whether a company email address has appeared in a known data breach | The email address submitted for checking. We do not transmit or store passwords | United States: personal data is stored in a Microsoft Azure data centre in the Western United States. The entity's registered office is in the state of Queensland, Australia | Standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated by reference into the data processing agreement concluded with that entity | Yes |
| Stripe Payments Europe, Limited | Handling of payments and subscriptions | The Controller's billing data: company name, address, tax identification number, email address. Guardiso neither sees nor stores payment card data | Ireland (the Stripe group also in the United States) | Standard contractual clauses — Commission Implementing Decision (EU) 2021/914 | No — Guardiso is the controller of that data |
| Fakturownia sp. z o.o. | Issuing invoices | Purchaser's invoicing data: name, address, tax identification number | Poland | The data does not leave the European Economic Area | No — Guardiso is the controller of that data |
The current list is available in the Platform and in the Processor's trust portal. The Processor gives 30 days' advance notice of changes, in accordance with the rules described in § 7.