FeaturesAI AdvantagePricingCompareSecurity
Log InBook a Demo →
← All Policies UK GDPR Contract

UK Data Processing Agreement

Data processing framework for UK customers incorporating the UK International Data Transfer Agreement (IDTA).

Effective: April 1, 2026  ·  Applies to: UK customers  ·  Contact: legal@guardarra.com

This UK Data Processing Agreement is incorporated into the GuardArra Terms of Service and applies where GuardArra processes personal data on behalf of UK customers under the UK GDPR and Data Protection Act 2018.

1. Processor Obligations

GuardArra’s processor obligations mirror those in our EU DPA, adapted for UK requirements. GuardArra shall process personal data only on the Controller’s instructions, maintain appropriate security measures, assist with data subject rights, and notify of breaches without undue delay.

2. UK International Transfers

Transfers of personal data from the UK to the US are governed by the UK International Data Transfer Agreement (IDTA) issued by the ICO under Section 119A of the Data Protection Act 2018. By accepting these terms, UK customers execute the IDTA with GuardArra, LLC as the data importer.

3. Sub-Processors

See our Sub-Processor List. UK customers will be notified of sub-processor changes with 30 days notice.

4. Security

GuardArra implements appropriate technical and organizational measures consistent with Article 32 UK GDPR, including encryption at rest (AES-256-GCM), encryption in transit (TLS 1.3), access controls, 2FA, and audit logging.

5. Signed DPA

Contact legal@guardarra.com to request a signed copy of this DPA incorporating the IDTA, suitable for your compliance records.

6. ICO Registration

UK customers who are data controllers are responsible for their own ICO registration obligations. GuardArra as a US-based processor with no UK establishment is not required to register with the ICO.

← All Policies