Data Processing Agreement
Last updated 5 October 2026 · version 2026-10-05
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Velkeep ("Processor") and the customer ("Controller"). It sets out the terms required by Article 28 of the UK GDPR for our processing of Customer Data.
1. Subject matter and duration
The Processor processes Customer Data to provide Velkeep for as long as the customer's account is open, and afterwards only to return or delete it as set out below.
2. Nature and purpose
Storing, organising, displaying, transmitting and deleting records of security work: asset photos, check and check-in records, shifts, rotas, incidents and the related user accounts, and sending alerts and emails about them.
3. Personal data and data subjects
- Data subjects: the Controller's staff (guards, managers and administrators) and people who may appear in photos.
- Data: names, usernames, contact details, photos, location (GPS coordinates and accuracy at the time of a check), times of shifts, checks and check-ins, rota information, incident notes, device and sign-in information.
- No special category data is required; the Controller should not upload it.
4. Processor obligations
The Processor will:
- process Customer Data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of the service, unless the law requires otherwise (in which case it will tell the Controller first where allowed);
- make sure everyone authorised to process Customer Data is bound by confidentiality;
- apply appropriate technical and organisational security measures (Annex B);
- help the Controller respond to data subject requests and with security, breach notification, impact assessments and consultation with the ICO, taking into account the information available to it;
- notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data, with the information the Controller needs;
- make available the information needed to show compliance with this DPA and allow for reasonable audits, normally by providing written answers and certifications;
- at the end of the service, delete or return Customer Data at the Controller's choice (an export is available on request within 30 days), and delete remaining copies within 90 days unless the law requires storage.
5. Sub-processors
The Controller gives general authorisation for the sub-processors listed in Annex A. The Processor will give at least 30 days' notice by email of any new sub-processor, so the Controller can object on reasonable data protection grounds; if the objection cannot be resolved the Controller may cancel. The Processor imposes data protection terms on each sub-processor that are no less protective than this DPA and remains responsible for them.
6. International transfers
Where Customer Data is transferred outside the UK, the Processor ensures a lawful transfer mechanism is in place, such as UK adequacy regulations or the UK International Data Transfer Agreement or Addendum.
7. Controller obligations
The Controller is responsible for the lawfulness of the processing it instructs, including having a lawful basis, giving its staff clear privacy information about monitoring and location tracking at work, and only monitoring during working time.
Annex A: Sub-processors
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting of the app and website, network security | Worldwide edge network (USA company) |
| Neon (Databricks, Inc.) | Database hosting | London, United Kingdom |
| Cloudinary Ltd. | Storage and delivery of photos | USA / EU |
| Stripe Payments UK Ltd / Stripe, Inc. | Card payments and invoicing data | UK / USA |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | PayPal payments | EU / USA |
| Our email provider (for example Zoho Corporation) | Sending account and alert emails | EU / UK / India / USA |
| tawk.to, Inc. | Live chat on our website and for agency managers, when switched on (chat messages and the details you give) | USA / worldwide |
| Google, Apple and Mozilla push services | Delivering phone alerts (alerts carry no message content) | USA |
Annex B: Security measures
- Encryption in transit (HTTPS/TLS) for all traffic; secrets and keys encrypted at rest.
- Passwords stored as salted PBKDF2 hashes; sign-in rate limiting and lock-out; two-factor sign-in for managers and mandatory for platform administrators.
- Strict separation of each customer's data, tested automatically.
- Sessions that can be revoked at once; automatic sign-out on password change.
- Audit log of sign-ins and important changes.
- Photos limited to the customer's own storage folder and signed uploads.
- Database backups and point-in-time recovery from the hosting provider.