Data Processing Agreement

Last updated 5 October 2026 · version 2026-10-05

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Velkeep ("Processor") and the customer ("Controller"). It sets out the terms required by Article 28 of the UK GDPR for our processing of Customer Data.

1. Subject matter and duration

The Processor processes Customer Data to provide Velkeep for as long as the customer's account is open, and afterwards only to return or delete it as set out below.

2. Nature and purpose

Storing, organising, displaying, transmitting and deleting records of security work: asset photos, check and check-in records, shifts, rotas, incidents and the related user accounts, and sending alerts and emails about them.

3. Personal data and data subjects

  • Data subjects: the Controller's staff (guards, managers and administrators) and people who may appear in photos.
  • Data: names, usernames, contact details, photos, location (GPS coordinates and accuracy at the time of a check), times of shifts, checks and check-ins, rota information, incident notes, device and sign-in information.
  • No special category data is required; the Controller should not upload it.

4. Processor obligations

The Processor will:

  • process Customer Data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of the service, unless the law requires otherwise (in which case it will tell the Controller first where allowed);
  • make sure everyone authorised to process Customer Data is bound by confidentiality;
  • apply appropriate technical and organisational security measures (Annex B);
  • help the Controller respond to data subject requests and with security, breach notification, impact assessments and consultation with the ICO, taking into account the information available to it;
  • notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data, with the information the Controller needs;
  • make available the information needed to show compliance with this DPA and allow for reasonable audits, normally by providing written answers and certifications;
  • at the end of the service, delete or return Customer Data at the Controller's choice (an export is available on request within 30 days), and delete remaining copies within 90 days unless the law requires storage.

5. Sub-processors

The Controller gives general authorisation for the sub-processors listed in Annex A. The Processor will give at least 30 days' notice by email of any new sub-processor, so the Controller can object on reasonable data protection grounds; if the objection cannot be resolved the Controller may cancel. The Processor imposes data protection terms on each sub-processor that are no less protective than this DPA and remains responsible for them.

6. International transfers

Where Customer Data is transferred outside the UK, the Processor ensures a lawful transfer mechanism is in place, such as UK adequacy regulations or the UK International Data Transfer Agreement or Addendum.

7. Controller obligations

The Controller is responsible for the lawfulness of the processing it instructs, including having a lawful basis, giving its staff clear privacy information about monitoring and location tracking at work, and only monitoring during working time.

Annex A: Sub-processors

ProviderWhat forWhere
Cloudflare, Inc.Hosting of the app and website, network securityWorldwide edge network (USA company)
Neon (Databricks, Inc.)Database hostingLondon, United Kingdom
Cloudinary Ltd.Storage and delivery of photosUSA / EU
Stripe Payments UK Ltd / Stripe, Inc.Card payments and invoicing dataUK / USA
PayPal (Europe) S.à r.l. et Cie, S.C.A.PayPal paymentsEU / USA
Our email provider (for example Zoho Corporation)Sending account and alert emailsEU / UK / India / USA
tawk.to, Inc.Live chat on our website and for agency managers, when switched on (chat messages and the details you give)USA / worldwide
Google, Apple and Mozilla push servicesDelivering phone alerts (alerts carry no message content)USA

Annex B: Security measures

  • Encryption in transit (HTTPS/TLS) for all traffic; secrets and keys encrypted at rest.
  • Passwords stored as salted PBKDF2 hashes; sign-in rate limiting and lock-out; two-factor sign-in for managers and mandatory for platform administrators.
  • Strict separation of each customer's data, tested automatically.
  • Sessions that can be revoked at once; automatic sign-out on password change.
  • Audit log of sign-ins and important changes.
  • Photos limited to the customer's own storage folder and signed uploads.
  • Database backups and point-in-time recovery from the hosting provider.