Preamble
This Data Processing Agreement ("DPA") supplements the GMC Guardian Terms of Service and applies to merchants using GMC Guardian whose end customers are located in the European Economic Area, the United Kingdom, or Switzerland.
1. Definitions
- Data Controller: you (the merchant), determining the purposes and means of processing personal data.
- Data Processor: GMC Guardian, processing personal data on your behalf. Full corporate identification of the operating entity is available on request to [email protected].
- Personal Data: any data relating to an identified or identifiable natural person, as defined in GDPR Article 4.
2. Subject and duration
The Processor processes Personal Data of merchants only - not of merchants' end customers - to deliver the GMC Guardian service for the duration of the Controller's subscription.
3. Nature and purpose of processing
Processing operations include: storage of authentication tokens, scan execution, reinstatement report generation, AI-driven feed correction proposals, email notifications, and audit logging - strictly limited to what's required to deliver the contracted service.
4. Categories of data subjects and personal data
Data subjects: the merchant (shop owner) and authorized agency users.
Personal data categories: business identity (name, email, address, phone), authentication tokens (encrypted), scan results, audit log entries (IP, user agent, action, timestamp).
The Processor does not process Personal Data of the merchant's end customers (shoppers).
5. Sub-processors
The Controller authorizes the use of the sub-processors listed at /trust. The Processor will update that list before a new sub-processor begins processing. The Controller may object on legitimate grounds, in which case the Processor will offer a commercially reasonable alternative or, failing that, allow termination of the affected service.
6. International transfers
Where Personal Data is transferred outside the EEA, the Processor relies on Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework where applicable.
7. Security measures
The Processor implements appropriate technical and organizational measures, including:
- Encryption at rest of all authentication tokens (libsodium AEAD)
- TLS 1.3 in transit
- Append-only audit log
- Access control with role separation (operator / admin / merchant)
- Regular security audits and dependency scanning
- Incident response procedures with 72-hour breach notification commitment
8. Data subject rights
The Processor will assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability, restriction, objection) within 14 days of receipt.
9. Audits
The Controller may, at their cost and with 30 days' notice, audit the Processor's compliance with this DPA - by remote questionnaire, by review of independent third-party certifications (SOC 2 Type II, once obtained), or by on-site visit when justified.
10. Breach notification
The Processor will notify the Controller of any Personal Data breach without undue delay and in any event within 72 hours of becoming aware, providing all information necessary for the Controller to comply with their own notification obligations under GDPR Article 33.
11. Return or deletion
On termination, the Processor will delete or return all Personal Data within 30 days, except where retention is required by law (e.g., audit log retention obligations).
12. Liability
This DPA is governed by the GMC Guardian Terms of Service liability clauses.
13. Contact
For data protection inquiries, email [email protected].