All legal documents

Data Processing Agreement

The Article 28 terms that apply when we process personal data on a customer's behalf. Mandatory, and it forms part of the contract.

Version 1.0 · Effective 6 August 2026 · Last updated 6 August 2026

This Agreement is incorporated into the Terms of Service and applies whenever we process personal data on behalf of a subscribing organisation. The Customer is the controller. Care Shield Compliance (Africa Procurement Group Ltd) is the processor.

It is written to satisfy Article 28(3) of the UK GDPR. It does not need to be signed separately: accepting the Terms accepts this. A countersigned copy is available on request for customers whose own governance requires one.

1. Subject matter and duration

We process the Customer's personal data to provide the Service, for as long as the subscription lasts and for the 30-day export window after it ends.

2. Nature and purpose of processing

Hosting, storage, retrieval, structuring, display, export and deletion of records the Customer creates or uploads, and transmission of notifications to the Customer's own users. We do not use the Customer's personal data to train models, to build products, or for any purpose of our own.

3. Types of personal data

  • Staff data: names, work contact details, roles, training and acknowledgement records, supervision and competence notes the Customer chooses to record.
  • Data about people the Customer supports, where the Customer enters it: names or initials, room or reference identifiers, and the content of risk assessments, incident and audit records.
  • Special category data, where the Customer enters it: health and care information, and information capable of revealing disability. The Customer decides what to enter.
  • Uploaded files and evidence attachments, whose contents the Customer controls.

The Service does not require identifiable resident data to work. Risk assessments, incident records and audits can be recorded against initials or a reference. We recommend that, and the demonstration data is written that way deliberately. Minimising what goes in is the single most effective control available to the Customer, and it is the Customer's to exercise.

4. Categories of data subject

  • The Customer's employees, workers, volunteers and agency staff.
  • People the Customer supports, and their relatives or representatives where recorded.
  • Visiting professionals named in records.

5. Our obligations

  1. 1.We process only on the Customer's documented instructions, which include use of the Service's features. Where we are required by law to process otherwise, we will tell the Customer first unless the law forbids it.
  2. 2.Everyone we authorise to process the data is bound by a duty of confidentiality that survives the end of their engagement.
  3. 3.We implement the technical and organisational measures described in the Security Statement, appropriate to the risk, and keep them under review.
  4. 4.We assist the Customer, taking into account the nature of processing and the information available to us, with data subject requests, with security obligations, with breach notification, and with data protection impact assessments and prior consultation.
  5. 5.At the Customer's choice we delete or return the personal data at the end of the contract, and delete existing copies unless law requires retention. Our default is deletion after the 30-day export window.
  6. 6.We make available the information needed to demonstrate compliance with Article 28 and allow for and contribute to audits — see section 9.
  7. 7.We tell the Customer immediately if, in our opinion, an instruction infringes data protection law.

6. Sub-processors

The Customer gives general authorisation for us to appoint sub-processors. The current list, what each does and where it processes, is published in the Sub-processors document.

We will give at least 30 days' notice by email and on that page before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro-rata refund of Charges paid for the unexpired term — an express exception to the no-refund rule in the Terms.

We impose on every sub-processor obligations no less protective than these, and we remain fully liable to the Customer for their performance.

7. International transfers

Primary hosting is in the United Kingdom and the European Economic Area. Where a sub-processor processes outside the UK we rely on UK adequacy regulations or, failing that, on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. We will not transfer the Customer's personal data outside the UK without one of those safeguards in place.

8. Personal data breaches

We will notify the Customer without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting their data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide everything at once we will provide it in phases without further undue delay.

The Customer, as controller, decides whether to notify the ICO within 72 hours and whether to tell the individuals concerned. That decision is not ours to make and we will not make it for them — but we will give them what they need to make it, quickly, and in writing.

The full procedure is in the Security Incident and Breach Response document.

9. Audit

On reasonable written notice, no more than once in any twelve months unless a breach or a regulator requires otherwise, we will respond to a written security questionnaire and provide our current security documentation. Customers completing the NHS Data Security and Protection Toolkit may use that material as supplier evidence.

An on-site or hands-on audit may be conducted at the Customer's cost, during business hours, subject to confidentiality, and arranged so that it does not compromise the security or confidentiality of other customers' data.

10. Liability

The limitation of liability in the Terms of Service applies to this Agreement, save that nothing here limits liability that cannot be limited by law.

Stated plainly because it is often misunderstood: a contractual cap between us governs claims between us. It has no effect on a data subject's right to bring a claim under Article 82 of the UK GDPR, or on a regulator's power to act against either party. Neither of us can contract that away, and neither of us should present the contract as though we had.

11. Order of precedence

If this Agreement conflicts with the Terms of Service on the processing of personal data, this Agreement prevails.

Contact for anything in this Agreement: hello@careshieldcompliance.co.uk.

Care Shield Compliance is a division of Africa Procurement Group Ltd, registered in England and Wales, company number 10553435. Registered office: Devonshire House, One Mayfair Place, London, England, W1J 8AJ. Questions about this document: hello@careshieldcompliance.co.uk.