Data Processing Agreement

Version 1.1 · In force from 8 October 2026

You do not need to sign this, and you do not need to ask us for it. This agreement applies automatically to every account from the moment you accept our Terms of Service, and it is part of them. It is published here as its own document because a procurement or data-protection review needs something it can read, file and attach - not a clause buried in a longer contract.

If your own policy requires a signed copy, or your organization has its own form of DPA, email contact@walterssentinel.com and we will sign. We do not charge for that and we do not put it behind a sales conversation.

1. Who this is between

This agreement is between Lewis Walters, a sole trader trading as Walters Sentinel, based in the United Kingdom (the processor, "we", "us") and the customer who holds the account (the controller, "you").

It governs our processing of personal data that you put into the services, about other people: your customers, the people you send documents to, the people who raise tickets with you, and your own staff. Annex 1 lists it.

It does not govern the data we hold about you as our own customer - your account, your sign-ins, your billing and your messages to us. For that we are the controller ourselves, and our Privacy Policy explains it.

2. What each of us is responsible for

You decide what personal data goes into the service and why. You confirm that you have a lawful basis for it, that you have told the people concerned what they need to know, and that you are entitled to give it to us to process.

We process it only to provide the service to you, and only on your instructions. Your instructions are these Terms, this agreement, and the way you configure the service. We will not use your data to train models, to build any product, for advertising, or for any purpose of our own. If we ever believe an instruction of yours would breach data protection law, we will tell you and may pause that processing rather than carry it out.

3. Our obligations

These are the commitments required of a processor under Article 28 of the UK GDPR and the EU GDPR, written out so that each one can be checked:

  1. Only on your instructions. We process your data only as described in section 2, and never for our own purposes.
  2. Confidentiality. Everyone with access to your data is bound by confidentiality. Access is limited to what is needed to run and support the service.
  3. Security. We protect your data with the technical and organisational measures in Annex 3, appropriate to the risk.
  4. Sub-processors. We use only the sub-processors on our published list, we hold each of them to obligations equivalent to these, and we remain responsible to you for what they do. You give general authorisation for those listed, and we will give you at least 30 days' notice before adding another, with a right to object - the process is set out on that page.
  5. Helping with people's rights. If somebody exercises their rights over data you hold here, the tools to find, correct and delete it are in the service itself, and everything in your organization can be exported as a single machine-readable file from its settings - no request, no fee, no sales conversation. Where the service cannot do what you need, we will help within reason and without extra charge.
  6. Breach notification. If we become aware of a personal data breach affecting your data we will tell you without undue delay and in any event within 48 hours, with what we know, what we are doing and what we advise. We will not wait for the picture to be complete before telling you.
  7. Assistance. We will help, within reason, with your data protection impact assessments, your own security reviews and any consultation with a regulator, so far as it concerns processing we carry out for you.
  8. Deletion and return. When you delete data, or delete the organization it belongs to, it is destroyed immediately and permanently - not hidden, and not kept in an archive. Deleting an organization also cancels any subscription on it, so nothing is charged for something that no longer exists. When this agreement ends you may export everything first, using the same button; after that we delete it, save for the sales records UK tax law requires us to keep for six years, which are stripped of anything identifying a person. A paid plan ending does not itself delete anything.
  9. Demonstrating compliance. We will make available the information reasonably needed to show that we meet these obligations, and allow an audit as section 5 describes.

4. Transfers out of the UK and the EEA

The service runs on servers in London. Where a sub-processor processes data outside the UK or the EEA, the transfer is covered by the UK International Data Transfer Addendum to the Standard Contractual Clauses, by the Standard Contractual Clauses themselves, or by an adequacy decision, depending on the supplier and the country. Our sub-processor list says which suppliers those are, and we will provide the paperwork for any of them on request.

5. Audit

You may ask us to demonstrate compliance with this agreement once in any twelve-month period, and again after a breach affecting your data. In the first instance we will answer in writing, which for most reviews is what is actually wanted: send us your security questionnaire and we will complete it, free, rather than returning a certificate that answers a different question.

Where writing is genuinely not enough, we will arrange a remote session at a reasonable time with reasonable notice. We will not use a non-disclosure agreement, a fee, or a sales process as a condition of any of this. What we cannot do is give access that would expose another customer's data, and we will say so rather than refuse vaguely.

We are a small business and we would rather tell you that plainly than imply certifications we do not hold. We hold no ISO 27001 certificate and no SOC 2 report. Annex 3 is what we actually do, written so you can judge it yourself.

6. Liability, and how this fits the Terms

This agreement forms part of our Terms of Service. The limits of liability in section 10 of those Terms apply to it. Where this agreement and the Terms conflict on the handling of personal data covered here, this agreement wins. It lasts as long as we process your data, and the obligations that are meant to survive it - confidentiality, deletion - do.

If we change this agreement in a way that materially affects you, we will email you rather than rely on you noticing, and the version and date at the top of this page will change.

Annex 1. What is processed, and about whom

The service only holds what you put into it, so this depends on which services you use. In full:

Categories of people

Categories of data

ServiceWhat it may hold about those people
Monitoring, Status PagesCheck results for the addresses you monitor, and whatever you write in incident updates. Credentials you give us for your own systems, encrypted with AES-256-GCM and never shown back to anyone.
Mail ShieldIP addresses and host names of mail servers sending as your domain, from DMARC reports you upload.
SignDocuments you upload; each signer's name and email; their signature image, the name they typed, when they opened and signed, the IP address and browser they used, and any reason for declining.
DeskNames, email addresses and messages from people who contact you, plus your team's replies and internal notes.
BookingsNames, email addresses, phone numbers, notes and appointment times.
FormsWhatever your own questions ask for, plus a one-way hash of the responder's IP address to spot abuse.
People, leave and HRNames, contact details, job titles, start dates, emergency contacts, notes, holiday allowances and leave records.
AssetsWhich person holds which device, and when it was issued or returned.
Comply, risks, incidents, handbookPolicy and register content, and the names of people you assign items to or record as involved.
Certificates, Trust Centre, trainingWho completed which training and when, and what you choose to publish.

Special category data

The service is not designed for special category data, and nothing in it asks for any. Two places can nonetheless receive it from you, so they are called out rather than left to be discovered: leave records can include sickness absence, which is health data, and a form you write yourself can ask any question you choose. Where you put such data in, you decide the Article 9 condition that permits it, and we process it under this agreement like everything else.

Purpose and duration

The purpose is to provide the services you have bought, and nothing else. Processing lasts while your account is open and, for each item, until you delete it or delete the organization it belongs to. Retention periods are set out in section 6 of the Privacy Policy.

Annex 2. Sub-processors

The authorised list, what each handles and where, is published and kept current at walterssentinel.com/legal/subprocessors. It is maintained as a page rather than reproduced here so that there is one authoritative version and no stale copy to reconcile.

Annex 3. Security measures

What we actually do, rather than a list of words:

AreaMeasure
In transitHTTPS everywhere, with HTTP redirected. Connections to the database and to every supplier are encrypted.
PasswordsStored as a one-way hash with a per-password salt. We cannot read yours, and neither can anybody who obtained the database.
Your systems' credentialsCredentials you give us so we can monitor something behind a login are encrypted with AES-256-GCM before storage, are never returned to a browser once saved, and are not readable in any interface, including ours.
Access controlEach organization's data is reachable only by its own members, and each member only at the role you give them. Permissions are checked on every request on the server, never in the browser.
Sign-inEmail and password, or a one-time code emailed to you. Passwords are checked server-side with a deliberately slow hash, so guessing is expensive. Sessions are per-browser, can be ended one at a time, and all end at once when a password changes.
Administrative accessOne named person, on a separate administrative surface, over an authenticated session. Server access is by SSH key only - passwords are disabled.
Audit trailAdministrative and security-relevant actions are written to a hash-chained log, so that an entry cannot be altered or removed without breaking the chain. The chain can be verified on demand.
Abuse and rate limitingSign-in, sign-up, code and API requests are rate limited per account and per address. Repeated failures lock an account rather than allow a guessing attempt to continue.
SeparationDevelopment and testing run against a separate database. Live customer data is not copied into either.
BackupsTwo independent copies. Our database provider keeps its own, and we take our own nightly backup of the entire database to a separate machine in London, held for 30 days. A provider's copies protect against their hardware failing and against nothing else, which is why we do not rely on them alone.
Backups that are known to workEvery night, immediately after the backup is taken, it is automatically restored into an empty database and compared against the live one table by table - including the audit log, which verifies its own hash chain. If anything fails to come back, we are emailed. An untested backup is an assumption, and this is the step that is normally skipped.
DeletionDeleting an item or an organization destroys it immediately rather than hiding it, and the deletion reaches backups as they age out. Tested by deleting: our release checks create an organization, fill it, delete it, and then assert that nothing of it is left anywhere in the database.
Getting your data outOne button, in the organization's own settings, produces everything in it as JSON. Secrets - signing links, portal tokens, webhook secrets, API keys, the credentials you gave us for your own systems - are withheld by default rather than listed, so a copy of your data is not also a way into it.
Change controlEvery release is checked by an automated suite of several hundred assertions covering access control, permissions, billing and data handling before it is deployed.
SuppliersKept to the short published list, each bound to equivalent obligations, each chosen so that the core of the service stays in the UK.
Data minimisationWe do not run analytics that follow people, we set no advertising or third-party cookies, and we count visits only as a daily total per country with nothing that points at a person.

Where a measure is a plan rather than a fact, it is not in this table.

Contact

For anything about this agreement, a signed copy, a security questionnaire or transfer paperwork: contact@walterssentinel.com.