Last updated: 18 July 2026
This Data Processing Addendum ("DPA") forms part of the GUARD GRC Terms of Service between GUARD GRC L.L.C-FZ, Meydan Free Zone, Dubai, United Arab Emirates ("GUARD", "we", "us") and the organisation identified in the account registration ("Customer", "you"). It applies whenever Customer Content processed on the GUARD platform at guard.aigovernance.ae (the "Platform") includes personal data. No signature is required: the DPA applies automatically to every Customer. Customers who require a countersigned copy for their records may request one via our contact page.
If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
For personal data contained in Customer Content, the Customer is the controller and GUARD is the processor. The subject matter, duration, nature, and purposes of processing, the types of personal data, and the categories of data subjects are set out in Annex 1.
For personal data GUARD collects for its own purposes (account registration, billing, service communications, website enquiries), GUARD is the controller, and its Privacy Policy applies instead of this DPA.
GUARD processes personal data in Customer Content only on the Customer's documented instructions. The Customer instructs GUARD, through the Terms of Service and its use of Platform features, to process Customer Content to provide, secure, and support the Platform, including generating AI Outputs the Customer requests. GUARD will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing until instructions are clarified.
The Customer is responsible for the accuracy and lawfulness of the personal data it places on the Platform, including having a lawful basis to process the personal data of its employees, clients, and other data subjects it uploads.
GUARD ensures that every person it authorises to process Customer Content is bound by a contractual or statutory duty of confidentiality. Platform administrative access is scoped to system management; administrative interfaces do not expose customer governance content, as described in Annex 2.
GUARD implements and maintains the technical and organisational measures described in Annex 2, and keeps them under continuous review. GUARD may update Annex 2 from time to time, provided the overall level of protection is not reduced.
The Customer grants GUARD general authorisation to engage the sub-processors listed at aigovernance.ae/sub-processors, the single authoritative list for this DPA. GUARD will:
If the Customer reasonably objects to a new sub-processor on data protection grounds and the parties cannot resolve the objection, the Customer may terminate the affected Subscription and receive a pro-rata refund of any prepaid fees for the remaining term.
Taking into account the nature of the processing, GUARD will assist the Customer, through the export and deletion procedures described in Section 12 and through the support channel, in fulfilling the Customer's obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts GUARD directly about personal data in Customer Content, GUARD will refer the request to the Customer without undue delay and will not respond on the Customer's behalf except where legally required.
GUARD will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Content. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. GUARD will cooperate with the Customer's reasonable requests to support the Customer's own notification obligations. Notification is not an admission of fault.
Taking into account the nature of the processing and the information available to it, GUARD will provide reasonable assistance with the Customer's data protection impact assessments, transfer assessments, and consultations with supervisory authorities, where they relate to processing on the Platform.
Customer Content is stored on dedicated infrastructure in the United Kingdom. Processing by AI and email sub-processors takes place in the United States and the EU, as set out in the sub-processor list. GUARD ensures each transfer is subject to appropriate contractual safeguards consistent with Applicable Data Protection Law, including Articles 22 and 23 of the PDPL and, for DIFC Customers, the DIFC transfer regime, under which the United Kingdom is a recognised adequate jurisdiction. Where the EU or UK GDPR applies to the Customer, transfers to US sub-processors are covered by each provider's data processing agreement incorporating the EU Standard Contractual Clauses and, where relevant, the UK Addendum. On request, GUARD will provide the Customer with information reasonably necessary to assess these transfers.
GUARD makes the following available to demonstrate compliance with this DPA: this DPA and the sub-processor list, the GUARD Data Handling and Security Overview, and, for qualified evaluators under NDA, a detailed technical security brief. Where Applicable Data Protection Law grants the Customer a mandatory audit right that these materials do not satisfy, the Customer may conduct an audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, at its own cost, without access to other customers' data, and subject to GUARD's confidentiality and security requirements.
While the Subscription is active, the Customer can request an export of Customer Content at any time, provided in a structured, commonly used format. On termination, export and deletion of Customer Content follow the timelines in the Privacy Policy's retention schedule, and deleted data leaves rotating backups in the ordinary backup cycle thereafter, except where retention is required by law. Deletion of individual documents inside the Platform follows the Platform's managed lifecycle: removed records are withdrawn from availability immediately and permanently purged within 30 days.
The liability of each party under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA replaces any prior data processing terms between the parties for the Platform.
This DPA applies for as long as GUARD processes personal data in Customer Content and is governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai, with disputes subject to the exclusive jurisdiction of the courts of Dubai, UAE.
Subject matter. Provision of the GUARD AI governance platform: regulatory intelligence, risk and readiness assessment, policy and governance document generation, compliance recordkeeping, and related support.
Duration. The Subscription term, plus the export and deletion periods in Section 12.
Nature and purposes. Hosting and storage; retrieval and display; AI-assisted analysis and text generation requested by the Customer; team collaboration and access management; audit trail maintenance; export; deletion.
Categories of data subjects. The Customer's employees and other authorised users; the Customer's external consultants; individuals referred to in documents and records the Customer uploads, which may include employees, clients, suppliers, and other business contacts.
Types of personal data. User account details (name, business email, role); identity and contact details appearing in uploaded documents and text the Customer enters; personal data appearing in governance records the Customer creates, such as names of process owners, approvers, and assessors. The Platform is not designed or intended for special category data, and the Customer agrees not to upload it except where genuinely necessary for a governance record and lawful for the Customer to process.
The approved sub-processor list, naming each provider, the service it performs, the data it processes, and its location, is maintained in one place: aigovernance.ae/sub-processors (Section 6).
Questions about this policy? Get in touch