Data Processing Agreement

Effective date: 9 October 2026 · Version 1.0

This agreement forms part of the customer's service agreement where RetailShield processes personal data for the customer. Controller: the customer identified in the accepted order. Processor: Sag Hussain trading as Retail Shield Group (a sole trader), 52 Woodlands Road, Middlesbrough TS1 3BW. Data protection law means applicable UK data protection and electronic-communications law, including the UK GDPR and Data Protection Act 2018 as amended.

1. Processing scope and instructions

The subject matter is hosting and operating the customer's RetailShield workspace. Processing continues during the service and the agreed return/deletion period. Its purpose is to maintain customer-directed operational records, enable authorised access and review, deliver agreed notifications and exports, and provide necessary support and security.

Operations include receiving, storing, organising, displaying, retrieving, transmitting, correcting, restricting and deleting data. Data subjects may include staff, managers, contractors, licence/DPS contacts and individuals necessarily mentioned in store records. Data categories include identifiers and work contacts, store/role assignments, check activity, training results, document details, incident/refusal records, permitted attachments and attributable audit history. Sensitive or offence-related information is included only where lawfully necessary within the agreed scope; excluded specialist uses require separate written agreement.

Documented instructions comprise the agreement, customer-selected settings and authorised support instructions. We process only on those instructions, including instructions concerning transfers, unless UK law requires otherwise; where permitted we notify you of that requirement before processing. We inform you promptly if we consider an instruction infringes applicable data protection law and pause the affected instruction where necessary while seeking clarification.

2. Customer obligations

You determine lawful purposes and grounds, provide required notices, maintain necessary special-category/offence safeguards and minimise data. You verify authority of people issuing instructions, configure appropriate access and retention and respond to rights requests. You inform us of relevant higher-risk requirements before upload. Instructions must not require us to breach law or disclose another customer's information.

3. Confidentiality and security

We ensure people authorised to process the data are bound by confidentiality duties. We implement risk-appropriate measures and maintain them during processing.

Control areaDescription
Transmission and stored dataEncrypted in transit (HTTPS) and at rest by our hosting platform
AuthenticationIndividual email sign-in with password recovery; sessions expire automatically
Customer isolationServer-side organisation and store permissions enforced in the database on every request, not only by hiding menus; platform administration is separated from customers' compliance records
Privileged/support accessLimited to named platform administrators, used only for support, security or legal work
Monitoring and auditChanges to compliance records are recorded automatically with the user and timestamp
Vulnerability managementSecurity scanning of the application and database configuration
Backups and recoveryManaged by our hosting platform; deleted data expires from backups within 90 days of active deletion
Incident responseCustomers are notified without undue delay after we become aware of a personal data breach involving their data — see clause 6
Staff and supplier controlsConfidentiality duties and contractual data-protection terms with suppliers
DeletionActive-system deletion within 60 days after the 30-day export window; deletion is reapplied if a backup is restored

We assess changes and do not materially reduce the agreed overall level of protection during a paid term without an appropriate lawful agreement and customer remedy.

4. Subprocessors

You give general written authorisation for the providers listed in our supplier register to process within their stated scope. Questions or objections can be sent through sagarhussain2020@gmail.com.

We give at least 30 days' prior notice of a proposed new or replacement subprocessor and a reasonable opportunity to object on documented data-protection grounds. We address the objection by a suitable alternative or agreed safeguards; if it cannot reasonably be resolved, you may terminate the affected service before the new processing begins and receive unused prepaid fees for that service. In an exceptional urgent replacement necessary to protect service or data, we notify you as soon as practical and preserve an effective objection/remedy route.

We contractually impose equivalent applicable data-protection duties and remain responsible to you for our subprocessor's performance of those duties. A generic supplier listing does not authorise unrestricted onward use.

5. Transfers

We do not carry out restricted transfers without documented instructions and a valid legal mechanism. Where required, we execute the appropriate transfer terms and complete relevant assessments with supplementary protections. We provide information necessary for you to assess the arrangement. A customer's staff accessing their own workspace abroad and a processor engaging an overseas supplier are assessed according to their actual legal roles; neither is described inaccurately as universally prohibited or exempt.

6. Assistance and personal data breaches

Taking account of the nature of processing and information available, we assist with rights requests, security obligations, breach assessment and notifications, impact assessments and prior regulatory consultation. If contacted directly about customer-controlled data, we notify you promptly and do not respond substantively except on instructions or where legally required.

We notify your designated incident contact without undue delay after becoming aware of a personal data breach involving your data. Our operational target is an initial notice within 24 hours of awareness; this does not permit delay beyond the legal duty. Initial notice is not postponed until an investigation is complete.

We provide available details of the nature and likely impact, affected information/people, relevant contact and containment/remedial steps, with updates as information develops. We preserve relevant evidence proportionately and cooperate with your notifications. You retain responsibility for controller decisions; we do not make a public statement identifying you without authorisation unless legally required.

Ordinary compliance assistance is included to a reasonable extent. Substantial bespoke work may require agreed reasonable charges, but no charge excuses required processor assistance or makes correction of our own breach conditional on payment.

7. Demonstrating compliance and audits

We provide information reasonably needed to demonstrate compliance with these processor duties and allow and contribute to relevant audits and inspections by you or your appointed auditor. We may initially provide suitable reports or documentation to reduce duplication, but this does not extinguish a necessary inspection right.

Audits are proportionate, preserve other customers' confidentiality and avoid unnecessary disruption. Reasonable notice and confidentiality arrangements apply except where an urgent incident, reasonable evidence of non-compliance or regulator requirement justifies otherwise. Costs are agreed reasonably; access is not obstructed by prohibitive charges. We bear reasonable remedial costs attributable to our material breach. We keep records where required by law.

8. Return, deletion and survival

At your choice on service end, we return or delete personal data and delete existing copies except to the extent UK law requires retention. You communicate your choice through the documented exit route; the standard exit process offers both options. The export window is 30 days, with active-system deletion within 60 days after that window, mirrored in the privacy notice and termination notice.

Retained legal copies remain restricted and protected. Backups expire within 90 days of active deletion, are isolated from normal use and subject to re-deletion after restoration. We provide reasonable written confirmation of completed deletion on request, identifying any lawful exceptions. An outstanding invoice does not justify indefinite retention or withholding legally required assistance.

Confidentiality, security and transfer safeguards continue for as long as we retain the data. Contractual caps do not reduce processor duties, regulators' powers or individuals' statutory rights.

Operated by Sag Hussain trading as Retail Shield Group (a sole trader), 52 Woodlands Road, Middlesbrough TS1 3BW. Related documents: Privacy Policy · Business Terms · Data Processing Agreement · Suppliers · Contact