This Data Processing Agreement (“DPA”) is the document our Terms of Service (§6.3) and our GDPR Statement refer to when they describe processing carried out under a Data Processing Agreement. It sets out our obligations as a processor wherever the Subscriber is the controller of personal data processed through our products.
1. Parties and how this DPA is incorporated
This DPA is between the Subscriber (as defined in the Terms of Service) and Friam Limited, a company registered in England and Wales under company number 14219476, with its registered office at 164–170 High Street, Crowthorne, England, RG45 7AT (“Friam”, “we”, “us”, “our”).
Terms of Service §6.3 states that our processor obligations are set out in this Data Processing Agreement, and that it forms part of the Terms of Service by reference. This document is that Data Processing Agreement (the full defining clause is quoted in Section 2 below). It forms part of, and is incorporated into, the Terms of Service, and it applies automatically, with no separate signature required, to every Subscriber from the point the Subscriber’s use of the Services described in Section 3 below begins, in the same way the Terms of Service themselves apply on use of the Services (Terms §1). Where a Subscriber needs a signed or countersigned copy for its own records, contact legal@everyguard.uk.
2. Roles: who is controller, who is processor
Terms of Service §6.3 sets out the roles that apply to personal data processed through the Services, and this DPA adopts that definition word for word:
“Where the Subscriber processes an end-customer’s personal data through the product — for example a CDD check, or feedback submitted through a Subscriber’s form — the Subscriber is the data controller and we are the data processor. … Where we decide the purposes and means of processing (for example, our own customer records and the public-source data described in Section 17), we are the controller, and our Privacy Policy and Data Collection Policy apply.”
In short: for the personal data described in Section 3 below, the Subscriber is the controller and Friam is the processor. This DPA governs that relationship only. Where Friam decides the purposes and means of processing (Friam’s own customer and account records, and the public-source business data described in Terms §17), Friam is the controller, and the Privacy Policy and Data Collection Policy apply instead of this DPA.
3. Subject matter, duration, nature and purpose of processing
This DPA covers the following processing activities Friam carries out on the Subscriber’s documented instructions, by product family:
3.1 Identity verification and screening (customer due diligence)
Subject matter: verifying the identity of an end-customer the Subscriber is dealing with, and screening that end-customer against sanctions and PEP lists, so the Subscriber can meet its own customer due-diligence duties (Terms §5, §11). Nature: capture and matching of identity documents and a biometric selfie, sanctions/PEP list screening, and production of a dated audit pack recording what was checked and found (Terms §6.1, §11.2). Purpose: solely to perform and evidence the check the Subscriber instructed (Privacy Policy §3.4); never for advertising, profiling, or any other purpose. Duration: for the length of the Subscription, and for the further period described in Section 8 below.
3.2 Forms (for example, guest feedback)
Subject matter: capturing feedback an end-customer submits through a Subscriber’s feedback form or QR card. Nature: storage of the end-customer’s name, contact details and message so the Subscriber can see, reply to, and resolve the issue raised (Privacy Policy §3.1). Purpose: solely to deliver that feedback to the Subscriber; never used for marketing or shared beyond the Subscriber. Duration: for as long as the Subscriber’s account holds the record.
3.3 Compliance logs, diaries and workforce tools
Where the Subscriber’s product includes logbooks, diaries, rotas, hours records or similar record-keeping tools, Friam provides the recording and evidencing machinery (timestamping, tamper-evident history, reminders and export) over records the Subscriber’s team enters (Terms §15). The accuracy and completeness of what is recorded remains the Subscriber’s responsibility, and this processing runs for the length of the Subscription.
4. Categories of data subjects and personal data
Data subjects: end-customers the Subscriber runs a customer due-diligence check on, and end-customers (for example guests) who submit feedback through a Subscriber’s form (Terms §5 definitions; Privacy Policy §3.1, §3.4).
Categories of personal data (Privacy Policy §3.4; GDPR Statement §3):
- Identity data: full name, date of birth, and nationality
- Images of the identity document(s) provided (for example a passport photo page, or a driving licence front and back), and the data extracted from them
- For passport NFC reads: the machine-readable-zone fields, the cryptographic hashes of the chip data groups, and the passive-authentication result
- Feedback content: an end-customer’s name, contact details and message, where the product includes a feedback form
- The decision recorded by the Subscriber (clear/proceed, review, decline/SAR) and the Subscriber’s reasoning
- The audit pack evidencing what was screened and what was found
Special category and criminal-offence-related data. A liveness selfie is compared against the identity document and, where read, the passport chip photo, to confirm the customer is the genuine document holder. This face-matching is processing of special-category biometric data under Article 9 UK GDPR. Sanctions and PEP screening matches and corroborating attributes are treated as criminal-offence-related data under Article 10. Our GDPR Statement §4 table states, of this processing, that “the Article 9 / 10 condition is substantial public interest — preventing money laundering (Sch 1, DPA 2018) — tied to your MLR 2017 obligations” (quoted here verbatim; “your” there means the Subscriber, as the GDPR Statement addresses the controller directly).
5. The Subscriber’s instructions and obligations
5.1 Documented instructions
The Subscriber instructs Friam to process personal data under this DPA by:
- Initiating and running a customer due-diligence check, or enabling a feedback form, through the product (Terms §6.1, §11)
- Instructing Friam to retain a record for longer than the regulatory floor described in Section 8 (Terms §18 records that Friam will retain data “for the retention floor the Subscriber’s regime requires… and longer where the Subscriber instructs”)
- Requesting deletion of a record, which Friam will action once any retention floor that applies to that record has expired (Privacy Policy §9)
5.2 The Subscriber’s own obligations
As the controller for this processing, the Subscriber is responsible for:
- Having a lawful basis under Article 6 (and, where special category or criminal-offence data is involved, an Article 9/10 condition) for the checks it instructs
- Its own transparency to the end-customer about the check; the Subscriber’s decisions and reasoning remain its own responsibility (Terms §11.2, §11.3)
- Its own record-keeping duty under regulation 40 of the Money Laundering Regulations 2017 (“MLR 2017”), which is a legal obligation on the Subscriber’s business, not on Friam (Privacy Policy §9)
- Using screening and verification features only for genuine due-diligence purposes, never as a general people-search tool (Terms §11.1)
6. Friam’s processor obligations
As processor, Friam agrees to the following, one clause per limb of Article 28(3) UK GDPR:
6.1 Instructions only
Friam processes personal data covered by this DPA only on the Subscriber’s documented instructions (Section 5.1), including in relation to international transfers, unless required to do otherwise by UK law, in which case Friam will inform the Subscriber of that legal requirement first, unless the law prohibits this.
6.2 Confidentiality
Friam ensures that people authorised to process the data are subject to confidentiality obligations. Our Information Security Overview describes least-privilege, need-to-know access controls, and that where we engage staff or contractors with access to sensitive data we put confidentiality obligations in place, set clear security responsibilities, and grant access on a least-privilege basis (ISMS Overview §5.1, §7).
6.3 Security (Article 32)
Friam implements the technical and organisational measures described in our Information Security Overview and summarised in “How we keep your data safe” on the Legal & Trust Centre: encryption of data in transit (TLS 1.2+) and at rest (AES-256); role-based, least-privilege access controls; magic-link authentication for end-user logins, with account passwords hashed with bcrypt; cryptographic hashing of signed compliance documents and audit packs so any tamper is detectable; automated daily database backups with point-in-time recovery; and incident response procedures aligned with the UK GDPR 72-hour ICO notification rule. Our primary infrastructure runs on Amazon Web Services in the London region (eu-west-2), giving UK data residency for the large majority of the personal data we hold. We state no more than those pages state: we have not pursued formal ISO 27001 certification, and apply these controls proportionately to our size and risk as an early-stage company.
6.4 Sub-processors
The Subscriber gives Friam general written authorisation to engage the sub-processors listed in Section 7 below. Friam will tell the Subscriber of any intended addition or replacement of a sub-processor before that change takes effect, giving the Subscriber the opportunity to object on reasonable data-protection grounds. Friam remains liable to the Subscriber for a sub-processor’s performance of the obligations it is engaged to carry out, and imposes data-protection terms on each sub-processor that are no less protective than this DPA.
6.5 Assistance with data-subject rights
Friam will assist the Subscriber, by appropriate technical and organisational measures, to respond to a data subject’s exercise of their rights under UK GDPR in relation to data processed under this DPA. Where MLR 2017 requires Friam to retain a record (for example, a customer due-diligence audit pack) on the Subscriber’s behalf, Friam cannot delete it until that retention period expires; this is a legal obligation on the Subscriber’s business, not a choice Friam makes (Privacy Policy §9).
6.6 Assistance with Articles 32–36
Breach notification. For a breach affecting data Friam processes on the Subscriber’s behalf, Friam will notify the Subscriber without undue delay so the Subscriber can meet its own notification obligations, the same commitment our GDPR Statement §9 makes, alongside Friam’s own alignment with the UK GDPR 72-hour ICO notification rule. DPIA support. Friam will give the Subscriber the information set out in this DPA and in our GDPR Statement §10 to support any data protection impact assessment the Subscriber needs to carry out for processing that uses our sanctions/PEP screening or biometric customer-verify flow, both of which our own GDPR Statement §10 already treats as likely-high-risk processing for which we conduct our own DPIAs.
6.7 Deletion or return at the end of the Services
On expiry or termination of the Subscription, Friam handles data processed under this DPA exactly as Terms §8.6 describes: the Subscriber’s public Trust page is taken down within one working day of cancellation; signed compliance documents, certificates and audit packs remain the Subscriber’s and can be exported as PDFs at any point, before or after cancellation; and where the law applicable to a record requires Friam to retain it (for example, signed documents, CDD audit packs and training records under MLR 2017), Friam retains it for the regulatory minimum and then deletes it.
6.8 Information and audit
Friam will make available to the Subscriber the information reasonably necessary to demonstrate compliance with this Section 6, and will allow for, and contribute to, audits (including inspections) conducted by the Subscriber or an auditor the Subscriber mandates, on reasonable notice and subject to reasonable confidentiality and security conditions.
7. Sub-processors and international transfers
The table below lists Friam’s current sub-processors, the purpose each serves, the category of data each sees, and where it operates. It corresponds to Privacy Policy §7.1, with a data category column added.
| Sub-processor | Purpose | Data category | Region |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure (compute, database, object storage); document text extraction (Textract); optional facial liveness & face-matching (Rekognition) | CDD evidence at rest: identity data, document images, extracted document text, biometric selfie / liveness reference frame, audit packs; Subscriber account and platform data | UK (eu-west-2); facial verification eu-west-1 (Ireland) |
| Anthropic | AI assistance for compliance-scan classification, document drafting, SAR brief preparation, and (as a fallback when automated reading fails) optical-character recognition and address extraction from a CDD identity-document image | The identity-document image (and any address shown on it), sent only when automated extraction has failed; not retained by Anthropic | US (UK IDTA safeguards in place) |
| Resend | Outbound and inbound transactional email, including the customer due-diligence verify-link email and reminder sent to the end-customer | End-customer name, email address, and the verify-link message | EU |
| Twilio | SMS delivery for training invitations, magic-link authentication, and the customer due-diligence verify-link SMS and reminder sent to the end-customer’s mobile number | End-customer name and mobile number, and the verify-link message | UK / EU (ie1 region) |
| Stripe Payments UK Ltd | Subscription billing | Subscriber’s own payment and billing data. Not end-customer CDD data: Friam is controller for this, so it sits outside the processing this DPA covers | UK / EU |
| Google (Places API) | Prospect business-listing enrichment for Friam’s own outreach | Not end-customer CDD data: Friam is controller for this (Data Collection Policy applies), listed here for completeness | Global (US-based) |
| Companies House (GOV.UK) | Live company and persons-with-significant-control lookups performed during a customer due-diligence check, at the Subscriber’s instruction, to identify a corporate customer’s beneficial owners | The company name/number being checked, and the officer/PSC names, roles and appointment dates Companies House’s public register returns | UK |
| OpenSanctions | Periodic bulk download of the consolidated PEP dataset our local PEP-screening index is built from. This is a one-way download of OpenSanctions’ own published data, not a live per-check query; no Subscriber or end-customer data is sent to OpenSanctions | None of the Subscriber’s or end-customer’s data is sent | Not applicable (one-way download) |
7.1 International transfers
Almost all personal data covered by this DPA is stored and processed within the UK. Two flows occur outside it: optional facial-liveness / face-match processing uses AWS in Ireland (eu-west-1, EU), and our AI sub-processor Anthropic operates in the United States (including, as a fallback, reading a CDD identity-document image when automated extraction fails). For the EU we rely on the UK’s adequacy finding; for the US we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (GDPR Statement §7; Privacy Policy §12). No other personal data covered by this DPA leaves the UK.
8. Data retention
Friam holds customer due-diligence evidence (identity document images, the passport chip photo, and the selfie / face-match reference frame) as part of the record it keeps for the Subscriber, in encrypted, access-controlled, tamper-evident UK storage with write-once (object-lock) protection, for the period the Subscriber needs to meet its own record-keeping duty under regulation 40 of the Money Laundering Regulations 2017, a minimum of five years from the end of the business relationship (Privacy Policy §3.4, §8). This is the Subscriber’s legal obligation as the regulated business, not an obligation the law places on Friam: Friam holds the record on the Subscriber’s instruction so the Subscriber can meet it, and cannot delete it before that period expires (Privacy Policy §9). Liveness video is not retained; only the still reference frame described above is kept.
9. Liability and precedence
Liability under this DPA is governed by, and forms part of, the liability provisions of the Terms of Service (§20–22). This DPA adds no liability terms beyond those already set out there. If there is any conflict between this DPA and the Terms of Service on a data-protection point, this DPA takes precedence for that point; the Terms of Service govern everything else.
10. Governing law and contact
This DPA is governed by the laws of England and Wales, and is subject to the exclusive jurisdiction of the courts of England and Wales, matching Terms of Service §28.
Friam Limited
164–170 High Street, Crowthorne, England, RG45 7AT
Company No. 14219476 · VAT No. GB419765755
Email: legal@everyguard.uk