GDPR and data processing
Roles, safeguards and processor commitments.
This page explains how Agent Days approaches UK GDPR compliance and the terms that apply when we process personal data on a client's behalf.
Last updated: 27 August 2026
Data protection by design, not afterwards.
This framework supports our standard business services. The accepted scope must still identify the actual data, people, systems, purpose, duration and risks for each project. A separate data processing agreement may be required for complex or higher-risk work.
1. Roles and contact details
Tristan Ader, trading as the currently unincorporated Agent Days business, is controller for our website, subscriptions, enquiries, contracts, security and business administration.
Where we process personal data solely on a client's documented instructions to deliver an agreed service, the client is controller and Agent Days acts as processor. Contact agent@agentdays.co. If a future Agent Days company assumes either role, this page and the relevant contract will be updated before that change takes effect.
2. Data protection principles
We design processing around lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. We will not knowingly use client personal data for an incompatible purpose.
3. Controller processing
For our own purposes, we process business contact, subscription, booking, contract, billing and security information under the lawful bases described in our Privacy Policy. We remain responsible for selecting suitable processors and providing required privacy information.
4. Processor commitments
When acting as processor, we will:
- Process personal data only on documented instructions, including instructions about international transfers, unless UK law requires otherwise.
- Ensure people authorised to process the data are bound by confidentiality.
- Apply security measures appropriate to the nature and risk of the processing.
- Assist the controller, taking account of the processing and information available, with individual rights, security, breach notification, DPIAs and regulator consultation.
- Delete or return personal data at the end of the service, at the controller's choice, unless law requires retention.
- Provide information reasonably needed to demonstrate compliance and support proportionate audits.
5. Processing details
The accepted proposal, statement of work or written instructions must describe the subject matter, duration, nature and purpose of processing, the types of personal data, categories of people, and the controller's rights and obligations.
Typical project data may include staff, prospect or customer business contact details; communications; workflow events; support records; and information contained in systems selected by the client. We do not accept special-category, criminal-offence, children's or high-risk data unless expressly assessed and agreed in writing.
6. Subprocessors
The controller gives general authorisation for us to use appropriate providers supporting hosting, infrastructure, workflow automation, communications, secure storage and approved AI services. We remain responsible for imposing equivalent data protection obligations on subprocessors.
For material new subprocessors used to process client personal data, we will provide reasonable notice where the agreed service makes notice practicable. The controller may raise a reasoned data protection objection.
7. International transfers
We will not transfer client personal data outside the United Kingdom except on documented instructions or using a lawful transfer mechanism. Depending on the destination and provider, this may include UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum, and proportionate supplementary measures.
8. Security
Measures are selected according to scope and risk and may include access controls, least-privilege administration, managed hosting, encryption in transit, protected credentials, environment separation, backups, logging, patching, provider review, data minimisation and documented human approval points.
No system can promise absolute security. The client remains responsible for security and access controls in systems it owns or administers unless those responsibilities are expressly included in our scope.
9. Personal data breaches
When acting as processor, we will notify the controller without undue delay after becoming aware of a personal data breach affecting the service. We will provide available information reasonably needed for assessment and notification, take appropriate containment steps within our control, and preserve relevant records.
10. Retention, return and deletion
At the end of processor services, we will return or delete client personal data as instructed, unless UK law requires retention. Data in protected backups may remain beyond operational deletion until the relevant backup expires, provided it is put beyond ordinary use and remains protected.
11. Individual rights
The controller is responsible for responding to individual rights requests. Taking account of the nature of processing, we will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability and objection requests relating to data we process for the controller.
12. AI-assisted processing
AI use must be specified and governed according to purpose and risk. We use data minimisation, approved accounts, access controls, human review and evaluation appropriate to the work. We do not use client personal data to train public models on our own initiative.
High-risk, special-category, biometric, employment, credit, health or similarly consequential uses require explicit assessment, documented controls and, where required, a DPIA before processing begins.
13. Records, audits and complaints
We maintain records appropriate to our role and will provide reasonable compliance information. Audits must be proportionate, protect other clients and confidential systems, and normally take place during business hours with reasonable notice. The controller bears its audit costs unless an audit identifies our material breach.
Concerns should be sent to agent@agentdays.co. Individuals may also complain to the Information Commissioner's Office at ico.org.uk.