Agent DaysBook a consultation
Advisory
Gauge
Engage
No-code
Train

GDPR and data processing

Roles, safeguards and processor commitments.

This page explains how Agent Days approaches UK GDPR compliance and the terms that apply when we process personal data on a client's behalf.

Last updated: 27 August 2026

Data protection by design, not afterwards.

This framework supports our standard business services. The accepted scope must still identify the actual data, people, systems, purpose, duration and risks for each project. A separate data processing agreement may be required for complex or higher-risk work.

This page does not make Agent Days the controller of client data. Roles depend on who decides why and how personal data is processed.
1. Roles and contact details

Tristan Ader, trading as the currently unincorporated Agent Days business, is controller for our website, subscriptions, enquiries, contracts, security and business administration.

Where we process personal data solely on a client's documented instructions to deliver an agreed service, the client is controller and Agent Days acts as processor. Contact [email protected]. If a future Agent Days company assumes either role, this page and the relevant contract will be updated before that change takes effect.

2. Data protection principles

We design processing around lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. We will not knowingly use client personal data for an incompatible purpose.

3. Controller processing

For our own purposes, we process business contact, subscription, booking, contract, billing and security information under the lawful bases described in our Privacy Policy. We remain responsible for selecting suitable processors and providing required privacy information.

4. Processor commitments

When acting as processor, we will:

  • Process personal data only on documented instructions, including instructions about international transfers, unless UK law requires otherwise.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Apply security measures appropriate to the nature and risk of the processing.
  • Assist the controller, taking account of the processing and information available, with individual rights, security, breach notification, DPIAs and regulator consultation.
  • Delete or return personal data at the end of the service, at the controller's choice, unless law requires retention.
  • Provide information reasonably needed to demonstrate compliance and support proportionate audits.
5. Processing details

The accepted proposal, statement of work or written instructions must describe the subject matter, duration, nature and purpose of processing, the types of personal data, categories of people, and the controller's rights and obligations.

Typical project data may include staff, prospect or customer business contact details; communications; workflow events; support records; and information contained in systems selected by the client. We do not accept special-category, criminal-offence, children's or high-risk data unless expressly assessed and agreed in writing.

6. Subprocessors

The controller gives general authorisation for us to use appropriate providers supporting hosting, infrastructure, workflow automation, communications, secure storage and approved AI services. We remain responsible for imposing equivalent data protection obligations on subprocessors.

For material new subprocessors used to process client personal data, we will provide reasonable notice where the agreed service makes notice practicable. The controller may raise a reasoned data protection objection.

7. International transfers

We will not transfer client personal data outside the United Kingdom except on documented instructions or using a lawful transfer mechanism. Depending on the destination and provider, this may include UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum, and proportionate supplementary measures.

8. Security

Measures are selected according to scope and risk and may include access controls, least-privilege administration, managed hosting, encryption in transit, protected credentials, environment separation, backups, logging, patching, provider review, data minimisation and documented human approval points.

No system can promise absolute security. The client remains responsible for security and access controls in systems it owns or administers unless those responsibilities are expressly included in our scope.

9. Personal data breaches

When acting as processor, we will notify the controller without undue delay after becoming aware of a personal data breach affecting the service. We will provide available information reasonably needed for assessment and notification, take appropriate containment steps within our control, and preserve relevant records.

10. Retention, return and deletion

At the end of processor services, we will return or delete client personal data as instructed, unless UK law requires retention. Data in protected backups may remain beyond operational deletion until the relevant backup expires, provided it is put beyond ordinary use and remains protected.

11. Individual rights

The controller is responsible for responding to individual rights requests. Taking account of the nature of processing, we will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability and objection requests relating to data we process for the controller.

12. AI-assisted processing

AI use must be specified and governed according to purpose and risk. We use data minimisation, approved accounts, access controls, human review and evaluation appropriate to the work. We do not use client personal data to train public models on our own initiative.

High-risk, special-category, biometric, employment, credit, health or similarly consequential uses require explicit assessment, documented controls and, where required, a DPIA before processing begins.

13. Records, audits and complaints

We maintain records appropriate to our role and will provide reasonable compliance information. Audits must be proportionate, protect other clients and confidential systems, and normally take place during business hours with reasonable notice. The controller bears its audit costs unless an audit identifies our material breach.

Concerns should be sent to [email protected]. Individuals may also complain to the Information Commissioner's Office at ico.org.uk.

GDPR
Agent Days

Our intelligence is not artificial.

Agent Days helps founders and SMEs build useful, governed AI capability around real business work.

Book a consultation
Agent Days3D1 Zetland House, 5-25 Scrutton Street, London EC2A 4HJ+44 (0)208 106 1937[email protected]
ServicesAdvisoryGaugeEngageNo-codeTrain
LegalPrivacyTerms and ConditionsGDPR
ContactAsk a questionCall 0208 106 1937