Legal
Data Processing Addendum
Last updated: 28 May 2026
About this page. This page is a non-binding summary of the core GDPR Article 28 commitments that Ultrafast Digital makes as a data processor in CheckSync deployments. The operative Data Processing Addendum is a separate document executed in writing with each customer before go-live and prevails over anything on this page in all cases.
Roles and subject matter
- Controller: the customer organisation deploying CheckSync, determining the purposes and means of processing.
- Processor: Ultrafast Digital - processing personal data only on documented controller instructions.
- Purpose: visitor, contractor, staff, guest and agency workforce management; safety roll call; operational reporting and audit records.
- Duration: for the subscription term and as required by applicable law thereafter.
Personal data and data subjects
The categories of personal data and data subjects covered by the DPA depend on each customer's deployment configuration. They typically include:
- Identifiers: name, company, agency, role or job title
- Contact details: email address and phone number where collected
- Visit metadata: timestamps, site, terminal, host and purpose
- Mathematical biometric embeddings where agency worker verification is configured, not face photographs
- Consent and acknowledgement flags
- Audit log entries: sign-in, sign-out, erasure and administrative events
- Data subjects: visitors, contractors, staff, guests, agency workers and dashboard administrators
Processor obligations - summary
As data processor, Ultrafast Digital commits to the following under the signed DPA:
- Process personal data only on documented instructions from the controller.
- Ensure all personnel with access to personal data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organisational security measures - including authentication, role-based access, encryption in transit and at rest, and per-client deployment isolation.
- Not engage sub-processors without prior notice to the controller, and flow down equivalent data protection obligations to any sub-processors used.
- Assist the controller in responding to data subject requests (access, erasure, rectification, portability, objection) within a reasonable timeframe.
- Support the controller in carrying out Data Protection Impact Assessments (DPIAs) where applicable.
- Notify the controller of a personal data breach without undue delay upon becoming aware of it.
- At the end of the service term, delete or return all personal data as instructed by the controller, subject to any legal retention obligations.
- Make available information necessary to demonstrate compliance and support reasonable audits by the controller.
Sub-processors
CheckSync currently uses the following categories of sub-processor infrastructure in production deployments:
- Cloudflare - hosting, CDN, edge network, DDoS protection and WAF
- Auth0 - identity and authentication for dashboard access
- Resend - transactional email delivery for system notifications
Customers will be notified of material changes to sub-processors in advance. The operative DPA sets out the notification mechanism and objection process.
International transfers
Where personal data is processed outside the UK or EEA by sub-processors, appropriate transfer mechanisms are relied upon - including adequacy decisions and standard contractual clauses where applicable. Details are set out in the operative DPA.
Requesting the DPA
The full Data Processing Addendum is available to prospective and current customers on request. Contact us to receive a copy for review before or during your pilot.
Email: info@ultrafastdigital.com
Phone: +44 1226 972759
This page is a summary for information only and does not constitute legal advice. The operative DPA is a separate signed document and prevails in all cases.