Registered in England & Wales. Company No. 16820234.
01 / Trust overview
Designed for scrutiny.
GGA is built around data minimisation, clear access boundaries, auditable records and procurement-ready documentation. The exact controls depend on the service and client configuration.
Commercial, privacy and trust enquiries can be routed through the same address.
Current Authorise materials describe edge compute/storage, HTTPS and access-control options.
DPA, security measures, subprocessors and supporting materials are available during diligence.
GGA technology and advisory materials support compliance operations. They are not a substitute for legal advice, regulatory interpretation or an organisation’s own accountable decision-making.
02 / Privacy
Privacy notice.
We aim to collect only what is necessary to operate GGA services and support auditable compliance workflows.
Who we are
GiftGuard Technologies Ltd is the legal entity behind GGA. Contact: [email protected]. Our current jurisdictional framework is England & Wales, including UK GDPR and the Data Protection Act 2018 where applicable.
What data we may process
Depending on the service and client configuration, this may include user identity/contact details, organisation and department information, compliance submissions, declarations, learning activity, assessment responses, decisions, rationale, timestamps, audit identifiers, tenant identifiers and limited reliability/security logs.
Why we process it
Processing may be necessary to perform a contract, pursue legitimate interests in operating and securing the service, and meet applicable legal obligations. Where GGA acts as a processor, the customer remains responsible for its controller obligations.
Retention
Retention is service and client-policy dependent. For Authorise, existing materials provide for configurable retention with a short administrative buffer after subscription end unless deletion is instructed sooner.
Infrastructure and subprocessors
Current Authorise materials identify Cloudflare infrastructure for compute/storage. GGA does not sell personal data or use client submission data for third-party advertising. Additional subprocessors, if any, should be set out in the relevant contract or DPA.
Security
Current Authorise controls include HTTPS, tenant isolation approaches, audit identifiers and optional Cloudflare Access policies. Security measures for other GGA services depend on their deployment model and agreed scope.
Your rights
Applicable rights may include access, rectification, erasure, restriction, objection and portability. Where we act as processor, end users should normally contact their employer/controller first. UK users may also complain to the Information Commissioner’s Office.
Cookies and tracking
The public GGA site is designed without advertising cookies or tracking pixels. Strictly necessary functionality may use local browser storage - for example, remembering your chosen light/dark theme.
Changes
We may update this notice as our services evolve. Material service-specific processing should be reflected in the applicable client documentation.
Consolidated website notice · September 2026 · Based on the previously published GiftGuard Authorise privacy notice.
03 / Service terms
Current Authorise terms.
The terms below consolidate the existing published GiftGuard Authorise website terms. Learn, Assess and Advisory engagements should be governed by the relevant order form, statement of work or master services agreement.
1. Parties & contract
The Authorise service is provided by GiftGuard Technologies Ltd. The customer entity accepts the applicable terms when purchasing or accessing the service.
2. Subscription & fees
Subscriptions are billed annually in advance unless agreed otherwise. Fees exclude applicable taxes. Packaging and prices may change on renewal with notice.
3. Scope
Authorise provides a hosted approval workflow with policy-based decisions, audit identifiers and export functionality. Features may evolve provided overall contracted functionality is not materially degraded.
4. Customer responsibilities
Customers remain responsible for configuring policies and thresholds appropriately, managing authorised access, and ensuring their use of GGA complies with applicable law and internal policy.
5. Acceptable use
Users must not use the service unlawfully, attempt to circumvent security, reverse engineer protected components or interfere with networks and infrastructure.
6. Data protection
Each party must comply with applicable data protection law. Where GGA processes end-user submission data on the customer’s behalf, the contractual allocation of controller/processor responsibilities should be reflected in the DPA.
7. Security & availability
GGA implements reasonable security measures appropriate to the service architecture. No online service can guarantee 100% availability.
8. Intellectual property
GiftGuard Technologies Ltd retains intellectual property rights in the service. Customer data remains the customer’s data, subject to the limited processing rights needed to deliver the service.
9. Confidentiality
Each party should protect the other party’s confidential information and use it only as necessary for the engagement.
10. Warranties & disclaimers
The service is not legal advice. Customers remain responsible for their policies, regulatory obligations and final decisions.
11. Liability
The existing published Authorise terms limit aggregate liability in a 12-month period to fees paid for the service in that period, subject to liabilities that cannot lawfully be excluded. Signed client agreements may supersede website terms.
12. Termination
Contract duration, renewal, breach remedies and data return/deletion should follow the applicable subscription agreement or signed terms.
13. Governing law
Existing Authorise website terms are governed by the laws of England and Wales, with the courts of England and Wales having exclusive jurisdiction.
Consolidated website terms · September 2026 · Signed MSAs/order forms take precedence where applicable.
04 / Legal & company
Corporate information.
- Legal entity
- GiftGuard Technologies Ltd
- Company number
- 16820234
- Jurisdiction
- England & Wales
- Commercial / privacy contact
- [email protected]
- Website brand
- GGA
05 / Procurement
For diligence teams.
We keep commercial and diligence detail here rather than interrupting the main product story.
Documentation available during diligence +
Depending on scope, GGA can provide or discuss the relevant DPA, security measures, subprocessor information, data map/DPIA support, service-level targets, onboarding/offboarding information and sample evidence/export structures.
Security and architecture discussion +
Architecture varies by service. Authorise currently uses a lightweight Cloudflare-based deployment model. Enterprise requirements such as SSO, retention, access control and integration should be captured during scoping.
Commercial framework +
GGA prices engagements around scope, population, complexity and implementation requirements. The current standard minimum engagement values are:
These are standard starting values, not quotes. Final pricing can vary with headcount, jurisdictions, integrations, service depth, remediation scope and contracting requirements.