Legal

Data Protection Impact Assessment

A summary of the DPIA WatchTower maintains for its endpoint security processing, provided to help customers complete their own assessment under Article 35 of the UK GDPR.

Last updated 15 September 2026.

Purpose of processing

The controller for WatchTower’s own processing is Nikah AI Ltd (trading as WatchTower), registered in England and Wales, Company No. 17199968, registered office: Office 1216, 60 Tottenham Court Road, London W1T 2EW.

WatchTower processes endpoint telemetry to protect business devices: detecting malware and intrusions, preventing data loss, responding to threats (automatically only where the customer switches that on), and maintaining an audit record for investigation and compliance. The customer organisation is the controller and decides which monitoring to enable; WatchTower is the processor under the Data Processing Terms.

Necessity and proportionality

Default telemetry is limited to security information: processes, files (names and fingerprints, not contents), network connections, device posture and detections. Features that look at how people use their devices (activity and time tracking, document and window titles, full web addresses) are off by default and must be switched on by the customer. Remote support, in which an administrator can view a device’s screen, is available by default and can be turned off. Data-loss findings store redacted matches. Access is limited to the customer’s authorised console users. Detailed telemetry is deleted automatically after a retention period the customer can set. Keylogging, microphone and webcam capture are not implemented.

Data and data subjects

  • Data subjects — employees, contractors and, in monitored-device contexts, other authorised device users.
  • Data — device identifiers, IP address, operating system and posture, visited URLs and domains, process and file names, file hashes, detection and response events, and administrator actions. Where enabled by the controller: application use and time, document and window titles, web addresses, redacted data-loss findings and phishing-simulation results; screenshots during an administrator’s remote session unless remote support is turned off; and country-level location of sign-ins for identity-defence features.

Risks identified

  • Over-collection or excessive visibility into individual behaviour.
  • Unauthorised access to security data or the console.
  • Function creep — using security telemetry for unrelated purposes.
  • Insufficient transparency to the people being monitored.
  • Retention of data for longer than necessary.

Mitigations

  • Data minimisation, redaction and hashing of sensitive content.
  • TLS encryption in transit; agent secrets and integration credentials encrypted in the database; role-based access.
  • A tamper-evident audit log of all privileged and configuration actions.
  • Per-workspace retention with automatic deletion of detailed telemetry.
  • Workforce features off by default; an education profile that switches them off for schools.
  • Customer obligations in the Terms of Service to establish a lawful basis and inform people before monitoring, and a monitoring notice customers can give to device users.
  • Contractual restriction of processing to the documented security purpose only.

Residual risk and review

With the mitigations applied, we assess the residual risk to individuals as low, provided controllers configure monitoring proportionately and inform their users. This assessment is reviewed at least annually and whenever the processing changes materially.

Contact

This page is our assessment of the processing WatchTower carries out as a processor. Your own DPIA must cover how and why your organisation monitors people. For questions that would help with it, use the contact form or email info@nikah-ai.com.