This DPA applies whenever ShinobiOps processes Customer Personal Data on the Customer’s behalf, regardless of Plan.

1. Application, roles and interpretation

1.1 This Schedule (the "DPA") forms part of the Agreement and applies where the Provider processes personal data contained in Customer Content ("Customer Personal Data") on behalf of the Customer.

1.2 As between the parties, the Customer is controller and the Provider is processor; or, where the Customer is itself a processor for a third-party controller, the Customer is processor and the Provider is subprocessor. Where the Customer acts as processor, it warrants that it has the controller's authority to appoint the Provider on these terms and to give the instructions contemplated by this DPA.

1.3 Each party remains independently responsible for processing for which it determines the purposes and essential means as a controller in its own right. To the extent the Provider makes those determinations, its controller activities may include account administration, billing, support, security, telemetry, compliance and service protection. The relevant categories, purposes, lawful bases, recipients and retention must be described accurately in the Privacy Notice at /privacy. This clause does not determine a role contrary to the actual processing or applicable law.

1.4 In this DPA, "Applicable Data Protection Law" means all law applicable to the processing of Customer Personal Data under the Agreement, including any applicable regional schedule; "Restricted Transfer" means a transfer of Customer Personal Data to a country not covered by an adequacy decision or regulations applicable to that transfer; and "Subprocessor" means a processor engaged by the Provider to process Customer Personal Data. Other terms defined in Applicable Data Protection Law bear the meaning given there.

1.5 In the event of conflict between this DPA and the remainder of the Agreement, this DPA prevails in relation to the processing of Customer Personal Data. In the event of conflict between this DPA and a transfer mechanism incorporated under Clause 10, the mandatory terms of that transfer mechanism prevail.

2. Scope and details of processing

2.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex A.

2.2 The Customer is responsible for the accuracy and completeness of Annex A and must notify the Provider promptly if it ceases to reflect the Customer's actual use of the Services.

3. Instructions

3.1 The Provider will process Customer Personal Data only to provide, secure and support the Services, on the Customer's documented instructions, and as required by law.

3.2 The Customer's documented instructions comprise the Agreement, each Order, the Customer's configuration of the Services, the inputs and settings of its Authorised Users, and any further instruction agreed by the parties in writing.

3.3 If law requires the Provider to process Customer Personal Data otherwise than on the Customer's instructions, the Provider will inform the Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest.

3.4 The Provider will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, and may suspend performance of that instruction pending resolution.

3.5 The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all transparency information required to data subjects, including where personal data was not obtained from the data subject, and that it has completed any data protection impact assessment or prior consultation required before instructing the processing.

4. Confidentiality and personnel

4.1 The Provider will ensure that each person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and receives appropriate privacy and security training.

4.2 The Provider will ensure that no person acting under its authority processes Customer Personal Data except on the Customer's instructions, unless required to do so by law.

4.3 The Provider will limit access to Customer Personal Data to those personnel who require it in order to perform the Agreement.

5. Security

5.1 The Provider will implement and maintain the technical and organisational measures described in Annex B, having regard to the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to individuals.

5.2 The Provider may update those measures from time to time, provided that no update materially reduces the overall level of protection.

5.3 The Customer is responsible for the security of its own systems, credentials and connected Third-Party Services, for configuring access appropriately, and for deactivating Seats and revoking integrations promptly when no longer required.

6. Personal data breaches

6.1 The Provider will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. It will provide information then available and supplement it as the investigation develops. Notification must not wait for all supplier information or a completed investigation. Any shorter fixed deadline applies only where expressly agreed; no fixed deadline extends the without-undue-delay obligation.

6.2 The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. The Provider will supplement the notification as further information becomes available.

6.3 Notification is not, and must not be construed as, an admission of fault or liability by the Provider.

6.4 The Customer is responsible for notifications to supervisory authorities and to data subjects, unless Applicable Data Protection Law requires the Provider to notify directly. Neither party will name the other in a public statement about a breach without prior consultation, except where required by law.

7. Data subject rights

7.1 Taking into account the nature of the processing, the Provider will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights, including rights of access, rectification, erasure, restriction, portability and objection.

7.2 The Provider will make available the access, correction, export and deletion functionality described in the Documentation. Where the Customer cannot give effect to a data-subject request through that functionality, the Provider will provide reasonable additional assistance. To the extent permitted by Applicable Data Protection Law, the Provider may charge reasonable, pre-disclosed costs for assistance that is materially disproportionate to the ordinary operation of the Services.

7.3 If the Provider receives a request from a data subject relating to Customer Personal Data, it will not respond other than to acknowledge receipt and direct the requester to the Customer, unless legally required to respond or otherwise authorised by the Customer, and will inform the Customer of the request without undue delay.

8. Assistance with assessments, consultations and authorities

8.1 Taking into account the nature of the processing and the information available to it, the Provider will assist the Customer in complying with its obligations relating to security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments and prior consultation with a supervisory authority.

8.2 The Provider will provide the information reasonably necessary for the Customer to conduct a data protection impact assessment relating to the Services, including a description of the processing operations, the categories of data involved, the retention applied, the Subprocessors engaged and the transfer mechanisms used.

8.3 Each party will cooperate with the other, and provide information reasonably required, in responding to an enquiry, investigation or order from a supervisory authority relating to the processing under the Agreement, subject to confidentiality and to the protection of other customers' data.

9. Subprocessors

9.1 The Customer gives general written authorisation for the Subprocessors identified in the supplier schedule applicable to its processing. The register at /subprocessors provides supplier information and the process for obtaining the applicable schedule. Before a route is enabled, its recipients, roles, purposes, locations and safeguards must be identified in that schedule. Authorisation of a brand does not authorise undisclosed recipients or purposes.

9.2 The Provider will give at least 15 days' prior notice of the addition or replacement of a Subprocessor by email to the Customer's registered administrator and by updating the published list. Email notice is automatic and does not require a separate subscription. The notice will identify the Subprocessor, processing purpose, relevant locations and applicable safeguards so that the Customer can assess the change.

9.3 The Provider will impose on each Subprocessor, by written contract, data protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the performance of each Subprocessor's obligations.

9.4 The Customer may object on reasonable data-protection grounds within 15 days after notice of a new Subprocessor. The parties will seek a reasonable solution for up to 30 days after the objection. The Provider may offer an authorised alternative, suspend only the affected processing where necessary or terminate that part of the Service with unused prepaid fees refunded if no reasonable solution is available. It need not maintain an obsolete supplier or build a bespoke route indefinitely. A timely unresolved objection must not be bypassed by sending the Customer’s data to the proposed Subprocessor. The Customer may terminate the affected Service with unused prepaid fees refunded if a solution cannot be agreed or the affected Service cannot be maintained during resolution.

10. International transfers

10.1 Customer Personal Data may be processed at the locations identified in the applicable supplier and processing schedules. Data residency is not guaranteed merely by an Order’s currency, governing law, customer location or account region. Restricted Transfers require documented instructions and the applicable legal safeguards; a change of model or routing may not bypass those safeguards.

10.2 Before a Restricted Transfer begins, the parties must identify the exporter, importer, actual roles, processing locations and lawful transfer mechanism in the applicable transfer schedule. Where used, the EU standard contractual clauses under Decision (EU) 2021/914 are selected by actual role, including controller-to-processor or processor-to-subprocessor as appropriate, with the UK Addendum or IDTA and Swiss adaptations where required. Parties relying on adequacy must establish that it covers the recipient and processing. A generic reference to this DPA does not complete unsigned or unspecified transfer instruments. Mandatory transfer terms prevail over conflicting provisions.

10.3 The responsible party will complete any required transfer risk or impact assessment and supplementary measures before the affected transfer. The Provider will supply a legally permissible summary reasonably needed for the Customer’s assessment, subject to security, confidentiality and third-party rights.

10.4 The Provider will notify the Customer promptly if it becomes unable to comply with the transfer mechanism adopted, and the Customer may suspend the affected transfer or terminate the affected part of the Services.

10.5 To the extent legally permitted, the Provider will notify the Customer of a legally binding public-authority request for Customer Personal Data. Where reasonable, proportionate and permitted, it will seek clarification or challenge a request that appears unlawful or overbroad and will disclose only the data it is legally required to disclose. This commitment is subject to the information and procedural rights available to the Provider and its Subprocessors in the relevant jurisdiction.

11. Model providers and model improvement

11.1 A model processor or intermediary may receive Customer Personal Data only under the applicable supplier schedule and documented purpose, location, retention and safeguards. Model or version substitution within an authorised route does not itself require a new agreement, provided it does not change those authorised conditions. A new recipient, different role, purpose or transfer must first follow the relevant authorisation and change process.

11.2 Neither the Provider nor its model processors may use Customer Personal Data to train, fine-tune or improve generally available models under this DPA. Customer-specific memory and calibration remain within documented instructions. The restriction covers intermediaries, generation, embeddings, research and fallbacks. A future training offering requires separate specific terms and required permissions; it cannot be introduced through ordinary feature enablement or a supplier-policy update.

11.3 Model suppliers may retain Inputs or Output only for the purpose and period specified in the applicable supplier schedule and consistent with this DPA. No zero-retention promise applies unless expressly verified and recorded for the route. Abuse-monitoring retention does not authorise unrelated processing.

11.4 The Customer must not configure or use the Services to make a decision based solely on automated processing that produces legal effects concerning an individual or similarly significantly affects an individual, unless an Order expressly authorises the use after the parties have validated the applicable legal basis, notices, safeguards, human intervention and contest rights. Neither this DPA nor the default product configuration is a representation that every Customer deployment falls outside an automated-decision regime.

12. Retention, deletion and return

12.1 The Provider will retain Customer Personal Data for the periods stated in Annex A.

12.2 On termination or expiry of the Agreement, the Provider will, at the Customer's election, delete or return Customer Personal Data and delete existing copies, unless retention is required by law.

12.3 The Customer may request a standard return during the 30-day export window or choose earlier deletion. The export window does not remove mandatory personal-data return or erasure rights. The Provider will arrange lawful secure return where interactive access is unsafe. Deletion covers source copies and derived personal data, including stored Output, embeddings, indexes, wiki content, customer-specific memory and Subprocessor copies. There is no separate obligation to reconstruct historical artefacts that are no longer stored, unless law requires it. Timing is set out in Annex A.

12.4 Data in backups must be put beyond ordinary use and deleted within the deadline in Annex A. It remains protected by this DPA until deletion and must not be restored to ordinary processing without reapplying relevant deletion instructions. Where law requires retention, the Provider will restrict it to the required categories, purpose and period and, where legally permitted, tell the Customer the basis and scope. The exception does not permit continued general use of Customer Personal Data or blanket retention of Customer Content as a business record.

13. Information and audits

13.1 The Provider will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA. Where they exist and may lawfully be shared, the Provider may do so in the first instance through current third-party audit reports or certifications, security documentation and completed security questionnaires.

13.2 The Provider may respond first with relevant documentation, questionnaires and existing assurance reports. Where further examination is reasonably needed, the Customer or its independent auditor may conduct a proportionate audit, ordinarily once in 12 months on 30 days’ notice during business hours. An independent auditor must not be a competitor and must be bound by confidentiality. These arrangements do not remove the Customer’s right to demonstrate and verify compliance or the exceptions in Clause 13.4.

13.3 An audit must not access the data of any other customer, must not unreasonably disrupt the Provider's business, and must be limited in scope to the processing carried out under the Agreement. The Customer bears the cost of the audit unless it identifies material non-compliance by the Provider.

13.4 Clauses 13.2 and 13.3 do not limit an audit or inspection right that Applicable Data Protection Law or a supervisory authority requires the Customer or the authority to have, or that arises following a personal data breach.

13.5 The Provider will maintain records of processing carried out on the Customer's behalf as required by Applicable Data Protection Law and will make the relevant extract available to the Customer on reasonable request.

14. United states state privacy laws

14.1 This Clause 14 applies where Customer Personal Data is otherwise subject to United States state privacy law.

14.2 Where applicable US state privacy law assigns the Provider the role of processor, service provider or contractor, it will process only for the limited purposes described in this DPA, will not sell Customer Personal Data or share it for cross-context behavioural advertising, and will not retain, use, disclose or combine it outside the permitted business relationship except as that law permits. It will provide the required level of protection, permit reasonable verification and certifies that it understands and will comply with the applicable restrictions. Controller activities are separately described in the Privacy Notice; a contractual label does not determine statutory role.

14.3 The Provider will notify the Customer if it determines that it can no longer meet those obligations, and the Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use.

15. Liability under this dpa

15.1 Liability arising out of or in connection with this DPA is subject to the limitation of liability provisions of the Terms, including any separate cap applicable to breach of this DPA, save to the extent that Applicable Data Protection Law does not permit that limitation.

15.2 Nothing in this DPA limits any right or remedy that a data subject has under Applicable Data Protection Law.

Annex A — Processing details and retention

Subject matter and duration: delivery of the purchased AI-assisted business services during the subscription and the return, deletion and legally required retention periods below. The Customer acts as controller or authorised processor and determines its lawful purposes and instructions; the Provider acts as processor or subprocessor for Customer Personal Data.

Nature and purposes: hosting, retrieval, indexing, analysis, generation, customer-specific memory, authorised tool execution, support and security necessary for the selected functionality. Processing is continuous or on demand according to Customer use and authorised integrations.

Individuals: Authorised Users and the Customer’s personnel, business contacts, prospects, customers and suppliers whose data it lawfully supplies. Categories: identity/contact details, professional information, business communications and records, selected integration content, Inputs, Output and relevant technical data. The Order must narrow or supplement these details for materially different authorised processing.

Sensitive, criminal-offence, children’s, biometric, precise-location and regulated health or financial data is not permitted as general content unless a specific category and purpose is authorised in the Order and this schedule with the required safeguards. Credentials and card details may be supplied only through the designated connection or payment mechanisms for those purposes.

Standard post-termination export window: 30 days, subject to earlier deletion. Active personal-data copies must be deleted within 90 days after an earlier deletion instruction or completed return and no later than 120 days after termination. Corresponding backups expire within 90 days after active deletion and no later than 210 days after termination. Backups remain beyond ordinary use and protected; deletion instructions must be reapplied on restoration. These deadlines cover derived personal data and Subprocessor copies.

Legal retention is limited to the required data, basis, purpose and period. The Provider’s own billing, security and business-contact records are described separately in the Privacy Notice; that classification does not authorise blanket retention of Customer Content. The Customer may issue lawful documented instructions under this DPA and request information needed to verify compliance.

Annex B — Security obligations

The Provider will maintain measures appropriate to the processing risk, including controlled access and personnel confidentiality, separation of customer access, protection of credentials, secure transmission and storage appropriate to the data, vulnerability management, incident response and tested arrangements for availability, restoration and secure deletion. The applicable security schedule supplies agreed implementation details and any additional measures required by the particular processing.

Implementation methods may be updated without materially reducing the overall protection. No particular certification, penetration-test frequency, encryption algorithm, recovery target, hosting region or dedicated environment is represented by this baseline schedule alone. The Provider will supply relevant security information reasonably required for the Customer to assess the measures and compliance.

Annex C — Suppliers and transfers

The supplier schedule for the Customer’s processing identifies authorised recipients by legal entity, service, purpose, data categories, location, retention and safeguard. See /subprocessors and contact contact@shinobiops.ai for the applicable schedule. A new recipient follows Clause 9; model substitution within an authorised route follows Clause 11.

For Restricted Transfers, the completed transfer schedule must record exporter and importer details, roles, selected instrument/module and options, processing and security annexes, governing law/forum where required, and applicable UK or Swiss provisions, assessments and supplementary measures. A reference to standard clauses alone does not complete this schedule. Processing that needs a missing authorisation or transfer safeguard must not begin.

← Back to home