Legal
Data Processing Addendum
Shieldra data processing commitments under the GDPR, UK GDPR, and CCPA/CPRA. This DPA forms part of the Shieldra Terms of Service and prevails over them in any conflict concerning personal data. Version 2026-09-16, effective September 16, 2026.
Key takeaways
- Under the GDPR, Shieldra is the processor and the Customer is the controller — or Shieldra acts as sub-processor where the Customer is itself a processor; under CCPA/CPRA, Shieldra is a service provider.
- Shieldra processes personal data only on the Customer’s documented instructions.
- Sub-processors are permitted with at least 30 days’ notice and a right to object; Shieldra remains responsible for their compliance under terms no less protective than this DPA.
- Shieldra notifies the Customer of a personal data breach without undue delay and within 72 hours of becoming aware.
- EU Standard Contractual Clauses (Module Two or Module Three), the UK Addendum, and the Swiss addendum are incorporated for international transfers.
- The standard service is No-PHI: PHI is excluded unless Shieldra expressly authorizes it in writing under a BAA, and an executed BAA prevails over this DPA for PHI.
Roles and scope
This Data Processing Addendum forms part of the Shieldra Terms of Service between Shieldra AI, Inc. and the Customer, and applies to the processing of personal data on the Customer’s behalf in connection with the services. Where the GDPR applies, Shieldra acts as processor and the Customer as controller — or as the Customer’s sub-processor where the Customer itself acts as a processor for its own clients; where the CCPA/CPRA applies, Shieldra acts as a service provider. In any conflict concerning personal data, this DPA prevails over the Terms, except that any executed Business Associate Agreement prevails with respect to PHI.
Subject matter, duration, nature, and purpose
- Subject matter: processing of personal data submitted to, or collected through, the services by or on behalf of the Customer, including through integrations the Customer connects
- Duration: the term of the Customer’s subscription, plus the wind-down period in the Terms
- Nature and purpose: compliance management and AI-governance functionality — document analysis, AI-assisted analysis, regulatory classification, compliance integrity records, evidence collection, vendor risk management, training tracking, and reporting
- Categories of personal data: identification and contact data, employment and training data, device identifiers and posture data, system access and audit logs, AI prompts and outputs, and any personal data in documents the Customer uploads — PHI is excluded unless separately authorized in writing under a BAA
Processing obligations
Shieldra processes personal data only on the Customer’s documented instructions, including with regard to international transfers, unless otherwise required by law. If Shieldra believes an instruction infringes the GDPR or other applicable data protection law, it will say so unless legally prohibited from doing so.
Personnel authorized to process personal data are bound by appropriate confidentiality obligations and have received data protection training. Shieldra’s security program is described on the public Security and Trust Center pages, and audit reports and security assessments are made available to customers on request and under NDA as and when available.
Sub-processors and international transfers
The Customer authorizes Shieldra to engage sub-processors for specific processing activities, with at least 30 days’ notice of additions or replacements and a right to object on reasonable data-protection grounds. Shieldra remains responsible for each sub-processor’s compliance and imposes data protection obligations on them no less protective than those in this DPA — AI sub-processors are engaged under agreements or service terms that exclude use of Customer personal data to train their models. The current list of sub-processors, their locations, and their roles is published on the sub-processors page.
Where personal data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Module Two: controller to processor, or Module Three: processor to processor, as applicable), the UK International Data Transfer Addendum, and the Swiss FDPIC addendum are incorporated by reference. Shieldra conducts transfer impact assessments and implements supplementary measures where required.
Data subject requests and breach notification
Taking into account the nature of the processing, Shieldra assists the Customer by appropriate technical and organizational measures, so far as possible, in fulfilling the Customer’s obligations to respond to data subject requests. Where Shieldra receives a request directly from a data subject, it refers them to the Customer or to the privacy request page unless legally required to respond directly.
Shieldra notifies the Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Customer Data, providing the information the Customer needs to meet its own notification obligations. Shieldra also provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities.
Frequently asked questions
Is Shieldra a controller or a processor?
Under the GDPR, Shieldra is the processor and the Customer is the controller — or, where the Customer itself acts as a processor for its own clients, Shieldra acts as the Customer’s sub-processor. Under the CCPA/CPRA, Shieldra acts as a service provider. Shieldra processes personal data only on the Customer’s documented instructions.
How quickly does Shieldra report a personal data breach?
Without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, together with the information the Customer needs to meet its own breach notification obligations.
Does the DPA cover PHI?
The standard service is No-PHI: protected health information is excluded unless Shieldra expressly authorizes that processing in writing under a Business Associate Agreement. Where a BAA is executed, it prevails over the DPA with respect to PHI.
Where can I see the current sub-processor list?
The sub-processors page lists every third party involved in delivering the service, along with its purpose and processing location. Shieldra remains responsible for sub-processor compliance under terms no less protective than the DPA.