Data Processing Agreement
Last Updated: 10/22/2025
Parties:
(1) ShopShield.com, operated by ShopShield, LLC., ("Processor," "we," "us"), and
(2) The customer or subscriber who has entered into a subscription or other agreement for our services ("Controller," "you").
1. Purpose
This Agreement governs how ShopShield.com processes personal data on your behalf while delivering subscription services that (a) monitor publicly available policy or terms-of-service pages on third-party websites, (b) identify and summarize changes, and (c) send notifications or reports to your designated contacts.
2. Definitions
Applicable Law means all privacy and data-protection laws, including the EU GDPR, UK GDPR, CCPA/CPRA, and any equivalent local laws.
Personal Data means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller.
Processing and related terms have the meaning given in the GDPR.
Services means the ShopShield.com platform, APIs, web application, and related automation services.
3. Subject Matter, Nature, and Duration
Subject Matter: Processing of subscriber account information and delivery of notifications.
Nature & Purpose: Collection, storage, transmission, and analysis necessary to (i) manage user accounts; (ii) send change alerts and summaries; and (iii) provide analytics and billing.
Duration: For as long as you maintain an active account or as otherwise required by law.
4. Roles of the Parties
You are the Controller of any Personal Data you provide. ShopShield.com acts as your Processor and will process that data solely on your documented instructions, including those contained in your subscription agreement and this DPA.
5. Categories of Data and Data Subjects
Data Subjects: your account holders, team members, or end users designated to receive updates.
Categories of Data: name, email address, billing details, login credentials (hashed), communication preferences, and audit logs.
ShopShield.com does not collect or process sensitive categories of data.
6. Processor Obligations
ShopShield.com shall:
- Process Personal Data only on your documented instructions.
- Ensure persons with access are bound by confidentiality obligations.
- Maintain technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and accidental loss or destruction.
- Assist you in responding to data-subject requests and compliance obligations (Articles 12–23 GDPR).
- Notify you without undue delay of any confirmed Personal-Data Breach and provide relevant details.
- Make available all information necessary to demonstrate compliance and allow reasonable audits (subject to confidentiality and scheduling).
- Delete or return Personal Data at termination of Services, unless retention is required by law.
7. Controller Obligations
You confirm that:
- You have a lawful basis for all Personal Data provided.
- You will not instruct us to process data in violation of law.
- You are responsible for the accuracy and legality of the data you supply.
8. Sub-Processors
We may engage sub-processors to perform infrastructure, storage, or communication services.
Current sub-processors include:
- Make.com (Celonis SE) – workflow automation
- Lovable.dev – application hosting and database services
- Amazon Web Services (AWS) – cloud infrastructure and storage
- SendGrid (Twilio Inc.) – transactional email delivery
- Stripe Inc. – payment processing
We will maintain an updated list at https://shopshield.co/legal/sub-processors and notify you of any material changes. You may object on reasonable grounds within 30 days.
9. International Transfers
Where data is transferred outside the EEA, UK, or other jurisdictions requiring adequacy, ShopShield.com will implement appropriate safeguards such as the EU Standard Contractual Clauses (2021/914) and UK Addendum.
10. Security Measures
We maintain, at a minimum:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Access control via unique credentials and least-privilege roles.
- Daily off-site backups and integrity checks.
- Logging and anomaly detection of all administrative actions.
- Annual review of incident-response and disaster-recovery plans.
A current summary of technical and organizational measures (TOMs) is available upon request.
11. Data Breach Notification
Upon discovering a confirmed Personal-Data Breach, we will:
- Notify you within 72 hours.
- Provide known details on the nature, scope, and mitigation steps.
- Cooperate to meet your legal reporting duties.
12. Assistance
ShopShield.com will provide reasonable support for:
- Responding to data-subject requests.
- Performing Data-Protection-Impact Assessments.
- Consulting with supervisory authorities when legally required.
13. Deletion and Return
After termination, upon written request, we will either delete or return all Personal Data within 30 days unless retention is required for billing, dispute resolution, or legal compliance.
14. Liability and Indemnity
Each party remains liable for its own acts and omissions and shall indemnify the other for damages arising from violations of this DPA or Applicable Law, subject to limitations defined in the main Terms of Service.
15. Governing Law and Jurisdiction
This DPA is governed by the same law and forum as specified in your main service agreement with ShopShield.com.
16. Miscellaneous
Inconsistencies between this DPA and the main agreement are resolved in favor of the DPA regarding data-protection matters.
Updates may be made to maintain compliance; continued use constitutes acceptance of the revised DPA.
Signed on behalf of ShopShield.com
