Skip to content

Data Processing Agreement

A summary of the Data Processing Agreement we sign with clients before processing personal data on their behalf. This page is informational; the executed DPA governs any specific engagement.

Last updated

When a DPA applies

Any engagement where Shoora Global processes personal data on a client’s behalf — as their processor — is covered by a signed DPA, executed before that processing begins.

What the DPA covers

  • The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects involved.
  • Our obligation to process data only on documented client instructions.
  • Confidentiality commitments binding everyone with access to the data.
  • Security measures appropriate to the risk, consistent with our information-security programme.
  • Sub-processor terms, including the requirement to flow down equivalent obligations and to notify clients of changes.
  • Assistance with data-subject requests, and with the client’s own compliance and breach-notification obligations.
  • Return or deletion of data at the end of the engagement, and audit rights.
  • International transfer terms, including Standard Contractual Clauses where applicable.

Requesting the full agreement

The full DPA template is available via the document-request flow on our Security & Compliance page, or directly from your account owner during scoping.