Data Processing Agreement
A summary of the Data Processing Agreement we sign with clients before processing personal data on their behalf. This page is informational; the executed DPA governs any specific engagement.
Last updated
When a DPA applies
Any engagement where Shoora Global processes personal data on a client’s behalf — as their processor — is covered by a signed DPA, executed before that processing begins.
What the DPA covers
- The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects involved.
- Our obligation to process data only on documented client instructions.
- Confidentiality commitments binding everyone with access to the data.
- Security measures appropriate to the risk, consistent with our information-security programme.
- Sub-processor terms, including the requirement to flow down equivalent obligations and to notify clients of changes.
- Assistance with data-subject requests, and with the client’s own compliance and breach-notification obligations.
- Return or deletion of data at the end of the engagement, and audit rights.
- International transfer terms, including Standard Contractual Clauses where applicable.
Requesting the full agreement
The full DPA template is available via the document-request flow on our Security & Compliance page, or directly from your account owner during scoping.
