Data Processing Agreement.
This is the real RoboShadow DPA, not a teaser. You are the controller. We are the processor. The clauses below are the template legal and procurement teams counter-sign.
You decide. We process.
The customer is the Controller. Robo Shadow Ltd is the Processor. We only process personal data on your documented instructions.
Built for due diligence
Roles, security measures, subprocessors, breach notice and deletion sit in one document your supplier pack can take as-is.
Data stays in the EU
Platform data is hosted on AWS, primarily in EU and UK regions unless you agree otherwise. Transfers use standard contractual clauses where the law requires them.
Signable on request
This page is the public template. Email legal@roboshadow.com for a countersigned copy with your company name on it.
RoboShadow Data Protection Agreement Template v1.1
This is the wording from the compliance pack uploaded by Liz Teague on 6 July 2026. Version 1.1, dated 16 December 2025. It supplements the privacy notice. The document itself also cites https://www.roboshadow.com/privacy-policy.
Amendment log
| Version | Date | Details | Author | Pages |
|---|---|---|---|---|
| 1.0 | 23 Oct 2025 | Original document published | Liz Teague | All |
| 1.1 | 16 Dec 2025 | Updated to include link to Privacy Policy | Liz Teague | 2 |
This Data Processing Addendum ("DPA") forms part of the agreement between Robo Shadow Ltd ("RoboShadow", "Processor") and [Customer Name] ("Controller") and applies where RoboShadow processes Personal Data on behalf of the Controller.
This DPA is intended to reflect and supplement RoboShadow's Privacy Policy available at: https://www.roboshadow.com/privacy-policy
1. Definitions
For the purposes of this DPA:
- "Applicable Data Protection Law" means the UK GDPR, EU GDPR (where applicable), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA), and any applicable data protection or privacy laws.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, as defined under Applicable Data Protection Law.
- "Controller" means the entity that determines the purposes and means of Processing Personal Data.
- "Processor" means the entity that Processes Personal Data on behalf of the Controller.
- "Subprocessor" means any third party engaged by the Processor to Process Personal Data.
Capitalised terms not defined here have the meaning given in Applicable Data Protection Law.
2. Scope and Purpose of Processing
RoboShadow shall Process Personal Data only as necessary to provide the services agreed with the Controller and in accordance with:
- this DPA;
- the Controller's documented instructions; and
- the purposes described in RoboShadow's Privacy Policy.
Processing activities may include hosting, storing, analysing, securing, transmitting, and otherwise using Personal Data to operate and support RoboShadow's services.
3. Controller Responsibilities
The Controller represents and warrants that:
- it has a lawful basis for Processing Personal Data;
- it has provided all required notices to Data Subjects;
- its instructions to RoboShadow comply with Applicable Data Protection Law; and
- it remains responsible for determining the purposes and means of Processing.
4. Processor Obligations
RoboShadow shall:
- Process Personal Data only on documented instructions from the Controller.
- Ensure that personnel authorised to Process Personal Data are subject to confidentiality obligations.
- Implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing, loss, destruction, or damage.
- Assist the Controller, where reasonably requested, in responding to Data Subject rights requests.
- Notify the Controller without undue delay if it becomes aware of a Personal Data breach affecting Controller data.
- Not knowingly engage in Processing that would violate Applicable Data Protection Law.
5. Subprocessors
The Controller authorises RoboShadow to engage Subprocessors to support service delivery.
RoboShadow shall:
- ensure Subprocessors are bound by written agreements imposing data protection obligations equivalent to this DPA;
- maintain a list of Subprocessors and make it available upon request; and
- remain responsible for the acts and omissions of its Subprocessors.
Subprocessors can be found in Appendix A.
6. Data Subject Rights
Taking into account the nature of the Processing, RoboShadow shall provide reasonable assistance to the Controller to enable compliance with Data Subject rights requests, including access, correction, deletion, restriction, and objection, as required by law.
7. Security Measures
RoboShadow maintains appropriate administrative, technical, and physical safeguards designed to protect Personal Data, consistent with the measures described in its Privacy Policy and internal security policies which are written in line with SOC2 compliance.
8. Personal Data Breach
In the event of a Personal Data breach involving Controller Personal Data, RoboShadow shall notify the Controller without undue delay and provide information reasonably necessary for the Controller to comply with its legal obligations.
9. Retention and Deletion
Personal Data shall be retained only for as long as necessary to fulfil the purposes described in the Privacy Policy or as required by law. Upon termination of services, RoboShadow shall delete or return Personal Data in accordance with the Controller's instructions, unless retention is legally required.
10. International Transfers
Where Personal Data is transferred outside the UK or EEA, RoboShadow shall ensure appropriate safeguards are in place in accordance with Applicable Data Protection Law, including standard contractual clauses where required.
11. CCPA Compliance
To the extent CCPA applies, RoboShadow acts as a "Service Provider" and Processes Personal Data solely to provide the services, does not sell Personal Data, and does not retain, use, or disclose Personal Data for purposes other than those permitted by CCPA.
12. Governing Law
This DPA shall be governed by and construed in accordance with the laws of England and Wales, unless otherwise required by Applicable Data Protection Law.
13. Order of Precedence
In the event of a conflict between this DPA and any other agreement between the Parties, this DPA shall prevail with respect to data protection matters.
Signatures
This is the blank template. Ask legal@roboshadow.com if you need it filled and counter-signed.
For Robo Shadow Ltd (Processor)
Name
Title
Date
For [Customer Name] (Controller)
Name
Title
Date
Appendix A. Subprocessors
Robo Shadow Ltd uses the following subprocessors to support delivery of its services. Each subprocessor is subject to contractual data protection obligations consistent with applicable data protection laws.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting and operation of RoboShadow services | Customer and service data stored within RoboShadow systems | AWS data centres (primarily EU/UK regions unless otherwise agreed) |
| Microsoft 365 (Microsoft Corporation) | Business email and communications | Business contact details and any information submitted to RoboShadow via email | Microsoft global infrastructure (with appropriate transfer safeguards) |
| Google Firebase (Google LLC) | Authentication and user login services | User login credentials and authentication metadata | Google global infrastructure (with appropriate transfer safeguards) |
| Contractors | Support business operations | Contractors do not have access to personal data unless explicitly required and approved. A list of contractors can be provided upon request. | As approved |
The Trust Centre also keeps a live operational list. That list currently names extra vendors used for billing, CRM, CDN and email. If those two lists should be one list, say so and we will line them up.
Need a countersigned copy?
Procurement and security teams can request the signed DPA, the sub-processor list, and the rest of the compliance pack.