Legal

Data Processing Agreement.

This is the real RoboShadow DPA, not a teaser. You are the controller. We are the processor. The clauses below are the template legal and procurement teams counter-sign.

v1.1 16 December 2025 Author Liz Teague England and Wales SOC 2 aligned

You decide. We process.

The customer is the Controller. Robo Shadow Ltd is the Processor. We only process personal data on your documented instructions.

Built for due diligence

Roles, security measures, subprocessors, breach notice and deletion sit in one document your supplier pack can take as-is.

Data stays in the EU

Platform data is hosted on AWS, primarily in EU and UK regions unless you agree otherwise. Transfers use standard contractual clauses where the law requires them.

Signable on request

This page is the public template. Email legal@roboshadow.com for a countersigned copy with your company name on it.

The agreement

RoboShadow Data Protection Agreement Template v1.1

This is the wording from the compliance pack uploaded by Liz Teague on 6 July 2026. Version 1.1, dated 16 December 2025. It supplements the privacy notice. The document itself also cites https://www.roboshadow.com/privacy-policy.

Amendment log

VersionDateDetailsAuthorPages
1.023 Oct 2025Original document publishedLiz TeagueAll
1.116 Dec 2025Updated to include link to Privacy PolicyLiz Teague2

This Data Processing Addendum ("DPA") forms part of the agreement between Robo Shadow Ltd ("RoboShadow", "Processor") and [Customer Name] ("Controller") and applies where RoboShadow processes Personal Data on behalf of the Controller.

This DPA is intended to reflect and supplement RoboShadow's Privacy Policy available at: https://www.roboshadow.com/privacy-policy

1. Definitions

For the purposes of this DPA:

  • "Applicable Data Protection Law" means the UK GDPR, EU GDPR (where applicable), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA), and any applicable data protection or privacy laws.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, as defined under Applicable Data Protection Law.
  • "Controller" means the entity that determines the purposes and means of Processing Personal Data.
  • "Processor" means the entity that Processes Personal Data on behalf of the Controller.
  • "Subprocessor" means any third party engaged by the Processor to Process Personal Data.

Capitalised terms not defined here have the meaning given in Applicable Data Protection Law.

2. Scope and Purpose of Processing

RoboShadow shall Process Personal Data only as necessary to provide the services agreed with the Controller and in accordance with:

  • this DPA;
  • the Controller's documented instructions; and
  • the purposes described in RoboShadow's Privacy Policy.

Processing activities may include hosting, storing, analysing, securing, transmitting, and otherwise using Personal Data to operate and support RoboShadow's services.

3. Controller Responsibilities

The Controller represents and warrants that:

  • it has a lawful basis for Processing Personal Data;
  • it has provided all required notices to Data Subjects;
  • its instructions to RoboShadow comply with Applicable Data Protection Law; and
  • it remains responsible for determining the purposes and means of Processing.

4. Processor Obligations

RoboShadow shall:

  1. Process Personal Data only on documented instructions from the Controller.
  2. Ensure that personnel authorised to Process Personal Data are subject to confidentiality obligations.
  3. Implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing, loss, destruction, or damage.
  4. Assist the Controller, where reasonably requested, in responding to Data Subject rights requests.
  5. Notify the Controller without undue delay if it becomes aware of a Personal Data breach affecting Controller data.
  6. Not knowingly engage in Processing that would violate Applicable Data Protection Law.

5. Subprocessors

The Controller authorises RoboShadow to engage Subprocessors to support service delivery.

RoboShadow shall:

  • ensure Subprocessors are bound by written agreements imposing data protection obligations equivalent to this DPA;
  • maintain a list of Subprocessors and make it available upon request; and
  • remain responsible for the acts and omissions of its Subprocessors.

Subprocessors can be found in Appendix A.

6. Data Subject Rights

Taking into account the nature of the Processing, RoboShadow shall provide reasonable assistance to the Controller to enable compliance with Data Subject rights requests, including access, correction, deletion, restriction, and objection, as required by law.

7. Security Measures

RoboShadow maintains appropriate administrative, technical, and physical safeguards designed to protect Personal Data, consistent with the measures described in its Privacy Policy and internal security policies which are written in line with SOC2 compliance.

8. Personal Data Breach

In the event of a Personal Data breach involving Controller Personal Data, RoboShadow shall notify the Controller without undue delay and provide information reasonably necessary for the Controller to comply with its legal obligations.

9. Retention and Deletion

Personal Data shall be retained only for as long as necessary to fulfil the purposes described in the Privacy Policy or as required by law. Upon termination of services, RoboShadow shall delete or return Personal Data in accordance with the Controller's instructions, unless retention is legally required.

10. International Transfers

Where Personal Data is transferred outside the UK or EEA, RoboShadow shall ensure appropriate safeguards are in place in accordance with Applicable Data Protection Law, including standard contractual clauses where required.

11. CCPA Compliance

To the extent CCPA applies, RoboShadow acts as a "Service Provider" and Processes Personal Data solely to provide the services, does not sell Personal Data, and does not retain, use, or disclose Personal Data for purposes other than those permitted by CCPA.

12. Governing Law

This DPA shall be governed by and construed in accordance with the laws of England and Wales, unless otherwise required by Applicable Data Protection Law.

13. Order of Precedence

In the event of a conflict between this DPA and any other agreement between the Parties, this DPA shall prevail with respect to data protection matters.

Signatures

This is the blank template. Ask legal@roboshadow.com if you need it filled and counter-signed.

For Robo Shadow Ltd (Processor)

Name

Title

Date

For [Customer Name] (Controller)

Name

Title

Date

Appendix A. Subprocessors

Robo Shadow Ltd uses the following subprocessors to support delivery of its services. Each subprocessor is subject to contractual data protection obligations consistent with applicable data protection laws.

ProviderPurposeData processedLocation
Amazon Web Services (AWS) Hosting and operation of RoboShadow services Customer and service data stored within RoboShadow systems AWS data centres (primarily EU/UK regions unless otherwise agreed)
Microsoft 365 (Microsoft Corporation) Business email and communications Business contact details and any information submitted to RoboShadow via email Microsoft global infrastructure (with appropriate transfer safeguards)
Google Firebase (Google LLC) Authentication and user login services User login credentials and authentication metadata Google global infrastructure (with appropriate transfer safeguards)
Contractors Support business operations Contractors do not have access to personal data unless explicitly required and approved. A list of contractors can be provided upon request. As approved

The Trust Centre also keeps a live operational list. That list currently names extra vendors used for billing, CRM, CDN and email. If those two lists should be one list, say so and we will line them up.

See the Trust Centre sub-processor list

Need a countersigned copy?

Procurement and security teams can request the signed DPA, the sub-processor list, and the rest of the compliance pack.

Request the documents Trust Centre Back to Legal