Article 28

Data processing agreement

This agreement describes the commitments applicable to data processed by Shugoi on behalf of a customer. It complements the contractual terms and order where such processing takes place.

Scope

When the customer determines the purposes of protecting its website, Shugoi processes the documented technical data on its behalf for the service term and only on documented lawful instructions.

Confidentiality and security

Access is limited to authorised persons. Shugoi applies account separation, secret encryption, pseudonymisation, access control, logging, backups and vulnerability management proportionate to risk.

Assistance

Shugoi assists the customer with rights requests, impact assessments, security, incidents and authority consultations to the extent of available information and the nature of processing.

Subprocessors and transfers

Providers are publicly listed. Shugoi imposes equivalent obligations, gives notice of material changes and documents safeguards for transfers outside the EEA.

End of service

At the customer's choice and subject to legal duties, Shugoi returns or deletes data processed on its behalf, then purges backups according to their documented cycle.

Audit

Shugoi provides information needed to demonstrate Article 28 compliance and permits a reasonable audit scoped to preserve the security and confidentiality of other customers.