Data Processing Agreement (DPA)

Last updated: January 2025

1. Introduction

This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between Shelfu (“we,” “our,” or “us”) and you (“the User”). It governs how we process personal data on your behalf when you use the Shelfu platform.

2. Definitions

  • “Personal Data” means any information relating to an identified or identifiable natural person.
  • “Processing” means any operation performed on Personal Data, such as collection, storage, use, or deletion.
  • “Controller” refers to the entity that determines the purposes and means of processing Personal Data.
  • “Processor” refers to Shelfu, which processes data on behalf of the Controller.

3. Roles and Responsibilities

As the Controller, you are responsible for ensuring that your use of Shelfu complies with applicable data protection laws. Shelfu acts as a Processor and will only process Personal Data in accordance with your documented instructions.

4. Data Processing and Purpose

Shelfu processes Personal Data solely for the purpose of providing and improving our services, managing user accounts, ensuring platform security, and offering user support.

5. Confidentiality

All employees and contractors of Shelfu who have access to Personal Data are bound by strict confidentiality obligations. Unauthorized disclosure or misuse of data is strictly prohibited and may result in disciplinary action.

6. Security Measures

Shelfu implements technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access control, and regular security reviews to protect against data breaches and unauthorized access.

7. Subprocessors

Shelfu may engage third-party subprocessors to assist in providing our services. Each subprocessor is carefully vetted and bound by equivalent data protection obligations to those set forth in this Agreement.

8. International Data Transfers

If Personal Data is transferred outside your jurisdiction, Shelfu ensures that adequate safeguards (such as Standard Contractual Clauses) are in place to protect the data in compliance with applicable laws.

9. Data Subject Rights

Shelfu assists the Controller in responding to data subject requests, including access, correction, and deletion of personal information, in accordance with applicable laws.

10. Term and Termination

This Agreement remains in effect for as long as Shelfu processes Personal Data on behalf of the User. Upon termination, Shelfu will securely delete or return all Personal Data unless retention is required by law.

11. Contact Information

For questions regarding this Data Processing Agreement or data privacy matters, contact us at privacy@shelfu.app.