FIG L.3 · DATA PROCESSING AGREEMENT

DPA.

! TEMPLATE. UNDER LEGAL REVIEW. NOT LEGAL ADVICE.

1. Roles.

For workspace content, the Customer is the Controller and SHIFT (operator of ARK) is the Processor. Each party complies with the GDPR in its role.

2. Scope and purpose.

SHIFT processes personal data on the Customer's documented instructions to provide the ARK service subscribed to by the Customer.

3. Categories of data and subjects.

Employees / team members of the Customer. Data: account identifiers, profile fields, records and notes the users choose to store, activity events, aggregated capability signals.

4. Subprocessors.

Current list at /legal/subprocessors. SHIFT will give reasonable notice of new subprocessors and allow the Customer to object on reasonable grounds.

5. International transfers.

Where personal data is transferred outside the EEA, transfers are covered by the EU Standard Contractual Clauses (SCCs) between the parties and imposed on subprocessors.

6. Security measures.

Row-level security on every table, security-definer functions for cross-tenant reads, TLS in transit, encryption at rest by the infrastructure provider, server-side-only AI calls, principle of least privilege for staff access. See /security.

7. Personnel.

SHIFT staff with access are bound by confidentiality.

8. Assistance.

SHIFT will reasonably assist the Customer with DSARs, DPIAs and prior consultations, taking into account the nature of the processing.

9. Breach notification.

SHIFT will notify the Customer of a personal-data breach affecting the Customer's data without undue delay and no later than 72 hours after becoming aware.

10. Audit rights.

The Customer may request the latest third-party audit reports (when available) and, once per year, a proportionate audit conducted with reasonable notice.

11. Return / deletion.

At contract end, SHIFT deletes or returns personal data within 60 days, except where retention is required by law.