Version 2.0 · Effective 18 September 2026
What this document is. These are our standard terms for handling personal data on a client’s behalf. Where incorporated into an agreement between us, they form part of that agreement and take effect through it rather than on their own. We publish them so you can review them during procurement without waiting for a draft. The specifics of what we process for you, and why, are set out in Annex 1, where applicable, which we complete for each engagement.
This Data Processing Agreement (“DPA”) is between Illuminz Solutions Inc., a company incorporated in Canada and operating as ShyftLabs, of 100 Yonge St, Suite 1501, Toronto, Ontario M5C 2W1, Canada (“ShyftLabs”, “we”, “us”), and the client named in the Agreement (“Customer”, “you”), where this DPA is incorporated into or otherwise made applicable to that Agreement.
“Agreement” means the master services agreement, engagement letter, statement of work, order form, or other written agreement between us that incorporates or otherwise makes this DPA applicable. “Data Protection Law” means every law on the protection of personal data that applies to our processing under the Agreement, including the EU General Data Protection Regulation (2016/679) (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, Canada’s Personal Information Protection and Electronic Documents Act, Quebec’s Act respecting the protection of personal information in the private sector, and the California Consumer Privacy Act as amended.
“Customer Personal Data” means personal data we process on your behalf under the Agreement. Terms such as controller, processor, data subject, personal data, processing and personal data breach have the meanings given to them in the GDPR, and equivalent terms under other Data Protection Law are read accordingly.
For Customer Personal Data, to the extent you act as controller, you are the controller and we are the processor. Where you are yourself a processor acting for another controller, we are a sub-processor, and references to your instructions include the instructions that controller has given you.
You are responsible for the lawfulness of the personal data you give us, for having a valid basis for the processing you instruct, and for giving data subjects the notices Data Protection Law requires.
This DPA does not cover personal data for which we are the controller, such as the business contact details of your staff who deal with us. Our Privacy Policy explains that processing.
We process Customer Personal Data only on your documented instructions, which are the Agreement, this DPA, Annex 1 where completed or applicable, and any further written instruction you give us. We do not process it for our own purposes, and we do not sell it or share it for cross-context behavioral advertising.
If we are required by law to process Customer Personal Data other than as you have instructed, we will tell you before we do, unless that law prohibits us from telling you.
If we believe an instruction breaches Data Protection Law, we will tell you promptly. We may suspend or decline the affected processing until the instruction is resolved.
We restrict access to Customer Personal Data to personnel who need it to deliver the services. Everyone with access is bound by confidentiality obligations that survive the end of their engagement with us, is subject to appropriate screening or background checks where permitted and appropriate, and receives data protection and security training.
We maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to data subjects. Annex 2 describes those measures.
Where Customer Personal Data is processed within the Customer’s environment or systems, the Customer remains responsible for the security, configuration and operation of those systems and infrastructure, while ShyftLabs is responsible for the security measures applicable to its personnel, access and processing activities under the Agreement.
Illuminz Solutions Inc. operates an information security management system certified to ISO/IEC 27001:2022 (certificate IC-IS-2507502) and a privacy information management system certified to ISO/IEC 27701:2019 (certificate IC-PI-2602112). Current certificates and assessment reports are available at trust.shyftlabs.io.
We may update the measures in Annex 2 over time, provided the updates do not materially reduce the overall level of protection for Customer Personal Data.
You give us general authorization to engage sub-processors. Our current sub-processors are listed at trust.shyftlabs.io.
Before we add or replace a sub-processor, we will give you reasonable advance notice, which may be provided through our sub-processor list or other written notice. You may object on reasonable data protection grounds within that period. If you do, we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected services without penalty, and your sole remedy is that termination and a refund of prepaid fees for the terminated services.
We impose data protection obligations on each sub-processor that provide an appropriate level of protection for Customer Personal Data and satisfy applicable Data Protection Law, and we remain liable to you for their performance as if it were our own.
Taking into account the nature of the processing, we will provide reasonable assistance, as required by applicable Data Protection Law, to help you respond to requests from data subjects exercising their rights, by appropriate technical and organizational measures and so far as it is reasonably possible.
If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request. We will refer or forward the request to you without undue delay, unless you have instructed us otherwise in writing.
Taking into account the nature of the processing and the information available to us, we will give you reasonable help as required by applicable Data Protection Law with:
Where this help goes beyond what is reasonably included in the services, we may charge our reasonable costs, agreed with you in advance.
If we become aware of a personal data breach affecting Customer Personal Data in connection with our processing under the Agreement, we will notify you without undue delay. Our notification will describe, to the extent known and reasonably available at the time, the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures we have taken or propose to take, and a contact point for more information. Where we cannot provide all of that at once, we will provide it in phases as it becomes available.
We will take reasonable steps to contain the breach and mitigate its effects, and we will keep a record of it.
Unsuccessful access attempts and routine network attacks that do not compromise the security of Customer Personal Data are not personal data breaches for the purposes of this clause. Our notification is not an acknowledgement of fault or liability.
Customer Personal Data is generally processed within the Customer’s environment or systems, where the services are performed there. Where ShyftLabs or an authorized sub-processor processes Customer Personal Data outside the Customer’s environment, such processing may occur in Canada, including in the AWS Canada (Central) region, and in the other locations set out in Annex 1 or our sub-processor list.
Transfers from the EEA. The European Commission has decided that Canada provides an adequate level of protection for personal data handled by commercial organizations subject to Canada’s federal privacy law, and we rely on that decision where it applies to the processing. Where it does not apply, the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 are incorporated into this DPA and apply to the transfer, on the basis set out in Annex 4.
Transfers from the UK. The Standard Contractual Clauses apply as varied by the UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, completed as set out in Annex 4.
Transfers from Switzerland. The Standard Contractual Clauses apply, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority being the Federal Data Protection and Information Commissioner, and the term “member state” not being read to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence.
If any transfer mechanism we rely on ceases to be valid, we will take reasonable steps to implement an appropriate alternative transfer mechanism where required by applicable Data Protection Law.
We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint to the extent required by applicable Data Protection Law.
You agree to satisfy an audit request first by reviewing our current certifications and assessment reports, which we may make available through our trust portal, under appropriate confidentiality restrictions, or otherwise on request. If those do not reasonably answer your question, you may conduct an audit to the extent required by applicable Data Protection Law, on the following basis: no more than once in any twelve months, unless a supervisory authority requires otherwise or a personal data breach has affected your data; on at least 30 days’ written notice; during business hours; without unreasonably disrupting our operations; subject to confidentiality obligations; and not in a way that gives you access to another client’s data. You bear your own costs, and our reasonable costs where an audit goes beyond the above.
On termination or expiry of the Agreement, we will, at your choice, return or delete Customer Personal Data in our possession or control. This obligation does not apply to Customer Personal Data that remains solely within your environment or systems.
We may retain Customer Personal Data where the law requires it, and for as long as the law requires. Anything we retain remains subject to this DPA. Data held in routine backups under our control is deleted in accordance with our backup retention cycle.
Each party’s liability under this DPA is subject to the exclusions and limits on liability in the Agreement.
This DPA takes effect when it is incorporated into or otherwise made applicable to the Agreement, and continues for as long as we process Customer Personal Data under that Agreement.
Where this DPA is incorporated into the Agreement, it forms part of the Agreement. If the parties have entered into a separate data processing agreement or other expressly agreed data protection terms for the applicable services, those terms will prevail over this DPA to the extent of any conflict. Otherwise, where this DPA conflicts with the Agreement on the protection of personal data, this DPA prevails. Where the Standard Contractual Clauses conflict with this DPA or any other agreement between the parties, the Clauses prevail to the extent required by their terms. In all other respects the Agreement governs.
This DPA is governed by the law that governs the Agreement. Where the Agreement does not specify, it is governed by the laws of the Province of Ontario and the federal laws of Canada that apply there. This does not affect the governing law and forum of the Standard Contractual Clauses, which are set out in Annex 4.
Illuminz Solutions Inc. (operating as ShyftLabs)
Attn: Data Protection Officer
100 Yonge St, Suite 1501
Toronto, Ontario M5C 2W1
Canada
Where this DPA applies, the details below may be completed in the Agreement, statement of work, order form, or other applicable engagement documentation. Where they are not completed separately, the description in the applicable scope of services will apply.
Subject matter
The services described in the Agreement
Duration
The term of the Agreement, plus any retention period stated in it
Nature and purpose
To be completed. For example: data ingestion, cleansing, standardization, enrichment, storage, analysis, model development, application development or support, and other processing necessary to provide the services. Where applicable, processing may take place within the Customer’s environment or systems.
Categories of data subjects
To be completed. For example: the Customer’s own customers, employees, or end users
Types of personal data
To be completed
Special category data
To be completed. State none where none is processed, and state the additional safeguards where any is
Frequency of transfer
As required for the services, which may include continuous or periodic access or transfer
Processing locations
The Customer’s environment or systems, where applicable; Canada, including AWS Canada Central where ShyftLabs-hosted processing is used; the locations of applicable sub-processors listed in Annex 3; and any additional location stated in the Agreement.
Our measures include, as applicable to the services and the environment in which Customer Personal Data is processed, and are supported by the security and privacy management systems described in clause 5:
Where Customer Personal Data is processed within the Customer’s environment or systems, the Customer remains responsible for the security, configuration and operation of those systems and infrastructure, except to the extent responsibility for specific systems, configurations, controls or activities is expressly assigned to ShyftLabs under the Agreement. ShyftLabs remains responsible for the security controls applicable to its personnel, access, systems and processing activities under the Agreement.
The current list is published at trust.shyftlabs.io and is incorporated into this DPA by reference. Changes are notified as set out in clause 6.
Where the Standard Contractual Clauses apply under clause 10, Module Two (controller to processor) applies where the Customer acts as controller, and Module Three (processor to processor) applies where the Customer acts as processor on behalf of another controller, with the Customer as the data exporter and ShyftLabs as data importer, and with the following selections:
Clause 7, docking clause
Applies
Clause 9(a), sub-processors
Option 2, general written authorization, the notice period set out in clause 6
Clause 11(a), independent dispute resolution
Does not apply
Clause 17, governing law
The law of Ireland
Clause 18(b), forum
The courts of Ireland
Annex I.A, parties
As set out in the Agreement and in clause 1 of this DPA
Annex I.B, description of transfer
As set out in Annex 1
Annex I.C, competent supervisory authority
The authority of the EEA member state in which the data exporter is established, or, where the exporter is not established in the EEA, the authority of the member state in which its Article 27 representative is established
Annex II, security measures
As set out in Annex 2
Annex III, sub-processors
As set out in Annex 3
For transfers from the UK, the UK International Data Transfer Addendum applies to the Clauses. In Table 1 the parties are as set out in clause 1. In Tables 2 and 3 the selections above apply. In Table 4, neither party may end the Addendum as set out in section 19.