Data Processing Agreement Shyftlabs

Version 2.0 · Effective 18 September 2026

What this document is. These are our standard terms for handling personal data on a client’s behalf. Where incorporated into an agreement between us, they form part of that agreement and take effect through it rather than on their own. We publish them so you can review them during procurement without waiting for a draft. The specifics of what we process for you, and why, are set out in Annex 1, where applicable, which we complete for each engagement.

1. Parties and interpretation

This Data Processing Agreement (“DPA”) is between Illuminz Solutions Inc., a company incorporated in Canada and operating as ShyftLabs, of 100 Yonge St, Suite 1501, Toronto, Ontario M5C 2W1, Canada (“ShyftLabs”, “we”, “us”), and the client named in the Agreement (“Customer”, “you”), where this DPA is incorporated into or otherwise made applicable to that Agreement.

“Agreement” means the master services agreement, engagement letter, statement of work, order form, or other written agreement between us that incorporates or otherwise makes this DPA applicable. “Data Protection Law” means every law on the protection of personal data that applies to our processing under the Agreement, including the EU General Data Protection Regulation (2016/679) (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, Canada’s Personal Information Protection and Electronic Documents Act, Quebec’s Act respecting the protection of personal information in the private sector, and the California Consumer Privacy Act as amended.

“Customer Personal Data” means personal data we process on your behalf under the Agreement. Terms such as controller, processor, data subject, personal data, processing and personal data breach have the meanings given to them in the GDPR, and equivalent terms under other Data Protection Law are read accordingly.

2. Roles

For Customer Personal Data, to the extent you act as controller, you are the controller and we are the processor. Where you are yourself a processor acting for another controller, we are a sub-processor, and references to your instructions include the instructions that controller has given you.

You are responsible for the lawfulness of the personal data you give us, for having a valid basis for the processing you instruct, and for giving data subjects the notices Data Protection Law requires.

This DPA does not cover personal data for which we are the controller, such as the business contact details of your staff who deal with us. Our Privacy Policy explains that processing.

3. Our instructions

We process Customer Personal Data only on your documented instructions, which are the Agreement, this DPA, Annex 1 where completed or applicable, and any further written instruction you give us. We do not process it for our own purposes, and we do not sell it or share it for cross-context behavioral advertising.

If we are required by law to process Customer Personal Data other than as you have instructed, we will tell you before we do, unless that law prohibits us from telling you.

If we believe an instruction breaches Data Protection Law, we will tell you promptly. We may suspend or decline the affected processing until the instruction is resolved.

4. People

We restrict access to Customer Personal Data to personnel who need it to deliver the services. Everyone with access is bound by confidentiality obligations that survive the end of their engagement with us, is subject to appropriate screening or background checks where permitted and appropriate, and receives data protection and security training.

5. Security

We maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to data subjects. Annex 2 describes those measures.

Where Customer Personal Data is processed within the Customer’s environment or systems, the Customer remains responsible for the security, configuration and operation of those systems and infrastructure, while ShyftLabs is responsible for the security measures applicable to its personnel, access and processing activities under the Agreement.

Illuminz Solutions Inc. operates an information security management system certified to ISO/IEC 27001:2022 (certificate IC-IS-2507502) and a privacy information management system certified to ISO/IEC 27701:2019 (certificate IC-PI-2602112). Current certificates and assessment reports are available at trust.shyftlabs.io.

We may update the measures in Annex 2 over time, provided the updates do not materially reduce the overall level of protection for Customer Personal Data.

6. Sub-processors

You give us general authorization to engage sub-processors. Our current sub-processors are listed at trust.shyftlabs.io.

Before we add or replace a sub-processor, we will give you reasonable advance notice, which may be provided through our sub-processor list or other written notice. You may object on reasonable data protection grounds within that period. If you do, we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected services without penalty, and your sole remedy is that termination and a refund of prepaid fees for the terminated services.

We impose data protection obligations on each sub-processor that provide an appropriate level of protection for Customer Personal Data and satisfy applicable Data Protection Law, and we remain liable to you for their performance as if it were our own.

7. Data subject requests

Taking into account the nature of the processing, we will provide reasonable assistance, as required by applicable Data Protection Law, to help you respond to requests from data subjects exercising their rights, by appropriate technical and organizational measures and so far as it is reasonably possible.

If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request. We will refer or forward the request to you without undue delay, unless you have instructed us otherwise in writing.

8. Other assistance

Taking into account the nature of the processing and the information available to us, we will give you reasonable help as required by applicable Data Protection Law with:

  • keeping Customer Personal Data secure;
  • notifying personal data breaches to supervisory authorities and data subjects;
  • data protection impact assessments; and
  • prior consultation with a supervisory authority.

Where this help goes beyond what is reasonably included in the services, we may charge our reasonable costs, agreed with you in advance.

9. Personal data breach

If we become aware of a personal data breach affecting Customer Personal Data in connection with our processing under the Agreement, we will notify you without undue delay. Our notification will describe, to the extent known and reasonably available at the time, the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures we have taken or propose to take, and a contact point for more information. Where we cannot provide all of that at once, we will provide it in phases as it becomes available.

We will take reasonable steps to contain the breach and mitigate its effects, and we will keep a record of it.

Unsuccessful access attempts and routine network attacks that do not compromise the security of Customer Personal Data are not personal data breaches for the purposes of this clause. Our notification is not an acknowledgement of fault or liability.

10. International transfers

Customer Personal Data is generally processed within the Customer’s environment or systems, where the services are performed there. Where ShyftLabs or an authorized sub-processor processes Customer Personal Data outside the Customer’s environment, such processing may occur in Canada, including in the AWS Canada (Central) region, and in the other locations set out in Annex 1 or our sub-processor list.

Transfers from the EEA. The European Commission has decided that Canada provides an adequate level of protection for personal data handled by commercial organizations subject to Canada’s federal privacy law, and we rely on that decision where it applies to the processing. Where it does not apply, the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 are incorporated into this DPA and apply to the transfer, on the basis set out in Annex 4.

Transfers from the UK. The Standard Contractual Clauses apply as varied by the UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, completed as set out in Annex 4.

Transfers from Switzerland. The Standard Contractual Clauses apply, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority being the Federal Data Protection and Information Commissioner, and the term “member state” not being read to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence.

If any transfer mechanism we rely on ceases to be valid, we will take reasonable steps to implement an appropriate alternative transfer mechanism where required by applicable Data Protection Law.

11. Audit

We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint to the extent required by applicable Data Protection Law.

You agree to satisfy an audit request first by reviewing our current certifications and assessment reports, which we may make available through our trust portal, under appropriate confidentiality restrictions, or otherwise on request. If those do not reasonably answer your question, you may conduct an audit to the extent required by applicable Data Protection Law, on the following basis: no more than once in any twelve months, unless a supervisory authority requires otherwise or a personal data breach has affected your data; on at least 30 days’ written notice; during business hours; without unreasonably disrupting our operations; subject to confidentiality obligations; and not in a way that gives you access to another client’s data. You bear your own costs, and our reasonable costs where an audit goes beyond the above.

12. Return and deletion

On termination or expiry of the Agreement, we will, at your choice, return or delete Customer Personal Data in our possession or control. This obligation does not apply to Customer Personal Data that remains solely within your environment or systems.

We may retain Customer Personal Data where the law requires it, and for as long as the law requires. Anything we retain remains subject to this DPA. Data held in routine backups under our control is deleted in accordance with our backup retention cycle.

13. Liability

Each party’s liability under this DPA is subject to the exclusions and limits on liability in the Agreement.

14. Term, precedence and governing law

This DPA takes effect when it is incorporated into or otherwise made applicable to the Agreement, and continues for as long as we process Customer Personal Data under that Agreement.

Where this DPA is incorporated into the Agreement, it forms part of the Agreement. If the parties have entered into a separate data processing agreement or other expressly agreed data protection terms for the applicable services, those terms will prevail over this DPA to the extent of any conflict. Otherwise, where this DPA conflicts with the Agreement on the protection of personal data, this DPA prevails. Where the Standard Contractual Clauses conflict with this DPA or any other agreement between the parties, the Clauses prevail to the extent required by their terms. In all other respects the Agreement governs.

This DPA is governed by the law that governs the Agreement. Where the Agreement does not specify, it is governed by the laws of the Province of Ontario and the federal laws of Canada that apply there. This does not affect the governing law and forum of the Standard Contractual Clauses, which are set out in Annex 4.

15. Contact

dpo@shyftlabs.io

Illuminz Solutions Inc. (operating as ShyftLabs)
Attn: Data Protection Officer
100 Yonge St, Suite 1501
Toronto, Ontario M5C 2W1
Canada

Annex 1 — Details of processing

Where this DPA applies, the details below may be completed in the Agreement, statement of work, order form, or other applicable engagement documentation. Where they are not completed separately, the description in the applicable scope of services will apply.

Subject matter

The services described in the Agreement

Duration

The term of the Agreement, plus any retention period stated in it

Nature and purpose

To be completed. For example: data ingestion, cleansing, standardization, enrichment, storage, analysis, model development, application development or support, and other processing necessary to provide the services. Where applicable, processing may take place within the Customer’s environment or systems.

Categories of data subjects

To be completed. For example: the Customer’s own customers, employees, or end users

Types of personal data

To be completed

Special category data

To be completed. State none where none is processed, and state the additional safeguards where any is

Frequency of transfer

As required for the services, which may include continuous or periodic access or transfer

Processing locations

The Customer’s environment or systems, where applicable; Canada, including AWS Canada Central where ShyftLabs-hosted processing is used; the locations of applicable sub-processors listed in Annex 3; and any additional location stated in the Agreement.

Annex 2 — Technical and organizational measures

Our measures include, as applicable to the services and the environment in which Customer Personal Data is processed, and are supported by the security and privacy management systems described in clause 5:

  • Access control. Role-based access, least privilege, multi-factor authentication, and periodic access reviews. Access to production is restricted to authorized personnel.
  • Encryption. Personal data encrypted in transit using TLS and, where ShyftLabs controls the relevant storage environment, encrypted at rest.
  • Segregation. Where ShyftLabs hosts or operates the relevant environment, client data is isolated within our multi-tenant cloud environment. Development, test and production environments are kept separate. Production data is not used for testing.
  • Resilience. Where ShyftLabs hosts or operates the relevant infrastructure, multi-availability-zone cloud infrastructure, with periodic backups and backup restoration testing.
  • Network and application security. Where ShyftLabs controls the relevant systems, web application firewall, secure APIs for backend integration, and audit logging across systems with logs available for extraction.
  • Vulnerability management. Periodic vulnerability assessment and penetration testing of systems within ShyftLabs’ responsibility, with critical findings remediated without undue delay, and timely security patching.
  • Personnel. Background checks to the extent permitted by law, confidentiality agreements, and periodic security and privacy training.
  • Supplier management. Risk assessment of suppliers, with written data protection terms in place before any personal data is shared with them on our behalf.
  • Incident management. Documented incident response procedures with monitoring, escalation and post-incident review.
  • Governance. Records of processing activities, data protection impact assessments, change management for processing changes, and privacy by design and by default in our development lifecycle.

Where Customer Personal Data is processed within the Customer’s environment or systems, the Customer remains responsible for the security, configuration and operation of those systems and infrastructure, except to the extent responsibility for specific systems, configurations, controls or activities is expressly assigned to ShyftLabs under the Agreement. ShyftLabs remains responsible for the security controls applicable to its personnel, access, systems and processing activities under the Agreement.

Annex 3 — Sub-processors

The current list is published at trust.shyftlabs.io and is incorporated into this DPA by reference. Changes are notified as set out in clause 6.

Annex 4 — Standard Contractual Clauses

Where the Standard Contractual Clauses apply under clause 10, Module Two (controller to processor) applies where the Customer acts as controller, and Module Three (processor to processor) applies where the Customer acts as processor on behalf of another controller, with the Customer as the data exporter and ShyftLabs as data importer, and with the following selections:

Clause 7, docking clause

Applies

Clause 9(a), sub-processors

Option 2, general written authorization, the notice period set out in clause 6

Clause 11(a), independent dispute resolution

Does not apply

Clause 17, governing law

The law of Ireland

Clause 18(b), forum

The courts of Ireland

Annex I.A, parties

As set out in the Agreement and in clause 1 of this DPA

Annex I.B, description of transfer

As set out in Annex 1

Annex I.C, competent supervisory authority

The authority of the EEA member state in which the data exporter is established, or, where the exporter is not established in the EEA, the authority of the member state in which its Article 27 representative is established

Annex II, security measures

As set out in Annex 2

Annex III, sub-processors

As set out in Annex 3

For transfers from the UK, the UK International Data Transfer Addendum applies to the Clauses. In Table 1 the parties are as set out in clause 1. In Tables 2 and 3 the selections above apply. In Table 4, neither party may end the Addendum as set out in section 19.