Data Processing Agreement
Last updated 1 October 2026
This agreement covers the personal data we process on your behalf when your organisation uses ShieldGuard. It forms part of our Terms of Service, and applies automatically when you accept them. It is written for the GDPR and, where equivalent, the UK GDPR.
1. Roles and scope
You — the company whose workspace it is — are the controller of the personal data in that workspace. Xu Jack is the processor. We process that data only on your documented instructions, which include using the service as described in our documentation and configuring it through the interface. We will tell you if an instruction appears to breach data protection law.
2. What is processed
- Subject matter
- Provision of the ShieldGuard service to your workspace.
- Duration
- For as long as your workspace is active, plus the retention window described in section 9.
- Nature and purpose
- Storing and organising employee and training records; sending reminder and notification email; processing uploaded certificates; producing compliance reports.
- Categories of data subjects
- Your employees, contractors, and other people you track training for, plus the staff you invite into the workspace.
- Types of personal data
- Names, work email addresses, departments, roles, optional phone numbers, training assignments and completion dates, review decisions, uploaded certificate files, and the text read from them.
- Special categories
- Certificates can incidentally reveal health data (for example first-aid or medical fitness records). You must have a lawful basis for uploading them; we process them only to display and review them for you.
3. Our obligations
- Process personal data only on your instructions, and only for the purposes above.
- Ensure the people who can access the data are bound by confidentiality.
- Implement the security measures in section 6, and take reasonable steps to ensure they hold.
- Help you respond to data subject requests. Where someone contacts us directly, we will refer them to you unless the law requires otherwise.
- Inform you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notifications.
- Help with impact assessments and prior consultations, within reason and taking account of the information we already hold.
- Delete or return personal data at the end of the arrangement, as described in section 9.
4. Sub-processors
You give general authorisation for the sub-processors below, each bound by terms consistent with this agreement:
- Supabase — database, authentication, and file storage;
- Stripe — subscription billing and invoices;
- Resend — email delivery for invitations and reminders;
- Google Analytics and Crisp — only when the operator enables them for the website.
We will give workspace admins notice of any intended change to this list, and a reasonable chance to object. If you object on data-protection grounds and we cannot find a compromise, you may terminate the affected subscription.
5. International transfers
Where a sub-processor processes data outside the EEA or the UK, we put appropriate safeguards in place — the European Commission’s Standard Contractual Clauses together with the UK Addendum, or an equivalent adequacy decision — and we can provide details for the relevant provider on request.
6. Security measures
In addition to the summary on the security page — tenant isolation at the database level, encryption in transit and at rest, private certificate storage with short-lived links, and role-based access — we maintain internal policies for access control, backups, incident response, and supplier review, and we review them as the service changes.
7. Audits and information
We will make the information you reasonably need to demonstrate compliance available — this agreement, our security page, and answers to a security questionnaire. If your regulator requires a more detailed review, we will agree a scope, timing, and confidentiality terms in advance, so that audits do not compromise other customers’ data.
8. Liability
Each party’s liability under this agreement is subject to the limitations in the Terms of Service, except that nothing limits liability that cannot lawfully be limited.
9. Term and deletion
This agreement runs alongside the Terms of Service. When your processing ends, we delete or return the personal data at your choice — the service lets you export everything before then. Data deleted from a terminated workspace is removed from production systems after the 30-day window; it may persist briefly in encrypted backups before rotating out, and we keep billing records where tax law requires it.
10. Countersigning
Acceptance of the Terms of Service covers this agreement. If your organisation needs a countersigned copy, send the details to safetytracker@xack.dev and we will return a signed version:
- For the customer
- [Name, title, signature, date]
- For the processor
- [Name, title, signature, date]
