Roles and instructions
The customer is the controller or business and FocalShift is the processor or service provider for Customer Personal Data submitted to the Services. FocalShift will process that data only on documented instructions in the agreement, product configuration, support requests, and this DPA, unless law requires otherwise.
Processing details
Processing supports hosting, storage, organization, retrieval, transmission, communication, automation, analytics, security, support, and deletion. Data subjects may include the customer’s users, employees, contractors, customers, leads, members, students, subscribers, vendors, and other contacts. Data may include identifiers, contact and profile data, communications, files, commercial records, usage information, and other data the customer chooses to submit.
Confidentiality and security
FocalShift will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations. We maintain reasonable administrative, technical, and organizational measures designed to protect confidentiality, integrity, availability, and resilience, including access controls, authentication, logging, backups, vulnerability management, and incident-response procedures appropriate to risk.
Customer responsibilities
The customer is responsible for lawful collection, instructions, notices, consents, account configuration, user permissions, and the accuracy and proportionality of Customer Personal Data. The customer will not instruct FocalShift to process data unlawfully and will use available security controls.
Subprocessors
The customer generally authorizes FocalShift to engage subprocessors that provide infrastructure, security, communications, payments, support, analytics, and AI functionality. FocalShift will impose data-protection obligations appropriate to the services each subprocessor performs and remains responsible for its processing obligations under this DPA.
| Subprocessor | Purpose | Processing location |
|---|---|---|
| DigitalOcean | Cloud hosting, compute, storage, networking, and infrastructure services | United States and configured service regions |
| Payment, communications, security, analytics, and AI providers enabled for the customer’s selected features | Limited to the connected or enabled service function | Provider and configured service regions |
FocalShift may update this list as the Services change. A customer with a legally supportable objection to a new subprocessor may contact FocalShift before the subprocessor begins materially processing that customer’s data. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate the affected feature.
Data-subject requests
Taking into account the nature of processing, FocalShift will provide reasonable assistance through available product functions and support so the customer can respond to requests to access, correct, delete, restrict, object to, or port personal data. If FocalShift receives a request relating to Customer Personal Data, it may direct the requester to the customer unless law requires a direct response.
Security incidents
FocalShift will notify the customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and will provide available information reasonably needed for the customer’s legal obligations. Notification is not an admission of fault or liability.
International transfers
Where a legally recognized transfer mechanism is required, the parties incorporate the applicable standard contractual clauses or equivalent mechanism. FocalShift will provide information reasonably necessary for transfer assessments and supplementary measures.
Deletion and return
During the service term, customers may use available tools to access or export data. After termination, FocalShift will delete or return Customer Personal Data within a reasonable period, subject to backup cycles, security requirements, and legal retention duties.
Audits and information
FocalShift will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be proportionate, protect other customers and security information, occur no more than annually unless required by a regulator or material incident, and be conducted under confidentiality obligations without unreasonable disruption.
Priority and contact
If this DPA conflicts with the Terms concerning processing of Customer Personal Data, this DPA controls. Data-protection questions may be submitted through FocalShift Contact.