Data Processing Addendum

Last updated: May 13, 2026

This Data Processing Addendum (DPA) supplements and forms part of the Access Shift Terms of Service. It describes how Access Shift processes personal data on behalf of customers in its capacity as a data processor, and the obligations of each party under applicable data protection law, including the EU General Data Protection Regulation (GDPR) and UK GDPR.

Overview

When Access Shift scans your website or serves the remediation widget on your pages, it acts as a data processor under your instructions. You, as the customer, are the data controller. This DPA sets out the terms under which Access Shift processes personal data on your behalf.

Roles of the parties

For personal data Access Shift processes to provide the Service (scan results, usage data, account records where you are an enterprise customer), you are the data controller and Access Shift is the data processor. For personal data Access Shift processes for its own operational purposes (billing, support, product improvement), Access Shift is the data controller and the Access Shift Privacy Policy governs.

Security measures

Access Shift implements technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls with least-privilege principles, multi-factor authentication on production systems, regular vulnerability assessments, and documented incident response procedures. See the Security page for details.

How to execute a DPA

Enterprise customers may request a countersigned DPA by emailing privacy@accessshift.com. Growth and Scale customers are covered by the self-service DPA incorporated by reference into the Terms of Service.