This Personal Data Protection Agreement (the “DPA”) is intended to ensure compliance with the legal obligations applicable to the processing of personal data in connection with the Client's subscription to Shadow's managed inference API, Open Models (hereinafter the “Services”).
This DPA reflects the Parties' agreement regarding the processing of personal data by Shadow. This DPA forms an integral part of the Agreement. It takes effect on the effective date of the Agreement and remains in force for as long as Shadow processes data on behalf of the Client. In the event of a conflict between this DPA and the Agreement with respect to the processing of personal data, this DPA prevails.
The “Agreement” means the Open Models General Terms of Use accepted by the Client, to which this DPA is attached.
1. Definitions
Under this DPA, Shadow and the Client agree that the terms, whether used in the singular or the plural, "Controller", "Data", "Personal Data Breach", "Processing", "Processor", "Subprocessor", and "Supervisory Authority" have the meaning given to them by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "General Data Protection Regulation" or "GDPR").
"Data Protection Legislation" means the GDPR together with French Act No. 78-17 of 6 January 1978, as amended, on information technology, data files and civil liberties.
2. Processing of Personal Data carried out by Shadow as Processor.
Shadow is authorized, as a Processor acting on the Client's instructions, to process the Controller's Personal Data to the extent necessary to provide the Services.
The nature of the operations carried out by Shadow with respect to the Personal Data may be:
The provision of a managed inference API allowing the execution of artificial intelligence models (Blade);
Responding to technical support requests;
Billing management.
The type of Personal Data and the categories of data subjects are determined and controlled by the Client, at its sole discretion, and are detailed in Annex 1. The processing activities are carried out by Shadow for the term set out in the Agreement.
3. Deployed content and Client requests
As part of the Services, the Client may transmit to Shadow's infrastructure requests, inference data and, where applicable, models that may contain personal data for which the Client is responsible, including data relating to its own end users (the “Client Content”).
Shadow does not access or exploit the Client Content, except to the extent strictly and technically necessary to perform the Services. Shadow does not process the Client Content for any other purpose and, in particular, does not use the Client Content, the Client's requests, or the Client's models to train or improve its own models or those of third parties.
Only technical statistics are processed by Shadow for the purposes of providing, billing, monitoring, and maintaining the Services. These statistics are, to the greatest extent possible, pseudonymized or aggregated, in accordance with the principles of data minimization and privacy by design and by default, which prevail in the event of doubt as to the scope of the processing.
4. Shadow's Obligations
Shadow undertakes to:
Process the Personal Data provided by the Client solely within, and as necessary for, the provision of the Services as defined in the Agreement,
Refrain from accessing or using the Personal Data for any purpose other than those essential to the performance of the Services, in particular for incident management.
Implement and maintain appropriate technical and organizational measures to ensure the security, confidentiality, integrity, and availability of the Personal Data processed in connection with the Services.
Ensure that any person authorized by Shadow to process the Personal Data under the Agreement is subject to a contractual confidentiality obligation.
Inform the Client without delay if an instruction it has issued constitutes, in Shadow's view, a breach of the GDPR or of any other applicable European Union or Member State data protection provision.
In the event of a request from a competent authority concerning the Personal Data processed under the Agreement, inform the Client beforehand, unless a legal provision or an order from that authority prohibits it, and limit any disclosure of Data to what is strictly required by the formal request.
5. Obligations of the Controller
In its capacity as Controller, the Client is solely responsible for:
(i) the accuracy, quality, and lawfulness of the personal data transmitted to Shadow and of the means by which it obtained such personal data;
(ii) informing data subjects about the processing of personal data carried out by Shadow in accordance with the requirements set out in the Data Protection Legislation;
(iii) where applicable, obtaining any authorization required by the applicable regulations for the purposes of processing the personal data.
6. Compliance with documented instructions
Shadow processes the personal data in accordance with the Client's documented instructions, including with regard to transfers of personal data to a third country, unless it is required to do so under a regulation applicable to it. In that case, Shadow informs the Client of that legal obligation before processing, unless the relevant regulation prohibits such information on important grounds of public interest.
7. Security and confidentiality measures
Shadow implements the technical and organizational security measures described in Annex 2 to this DPA in order to ensure the protection of the personal data.
Shadow ensures the confidentiality of the personal data. To this end, Shadow ensures that persons authorized to process the personal data have undertaken to respect its confidentiality or are subject to an appropriate statutory confidentiality obligation.
Shadow undertakes not to disclose the personal data to unauthorized third parties.
Shadow limits access to the personal data to only those employees for whom access to such data is necessary to comply with Shadow's obligations under this DPA.
The Client Content is processed and stored on Shadow's infrastructure and that of its hosting provider, both located within the European Union. Shadow and its hosting provider do not transfer the Client Content to servers located outside the European Union.
8. Duty to assist
Upon request, Shadow undertakes to make available to the Client any relevant information to help the Client comply with the obligations set out in Articles 32 to 36 of the GDPR (security of processing – notification to the supervisory authority and communication to the data subject in the event of a personal data breach – data protection impact assessment – prior consultation of the supervisory authority).
As far as possible, Shadow cooperates with the Client to help it:
(i) respond to requests from data subjects exercising their rights under the Data Protection Legislation;
(ii) inform data subjects of the processing of their personal data;
(iii) obtain valid consent from data subjects where required.
9. Audit
Upon request, Shadow undertakes to make available to the Client all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR.
The Client is entitled to carry out such audits and inspections as it deems relevant regarding Shadow's compliance with its obligations under this annex. The Client must notify Shadow in writing of its intention to carry out an audit or inspection (stating the date and subject matter) at least fourteen (14) business days before it takes place. Audits are limited to a frequency of once (1) per year. In this context, Shadow cooperates with the Client in conducting the audit and provides it with assistance where the Client so requires.
10. Personal Data Breach
In the event of a personal data breach, Shadow must inform the Client as soon as possible and, in any event, within forty-eight (48) hours of becoming aware of it.
This notice must contain all of the following information regarding the personal data breach:
(i) the nature of the personal data breach, indicating the categories and (approximate) number of data subjects and personal data records affected;
(ii) the likely consequences of the personal data breach;
(iii) a proposal of measures to be taken to address the personal data breach, including (where appropriate) measures to mitigate its possible adverse effects.
Under no circumstances does Shadow notify the breach to a supervisory authority or to natural persons without first informing the Client and obtaining the Client's approval of the content of the notification.
11. Subprocessors
The up-to-date list of our subprocessors is available in the “List of Subprocessors” document.
The Client authorizes Shadow to engage Subprocessors in connection with the provision of the Services.
It is Shadow's responsibility to ensure that the Subprocessor provides sufficient guarantees regarding the implementation of appropriate technical and organizational measures so that the processing meets the requirements of the Data Protection Legislation. Before engaging a Subprocessor, Shadow enters into a written contract with the Subprocessor containing obligations similar to those set out in this annex.
12. Transfer of Personal Data to third countries
In the event of a transfer of personal data to a third country, Shadow implements the appropriate safeguards required by the Data Protection Legislation, in particular by ensuring that such transfer is covered by an adequacy decision of the European Commission or by standard contractual clauses, or is subject to binding corporate rules, as well as, where applicable, by assessing the impact and the ability of the third country's legislation to guarantee the effectiveness of data subjects' rights.
Shadow also ensures that its Subprocessors are bound by similar obligations regarding the transfer of personal data to third countries.
13. End of the processing of personal data
At the end of the business relationship, at the Client's choice, Shadow deletes or returns all of the personal data in full within thirty (30) days. In all cases, Shadow undertakes to keep no copy of it and to no longer use it for any reason whatsoever, except for the period during which its archiving or retention is required by applicable laws or regulations.
Annex 1 – Description of the processing of personal data
Processing activities | Data | Purpose | Legal basis for the processing | Subprocessor |
|---|---|---|---|---|
Provision of a managed inference API (Open Models): execution of AI models | Identification data Professional data Usage data (pseudonymized) Content of requests: processed solely for the performance of the Service | Provision of the Service | Performance of the Agreement | OVH |
Responding to support requests | Identification data Professional data Usage data (pseudonymized) | Provision of the Service | Performance of the Agreement | Google (Gmail) |
Billing | Identification data Professional data Banking data | Payment of the Service | Performance of the Agreement | Stripe |
Usage measurement and billing | Identification data; Professional data; Banking data | Usage tracking, wallet management, and payment of the Service | Performance of the Agreement | Metronome |
Annex 2 – Security measures
Shadow undertakes to implement the following technical and organizational measures:
Physical security measures are set out in the DPA of our subprocessor OVH.
Technical security measures intended to prevent malicious intrusion:
authentication and streamlining of access via VPN
Workstation management (Primo) and protection against malware (Bitdefender)
data minimization
Regular security updates (servers) via CVE patching.
Securing of IT channels: each client is isolated from other clients,
Deletion of data on request,
Access logging.
Organizational security measures:
Personnel management,
Management of third parties accessing the data,
Integration of privacy protection into projects,