Skip to main content

Data Processing Agreement

Last updated: August 2, 2026

This agreement applies whenever you use HeaderShield to process personal data for which you are the controller. It takes effect when you create an account and needs no signature. If your organisation requires a countersigned copy, write to hello@headershield.dev.

1. Roles

You are the controller: you decide what personal data enters the service and why. We are the processor: we act only on your instructions, and using the product is how you give them.

2. Scope

Subject matter: providing the service you subscribed to. Duration: as long as your account exists. Nature and purpose: the operations the product performs on your input. Categories of data subjects and of personal data: whatever you choose to send — we do not control that, which is why the next section matters.

3. Your obligations

You warrant that you have a lawful basis for the data you send, and that sending it to us is compatible with the notice you gave your own data subjects. Send only what the service needs. Where the product offers test or redacted modes, prefer them.

4. Our obligations

5. Sub-processors

You give general authorisation for the sub-processors below. We will tell you before adding or replacing one, and you may object on reasonable data-protection grounds. This table is generated from the same source as the privacy policy, so the two cannot disagree.

Sub-processorPurposeLocation
VercelApplication hosting and page deliveryEU (deploy region) and United States
UpstashDatabase holding accounts, keys and product dataEU
StripePayments and subscription managementEU and United States
BrevoTransactional email (welcome, API key, alerts)EU (France)
SentryApplication error reportingEU (.de ingestion host)
Vercel BotIDBot protection on public formsEU and United States
Google Analytics 4Aggregate visit statisticsUnited States
Vercel Analytics and Speed InsightsPage performance metricsEU and United States

6. Security

Encryption in transit (TLS) and at rest. API keys are stored only as a hash, never in clear text. Access to production data is limited to what operating the service requires. Errors are reported to our monitoring without personal data attached.

7. Breach notification

If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any case within 48 hours, with what we know and what we are doing about it. That leaves you time inside your own 72-hour deadline under Art. 33.

8. Deletion

On request, or when your account closes, we delete your personal data. Write to hello@headershield.dev and we act within 30 days. Backups age out on their own schedule and are never written back.

9. International transfers

Some sub-processors operate outside the EEA — the table in section 5 says which. Those transfers rely on the European Commission’s Standard Contractual Clauses, which each of those vendors has in place.

10. Audit

We answer reasonable written questions about this agreement and provide the documentation we hold. For an on-site audit, write to us and we will agree scope and timing.

11. Contact

hello@headershield.dev