1. Scope & Relationship to the Terms
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ShipReady (“Processor”) and the customer accepting those Terms (“Controller” or “you”). It applies where, and to the extent that, ShipReady processes Personal Data on your behalf in the course of providing the Service.
It takes effect automatically when you accept the Terms; no signature is required. Where this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. Terms not defined here have the meaning given in the Terms or in applicable Data Protection Law.
“Data Protection Law” means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (2016/679) (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), and India’s Digital Personal Data Protection Act, 2023, in each case as applicable to you.
2. Roles of the Parties
For Personal Data contained in or observed through the targets, repositories, and projects you submit for scanning (“Customer Personal Data”), you are the Controller and ShipReady is the Processor. You determine the purposes and means of that processing by choosing what to scan and which integrations to connect.
For data we process to run our own business — your account and billing records, service telemetry, security logs, and aggregated usage analytics — ShipReady acts as an independent Controller. That processing is governed by our Privacy Policy, not by this DPA.
Under the CCPA, ShipReady acts as a “service provider.” We do not sell or share Customer Personal Data, and we do not retain, use, or disclose it for any purpose other than performing the Service.
3. Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Automated production readiness and security analysis of the systems and repositories the Controller submits. |
| Duration | For the term of the Terms, plus the retention periods stated in the Privacy Policy. |
| Nature & purpose | Retrieving, storing, analyzing, scoring, and reporting on target responses and repository content; generating remediation guidance. |
| Categories of data subjects | The Controller’s personnel and account users, and any individuals whose personal data happens to appear in a scanned response, repository, log, or configuration. |
| Categories of personal data | Account identifiers and email addresses; integration tokens; IP addresses and request metadata; and any personal data incidentally present in scanned content. |
| Special categories | None requested or required. The Controller must not deliberately submit special-category data to the Service. |
4. Processor Obligations
ShipReady will:
- process Customer Personal Data only on your documented instructions, which include the Terms, this DPA, your configuration of the Service, and each scan you initiate — unless required otherwise by law, in which case we will inform you first unless the law prohibits it;
- ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations;
- implement the technical and organizational measures described in Section 6;
- engage subprocessors only on the terms in Section 7;
- assist you, taking into account the nature of the processing and the information available to us, with data-subject requests, security obligations, breach notification, data protection impact assessments, and prior consultation;
- on termination, delete or return Customer Personal Data as described in Section 9;
- make available the information reasonably necessary to demonstrate compliance with this DPA, as described in Section 10;
- inform you if, in our opinion, an instruction infringes Data Protection Law.
5. Controller Obligations
You warrant and undertake that:
- you have a valid legal basis for the processing you instruct, and have given all notices and obtained all consents required from data subjects;
- you own each target you submit or hold documented authorization from its owner, as required by the Terms and our Acceptable Use Policy;
- your instructions comply with Data Protection Law and do not require us to breach it;
- you will not deliberately submit special-category data, payment card data, or production credentials beyond the minimum an integration requires;
- you are responsible for the accuracy, quality, and legality of the Customer Personal Data you submit and for the security of your own account credentials.
6. Security Measures
Taking into account the state of the art, implementation cost, and the nature, scope, and risk of the processing, ShipReady maintains technical and organizational measures including:
- encryption of all data in transit over TLS, and encryption of credentials and integration tokens at rest with AES-256;
- automatic redaction of detected secrets, API keys, and sensitive header values before evidence is written to a stored report;
- row-level access isolation in the database so account data is not readable across tenants;
- least-privilege service credentials and scoped, individually revocable integration tokens;
- authentication with password and multi-factor options, and short-lived session tokens;
- rate limiting and abuse controls on scan submission and API access;
- error and anomaly monitoring, with alerting on the API and scanner;
- managed infrastructure with provider-level backups, redundancy, and restoration procedures;
- internal review of changes affecting security-relevant code paths.
We may update these measures over time, provided the overall level of protection is not reduced.
7. Subprocessors
You give general authorization for ShipReady to engage subprocessors to provide the Service. The current list is published at /subprocessors and is incorporated into this DPA.
Each subprocessor is engaged under a written contract imposing data-protection obligations no less protective than those in this DPA, and receives only the minimum data necessary for its function. ShipReady remains fully liable to you for the performance of its subprocessors’ obligations.
We will give reasonable advance notice of any new or replacement subprocessor by updating that page. To receive notifications by email, write to us with the subject “Subprocessor Updates.” You may object in writing on reasonable data-protection grounds within thirty (30) days of notice. If we cannot address the objection through reasonable measures, you may terminate the affected part of the Service without penalty.
8. International Transfers
ShipReady and its subprocessors operate globally, so Customer Personal Data may be transferred to and processed in countries outside your own, including the United States.
Where Customer Personal Data is transferred out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this DPA by reference and completed as follows: the Controller is the data exporter and ShipReady is the data importer; the optional docking clause applies; Clause 9 uses Option 2 (general written authorization) with a thirty (30) day notice period; Clause 11 does not include the optional independent dispute-resolution body; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland; Annex I is populated by Section 3 of this DPA; and Annex II is populated by Section 6.
For UK transfers, the parties incorporate the UK International Data Transfer Addendum to the SCCs, with the UK Information Commissioner as competent authority and the law and courts of England and Wales. For Swiss transfers, references in the SCCs are read to include the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner.
9. Deletion & Return of Data
You may delete individual scan records at any time from the dashboard, and may delete your account and its associated data at any time. On termination of the Terms, we will delete Customer Personal Data in accordance with the retention schedule in our Privacy Policy, except to the extent retention is required by law or necessary for the establishment, exercise, or defense of legal claims. Backups are rotated on a rolling schedule, so deleted data may persist in backup media for a limited period before being overwritten.
10. Audits & Information Rights
On reasonable written request, and no more than once in any twelve (12) month period unless required by a supervisory authority or following a personal data breach, ShipReady will provide the information reasonably necessary to demonstrate compliance with this DPA. That will normally take the form of written responses to a security questionnaire and copies of relevant documentation or provider certifications.
Where Data Protection Law entitles you to an on-site audit that written information cannot satisfy, the parties will agree its scope, timing, and duration in advance. Audits must be conducted during business hours, without unreasonable disruption, subject to confidentiality, and at your expense.
11. Personal Data Breach
ShipReady will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We will provide reasonable cooperation to assist you with your own notification obligations. Notification is not an acknowledgement of fault or liability.
12. Data Subject Requests
The Service gives you direct access to Customer Personal Data through your dashboard, enabling you to respond to most data-subject requests yourself. Where you cannot, and taking into account the nature of the processing, we will provide reasonable assistance. If we receive a request directly from a data subject relating to Customer Personal Data, we will not respond substantively and will refer them to you, unless legally required to act otherwise.
13. Liability & Term
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, to the extent permitted by Data Protection Law. This DPA remains in effect for as long as ShipReady processes Customer Personal Data on your behalf, and its provisions survive termination for as long as any such data is retained.
14. Contact
For questions about this DPA, to request subprocessor notifications, or to raise a data-protection matter, contact us at:
hello@useshipready.dev