Legal
Data Processing Agreement
Effective Date: June 26, 2026 · Last Updated: June 27, 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between ShineCRM and the Customer (the "Agreement"). It governs ShineCRM's processing of personal information relating to your End Clients and other individuals on your behalf when you use the Service.
ShineCRM is operated by Sean van Gessel as a sole proprietorship based in Victoria, British Columbia, Canada. In this DPA, "ShineCRM," "we," "us," and "our" refer to that business and any successor entity; "you," "your," and "Customer" refer to the business or individual that has entered into the Agreement.
Capitalized terms not defined in this DPA have the meaning given in the Agreement or the Privacy Policy. If there is a conflict between this DPA and the Agreement with respect to the processing of End Client personal information, this DPA controls. In all other respects the Agreement remains in full force.
2. Plain-Language Summary
We have written this DPA to be legally complete. Here is the short version:
- You decide what End Client data goes into ShineCRM and why. You are the "controller." We handle that data for you, on your instructions, as your "processor" (in California terms, your "service provider").
- We only use your End Client data to provide, operate, secure, debug, and support the Service. We do not sell it, share it for advertising, or use it for our own unrelated purposes.
- To run and support our AI features, the text we send to our AI providers and the text they return is recorded in an internal AI activity log that authorized ShineCRM staff can view across organizations. That raw content is automatically deleted 30 days after each AI call, and every staff view is recorded in an audit log you can review. See Section 7.
- We use vetted sub-processors (listed in Annex 2) and require them to protect your data. We will tell you before adding a new one.
- We protect your data with the security measures in Annex 3, and we will tell you without undue delay, and as required by law, if there is a confidentiality incident or personal data breach.
- We help you respond to data subject requests with reasonable assistance, and we delete or return your data after you leave.
- ShineCRM currently serves customers and data in Canada and the United States only. We do not onboard EEA or UK personal data today. If we expand, we will put appropriate transfer mechanisms in place at that time. See Section 12.
This summary does not replace the detailed terms below.
3. Definitions
- "Data Protection Laws" means all laws and regulations applicable to the processing of personal information under this DPA, including, as applicable: Canada's Personal Information Protection and Electronic Documents Act (PIPEDA); Quebec's Act respecting the protection of personal information in the private sector (Law 25); British Columbia's Personal Information Protection Act (BC PIPA); the EU General Data Protection Regulation 2016/679 (GDPR) and the UK GDPR; and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
- "End Client Data" means personal information relating to your End Clients and other individuals (such as your employees and contractors) that you, your Authorized Users, or your End Clients submit to or generate through the Service, and that ShineCRM processes on your behalf.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given under the GDPR. Equivalent terms under other Data Protection Laws (for example "service provider" and "business" under the CCPA/CPRA) apply where those laws govern.
- "Sub-Processor" means any third party engaged by ShineCRM to process End Client Data on ShineCRM's behalf.
- "Standard Contractual Clauses" or "SCCs" means the standard data protection clauses adopted by the European Commission, and, for the United Kingdom, the UK International Data Transfer Agreement or Addendum issued by the Information Commissioner's Office.
4. Roles of the Parties
As between the parties, with respect to End Client Data:
- You are the Controller (and, under the CCPA/CPRA, the Business). You determine the purposes and means of processing End Client Data and are responsible for the lawfulness of that processing, including establishing a valid legal basis and providing all notices and obtaining all consents required from your End Clients.
- ShineCRM is the Processor (and, under the CCPA/CPRA, your Service Provider). ShineCRM processes End Client Data only on your behalf and in accordance with this DPA and your documented instructions.
ShineCRM acts as an independent Controller for the limited categories of data described in the Privacy Policy that ShineCRM collects for its own purposes, such as Customer account data, billing data, and Service usage and security telemetry. This DPA does not govern that processing, which is described in the Privacy Policy.
5. Scope, Subject Matter, and Details of Processing
ShineCRM processes End Client Data for the duration of the Agreement, plus any period required to return or delete the data and to comply with law. The subject matter, nature and purpose of the processing, the categories of Data Subjects, and the types of End Client Data are set out in Annex 1.
6. ShineCRM's Processing Obligations
ShineCRM will:
- Process on documented instructions. Process End Client Data only on your documented instructions, including with respect to international transfers, unless required to do otherwise by a law to which ShineCRM is subject. Your instructions are set out in the Agreement, this DPA, the Privacy Policy, and your configuration and use of the Service. If ShineCRM is required by law to process beyond your instructions, it will inform you of that legal requirement before processing unless the law prohibits it.
- Limit purpose. Not retain, use, or disclose End Client Data for any purpose other than providing, operating, securing, debugging, and supporting the Service as described in the Privacy Policy, and not sell or share End Client Data (as those terms are defined under the CCPA/CPRA), and not combine it with personal information from other sources except as permitted by Data Protection Laws to perform the Service.
- Confidentiality. Ensure that personnel authorized to process End Client Data are bound by an appropriate duty of confidentiality and access it only on a need-to-know, least-privilege basis.
- Flag unlawful instructions. Inform you if, in ShineCRM's opinion, an instruction infringes Data Protection Laws.
- Security, sub-processing, assistance, breach, transfers, deletion, and audits as set out in Sections 7 through 14.
7. ShineCRM Staff Access and the AI Activity Log
You instruct and authorize ShineCRM to access End Client Data as reasonably necessary to provide, operate, secure, debug, and support the Service, including its AI features. ShineCRM minimizes this access by default and applies the controls described in this Section and in Sections 7.6 and 15.1 of the Privacy Policy.
AI activity log. The AI features route End Client Data to AI providers (currently Anthropic and OpenAI; we may add others, such as Google, and will update this list). To operate, monitor, debug, and support those features, ShineCRM records, for every AI feature, the full text it sends to the AI provider and the full text the provider returns, in an internal AI activity log. The text sent can include the content of communications, notes, transcripts, and other End Client Data passed to the AI, and the text returned can include AI-drafted reply bodies. Authorized ShineCRM personnel holding the super-administrator role can view these raw records across organizations through ShineCRM's administrative surface, for the limited purposes stated above.
ShineCRM applies the following safeguards to this access:
- Least-privilege gating. Access is restricted to an explicit super-administrator role held by a small number of people (initially the founder only) and enforced by Row-Level Security in the database.
- Audit logging you can review. Every access to a specific organization's records through the administrative surface, including each time a raw AI activity log entry is opened, is recorded in an append-only audit log capturing the accessor, the action, the records touched, the affected organization, and the time. You can review the entries that touched your organization through your account dashboard and may request a copy or export by emailing sean@shinecx.com.
- Short retention of raw content. The raw request and response text in the AI activity log is automatically and permanently deleted 30 days after each AI call by a scheduled process, after which only metadata (organization, AI surface, model, token counts, cost, and success or error status) remains.
- Deletion on termination. All AI activity log records for your organization, including any remaining metadata, are deleted when your organization is deleted, as described in Section 13.
This access and logging is part of the Service that you instruct ShineCRM to provide. ShineCRM does not use the AI activity log to train AI models. Any separate use of End Client Data to train or improve AI models is governed by the Agreement and the Privacy Policy, is limited to de-identified, anonymized, or aggregated data and/or Customer Data of Customers who have opted in and not opted out, and is subject to the opt-out described there. For personal information of End Clients who are residents of California, the European Economic Area, or the United Kingdom, ShineCRM acts solely as your service provider and processor and does not use that personal information to train or improve AI models or for any other purpose of its own, except in de-identified, anonymized, or aggregated form, as set out in Section 15.3 and in Section 6.3 of the Terms of Service.
8. Sub-Processors
You provide ShineCRM with a general authorization to engage Sub-Processors to process End Client Data, subject to this Section. ShineCRM's current Sub-Processors are listed in Annex 2.
ShineCRM will: (a) impose data protection obligations on each Sub-Processor that are substantially similar to and no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures; and (b) remain responsible to you for each Sub-Processor's performance of its obligations.
ShineCRM will give you advance notice of the addition or replacement of a Sub-Processor by updating Annex 2 and, where you have subscribed to such notice, by email, at least 14 days before the new Sub-Processor begins processing End Client Data, except where a shorter period is required to protect the security or continuity of the Service. You may object to a new Sub-Processor on reasonable, data-protection grounds by notifying sean@shinecx.com within that notice period. If the parties cannot resolve the objection, you may terminate the affected part of the Service in accordance with the Agreement.
9. Security Measures
ShineCRM implements and maintains appropriate technical and organizational measures designed to protect End Client Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects. A description of ShineCRM's current measures is set out in Annex 3. ShineCRM may update its measures from time to time provided the level of protection is not materially reduced.
10. Confidentiality Incident and Personal Data Breach Notification
Consistent with the early-access nature of the Service, ShineCRM keeps this commitment light and tied to what the law requires. ShineCRM will notify you of a confidentiality incident or Personal Data Breach affecting End Client Data without undue delay after becoming aware of it, and as required by applicable law. The notification will, to the extent known and as it becomes available, describe the nature of the incident, the data and individuals affected so far as known, the likely consequences, and the measures taken or proposed to address it, and will identify a contact point for more information.
ShineCRM will provide reasonable assistance and cooperation, as required by applicable law, to help you meet your own notification and record-keeping obligations (for example, notification of affected individuals and of regulators such as the Office of the Privacy Commissioner of Canada, the Commission d'acces a l'information du Quebec under Quebec Law 25, and, if the Service expands to those regions in the future, EEA/UK supervisory authorities). Where applicable law requires ShineCRM to keep a register of confidentiality incidents, it will do so and make the entries relevant to your organization available to you on request. As the Controller, you are responsible for determining whether an incident triggers a notification obligation and for making any required notifications, unless ShineCRM is independently required to do so by law.
11. Assistance: Data Subject Requests, Impact Assessments, and Consultation
Data subject requests. Taking into account the nature of the processing, ShineCRM will provide reasonable assistance, as required by applicable law and insofar as possible, to help you respond to requests from Data Subjects to exercise their rights (such as access, correction, deletion, portability, restriction, and objection). The Service provides self-serve tools that let you access, export, correct, and delete End Client Data directly. If ShineCRM receives a request directly from one of your End Clients, it will not respond substantively (except to acknowledge the request and direct the individual to you) and will, where permitted, promptly inform you so that you can respond.
Impact assessments and prior consultation. ShineCRM will provide reasonable assistance, as required by applicable law and taking into account the information available to it, with data protection impact assessments and prior consultations with supervisory authorities.
Withdrawal and objection for the AI activity log. Because the AI activity log records the text exchanged with AI providers as part of operating the AI features on your instruction, the operative mechanism to stop further AI processing of a given individual is for you, as Controller, to cease using AI processing for that individual (for example, by disabling the relevant AI feature or excluding that End Client) or to delete your organization. ShineCRM will honor a documented Controller instruction to stop AI processing for a given End Client. Raw content already recorded is in any event deleted 30 days after each AI call as described in Section 7, and all AI activity log records are deleted when your organization is deleted.
12. International Data Transfers
ShineCRM is operated from Canada, and most of its infrastructure and Sub-Processors are located in the United States. By using the Service, you instruct ShineCRM to transfer and process End Client Data in Canada, the United States, and other countries where ShineCRM or its Sub-Processors operate.
Current scope: Canada and the United States only. ShineCRM currently serves customers and data in Canada and the United States only. It does not onboard Customers, or End Client Data, originating in the European Economic Area or the United Kingdom. As an early-access product run by a solo developer, ShineCRM has not put in place the formal EU/UK cross-border transfer machinery (such as executed Standard Contractual Clauses, the UK International Data Transfer Addendum, or a transfer risk assessment) and does not represent that it has. If ShineCRM expands to serve EEA or UK personal data in the future, it will put appropriate transfer mechanisms in place at that time and will update this DPA accordingly.
If you nonetheless submit EEA or UK personal information while the Service is scoped to Canada and the United States, you do so on your own instruction and responsibility as Controller, outside the intended scope of the Service.
Canada. For transfers of personal information out of Canada and Quebec, ShineCRM uses contractual and organizational measures intended to provide a comparable level of protection as required by PIPEDA, BC PIPA, and Quebec Law 25. You acknowledge that processing outside the originating jurisdiction may make the data accessible to courts and authorities in those countries as required by their laws.
13. Return and Deletion of Data on Termination
On expiry or termination of the Agreement, or earlier on your written request, ShineCRM will delete or return End Client Data and delete existing copies, unless retention is required by law. ShineCRM will complete deletion or return within 30 days of the relevant event, subject to the following: (a) the Service provides self-serve export and permanent deletion, and deleting your organization cascades deletion through your organization's data, including its AI activity log records; (b) raw content in the AI activity log is in any event deleted 30 days after each AI call as described in Section 7; (c) residual copies may persist in encrypted backups for a limited period until they are overwritten in the ordinary course; and (d) ShineCRM may retain de-identified, anonymized, or aggregated data, and any AI models that previously incorporated data while permitted, as described in the Privacy Policy and the Agreement.
14. Audits and Demonstrating Compliance
ShineCRM will make available to you information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. The parties will agree on the reasonable scope, timing, and conduct of any audit in advance. To minimize disruption, ShineCRM may satisfy audit requests by providing relevant documentation, security summaries, and written responses to a reasonable security questionnaire, and on-site or live inspections will be limited to no more than once per year (absent a Personal Data Breach or a regulator requirement), conducted on reasonable prior notice, during business hours, and subject to confidentiality.
15. Region-Specific Terms
15.1 Canada (PIPEDA, Quebec Law 25, BC PIPA)
ShineCRM processes End Client Data as a service provider acting on your behalf and uses contractual and organizational measures intended to ensure a comparable level of protection where data is transferred or processed outside the originating province or Canada. ShineCRM will provide reasonable assistance, as required by applicable law, with breach reporting (including the "real risk of significant harm" assessment under PIPEDA) and with responding to access and correction requests. With respect to Quebec Law 25, ShineCRM will notify you of any confidentiality incident (within the meaning of art. 3.5) without undue delay and as required by law, will keep the register of confidentiality incidents where required by art. 3.8 and make the entries relevant to your organization available to you on request, and, where an incident presents a risk of serious injury, will provide reasonable assistance in notifying the Commission and affected individuals, as set out in Section 10. ShineCRM's Privacy Officer is Sean van Gessel, reachable at sean@shinecx.com.
15.2 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
These terms are included so that they are ready if and when ShineCRM expands to serve EEA, UK, or Swiss personal data. As described in Section 12, ShineCRM currently scopes the offering to Canada and the United States and does not onboard EEA or UK Customers or End Client Data. It has not executed Standard Contractual Clauses, the UK International Data Transfer Addendum, or a transfer risk assessment, and does not maintain an EU or UK representative. The processor obligations in this DPA (including Sections 6, 7, 9 through 14) are intended to be consistent with the standards in Article 28 of the GDPR and UK GDPR. If ShineCRM expands to those regions, it will put in place the appropriate transfer mechanisms (such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum) before processing such data and will update this DPA accordingly.
15.3 California (CCPA / CPRA)
ShineCRM is a Service Provider and processes End Client Data ("personal information") solely to perform the Service for you (the Business) under the Agreement. ShineCRM does not sell or share personal information, does not retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement (or as otherwise permitted by the CCPA/CPRA), and does not combine it with personal information from other sources except as permitted to perform the Service. ShineCRM will comply with applicable CCPA/CPRA obligations and provide the same level of privacy protection as required of a Service Provider. You may take reasonable steps to ensure ShineCRM uses personal information consistent with your obligations.
ShineCRM certifies that it understands the restrictions set out in this Section 15.3 and in the CCPA/CPRA applicable to a Service Provider, and that it will comply with them.
ShineCRM will not retain, use, or disclose the personal information outside the direct business relationship between ShineCRM and the Business, except as permitted by the CCPA/CPRA.
16. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory, is subject to the exclusions and limitations of liability set out in the Agreement, including the aggregate liability caps in Section 12 of the Terms of Service. The parties confirm that a breach by ShineCRM of its confidentiality or data-protection obligations under this DPA (including a Personal Data Breach, a confidentiality incident within the meaning of Quebec Law 25, or a breach of this DPA) is governed by the data and confidentiality cap in Section 12.2 of the Terms of Service, and not the lower general cap. This DPA and the Agreement do not exclude or limit any liability that cannot be limited under applicable law, including liability for gross negligence, willful misconduct, or fraud, and, where applicable, liability to Data Subjects under Data Protection Laws.
17. Term, Order of Precedence, and Changes
This DPA takes effect when you accept the Agreement and continues for as long as ShineCRM processes End Client Data on your behalf. In the event of a conflict, the order of precedence is: (1) the Standard Contractual Clauses (where they apply), (2) this DPA, and (3) the rest of the Agreement, in each case with respect to the processing of End Client personal information. We may update this DPA in accordance with the changes process in the Agreement and the Privacy Policy; for material changes that reduce your protections, we will provide advance notice and, where required, seek your agreement.
18. Contact
Questions about this DPA, or requests for a countersigned copy, can be sent to:
Email: sean@shinecx.com
Privacy Officer: Sean van Gessel
Mailing Address: 1279 Derby Rd, Victoria, BC, Canada
Annex 1: Details of Processing
Subject matter. ShineCRM's provision of the Service to the Customer, including its CRM, communications, scheduling, payments, and AI features.
Duration. For the term of the Agreement, plus the return and deletion period described in Section 13.
Nature and purpose. Hosting, storage, transmission, organization, analysis, and other processing of End Client Data to provide, operate, secure, debug, and support the Service, including AI-assisted drafting, summarization, transcription, scoring, scheduling assistance, and the operating and support access and AI activity log described in Section 7.
Categories of Data Subjects. Your End Clients (such as homeowners, property managers, and commercial clients), your Authorized Users, and your employees and contractors whose information you enter into or generate through the Service.
Types of End Client Data. Identifiers and contact details (name, address, email, phone); service, job, estimate, invoice, and payment history; property photos and job-site images; SMS, email, and call content and metadata; call recordings where enabled; notes, tags, and custom fields; location and routing data tied to jobs; and any other personal information you choose to submit. The Service is not intended for special categories of data, and you should not submit such data except as necessary and lawful.
Annex 2: List of Sub-Processors
The following Sub-Processors process End Client Data to help ShineCRM provide the Service. This list mirrors the sub-processor list in the Privacy Policy and may be updated as described in Section 8.
| Sub-Processor | Purpose | Data Region |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Stripe | Online payment processing, subscription billing, card-on-file | United States |
| Square | In-person payments (Tap to Pay, Square Reader), card-on-file | United States |
| Twilio | SMS messaging, voice calling, voicemail and call recording storage | United States |
| Resend | Transactional and marketing email delivery, inbound email parsing | United States |
| Anthropic | AI inference (Claude models) | United States |
| OpenAI | AI inference (GPT models) | United States |
| AI inference (Gemini), Google Calendar API integration, infrastructure | United States and global | |
| Attio | Internal CRM sync (Customer organization name and owner identity for sales operations) | United States |
| Cloudflare | Content delivery, DDoS protection, marketing site and operator dashboard hosting | Global |
| Expo (EAS) | Mobile app build infrastructure and over-the-air update delivery | United States |
| Apple (APNs) | Push notification delivery to iOS devices, including VoIP push for incoming calls | United States |
| Google (Firebase Cloud Messaging) | Push notification delivery to Android devices | United States and global |
| Sentry or equivalent | Error tracking and performance monitoring | United States |
| PostHog, Mixpanel, or equivalent | Product analytics and session replay | United States |
| LogRocket or equivalent | Session recording and debugging | United States |
| GitHub (a Microsoft company) | Source code hosting and issue tracking for support and bug resolution, including bug reports submitted through the Service | United States |
| Cursor (Anysphere, Inc.) | AI-assisted code review and bug fixing based on issues created from bug reports | United States |
Annex 3: Technical and Organizational Security Measures
ShineCRM maintains measures including:
- Encryption. Encryption of data in transit using HTTPS/TLS and encryption of data at rest.
- Tenant isolation. Row-Level Security policies that scope every read and write to the calling user's organization.
- Access control and least privilege. Production access limited to authorized personnel; cross-tenant access gated behind an explicit super-administrator role recorded in a dedicated table; salted password hashing for credentials.
- Audit logging. An append-only audit log of administrative access to tenant-identifiable records, including views of raw AI activity log entries, reviewable by the affected tenant's administrators and retained for a minimum of 24 months.
- Data minimization and retention limits. Automatic 30-day deletion of raw AI request and response content, and deletion of an organization's data on organization deletion.
- Monitoring. Security monitoring and error tracking.
- Sub-processor diligence. Contractual data protection obligations imposed on Sub-Processors.
These measures are described at a level intended to be informative without compromising security, and may evolve as described in Section 9.