数据处理协议
可下载、签署并存档的数据处理协议。
这些政策以英文发布。英文文本为准,译文仅供参考。
最后更新: 2026-08-01
本服务运营公司的注册信息尚未公布。信息确认后将显示在此处及页脚。
This is the template we sign. Download it, fill in your organisation's details, and return it to legal@shelftap.com. We counter-sign and return a copy.
1. Roles
For the personal data a customer submits or generates through the Service, the customer is the controller and [LEGAL ENTITY NAME — TO BE SUPPLIED] is the processor. For the account, billing and public-source directory data described in the 隐私政策, [LEGAL ENTITY NAME — TO BE SUPPLIED] is an independent controller and this agreement does not apply.
2. Subject matter and duration
Processing lasts for the term of the subscription plus the retention windows published on the 数据留存 page. The subject matter is the operation of a B2B company-discovery service.
3. Nature and purpose
Storage, retrieval, structuring, analysis and export of company records and search results; delivery of transactional email; and processing of payment metadata.
4. Categories of data subject and data
Data subjects: the customer's own users, and individuals named in publicly published company contact information. Data: name, business email, business telephone, business address, job title where published, and the source URL of each fact. No special-category data is processed.
5. Processor obligations
- Process personal data only on the controller's documented instructions, including for transfers.
- Ensure that personnel with access are bound by confidentiality.
- Apply the technical and organisational measures published on the 安全概览 page.
- Engage only the sub-processors listed on the 次级处理方 page, and give notice before adding another.
- Assist the controller with data-subject requests, security, breach notification and impact assessments.
- Delete or return personal data at the end of the term, at the controller's choice.
- Make available the information needed to demonstrate compliance and allow audits, subject to reasonable notice and confidentiality.
6. Breach notification
We notify the controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting their data. Details are on the 事件响应 page.
7. Transfers
Where a listed sub-processor is outside the EEA, the United Kingdom or Türkiye, transfers are made under that provider's standard contractual clauses or an equivalent mechanism.
8. Signature block
Processor: [LEGAL ENTITY NAME — TO BE SUPPLIED], [REGISTERED ADDRESS — TO BE SUPPLIED], registration number [REGISTRATION NUMBER — TO BE SUPPLIED]. Controller: to be completed by the customer.