Data Processing Agreement
Last updated: July 21, 2026
1. Scope and parties
This Data Processing Agreement (“DPA”) forms part of the Shifu Intel Terms of Servicebetween you, the practitioner using Shifu Intel (“Controller”), and Shifu Intel (“Processor”). It applies whenever Shifu Intel processes personal data on your behalf: your own client records, and personal data submitted by guests through your public booking page. Shifu Intel is currently an independently operated, solo project and is not yet incorporated as a registered company; for the purposes of this DPA, references to “Processor” and “we” mean the individual operating Shifu Intel. If there is a conflict between this DPA and the Terms of Service on data protection matters, this DPA controls.
2. Roles
You are the Controller of the client and guest personal data you collect and store using Shifu Intel: you determine why it's collected and how it's used in your practice. Shifu Intel is the Processor: we store and process that data only to provide the service (hosting your dashboard, running your public booking page, matching bookings to client records, sending confirmations/reminders you've configured, processing payments), and only on your instructions as given through your use of the product.
3. Subject matter and duration
Subject matter: hosting and processing of client records, guest booking data, and related business data within Shifu Intel. Duration: for as long as you maintain an active Shifu Intel account, plus the deletion period described in Section 8.
4. Categories of data and data subjects
- Data subjects: your clients, and guests who book sessions or leave reviews through your public page.
- Categories of data: name, email address, phone number, and any notes you choose to record about a client; booking date/time and service selected; review star rating and written text; payment status and amount (card details themselves are held by Stripe, not by us).
5. Processor obligations
We will:
- Process personal data only to provide the Shifu Intel service and only on your instructions, except where required by law.
- Apply appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, and row-level security scoping every practitioner's data to their own account.
- Ensure that anyone processing the data on our behalf (including us) is bound by confidentiality.
- Notify you without undue delay if we become aware of a personal data breach affecting your data.
- Assist you, to the extent reasonably possible, in responding to data subject access, correction, or deletion requests, and in meeting your own obligations under applicable data protection law.
- Not engage a new subprocessor materially changing the risk profile of processing without giving you reasonable notice.
6. Subprocessors
We use the following subprocessors to provide the service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Stripe — payment processing for subscriptions and client payments collected at booking.
- PostHog — product analytics on the practitioner-facing dashboard only.
- Sentry — error monitoring.
- Resend and Twilio — booking confirmation/reminder emails and texts, where you've configured them.
Each subprocessor is bound by contract to protect personal data to a standard consistent with this DPA. We'll update this list as it changes; see Section 10 for how we notify you of changes.
7. International transfers
Our subprocessors may process data in the United States and other countries where they operate infrastructure. Where required, we rely on those subprocessors' own standard contractual clauses or equivalent safeguards for cross-border transfers.
8. Data return and deletion
On request, or when you close your account, we will delete or return your client and guest data within a reasonable period, except where we're required to retain it by law. You can request export or deletion at any time by contacting us (Section 11).
9. Audit
On reasonable written request, and no more than once per year, we will provide information reasonably necessary to demonstrate compliance with this DPA. Given Shifu Intel's current scale as a solo-operated project, this is provided as documentation and written responses rather than on-site audits.
10. Changes to this agreement
We may update this DPA, including the subprocessor list, as Shifu Intel grows. We'll update the date at the top of this page when we do, and material changes will be communicated by email where practical.
11. Contact
Questions about this agreement or a data protection request: hello@shifuintel.com