01DPA scope
This DPA covers all personal data processing activities Sharebri performs on behalf of customers (the Data Controller).
Effective from the date the customer activates their account, lasting throughout the service contract term.
02Roles of the parties
Customer: Data Controller — decides the purpose and means of processing.
Sharebri: Data Processor — carries out processing per the customer's lawful instructions.
03Processing activities
Sharebri processes data only within the scope necessary to provide the service per the contract.
Will not process beyond scope without written instruction from the customer.
Sharebri staff with data access must sign NDAs and complete security training.
04Security measures
Data encrypted in transit (TLS 1.3) and at rest (AES-256).
Access control follows the principle of least privilege, with CASL + RLS integration.
Full audit log for any access to sensitive data.
Daily automatic backups with 30-day retention.
05Subprocessors
Sharebri uses the following infrastructure providers, each under a corresponding DPA:
Supabase Inc. — database and auth management.
Railway Corp. — backend hosting.
Resend / SendGrid — transactional email delivery.
Customers receive 30 days' notice of any subprocessor list change.
06Incident response
Upon detecting a security incident, Sharebri notifies the customer within 72 hours.
Notification includes: scope of impact, remediation steps, actions required from the customer.
Sharebri assists the customer in fulfilling regulatory notification obligations as needed.
07Audit rights
Enterprise customers may request annual independent audit reports (SOC 2 Type II).
Onsite audits may be arranged in advance with the requesting party covering the cost.