This Data Processing Addendum ("DPA") forms part of the agreement for the ShookAI service between Shook Digital Oy, trading as ShookAI ("Processor"), and the Customer ("Controller"). Terms not defined in this DPA have the meanings given in the ShookAI Terms of Service and the GDPR.
1. Roles and scope
1.1 Controller is the controller of the Service Personal Data or a processor acting on behalf of its own clients, in which case Processor acts as Controller's subprocessor. Processor processes Service Personal Data on Controller's behalf.
1.2 "Service Personal Data" means Personal Data contained in Customer Data that Processor processes on Controller's behalf in providing the Service.
1.3 This DPA does not apply to Personal Data that Processor processes as an independent controller under Section 12.2 of the Terms of Service.
1.4 The Agreement, this DPA and Controller's configuration and use of the Service constitute Controller's documented instructions. Further instructions must be agreed in writing. Controller instructs Processor to anonymise Service Personal Data for the purposes set out in Section 6.4 of the Terms of Service. Once anonymised, the data is no longer Personal Data.
2. Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the ShookAI Service to Controller |
| Nature and purpose | Retrieval of data from Connected Accounts through APIs; hosting and storage; automated analysis of creatives and performance data, including with AI models; display, export and deletion |
| Duration | The Subscription Term and the deletion period set out in Section 9 |
| Data subjects | Controller's Users and personnel named in Customer Data; creators, actors, influencers and other persons who appear in or are credited on Controller's creatives, including holders of Spark Ads or similar identities |
| Categories of data | Names, usernames and handles, likeness and voice in images and videos, contact details, and Personal Data in documents uploaded by Controller |
| Special categories | None intended. Controller shall not submit special categories of Personal Data |
| Excluded data | Personal Data of advertising audiences. The Service receives only aggregated statistics from platform providers |
3. Controller obligations
3.1 Controller shall ensure that its processing of Service Personal Data complies with the GDPR and other applicable data protection laws ("Data Laws").
3.2 Controller is responsible for having valid legal grounds for the processing, including any consents and rights needed from creators and other persons who appear in its creatives for those creatives to be analysed by the Service.
3.3 Controller is responsible for ensuring that its instructions comply with Data Laws.
4. Processor obligations
4.1 Processor processes Service Personal Data only on Controller's documented instructions, including with regard to transfers to third countries, unless EU or Member State law requires otherwise. In that case, Processor informs Controller before the processing, unless that law prohibits it from doing so.
4.2 Processor informs Controller without delay if, in its opinion, an instruction infringes Data Laws.
4.3 Processor ensures that persons authorised to process Service Personal Data are bound by confidentiality.
4.4 Processor implements the technical and organisational measures set out in Section 11 and may update them, provided that the overall level of protection is not reduced.
4.5 Taking into account the nature of the processing, Processor assists Controller (i) through appropriate technical and organisational measures in responding to data subject requests, and (ii) in ensuring compliance with Articles 32–36 GDPR. Processor forwards to Controller without undue delay any request it receives from a data subject or an authority concerning Service Personal Data.
4.6 Processor may charge reasonable fees at its then-current hourly rates for assistance that goes beyond the standard functionality of the Service, except where the assistance is needed because of Processor's own breach.
5. Subprocessors
5.1 Controller gives Processor a general authorisation to engage subprocessors. The current list of subprocessors, including AI model providers, is published at https://shook.ai/legal/subprocessors.
5.2 Processor notifies Controller of any intended addition or replacement of a subprocessor at least thirty (30) days in advance through the list and by email to subscribed contacts.
5.3 Controller may object to a new subprocessor on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Controller may terminate the affected part of the Service before the change takes effect and receive a pro rata refund of any prepaid Fees for it.
5.4 Processor shall impose on each subprocessor, by written contract, data protection obligations that provide at least the same level of protection as this DPA. Processor remains fully liable to Controller for the performance of its subprocessors.
6. International transfers
Processor processes Service Personal Data primarily within the EU/EEA. Transfers outside the EU/EEA are made only in accordance with Chapter V of the GDPR, relying on an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified) or on the European Commission's Standard Contractual Clauses, together with a transfer impact assessment and supplementary measures where required.
7. Personal data breaches
7.1 Processor notifies Controller of a personal data breach concerning Service Personal Data without undue delay and in any event within forty-eight (48) hours after becoming aware of it.
7.2 The notification includes, to the extent available, a description of the nature of the breach (including the categories and approximate number of data subjects and records concerned), a contact person for further information, the likely consequences of the breach and the measures taken or proposed to address it. Where all information is not available at once, Processor provides it in phases without undue delay.
7.3 Processor takes reasonable measures to contain the breach and mitigate its effects, and documents the breach. Processor does not inform third parties of the breach without Controller's prior written consent, unless required by law.
8. Audits
8.1 Processor makes available to Controller the information necessary to demonstrate compliance with this DPA, primarily through security documentation, questionnaires and any available certifications or audit reports.
8.2 If that information is not sufficient, Controller may audit Processor once per calendar year on at least thirty (30) days' notice, during business hours, through an independent auditor who is not a competitor of Processor and who is bound by confidentiality. Controller bears its own audit costs.
8.3 The frequency limit does not apply where a supervisory authority requires an audit or after a personal data breach at Processor.
8.4 Processor is not required to disclose trade secrets, other customers' data or information that it is legally bound to keep confidential.
9. Return and deletion
When the Service ends, Controller may export Service Personal Data within thirty (30) days. Processor then deletes Service Personal Data within ninety (90) days, unless EU or Member State law requires its storage. Data in backups is deleted in the normal backup cycle and remains protected until then. On request, Processor confirms the deletion in writing.
10. Liability
The limitations of liability in the Terms of Service apply to claims under this DPA. Nothing in this DPA limits either party's liability towards data subjects under Article 82 of the GDPR.
11. Security measures
| Area | Measure |
|---|---|
| Encryption | TLS 1.2 or higher in transit; AES-256 at rest |
| Access control | Role-based, least-privilege access; SSO and multi-factor authentication for staff; access reviews at least twice a year |
| Customer isolation | Logical separation of each customer's data by Organization |
| Hosting | Hosted on Google Cloud in the EU |
| Logging and monitoring | Logging of administrative access and security events; alerting on anomalies |
| Backups | Encrypted backups with defined retention; periodic restore tests |
| Vulnerability management | Dependency scanning, timely patching and periodic penetration testing |
| AI providers | Contractual prohibition on training with Customer Data; retention limited to what the provider needs to deliver its service |
| Personnel | Confidentiality undertakings; security and data protection training |
| Incident response | Documented incident response process covering the 48-hour notification in Section 7 |