Legal

Data Processing Agreement

Shift Copilot · Version 1.2 · Effective June 2026 · jordan.deboer807@gmail.com

This Data Processing Agreement ("DPA") forms part of the service agreement between Shift Copilot ("we", "us", "our") and the organisation accessing Shift Copilot services ("Customer", "you"). By using Shift Copilot, the Customer agrees to the terms of this DPA.

Version 1.2 changelog: aligned session duration, retention wording, sub-processor disclosures, and basic rate-limiting controls with current service behaviour.

1. Definitions

Personal Data means any information relating to an identified or identifiable natural person processed by Shift Copilot on behalf of the Customer.

Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

Data Controller means the Customer, who determines the purposes and means of Processing Personal Data.

Data Processor means Shift Copilot, which Processes Personal Data on behalf of the Customer.

Sub-processor means any third party engaged by Shift Copilot to Process Personal Data.

2. Scope and Purpose

Shift Copilot processes Personal Data solely to provide the shift handover documentation service described in our Terms of Service. Processing occurs only on documented instructions from the Customer.

The subject matter of processing is the provision of AI-assisted shift handover report generation, report storage, user account management, and related services for Australian mining and industrial operations.

3. Data We Process

CategoryData TypesPurposeRetention
Account DataName, email address, role, site assignmentUser authentication and access controlDuration of subscription + 30 days
Handover ReportsShift notes, structured report content, site name, supervisor name, shift type, date, commodityCore service delivery and audit trailMinimum 24 months from creation, to support handover record-keeping obligations under the WHS (Mines) Regulations 2022 (WA)
Attached PhotosImages uploaded by supervisorsVisual documentation within reports24 months from creation
Contact and Pilot EnquiriesName, email address, phone number, organisation, site details, role, and message content submitted through public formsResponding to enquiries, pilot applications, and sales conversationsFor as long as reasonably necessary to manage the enquiry or customer relationship, then deleted on verified request where applicable
Usage DataLogin timestamps, report generation eventsService improvement and security12 months
Session DataAuthentication tokensSecure session management14 days from creation

4. Sub-processors

Shift Copilot uses the following sub-processors to deliver the service. The Customer authorises engagement of these sub-processors:

Sub-processorPurposeData Location
Vercel Inc.Application hosting and serverless functionsGlobal CDN (primary US infrastructure)
Neon Inc.Database storage for reports, users, and session dataAustralia (AWS Sydney, ap-southeast-2)
Vercel BlobAttached photo storageGlobal CDN (primary US infrastructure)
Formspree Inc.Contact and pilot application form processingUnited States
Resend Inc.Transactional email deliveryUnited States
Sentry (Functional Software Inc.)Application error monitoringUnited States
Anthropic PBCAI report generation (processes shift notes)United States

Note on data location: Account data, handover reports, and session data are stored in Australia (Neon, AWS Sydney ap-southeast-2). Certain sub-processors listed above operate in the United States: shift notes are transmitted to Anthropic's US-based API for report generation and may be retained for up to 30 days under Anthropic's standard commercial API terms unless separate retention terms have been agreed; API data is not used for model training by default. Public form submissions are handled by Formspree, transactional email by Resend, and error monitoring by Sentry. Customers requiring AI processing to remain fully on-shore should contact us at jordan.deboer807@gmail.com; on-shore AI processing via AWS Bedrock (Sydney) is on our roadmap.

5. Security Measures

Shift Copilot implements the following technical and organisational security measures:

6. Data Subject Rights

Shift Copilot will assist the Customer in responding to requests from individuals to exercise their rights under the Privacy Act 1988 (Cth) and applicable Australian Privacy Principles, including rights to access, correction, and deletion of Personal Data.

To submit a data subject rights request, contact: jordan.deboer807@gmail.com

7. Data Breach Notification

In the event of a Personal Data breach, Shift Copilot will notify the Customer without undue delay and in any event within 72 hours of becoming aware of the breach, providing sufficient information to allow the Customer to meet any applicable notification obligations under the Notifiable Data Breaches scheme.

8. Deletion and Return of Data

Upon termination of the service agreement, Shift Copilot will, at the Customer's election, delete or return all Personal Data within 30 days. Deletion certificates are available on request. Data retained beyond this period will only be kept where required by law.

9. Audit Rights

The Customer may request information reasonably necessary to demonstrate compliance with this DPA. Shift Copilot will provide written responses to reasonable audit questionnaires within 30 days.

10. Governing Law

This DPA is governed by the laws of Western Australia, Australia. The parties submit to the non-exclusive jurisdiction of the courts of Western Australia.

11. Contact

For questions about this DPA or data processing practices: jordan.deboer807@gmail.com