Governance record
Data Processing Addendum
Processing roles, instructions, safeguards, subprocessors, assistance, and deletion for customer personal data handled by Edgion Shield.
Effective 11 July 20261. Scope and roles
This addendum applies when Edgion Shield processes personal data on behalf of a customer in providing the service. The customer acts as controller or processor, as applicable, and Edgion acts as processor or subprocessor for that data. Customer instructions are documented by the agreement, product configuration, and authorized support requests.
2. Processing details
Processing may include collection, transmission, routing, security analysis, storage, retrieval, deletion, and support access needed to operate the selected service. Data subjects may include customer users, visitors, mail users, and people represented in authorized support material. Categories may include identifiers, network metadata, security events, configuration, and communications metadata.
3. Confidentiality and security
Edgion applies least privilege, tenant isolation, authentication controls, audit records, secret protection, and incident handling appropriate to the service. People authorized to process customer personal data are subject to confidentiality obligations. The customer remains responsible for secure deployment, credentials, lawful configuration, and retention choices under its control.
4. Public telemetry
The delayed public aggregate is designed to contain only rounded, thresholded global measurements. Data that does not pass the documented contribution, visitor, delay, and dominance controls is suppressed before the public response is serialized. The public endpoint is not a customer-level export.
5. AI subprocessing
OpenAI is used only when eligible optional AI processing is enabled. Model input is limited to numeric aggregates, enums, and an ephemeral scope reference. Production processing requires an approved Zero Data Retention project and non-storage requests. Raw logs, domains, customer prompts, and direct identifiers are excluded from model input by product design.
6. Subprocessors and transfers
Edgion may use infrastructure, email, payment, support, and optional AI providers to provide their documented functions. Edgion will maintain appropriate contractual safeguards for international transfers where required and provide notice of material subprocessor changes through the agreed channel.
7. Assistance and incidents
Taking into account the nature of processing, Edgion will provide reasonable assistance with data-subject requests, security obligations, breach notifications, and legally required assessments. The customer should report suspected incidents promptly through the support channel and provide enough information for investigation.
8. Return, deletion, and audit information
At termination or verified request, customer personal data will be returned or deleted where applicable, subject to lawful retention, backup cycles, security evidence, and records required to establish or defend legal claims. Edgion will provide information reasonably necessary to demonstrate compliance with this addendum, subject to confidentiality and security limits.