Skip to document
Koreshield
ProductDemoHow It WorksResearchPricingFAQCompany
Go to workspace
ProductDemoHow It WorksResearchPricingFAQCompanyGo to workspace
Data protection

Data Processing Agreement

The processor terms that apply when Koreshield handles personal data on a customer's behalf.

Effective 8 October 2026Koreshield Labs Ltd · Company No. 17057784
Legal documentsPrivacy PolicyTerms of ServiceData Processing AgreementLegal and privacy enquiriesReport a security incident
01

Parties and scope

This Data Processing Agreement ("DPA") forms part of the Koreshield Terms of Service or other written agreement (the "Agreement") between the customer identified in that Agreement ("Customer") and Koreshield Labs Ltd, company number 17057784, of 3rd Floor, 86–90 Paul Street, London, EC2A 4NE ("Koreshield").

It applies where Koreshield processes personal data on Customer's behalf in providing the Services. Customer is the controller, or a processor acting for another controller; Koreshield is the processor or sub-processor. If this DPA conflicts with the Agreement on personal-data processing, this DPA controls.

02

Definitions and applicable law

Controller, processor, data subject, personal data, processing, personal data breach, and supervisory authority have the meanings in applicable data-protection law. Applicable Data Protection Law includes the UK GDPR and Data Protection Act 2018 and, where applicable, the EU GDPR and laws implementing or supplementing them.

Customer Personal Data means personal data processed by Koreshield on Customer's behalf through the Services. Sub-processor means another processor engaged by Koreshield to process Customer Personal Data.

03

Processing details

Subject matter and purpose: providing AI-security scanning, policy decisions, security evidence, workspace administration, support, and related service operations. Duration: the term of the Agreement plus the limited deletion and recovery period described below.

Nature of processing: receiving, transiently analysing, classifying, hashing, recording decision evidence, optionally encrypting selected review content, retrieving for authorised review, securing, deleting, and supporting Customer Personal Data.

Data subjects may include Customer personnel, authorised users, end users, correspondents, and individuals mentioned in content submitted for scanning. Data may include account identifiers, contact details, authentication and network data, prompts, retrieved context, tool names and arguments, and security classifications. Customer must not submit special-category or criminal-offence data unless authorised by the Agreement and protected by appropriate safeguards.

04

Documented instructions

Koreshield will process Customer Personal Data only on Customer's documented instructions, including the Agreement, configured storage and retention settings, API requests, support instructions, and applicable Order Forms, unless law requires other processing. Where legally permitted, Koreshield will notify Customer before processing required by law.

If Koreshield reasonably believes an instruction infringes Applicable Data Protection Law, it will inform Customer and may suspend the affected processing until the parties resolve the issue. Koreshield does not determine whether Customer's instructions satisfy Customer's own legal obligations.

05

Customer obligations

Customer warrants that its instructions are lawful and that it has provided all required notices and obtained all required rights, permissions, and lawful bases for Koreshield to process Customer Personal Data. Customer will configure the Services appropriately, minimise submitted data, protect credentials, and respond to data-subject and regulator requests for which it is responsible.

Where Customer acts as a processor, Customer confirms that its controller has authorised Koreshield's engagement as a sub-processor and the instructions Customer gives us.

06

Confidentiality and access

Koreshield will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and receive access only where needed for their duties. Koreshield will apply tenant-scoped controls and restrict production access to authorised personnel and service providers.

07

Security measures

Koreshield will maintain technical and organisational measures appropriate to the risk, including encrypted transport, one-way hashing of credentials and API keys, tenant-scoped authorisation, restricted administrative access, security and operational logging, vulnerability and dependency controls, and tested release procedures.

The default hosted content mode is hash-only, in which raw scan content is not persisted in event records. If Customer enables encrypted content storage, selected review content is encrypted before storage and follows workspace retention. Koreshield may update security measures as technology and risks evolve, provided the overall protection is not materially reduced.

08

Sub-processors

Customer gives general written authorisation for Koreshield to use sub-processors necessary to provide the Services. Current core providers include Hetzner for hosted application and database infrastructure; Cloudflare for network, DNS, edge security, Turnstile, Workers, and operational log storage; Postmark for transactional email; Polar for subscription billing; and Google or GitHub where Customer users choose optional sign-in.

Koreshield will impose data-protection obligations on a sub-processor appropriate to the services it performs and remains responsible for its own obligations under this DPA. We will provide reasonable notice of a material new sub-processor where required by law or contract. Customer may object on reasonable data-protection grounds; the parties will work in good faith on a practical resolution, which may include disabling an optional feature or ending the affected Service.

09

International transfers

Primary hosted application and database processing takes place in Germany. If Koreshield transfers Customer Personal Data from the UK or EEA to a country without an applicable adequacy decision, Koreshield will use a valid transfer mechanism, such as the approved standard contractual clauses and UK addendum or international data transfer agreement as applicable, and supplementary safeguards appropriate to the risk.

10

Data-subject requests and compliance assistance

Taking into account the nature of processing, Koreshield will provide reasonable assistance for Customer to respond to requests to exercise data-subject rights. If we receive a request concerning Customer Personal Data, we will direct it to Customer unless law requires otherwise and will not respond substantively without Customer's instruction.

Koreshield will provide information reasonably necessary for Customer's data-protection impact assessments, prior consultations, records of processing, and regulator enquiries, taking account of the processing and information available to us. Fees may apply for exceptional assistance beyond standard service obligations where permitted by the Agreement.

11

Personal data breaches

Koreshield will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature and likely consequences, affected data and people where known, mitigation taken or proposed, and a contact point, to the extent information is available. We may provide information in phases as the investigation progresses.

Koreshield will take reasonable steps to contain, investigate, and remediate the breach and will cooperate with Customer's legally required notifications. A notice is not an admission of fault or liability. Customer is responsible for notices to its controllers, data subjects, or regulators unless law assigns that duty to Koreshield.

12

Return, deletion, and retention

During the Agreement, Customer can access and export available event records through the Services. On termination or written instruction, Koreshield will delete or return Customer Personal Data from active systems within the period stated in the Agreement or, if none is stated, within 30 days, unless law requires retention.

Workspace event retention is configurable from 1 to 365 days, subject to plan and contract. Hash-only mode does not retain raw scan content. Where restricted recovery copies exist, deleted data may remain until those copies are retired; it will remain protected, isolated from routine processing, and used only for recovery, security, or legal requirements.

13

Audit and information rights

Koreshield will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may request an audit no more than once in a 12-month period, unless a breach, regulator, or credible evidence justifies another audit. Audits must use an independent qualified auditor, give at least 30 days' notice where practicable, occur during normal business hours, minimise disruption, protect other customers, and comply with security requirements.

Where a current independent report, questionnaire, or documented control review reasonably addresses the request, the parties will use it before an on-site audit. Customer bears its audit costs unless the audit identifies Koreshield's material breach of this DPA.

14

Liability, duration, and legal terms

The Agreement's liability limits and exclusions apply to this DPA to the extent permitted by law. This DPA begins with the Agreement and continues while Koreshield processes Customer Personal Data. Confidentiality, deletion, audit, transfer, and liability provisions survive as needed to give them effect.

This DPA is governed by the governing law and jurisdiction in the Agreement, or, if none is stated, the laws and courts of England and Wales. Changes must be in writing, except Koreshield may update this public DPA where needed to comply with law or improve protection without materially reducing Customer's rights.

15

Contact

Data-protection and security notices: hello@koreshield.ai. Use the subject “Security incident” for suspected incidents. Postal address: Koreshield Labs Ltd, 3rd Floor, 86–90 Paul Street, London, EC2A 4NE, United Kingdom.

Koreshield

Security boundaries for AI support workflows.

hello@koreshield.ai

Product

Security BoundariesHow It WorksInteractive DemoPricingFAQ

Company

AboutTeamCareersContact

Resources

ResearchDocumentationBlogFAQ

Legal

Privacy PolicyTerms of ServiceData Processing AgreementSecurity contact
© 2026 Koreshield. All rights reserved.Koreshield Labs Ltd. · Incorporated in England & Wales · Co. No. 17057784