Legal

Data Processing Agreement (DPA) — Alt+Shift+X

DATA PROCESSING AGREEMENT (DPA)

Alt+Shift+X Platform

Effective Date: June 14, 2026 | Version: 2.0

Processor: Trust AR LLC, a West Virginia limited liability company, doing business as Alt+Shift+X 1405 Earl L. Core Rd., Morgantown, WV 26501, United States Email: info@altshiftx.tech


This Data Processing Agreement ("DPA") forms part of the agreement between Trust AR LLC d/b/a Alt+Shift+X ("Processor") and the customer entity identified in the associated platform account ("Controller"). It governs the processing of personal data by Alt+Shift+X on behalf of the Controller in connection with the Controller's use of the Alt+Shift+X platform and services. This DPA is required under Article 28 of the EU GDPR and Article 28 of the UK GDPR where the Controller is established in the EEA or UK or processes personal data of EEA or UK residents. This DPA is incorporated into and supplements the Alt+Shift+X Terms of Service.


SECTION 1 — DEFINITIONS

1.1 "Controller" means the customer entity that determines the purposes and means of processing personal data through its use of the Platform.

1.2 "Processor" means Trust AR LLC d/b/a Alt+Shift+X, which processes personal data on behalf of the Controller.

1.3 "Personal Data" means any information relating to an identified or identifiable natural person as defined under applicable Data Protection Law.

1.4 "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, erasure, or destruction.

1.5 "Data Protection Law" means the EU GDPR (Regulation (EU) 2016/679), the UK GDPR, and any applicable national implementing legislation, as amended from time to time.

1.6 "Sub-processor" means any third party engaged by Alt+Shift+X to process Personal Data on behalf of the Controller.

1.7 "Data Subject" means the natural person to whom Personal Data relates.

1.8 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by the European Commission under Decision 2021/914/EU, as may be updated from time to time.


SECTION 2 — SCOPE & NATURE OF PROCESSING

2.1 Subject Matter — Trust AR LLC d/b/a Alt+Shift+X processes Personal Data on behalf of the Controller solely to provide Platform services as described in the Terms of Service.

2.2 Duration — Processing continues for the duration of the Controller's active platform subscription and for such period thereafter as required to fulfill legal obligations or resolve disputes.

2.3 Purposes of Processing:

  • Providing and operating the Platform and its features
  • Authenticating users and managing sessions
  • Processing payments and managing subscriptions
  • Delivering Component access and API functionality
  • Providing customer support
  • Security monitoring and fraud prevention
  • Sending transactional notifications

2.4 Categories of Personal Data:

  • User account data: name, email address, job title, company
  • Usage data: API calls, feature interactions, session data
  • Payment identifiers: Stripe/PayPal customer IDs (not full card numbers)
  • Communication records: support correspondence
  • Technical data: IP addresses, device data, browser information

2.5 Categories of Data Subjects:

  • Controller's employees, contractors, or representatives who use the Platform
  • Controller's end users who interact with Components deployed by the Controller (if applicable)

SECTION 3 — OBLIGATIONS OF TRUST AR LLC D/B/A ALT+SHIFT+X (PROCESSOR)

3.1 Instructions — Process Personal Data only on documented Controller instructions per this DPA and the Terms of Service.

3.2 Confidentiality — Ensure all authorized processors are bound by confidentiality obligations.

3.3 Security — Implement and maintain appropriate technical and organizational measures (see Section 5).

3.4 Sub-processors — Not engage Sub-processors without prior authorization (see Section 6).

3.5 Data Subject Rights — Assist the Controller in responding to Data Subject requests: access, rectification, erasure, restriction, portability, objection.

3.6 Security Assistance — Assist Controller compliance with GDPR Articles 32–36: security of processing, breach notification, DPIAs, prior consultation.

3.7 Deletion or Return — Upon termination, delete or return all Personal Data at Controller's choice, unless law requires retention.

3.8 Audit Rights — Make available all information necessary to demonstrate compliance; support Controller audits subject to advance notice and confidentiality.


SECTION 4 — OBLIGATIONS OF THE CONTROLLER

4.1 Ensure processing instructions comply with Data Protection Law. 4.2 Ensure a valid legal basis exists for processing. 4.3 Ensure Data Subjects have received required privacy notices. 4.4 Not instruct Alt+Shift+X to process in violation of Data Protection Law. 4.5 Be responsible for all Personal Data uploaded or processed through the Platform.


SECTION 5 — SECURITY MEASURES

| Measure | Implementation | |---|---| | Encryption in transit | TLS 1.2+ / HTTPS on all endpoints | | Encryption at rest | Sensitive data fields encrypted at rest | | Access controls | RBAC; least-privilege principle | | Authentication | MFA for administrative access | | Security monitoring | Automated threat detection via the Sentinel | | Audit logging | Comprehensive audit trail for all data access and modification | | Incident response | Documented breach notification and response procedure | | Vendor management | Sub-processors assessed for security compliance | | Data minimization | Only data necessary for service delivery processed |


SECTION 6 — SUB-PROCESSORS

6.1 Authorized Sub-processors

| Sub-processor | Location | Purpose | |---|---|---| | Stripe, Inc. | United States | Payment processing, subscription billing | | PayPal Holdings, Inc. | United States | Alternative payment processing | | Base44 | United States | Platform infrastructure and hosting | | Email delivery provider | United States | Transactional and notification emails |

6.2 14 days' notice before any Sub-processor change. Controller may object on legitimate data protection grounds.

6.3 Trust AR LLC d/b/a Alt+Shift+X imposes equivalent data protection obligations on all Sub-processors and remains liable for their performance.


SECTION 7 — INTERNATIONAL DATA TRANSFERS

Transfers from EEA/UK/Switzerland to the United States are made under:

  • EU SCCs: European Commission Decision 2021/914/EU, Module 2 (Controller to Processor), incorporated by reference
  • UK IDTA / UK Addendum to SCCs — for UK transfers
  • Adequacy Decisions — where applicable

SCC Annexes:

  • Annex I(A): Controller = platform account entity. Processor = Trust AR LLC d/b/a Alt+Shift+X, 1405 Earl L. Core Rd., Morgantown, WV 26501, United States.
  • Annex I(B): Description of transfer = Section 2 of this DPA.
  • Annex I(C): Competent supervisory authority = Controller's EU member state DPA / UK ICO.
  • Annex II: Technical and organizational measures = Section 5 of this DPA.

SECTION 8 — DATA BREACH NOTIFICATION

In the event of a Personal Data breach, Trust AR LLC d/b/a Alt+Shift+X will notify the Controller:

  • Without undue delay and within 72 hours of becoming aware
  • With details of: nature; categories and approximate number of Data Subjects and records affected; likely consequences; measures taken or proposed
  • With ongoing updates as more information becomes available

Controller is responsible for determining whether to notify its supervisory authority and/or Data Subjects.


SECTION 9 — DATA PROTECTION IMPACT ASSESSMENTS

Upon reasonable request, Trust AR LLC d/b/a Alt+Shift+X will provide information necessary to assist the Controller in conducting a DPIA under GDPR Article 35.


SECTION 10 — TERM & TERMINATION

Effective for the duration of the Controller's use of the Platform. Terminates automatically with the Terms of Service. Data deletion/return obligations survive termination.


SECTION 11 — GOVERNING LAW

This DPA is governed by the laws of the State of West Virginia, United States, subject to any mandatory provisions of applicable Data Protection Law that cannot be contractually varied.


SECTION 12 — CONTACT & EXECUTION

Trust AR LLC d/b/a Alt+Shift+X 1405 Earl L. Core Rd., Morgantown, WV 26501, United States Email: info@altshiftx.tech Subject: "DPA Request — [Company Name]"

Countersigned copies available upon request for EU/UK enterprise accounts.

© 2026 Trust AR LLC d/b/a Alt+Shift+X. All rights reserved. Data Processing Agreement — Version 2.0 — Effective June 14, 2026

We use cookies to keep you logged in, process payments, and understand how the Platform is used. Non-essential cookies stay off until you accept. By clicking Accept All, you agree to our Cookie Policy.