Store ShepherdRequest a pilot

Store Shepherd legal

Data Processing Addendum

Last updated: 24 July 2026

This Data Processing Addendum is a working public form for Store Shepherd customer engagements. It applies when referenced by a signed agreement and Store Shepherd processes personal data on a customer’s behalf.

1. Parties and scope

The “Customer” is the entity identified in the applicable order or pilot agreement. “Store Shepherd” is the processor or service provider; its final legal entity, address and trade licence are to be confirmed. This Addendum forms part of the agreement only when incorporated by reference or signed by both parties.

2. Roles and instructions

Customer acts as controller or business and determines why and how personal data is processed. Store Shepherd acts as processor or service provider and processes personal data only on Customer’s documented instructions, including the agreement, configuration choices and authorised support requests, unless law requires otherwise.

Customer is responsible for the lawfulness of its instructions, camera deployment, notices, signage, policies, retention settings and user access. Store Shepherd will notify Customer if, in its reasonable view, an instruction infringes applicable data-protection law.

3. Confidentiality and personnel

Store Shepherd will ensure that personnel authorised to process Customer personal data are subject to confidentiality obligations and receive access only as needed for their responsibilities.

4. Security

Store Shepherd will maintain technical and organisational measures appropriate to the risk, taking into account the nature of the data and available technology. Measures are expected to include:

  • Role-based access and authentication controls.
  • Encryption in transit and, where supported, at rest.
  • Logging, monitoring, vulnerability management and incident response.
  • Data minimisation, retention controls and secure deletion procedures.
  • Business continuity and recovery practices appropriate to the service.

The final security schedule, architecture and audit commitments will be confirmed in the applicable customer agreement.

5. Subprocessors

Customer authorises Store Shepherd to use subprocessors needed to provide infrastructure, hosting, support and communications services. Store Shepherd will impose data-protection obligations appropriate to their services and remain responsible for their performance to the extent required by applicable law. The initial subprocessor list and notice mechanism are to be confirmed before operational processing.

6. Assistance and data-subject requests

Taking into account the nature of processing, Store Shepherd will provide reasonable assistance for Customer to respond to data-subject requests, security assessments, impact assessments and consultations with authorities where required. If Store Shepherd receives a request relating to Customer data, it will direct the requester to Customer unless legally prohibited.

7. Security incidents

Store Shepherd will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer data and provide information reasonably available for Customer’s response. Notice is not an admission of fault or liability.

8. Return, deletion and audit

At the end of the service, Store Shepherd will delete or return Customer personal data as agreed, unless law requires retention. Store Shepherd will make information reasonably necessary to demonstrate compliance available and support proportionate audits subject to confidentiality, security and frequency safeguards.

9. International transfers

Where Customer personal data is transferred across borders, the parties will use the transfer mechanism required by applicable law, which may include approved standard contractual clauses and supplementary safeguards. The applicable mechanism, exporter, importer and governing module are to be confirmed for each deployment.

10. Processing details

Subject matter and duration

Retail camera intelligence, incident preparation, review workflow, support and related services for the term of the applicable agreement plus any documented return or deletion period.

Nature and purpose

Receiving or connecting to authorised camera streams; analysing event sequences; creating relevant clips, metadata and explanations; routing incidents for customer review; recording authorised user decisions; and maintaining service security and support.

Categories of personal data

Video images and actions visible within configured store areas; camera, location and timestamp metadata; incident labels and staff decisions; authorised user account, access and support information. Store Shepherd is not designed to require facial templates or demographic classifications.

Categories of data subjects

Customers, visitors, staff, contractors and other people visible in the Customer’s authorised retail camera environment, together with authorised service users.

11. Contact and precedence

Privacy and processing enquiries may be sent to [email protected]. If this Addendum conflicts with the main agreement on personal-data protection, this Addendum controls to the extent of the conflict. Final entity and notice details remain to be confirmed.

Company legal entity: To be confirmed · Trade licence: To be confirmed. This page will be updated when the final corporate details are confirmed.

Store Shepherd

Camera intelligence for retail loss-prevention teams.

ProductHow it worksWorkspaceRequest a pilot
LegalPrivacy PolicyTerms of ServiceData Processing AddendumCookie Policy

© 2026 Store Shepherd. Dubai, United Arab Emirates.

Legal entity: To be confirmed · Trade licence: To be confirmed