Draft v0.1 · available on request Legal · GDPR Art. 28

Data processing addendum.

Most Cult Shield users are sole creators acting in their personal capacity, in which case Cult Shield is the controller of your personal data and our privacy policy applies in full. This page is for studios and agencies who are the controller of their own clients' work and need a signed DPA.

Who needs this

You need a DPA with Cult Shield if you process the personal data of your own clients (other people's email addresses, legal names, or work for which they hold copyright) through your Cult Shield account. In that case, you are the controller for that personal data and Cult Shield is your processor under GDPR Article 28.

How to execute

Email legal@cultshield.com from a domain associated with your billing account, with subject line "DPA request". We will send you our standard DPA (built on the European Commission's Standard Contractual Clauses) for counter-signature. Average turnaround: two business days.

Subprocessors

Our current subprocessors are listed on the privacy page (Section 4). Material changes are notified 30 days in advance.

Contact

For any GDPR or DPA-related question: privacy@cultshield.com.

Effective date pending counsel review · Last drafted 2026-05-26