Data Processing Agreement
Version 2026-08-31 · Effective 31 August 2026
The processing terms we offer customers. Readable here in full, and signable on request.
1. Parties and scope
This agreement is offered by Adolfo Gastalver Rubio, Sole trader (autónomo), NIF 05294386Q, Carrer de la Igualtat 67, 6-2, 08902 Barcelona, Spain (the “processor”) to any customer of Shingou (the “controller”) whose use of the service involves the processor handling personal data on the controller’s behalf. It supplements the Terms of Service and prevails over them on any conflict about processing.
Read the scope narrowly, because it is narrow. Shingou is a read-only market-sentiment API. It receives no personal data from a customer beyond the account and request metadata described in the Privacy Policy, and it processes no data about a customer’s own users or clients. If your intended use would send us third-party personal data, tell us before you start, because nothing in the service is designed for it.
2. Subject matter, duration, nature and purpose
- Subject matter: provision of the Shingou sentiment API and the account, authentication, metering and billing functions around it.
- Duration: for as long as the controller’s account exists, plus the retention periods in the Privacy Policy.
- Nature and purpose: authentication, API-key issuance and verification, request metering, quota enforcement, abuse prevention, billing, and support correspondence.
- Categories of data subject: the natural persons who hold or use an account.
- Categories of personal data: email address, plan, API-key metadata (name, prefix, timestamps and a hash, never the key), request telemetry including truncated IP data, and any content of support email.
- Special categories: none. The service is not designed to receive any and none should be sent.
3. Processor obligations
- Process personal data only on the controller’s documented instructions, which these terms and the Terms of Service constitute.
- Not transfer personal data to a third country except as set out in section 6.
- Impose confidentiality on any person authorised to process the data.
- Implement the measures in section 4 and assist the controller in meeting its own obligations under Articles 32 to 36 GDPR.
- Assist with data-subject requests, and forward any request received directly.
- Delete or return personal data at the end of the engagement, save where retention is required by law. The Privacy Policy states the periods.
- Make available the information needed to demonstrate compliance, and allow audit. Given the size of this operation an audit is answered by written response and evidence rather than by an on-site visit, unless a supervisory authority requires otherwise.
4. Security measures
The measures actually in force are documented, in specifics rather than in adjectives, and the same document names the gaps. Row-level security on every table, hashed API keys, scoped service credentials, a content security policy, IP and quota guards, and a public append-only hash-commitment log for published signals.
Two limits are stated here rather than left to be discovered. There is no automated database backup on the current hosting tier: the database runs on a plan whose provider recommends self-managed exports, so recovery relies on those exports and on the published commitment log rather than on a provider-side daily snapshot with a retention window. And no professional-indemnity or cyber-liability insurance is currently held.
5. Sub-processors
The controller gives general authorisation for the sub-processors listed on the sub-processor register, currently 9 vendors. A new sub-processor handling personal data is published on that page before it begins processing, and the controller may object in writing. Each sub-processor is engaged under terms no less protective than these.
6. International transfers
Where personal data is transferred outside the European Economic Area the processor relies on the European Commission’s Standard Contractual Clauses or on an adequacy decision. The register names each sub-processor’s processing region.
7. Personal data breach
The processor notifies the controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the controller’s data, with the information available at the time and updates as it is established. The processor’s own notification duty to the Spanish supervisory authority (AEPD) under Article 33 runs to 72 hours where the processor is controller of the data concerned.
8. Liability
Liability under this agreement is governed by the limitations in the Terms of Service, except where GDPR Article 82 provides otherwise. The processor is a sole trader with unlimited personal liability and no insurance cover; a controller for whom that is unacceptable should say so before contracting rather than after.
9. Signing
Email contact@shingou.io and you will get this document as a signable file, or your own DPA reviewed and either countersigned or answered with what we cannot accept and why. Governing law and jurisdiction follow the Terms of Service: Barcelona, Spain.
Change history
Every entry below is checkable against this project’s public commit history. A change history nobody can verify is a claim rather than a record.
- 2026-08-31 — Data Processing Agreement and the sub-processor register published. Anthropic and Voyage AI added to the register, having previously been absent from the processor list on the Privacy Policy. GitHub moved from that list into the register's no-personal-data section, where it belongs: the Privacy Policy's list is who we share personal data with, and the hash-commitment log contains none. Nothing was removed from disclosure; the register lists every vendor and the Privacy Policy links to it.
- 2026-08-14 — Terms §5 backed by the billing code: listed prices are VAT-exclusive, the rate is shown before payment, and EU businesses supplying a VAT number are billed under the reverse charge.
- 2026-08-03 — Current version. Security and data-retention statements aligned with what the system actually enforces.
- 2026-08-02 — Controller contact address moved from a personal mailbox to contact@shingou.io, so data-subject rights survive any one mailbox.
- 2026-07-04 — Terms of Service, Privacy Policy and Legal Notice first published.