Skip to content
Shakeride

Enterprise compliance

Data Processing Agreement

Standard contractual terms governing the processing of personal data on behalf of B2B customers pursuant to Article 28 of the General Data Protection Regulation (GDPR).

Published by Altitude for Shakeride enterprise clients.

Scope and roles of the parties

This Data Processing Agreement ("DPA") applies whenever Altitude processes personal data on behalf of an enterprise or educational customer ("Customer") in connection with Shakeride.

The Customer acts as the Data Controller, and Altitude acts as the Data Processor under applicable European data protection laws.

Subject matter and nature of processing

The processing consists of provisioning isolated cloud environments, authenticating team members, executing automated technical challenge checks, and capturing CloudTrail telemetry to calculate operational readiness scores.

Categories of processed data

  • Professional identification details (name, corporate email, role, team ID).
  • Ephemeral session credentials generated for sandbox account access.
  • CloudTrail API call logs, diagnostic timestamps, and evaluation scores.

Technical and organizational security measures

Shakeride enforces robust technical and organizational measures (TOMs) designed to protect customer data against accidental loss, unauthorized access, or disclosure:

  • Cryptographic protection: All communications are encrypted in transit with TLS 1.3. Stored database records and telemetry logs are encrypted at rest using AES-256.
  • Complete sandbox isolation: Each ride runs in a separate, ephemeral AWS account with strictly scoped IAM boundary policies. No cross-account data sharing is possible.
  • Least privilege access: Internal access to production databases is restricted by role-based access control and multi-factor authentication.
  • Automated data purge: Ephemeral cloud accounts are wiped upon run termination, and raw CloudTrail event logs are purged after a standard 30-day retention window.

Subprocessors

Customer grants general written authorization for Altitude to engage vetted subprocessors to provide hosting and infrastructure services:

SubprocessorPurposeLocation
Amazon Web Services (AWS)Ephemeral sandbox accounts onlyus-east-1 (US East, N. Virginia)
InfomaniakCore platform hosting, databases, and application servicesSwitzerland (compliant with EU adequacy)

We notify customers of any intended appointment or replacement of subprocessors at least 30 days in advance.

Assistance and incident notification

In the event of a confirmed personal data breach affecting Customer data, Altitude will notify Customer without undue delay and at the latest within 48 hours of becoming aware of the breach. We will assist Customer in fulfilling their obligation to respond to data subjects exercising their GDPR rights.

Execution and bespoke DPA agreements

To request a countersigned copy of this Data Processing Agreement with your organization's legal entity details, or to submit your company's custom vendor DPA, contact our legal desk at:

contact@shakeride.com