Site policies

Data Processing Agreement

The processor terms that apply when you put your staff records in the platform.

Updated 2026-09-09

This Data Processing Agreement governs how Shog Consulting (FZC) processes personal data on behalf of a customer organisation using Shog Corporate Training. It forms part of your subscription terms. It is written for the customer that holds the account and for that customer's data protection or legal reviewer.

The processing at a glance

ItemDetail
ControllerYou, the customer organisation named on the account
ProcessorShog Consulting (FZC), licence SC242038101, STRIP Block C VL07-017, Sharjah, United Arab Emirates
Subject matterDelivery of workplace training, assessment, and issue and verification of training certificates
DurationThe term of your subscription, plus the 30-day export window after it ends
Nature of the processingCollection, storage, encryption, structuring, retrieval, transmission by email, generation of certificate records and documents, export and deletion
PurposeTo let you enrol your staff on courses, to record what they did, and to give you evidence you can show an auditor or a regulator
Categories of data subjectYour staff enrolled as learners; your administrators; auditors to whom you grant time-limited preview access
Categories of personal dataName, work email address, phone number, job details you enter, language chosen, enrolment and progress records, assessment answers and scores, certificate records, sign-in and audit events
Special category data by natureFacial images (identity photographs) and signatures on identity declarations
Sub-processorsOracle Cloud Infrastructure, Stripe, Microsoft, Google. See the Sub-processors list
Location of processingOracle Cloud Infrastructure, Middle East region, plus the sub-processor regions named in the Sub-processors list
DeletionSecure deletion after the 30-day export window, or earlier on your written instruction

1. Roles

You are the controller. You decide who is enrolled, on what course, for what purpose, and how long you need the results. You are responsible for having a lawful basis for that processing, for telling your staff what is happening, and for answering their questions in the first instance.

We are the processor. We process personal data only on your documented instructions. Your instructions are: this agreement, your subscription terms, your order form, and the actions your administrators take in the workspace. Configuring the product is an instruction.

We are not a joint controller with you, and we do not use your learners' personal data for our own purposes. We do not sell it, we do not use it to train models, and we do not use it to market to your staff.

If we believe an instruction from you breaches applicable data protection law, we will tell you, and we may pause that processing until it is resolved.

2. Applicable law and the state of UAE regulation

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data is the onshore UAE data protection law. Its Executive Regulations have still not been issued. The compliance grace period in Article 29 runs from the issue of those Regulations, so that clock has not started, and several operational requirements the Regulations are expected to set (the detail of breach notification timing, cross-border transfer mechanisms and registration duties among them) do not yet exist in binding text.

We state this plainly rather than claim compliance with regulations that do not exist. The commitments in this agreement are ones we make to you contractually. If the Executive Regulations are issued and impose requirements beyond them, we will work with you in good faith to meet those requirements, and we may need to update this agreement.

If you are established in the Dubai International Financial Centre or in Abu Dhabi Global Market, you are subject to that free zone's own data protection law and answer to that free zone's own commissioner rather than to the onshore regime. Those regimes differ from the onshore law and from each other. Your obligations under them are yours to assess. Tell us if they require terms beyond this agreement.

3. Our obligations as processor

We will:

  • process personal data only on your documented instructions, including on transfers;
  • ensure that the people we authorise to access personal data are bound by a duty of confidentiality;
  • apply the technical and organisational measures described in section 5 and in our Security Policy;
  • respect the conditions in section 6 before engaging a sub-processor;
  • assist you, so far as the product allows, with data subject requests, as set out in section 7;
  • assist you, so far as the information is available to us, with your security, breach notification and impact assessment duties;
  • delete or return personal data at the end of the relationship, as set out in section 9;
  • make available to you the information reasonably needed to show that we have met these obligations, as set out in section 10.

4. Confidentiality

Access to your workspace data is limited to the personnel who need it in order to run and support the service. They are bound by confidentiality obligations that survive the end of their engagement. We do not disclose your data to a third party except to a sub-processor listed in section 6, or where we are legally required to do so. Where we are legally compelled to disclose, we will tell you unless the law forbids it.

5. Security measures

The measures below are the ones that shape how this product is built. The Security Policy carries the operational detail.

Separate databases. There is a central platform database, a shared course catalogue, and a separate database for each customer organisation holding that organisation's learner records. Your learners' records are physically separated from every other customer's. This is the primary control: a query against one organisation's database cannot reach another's.

Encryption at rest, with per-organisation keys. Learner names, email addresses and phone numbers are encrypted with AES-256-GCM using data keys held per organisation. Key management uses OCI Vault in production.

Encryption in transit. Traffic to the service is carried over TLS.

Authentication. Your administrators sign in with an email address and password, optionally with a TOTP second factor, or with Google or Microsoft sign-in. Learners do not hold passwords. They receive a private link by email and confirm it with a one-time code.

Audit logging. Each organisation has its own event log, and that log is included in your data export.

Bring your own storage. Where you connect your own SharePoint, OneDrive or Google Drive, certificate files, identity photographs and signed declarations are written to your storage and not to ours. We hold the evidence record, not the file. See the Customer Data and Storage policy.

We may change these measures over time. We will not make a change that materially reduces the overall level of security.

We do not hold an independent security certification such as ISO 27001 or SOC 2, and we do not claim one. If that changes, this agreement will be updated to say so.

6. Sub-processors

You give general authorisation for us to engage the sub-processors listed in the Sub-processors document. That list names each sub-processor, the purpose it serves and its region.

Some of them are engaged only if you choose them. Microsoft SharePoint or OneDrive, and Google Drive, are engaged as storage only where you connect them. Google and Microsoft sign-in are engaged only where your administrators use them.

Before adding or replacing a sub-processor, we will give you at least 30 days' notice by email to the account contacts, and we will update the Sub-processors page. You may object on reasonable data protection grounds within that period by writing to training@shogconsulting.com. We will try to resolve the objection. If we cannot, you may terminate the affected part of the subscription and receive a pro rata refund of fees paid for the unused part of the term.

We remain responsible to you for a sub-processor's performance of its obligations, and we impose data protection terms on each of them that are no less protective than those in this agreement.

7. Data subject requests

Learners belong to you. If a learner asks us directly to access, correct, delete or export their data, we will not action it. We will tell them to contact you, and we will tell you that they asked.

We will help you answer their request. The product gives you direct means to do so: you can view and correct an attendee record, remove an attendee, and export your full data set at any time. Where a request cannot be answered through the product, write to training@shogconsulting.com and we will help within a reasonable period, at no additional charge for a reasonable volume of requests.

8. Personal data breach

If we become aware of a personal data breach affecting personal data that we process for you, we will notify you without undue delay by email to the account contacts, and to any dedicated security contact you have given us. Keep those contacts current.

Our notification will describe, so far as we know at the time, the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. Where we cannot give all of that at once, we will give it in stages as the investigation progresses.

Notifying a supervisory authority, or the affected individuals, is your decision as controller, not ours. We will give you the information you reasonably need in order to make it and to make it on time. As noted in section 2, no binding onshore deadline for that notification is yet in force, while your own regulator, particularly in DIFC or ADGM, may impose one that is.

9. Deletion and return

You can export your full data set at any time during the subscription. The export covers attendees, enrolments, certificates, assessment results and the audit log.

When the subscription ends, you have 30 days to run that export. After the 30-day window, your organisation's data is securely deleted. We will delete earlier on your written instruction.

Two limits, stated honestly:

  • Where you connected your own storage, the files written there are yours and are held by you. Our deletion does not touch them and cannot touch them.
  • Backups are retained on their own cycle and are overwritten in the ordinary course. Data in a backup that has not yet aged out is not restored into the live service, and it goes when that backup expires.

We may retain data where we are legally required to, for example records needed for tax or accounting purposes, and we will keep only what that purpose needs.

10. Audit

We will give you, on reasonable written request and not more than once in any 12-month period, the information reasonably needed to demonstrate our compliance with this agreement, including a description of our security measures and answers to a reasonable security questionnaire.

We do not publish an independent audit report, because we do not hold one.

An on-site inspection of our systems, or a penetration test against the service, is not permitted by default. If your own regulator requires one, tell us. Any such arrangement, including scope, notice, cost and confidentiality, has to be agreed in writing in advance, and it will be recorded on your order form.

11. International transfers

The service is hosted on Oracle Cloud Infrastructure in the Middle East region, and your organisation's database and any files we hold sit there.

Some sub-processors process personal data outside the UAE. Stripe processes payment data in Ireland and the United States. Microsoft processes email delivery, and Google and Microsoft process sign-in and connected storage, in regions determined by those providers and by your own tenant configuration. Where you connect your own SharePoint, OneDrive or Google Drive, the location of the files written there is set by your tenant, not by us.

Where a transfer outside the UAE takes place, we rely on the transfer terms in our agreements with those sub-processors. The onshore UAE transfer framework will be completed by the Executive Regulations described in section 2. When those are issued, we will align this section with them.

12. General

This agreement applies for the term of your subscription and for as long as we process personal data for you. If any part of it conflicts with the general subscription terms on a data protection matter, this agreement prevails on that matter.

Send notices about this agreement to training@shogconsulting.com.

This document is published in English. Published by Shog Consulting (FZC), licence SC242038101. Questions go to training@shogconsulting.com.