PickPackTrack

Data Processing Agreement

Effective date: 10 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between PickPackTrack ("Processor") and the Merchant ("Controller"), and applies where the Processor processes personal data of the Controller's customers on the Controller's behalf.

1. Definitions

"UK GDPR", "personal data", "processing", "data subject", "controller", "processor", "sub-processor" and "personal data breach" have the meanings in UK data protection law. "Merchant Personal Data" means personal data of the Controller's customers that the Processor processes on the Controller's behalf.

2. Roles & scope

The Controller is the controller and the Processor is the processor of Merchant Personal Data. The Processor processes it only to provide the order fulfilment service and only on the Controller's documented instructions (including via the product's configuration), unless required by law.

3. Subject-matter of processing

4. Processor obligations

The Processor shall: (1) process only on documented instructions; (2) ensure authorised persons are under confidentiality obligations; (3) implement the security measures in the Annex; (4) engage sub-processors only under clause 5; (5) assist the Controller to respond to data-subject requests; (6) assist with security, breach notification and DPIA obligations; (7) notify the Controller without undue delay (and within 72 hours) on becoming aware of a breach affecting Merchant Personal Data; (8) delete or return Merchant Personal Data at the end of the service (subject to legal retention); and (9) make available information needed to demonstrate compliance and allow audits.

5. Sub-processors

The Controller authorises the sub-processors used to deliver the service (hosting/infrastructure, connected carriers, and the sales channels the Controller connects). The Processor imposes equivalent data-protection terms on each, remains liable for their performance, and will give reasonable notice of changes with a right to object.

6. International transfers

Any transfer of Merchant Personal Data outside the UK/EEA is covered by an adequacy decision or appropriate safeguards (UK IDTA / Standard Contractual Clauses).

7. Audit

The Processor will make available its security documentation and (once obtained) third-party audit reports, and respond to reasonable audit requests, subject to confidentiality and frequency limits.

8. Deletion & retention

On termination, Merchant Personal Data is deleted or returned. The Processor operates automated retention/anonymisation — including Amazon PII purged within 30 days of shipment.

Annex — Technical & organisational measures