Data Processing Agreement
Effective date: 10 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between PickPackTrack ("Processor") and the Merchant ("Controller"), and applies where the Processor processes personal data of the Controller's customers on the Controller's behalf.
1. Definitions
"UK GDPR", "personal data", "processing", "data subject", "controller", "processor", "sub-processor" and "personal data breach" have the meanings in UK data protection law. "Merchant Personal Data" means personal data of the Controller's customers that the Processor processes on the Controller's behalf.
2. Roles & scope
The Controller is the controller and the Processor is the processor of Merchant Personal Data. The Processor processes it only to provide the order fulfilment service and only on the Controller's documented instructions (including via the product's configuration), unless required by law.
3. Subject-matter of processing
- Nature/purpose: import orders from the Controller's sales channels; produce shipping labels and customs documents; transmit tracking to carriers/channels.
- Duration: the term of the Terms of Service.
- Data subjects: the Controller's customers (order recipients).
- Categories of data: name, shipping/billing address, email, phone, order contents, buyer notes. No special-category data is required or intended.
4. Processor obligations
The Processor shall: (1) process only on documented instructions; (2) ensure authorised persons are under confidentiality obligations; (3) implement the security measures in the Annex; (4) engage sub-processors only under clause 5; (5) assist the Controller to respond to data-subject requests; (6) assist with security, breach notification and DPIA obligations; (7) notify the Controller without undue delay (and within 72 hours) on becoming aware of a breach affecting Merchant Personal Data; (8) delete or return Merchant Personal Data at the end of the service (subject to legal retention); and (9) make available information needed to demonstrate compliance and allow audits.
5. Sub-processors
The Controller authorises the sub-processors used to deliver the service (hosting/infrastructure, connected carriers, and the sales channels the Controller connects). The Processor imposes equivalent data-protection terms on each, remains liable for their performance, and will give reasonable notice of changes with a right to object.
6. International transfers
Any transfer of Merchant Personal Data outside the UK/EEA is covered by an adequacy decision or appropriate safeguards (UK IDTA / Standard Contractual Clauses).
7. Audit
The Processor will make available its security documentation and (once obtained) third-party audit reports, and respond to reasonable audit requests, subject to confidentiality and frequency limits.
8. Deletion & retention
On termination, Merchant Personal Data is deleted or returned. The Processor operates automated retention/anonymisation — including Amazon PII purged within 30 days of shipment.
Annex — Technical & organisational measures
- Encryption in transit (TLS 1.2+) and at rest (database and backups); stored credentials/tokens encrypted.
- MFA; role-based access; strict multi-tenant isolation; strong password policy with breach screening.
- Encrypted, tested backups (on-site and off-site); documented disaster recovery.
- Audit logging of sensitive actions and access logging of personal-data reads.
- Data minimisation and automated PII anonymisation on defined schedules.