Data Processing Agreement (DPA)

Effective Date: January 2025 | Version: 2.0

Introduction

This Data Processing Agreement (“DPA”) forms part of the Service Agreement between AMZ Prep (“Data Processor,” “we,” “us,” or “our”) and the Customer (“Data Controller,” “you,” or “your”) for the provision of fulfillment services.

This DPA reflects the parties’ agreement on the processing of personal data in accordance with the requirements of applicable data protection laws, including:

  • General Data Protection Regulation (EU) 2016/679 (“GDPR”)
  • UK General Data Protection Regulation (“UK GDPR”)
  • California Consumer Privacy Act (“CCPA”)
  • Personal Information Protection and Electronic Documents Act (“PIPEDA”)

1. Definitions

“Personal Data” means any information relating to an identified or identifiable natural person as defined under applicable data protection laws.

“Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

“Data Subject” means the individual to whom Personal Data relates.

“Sub-processor” means any third party engaged by AMZ Prep to process Personal Data on behalf of the Customer.

“Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. Scope and Application

2.1 Relationship of the Parties

The Customer (Controller) appoints AMZ Prep (Processor) to process Personal Data on its behalf in connection with the fulfillment services provided under the Service Agreement.

2.2 Customer Obligations

The Customer warrants that:

  • It has all necessary rights to provide Personal Data to AMZ Prep
  • It has obtained all required consents from Data Subjects
  • Its instructions comply with applicable data protection laws

3. Processing of Personal Data

3.1 Categories of Data Subjects

  • Customer’s clients and end consumers
  • Customer’s employees and contractors
  • Customer’s business partners and vendors

3.2 Types of Personal Data Processed

  • Names and contact information
  • Shipping and delivery addresses
  • Order and transaction details
  • Customer service communications
  • Payment information (processed through PCI-compliant systems)

3.3 Nature and Purpose of Processing

AMZ Prep processes Personal Data solely for the purpose of:

  • Order fulfillment and shipping
  • Inventory management
  • Customer service support
  • Returns and refunds processing
  • Compliance with legal obligations

3.4 Duration of Processing

Personal Data will be processed for the duration of the Service Agreement and as required by applicable retention laws or legitimate business purposes.

4. Data Processor Obligations

4.1 Lawful Processing

Process Personal Data only on documented instructions from the Customer, unless required by applicable law.

4.2 Confidentiality

Ensure all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

4.3 Security Measures

Implement and maintain appropriate technical and organizational measures, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication systems
  • Regular security assessments and penetration testing
  • Physical security at all fulfillment centers
  • Incident response procedures
  • Business continuity and disaster recovery plans

4.4 Assistance with Data Subject Rights

Assist the Customer in responding to Data Subject requests regarding:

  • Access to Personal Data
  • Rectification or erasure
  • Data portability
  • Restriction of processing
  • Objection to processing

4.5 Data Protection Impact Assessments

Provide reasonable assistance for data protection impact assessments and prior consultations with supervisory authorities.

5. Sub-processing

5.1 Authorized Sub-processors

The Customer provides general authorization for AMZ Prep to engage Sub-processors, subject to:

  • Implementation of appropriate data protection agreements
  • Notification of new Sub-processors with opportunity to object
  • Maintaining a current list of Sub-processors

5.2 Current Sub-processors

A list of current Sub-processors is available upon request and includes:

Infrastructure & Cloud Services

  • Amazon Web Services (AWS) – Cloud hosting
  • Google Cloud Platform – Data storage and processing
  • Microsoft Azure – Backup and disaster recovery
  • Cloudflare – CDN and security services
  • Cherry Servers – Bare Metal Cloud services

Business Operations

  • HubSpot – CRM and marketing automation
  • Salesforce – Customer relationship management
  • DocuSign – Electronic signature processing
  • Adobe Sign – Document management
  • Slack – Internal communications
  • Microsoft 365 – Productivity suite

Payment & Financial Services

  • Stripe – Payment processing
  • PayPal – Payment gateway
  • Square – Point of sale systems
  • Authorize.net – Payment verification

Shipping & Logistics

  • FedEx – Shipping services
  • UPS – Package delivery
  • DHL – International shipping
  • USPS – Postal services
  • ShipStation – Shipping management

Analytics & Marketing

  • Google Analytics – Website analytics
  • Segment – Customer data platform
  • Mixpanel – Product analytics
  • Facebook/Meta – Advertising services
  • LinkedIn – B2B marketing
  • Marketo – Marketing automation

Customer Support

  • Zendesk – Help desk services
  • Intercom – Customer messaging
  • Freshdesk – Support ticketing
  • Typeform – Survey platform

Security & Monitoring

  • Datadog – Performance monitoring
  • Sentry – Error tracking
  • Auth0 – Identity management
  • Okta – Single sign-on services

A complete and current list of all Sub-processors, including their locations and services provided, is maintained and available to Customers upon request.

5.3 Sub-processor Requirements

AMZ Prep ensures each Sub-processor:

  • Provides sufficient guarantees of compliance
  • Is bound by data protection obligations no less protective than this DPA
  • Processes Personal Data only per our instructions

6. International Data Transfers

6.1 Transfer Mechanisms

For transfers of Personal Data outside the EEA/UK, AMZ Prep relies on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreement (IDTA)
  • Adequacy decisions where applicable

6.2 Processing Locations

Personal Data may be processed at our facilities in:

  • United States: 238 Bay Ridge Pkwy, Brooklyn, NY 11209
  • United Kingdom: UNIT 3, Mountpark, 5 Wide Ln, Southampton SO18 2FA
  • Canada: 9 Van Der Graaf Ct 1st fl UNIT 1, Brampton, ON L6T 5E5

7. Data Security Incidents

7.1 Notification

AMZ Prep will notify the Customer without undue delay upon becoming aware of a Data Breach affecting Customer Personal Data.

7.2 Incident Response

We will:

  • Investigate the incident and implement remedial measures
  • Provide information necessary for Customer’s regulatory notifications
  • Cooperate with Customer’s reasonable requests regarding the incident
  • Document all breaches and actions taken

7.3 Communication

Breach notifications will be sent to: [Customer’s designated security contact] with a copy to: [Customer’s primary contact]

8. Audit Rights

8.1 Information and Audit

The Customer may:

  • Request information to demonstrate compliance with this DPA
  • Conduct audits (including inspections) no more than once per year
  • Engage an independent third-party auditor bound by confidentiality

8.2 Audit Process

  • 30 days’ advance written notice required
  • Conducted during business hours with minimal disruption
  • Costs borne by Customer unless material non-compliance found
  • AMZ Prep may provide recent third-party audit reports in lieu of on-site audit

9. Data Return and Deletion

9.1 End of Service

Upon termination of services, AMZ Prep will:

  • Return all Personal Data in a standard format
  • Delete Personal Data from all systems within 90 days
  • Provide written certification of deletion
  • Retain data only as required by law with appropriate protections

9.2 Ongoing Deletion

During the term, Personal Data is deleted according to:

  • Customer instructions
  • Agreed retention schedules
  • Legal requirements

10. Liability and Indemnification

10.1 Liability Cap

Liability under this DPA is subject to the limitations in the Service Agreement.

10.2 Indemnification

Each party shall indemnify the other against losses resulting from its breach of data protection laws or this DPA.

11. Term and Termination

11.1 Duration

This DPA remains in effect for the duration of the Service Agreement.

11.2 Survival

Obligations regarding confidentiality, security, and data deletion survive termination.

12. Governing Law and Jurisdiction

12.1 Governing Law

This DPA is governed by the laws specified in the Service Agreement.

12.2 Dispute Resolution

Disputes shall be resolved according to the dispute resolution provisions in the Service Agreement.

13. Order of Precedence

In case of conflict:

  1. Applicable data protection laws
  2. This DPA
  3. Service Agreement
  4. Other agreements between the parties

14. Amendments

This DPA may only be amended by written agreement of both parties, except for:

  • Updates to Sub-processor lists
  • Changes required by law
  • Updates to contact information

15. Entire Agreement

This DPA, together with the Service Agreement, constitutes the entire agreement regarding the processing of Personal Data.

Contact Information

AMZ Prep Data Protection Contact:

Email: info@amzprep.com

Subject Line: DPA Inquiry – [Company Name]

Mailing Address:

AMZ Prep Legal Department
238 Bay Ridge Pkwy
Brooklyn, NY 11209
United States

For EU/UK Specific Matters:

UK Office:
AMZ Prep
UNIT 3, Mountpark
5 Wide Ln
Southampton SO18 2FA
United Kingdom

Appendix A: Technical and Organizational Measures

Physical Security

  • 24/7 monitored access control systems
  • CCTV surveillance at all facilities
  • Visitor management protocols
  • Secure areas for data processing

Technical Security

  • End-to-end encryption for data transmission
  • Firewalls and intrusion detection systems
  • Regular vulnerability assessments
  • Multi-factor authentication
  • Role-based access controls
  • Automated backup systems

Organizational Measures

  • Information security policies and procedures
  • Regular employee training on data protection
  • Confidentiality agreements with all staff
  • Incident response team and procedures
  • Business continuity planning
  • Regular security audits and certifications

Appendix B: Standard Contractual Clauses

The EU Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference and available upon request.

For execution of this DPA or questions regarding data processing, please contact us at info@amzprep.com