Legal

Data Processing Addendum

Effective: May 1, 2026

This DPA supplements the Terms of Service for Customers subject to GDPR, UK GDPR, or similar data protection regimes.

1. Definitions

"Personal Data", "Data Subject", "Process", "Controller", "Processor" have the meanings given in GDPR Article 4.

iShipBiz is the Processor of Personal Data you (the Controller) upload to the Service.

2. Subject matter & duration

iShipBiz processes Personal Data to provide the Service for the duration of the subscription, plus a 30-day return window.

3. Nature & purpose of processing

Storage, transmission, and use as required to generate shipping labels, manage orders, and otherwise operate the Service.

4. Sub-processors

Current sub-processors: Stripe (payments), EasyPost (carriers), Resend (email), Supabase (hosting & database). The current list is maintained at /legal/subprocessors. We will give 30 days’ notice before adding new sub-processors.

5. Security

iShipBiz implements appropriate technical and organizational measures to protect Personal Data, including encryption in transit and at rest, access controls, audit logging, and personnel training.

6. International transfers

EU/EEA Personal Data may be transferred to the United States under Standard Contractual Clauses (Module 2: Controller to Processor) which are incorporated by reference.

7. Data subject requests

iShipBiz will assist Customer in responding to data subject requests where reasonable and consistent with our role as Processor.

8. Audit rights

Customer may request a copy of iShipBiz’s most recent SOC 2 report no more than once per year, subject to confidentiality terms.

9. Data return & deletion

Upon termination, iShipBiz will return or delete Personal Data within 30 days, except where retention is required by law.