Legal
Data Processing Addendum
Effective: May 1, 2026
This DPA supplements the Terms of Service for Customers subject to GDPR, UK GDPR, or similar data protection regimes.
1. Definitions
"Personal Data", "Data Subject", "Process", "Controller", "Processor" have the meanings given in GDPR Article 4.
iShipBiz is the Processor of Personal Data you (the Controller) upload to the Service.
2. Subject matter & duration
iShipBiz processes Personal Data to provide the Service for the duration of the subscription, plus a 30-day return window.
3. Nature & purpose of processing
Storage, transmission, and use as required to generate shipping labels, manage orders, and otherwise operate the Service.
4. Sub-processors
Current sub-processors: Stripe (payments), EasyPost (carriers), Resend (email), Supabase (hosting & database). The current list is maintained at /legal/subprocessors. We will give 30 days’ notice before adding new sub-processors.
5. Security
iShipBiz implements appropriate technical and organizational measures to protect Personal Data, including encryption in transit and at rest, access controls, audit logging, and personnel training.
6. International transfers
EU/EEA Personal Data may be transferred to the United States under Standard Contractual Clauses (Module 2: Controller to Processor) which are incorporated by reference.
7. Data subject requests
iShipBiz will assist Customer in responding to data subject requests where reasonable and consistent with our role as Processor.
8. Audit rights
Customer may request a copy of iShipBiz’s most recent SOC 2 report no more than once per year, subject to confidentiality terms.
9. Data return & deletion
Upon termination, iShipBiz will return or delete Personal Data within 30 days, except where retention is required by law.