Data Processing Addendum
PackGuru provides a GDPR and CCPA-aligned Data Processing Addendum as standard for enterprise customers. Delivered within 48 hours of a signed NDA
Eight standard clauses
Roles — controller and processor
Defines the customer as data controller and PackGuru as data processor. Sub-processors separately listed
Scope of processing
Each category of personal data, the purpose, the lawful basis, and the retention period
Sub-processor list
30-day advance notice of any addition or replacement. Customer may object within the notice period
Data-subject rights
PackGuru assists the customer in responding to data-subject requests. Response time within 5 business days
International transfers
Standard Contractual Clauses (SCCs) for transfers from the EEA. EU data residency option available
Security obligations
Encryption at rest and in transit, access control, penetration testing, incident response time
Breach notification
PackGuru notifies the customer within 48 hours of becoming aware of a personal-data breach
Audit rights
Customer may request audit evidence (SOC 2, DAST results) annually. On termination, customer data returned or destroyed within 30 days
Request the DPA
We send the DPA, the SOC 2 report (under NDA) and the ISA architecture document together as one pack