Company · DPAGDPR + CCPA-aligned

Data Processing Addendum

PackGuru provides a GDPR and CCPA-aligned Data Processing Addendum as standard for enterprise customers. Delivered within 48 hours of a signed NDA

01 /What the DPA covers

Eight standard clauses

Roles — controller and processor

Defines the customer as data controller and PackGuru as data processor. Sub-processors separately listed

Scope of processing

Each category of personal data, the purpose, the lawful basis, and the retention period

Sub-processor list

30-day advance notice of any addition or replacement. Customer may object within the notice period

Data-subject rights

PackGuru assists the customer in responding to data-subject requests. Response time within 5 business days

International transfers

Standard Contractual Clauses (SCCs) for transfers from the EEA. EU data residency option available

Security obligations

Encryption at rest and in transit, access control, penetration testing, incident response time

Breach notification

PackGuru notifies the customer within 48 hours of becoming aware of a personal-data breach

Audit rights

Customer may request audit evidence (SOC 2, DAST results) annually. On termination, customer data returned or destroyed within 30 days

Request the DPA

We send the DPA, the SOC 2 report (under NDA) and the ISA architecture document together as one pack