Data Processing Agreement
1. Parties
This DPA forms part of the agreement between:
- the Customer as Controller
- Ship Sherpa Limited as Processor
ShipSherpa may act as independent Controller for fraud prevention, payment compliance, legal defence and platform integrity functions.
2. Processing Subject Matter
Processing includes:
- booking data
- recipient data
- POD data
- route and tracking data
- user credentials
- support records
- reporting outputs
- API response data
3. Instructions
ShipSherpa shall process personal data only on documented instructions unless required by law.
4. Security Measures
Measures include:
- encryption in transit and at rest
- role-based access
- audit logging
- environment separation
- credential rotation
- fraud monitoring
- secure cloud hosting
5. Subprocessors
Approved subprocessors may include:
- Google Cloud
- Stripe
- Twilio
- SendGrid
- analytics providers
- fraud and observability vendors
6. Data Subject Rights Support
ShipSherpa will provide reasonable assistance with data subject requests.
7. Personal Data Breaches
ShipSherpa will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer-controlled data.
8. Deletion and Return
On termination, Customer personal data will be deleted or returned unless retention is required by law or claims defence obligations.
9. International Transfers
Restricted transfers require UK lawful transfer safeguards.
10. Audit Rights
Reasonable audit support is available subject to confidentiality and security safeguards.