Data Processing Agreement

1. Parties

This DPA forms part of the agreement between:

  • the Customer as Controller
  • Ship Sherpa Limited as Processor

ShipSherpa may act as independent Controller for fraud prevention, payment compliance, legal defence and platform integrity functions.

2. Processing Subject Matter

Processing includes:

  • booking data
  • recipient data
  • POD data
  • route and tracking data
  • user credentials
  • support records
  • reporting outputs
  • API response data

3. Instructions

ShipSherpa shall process personal data only on documented instructions unless required by law.

4. Security Measures

Measures include:

  • encryption in transit and at rest
  • role-based access
  • audit logging
  • environment separation
  • credential rotation
  • fraud monitoring
  • secure cloud hosting

5. Subprocessors

Approved subprocessors may include:

  • Google Cloud
  • Stripe
  • Twilio
  • SendGrid
  • analytics providers
  • fraud and observability vendors

6. Data Subject Rights Support

ShipSherpa will provide reasonable assistance with data subject requests.

7. Personal Data Breaches

ShipSherpa will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer-controlled data.

8. Deletion and Return

On termination, Customer personal data will be deleted or returned unless retention is required by law or claims defence obligations.

9. International Transfers

Restricted transfers require UK lawful transfer safeguards.

10. Audit Rights

Reasonable audit support is available subject to confidentiality and security safeguards.