1. Roles and instructions
For personal data a merchant submits through Prepacity to manage orders and fulfilment, the merchant acts as controller and Prepacity acts as processor. Prepacity processes that data on documented instructions in the agreement, to provide and secure the service, and as required by law.
Each merchant is responsible for its notices, lawful basis, customer requests, and instructions. Prepacity will inform the merchant if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.
2. Processing details
- Subject matter: capacity calculation, scheduling, reservation, operational fulfilment, self-service, notifications, reporting, integration, support, and security.
- Duration: the subscription term plus the limited retention and deletion period set by the agreement, configuration, and law.
- People: merchant customers, recipients, contacts, account users, staff, and other people whose data the merchant submits.
- Data: order references, names, contact details, delivery addresses where needed, products, quantities, slots, instructions, status, consent, and related audit data.
- Purpose: provide, maintain, support, and secure the services selected by the merchant.
3. Prepacity commitments
- Require authorised personnel to protect the confidentiality of personal data.
- Maintain technical and organisational measures appropriate to the risk.
- Assist with verified data-subject requests, security obligations, and reasonable compliance information.
- Notify the merchant of a confirmed personal-data breach without undue delay, as required by the agreement and law.
- Delete or return personal data after services end, subject to lawful retention and backup cycles.
4. Service providers and transfers
Prepacity may use subprocessors for infrastructure, communications, monitoring, support, and related service functions. We require them to protect personal data through written terms appropriate to their role and remain responsible for their processing as required by the agreement.
Where processing involves an international transfer, Prepacity uses a lawful transfer mechanism and supplementary safeguards where appropriate. Current subprocessor and hosting information is available to customers through the contracting or security review process.
5. Requests, audits, and deletion
Prepacity provides tools and reasonable assistance for data export, tenant deletion, customer erasure, configurable retention, consent settings, and log retention. Requests from merchant customers are normally referred to the merchant as controller.
Subject to confidentiality, security, frequency, and cost safeguards in the agreement, Prepacity will provide information reasonably needed to demonstrate compliance and support an audit where other evidence is insufficient.
6. Contractual terms
This page is an operational summary, not the full data processing agreement. Customers that require contractual processor terms, transfer provisions, security schedules, or procurement materials can request them from privacy@prepacity.com.