Data Processing Agreement
This Data Processing Agreement, including its Annexes, is the “DPA”. It forms part of the Agreement between the customer receiving the Services, as controller, and the applicable Quivo Contracting Entity providing the Services, as processor.
This DPA becomes binding when the Customer enters into an Agreement with a Quivo Contracting Entity that incorporates this DPA by reference or otherwise expressly makes it part of the Agreement, including through electronic acceptance. No separate signature of this DPA is required unless the parties expressly agree otherwise.
1. Definitions and Interpretation
1.1 “Applicable Data Protection Law” means the GDPR and any national law implementing or supplementing it that applies to the Processing, together with any other mandatory data protection law expressly applicable under the Agreement.
1.2 “Customer” means the person or entity identified as the customer in the Agreement. The Customer acts as Controller for Customer Personal Data.
1.3 “Customer Personal Data” means Personal Data Processed by Quivo on behalf of the Customer in connection with the Services. It does not include Personal Data that Quivo Processes as an independent Controller.
1.4 “GDPR” means Regulation (EU) 2016/679.
1.5 “Agreement” means the applicable signed contract, Quivo Terms and Conditions, order, statement of work, master services agreement or other terms governing the Services, whether signed or accepted electronically.
1.6 “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in Applicable Data Protection Law.
1.7 “Quivo” or “Processor” means the Quivo Contracting Entity identified as the service provider in the Agreement.
1.8 “Quivo Contracting Entity” means the Quivo group company identified as the service provider in the applicable Agreement. The legal entity details are set out in Annex 1.
1.9 “Services” means the fulfillment, warehousing, order, inventory, shipment, returns, platform, software, integration, support and related services ordered by the Customer under the Agreement.
1.10 “Subprocessor” means a third party engaged by Quivo to Process Customer Personal Data on behalf of the Customer.
1.11 If there is a conflict concerning the Processing of Customer Personal Data, this DPA prevails over the Agreement. The Agreement continues to govern all commercial matters. Any applicable transfer clauses prevail over this DPA to the extent of a conflict concerning an international transfer.
2. Scope and Formation
2.1 This DPA applies where and to the extent Quivo Processes Customer Personal Data as a Processor in connection with the Services.
2.2 The subject matter, nature, purposes and duration of the Processing, the categories of Customer Personal Data and the categories of Data Subjects are described in Annex 2 and, where applicable, the Agreement.
2.3 Quivo may update Annex 2 to reflect Services ordered, enabled or configured by the Customer and nonmaterial operational changes. An update shall not materially expand the purposes of Processing, introduce materially different categories of Customer Personal Data or Data Subjects, or authorize the Processing of special categories of Personal Data without the Customer’s documented instruction or another valid contractual amendment. Quivo shall provide advance notice of material changes.
2.4 This DPA does not apply to Personal Data that Quivo Processes as an independent Controller, including Personal Data Processed for contract administration, billing, accounting, fraud prevention, corporate security, legal compliance, business contact management, service improvement using aggregated or anonymized data, or the establishment, exercise or defense of legal claims. Such Processing is governed by Quivo’s applicable privacy notice and Applicable Data Protection Law.
3. Processing Instructions
3.1 Quivo shall Process Customer Personal Data only on documented instructions from the Customer, including the Agreement, this DPA, the Customer’s configurations and instructions submitted through the Services, and other written or electronic instructions accepted by Quivo.
3.2 The Customer may issue instructions through the Services or in written or electronic form. Instructions must be consistent with the Agreement and technically feasible. Instructions outside the agreed Services may be treated as a request for additional services and may be subject to reasonable fees.
3.3 Quivo shall inform the Customer without undue delay if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. Quivo may suspend the instruction until it is confirmed or amended and may refuse an obviously unlawful instruction.
3.4 Where applicable law requires Quivo to Process Customer Personal Data beyond the Customer’s instructions, Quivo shall inform the Customer before the Processing unless the law prohibits such notice.
3.5 Quivo may determine the technical and organizational means necessary to provide, secure, support and maintain the Services, provided that Quivo does not independently determine the purposes of Processing Customer Personal Data.
4. Customer Responsibilities
4.1 The Customer is responsible for:
(a) establishing and maintaining a lawful basis for the Processing and any transfer of Customer Personal Data;
(b) providing required notices and obtaining required consents or authorizations;
(c) ensuring that its instructions comply with Applicable Data Protection Law;
(d) ensuring that Customer Personal Data submitted to the Services is accurate, relevant and limited to what is necessary;
(e) configuring and using the Services securely and lawfully; and
(f) responding to Data Subject requests, with Quivo’s assistance as required under this DPA.
4.2 The Services are not designed for special categories of Personal Data under Article 9 GDPR or data relating to criminal convictions and offenses under Article 10 GDPR unless expressly agreed in writing and documented in Annex 2 or an applicable Agreement.
4.3 The Customer shall not submit sensitive or regulated information that is not required for the Services or expressly supported by the applicable service configuration.
5. Confidentiality
5.1 Quivo shall ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate data protection and security training.
5.2 Quivo shall restrict access to Customer Personal Data to personnel and authorized service providers who require access to perform, secure, support or maintain the Services.
5.3 Confidentiality obligations continue after the relevant person’s access or engagement ends.
6. Security
6.1 Quivo shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
6.2 The measures are described in Annex 3, which the Customer acknowledges as adequate. Quivo may update those measures to reflect technical developments, changes to the Services and evolving risks, provided that the overall level of protection is not materially reduced. Quivo shall inform the Customer of any significant change to the security measures, by publishing an updated Annex 3 with a new version date and, where the change is material, by notice to the Customer.
6.3 Quivo may implement security measures directly or through authorized hosting, infrastructure and other service providers, including under applicable shared responsibility models.
6.4 The Customer acknowledges that security is a shared responsibility and shall implement the Customer-side controls available through the Services, including appropriate identity, access, credential, device, configuration and integration controls.
7. Personal Data Breaches and Material Security Incidents
7.1 Quivo shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 The notification shall include, to the extent available at the time:
(a) a description of the incident and its nature;
(b) the categories and approximate volume of affected Personal Data and Data Subjects, where known;
(c) the likely consequences, where known;
(d) the measures taken or proposed to contain, investigate, remediate and prevent recurrence; and
(e) relevant contact details for follow-up.
7.3 Quivo may provide information in phases as further information becomes available. A notification does not constitute an admission of fault, liability or legal responsibility.
7.4 Quivo shall take reasonable measures to contain and remediate the Personal Data Breach and shall reasonably assist the Customer with legally required notifications and communications, taking into account the nature of the Processing and the information available to Quivo.
7.5 Quivo shall notify the Customer without undue delay of a confirmed security incident that materially and adversely affects the confidentiality, integrity or availability of Customer Personal Data or the Services used to Process it, where notification is reasonably necessary for the Customer to mitigate material harm or comply with applicable law. This obligation does not require notification of unsuccessful attacks, blocked events, vulnerabilities without exploitation, or minor or transient service disruptions.
8. Data Subject Rights and Regulatory Assistance
8.1 Taking into account the nature of the Processing, Quivo shall assist the Customer through appropriate technical and organizational measures, where reasonably possible, in responding to requests under Articles 12 to 22 GDPR.
8.2 If Quivo receives a request directly from a Data Subject relating to Customer Personal Data, Quivo shall, where it can reasonably identify the Customer, notify or refer the requester to the Customer and shall not respond substantively unless instructed by the Customer or required by law.
8.3 Quivo shall reasonably assist the Customer with obligations under Articles 32 to 36 GDPR, including security assessments, Personal Data Breach assessments, data protection impact assessments and prior consultations, taking into account the nature of the Processing and the information available to Quivo.
8.4 Ordinary assistance required under Article 28 GDPR is included in the Services. Quivo may charge reasonable fees for exceptional, repetitive or disproportionate assistance outside the ordinary operation of the Services, unless the assistance is required because of Quivo’s breach of this DPA or Applicable Data Protection Law.
9. Subprocessors
9.1 The Customer gives Quivo general written authorization to engage Subprocessors to provide, maintain, secure and support the Services, and to improve the technical performance and resilience of the Services, solely within the documented purposes of Processing.
9.2 The Subprocessors authorized as of the effective date of this DPA are listed in Annex 4. Quivo shall maintain the list in an up-to-date form and make the current version publicly or otherwise readily accessible to Customers.
9.3 Quivo shall provide advance notice of a material addition or replacement of a Subprocessor. The Customer may object within fourteen days on reasonable and documented data protection grounds.
9.4 If the Customer objects, the Parties shall work in good faith to resolve the objection. Quivo may make available a commercially reasonable alternative where technically feasible. If no resolution is possible and the Subprocessor is necessary for the affected Services, either Party may terminate only the affected Services in accordance with the Agreement.
9.5 Quivo shall impose data protection obligations on each Subprocessor that are no less protective than the relevant obligations in this DPA, to the extent applicable to the Subprocessor’s Processing.
9.6 Quivo remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.
9.7 Carriers, postal operators, customs authorities and similar recipients may act as independent Controllers where they determine their own purposes and essential means of Processing under applicable law or their own service terms. Such recipients are not Subprocessors for that independent Processing.
10. International Transfers
10.1 Quivo shall not transfer Customer Personal Data outside the European Economic Area unless the transfer is permitted under Applicable Data Protection Law.
10.2 Where required, Quivo shall rely on an adequacy decision, the applicable Standard Contractual Clauses adopted by the European Commission, binding corporate rules or another legally recognized transfer mechanism.
10.3 The Parties shall cooperate reasonably with transfer assessments and supplementary safeguards where required by Applicable Data Protection Law.
10.4 Where the EU Standard Contractual Clauses are required for a transfer from the Customer to Quivo, Module Two, Controller to Processor, shall apply unless another module is appropriate. The applicable annexes to those clauses shall be completed using the information in this DPA, the Agreement and the Subprocessor List.
10.5 United Kingdom, Switzerland, Saudi Arabia and other jurisdiction-specific transfer terms shall apply only where required by the applicable Processing or transfer and may be documented in a separate addendum or Agreement.
11. Audits and Compliance Information
11.1 Quivo shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.
11.2 The Customer shall first use available evidence such as security documentation, policies, questionnaires, independent assessment reports, penetration test summaries, certifications and the technical and organizational measures in Annex 3.
11.3 If the information made available under Clauses 11.1 and 11.2 is reasonably insufficient to demonstrate compliance, the Customer may request a remote documentation review.
11.4 An onsite inspection may be conducted only where reasonably necessary and where the relevant objective cannot reasonably be achieved through less intrusive means, including following a Personal Data Breach, where there is credible evidence of material noncompliance, or where required by a Supervisory Authority.
11.5 Quivo may require reasonable advance notice, limit audits to once in any twelve-month period unless a mandatory legal requirement or material incident reasonably justifies an additional review, and impose reasonable confidentiality, security, access, scope and operational safeguards.
11.6 The Customer shall ensure that any auditor is independent, appropriately qualified, bound by confidentiality obligations and not a direct competitor of Quivo.
11.7 Quivo is not required to disclose another customer’s data, privileged material, unrelated confidential information, source code, trade secrets, internal financial records or information whose disclosure would compromise security.
11.8 The Customer shall bear its audit costs and Quivo’s reasonable costs of extraordinary assistance, unless the audit identifies material noncompliance by Quivo. Nothing in this Clause limits a mandatory audit or inspection right under Applicable Data Protection Law or the powers of a Supervisory Authority.
12. Return, Retention and Deletion
12.1 During the term, the Customer may retrieve or export Customer Personal Data using available functionality or agreed support procedures.
12.2 Upon termination or expiry of the affected Services, Quivo shall, at the Customer’s choice and subject to available functionality, return or delete Customer Personal Data without undue delay, unless retention is required by applicable law or reasonably necessary for the establishment, exercise or defense of legal claims.
12.3 Following termination or expiry of the affected Services and completion of any agreed return or transition period, Quivo shall delete Customer Personal Data from active production systems without undue delay in accordance with its documented deletion procedures, unless continued retention is required by applicable law.
12.4 Customer Personal Data may remain in protected backup and disaster recovery copies until overwritten or expired under Quivo’s standard backup retention cycle. Such copies shall not be used for ordinary business Processing and shall be accessed or restored only where necessary for disaster recovery, business continuity, security or legal compliance. If backup data is restored, applicable deletion, return or restriction instructions shall be reapplied without undue delay.
12.5 Security logs, audit logs, deletion records and evidence required for compliance or legal claims may be retained for their applicable retention periods, provided that Personal Data is limited to what is necessary for those purposes.
12.6 Quivo shall provide reasonable confirmation of deletion upon request.
13. Liability
13.1 Each Party remains responsible for its own obligations under Applicable Data Protection Law.
13.2 Nothing in this DPA limits or excludes liability to the extent that limitation or exclusion is prohibited by Applicable Data Protection Law, including mandatory Data Subject compensation rights.
13.3 Subject to Clause 13.2, the limitations and exclusions of liability in the Agreement apply to this DPA.
14. Term, Termination and Suspension
14.1 This DPA starts when it becomes binding under the Agreement and remains in effect for as long as Quivo Processes Customer Personal Data on behalf of the Customer.
14.2 If Quivo materially breaches this DPA and fails to remedy the breach within a reasonable period after written notice, the Customer may exercise the remedies available under the Agreement and Applicable Data Protection Law.
14.3 Quivo may suspend Processing or the affected Services where reasonably necessary to prevent unlawful Processing, protect Customer Personal Data or comply with law, after providing notice where legally and operationally possible.
15. Changes to This DPA
15.1 Quivo may update this DPA to reflect changes in law, regulatory guidance, the Services or Quivo’s Processing practices.
15.2 Changes required by mandatory law may take effect when legally necessary. Administrative corrections, clarifications and changes that do not materially affect the Parties’ rights or obligations may take effect upon publication or notice with an updated version date.
15.3 Other material changes shall become effective in accordance with the change mechanism in the Agreement or, if the Agreement does not provide one, upon the Customer’s express or electronically documented acceptance. No change shall materially reduce the Customer’s protection or materially expand the purposes of Processing without a legally valid contractual basis.
15.4 Changes to Subprocessors and security measures are governed by Clauses 9 and 6, respectively.
15.5 Quivo shall retain or make available prior versions for reasonable evidence and contract administration purposes.
16. Final Provisions
16.1 This DPA is governed by the law of the jurisdiction in which the applicable Quivo Contracting Entity has its registered office, excluding its conflict-of-law rules. For LOGSTA UK LTD, the laws of England and Wales apply. For LOGSTA LLC, the laws of Pennsylvania apply. This is without prejudice to mandatory Applicable Data Protection Law or any mandatory governing law specified in applicable transfer clauses.
16.2 If any provision is invalid or unenforceable, the remaining provisions remain effective. The invalid provision shall be replaced, to the extent permitted, with a valid provision that most closely reflects its purpose.
16.3 Notices under this DPA may be provided electronically to the contacts specified in the Agreement, through the Services or by another documented communication channel agreed by the Parties.
16.4 Privacy contact: privacy@quivo.co. External Data Protection Officer for all Quivo Contracting Entities: heyData GmbH, Schützenstr. 5, 10117 Berlin, Germany, datenschutz@heydata.eu.
Annex 1
Quivo Contracting Entities
The applicable Processor is the Quivo Contracting Entity that provides the Services under the Agreement. This DPA applies to each of the following Quivo entities when it is the service provider under the Agreement:
- LOGSTA GmbH, Wiedner Gürtel 13/T24/2.OG, 1100 Vienna, Austria.
- ANCLA Logistik GmbH, Dillfeld 22, 35576 Wetzlar, Germany.
- LOGSTA Germany GmbH, Dillfeld 22, 35576 Wetzlar, Germany.
- LOGSTA SAS, 1 rue de Stockholm, 75008 Paris, France.
- LOGSTA UK LTD, Unit 5 Priors Industrial Estate, Priors Way, Maidenhead, United Kingdom, SL6 2HP.
LOGSTA LLC, 1648 Roseytown Road, Suite 400, Greensburg, PA 15601, United States.
Annex 2
Description of Processing
1. Subject matter
Processing of Customer Personal Data as necessary to provide the Services ordered under the Agreement, including applicable fulfillment, warehousing, software, platform, integration, support, monitoring and security services.
2. Duration
For the duration of the affected Services and any limited post-termination period required for return, deletion, backup expiry, security, compliance or legal retention.
3. Nature and Processing activities
Depending on the Services purchased and configured by the Customer:
(a) receiving and importing orders and related data;
(b) storing, organizing, retrieving, transmitting and updating data;
(c) warehouse allocation, inventory management and stock processing;
(d) picking, packing, labeling and fulfillment operations;
(e) shipment preparation, carrier selection, tracking and status processing;
(f) disclosure of necessary shipment information to carriers and logistics partners;
(g) returns processing;
(h) account, user, role and permission management;
(i) customer-configured integrations and API transfers;
(j) hosting, operation, maintenance, support and troubleshooting;
(k) logging, monitoring, fraud prevention and security operations; and
(l) deletion, restriction, export and recovery operations.
4. Purposes
(a) providing the Services under the Agreement;
(b) performing order, inventory, warehouse, fulfillment, shipment and returns operations;
(c) providing, operating, maintaining, supporting and securing Quivo platforms and software;
(d) enabling Customer-configured integrations with carriers, sales channels, marketplaces and downstream systems;
(e) providing reporting, auditability, service continuity, troubleshooting and security monitoring; and
(f) complying with documented Customer instructions and applicable legal obligations binding on Quivo.
5. Categories of Data Subjects
(a) Customer employees, administrators and authorized users;
(b) purchasers, consumers and the Customer’s customers;
(c) shippers, merchants, consignors, consignees and delivery recipients;
(d) return senders and collection contacts;
(e) carrier, transport partner, vendor and operational contacts;
(f) customer service and support contacts; and
(g) other individuals identified in orders, shipments, returns, integrations or Customer instructions.
6. Categories of Customer Personal Data
(a) identification and contact details, including name, postal address, email address and telephone number;
(b) customer, account, merchant, order, shipment, inventory and returns identifiers;
(c) order, product, quantity, warehouse, fulfillment and shipping information;
(d) pickup and delivery details, delivery instructions, tracking events and timestamps;
(e) carrier, transport, customs and export information where required for the Services;
(f) user account, role, permission and authentication-event information;
(g) operational communications and support interactions;
(h) application, access, audit, authentication, IP address, device, integration and security logs; and
(i) other Personal Data documented in the Agreement or Customer configuration.
7. Sensitive and special-category data
The Services are not intended for special categories of Personal Data or criminal-offense data unless expressly agreed in writing. Identity, customs, tax, age-verification or similarly regulated information may be Processed only where required for a supported service and documented in the applicable Agreement or service description.
8. Principal Processing locations
Production workloads are primarily hosted in Amazon Web Services in the European Union, currently primarily in the eu-west-1 region in Ireland. Processing may also occur at applicable Quivo operational locations, authorized Subprocessor locations and locations required for instructed carrier, customs or logistics operations.
9. Retention criteria
Customer Personal Data is retained for the duration of the Services and for the limited periods described in Clause 12, the Agreement, applicable Customer instructions and legally required retention schedules.
Annex 3
Technical and Organizational Measures
The measures below apply to Customer Personal Data and the systems used to provide the Services. Quivo may implement the measures directly or through authorized hosting, infrastructure and other service providers. Quivo maintains an information security governance framework that operationally covers the systems, services, shared functions, suppliers and relevant group entities used to provide the Services. References to NIS2-aligned controls do not mean that every Quivo Contracting Entity is independently subject to NIS2 registration or reporting obligations. Measures are maintained, reviewed and updated based on risk, technical feasibility, applicable law and the nature of the Services.
1. Security governance
(a) documented information security and privacy policies;
(b) assigned security, privacy, system and risk responsibilities;
(c) periodic security and privacy awareness training;
(d) risk assessment, vulnerability management and incident response processes;
(e) periodic review of controls and material changes; and
(f) supplier and Subprocessor security governance, including periodic assurance appropriate to risk.
2. Physical security
(a) production workloads are primarily hosted in professional cloud data centers with controlled facility access, surveillance, security personnel and environmental monitoring under the provider’s shared responsibility model;
(b) Quivo offices and operational facilities use access controls appropriate to their risk and function; and
(c) visitors are subject to appropriate access restrictions and supervision.
3. Identity and access management
(a) unique user identification for administrative and privileged access;
(b) multi-factor authentication for privileged, administrative, remote-access and other high-risk accounts, except where technically unavailable and subject to documented compensating controls;
(c) role-based access control and least privilege;
(d) application-level roles and permissions for customer data;
(e) joiner, mover and leaver procedures;
(f) periodic review of administrative and production access;
(g) controlled remote administration through approved channels; and
(h) logging of relevant administrative and authentication events.
4. Encryption and transfer controls
(a) encryption in transit using industry-standard secure protocols;
(b) encryption at rest for production Customer Personal Data using appropriate technical controls, subject only to documented technical exceptions supported by proportionate compensating safeguards;
(c) controlled key and secret management with restricted access;
(d) authenticated and authorized mechanisms for exports and integrations;
(e) restrictions on onward transfers and Processing; and
(f) secure disposal or erasure of media and data when no longer required.
5. Segregation and environment controls
(a) logical customer and tenant separation at application and data layers where applicable;
(b) separation of production and non-production environments;
(c) access restrictions for development and test environments;
(d) controls designed to avoid the unauthorized use of production Personal Data in testing; and
(e) network segmentation and cloud security controls appropriate to the architecture.
6. Logging, monitoring and input control
(a) logging of key administrative, authentication, access and security events;
(b) central collection and monitoring of relevant security logs;
(c) alerting for suspicious or anomalous activity where appropriate;
(d) traceability of material data changes where supported by the relevant system;
(e) monitoring of cloud, application and network security events; and
(f) protection of logs against unauthorized access and alteration.
7. Vulnerability, patch and secure development controls
(a) vulnerability scanning and remediation processes;
(b) dependency and software security monitoring;
(c) secure code review and automated security testing appropriate to the application;
(d) controlled deployment and change-management processes;
(e) patch management for applicable systems and workloads; and
(f) periodic penetration testing or equivalent security assessment based on risk.
8. Availability, backup and resilience
(a) regular backups appropriate to the relevant service and data store;
(b) backup protection and access restrictions;
(c) restoration and recovery procedures;
(d) monitoring and alerting for critical systems;
(e) business continuity and disaster recovery controls proportionate to the Services; and
(f) use of resilient cloud architecture and managed service capabilities where appropriate.
9. Incident response
(a) documented incident identification, escalation, containment, investigation and remediation procedures;
(b) defined privacy and security notification processes;
(c) preservation of relevant evidence and audit information;
(d) involvement of appropriate security, privacy, legal and management personnel; and
(e) post-incident review and corrective actions where appropriate.
10. Personnel and organizational controls
(a) confidentiality obligations for personnel with access to Customer Personal Data;
(b) security and privacy training appropriate to role;
(c) access approval and removal processes;
(d) acceptable-use and device-security requirements; and
(e) disciplinary and escalation procedures for material policy violations.
11. Data minimization and deletion
(a) collection and Processing limited to data required for the Services and Customer instructions;
(b) configurable or operational retention and deletion procedures where available;
(c) controlled deletion from active systems and expiry from backup cycles;
(d) limitation of retained logs and evidence to legitimate security, audit, compliance and legal purposes; and
(e) use of anonymization or aggregation where appropriate for non-customer-specific analytics and service improvement.
Annex 4
Current Subprocessors
The following Subprocessors are authorized to Process Customer Personal Data for the purposes described below. The current version of this list forms part of this DPA.
| Subprocessor | Purpose | Primary processing location |
| Quivo group companies listed in Annex 1 | Parts of the Services performed for the Quivo Contracting Entity, in particular operation of the Quivo platform by LOGSTA GmbH, under intra-group data processing agreements. | European Union and United Kingdom; United States for LOGSTA LLC, with transfers made under the EU Standard Contractual Clauses. |
| Amazon Web Services EMEA Sàrl | Cloud infrastructure, managed databases, storage, serverless computing, security, logging, and related hosting services. | European Union, primarily Ireland. |
| Google Ireland Limited | Identity and single sign-on services, where enabled. | European Union; other locations permitted under applicable Google contractual terms. |
| Zendesk, Inc. | Customer support ticketing and related correspondence, where support requests and their attachments contain Customer Personal Data. | European Union, Ireland. |
| AfterShip Limited | Shipment tracking and delivery status information for consignments dispatched under the Services. | United States. Transfers made under the EU Standard Contractual Clauses. |
Version: 2.0 (22 September 2026)