Data Processing Addendum
Last updated: May 29, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the merchant identified in the order form or account signup ("Customer", "Controller") and PrintReactor, LLC ("PrintReactor", "Processor") for the provision of the Services (the "Agreement"). This DPA applies to the extent PrintReactor processes Personal Data on behalf of Customer in connection with the Services. If there is a conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Personal Data.
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement or in applicable Data Protection Laws.
- Applicable Data Protection Laws means all laws applicable to the processing of Personal Data under the Agreement, including the EU and UK GDPR, the Swiss FADP, US state privacy laws (including the CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, and comparable laws), Canada's PIPEDA and Quebec Law 25, Brazil's LGPD, and the Australian Privacy Act.
- Personal Data means any information relating to an identified or identifiable natural person that is processed by PrintReactor on behalf of Customer under the Agreement.
- Data Subject means the individual to whom Personal Data relates.
- Sub-processor means any third party engaged by PrintReactor to process Personal Data.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data.
- Standard Contractual Clauses or SCCs means (a) for EEA transfers, the clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and (b) for UK transfers, the UK International Data Transfer Addendum issued by the UK ICO, and (c) for Swiss transfers, the SCCs as modified for use under the FADP.
2. Roles and scope
Customer is the controller (or, under US laws, the "business") of Personal Data and PrintReactor is the processor (or "service provider" / "contractor"). The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.
3. Processing instructions
PrintReactor will process Personal Data only (a) to provide the Services in accordance with the Agreement and Customer's documented instructions (including those issued through configuration of the Services), and (b) as required by applicable law (in which case PrintReactor will notify Customer unless legally prohibited). PrintReactor will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.
4. Confidentiality and personnel
PrintReactor ensures that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and are trained on the handling of Personal Data.
5. Security
PrintReactor will implement and maintain the technical and organizational measures set out in Annex 2 to protect Personal Data against Security Incidents. PrintReactor may update these measures from time to time provided the overall level of protection is not reduced.
6. Security Incidents
PrintReactor will notify Customer without undue delay, and no later than 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include the information reasonably available at that time, including the nature of the incident, likely categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed. PrintReactor will reasonably assist Customer with its own notification obligations.
7. Sub-processors
Customer grants PrintReactor a general authorization to engage Sub-processors to process Personal Data, subject to the following:
- PrintReactor maintains a current list of Sub-processors at /subprocessors;
- PrintReactor will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA;
- PrintReactor will give Customer at least 30 days' prior notice of the addition or replacement of a Sub-processor (for example via a subscription to the Sub-processor list). Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Services and receive a pro-rata refund of prepaid fees;
- PrintReactor remains liable to Customer for the acts and omissions of its Sub-processors to the same extent as its own.
8. Data Subject requests
Taking into account the nature of the processing, PrintReactor will provide reasonable assistance to Customer, by appropriate technical and organizational measures, to respond to Data Subject requests (access, rectification, erasure, restriction, objection, portability, and opt-out requests). If a Data Subject contacts PrintReactor directly, PrintReactor will, where practicable, direct them to Customer and, if Customer's identity is not clear, inform the Data Subject that they should contact the Merchant through whom they interacted with the Services.
9. Data Protection Impact Assessments and consultations
PrintReactor will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and the information available to PrintReactor.
10. International transfers
PrintReactor may transfer Personal Data to, and process it in, the United States and other countries in which PrintReactor or its Sub-processors operate. For transfers that require a transfer mechanism under Applicable Data Protection Laws, the parties agree that:
- EEA transfers. The EU SCCs are incorporated by reference. Module Two (Controller to Processor) applies where Customer is a controller and PrintReactor is a processor; Module Three (Processor to Processor) applies where Customer is itself a processor. Clause 7 (docking) applies; in Clause 9, Option 2 (general written authorization) applies with 30 days' notice; in Clause 11, the optional independent-dispute-resolution language does not apply; the governing law is Ireland; the supervisory authority is the DPC of Ireland; Clauses 17 and 18(b) follow the governing law selected.
- UK transfers. The UK International Data Transfer Addendum is incorporated by reference and amends the SCCs as needed for UK personal data.
- Swiss transfers. The SCCs apply with references to EU law understood to include the Swiss FADP where appropriate.
- Where Customer is located in a jurisdiction for which the European Commission has issued an adequacy decision, the adequacy decision applies instead.
- PrintReactor will conduct and document transfer impact assessments as required by Applicable Data Protection Laws.
11. Audit
PrintReactor will make available to Customer information necessary to demonstrate compliance with this DPA, including available security documentation and responses to reasonable security questionnaires. If Customer requires further information, the parties will agree on an audit scope, provided audits are conducted (a) no more than once per 12-month period unless required by a supervisory authority or following a Security Incident, (b) on at least 30 days' written notice, (c) during business hours, and (d) subject to confidentiality obligations. Audits are at Customer's expense unless they reveal a material breach.
12. Deletion and return
Upon termination or expiration of the Agreement, PrintReactor will, at Customer's choice, delete or return to Customer all Personal Data processed under the Agreement, except where applicable law requires retention. Following the deletion or return, PrintReactor will delete all existing copies within 90 days, subject to rolling backup retention described in our Privacy Policy.
13. US state privacy law addendum
To the extent CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, or comparable US state laws apply, PrintReactor:
- will process Personal Data only for the business purposes set out in the Agreement and will not retain, use, or disclose it for any other purpose;
- will not sell or share Personal Data (as defined by those laws);
- will not combine Personal Data received from Customer with Personal Data from other sources except as permitted by those laws;
- certifies that it understands and will comply with the restrictions applicable to service providers, processors, and contractors; and
- will notify Customer if it determines it can no longer meet its obligations under those laws.
14. Quebec Law 25 addendum
To the extent Quebec Law 25 applies, PrintReactor will process Personal Data only in accordance with Customer's documented instructions and this DPA, will maintain appropriate safeguards, and will notify Customer of any "confidentiality incident" within the meaning of Law 25 without undue delay. The Sub-processor list and transfer commitments in this DPA support Customer's transfer impact assessments under Law 25.
15. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except that no limitation applies to a party's liability to Data Subjects under the third-party beneficiary rights in the SCCs, to the extent required by law.
16. Term
This DPA takes effect on the effective date of the Agreement and terminates automatically when the Agreement terminates, except that the provisions necessary to protect Personal Data remaining with PrintReactor after termination survive.
Annex 1. Description of processing
- Subject matter: PrintReactor's provision of the Services to Customer.
- Duration: the term of the Agreement plus any period needed for wind-down, return, or deletion.
- Nature and purpose: hosting, storing, transmitting, rendering, and processing Personal Data as necessary to provide custom-sticker and related e-commerce functionality, including storefront integrations, design and proofing, cutline generation, production file output, fulfillment, and support.
- Types of Personal Data: contact details (name, email, phone), shipping/billing address, order history, uploaded artwork and its metadata, IP address and device/browser identifiers, and any additional data submitted by Customer or its end-customers through the Services.
- Categories of Data Subjects: Customer's personnel (admins, production users, customer-service users) and Customer's end-customers (shoppers who place orders on Customer's storefronts).
- Sensitive data: none intended. Customer agrees not to submit special-category data (GDPR Art. 9) or US sensitive PI through the Services unless separately agreed in writing.
- Frequency: continuous, for the duration of the Services.
- Retention: as set out in the Privacy Policy and as instructed by Customer.
Annex 2. Technical and organizational measures
These measures describe our current program and the controls we are putting in place as the Service matures. We do not represent a control as fully operational until it is.
- Access control: role-based access, least privilege, multi-factor authentication for administrative access, and prompt offboarding.
- Encryption: TLS 1.2+ in transit; AES-256 at rest for databases, object storage, and backups; per-tenant logical separation.
- Network security: private networking between services; WAF and rate limiting at the edge; segregated production and non-production environments.
- Application security: secure development practices, peer code review, and dependency scanning. We plan to add third-party penetration testing as the Service matures.
- Infrastructure: hardened base images, automated patch management, infrastructure-as-code with change review.
- Logging and monitoring: centralized audit logs and alerting for production incidents.
- Backups and resilience: encrypted backups with retention appropriate to the data, and periodic restore testing.
- Vendor management: security review before onboarding Sub-processors; periodic reassessment; contractual flow-down of data-protection obligations.
- Personnel: confidentiality obligations and security and privacy training for personnel with access to Personal Data.
- Incident response: an incident-response process (which we are formalizing as the Service matures) with defined roles for containment, eradication, and notification.
- Policy framework: written security, privacy, acceptable-use, and data-retention policies, reviewed periodically.
Annex 3. Approved Sub-processors
The current list of Sub-processors is published at /subprocessors and is incorporated into this DPA by reference.
Signature
This DPA is deemed executed by the parties on the effective date of the Agreement. Customer may request a countersigned copy by emailing [email protected].