A Data Processing Agreement (DPA) is a contract required by the General Data Protection Regulation (GDPR, Article 28) between a data controller and a data processor. If your business uses TrackLogy to process personal data belonging to your customers, you act as the data controller and WINDCODEX INC acts as the data processor.
Enterprise and business customers who require a signed DPA for GDPR compliance may request one by emailing [email protected]. We aim to respond within 5 business days.
What Our DPA Covers
Our standard DPA includes provisions covering:
- Roles and responsibilities — Clear definition of controller and processor obligations as required by GDPR Article 28.
- Subject matter and duration — The nature, purpose, and duration of processing performed on your behalf.
- Categories of data and data subjects — The types of personal data processed (e.g. customer name, email, shipping address) and who they relate to.
- Sub-processors — Authorisation to engage sub-processors listed at tracklogy.com/legal/subprocessors, with 30-day advance notice of any additions.
- International data transfers — Use of Standard Contractual Clauses (SCCs) where data is transferred outside the EEA to sub-processors in the United States.
- Security measures — Technical and organisational measures we implement to protect personal data.
- Data subject rights — Our obligation to assist you in responding to data subject requests (access, erasure, portability, etc.).
- Breach notification — Our obligation to notify you within 72 hours of becoming aware of a personal data breach affecting your data.
- Audit rights — Your right to audit our data processing activities, subject to reasonable notice.
- Deletion on termination — Our obligation to delete or return personal data at the end of the service relationship.
Who Needs a DPA?
You are likely required to have a DPA in place with us if:
- Your business is established in the EEA or United Kingdom, or you offer goods and services to individuals in the EEA or UK.
- You use TrackLogy to process personal data about your customers (names, email addresses, shipping addresses, phone numbers).
- Your legal or compliance team has requested a DPA as part of vendor due diligence.
If you are unsure whether you need a DPA, we recommend consulting with your legal counsel or data protection officer.
How to Request a DPA
Email us at [email protected] with the subject line “DPA Request” and include:
- Your company name and registered address.
- The name and email of the signatory authorised to execute agreements on behalf of your company.
- Any specific requirements or amendments you need discussed before signing.
We will send you our standard DPA for review. If you require material amendments, we will assess these on a case-by-case basis.