Data Processing Addendum
Effective date: August 27, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Anderson & Associates ("ShipmentBot," the "Processor") and the customer (the "Controller") and applies where ShipmentBot processes personal data on the Controller's behalf.
1. Definitions
"Personal data," "processing," "controller," "processor," and "data subject" have the meanings given in applicable data protection law, including the GDPR and the CCPA/CPRA where they apply. "Applicable law" means the data protection laws that apply to the personal data processed under this DPA.
2. Scope and Roles
The Controller is the controller of personal data submitted to the Service, including personal data received from Amazon under the Controller's SP-API authorization. ShipmentBot is the processor and processes personal data only on the Controller's documented instructions, as set out in the Terms and this DPA, unless required by law. Where the CCPA applies, ShipmentBot is a "service provider" and does not sell or share personal information.
3. Details of Processing
- Subject matter: operation of the ShipmentBot Service.
- Duration: the term of the Terms plus the deletion period in Section 9.
- Nature and purpose: hosting, inventory forecasting, shipment and order management, settlement reporting, and related support.
- Categories of data subjects: the Controller's users and employees; buyers of the Controller's products on Amazon.
- Categories of personal data: names, email addresses, and account identifiers of users; buyer names, shipping addresses, and order details from Amazon. No special categories of data are intended to be processed.
4. Amazon Data Protection Policy
For personal data received through the Amazon Selling Partner API, ShipmentBot complies with the Amazon Acceptable Use Policy and Data Protection Policy, including restrictions on use, retention, and disclosure of buyer personal information. Where Amazon's policies are stricter than this DPA, Amazon's policies control for that data.
5. Confidentiality
ShipmentBot ensures that persons authorized to process personal data are bound by confidentiality obligations.
6. Security
ShipmentBot implements appropriate technical and organizational measures, including: encryption in transit (TLS 1.2+) and at rest; role-based access controls and least-privilege access; credential management and multi-factor authentication for infrastructure access; logging and monitoring; and regular security patching and dependency scanning.
7. Subprocessors
The Controller authorizes the subprocessors listed below. ShipmentBot will notify the Controller of new subprocessors (by updating this page and, for material changes, by email) and the Controller may object on reasonable data protection grounds within 14 days. ShipmentBot remains responsible for its subprocessors' performance.
| Subprocessor | Purpose | Location |
|---|---|---|
| Heroku (Salesforce) | Application hosting and database | United States |
| Amazon Web Services | File storage (S3) and message queues (SQS); background worker hosting | United States |
| Cloudflare | DNS, CDN, and network security | Global |
| Auth0 (Okta) | Authentication | United States |
| Stripe | Payment processing | United States |
| Postmark (ActiveCampaign) | Transactional email | United States |
| OpenAI | AI-generated forecasts and content (no buyer personal data) | United States |
| Sentry (Functional Software) | Error monitoring | United States |
| Site analytics (aggregated usage data) | United States | |
| Slack (Salesforce) | Operational notifications | United States |
8. Assistance
Taking into account the nature of the processing, ShipmentBot will assist the Controller with data subject requests, security of processing, breach notification, and data protection impact assessments, as required by applicable law.
9. Data Breach Notification
ShipmentBot will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide information reasonably required for the Controller to meet its own notification obligations.
10. Deletion and Return
On termination of the Terms, ShipmentBot will, at the Controller's choice, delete or return the Controller's personal data within 30 days, unless retention is required by law. Amazon buyer personal information is deleted on the shorter schedule required by Amazon's Data Protection Policy.
11. International Transfers
Personal data is processed in the United States. Where the GDPR or UK GDPR applies to a transfer, the parties incorporate the European Commission's Standard Contractual Clauses (Module 2: controller-to-processor) and the UK Addendum, completed with the processing details in this DPA.
12. Audits
On reasonable written notice, no more than once per year, ShipmentBot will make available information reasonably necessary to demonstrate compliance with this DPA, including responses to security questionnaires.
13. Contact
Anderson & Associates (ShipmentBot)
Washington, USA
support@shipmentbot.com