Third Party Index

Snapshot 35490

Document
Data processing addendum
URL
https://www.postgrid.com/legal/data-processing-addendum-dpa/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
281551 bytes
SHA-256 (raw)
f218b40b60af4b775b9fe6e714173760f68d9714305fec28a7b549f8a12f6d73
SHA-256 (normalized text)
eb15df13e8e991311643e9a482a2d7eb3dc84c9b8a875af21624b43aef4023b4

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Addendum (DPA)
Last updated: April 1, 2026
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Underlying Agreement governing Customer’s use of the Services. This DPA applies to PostGrid’s Processing of Customer Data on behalf of Customer in connection with the Services. In the event of any conflict between the Underlying Agreement and this DPA, this DPA will control solely with respect to the Processing of Customer Data.
Capitalized terms not defined herein have the meanings given to them in the Definitions section (or Definitions page), as applicable.
1. Definitions
For purposes of this DPA:
“Customer Data” means any personal data included in the data that Customer submits to the Services or otherwise provides to PostGrid as part of receiving the Services.
“Data Protection Laws” means all privacy and data-protection laws applicable to the processing of Customer Data under this DPA, including the EU General Data Protection Regulation (“GDPR”), the UK Data Protection Act 2018 and UK GDPR, the Swiss Federal Act on Data Protection, and U.S. state privacy laws.
“SCCs” means the European Commission’s Standard Contractual Clauses (2021 Controller-to-Processor module), as officially published by the European Commission and as required by applicable law.
“UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner’s Office, as officially published by the ICO and as required by applicable law.
“Swiss Modifications” means the mandatory adjustments to the SCCs required by the Swiss Federal Act on Data Protection for transfers of personal data from Switzerland.
2. Roles and Scope
2.1 Roles.
Customer is the controller or business of Customer Data. PostGrid is the processor or service provider that processes Customer Data on behalf of Customer.
2.2 Scope.
This DPA applies only to the processing of Customer Data necessary for PostGrid to provide the Services and fulfill Customer’s documented instructions under the Underlying Agreement.
2.3 Customer Instructions.
PostGrid will process Customer Data only in accordance with:
the Underlying Agreement and this DPA;
Customer’s configuration and use of the Services; and
additional written instructions provided by Customer and accepted by PostGrid.
PostGrid will promptly notify Customer if PostGrid determines that an instruction violates applicable law.
2.4 Restricted Data Types.
Customer shall not provide special-category, biometric, financial account, or other highly regulated personal data unless expressly agreed in writing. Protected Health Information is handled only under a separate Business Associate Agreement (“BAA”), where applicable.
3. Customer Responsibilities
Customer is responsible for:
ensuring Customer Data is collected and provided in compliance with Data Protection Laws;
obtaining all required consents and permissions;
ensuring Customer Data does not violate any law or third-party rights;
securing Customer’s own accounts, credentials, systems, and integrations; and
determining the lawfulness of Customer’s chosen use of the Services.
4. PostGrid Obligations
4.1 Confidentiality.
PostGrid will ensure that persons authorized to process Customer Data are subject to confidentiality obligations.
4.2 Security Measures.
PostGrid will maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Customer Data from accidental or unlawful destruction, loss, alteration, or unauthorized access or disclosure, in accordance with industry-recognized standards including SOC 2 Type II frameworks. PostGrid will maintain a current attestation for SOC 2 Type II and will renew such attestation at least annually. These safeguards include: (a) encryption of Customer Data at rest using AES-256 or equivalent and in transit using TLS 1.2 or higher; (b) access controls including multi-factor authentication, role-based access, and least-privilege principles; (c) network protections including firewalls, intrusion detection, and network segmentation; (d) incident response procedures and security monitoring; (e) vendor management and security assessment processes for subprocessors; and (f) regular security assessments, vulnerability scanning, and penetration testing. PostGrid will review and update these measures at least annually to address evolving threats and maintain compliance with Data Protection Laws.
4.4 Security Information and Audit Rights.
PostGrid will make available, upon written request, information reasonably necessary for Customer to verify PostGrid’s compliance with this DPA, to the extent required by Data Protection Laws. Customer may, at its own expense and no more than once per year (or more frequently if required by Data Protection Laws or upon reasonable evidence of non-compliance), conduct or appoint an independent third-party auditor to conduct an audit of PostGrid's compliance with this DPA. Such audits must be conducted during business hours with at least 30 days' advance notice, subject to reasonable confidentiality obligations, and in a manner that does not unreasonably interfere with PostGrid's operations. PostGrid may require the auditor to execute a non-disclosure agreement. In lieu of an audit, Customer may accept PostGrid's SOC 2 Type II report or equivalent third-party attestation as satisfying the audit requirement.
4.5 Assistance with Data Subject Rights.
To the extent required by Data Protection Laws and reasonably possible, PostGrid will assist Customer in responding to data subject rights requests by providing appropriate technical and organizational measures to enable Customer to fulfil its obligations. PostGrid will respond to Customer's reasonable requests for assistance within 10 business days. PostGrid may charge reasonable fees for assistance with excessive, repetitive, or unusual requests that require significant manual effort beyond the scope of standard platform functionality.
4.6 No Sale or Sharing.
PostGrid will not “sell” or “share” Customer Data (as such terms are defined under U.S. state privacy laws), nor use Customer Data for targeted or cross-context behavioral advertising.
4.7 Purpose Limitation.
PostGrid will process Customer Data only as necessary to provide the Services, to maintain and improve the Services, and as permitted under the Underlying Agreement. PostGrid will process only the Customer Data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed (data minimization).
5. Subprocessors
5.1 Use of Subprocessors.
Customer authorizes PostGrid to engage subcontractors and subprocessors to support the performance of the Services.
5.2 Protections.
PostGrid will ensure subprocessors are bound by written obligations that are no less protective of Customer Data than those set out in this DPA.
5.3 Confidentiality of Subprocessor Information.
PostGrid will provide a list of its active subprocessors upon reasonable request by Customer and upon Customer’s execution of a valid non-disclosure agreement with PostGrid.
5.4 No Notice or Objection Rights.
Customer acknowledges that PostGrid is not required to provide advance notice of new subprocessors and Customer has no right to approve, reject, or object to PostGrid’s use of subprocessors.
6. International Transfers
6.1 General.
PostGrid processes Customer Data primarily within the region associated with the Customer’s account configuration.
For Customers whose accounts are configured for United States processing, Customer Data is processed and stored in the United States. Customer Data may be transferred outside the United States only where necessary to perform the Services requested by Customer, such as facilitating international mail delivery to another jurisdiction.
For Customers located in the United Kingdom or the European Economic Area (“EEA”), PostGrid may offer regional processing within the European Union, including through infrastructure located in Ireland. Use of such regional processing may require specific onboarding and configuration coordinated through PostGrid’s customer success or implementation team.
If Customer does not request or complete configuration for regional processing, Customer Data may be processed in other jurisdictions where PostGrid or its subprocessors operate, subject to the transfer mechanisms described in Sections 6.2–6.4.
6.2 EEA Transfers — SCCs.
Where required by Data Protection Laws for transfers of Customer Data from the EEA to a jurisdiction not recognized as adequate, the SCCs apply and are hereby incorporated by reference. The official text published by the European Commission shall govern.
6.3 UK Transfers — UK Addendum.
For transfers subject to UK law, the UK Addendum applies and is incorporated by reference. The official version published by the UK Information Commissioner’s Office shall govern.
6.4 Swiss Transfers — Swiss Modifications.
For transfers subject to Swiss law, the SCCs apply with the Swiss Modifications mandated by the Swiss Federal Act on Data Protection.
6.5 Conflicts.
If there is a conflict between the SCCs, the UK Addendum, or the Swiss Modifications and this DPA or the Underlying Agreement, the applicable transfer mechanism controls to the extent required by law.
7. Personal Data Breaches
7.1 Notification.
PostGrid will notify Customer without undue delay and in any event within 3 business days after confirming a Personal Data Breach involving Customer Data, to the extent required by Data Protection Laws.
7.2 Limitations.
PostGrid will provide notifications in accordance with the timeline specified in Section 7.1. PostGrid will provide reasonably available information about the breach, including the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed to address the breach. PostGrid is not required to provide detailed forensic reports or ongoing updates except where required by law or reasonably necessary for Customer to meet its legal obligations.
7.3 BAA Controls.
Where Customer and PostGrid have executed a BAA, the BAA governs breach notification with respect to Protected Health Information.
8. Deletion and Return of Customer Data
8.1 Deletion or Return.
Within 30 days after Customer’s written request or termination of the Underlying Agreement (or such shorter period as required by applicable Data Protection Laws), PostGrid will delete or return Customer Data as directed by Customer, unless retention is required or permitted by law or necessary for legitimate business purposes including billing, audit, security, or fraud-prevention. Customer may request certification of deletion, which PostGrid will provide within 15 days of completing the deletion process.
8.2 Backups.
Customer Data stored in backups will be deleted according to PostGrid’s standard backup retention schedule, typically not exceeding 1 year from the date of backup creation. Upon Customer’s request, PostGrid may configure data backups to support Customer’s data retention or deletion requirements. Such configuration may be subject to additional fees.
8.3 Aggregated Anonymous Data.
This DPA does not restrict PostGrid’s ability to retain or use Aggregated Anonymous Data as permitted under the Underlying Agreement.
9. Government and Legal Requests
PostGrid will notify Customer of any legally compelled request for access to Customer Data unless prohibited by law.
10. U.S. State Privacy Laws (Service Provider / Processor Terms)
For purposes of the CCPA/CPRA and other similar U.S. state privacy laws:
PostGrid acts as a “Service Provider” or “Processor”;
PostGrid will process Customer Data only as permitted under this DPA and the Underlying Agreement;
PostGrid will not sell or share Customer Data;
PostGrid will not combine Customer Data with other data except as permitted for the Services; and
Customer Data will not be used for targeted advertising or profiling.
11. Governing Law
This DPA is governed by the laws of the State of Delaware, with exclusive jurisdiction and venue in the courts located in Delaware, USA.
This Section applies except where Data Protection Laws (including the SCCs, the UK Addendum, or the Swiss Modifications) require otherwise.
12. Changes to this DPA
PostGrid may update this DPA from time to time to reflect changes in applicable Data Protection Laws, regulatory guidance, industry standards, or PostGrid’s processing practices. Any updated DPA will be posted on the Legal Page and will become effective upon posting unless a later effective date is specified. PostGrid will not materially reduce its data protection obligations with respect to Personal Data processed during an active Subscription Term without providing reasonable notice. Customer’s continued use of the Services after the effective date of any update constitutes acceptance of the revised DPA.
Appendix A: Processing Details (Article 28 Requirements)
Subject Matter: Processing of Customer Data to provide the Services.
Nature and Purpose: Hosting, transmitting, validating, formatting, printing, mailing, and otherwise processing Customer Data as necessary to provide the Services and fulfill Customer’s instructions.
Categories of Data Subjects: Customer’s users, employees, clients, and other individuals whose data Customer submits to the Services.
Categories of Personal Data: Names, addresses, contact information, device identifiers, account credentials, mailing data, and any other personal data Customer includes in the Customer Data.
Special Categories: Not permitted unless expressly agreed in writing.
Duration: For the term of the Underlying Agreement and any legally required retention period.
Previous Agreements
Archived versions for transparency
These are prior versions of PostGrid’s agreements and policies that are no longer in effect.
Each document below includes the date range during which it governed use of the Services.
For the current versions, please refer to the active Legal Hub above.
Effective: September 1, 2023 – April 1, 2026
View Archived Version →
PostGrid has you covered from all sides
Regulatory Compliance
Build trust by ensuring your customers that your data is PIPEDA, PHIPA HIPPA, GDPR & SOC-2 Certified and Compliant.
Data Security
Your data security is important to us, which is why we use Amazon web services for quick, easy to use, and safe hosting.
Scalable Solutions
Level up your marketing with PostGrid, as we provide native integration and API documentation for easy operations.
Integrates with Your Favorite Tech Stack & Tools
Easily Improve your workflow and automate print & mail through seamless integration capabilities.
Learn more about our integrations
Ready to Get Started?
Start transforming and automating your offline communications with PostGrid
SIGN UPREQUEST A DEMO
Best-in-class Enterprise Ready Data Security & Compliance Certifications
Company
About Us
Why Us
How It Works
Sustainability
Careers
Blogs
Address Coverage
Template Gallery
Request a Demo
Partner With Us
Talk To Sales
Products & Features
Letter API
Postcard API
Check API
Address Verification API
Address Autocomplete API
Address Lookup API
Address Standardization API
Geocoding API
Address Verification Software
Bulk Address Verification
International Address Verification
Integrations
Salesforce Address Verification
Salesforce Direct Mail
HubSpot Direct Mail
Zapier Direct Mail
Klaviyo Direct Mail
ActiveCampaign Direct Mail
Customer.io Direct Mail
Stripe Direct Mail
MS Dynamics 365 Direct Mail
View All Integration
Integration Guides
Print & Mail Resources
Print & Mail Documents
Print & Mail Service
Print & Mail Letter
Print & Mail Postcards
Print & Mail Checks
Print & Mail Invoices
Print & Mail Statements
Print & Mail Brochures
Print & Mail Folded Self-Mailers
Check Mailing Service
Print & Mail API
Direct Mail Resources
Direct Mail Automation Software
Direct Mail API
Direct Mail Service
Direct Mail Marketing
Direct Mail Marketing Costs
Direct Mail for Healthcare
HIPAA Compliant Mailing
HIPAA Mailing Services
Bulk Mailing Services
Best Direct Mail Companies
Automated Direct Mail
PostGrid
Status
Legal
Security
Contact Us
Sitemap
USA
Canada
UK
Australia
Copyright 2026, PostGrid. PostGrid™ and Post Grid™ are Registered Trademarks of PostGrid Inc. All rights reserved.
Request a Demo
Talk with a specialist about getting started with PostGrid.
×
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Read MoreACCEPT
Manage consent