Snapshot 35490
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Data Processing Addendum (DPA) Last updated: April 1, 2026 This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Underlying Agreement governing Customer’s use of the Services. This DPA applies to PostGrid’s Processing of Customer Data on behalf of Customer in connection with the Services. In the event of any conflict between the Underlying Agreement and this DPA, this DPA will control solely with respect to the Processing of Customer Data. Capitalized terms not defined herein have the meanings given to them in the Definitions section (or Definitions page), as applicable. 1. Definitions For purposes of this DPA: “Customer Data” means any personal data included in the data that Customer submits to the Services or otherwise provides to PostGrid as part of receiving the Services. “Data Protection Laws” means all privacy and data-protection laws applicable to the processing of Customer Data under this DPA, including the EU General Data Protection Regulation (“GDPR”), the UK Data Protection Act 2018 and UK GDPR, the Swiss Federal Act on Data Protection, and U.S. state privacy laws. “SCCs” means the European Commission’s Standard Contractual Clauses (2021 Controller-to-Processor module), as officially published by the European Commission and as required by applicable law. “UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner’s Office, as officially published by the ICO and as required by applicable law. “Swiss Modifications” means the mandatory adjustments to the SCCs required by the Swiss Federal Act on Data Protection for transfers of personal data from Switzerland. 2. Roles and Scope 2.1 Roles. Customer is the controller or business of Customer Data. PostGrid is the processor or service provider that processes Customer Data on behalf of Customer. 2.2 Scope. This DPA applies only to the processing of Customer Data necessary for PostGrid to provide the Services and fulfill Customer’s documented instructions under the Underlying Agreement. 2.3 Customer Instructions. PostGrid will process Customer Data only in accordance with: the Underlying Agreement and this DPA; Customer’s configuration and use of the Services; and additional written instructions provided by Customer and accepted by PostGrid. PostGrid will promptly notify Customer if PostGrid determines that an instruction violates applicable law. 2.4 Restricted Data Types. Customer shall not provide special-category, biometric, financial account, or other highly regulated personal data unless expressly agreed in writing. Protected Health Information is handled only under a separate Business Associate Agreement (“BAA”), where applicable. 3. Customer Responsibilities Customer is responsible for: ensuring Customer Data is collected and provided in compliance with Data Protection Laws; obtaining all required consents and permissions; ensuring Customer Data does not violate any law or third-party rights; securing Customer’s own accounts, credentials, systems, and integrations; and determining the lawfulness of Customer’s chosen use of the Services. 4. PostGrid Obligations 4.1 Confidentiality. PostGrid will ensure that persons authorized to process Customer Data are subject to confidentiality obligations. 4.2 Security Measures. PostGrid will maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Customer Data from accidental or unlawful destruction, loss, alteration, or unauthorized access or disclosure, in accordance with industry-recognized standards including SOC 2 Type II frameworks. PostGrid will maintain a current attestation for SOC 2 Type II and will renew such attestation at least annually. These safeguards include: (a) encryption of Customer Data at rest using AES-256 or equivalent and in transit using TLS 1.2 or higher; (b) access controls including multi-factor authentication, role-based access, and least-privilege principles; (c) network protections including firewalls, intrusion detection, and network segmentation; (d) incident response procedures and security monitoring; (e) vendor management and security assessment processes for subprocessors; and (f) regular security assessments, vulnerability scanning, and penetration testing. PostGrid will review and update these measures at least annually to address evolving threats and maintain compliance with Data Protection Laws. 4.4 Security Information and Audit Rights. PostGrid will make available, upon written request, information reasonably necessary for Customer to verify PostGrid’s compliance with this DPA, to the extent required by Data Protection Laws. Customer may, at its own expense and no more than once per year (or more frequently if required by Data Protection Laws or upon reasonable evidence of non-compliance), conduct or appoint an independent third-party auditor to conduct an audit of PostGrid's compliance with this DPA. Such audits must be conducted during business hours with at least 30 days' advance notice, subject to reasonable confidentiality obligations, and in a manner that does not unreasonably interfere with PostGrid's operations. PostGrid may require the auditor to execute a non-disclosure agreement. In lieu of an audit, Customer may accept PostGrid's SOC 2 Type II report or equivalent third-party attestation as satisfying the audit requirement. 4.5 Assistance with Data Subject Rights. To the extent required by Data Protection Laws and reasonably possible, PostGrid will assist Customer in responding to data subject rights requests by providing appropriate technical and organizational measures to enable Customer to fulfil its obligations. PostGrid will respond to Customer's reasonable requests for assistance within 10 business days. PostGrid may charge reasonable fees for assistance with excessive, repetitive, or unusual requests that require significant manual effort beyond the scope of standard platform functionality. 4.6 No Sale or Sharing. PostGrid will not “sell” or “share” Customer Data (as such terms are defined under U.S. state privacy laws), nor use Customer Data for targeted or cross-context behavioral advertising. 4.7 Purpose Limitation. PostGrid will process Customer Data only as necessary to provide the Services, to maintain and improve the Services, and as permitted under the Underlying Agreement. PostGrid will process only the Customer Data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed (data minimization). 5. Subprocessors 5.1 Use of Subprocessors. Customer authorizes PostGrid to engage subcontractors and subprocessors to support the performance of the Services. 5.2 Protections. PostGrid will ensure subprocessors are bound by written obligations that are no less protective of Customer Data than those set out in this DPA. 5.3 Confidentiality of Subprocessor Information. PostGrid will provide a list of its active subprocessors upon reasonable request by Customer and upon Customer’s execution of a valid non-disclosure agreement with PostGrid. 5.4 No Notice or Objection Rights. Customer acknowledges that PostGrid is not required to provide advance notice of new subprocessors and Customer has no right to approve, reject, or object to PostGrid’s use of subprocessors. 6. International Transfers 6.1 General. PostGrid processes Customer Data primarily within the region associated with the Customer’s account configuration. For Customers whose accounts are configured for United States processing, Customer Data is processed and stored in the United States. Customer Data may be transferred outside the United States only where necessary to perform the Services requested by Customer, such as facilitating international mail delivery to another jurisdiction. For Customers located in the United Kingdom or the European Economic Area (“EEA”), PostGrid may offer regional processing within the European Union, including through infrastructure located in Ireland. Use of such regional processing may require specific onboarding and configuration coordinated through PostGrid’s customer success or implementation team. If Customer does not request or complete configuration for regional processing, Customer Data may be processed in other jurisdictions where PostGrid or its subprocessors operate, subject to the transfer mechanisms described in Sections 6.2–6.4. 6.2 EEA Transfers — SCCs. Where required by Data Protection Laws for transfers of Customer Data from the EEA to a jurisdiction not recognized as adequate, the SCCs apply and are hereby incorporated by reference. The official text published by the European Commission shall govern. 6.3 UK Transfers — UK Addendum. For transfers subject to UK law, the UK Addendum applies and is incorporated by reference. The official version published by the UK Information Commissioner’s Office shall govern. 6.4 Swiss Transfers — Swiss Modifications. For transfers subject to Swiss law, the SCCs apply with the Swiss Modifications mandated by the Swiss Federal Act on Data Protection. 6.5 Conflicts. If there is a conflict between the SCCs, the UK Addendum, or the Swiss Modifications and this DPA or the Underlying Agreement, the applicable transfer mechanism controls to the extent required by law. 7. Personal Data Breaches 7.1 Notification. PostGrid will notify Customer without undue delay and in any event within 3 business days after confirming a Personal Data Breach involving Customer Data, to the extent required by Data Protection Laws. 7.2 Limitations. PostGrid will provide notifications in accordance with the timeline specified in Section 7.1. PostGrid will provide reasonably available information about the breach, including the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed to address the breach. PostGrid is not required to provide detailed forensic reports or ongoing updates except where required by law or reasonably necessary for Customer to meet its legal obligations. 7.3 BAA Controls. Where Customer and PostGrid have executed a BAA, the BAA governs breach notification with respect to Protected Health Information. 8. Deletion and Return of Customer Data 8.1 Deletion or Return. Within 30 days after Customer’s written request or termination of the Underlying Agreement (or such shorter period as required by applicable Data Protection Laws), PostGrid will delete or return Customer Data as directed by Customer, unless retention is required or permitted by law or necessary for legitimate business purposes including billing, audit, security, or fraud-prevention. Customer may request certification of deletion, which PostGrid will provide within 15 days of completing the deletion process. 8.2 Backups. Customer Data stored in backups will be deleted according to PostGrid’s standard backup retention schedule, typically not exceeding 1 year from the date of backup creation. Upon Customer’s request, PostGrid may configure data backups to support Customer’s data retention or deletion requirements. Such configuration may be subject to additional fees. 8.3 Aggregated Anonymous Data. This DPA does not restrict PostGrid’s ability to retain or use Aggregated Anonymous Data as permitted under the Underlying Agreement. 9. Government and Legal Requests PostGrid will notify Customer of any legally compelled request for access to Customer Data unless prohibited by law. 10. U.S. State Privacy Laws (Service Provider / Processor Terms) For purposes of the CCPA/CPRA and other similar U.S. state privacy laws: PostGrid acts as a “Service Provider” or “Processor”; PostGrid will process Customer Data only as permitted under this DPA and the Underlying Agreement; PostGrid will not sell or share Customer Data; PostGrid will not combine Customer Data with other data except as permitted for the Services; and Customer Data will not be used for targeted advertising or profiling. 11. Governing Law This DPA is governed by the laws of the State of Delaware, with exclusive jurisdiction and venue in the courts located in Delaware, USA. This Section applies except where Data Protection Laws (including the SCCs, the UK Addendum, or the Swiss Modifications) require otherwise. 12. Changes to this DPA PostGrid may update this DPA from time to time to reflect changes in applicable Data Protection Laws, regulatory guidance, industry standards, or PostGrid’s processing practices. Any updated DPA will be posted on the Legal Page and will become effective upon posting unless a later effective date is specified. PostGrid will not materially reduce its data protection obligations with respect to Personal Data processed during an active Subscription Term without providing reasonable notice. Customer’s continued use of the Services after the effective date of any update constitutes acceptance of the revised DPA. Appendix A: Processing Details (Article 28 Requirements) Subject Matter: Processing of Customer Data to provide the Services. Nature and Purpose: Hosting, transmitting, validating, formatting, printing, mailing, and otherwise processing Customer Data as necessary to provide the Services and fulfill Customer’s instructions. Categories of Data Subjects: Customer’s users, employees, clients, and other individuals whose data Customer submits to the Services. Categories of Personal Data: Names, addresses, contact information, device identifiers, account credentials, mailing data, and any other personal data Customer includes in the Customer Data. Special Categories: Not permitted unless expressly agreed in writing. Duration: For the term of the Underlying Agreement and any legally required retention period. Previous Agreements Archived versions for transparency These are prior versions of PostGrid’s agreements and policies that are no longer in effect. Each document below includes the date range during which it governed use of the Services. For the current versions, please refer to the active Legal Hub above. Effective: September 1, 2023 – April 1, 2026 View Archived Version → PostGrid has you covered from all sides Regulatory Compliance Build trust by ensuring your customers that your data is PIPEDA, PHIPA HIPPA, GDPR & SOC-2 Certified and Compliant. Data Security Your data security is important to us, which is why we use Amazon web services for quick, easy to use, and safe hosting. Scalable Solutions Level up your marketing with PostGrid, as we provide native integration and API documentation for easy operations. Integrates with Your Favorite Tech Stack & Tools Easily Improve your workflow and automate print & mail through seamless integration capabilities. Learn more about our integrations Ready to Get Started? Start transforming and automating your offline communications with PostGrid SIGN UPREQUEST A DEMO Best-in-class Enterprise Ready Data Security & Compliance Certifications Company About Us Why Us How It Works Sustainability Careers Blogs Address Coverage Template Gallery Request a Demo Partner With Us Talk To Sales Products & Features Letter API Postcard API Check API Address Verification API Address Autocomplete API Address Lookup API Address Standardization API Geocoding API Address Verification Software Bulk Address Verification International Address Verification Integrations Salesforce Address Verification Salesforce Direct Mail HubSpot Direct Mail Zapier Direct Mail Klaviyo Direct Mail ActiveCampaign Direct Mail Customer.io Direct Mail Stripe Direct Mail MS Dynamics 365 Direct Mail View All Integration Integration Guides Print & Mail Resources Print & Mail Documents Print & Mail Service Print & Mail Letter Print & Mail Postcards Print & Mail Checks Print & Mail Invoices Print & Mail Statements Print & Mail Brochures Print & Mail Folded Self-Mailers Check Mailing Service Print & Mail API Direct Mail Resources Direct Mail Automation Software Direct Mail API Direct Mail Service Direct Mail Marketing Direct Mail Marketing Costs Direct Mail for Healthcare HIPAA Compliant Mailing HIPAA Mailing Services Bulk Mailing Services Best Direct Mail Companies Automated Direct Mail PostGrid Status Legal Security Contact Us Sitemap USA Canada UK Australia Copyright 2026, PostGrid. PostGrid™ and Post Grid™ are Registered Trademarks of PostGrid Inc. All rights reserved. Request a Demo Talk with a specialist about getting started with PostGrid. × We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies. Do not sell my personal information. Read MoreACCEPT Manage consent