Data Processing Addendum
Data Processing Addendum
STATUS: DRAFT. Requires legal review before publication. Fields marked [TODO: …] need jurisdiction-specific or business-specific input.
>
Last updated: 2026-06-24.
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between [TODO: legal entity name] ("4klyft", "Processor") and the Customer identified in the Agreement ("Customer", "Controller") and applies to the extent that 4klyft processes Personal Data on behalf of the Customer.
The DPA reflects the parties' agreement on the terms governing the processing of Personal Data under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR as supplemented by the Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), and equivalent or stricter local data protection laws where they apply ("Data Protection Laws").
Capitalised terms not defined here have the meanings given in the Agreement or in the GDPR.
1. Subject matter, duration, nature, and purpose of processing
| Subject matter | The provision of the 4klyft Service as described in the Agreement and the Service documentation. |
| Duration | The term of the Agreement plus the data-retention periods specified in the Privacy Policy. |
| Nature of processing | Collection, storage, transmission, retrieval, structuring, organisation, use, restriction, return, and deletion of Personal Data, as required to operate the Service for the Controller. |
| Purpose | Enabling the Controller to plan and execute logistics operations (route optimisation, fulfilment workflow, dispatch, proof of delivery, tracking, invoicing). |
| Type of Personal Data | Names, contact details (email, phone), postal addresses, signatures captured at delivery, photos captured at delivery, vehicle/driver identifiers, GPS coordinates of drivers and stops, order references, shipment metadata, and any Personal Data Controller chooses to submit via the Service. |
| Categories of Data Subjects | Controller's end-customers (delivery recipients), drivers, warehouse staff, dispatchers, and Controller's authorised users of the Service. |
| Special categories of data | Not processed under this DPA unless Controller explicitly requests in writing and 4klyft agrees in writing. |
2. Roles of the parties
The parties agree that for Personal Data submitted by the Controller through the Service, Controller is the Controller and 4klyft is the Processor under Article 28 GDPR.
For Personal Data 4klyft collects directly about Controller's authorised users in the course of administering the contract (account credentials, billing details, support communications), 4klyft is the Controller under its Privacy Policy.
For any joint-controllership scenario (Article 26 GDPR) — none is contemplated under this DPA. If one arises, the parties will enter into a separate written joint-controllership arrangement before processing begins.
3. Controller's instructions
4klyft will process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by EU or Member State law to which 4klyft is subject. In such a case, 4klyft will inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Controller's instructions are:
1. The Agreement and this DPA (the primary instructions). 2. The Service's standard functionality (route planning, fulfilment, tracking, etc.) — using the Service in its intended manner constitutes a documented instruction. 3. The Controller's documented configuration choices within the Service (such as notification preferences, retention windows, integration enable/disable choices). 4. Specific written instructions the Controller may give from time to time, where the Service supports them.
4klyft will immediately inform the Controller if, in 4klyft's opinion, an instruction infringes the GDPR or other applicable Data Protection Laws. 4klyft may suspend processing under such an instruction until the Controller withdraws or amends it.
4. Confidentiality
4klyft ensures that its personnel authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Confidentiality obligations survive termination of those personnel's relationship with 4klyft.
5. Security of processing
4klyft implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR.
The current measures are described in Annex II — Technical and Organisational Measures of this DPA. They include:
- Pseudonymisation and encryption of Personal Data where appropriate.
- Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- The ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident.
- A process for regularly testing, assessing, and evaluating the effectiveness of these measures.
4klyft may update these measures from time to time, provided that any update does not materially decrease the overall level of security.
6. Subprocessors
6.1 General authorisation
The Controller hereby provides general written authorisation under Article 28(2) GDPR for 4klyft to engage subprocessors, subject to the conditions below.
6.2 Current subprocessors
The current list of authorised subprocessors is published at 4klyft.com/legal/subprocessors and is incorporated into this DPA by reference. The list identifies each subprocessor, the location of processing, and the activities performed.
The current list (as of the Last-updated date of this DPA) is:
| Subprocessor | Activity | Location |
|---|---|---|
| Amazon Web Services Inc. — eu-west-1 / eu-central-1 | Hosting and infrastructure | Ireland and/or Germany (EU) |
| Stripe Payments Europe Ltd | Payment processing | Ireland (EU) |
| Cloudflare, Inc. | DDoS protection, CDN, DNS | Global edge, primary EU |
| Sentry GmbH | Error tracking with PII scrubbing | Germany (EU) |
| Plausible Analytics | Cookie-free aggregate analytics | Germany (EU) |
| [TODO: Email vendor] | Transactional email | EU + US |
| [TODO: CRM vendor] | CRM and marketing email | US, EU residency available |
| Google Cloud (Maps/Routes APIs) | Geocoding and routing | US, EU edge |
| SendCloud B.V. | Carrier integration where Controller enables it | Netherlands (EU) |
| [TODO: any others currently in use] |
6.3 Changes to subprocessors
4klyft will give the Controller at least 30 days' advance notice of any intended change to subprocessors (adding a new subprocessor or replacing an existing one), by:
- Publishing the updated list at
4klyft.com/legal/subprocessors. - Notifying the Controller's primary contact by email, where the Controller has subscribed to subprocessor-change notifications (default: subscribed).
The Controller may object to a proposed change on reasonable data-protection grounds within 15 days of the notice. If the Controller objects, the parties will discuss in good faith. If the parties cannot agree, the Controller may terminate the Agreement for cause with respect to the affected portion of the Service, with a pro-rated refund of pre-paid unused fees.
6.4 Conditions on subprocessor engagement
For each subprocessor:
- 4klyft imposes data-protection obligations no less protective than those in this DPA, in particular with regard to security measures and onward transfer restrictions.
- 4klyft remains fully liable to the Controller for the performance of the subprocessor's obligations.
7. Data subject rights
Taking into account the nature of the processing, 4klyft assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Articles 15 to 22 GDPR.
In practice:
- Self-service: The Service provides functionality allowing the Controller to access, export, correct, and delete Personal Data about its own data subjects directly. Use of that functionality is the primary route for fulfilling data-subject requests.
- Forwarded requests: If 4klyft receives a data-subject request that relates to Personal Data the Controller has submitted to the Service, 4klyft will not respond to the data subject directly. Instead, it will redirect the data subject to the Controller and, where possible, notify the Controller within 5 business days so the Controller can respond within its own GDPR Article 12 deadlines.
- Reasonable assistance: Where the Controller cannot fulfil a request through the Service's self-service functionality alone, 4klyft will provide reasonable assistance at the Controller's expense, subject to the cost-recovery provisions of this DPA.
8. Assistance with the Controller's GDPR obligations
4klyft provides reasonable assistance to the Controller, at the Controller's expense (except as required to be at 4klyft's expense under applicable law), with:
- Article 32 (Security of processing) — by maintaining and documenting the security measures in Annex II.
- Article 33 (Notification of personal data breach) — see Section 9 below.
- Article 34 (Communication of breach to data subjects) — by providing reasonable factual information the Controller needs to communicate.
- Articles 35 + 36 (Data Protection Impact Assessment, prior consultation) — by providing reasonable information the Controller needs to conduct a DPIA or consult with a supervisory authority.
9. Personal Data breach notification
4klyft notifies the Controller of any Personal Data Breach affecting Personal Data processed under this DPA without undue delay after becoming aware of it, and in any case within 48 hours of becoming aware. The notification includes, to the extent then known:
- A description of the nature of the breach, including categories and approximate number of data subjects and Personal Data records concerned.
- The name and contact details of 4klyft's DPO or other point of contact.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach and mitigate its possible adverse effects.
Information provided initially may be incomplete. 4klyft provides further information in stages as it becomes available.
4klyft does not notify supervisory authorities or data subjects on the Controller's behalf — the Controller, as Controller of the Personal Data, remains responsible for notification under Articles 33 and 34. 4klyft provides the Controller with the information the Controller reasonably needs to make those notifications.
10. International data transfers
Where 4klyft or a subprocessor transfers Personal Data outside the EEA, the UK, or Switzerland to a country not benefiting from an adequacy decision, the transfer is governed by:
- Standard Contractual Clauses (SCCs) approved by European Commission Decision 2021/914, in their applicable Module (typically Module 2: Controller-to-Processor; Module 3: Processor-to-Processor where 4klyft engages a sub-processor that further processes the data) — incorporated into this DPA by reference.
- For UK transfers: the UK International Data Transfer Addendum (IDTA) to the SCCs.
- For Swiss transfers: the SCCs as adapted for Swiss law.
The parties acknowledge that, where the SCCs are incorporated by reference:
- Clause 7 (docking) applies.
- Clause 11 (Independent supervisory authority): the supervisory authority is [TODO: name of supervisory authority].
- Clause 17 (Governing law): [TODO: law of EU Member State].
- Clause 18 (Choice of forum): [TODO: courts of EU Member State].
For each onward transfer to a third country, 4klyft conducts a Transfer Impact Assessment under the Schrems II framework and implements supplementary measures (encryption in transit and at rest, access controls, pseudonymisation where practical, contractual flow-down) as necessary to ensure an essentially equivalent level of protection.
The Controller may request a copy of the most recent Transfer Impact Assessment for any subprocessor by emailing dpo@4klyft.com.
11. Audits and inspections
4klyft makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
In practice:
1. Standard reports. 4klyft provides the Controller with copies of its current third-party audit reports (ISO 27001 statement of applicability, SOC 2 Type II report, penetration test summary) on reasonable request. These reports are intended to satisfy most audit needs. 2. On-site audits. If standard reports are insufficient, the Controller may conduct an on-site audit no more frequently than once per calendar year, with at least 30 days' written notice, during normal business hours, in a manner that does not disrupt 4klyft's operations or compromise the security or confidentiality of other Customers' data. Auditors must be bound by confidentiality obligations no less protective than those in the Agreement. 3. Cost. The Controller bears its own audit costs. Where 4klyft's reasonable assistance in support of an audit exceeds [TODO: 4 hours] of 4klyft personnel time per year, 4klyft may invoice the Controller at its then-current professional services rates for the excess. 4. Findings. 4klyft remedies any non-compliance identified by an audit, at its own expense, within a reasonable time appropriate to the severity of the finding. 5. Regulatory audits. Where a Supervisory Authority requires an audit, the above frequency and notice limits do not apply, and 4klyft cooperates fully with the audit at its own expense.
12. Return and deletion of Personal Data
On termination of the Agreement, 4klyft, at the choice of the Controller (expressed in writing within 30 days of termination), deletes or returns all Personal Data to the Controller, and deletes existing copies, unless EU or Member State law requires storage of the Personal Data.
Personal Data is deleted from production systems within 60 days of the Controller's instruction. Backup copies are overwritten on 4klyft's rolling 35-day backup cycle; deleted Personal Data is not separately purged from backups, but restoration of deleted Personal Data is suppressed through documented technical controls.
Personal Data that has been aggregated or de-identified such that it can no longer be attributed to a specific data subject is not deleted; it has ceased to be Personal Data.
13. Indemnity for processor breaches
4klyft indemnifies the Controller against any administrative fines or regulatory penalties imposed by a Supervisory Authority on the Controller, to the extent those fines or penalties result from a breach by 4klyft of its obligations under this DPA, subject to the limitation-of-liability cap in the Agreement.
The Controller indemnifies 4klyft against any administrative fines or regulatory penalties imposed by a Supervisory Authority on 4klyft, to the extent those fines or penalties result from the Controller's instructions or breach of the Controller's obligations under this DPA or applicable Data Protection Laws.
14. Term
This DPA takes effect on the effective date of the Agreement and continues for as long as 4klyft processes Personal Data on behalf of the Controller. The provisions on confidentiality (clause 4), security (clause 5), breach notification (clause 9), audit (clause 11), and deletion (clause 12) survive termination.
15. Order of precedence
In the event of any conflict between this DPA, the Agreement, and the SCCs (where they apply), the order of precedence is: 1. The SCCs (where they apply, for matters they cover). 2. This DPA. 3. The Agreement.
16. Signatures
This DPA is incorporated into and forms part of the Agreement. The Controller's acceptance of the Agreement constitutes acceptance of this DPA.
For Customers who require a signed DPA, contact dpo@4klyft.com to receive a counter-signed copy.
Annex I — Description of the processing
This Annex describes the processing of Personal Data under this DPA in the structured form required by the SCCs.
List of parties
- Data exporter (Controller): The Customer identified in the Agreement.
- Data importer (Processor): [TODO: legal entity name + registered address].
Description of transfer
| Item | Detail |
|---|---|
| Categories of data subjects | End-customers (delivery recipients), drivers, warehouse staff, dispatchers, and the Controller's authorised users. |
| Categories of personal data | Names, contact details, postal addresses, signatures, photos captured at delivery, vehicle/driver identifiers, GPS coordinates, order references, shipment metadata, and any other Personal Data the Controller submits via the Service. |
| Special categories | None, unless the Controller submits them with written notice. |
| Frequency | Continuous, during the term of the Agreement. |
| Nature of processing | See clause 1 of this DPA. |
| Purpose | See clause 1 of this DPA. |
| Retention | See clause 12 of this DPA and the Privacy Policy. |
| Onward transfers | See clause 6 (subprocessors) and clause 10 (international transfers) of this DPA. |
Competent supervisory authority
For SCC purposes, the competent supervisory authority is [TODO: name of supervisory authority in the EU Member State of establishment of the Controller, or the lead supervisory authority for the Controller's group].
Annex II — Technical and Organisational Measures
The current state of 4klyft's technical and organisational measures. Measures may be updated from time to time, provided the overall level of security is not materially reduced.
Organisational measures
- ISO 27001 certified information security management system [TODO: confirm or change to "in progress"].
- SOC 2 Type II audit, annually [TODO: confirm or change to "in progress"].
- GDPR-compliant data-protection programme.
- Documented security policies covering access control, change management, incident response, business continuity, supplier management, secure development, and data classification.
- Mandatory annual security and data-protection training for all personnel.
- Background checks on all personnel with access to production systems, where lawful.
- Confidentiality agreements with all personnel and contractors.
Access control
- Single sign-on (SSO) and multi-factor authentication (MFA) required for all personnel access to production systems.
- Role-based access control (RBAC) with least-privilege principle. No standing access to customer Personal Data; access is granted just-in-time through an audited approval workflow.
- All access to production systems is logged and reviewed quarterly.
- Personnel access is revoked within 24 hours of role change or termination.
Application security
- Tenant data is isolated at the database row level through tenant-scoped queries; cross-tenant queries are prevented at the application layer.
- Every operator action inside the platform is recorded in an immutable audit log, retained for the duration of the Agreement plus 12 months.
- Outbound webhooks are signed with HMAC; subscribers verify signatures to detect tampering.
- All inbound webhooks are verified for signature, where the issuer supports signing (e.g. SendCloud, Stripe).
- The platform supports user-managed connected-account revocation: each user can list and revoke their linked authentication methods.
- A "last authentication method" guard prevents users from removing their only remaining login mechanism.
Network security
- All client-to-server and server-to-server traffic uses TLS 1.2 or above.
- Production database access is restricted to application servers in the same VPC; no public-internet ingress to databases.
- DDoS protection via Cloudflare.
- Rate limiting on all public endpoints.
- Web Application Firewall in front of public endpoints.
Cryptography
- Personal Data at rest is encrypted using AES-256 (or equivalent).
- Personal Data in transit is encrypted using TLS 1.2 or above.
- Key management uses a hardware security module (HSM) or equivalent. Keys are rotated annually.
Data segregation
- Multi-tenant architecture with tenant-id row-level filtering on every read and write.
- Separate logical schemas where regulatory or contractual requirements demand it.
Backup and recovery
- Encrypted backups taken daily, retained on a rolling 35-day cycle.
- Backups stored in a separate availability zone from production.
- Restore tested at least quarterly.
- Documented Recovery Time Objective (RTO) of [TODO: 4 hours] and Recovery Point Objective (RPO) of [TODO: 24 hours] for the production environment.
Logging and monitoring
- Centralised logging of application, security, and audit events.
- Real-time monitoring with alerting on anomalous activity.
- Logs retained for [TODO: 12 months] for security investigations.
Vendor management
- Subprocessors selected based on documented data-protection due diligence.
- Subprocessor agreements impose data-protection obligations no less protective than this DPA.
- Annual review of subprocessor compliance.
Secure development
- Code review required for every change to production code.
- Automated security testing (SAST and dependency scanning) on every commit.
- Annual third-party penetration testing.
- Public bug bounty programme [TODO: confirm scope and URL].
- Vulnerabilities tracked and remediated per documented SLAs (critical: 24h; high: 7d; medium: 30d; low: 90d).
Incident response
- Documented incident response plan, exercised annually.
- 24/7 on-call rotation for security and operational incidents.
- Personal Data Breach notification per clause 9 of this DPA.
Business continuity
- Multi-availability-zone deployment in primary regions.
- Documented disaster recovery plan, exercised annually.
- Recovery targets per the "Backup and recovery" section above.
Contact: Questions about this DPA? Email dpo@4klyft.com.