Legal

Data Processing Addendum

The terms under which EasyEcom processes personal data on behalf of its customers: GDPR Article 28 commitments, subprocessors, transfers, security and deletion.

Effective date · Aug 19, 2026 Applies to · EasyEcom platform customers

01Overview

This page summarizes the EasyEcom Data Processing Addendum (the "DPA"). The DPA forms part of the agreement between EasyEcom and each customer, and sets out the terms under which EasyEcom processes personal data on the customer's behalf in line with Article 28 of the GDPR and comparable laws in other regions.

To put the DPA in place for your account, request the current signature-ready copy from privacy@easyecom.io. It is pre-signed by EasyEcom and countersigned copies are returned to you for your records.

02Roles of the parties

For personal data submitted to the platform, the customer acts as the data controller and EasyEcom acts as a data processor. Where a customer is itself a processor for its own clients, for example a 3PL running EasyEcom as a multi-client platform, EasyEcom acts as a subprocessor. EasyEcom processes personal data only on the customer's documented instructions, which are given through the agreement, the platform's configuration and its APIs.

03Scope of processing

ItemDescription
Subject matterOrder management, inventory, warehouse and fulfillment operations, and payment reconciliation run through the EasyEcom platform.
DurationThe term of the customer agreement, plus the deletion window described below.
Nature and purposeHosting, syncing, routing and reporting on commerce operations data as instructed by the customer.
Categories of dataBuyer names, shipping and billing addresses, email addresses, phone numbers, order contents and values, courier tracking references, payment settlement references. EasyEcom does not require or store full payment card numbers.
Data subjectsThe customer's buyers and end-recipients, and the customer's own staff who use the platform.

04Subprocessors

EasyEcom uses a limited set of vetted subprocessors to run the platform, for example cloud infrastructure and email delivery. The current list, with processing locations, is published at easyecom.io/trust/subprocessors. Changes are announced on that page in advance, and customers may raise a reasoned objection to a new subprocessor before it takes effect.

05Security measures

EasyEcom maintains a security program aligned to SOC 2 and ISO 27001, including encryption of data in transit and at rest, role-based access control, environment separation, centralized logging and a recurring VAPT (vulnerability assessment and penetration testing) program. A fuller description of the program lives in the Trust Center, and security documentation is available to customers on request.

06International transfers

Where personal data is transferred out of the EEA or the UK, the DPA incorporates the EU Standard Contractual Clauses (Commission Decision 2021/914) and the UK International Data Transfer Addendum. Processing locations for each subprocessor are listed on the subprocessors page. EasyEcom offers multi-country data residency: customer accounts can be provisioned to store platform data in India, the United States, the EU, the UK or APAC, and the chosen region is honored for that account’s processing.

07Breach notification

EasyEcom notifies affected customers without undue delay after becoming aware of a personal data breach affecting their data, and provides the information reasonably needed for the customer to meet its own notification obligations.

08Data subject requests

Taking into account the nature of the processing, EasyEcom assists customers in responding to data subject requests (access, rectification, erasure, portability and the rest) with appropriate technical and organizational measures. Requests that reach EasyEcom directly are forwarded to the relevant customer.

09Return and deletion

On termination, customers can export their data through the platform's reporting and API tools. On written request, EasyEcom deletes the customer's personal data within 90 days of termination, except where retention is required by law.

10Audit rights

EasyEcom makes its most recent independent audit reports and certifications available to customers under NDA, and supports audits as set out in the DPA.

Execute the DPA

Request the signature-ready DPA, current audit reports or security documentation:

Email privacy@easyecom.io. Postal: EasyEcom, 2nd Floor, Building 209, Hustle Hub, 27th Main Road, HSR Layout, Bengaluru 560102, India.