01About this agreement
This Data Processing Agreement (“DPA”) applies where Repark LTD (“Repark”) provides order fulfilment, despatch or related services to a business client (the “Client”) and, in doing so, processes personal data on the Client’s behalf. It sets out the terms required by Article 28 of the UK GDPR for that relationship.
This DPA forms part of, and should be read together with, the service agreement between Repark and the Client. If there is a conflict about the processing of personal data, this DPA prevails.
Where Repark sells its own products through online marketplaces, it acts as an independent controller of the order data it receives — that processing is covered by our Privacy Policy, not this DPA.
02Roles and definitions
For the purposes of this DPA, the Client is the controller of the personal data it provides, and Repark is the processor, acting on the Client’s documented instructions. If the Client is itself a processor appointing Repark as a sub‑processor, the Client warrants that it has the controller’s authority to do so on these terms.
Words and phrases defined in the UK GDPR — including “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” — have the same meanings in this DPA. “UK GDPR” means the UK General Data Protection Regulation, read with the Data Protection Act 2018.
03Details of the processing
| Item | Description |
|---|---|
| Subject matter | Order fulfilment and despatch of physical goods on the Client’s behalf. |
| Duration | The term of the service agreement, plus the deletion period in section 11. |
| Nature and purpose | Receiving order data; picking, packing, labelling and shipping orders via carriers; tracking, returns and related customer‑service support. |
| Types of personal data | Recipient name; delivery and, where provided, billing address; phone number; email address; order details (items, values, references); and, for some export destinations, a tax identifier where required by customs. |
| Categories of data subjects | The Client’s customers — the recipients of orders. |
| Special category data | None. It is not required for the services and must not be sent to us. |
04Instructions and confidentiality
We will process the Client’s personal data only on the Client’s documented instructions — being the service agreement, this DPA and the order data the Client transmits to us — including as regards transfers outside the UK, unless we are required to process it by UK law, in which case we will inform the Client of that requirement before processing unless the law prohibits it.
We ensure that every person we authorise to process the Client’s data is committed to confidentiality. We will not use the data for our own purposes, and never for marketing.
05Security of processing
We apply technical and organisational measures appropriate to the risk, as required by Article 32 and as detailed in our Data Protection Policy (available to the Client on request), including:
- AES‑256‑GCM envelope encryption of personal data at rest, and TLS 1.3 for all data in transit.
- Authentication with Argon2id‑hashed passwords under an enforced password policy (minimum 12 characters with mixed case, number and symbol; breached-password and name/email exclusion; last-10 history; 365-day expiry; 5-attempt/15-minute lockout), and two‑factor authentication (TOTP) required on privileged accounts, with admin approval for new devices. Server access is by SSH key only.
- Default‑deny, role‑based access control on a need‑to‑know and least‑privilege basis.
- Tamper‑evident access-audit logging that records which record and field an operator accessed, together with their IP address, held securely for security purposes; operational and error logs are stripped of personal data at the database-driver boundary and are retained for 400 days.
- Hosting on AWS infrastructure in the Asia Pacific (Singapore) region, with encrypted backups copied to AWS Europe (London) in the United Kingdom.
06Sub‑processors
The Client gives general written authorisation for the sub‑processors listed below. We will give the Client notice of any intended addition or replacement, giving the Client the opportunity to object on reasonable grounds. We impose data‑protection obligations on every sub‑processor equivalent to those in this DPA, and we remain liable to the Client for their performance.
| Sub‑processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting and database (with encrypted backups in the UK — London) | Singapore, with backups in the UK (London) (under the IDTA / UK Addendum to the EU SCCs) |
| Shipping / courier carriers | Delivery of orders (name, address and contact details only) | UK and the destination country of each order |
| Google (Gmail SMTP) | Transactional / operational email | US / EEA, under the UK extension to the EU‑US Data Privacy Framework |
07Assisting the Client
Taking into account the nature of the processing, we will assist the Client with appropriate technical and organisational measures, so far as this is possible, in responding to data subject rights requests (access, rectification, erasure, restriction, objection and portability). If a data subject contacts us directly, we will forward the request to the Client without undue delay and will not respond to it except on the Client’s instructions or where the law requires.
We will also assist the Client in meeting its obligations under Articles 32 to 36 of the UK GDPR — security, breach notification, data protection impact assessments and prior consultation — taking into account the nature of the processing and the information available to us.
08Personal data breaches
If we become aware of a personal data breach affecting the Client’s personal data, we will notify the Client without undue delay, and provide the information the Client reasonably requires for its own notification duties under Articles 33 and 34 — the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We document all breaches and handle them under our Data Breach Notification & Incident Response Plan.
09International transfers
The Client’s personal data is hosted by AWS in its Singapore region. Because this is outside the UK, the transfer is protected by an appropriate safeguard — the International Data Transfer Agreement (IDTA) / UK Addendum to the EU Standard Contractual Clauses that forms part of AWS’s data-processing terms. We also hold encrypted backup copies in AWS Europe (London), within the United Kingdom, so a copy exists outside the live hosting region. In addition, carriers delivering orders internationally receive only the details needed to deliver each order to its destination. We keep a record of these transfers and their safeguards.
10Audits and information
We will make available to the Client the information necessary to demonstrate our compliance with Article 28, and will allow and contribute to audits or inspections conducted by the Client or an auditor it mandates — on reasonable prior notice, during business hours, no more than once in any 12‑month period (unless following a personal data breach or where required by a regulator), and subject to reasonable confidentiality undertakings.
11Return and deletion of data
At the end of the services, at the Client’s choice, we will delete or return all of the Client’s personal data and delete existing copies, unless UK law requires us to store it — for example accounting and transaction records — in which case we will protect and isolate that data from further processing until deletion is possible. We will certify deletion on request. In all cases, buyer personal data (recipient name, delivery and billing address, phone number and email address, and any file rendered from it such as shipping labels, invoices and packing documents) is deleted or irreversibly anonymised within 30 days of confirmed delivery, or from dispatch where no delivery confirmation is available. No buyer personal data is retained beyond 30 days. Transaction and accounting records, which contain no buyer name, address, phone number or email address, are kept for up to 6 years to meet UK tax and company-law obligations.
12General, law and contact
This DPA is governed by the law of England and Wales. Liability between the parties is as set out in the service agreement; nothing in this DPA excludes any liability that cannot be excluded by law.
Questions about this DPA:
- Email: hamza@repark.co.uk
- Post: Repark LTD, Unit 2 Brook Street, Thurmaston, Leicester, LE4 8DA, United Kingdom