Data Processing Agreement (DPA)
Standard Contractual Terms Governing Customer Personal & Shipment Data Processing (GDPR Article 28 & EU SCCs Module 2 Aligned)
Definitions & Interpretation
1.1. “Applicable Data Protection Law” means all worldwide privacy and data protection laws applicable to the processing of personal data under the Principal Agreement, including: (a) the General Data Protection Regulation (EU 2016/679) (“EU GDPR”); (b) the UK Data Protection Act 2018 and the UK GDPR; (c) the Swiss Federal Act on Data Protection (“FADP”); and (d) the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).
1.2. “Customer Personal Data” means any Personal Data processed by Panvaya on behalf of Customer in the course of providing the Services under the Principal Agreement.
1.3. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” have the meanings given in the EU GDPR.
1.4. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by European Commission Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries.
1.5. “Sub-processor” means any third party appointed by or on behalf of Panvaya to process Customer Personal Data in connection with the Principal Agreement.
Scope & Roles of the Parties
2.1. Status of the Parties: The parties acknowledge and agree that with respect to the processing of Customer Personal Data:
- Customer is the Controller (or an intermediary Processor acting on behalf of a third-party Controller); and
- Panvaya is the Processor (or Sub-processor, as applicable).
2.2. Scope of Processing: Schedule 1 to this DPA sets out the duration, nature, and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects.
Processing & Documented Instructions
3.1. Instructions: Panvaya shall process Customer Personal Data only on documented instructions from Customer, including with respect to transfers of Customer Personal Data outside the EEA or UK, unless required to do so by applicable Union, Member State, or national statutory law to which Panvaya is subject.
3.2. Scope of Instructions: The Principal Agreement, this DPA, and Customer’s configuration or programmatic utilization of the Services (via dashboard, API calls, or webhooks) constitute Customer’s complete and finalized instructions to Panvaya.
3.3. Compliance with Law: Panvaya shall promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law.
Confidentiality & Personnel
Panvaya shall ensure that all persons authorized by Panvaya to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Personnel access to Customer Personal Data is restricted strictly to authorized individuals who require access to perform maintenance, support, or fulfillment of the Services.
Technical & Organizational Measures (TOMs)
5.1. Implementation: Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Panvaya shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to that risk.
5.2. Current Measures: The technical and organizational measures implemented by Panvaya as of the Effective Date are set forth in Schedule 2 of this DPA. Customer acknowledges that technical measures are subject to continuous technical progress and that Panvaya may update or modify such measures from time to time, provided that such updates do not materially diminish the overall security of the Services.
Sub-processors & Third Parties
6.1. General Authorization: Customer hereby grants Panvaya general written authorization to engage Sub-processors to assist in delivering the Services. Panvaya maintains a list of approved infrastructure Sub-processors, which currently includes:
- Amazon Web Services, Inc. (AWS): Cloud hosting, managed database infrastructure, cloud storage, and automated backups.
- Cloudflare, Inc.: Content delivery network, edge DNS, DDoS protection, and Web Application Firewall (WAF).
- PCI-DSS Certified Payment Gateways: Subscription billing and payment processing (where applicable).
6.2. Sub-processor Agreements: Where Panvaya engages a Sub-processor, Panvaya shall enter into a written agreement imposing data protection obligations no less protective than those imposed upon Panvaya under this DPA.
6.3. Liability: Panvaya remains responsible to Customer for the performance of its Sub-processors’ obligations to the extent required by Applicable Data Protection Law.
Data Subject Rights Assistance
Taking into account the nature of the processing, Panvaya shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to requests by Data Subjects exercising their statutory rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, objection, and data portability).
If a Data Subject makes a request directly to Panvaya, Panvaya shall promptly advise the Data Subject to submit their request to Customer, and shall notify Customer without undue delay.
Personal Data Breach Notification
8.1. Notification: Panvaya shall notify Customer without undue delay (and in any event within forty-eight (48) to seventy-two (72) hours) after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
8.2. Breach Details: To the extent available, such notification shall describe: (a) the nature of the Personal Data Breach; (b) the categories and approximate number of Data Subjects and records concerned; (c) the likely consequences of the breach; and (d) measures taken or proposed to mitigate its potential adverse effects.
8.3. Cooperation: Panvaya shall provide reasonable cooperation to assist Customer in fulfilling its regulatory breach reporting obligations under Articles 33 and 34 of the GDPR.
Deletion & Return of Personal Data
Upon termination of the Principal Agreement or upon Customer’s authenticated request, Panvaya shall, at Customer’s election, delete or return all Customer Personal Data in its possession or control within thirty (30) days, and delete existing copies unless Applicable Data Protection Law or mandatory statutory record-keeping obligations require continued storage.
Audits & Regulatory Cooperation
Panvaya shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA, and shall allow for and contribute to audits conducted by Customer or an independent auditor mandated by Customer (at Customer’s sole expense and subject to customary confidentiality undertakings and advance notice of at least thirty (30) days).
International Transfers & EU SCCs
11.1. Transfer Mechanism: Where Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to countries that have not been recognized as providing an adequate level of data protection, the parties agree that the Standard Contractual Clauses (Module Two: Controller-to-Processor) shall be incorporated into this DPA by reference.
11.2. Clause Hierarchy: In the event of any conflict between the terms of this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.
Liability & Governing Law
12.1. Liability Cap: Any liability arising under or in connection with this DPA shall be subject to the limitations and exclusions of liability set forth in the Principal Agreement.
12.2. Governing Law: This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions of the Principal Agreement, except where Applicable Data Protection Law requires otherwise.
Schedule 1: Details of Data Processing
- Subject Matter of Processing: The provision of real-time container tracking, sailing schedule lookup, demurrage analytics, and developer logistics APIs under the Principal Agreement.
- Duration of Processing: The term of the Principal Agreement, plus the period until all Customer Personal Data is deleted or returned in accordance with Section 9.
- Nature and Purpose of Processing: Ingestion of shipment references (container numbers, Bills of Lading, booking numbers), retrieval and normalization of carrier milestones, calculation of arrival estimates, and delivery of notifications.
- Categories of Data Subjects: Customer employees, contractors, beneficial cargo owners, shippers, consignees, and freight forwarding representatives.
- Categories of Personal Data: Business contact information (names, corporate email addresses, company name, job titles), user authentication credentials (hashed), IP addresses, and shipment identifiers that may associate with identifiable individuals.
Schedule 2: Technical & Organizational Measures (TOMs)
Panvaya maintains the following technical and organizational security controls:
Enforced TLS 1.3 encryption on all public endpoints. AES-256 encryption at rest for managed databases, persistent storage, and automated snapshot backups.
Database clusters reside in private VPC subnets with no public internet routing. Access is mediated strictly via authenticated internal microservices.
Salted one-way password hashing. Irreversible SHA-256 hashing for B2B developer API keys. Principle of least privilege enforced across all services.
Logical data segregation enforces organization-level boundaries, ensuring shipment references cannot be enumerated or accessed across accounts.
Custom Bilateral Execution
Panvaya Logistics Compliance Desk
If your organization requires a countersigned bilateral DPA executed via DocuSign, please contact: [email protected]