Legal · Data Processing

Data Processing Addendum

Last updated: September 22, 2026

This Addendum governs how PrintClose™ handles personal information about your customers. You are the controller, we are the processor, and this sets out exactly what that means: what we will and will not do with your contact data, who else touches it, how fast we tell you if something goes wrong, and when it gets deleted. It applies automatically to every account with nothing to sign.

01 Scope & Roles

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you (the "Member") and PrintClose LLC ("PrintClose™," "we," "us"). It applies automatically to every account. You do not need to sign anything for it to be in force.

It governs our processing of personal information about your customers and contacts, which we refer to as Contact Data.

Who is who

You are the controller. You decide whose information goes into the Service, why, and what messages they receive. We are the processor. We handle that information only to run the Service for you.

For information about you as our customer, such as your account and billing details, we are the controller and our Privacy Policy applies instead.

If you need a countersigned copy of this DPA for your own records or for a client's procurement process, email support@printclose.com and we will send one.

02 Definitions

  • Contact Data: personal information about your customers, prospects, and other individuals that you upload to or collect through the Service.
  • Data Subject: the individual the Contact Data is about.
  • Data Protection Laws: all privacy and data protection laws that apply to the processing, including the California Consumer Privacy Act as amended, the Texas Data Privacy and Security Act, other US state privacy laws, and the UK and EU GDPR where applicable.
  • Subprocessor: a third party we engage to process Contact Data on our behalf.
  • Security Incident: a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Contact Data.
  • Controller, processor, and processing carry the meanings given in applicable Data Protection Laws.

03 Our Processing Instructions

We process Contact Data only on your documented instructions. Your instructions consist of the Terms of Service, this DPA, and your configuration and use of the Service, including the campaigns, automations, and imports you set up.

We will not

  • Sell or share Contact Data, as those terms are defined under US state privacy laws.
  • Use Contact Data to market our own products to your contacts.
  • Combine Contact Data from your account with data from another member's account, or with data obtained from any other source.
  • Retain, use, or disclose Contact Data for any purpose outside our direct business relationship with you, or outside the permitted purposes in this DPA.

We may use aggregated, de-identified data that cannot reasonably be linked to any individual, member, or contact, for security monitoring, capacity planning, and product improvement. We will not attempt to re-identify it.

If we believe an instruction from you violates Data Protection Laws, we will tell you and may decline to carry it out.

04 Confidentiality

We treat Contact Data as confidential. Access is limited to personnel who need it to operate or support the Service, each of whom is bound by written confidentiality obligations that survive the end of their engagement.

Access is role-based and logged. Support staff access an account's data only when responding to a request from that member or investigating a security, deliverability, or abuse issue.

05 Security Measures

We implement and maintain appropriate technical and organizational measures designed to protect Contact Data, described in Annex II. We review them periodically and may update them, provided the level of protection is not reduced.

You are responsible for security on your side: keeping credentials safe, controlling who in your business has an account, removing access for people who leave, and configuring the Service appropriately for the sensitivity of the data you upload.

06 Subprocessors

You give us general authorization to engage subprocessors to help deliver the Service. Our current subprocessors, with their function and processing location, are published at printclose.com/subprocessors.

Our obligations

  • We impose data protection terms on each subprocessor that are no less protective than those in this DPA.
  • We remain fully liable to you for a subprocessor's performance.
  • We give at least 30 days' notice before adding or replacing a subprocessor. Notice goes to the email address on your account. To receive it at a different address, email support@printclose.com.

Your right to object

If you reasonably object to a new subprocessor on data protection grounds, tell us within 30 days of notice and we will work with you to find an alternative. If no reasonable alternative exists, you may terminate the affected part of the Service and we will refund any prepaid, unused fees for it.

Worth knowing

Mobile carriers are not subprocessors in the usual sense. They are independent parties who must receive a phone number and message content in order to deliver a text, in the same way a postal service must see an envelope. We cannot deliver messages without them and cannot impose processing terms on them.

07 Assisting With Data Subject Requests

Because you are the controller, requests from your contacts to access, correct, delete, or port their information are yours to answer. We give you the tools to do it: search, export, edit, and delete any contact record from your account at any time.

If a data subject contacts us directly about data we process for you, we will not respond substantively. We will refer them to you and notify you promptly, unless law requires otherwise.

We will provide reasonable assistance, taking into account the nature of the processing, with your obligations around data subject requests, data protection impact assessments, and prior consultation with a supervisory authority.

The one exception

If a contact asks to stop receiving messages, by replying STOP to a text or by clicking an unsubscribe link in an email, we honor it immediately and suppress them, without waiting for your instruction. That is required by carrier rules and consumer protection law, and it protects you too.

08 Security Incidents

If we become aware of a Security Incident affecting Contact Data, we will notify you without undue delay and in any case within 72 hours of becoming aware.

Our notice will describe, to the extent known at the time:

  • The nature of the incident and the categories and approximate number of records affected.
  • The likely consequences.
  • The measures taken or proposed to address it and mitigate harm.
  • A contact point for further information.

We will provide reasonable cooperation and information to help you meet any notification obligations you have to regulators or data subjects. Notifying us of an incident is not an admission of fault by either of us.

09 Deletion & Return of Data

You can export Contact Data at any time while your account is active and throughout the retention period after it ends.

After your subscription ends, we retain Contact Data for 12 months so that it can be restored if you reactivate. During that period it is not used for any purpose other than storage and, at your request, export or restoration. We will email the account owner at least 30 days before the 12-month period ends. At the end of it, Contact Data is permanently deleted, in accordance with the schedule in the Refund and Cancellation Policy.

You may instruct us to delete Contact Data sooner at any time by emailing support@printclose.com, and we will do so, except for the records described below.

We retain certain records beyond that point where law or carrier requirements oblige us to, specifically opt-out, unsubscribe, and suppression records, consent attestations, and message delivery logs. Those records remain subject to this DPA for as long as we hold them.

Deleted data may persist in routine backups for up to 35 days, after which it is overwritten.

10 Audits & Documentation

We will make available the information reasonably necessary to demonstrate compliance with this DPA, including the descriptions in the Annexes and responses to a reasonable security questionnaire.

If that information is not sufficient for a specific compliance obligation you can identify, you may request an audit no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or affect other members' data. You bear the cost of the audit.

11 International Transfers

We are based in the United States. The Service is intended for shops operating in the United States and messaging recipients in the United States. Some of our subprocessors are headquartered or process data outside the United States, as listed on the Subprocessors page, and each is bound by written data protection terms no less protective than this DPA.

If you instruct us to process Contact Data about individuals in the UK or EEA, the applicable Standard Contractual Clauses, or UK Addendum, are incorporated into this DPA by reference, with you as data exporter and us as data importer, module two. Email support@printclose.com for an executed copy.

12 Liability & Order of Precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

If this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA controls. On every other subject, the Terms control. If this DPA conflicts with the Standard Contractual Clauses where they apply, the Clauses control.

13 Changes

We may update this DPA where required by changes in law, in the Service, or in our subprocessors. Material changes are announced with at least 30 days' notice and the "Last updated" date at the top of the page is revised. Changes that reduce the protection given to Contact Data will not be made without your consent.

14 Contact

15 Annex I: Details of Processing

Subject matter and duration

Provision of the PrintClose™ Service to the Member, for the duration of the Member's subscription plus the retention periods described in section 09.

Nature and purpose

Hosting, storing, organizing, and transmitting Contact Data in order to capture leads, send and receive SMS, MMS, email, and voice communications on the Member's behalf, follow up on quotes, re-engage past customers, request reviews, schedule and track production, and produce reporting for the Member.

Categories of data subjects

  • The Member's past, current, and prospective customers.
  • Individuals who contact the Member by phone or through a quote form.
  • The Member's own staff who use the Service.

Categories of personal data

  • Identifiers: name, business name, phone number, email address, postal address.
  • Commercial information: order and quote history, amounts, artwork and job specifications the Member uploads.
  • Communications: message content, replies, call records and voicemail where enabled, and email delivery, bounce, and complaint events.
  • Consent records: opt-in source, timestamp, IP address and user agent for web opt-ins, scope of consent, opt-out and unsubscribe events.
  • Inferences generated by the Service: dormancy status, engagement and campaign response.

Special category data

None. The Service is not designed for and must not be used to process special category or sensitive personal data, government identifiers, financial account numbers, or health information about contacts.

Frequency

Continuous, for as long as the Member's subscription is active.

16 Annex II: Technical & Organizational Measures

The measures below are those we maintain. They are described honestly rather than aspirationally, and they will grow as the business does.

Encryption

  • All traffic to and from the Service is encrypted in transit using TLS 1.2 or higher.
  • Data at rest is encrypted using our hosting provider's managed encryption.

Access control

  • Role-based access. Each member's data is logically separated and inaccessible to other members.
  • Administrative access is limited to personnel who need it, protected by multi-factor authentication, and reviewed periodically.
  • Credentials are held in a managed password vault. Access is revoked on the day a contractor or employee's engagement ends.

Operational security

  • Managed, patched infrastructure from our hosting provider.
  • Automated backups with a rolling 35-day retention window.
  • Application and access logging, retained for security investigation.
  • Monitoring of complaint, bounce, opt-out, and delivery-failure rates for abuse and deliverability signals, with automatic suppression of addresses that hard bounce or file complaints.
  • Webhooks and unsubscribe links are cryptographically signed so they cannot be forged.

Organizational

  • Written confidentiality obligations for all personnel and contractors, along with a written intellectual property assignment.
  • A documented incident response process, including the 72-hour notification commitment in section 08.
  • Subprocessor due diligence before engagement and written data protection terms with each.

Data minimization

  • We collect only what the Service needs to function.
  • Retention is time-limited and published in the Refund and Cancellation Policy.
  • Message content is deleted on a shorter schedule than delivery metadata, because the metadata is what compliance requires and the content is not.
Scroll to Top