This Addendum governs how PrintClose™ handles personal information about your customers. You are the controller, we are the processor, and this sets out exactly what that means: what we will and will not do with your contact data, who else touches it, how fast we tell you if something goes wrong, and when it gets deleted. It applies automatically to every account with nothing to sign.
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you (the "Member") and PrintClose LLC ("PrintClose™," "we," "us"). It applies automatically to every account. You do not need to sign anything for it to be in force.
It governs our processing of personal information about your customers and contacts, which we refer to as Contact Data.
You are the controller. You decide whose information goes into the Service, why, and what messages they receive. We are the processor. We handle that information only to run the Service for you.
For information about you as our customer, such as your account and billing details, we are the controller and our Privacy Policy applies instead.
If you need a countersigned copy of this DPA for your own records or for a client's procurement process, email support@printclose.com and we will send one.
We process Contact Data only on your documented instructions. Your instructions consist of the Terms of Service, this DPA, and your configuration and use of the Service, including the campaigns, automations, and imports you set up.
We may use aggregated, de-identified data that cannot reasonably be linked to any individual, member, or contact, for security monitoring, capacity planning, and product improvement. We will not attempt to re-identify it.
If we believe an instruction from you violates Data Protection Laws, we will tell you and may decline to carry it out.
We treat Contact Data as confidential. Access is limited to personnel who need it to operate or support the Service, each of whom is bound by written confidentiality obligations that survive the end of their engagement.
Access is role-based and logged. Support staff access an account's data only when responding to a request from that member or investigating a security, deliverability, or abuse issue.
We implement and maintain appropriate technical and organizational measures designed to protect Contact Data, described in Annex II. We review them periodically and may update them, provided the level of protection is not reduced.
You are responsible for security on your side: keeping credentials safe, controlling who in your business has an account, removing access for people who leave, and configuring the Service appropriately for the sensitivity of the data you upload.
You give us general authorization to engage subprocessors to help deliver the Service. Our current subprocessors, with their function and processing location, are published at printclose.com/subprocessors.
If you reasonably object to a new subprocessor on data protection grounds, tell us within 30 days of notice and we will work with you to find an alternative. If no reasonable alternative exists, you may terminate the affected part of the Service and we will refund any prepaid, unused fees for it.
Mobile carriers are not subprocessors in the usual sense. They are independent parties who must receive a phone number and message content in order to deliver a text, in the same way a postal service must see an envelope. We cannot deliver messages without them and cannot impose processing terms on them.
Because you are the controller, requests from your contacts to access, correct, delete, or port their information are yours to answer. We give you the tools to do it: search, export, edit, and delete any contact record from your account at any time.
If a data subject contacts us directly about data we process for you, we will not respond substantively. We will refer them to you and notify you promptly, unless law requires otherwise.
We will provide reasonable assistance, taking into account the nature of the processing, with your obligations around data subject requests, data protection impact assessments, and prior consultation with a supervisory authority.
If a contact asks to stop receiving messages, by replying STOP to a text or by clicking an unsubscribe link in an email, we honor it immediately and suppress them, without waiting for your instruction. That is required by carrier rules and consumer protection law, and it protects you too.
If we become aware of a Security Incident affecting Contact Data, we will notify you without undue delay and in any case within 72 hours of becoming aware.
Our notice will describe, to the extent known at the time:
We will provide reasonable cooperation and information to help you meet any notification obligations you have to regulators or data subjects. Notifying us of an incident is not an admission of fault by either of us.
You can export Contact Data at any time while your account is active and throughout the retention period after it ends.
After your subscription ends, we retain Contact Data for 12 months so that it can be restored if you reactivate. During that period it is not used for any purpose other than storage and, at your request, export or restoration. We will email the account owner at least 30 days before the 12-month period ends. At the end of it, Contact Data is permanently deleted, in accordance with the schedule in the Refund and Cancellation Policy.
You may instruct us to delete Contact Data sooner at any time by emailing support@printclose.com, and we will do so, except for the records described below.
We retain certain records beyond that point where law or carrier requirements oblige us to, specifically opt-out, unsubscribe, and suppression records, consent attestations, and message delivery logs. Those records remain subject to this DPA for as long as we hold them.
Deleted data may persist in routine backups for up to 35 days, after which it is overwritten.
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including the descriptions in the Annexes and responses to a reasonable security questionnaire.
If that information is not sufficient for a specific compliance obligation you can identify, you may request an audit no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or affect other members' data. You bear the cost of the audit.
We are based in the United States. The Service is intended for shops operating in the United States and messaging recipients in the United States. Some of our subprocessors are headquartered or process data outside the United States, as listed on the Subprocessors page, and each is bound by written data protection terms no less protective than this DPA.
If you instruct us to process Contact Data about individuals in the UK or EEA, the applicable Standard Contractual Clauses, or UK Addendum, are incorporated into this DPA by reference, with you as data exporter and us as data importer, module two. Email support@printclose.com for an executed copy.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
If this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA controls. On every other subject, the Terms control. If this DPA conflicts with the Standard Contractual Clauses where they apply, the Clauses control.
We may update this DPA where required by changes in law, in the Service, or in our subprocessors. Material changes are announced with at least 30 days' notice and the "Last updated" date at the top of the page is revised. Changes that reduce the protection given to Contact Data will not be made without your consent.
Provision of the PrintClose™ Service to the Member, for the duration of the Member's subscription plus the retention periods described in section 09.
Hosting, storing, organizing, and transmitting Contact Data in order to capture leads, send and receive SMS, MMS, email, and voice communications on the Member's behalf, follow up on quotes, re-engage past customers, request reviews, schedule and track production, and produce reporting for the Member.
None. The Service is not designed for and must not be used to process special category or sensitive personal data, government identifiers, financial account numbers, or health information about contacts.
Continuous, for as long as the Member's subscription is active.
The measures below are those we maintain. They are described honestly rather than aspirationally, and they will grow as the business does.