• We’re Hiring – Apply Here
  • [email protected]
  • Request a Demo
  • Sign In
Globe
USA
Canada
UK
Australia
Hit enter to search or ESC to close
PostGrid
Sign Up
  • Products
    • Print & Mail API
    • Address Verification
  • Solutions
    • Teams
      • Developers
      • Compliance
      • Marketing
      • Finance
      • Customer Success
    • Industries
      • Insurance
      • Retail & Ecommerce
      • Financial Services
      • Real Estate
      • Healthcare
    • Integrations
      • Zapier
      • Hubspot
      • Marketo
      • Salesforce
      • Quickbooks
    • Image
      • img
      • GET THE BOOK
  • Developers
    • API Docs
    • Quickstart Guide
    • GitHub
  • How It Works
  • Company
    • PostGrid
      • About Us
      • Why Us
      • Careers
      • Contact Us
    • Partnership
      • Print Partner
      • Integration Partners
      • Technology Partners
      • Become a Partner
    • Resources
      • API Docs
      • Blogs
      • E-Books
      • Whitepapers
    • SUPPORT
      • Talk To Sales
      • Dev Support
      • Request a Demo
      • Status
  • Pricing
    • Print & Mail
    • Address Verification
  • REQUEST DEMO
  • SIGN UP
PostGrid
  • Products
    • Print & Mail API
    • Address Verification
  • Solutions
    • Teams
      • Developers
      • Compliance
      • Marketing
      • Finance
      • Customer Success
    • Industries
      • Insurance
      • Retail & Ecommerce
      • Financial Services
      • Real Estate
      • Healthcare
    • Integrations
      • Zapier
      • Hubspot
      • Marketo
      • Salesforce
      • Quickbooks
    • Image
      • img
      • GET THE BOOK
  • Developers
    • API Docs
    • Quickstart Guide
    • GitHub
  • How It Works
  • Company
    • PostGrid
      • About Us
      • Why Us
      • Careers
      • Contact Us
    • Partnership
      • Print Partner
      • Integration Partners
      • Technology Partners
      • Become a Partner
    • Resources
      • API Docs
      • Blogs
      • E-Books
      • Whitepapers
    • SUPPORT
      • Talk To Sales
      • Dev Support
      • Request a Demo
      • Status
  • Pricing
    • Print & Mail
    • Address Verification

Data Processing Addendum

The customer agreeing to these terms (“Customer”), and PostGrid Inc. (“PostGrid”) have entered into an agreement under which PostGrid has agreed to provide certain services to Customer (as amended from time to time, the “Agreement”).

This Data Processing Addendum (the “DPA”) is an addendum to the Agreement and is governed by the terms and conditions of the Agreement.

Definitions

  1. Breach means a breach by PostGrid of its security obligations in this DPA that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in PostGrid’s possession, provided by Customer to PostGrid for processing under the Agreement.
  2. Data Protection Laws means (i) the General Data Protection Regulation 2016/679 (“GDPR”), (ii) the California Consumer Privacy Act of 2018 (the “CCPA”), as amended from time to time an (iii) and other privacy and data protection laws that are applicable to the Services provided by PostGrid under the Agreement.
  3. Personal Data means any information relating to an identified natural person or a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, in each case that is provided by Customer to PostGrid for processing under the Agreement (each such person a “data subject”).
  4. “Process” or “process” (whether or not capitalized) means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  5. “Standard Contractual Clauses” means the Standard Contractual Clauses for the transfer of Personal Data to Processors approved by EC Commission Decision of 5 February 2010 or any successor clauses adopted in accordance with GDPR Article 28(8).

Handling of Personal Data.

  1. Relationship of the Parties: Customer (the controller) appoints PostGrid as a processor to process Personal Data: (a) for the purposes described in the Agreement, or (b) with Customer’s prior written consent (collectively the “Permitted Purpose”). PostGrid is a service provider to the Customer under the CCPA. Each party will comply with the obligations that apply to it under the applicable Data Protection Laws. The details of the transfer and in particular the special categories of Personal Data where applicable are specified in the attached Exhibit A and incorporated herein by this reference.
  2. Cooperation and Data Subjects’ Rights: PostGrid will provide reasonable and timely assistance to Customer (at Customer’s expense) to enable Customer to respond to: (a) any request from a data subject to exercise any of its rights under Data Protection Laws (including its rights of access, correction, objection, erasure and data portability, as applicable); and (b) any other correspondence, enquiry or complaint received from a data subject, regulator or other third party in connection with the processing of the  Personal Data. If any such request, correspondence, enquiry, or complaint is made directly to PostGrid, PostGrid will promptly inform Customer providing full details of the same.
  3. Personal Data Return and Disposal: Within 30 days after a written request by Customer or the termination or expiration of the Agreement, PostGrid will: (a) securely destroy all Personal Data in PostGrid’s possession in a manner that makes such Personal Data non-readable and non-retrievable. Notwithstanding the foregoing, PostGrid may retain copies of Personal Data: (x) to the extent PostGrid has a separate legal right or obligation to retain some or all of the Personal Data; (y) in the capacity of a data controller for PostGrid’s business operations (such as in email records, customer support or accounting records), and (z) in backup systems until the backups have been overwritten or expunged in accordance with PostGrid’s backup policy.
  4. International Transfers: To the extent PostGrid processes (or causes to be processed) any Personal Data originating from the EEA in a country that has not been designated by the European Commission as providing an adequate level of protection for Personal Data, the Personal Data shall be deemed to have adequate protection (within the meaning of EU data protection legislation). The parties will enter into the Standard Contractual Clauses whereby Customer will be regarded as the data exporter and PostGrid will be regarded as the data importer.
  5. Subprocessing: PostGrid may engage, and Customer hereby consents to PostGrid’s engagement of, PostGrid affiliates and third-party sub-processors to process Personal Data for the Permitted Purpose. A list of sub-processors engaged by PostGrid as of the date of signing this DPA will be provided on Customer’s request,if required to do so under the applicable Data Protection Laws and provided that Customer enter into a separate confidentiality agreement as required by PostGrid, at its sole discretion. PostGrid will impose data protection terms on any sub-processor it appoints as required to protect Personal Data to the standard required by the applicable Data Protection Laws. Customer may object to PostGrid’s appointment or replacement of a sub-processor prior to its appointment or replacement, provided such objection is based on reasonable grounds relating to data protection. In such an event, PostGrid will either not appoint or replace the sub-processor or, if this is not possible, Customer may suspend or terminate the Agreement without penalty.
  6. Data Protection Impact Assessment: PostGrid will provide reasonable cooperation to Customer (at Customer’s expense) in connection with any data protection impact assessment that Customer may be required to perform under EU Data Protection Law.
  7. Compliance with Laws: PostGrid and Customer shall at all times comply with Data Protection Laws with respect to the Personal Data.

PostGrid Security Measures.

  1. Security in PostGrid-Managed Deployments: PostGrid shall implement procedural, technical, and administrative safeguards to protect from accidental or unlawful destruction of Personal Data in storage and protect against any loss, alteration, unauthorized disclosure of or access to Personal Data.
  2. Audit: The requirements of GDPR Article 28 and Clauses 5(f) and 12(2) of the Standard Contractual Clauses will be satisfied as follows. On Customer’s request and subject to the confidentiality obligations set forth in the Agreement or an appropriate non-disclosure agreement, Customer may contact PostGrid in accordance with the “Notices” Section of the Agreement to request an audit, not more than once per year, of the procedures relevant to the protection of Personal Data. Before the commencement of any such audit, Customer and PostGrid shall mutually agree upon the scope, timing, and duration of the audit and the reimbursement rate for any travel or other expenses PostGrid incurs in the course of such audit. All reimbursement rates shall be reasonable, taking into account the resources expended by PostGrid. Customer shall promptly notify PostGrid with information regarding any non-compliance discovered during the course of an audit.

Customer Security Measures.

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Customer shall maintain appropriate technical and organizational measures for the protection of Personal Data, including without limitation the following:

  1. PostGrid Permission to Access Customer Databases: In order to use the Services, Customer must authorize the Services to access Customer’s databases. When granting authorization, Customer must follow the principle of least privilege to Customer database information.

Data Breach Notification and Resolution.

  1. Breach Notice: If it becomes aware of a confirmed Breach, PostGrid shall inform Customer via email without undue delay. PostGrid shall further take any such reasonably necessary measures and actions to remedy or mitigate the effects of the Breach and will keep Customer informed of all material developments in connection with the Breach.
  2. Cooperation: PostGrid will provide reasonable information and cooperation to Customer so that Customer can fulfill any data breach reporting obligations it may have under (and in accordance with the timescales required by) applicable law.

Miscellaneous

  1. Construction; Interpretation: This DPA is not a standalone agreement and is only effective if an Agreement is in effect between PostGrid and Customer. This DPA is part of the Agreement and is governed by its terms and conditions (including limitations of liability set forth therein). This DPA and the Agreement are the complete and exclusive statement of the mutual understanding of the parties and supersede and cancel all previous written and oral agreements and communications relating to the subject matter hereof. Headings contained in this DPA are for convenience of reference only and do not form part of this DPA.
  2. Severability: If any provision of this DPA is adjudicated invalid or unenforceable, this DPA will be amended to the minimum extent necessary to achieve, to the maximum extent possible, the same legal and commercial effect originally intended by the parties. To the extent permitted by applicable law, the parties waive any provision of law that would render any clause of this DPA prohibited or unenforceable in any respect.
  3. Amendment, Enforcement of Rights: No modification of or amendment to this DPA, nor any waiver of any rights under this DPA, will be effective unless in writing signed by the parties to this DPA. The failure by either party to enforce any rights under this DPA will not be construed as a waiver of any rights of such party.
  4. Assignment: This DPA may be assigned only in connection with a valid assignment pursuant to the Agreement. If the Agreement is assigned by a party in accordance with its terms, this DPA will be automatically assigned by the same party to the same assignee.
  5. Governing Law: This DPA will be governed by and construed in accordance with the laws of the jurisdiction governing the Agreement unless otherwise required by EU Data Protection Law, in which case this DPA will be governed by the laws of the Republic of Ireland.

Exhibit A

This Exhibit A describes the details of the processing and serves the purposes of satisfying the requirements of GDPR Article 28.

Subject matter, nature and purpose:

As a PostGrid Customer, you are the Controller and determine how and when you use the Services. PostGrid Users are your employees that use the Services. Categories of data:

  1. Information about PostGrid Users. This information about PostGrid Users includes end-user login/registration information for PostGrid Users as well as metadata about their usage.
  2. Information about Customer clients: This information about Customer clients includes name, address, contact information, bank information, invoicing information and any other information provided by Customer to PostGrid for Processing.

Duration: For the Term of the Agreement between PostGrid and Customer.

Data subjects: Customer employees and clients

Categories of data

Personal data may include any category of personal data, including without limitation:

  • Name
  • Email address
  • Cookie Information
  • Device Identifiers, IP-address and other online identifiers
  • Account log-in details and passwords
  • Telephone/mobile number
  • Location Data
  • Mailing Address
  • Financial information

Processing operations

The Personal Data transferred will be subject to the following basic processing activities:

For Customer employees: logging into and accessing the portal

For Customer clients: Formatting into print materials, mailing print materials to clients

Best-in-class Enterprise Ready Data Security & Compliance Certifications

Hipaa Compliant
Soc 2
Pci Dss Compliant
Pipeda Compliant
Phipa Compliant

Company

  • About Us
  • Why Us
  • How It Works
  • Sustainability
  • Careers
  • Blogs
  • Address Coverage
  • Template Gallery
  • Request a Demo
  • Partner With Us
  • Talk To Sales

Products & Features

  • Letter API
  • Postcard API
  • Cheque API
  • Address Verification API
  • Address Autocomplete API
  • Address Lookup API
  • Address Standardization API
  • Geocoding API
  • Address Verification Software
  • Bulk Address Verification
  • International Address Verification

Integrations

  • Salesforce Address Verification
  • Salesforce Direct Mail
  • HubSpot Direct Mail
  • Zapier Direct Mail
  • Klaviyo Direct Mail
  • ActiveCampaign Direct Mail
  • Customer.io Direct Mail
  • Stripe Direct Mail
  • MS Dynamics 365 Direct Mail
  • View All Integration
  • Integration Guides

Print & Mail Resources

  • Print & Mail Documents
  • Print & Mail Service
  • Print & Mail Letters
  • Print & Mail Postcards
  • Print & Mail Cheques
  • Print & Mail Invoices
  • Print & Mail Statements
  • Print & Mail Brochures
  • Plastic Postcards
  • Check Mailing Service
  • Print & Mail API

Direct Mail Resources

  • Direct Mail Automation Software
  • Direct Mail API
  • Direct Mail Service
  • Direct Mail Marketing
  • Letterbox Advertising Cost
  • Direct Mail for Healthcare
  • Direct Mail Guide
  • Healthcare
  • Bulk Mailing Services
  • Best Direct Mail Companies
  • Automated Direct Mail
PostGrid
  • PostGrid
  • Status
  • Legal
  • Security
  • Contact Us
  • Sitemap
  • USA
  • Canada
  • UK
  • Australia

Copyright 2026, PostGrid. PostGrid™ and Post Grid™ are Registered Trademarks of PostGrid Inc. All rights reserved.

Request a Demo

Talk with a specialist about getting started with PostGrid.

  • This field is for validation purposes and should be left unchanged.
×
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Read MoreACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT