Data Processing Agreement

Version v2026-10. Effective October 2, 2026

This Data Processing Agreement ("DPA") forms part of the agreement under which Dispatchly provides its service to the customer, including the Terms of Service (together, the "Agreement"). It sets out how Dispatchly processes personal data on the customer's behalf, as required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). The customer's account owner accepts it in the Dispatchly dashboard under Settings, Privacy.

1. Parties and roles

  • Processor: Foutje, trading as Dispatchly, a sole proprietorship (eenmanszaak) of Sem Ashby, registered with the Netherlands Chamber of Commerce (KvK) under number 89649540 and established in Balgoij, the Netherlands ("Dispatchly", "we").
  • Controller: the organization that holds a Dispatchly account and on whose behalf the account owner accepts this DPA (the "Customer").

"Customer Personal Data" means the personal data Dispatchly processes on the Customer's behalf to provide the service, as described in Annex 1. The Customer is its controller and Dispatchly is its processor. Where the Customer itself processes the data for its own clients, for example as a fulfilment company, Dispatchly acts as its sub-processor and the Customer is responsible for holding its clients' authorization.

Data that Dispatchly controls itself, such as the logins of the Customer's users, billing details, security logs and website enquiries, is covered by our Privacy Policy, not by this DPA.

2. Instructions

  • Dispatchly processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers outside the European Economic Area, unless EU or Member State law requires otherwise. In that case Dispatchly tells the Customer of that legal requirement before processing, unless the law prohibits it.
  • The Agreement, this DPA and the way the Customer configures and uses the service (for example connecting carrier accounts, inviting users, requesting exports or deleting data) are the Customer's instructions. Further instructions can be given in writing to privacy@dispatch.ly. Where following one takes work the service does not already provide, Dispatchly may charge a reasonable fee agreed in advance.
  • Dispatchly informs the Customer immediately if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection law.
  • The Customer is responsible for the lawfulness of the data it supplies and of its instructions, including having a legal basis and informing the people concerned.

3. Confidentiality

Everyone Dispatchly authorizes to process Customer Personal Data is bound by a duty of confidentiality and has access only as far as their work requires. Dispatchly does not disclose Customer Personal Data to third parties except to sub-processors under section 5 or where the law requires it. A request from a public authority is checked for legal validity, answered with no more data than required, and reported to the Customer unless the law forbids that.

4. Security

  • Dispatchly takes appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing and its risks. The measures in place are described in Annex 2. Dispatchly may change them as long as the overall level of protection is not reduced.
  • The Customer is responsible for security within its own organization in the service: who it invites, the roles it assigns, two-factor authentication for its users, and the API tokens and carrier credentials it creates.
  • The service is not designed for special categories of personal data (Article 9 GDPR) or data about criminal convictions (Article 10 GDPR), and the Customer will not submit such data.

5. Sub-processors

  • The Customer gives Dispatchly general authorization to engage sub-processors. The current sub-processors are listed in Annex 3.
  • Dispatchly notifies the Customer's account owners by email at least 30 days before a new sub-processor starts processing Customer Personal Data, and updates Annex 3. The Customer may object on reasonable data protection grounds within that period. The parties will then look for a solution in good faith. If they find none, the Customer may terminate the affected service before the change takes effect, and Dispatchly refunds any fees paid for the period after termination.
  • Dispatchly imposes on each sub-processor, by contract, data protection obligations that give at least the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organizational measures. Dispatchly remains fully liable to the Customer for its sub-processors' performance of those obligations.
  • Carriers, shipping platforms such as Sendcloud, and other systems the Customer connects are not Dispatchly's sub-processors. The Customer chooses them and has its own relationship with them, and Dispatchly exchanges data with them at the Customer's instruction using the Customer's own credentials.

6. Transfers outside the EEA

The Dispatchly application and its database are hosted in Germany. Some sub-processors in Annex 3 process data outside the European Economic Area. Dispatchly transfers Customer Personal Data outside the EEA only in accordance with Chapter V GDPR: to a country covered by an adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the recipient is certified under it, or under the European Commission's Standard Contractual Clauses.

7. Assistance

  • Requests from individuals. Taking into account the nature of the processing, Dispatchly helps the Customer respond to requests from people exercising their rights under Chapter III GDPR. The service lets account owners export the organization's data as JSON and CSV and delete it. If Dispatchly receives such a request directly, it forwards it to the Customer without undue delay and does not answer it itself unless the Customer asks.
  • Security, breaches and assessments. Taking into account the nature of the processing and the information available to it, Dispatchly helps the Customer meet its obligations under Articles 32 to 36 GDPR, including by providing the information the Customer needs for a data protection impact assessment or a prior consultation.
  • Assistance beyond what the service and this DPA already provide may be charged at a reasonable rate agreed in advance.

8. Personal data breaches

  • Dispatchly notifies the Customer's account owners by email without undue delay, and no later than 24 hours after becoming aware of it, of a personal data breach affecting Customer Personal Data.
  • The notice describes, as far as known: the nature of the breach, including the categories and approximate number of people and records concerned; its likely consequences; the measures taken or proposed; and a contact person. Information not yet available is provided in further notices without undue delay.
  • Dispatchly takes reasonable steps to contain the breach, investigate it and limit its consequences, and records every breach.
  • The Customer decides whether to notify the supervisory authority and the people concerned. Dispatchly does not do so on the Customer's behalf unless the Customer asks.

9. Return and deletion

  • At any time, an account owner can download a full export of the organization's data in JSON and CSV from Settings. Exports are deleted 7 days after they are created.
  • An account owner can delete the organization from Settings. Deletion takes effect 30 days later and can be cancelled until then. The organization's Customer Personal Data is then permanently deleted from the production database. Backups are made daily and only the last 7 are kept, so deleted data is gone from backups within 7 days after that.
  • When the Agreement ends, Dispatchly deletes the Customer Personal Data, or returns it first, at the Customer's choice, on a request from an account owner or to privacy@dispatch.ly. Dispatchly keeps no copy unless EU or Member State law requires it to.

10. Information and audits

  • Dispatchly makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, by the Customer or an auditor it mandates.
  • Information comes first from this DPA and its annexes, Dispatchly's CSA STAR Level 1 self-assessment, and written answers to reasonable security questionnaires.
  • Where that is not sufficient, where a supervisory authority requires it, or after a personal data breach, the Customer may carry out an audit once a year on at least 30 days' written notice. The audit takes place during business hours, without disrupting the service and without access to other customers' data, and is carried out by an auditor bound by confidentiality who is not a competitor of Dispatchly. The Customer bears the cost of the audit. Dispatchly may charge for time it spends on an audit beyond one working day per year, at rates agreed in advance, unless the audit shows that Dispatchly materially failed to meet this DPA.

11. Liability

Each party's liability arising out of or related to this DPA is governed by the Agreement. Nothing in this DPA limits liability that cannot be limited by law, or either party's liability to individuals under Article 82 GDPR.

12. Term, changes and governing law

  • This DPA applies for as long as Dispatchly processes Customer Personal Data. Obligations that by their nature continue, such as confidentiality and deletion, survive its end.
  • Where this DPA and the rest of the Agreement conflict on the processing of personal data, this DPA prevails.
  • Dispatchly may update this DPA to reflect changes in the law, the service or its sub-processors. Each version is published on this page with a new version number, and account owners are told about material changes at least 30 days in advance. A change that reduces the protection of Customer Personal Data applies to a Customer only once its account owner accepts it.
  • This DPA is governed by Dutch law. Disputes are submitted to the competent court in Gelderland, the Netherlands, unless mandatory law provides otherwise.

Annex 1. Description of the processing

Subject matter and purpose
Providing the Dispatchly service: tracking the Customer's parcels across carriers and shipping platforms, detecting where a carrier's service commitments are not met, keeping tickets for follow-up, sending notifications and monthly reports (including a modelled CO2e estimate), and providing support.
Nature of the processing
Receiving data from the Customer's integrations and systems, storing, organizing, analyzing and displaying it to the Customer's users, emailing notifications and reports, exporting it on request, and deleting it.
Categories of people
Recipients and, for returns, senders of the Customer's parcels; the Customer's staff and others whose details appear in tickets, comments or emails the Customer sends to Dispatchly.
Categories of personal data
Tracking numbers and order references; delivery addresses, postcodes and locations; names, and where the Customer's integrations include them, email addresses, phone numbers and delivery instructions; the content of support emails and of raw requests received from the Customer's integrations.
Special categories
None. The service is not designed for them (section 4).
Frequency and duration
Continuous, for as long as the Customer uses the service, until deletion under section 9.

Annex 2. Security measures

  • Encryption in transit. All traffic to Dispatchly uses TLS 1.2 or higher with HSTS. Traffic between Cloudflare and the application server is also TLS, with the origin certificate validated.
  • Encryption at rest. Carrier credentials, webhook and intake secrets, two-factor secrets and recovery codes are encrypted in the application with AES-256. Raw integration requests are stored encrypted. Passwords are stored only as bcrypt hashes.
  • Credential handover. Credentials a customer's IT team hands over through the secure intake are encrypted in their browser (libsodium sealed boxes), and the web tier cannot decrypt them.
  • Separation of customers. Every organization's data is isolated by tenant scoping in the application.
  • Access control. Four roles (owner, admin, agent, viewer), with only owners and admins managing credentials; optional app-based two-factor authentication with recovery codes; a fresh verification for sensitive actions; rate limiting on sign-in; an optional per-organization IP allowlist.
  • Staff access. Administrative access to production is limited to named staff and protected by multi-factor authentication.
  • Logging. A security log records sign-ins and changes to members, roles, credentials and webhooks, and is kept for 540 days. Credentials are removed from application logs, and data exports list credential field names only.
  • Integrity. Inbound and outbound webhooks are signed with HMAC and checked against a replay window.
  • Availability. Daily backups of the application server, of which the last 7 are kept. Cloudflare provides DDoS protection at the network edge.
  • Physical security. Dispatchly has no premises that hold Customer Personal Data. It relies on its hosting providers' data centres, which are ISO 27001 certified.
  • Organization. A written information security policy set, reviewed at least once a year, including an incident and breach response procedure.

Annex 3. Sub-processors

  • Hetzner Online GmbH

    Hosting of the application server and database

    Location of the data: Germany (Falkenstein)

  • Cloudflare, Inc.

    Network edge, TLS and DDoS protection, the web application between the dashboard and the API, and storage of data exports (R2)

    Location of the data: Edge locations worldwide; export storage location chosen by Cloudflare

  • Brevo

    Sending notification and report emails to the Customer's users

    Location of the data: European Union

  • Postmark (ActiveCampaign)

    Receiving support emails sent to Dispatchly ticket addresses

    Location of the data: United States

  • Google Workspace (Google Cloud EMEA Ltd)

    Staff email, where the Customer sends personal data to Dispatchly by email

    Location of the data: Google data centres worldwide

Stripe processes billing details, for which Dispatchly is the controller, and receives no Customer Personal Data.

Contact

Questions about this DPA: privacy@dispatch.ly. Security matters: security@dispatch.ly.