This data processing addendum (DPA) forms part of the Printer's Friend terms of service, version 2026-10-09, at printersfriend.com/terms, which are incorporated by reference. It is made between Printer's Friend, Australia (Printer's Friend, the processor) and the business that holds the workspace (Customer, the controller). It takes effect when Customer accepts the terms at signup or, for a signed copy, on the date both parties sign below. It is written to meet GDPR Article 28, the UK GDPR, the California CCPA and the Australian Privacy Principles.
Customer is the controller of the personal data it loads into its workspace. Printer's Friend is the processor and acts only on Customer's documented instructions, which are the use of the platform's features as described in the help centre and the docs.
Personal data of Customer's end users (the shop's customers, their contacts, portal users and Customer's own staff) processed through the Printer's Friend platform to provide the service.
For the term of the subscription, plus the 30 day read-only window after a cancellation described in clause 13.
Storage, organisation, retrieval, transmission, alignment, combination, restriction and erasure of personal data, as required to provide the platform features Customer uses.
Customer's end users: business contacts at organisations Customer sells to, consumers buying through Customer's portal, team stores and campaign pages, walk-in customers who use the kiosk, and Customer's own staff.
Name, email, phone, postal address, billing details, order history, messages, artwork files (which may contain personal data such as names and numbers), and any free text the data subject submits.
Customer authorises the following subprocessors. The same list is published at printersfriend.com/privacy#subprocessors. We notify Customer by email 30 days before adding or replacing a subprocessor. Customer may object within that period; if we cannot resolve the objection, Customer may terminate without penalty and the clause 13 windows apply.
| Subprocessor | Location | Purpose | When |
|---|---|---|---|
| Hetzner Online GmbH | Helsinki, Finland | Application hosting, database and backup storage. | Always. |
| Amazon Web Services (Simple Email Service) | us-east-1, United States | Transactional email delivery from the platform mailer. | Always, unless the shop connects its own email provider. |
| Stripe | United States and Ireland | Subscription billing for Printer's Friend, and customer payments when the shop connects Stripe. | Always for subscription billing; customer payments only when the shop connects Stripe. |
| Twilio | United States | SMS delivery. | Only when the shop connects its own Twilio account. |
| Anthropic | United States | Answers for the Demi assistant. Workspace data is passed as context for the query and is not used for training. | Only when the assistant is enabled. |
| Umami (self-hosted) | Helsinki, Finland, on our own server | Aggregated page view analytics for the marketing site. No third party receives the data. | Only on the marketing site, and only after you accept analytics in the cookie banner. |
Providers that Customer connects itself (its own email service, Twilio, Stripe account, shipping carrier, supplier feed or accounting ledger) are Customer's own processors and are outside this DPA.
The platform and its backups are hosted in Helsinki, Finland. Where personal data leaves the EEA or the UK (transactional email, payments, SMS and the assistant involve subprocessors in the United States), the Standard Contractual Clauses (EU 2021/914) and the UK addendum apply. APP 8 obligations apply for Australian Customers, whose data is held outside Australia.
TLS in transit, encrypted disks at rest, tenant isolation enforced at the database layer, role based access in the workspace, least privilege production access, an append-only activity log, and nightly encrypted backups kept as daily copies for 16 days, then weekly, monthly and yearly copies. Full detail is in the security overview at printersfriend.com/security.
We assist Customer in responding to data subject requests within 30 days. Portal users can download their own data and request deletion from the portal privacy page; a deletion request notifies Customer and us, and Customer can anonymise the person from the workspace with one action. Financial records are retained with personal identifiers removed, as the law requires.
We notify Customer without undue delay and within 72 hours of becoming aware of a personal data breach affecting Customer's data, with the information required under GDPR Article 33.
Customer may audit our compliance once per year on 30 days notice. We may meet this by providing our security documentation, independent assessment reports once issued, and answering reasonable follow-up questions.
When Customer cancels the subscription or closes the workspace, the workspace stays open and read-only for 30 days so Customer can export its data or restart. After that we delete or anonymise all personal data, except where retention is required by law. Customer may request earlier deletion at any point in that window. A failed payment never deletes anything and does not start this window: a lapsed subscription drops the workspace to the free tier with every record intact until Customer restores or cancels it.
Accepting the terms of service at signup accepts this DPA. For a countersigned copy, download the PDF, sign it and send it to hello@printersfriend.com; we return it countersigned within five business days.
|
For Customer Name: ______________________________ Title: ______________________________ Workspace: __________________________ Date: ______________________________ Signature: __________________________ |
For Printer's Friend Name: ______________________________ Title: ______________________________ Date: ______________________________ Signature: __________________________ |