Data Processing Addendum
Last updated: 30 September 2026
This Data Processing Addendum forms part of the agreement between the merchant (the controller) and Camille Brand, a sole trader trading as FulfillIQ (the processor) whenever FulfillIQ processes merchant customer data. It takes effect when the merchant accepts the Terms or otherwise starts using the service.
1. Processing instructions and details
FulfillIQ processes personal data only to provide and secure the service under the merchant’s documented instructions, including the Terms, workspace settings and authorised support requests, unless UK law requires otherwise. FulfillIQ will tell the merchant if an instruction appears to infringe applicable data-protection law, unless prohibited by law.
The processing covers shipment-exception monitoring, ticketing, evidence, communications and merchant-authorised actions for the term of the agreement and the deletion lifecycle in the Privacy Notice. Data subjects are merchant customers, recipients, staff users and support contacts. Data includes names, email addresses, order and shipment identifiers, carrier events, ticket history and communications. Special-category data is not intentionally requested.
2. Confidentiality and security
FulfillIQ limits access to authorised people under confidentiality duties and applies measures appropriate to the risk, including tenant isolation, least privilege, authentication, encryption in transit and at rest, encrypted integration credentials, logging, authenticated webhooks, controlled automation, resilience and security testing.
3. Subprocessors and international transfers
The merchant gives general written authorisation for FulfillIQ to use subprocessors needed to provide the service. FulfillIQ will impose materially equivalent data-protection obligations, remain responsible for their processing as required by law, provide notice of a material new subprocessor and allow a reasonable objection based on data-protection grounds. Restricted transfers use an applicable UK safeguard or adequacy regulation.
4. Individual rights and compliance assistance
Taking account of the nature of processing and information available, FulfillIQ will reasonably assist the merchant with verified requests for access, correction, deletion, restriction, objection and portability, and with security obligations, breach notifications, impact assessments and regulator consultations. FulfillIQ will not respond substantively to an end customer except on the merchant’s instructions or where legally required.
5. Personal-data incidents
FulfillIQ will notify an affected merchant without undue delay after becoming aware of a confirmed personal-data breach involving that merchant’s data and will provide available information reasonably needed for assessment and notification.
6. Return and deletion
At termination or on a verified instruction, FulfillIQ will delete or return personal data unless law requires retention. Deleted data is put beyond use in the live service and expires from managed backups under the provider lifecycle.
7. Information and audits
FulfillIQ will provide information reasonably necessary to show compliance with these obligations and cooperate with proportionate audits or inspections. Audits must protect other customers, security and confidentiality, use existing independent evidence where reasonable, and avoid unnecessary disruption. The merchant pays its audit costs unless the audit identifies a material breach by FulfillIQ.
8. Contact and precedence
Data-protection questions and instructions should be sent to hello@fulfilliq.co.uk. If this Addendum conflicts with the Terms on processing merchant customer data, this Addendum prevails.