OpenBoxesLift
FeaturesPricingDemoDocsAboutContact
Sign InStart Free Trial

Data Processing Agreement

Last updated: May 14, 2026

Table of Contents

  • Preamble
  • 1. Definitions
  • 2. Scope and Roles
  • 3. Processing of Customer Personal Data
  • 4. Sub-Processors
  • 5. Security Measures
  • 6. International Data Transfers
  • 7. Data Subject Rights
  • 8. Security Incidents
  • 9. Audit Rights
  • 10. Return and Deletion of Data
  • 11. Liability
  • 12. General

Preamble

This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms of Service between OpenBoxes Solutions LLC ("OpenBoxes," "Processor") and the entity that has agreed to the Terms of Service ("Customer," "Controller").

This DPA governs OpenBoxes' processing of Customer Personal Data on behalf of Customer in connection with the Service. It applies to the extent OpenBoxes processes Customer Personal Data in the course of providing the Service.

This DPA is effective on the date the Customer first accesses the Service or otherwise accepts the Terms of Service. Customer accepts this DPA on behalf of itself and, to the extent required by applicable law, on behalf of its affiliates whose Personal Data is processed in connection with the Service.

1. Definitions

  • "Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of Customer Personal Data under this DPA, including the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), the Personal Information Protection and Electronic Documents Act of Canada ("PIPEDA"), and applicable provincial privacy laws in Canada.
  • "Customer Personal Data" means personal information processed by OpenBoxes solely on behalf of Customer in connection with the Service. This includes data Customer uploads to its OpenBoxes Lift instance about Customer's own employees, customers, suppliers, or other third parties.
  • "Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates.
  • "Processing" means any operation performed on Customer Personal Data, whether automated or not.
  • "Sub-Processor" means any third party engaged by OpenBoxes to process Customer Personal Data on its behalf in connection with the Service.
  • "Service" has the meaning given in the Terms of Service.

Capitalized terms not defined here have the meaning given in the Terms of Service or in Applicable Data Protection Law.

2. Scope and Roles

2.1 Roles

For Customer Personal Data, Customer is the data controller (or business, under CCPA/CPRA) and OpenBoxes is the data processor (or service provider). OpenBoxes processes Customer Personal Data only on documented instructions from Customer.

2.2 Customer's Instructions

The Terms of Service, this DPA, the Service's documentation, and Customer's use of the Service constitute Customer's documented instructions to OpenBoxes to process Customer Personal Data for the purposes of providing the Service. Customer may issue additional instructions in writing; OpenBoxes will inform Customer if it considers an instruction to violate Applicable Data Protection Law before complying.

2.3 Customer's Responsibilities

Customer represents and warrants that: (a) it has the legal basis to provide Customer Personal Data to OpenBoxes; (b) it has provided required notices and obtained required consents from Data Subjects; (c) its use of the Service complies with Applicable Data Protection Law; and (d) the data it uploads to its OpenBoxes instance does not include sensitive personal information beyond what is appropriate for a supply-chain management context.

3. Processing of Customer Personal Data

3.1 Subject Matter and Duration

Subject matter: Customer's use of the Service. Duration: for the term of the Terms of Service plus the retention periods set out in our Privacy Policy.

3.2 Nature and Purpose

OpenBoxes processes Customer Personal Data to provide, secure, and improve the Service, including hosting, transmission, storage, retrieval, encryption, backup, security monitoring, billing, support, and other operations necessary to provide the Service.

3.3 Categories of Data and Data Subjects

Categories of Customer Personal Data depend on what Customer uploads to its instance, and may include identifiers, contact information, professional information, and operational data of Customer's employees, customers, and suppliers. Categories of Data Subjects: Customer's authorized users, employees, customers, suppliers, and other third parties whose information Customer chooses to include in its OpenBoxes instance.

3.4 Confidentiality

OpenBoxes ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory.

4. Sub-Processors

4.1 Authorization

Customer provides general authorization for OpenBoxes to engage Sub-Processors to process Customer Personal Data, subject to the conditions in this Section 4.

4.2 Current Sub-Processors

The current list of Sub-Processors is maintained at openboxes.cloud/legal/sub-processors.

4.3 New Sub-Processors

OpenBoxes will provide at least 30 days' advance notice of any new Sub-Processor that processes Customer Personal Data, by updating the Sub-Processor list and, if Customer has subscribed to notifications, by email.

4.4 Customer's Right to Object

If Customer has reasonable grounds to object to a new Sub-Processor on data-protection grounds, Customer may notify OpenBoxes in writing within 30 days of the notice. OpenBoxes will work with Customer in good faith to resolve the objection. If the objection cannot be reasonably resolved, Customer may terminate the affected Service with a pro-rata refund of prepaid fees for the unused period.

4.5 Sub-Processor Obligations

OpenBoxes enters into a written agreement with each Sub-Processor imposing data-protection obligations substantially the same as those in this DPA. OpenBoxes remains liable to Customer for each Sub-Processor's compliance with its obligations.

5. Security Measures

5.1 Technical and Organizational Measures

OpenBoxes implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures include:

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Per-tenant data isolation via schema-per-tenant architecture (Customer Personal Data is segregated from other customers' data at the database level)
  • Identity and access management with multi-factor authentication required for administrative roles
  • Role-based access controls applied to all personnel access to production systems
  • Audit logging of administrative actions, retained 7 years
  • Automated daily database backups with 30-day rotation
  • Vulnerability management process, including dependency scanning and prompt patching
  • Documented incident response procedures and vulnerability-disclosure intake at security@openboxes.cloud

5.2 Personnel

Access to Customer Personal Data is limited to OpenBoxes personnel whose access is necessary for them to perform their duties. Such personnel are subject to confidentiality obligations.

5.3 Updates to Security Measures

OpenBoxes may update its security measures over time, provided that the level of protection is not materially decreased.

6. International Data Transfers

6.1 Storage Location

OpenBoxes stores Customer Personal Data on infrastructure operated by Google Cloud Platform in the us-east1 region (United States). Customer Personal Data may be accessed by authorized OpenBoxes personnel located in the United States or Canada.

6.2 Cross-Border Transfers

For Customer Personal Data originating in Canada, the transfer to the United States is made in reliance on appropriate contractual safeguards consistent with PIPEDA's principles for cross-border transfers. Customer acknowledges that data protection laws in the United States may differ from those in Canada and consents to such transfer for the purposes of receiving the Service.

6.3 No EU/EEA Service

OpenBoxes does not currently offer the Service to data controllers established in the European Union, European Economic Area, or United Kingdom, and does not knowingly process personal data of individuals located in those regions.

7. Data Subject Rights

7.1 Customer's Responsibility

As controller, Customer is responsible for responding to Data Subject requests to exercise their rights under Applicable Data Protection Law (access, deletion, correction, portability, opt-out, etc.).

7.2 OpenBoxes' Assistance

To the extent Customer cannot independently fulfill a Data Subject request using the Service's built-in functionality (data export, account closure, account settings), OpenBoxes will provide reasonable assistance, taking into account the nature of processing and the information available to OpenBoxes.

7.3 Direct Requests to OpenBoxes

If a Data Subject contacts OpenBoxes directly about Customer Personal Data, OpenBoxes will promptly refer the request to Customer and will not respond directly except as instructed by Customer or required by law.

8. Security Incidents

8.1 Notification

OpenBoxes notifies Customer without undue delay after becoming aware of a security incident affecting Customer Personal Data. The notification will include, to the extent reasonably available at the time:

  • The nature of the incident and categories of data affected
  • Likely consequences of the incident
  • Measures taken or proposed to address the incident and mitigate its effects
  • Contact information for follow-up

8.2 Cooperation

OpenBoxes will cooperate with Customer's reasonable efforts to investigate and respond to security incidents affecting Customer Personal Data.

8.3 Notice Method

Incident notifications are sent to the email address Customer has provided for security communications, or absent that, to the primary account email.

9. Audit Rights

9.1 Audit Reports

OpenBoxes will, upon written request, make available to Customer a summary of its security posture, security policies, and any then-current third-party audit reports or certifications relevant to the Service. As of the date of this DPA, OpenBoxes is preparing for SOC 2 attestation; available evidence will be shared as it is produced.

9.2 On-Site Audit

If Customer's data-protection requirements cannot reasonably be satisfied by the documents in Section 9.1, Customer may, no more than once in any 12-month period, request a documented audit by an independent third party of its reasonable choosing. Customer bears the cost of any such audit and provides at least 60 days' written notice. The audit is conducted during normal business hours and may not unreasonably interfere with OpenBoxes' operations or disclose information of other customers.

10. Return and Deletion of Customer Personal Data

On termination of the Service, OpenBoxes will delete or return Customer Personal Data in accordance with the retention windows set out in our Privacy Policy and the supporting data retention policy. Customer may export Customer Personal Data using the Service's export functionality before termination and during the 30-day soft-delete window following termination.

After the soft-delete window expires, the underlying tenant database schema containing Customer Personal Data is destroyed. Anonymized account metadata, audit logs (with PII redacted), and invoice records (with PII redacted) are retained per the retention policy for finance, security, and compliance purposes.

Backups roll over on a 30-day cycle; complete erasure including from backups can take up to 30 additional days after the underlying data is destroyed.

11. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set forth in the Terms of Service.

12. General

12.1 Order of Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to processing of Customer Personal Data; the Terms of Service control for all other matters.

12.2 Modifications

OpenBoxes may modify this DPA from time to time, with at least 30 days' notice for material changes, in the same manner as set out for changes to the Terms of Service.

12.3 Governing Law

This DPA is governed by the laws specified in the Terms of Service.

12.4 Contact

Questions about this DPA may be directed to legal@openboxes.cloud. Privacy-specific questions may be directed to privacy@openboxes.cloud.

OpenBoxesLift

Warehouse and inventory management made simple.

Product

  • Features
  • Pricing
  • Lift vs Self-Hosted
  • Status
  • Security

Resources

  • Documentation
  • Getting Started
  • API Reference
  • Community

Company

  • About Us
  • Contact
  • Careers

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Data Processing Agreement
  • Sub-Processors

© 2026 OpenBoxes Solutions LLC. All rights reserved.