Data Processing Agreement

How Printing Labs processes gift-recipient data on behalf of corporate clients under the DPDP Act, 2023 — roles, sub-processors, security, breach notice and deletion.

The Data Processing Agreement that applies whenever a corporate client shares gift-recipient data with Printing Labs for order fulfilment. Under the DPDP Act, 2023 the client is the Data Fiduciary and Printing Labs the Data Processor.

Scope and obligations

Recipient data — name, shipping address, contact details, sizes — is processed only to kit, address, dispatch and deliver orders, never for marketing. Access is confined to fulfilment personnel under confidentiality, and strict separation is kept between different clients.

Sub-processors and security

Courier partners (Delhivery, Blue Dart, DTDC, Shiprocket), payment processing (PayU) and Google Cloud infrastructure are the authorised sub-processor categories. Breaches affecting recipient data are notified to the client within 72 hours of Printing Labs becoming aware.

Retention and deletion

Recipient data is kept for fulfilment and delivery-issue resolution, then deleted or anonymised. Earlier deletion is available on written request, subject to statutory retention of tax records. Governed by Indian law, courts at Ahmedabad.