Book a demo Open the ROI calculator

[soc 2 type ii · 14-day trial · no card]

[legal / dpa]

Data processing addendum

[last updated ] [version 1.0] [illustrative]

[portfolio concept]

Throughline is fictional. This site is a design studio's portfolio piece, and this page shows the structure of a real data processing addendum: what a procurement reviewer should find, in the order they should find it. It is not a contract, it cannot be signed, and it is not legal advice.

[1]Parties and roles

This addendum would form part of the agreement between the customer and Throughline, Inc. [illustrative]. For personal data inside shipment records, the customer is the controller and Throughline is the processor. For account data, named users and billing contacts, Throughline is a controller in its own right, as the privacy policy describes.

Throughline processes personal data only on the customer's documented instructions. The agreement, this addendum, and the customer's configuration inside the product are those instructions.

[2]Scope and duration

The addendum covers all personal data Throughline processes on the customer's behalf, for the term of the agreement plus the 30-day export window that follows it, described in clause [9]. Nothing is processed before instructions exist or after deletion is confirmed.

[3]Nature and purpose

Ingesting carrier feeds and EDI 214/990 messages; detecting, routing, and resolving shipment exceptions; alerting named owners; producing audit trails and reports the customer runs. Nothing else. Processing for Throughline's own purposes is out of scope here and would need its own stated basis in the privacy policy.

[4]Data subjects and categories

[categories of data · illustrative]
Data subjects Personal data
The customer's users Name, work email, role, authentication identifiers
Contacts on shipping documents Names, business phone and email, pickup and delivery addresses
Carrier and customer-tier contacts Names and business contact details inside carrier feeds and EDI messages

The service is not designed for special-category data, and the customer agrees not to route any into it. The terms repeat this in the acceptable-use clause, so it cannot be missed in either document.

[5]Sub-processing

The customer authorises the subprocessors on the published list, which is the canonical record: /legal/subprocessors. At least 30 days before adding or replacing one, Throughline gives notice by email to account administrators.

The customer may object in writing, within the notice window, on reasonable data-protection grounds. If no resolution is found, the customer may terminate the affected service and receive a refund of prepaid, unused fees.

Every subprocessor is bound in writing to obligations no weaker than this addendum, and Throughline remains fully liable for their performance.

[6]Security measures

The measures a real annex would enumerate, and this one models [illustrative]:

  • Encryption. TLS 1.2 or higher in transit; AES-256 at rest.
  • Access. Role-based access control on least privilege, reviewed quarterly; SSO and SAML on Operations and up.
  • Auditability. An immutable audit trail per shipment, exportable by the customer at any time.
  • Assurance. SOC 2 Type II, audited annually; the report is available under NDA. Stated in text, on purpose: a claim you can request beats a badge you cannot verify.
  • Personnel. Confidentiality obligations, background screening where lawful, and security training on hire and annually.
  • Resilience. Encrypted backups, redundant within the customer's residency choice, with restores tested rather than assumed.

The wider security posture, including uptime history, lives at /trust.

[7]International transfers

Customer data is stored in the customer's chosen residency: United States or European Union, with custom residency on the Network tier. Where a transfer out of a protected region occurs, it relies on an adequacy decision or on standard contractual clauses, with a transfer impact assessment available on request [illustrative].

[8]Audit rights

Once per 12 months, on 30 days' notice, the customer may audit compliance with this addendum. The SOC 2 Type II report and the penetration test summary, provided under NDA, satisfy the audit in the first instance. A remaining, reasoned scope may be exercised on site, in business hours, at the customer's cost, and never with access to other customers' data.

[9]Deletion and return

On termination, all customer data remains exportable for 30 days as CSV or Parquet. When the window closes, Throughline deletes it from live systems, ages it out of encrypted backups on the backup cycle within a further 35 days [illustrative], and confirms deletion in writing. This is the commitment the pricing FAQ makes, in contract form.

[10]Breach notification

Throughline notifies the customer of a personal data breach without undue delay, and in any case within 72 hours of becoming aware of it, with what is known at the time: the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken. Updates follow as facts do. Notification is not an admission of fault; silence would be worse than either.

[11]Precedence and contact

If this addendum conflicts with the terms, this addendum wins for anything touching personal data.

privacy@throughline.example [illustrative]

A real DPA ends with signature blocks. This one ends here, because nobody should sign a fiction.