DUTT Privacy and Data Processing Addendum

Version: dutt-privacy-dpa-v1.0-2026-08-02
Effective: 2 August 2026

This Addendum forms part of the DUTT Merchant Agreement and is intended to satisfy the processor-contract requirements of Article 28 GDPR for merchant-platform delivery data.

1. Roles

The merchant is the controller for customer and recipient data it submits to arrange a delivery. DUTT acts as processor for that instructed delivery processing. DUTT acts as an independent controller where it determines processing required for its own legal obligations, driver safety, fraud prevention, payment, accounting, security or legal claims.

2. Subject matter and duration

The processing covers quotation, dispatch, pickup, delivery, tracking, support, returns, cancellation and service settlement. It continues for the term of the Merchant Agreement and for any limited retention period required to complete deliveries, protect rights or comply with law.

3. Data subjects and personal data

Data subjects may include merchant staff, customers, recipients, drivers and support participants. Data may include names, business contact details, phone numbers, email addresses, pickup and delivery addresses, location and route data, order references, delivery notes, support content, status events, proof of delivery and technical identifiers. Payment-card numbers and security codes must not be sent through merchant delivery payloads.

4. Documented instructions

DUTT processes merchant-controlled data only on documented instructions contained in the Merchant Agreement, API requests and authorised support instructions, unless Union or Greek law requires otherwise. DUTT will inform the merchant before legally required processing unless the law prohibits that notice.

5. Confidentiality and security

DUTT restricts access to authorised personnel and service providers bound by confidentiality. Appropriate measures include authenticated merchant keys, access control, encryption in transit, protected cloud storage, logging, key revocation, input validation, least-privilege access, backups and incident response proportionate to the risk.

6. Subprocessors

The merchant gives general written authorisation for subprocessors needed to operate the service. Current categories and providers may include Google Cloud/Firebase for hosting and databases, Google services for maps and routing, Viva for payments, Elorus for invoicing, Brevo for communications and OpenAI for support features where enabled. DUTT remains responsible for imposing appropriate data-protection obligations and will require fresh acceptance or otherwise notify the merchant when a material change requires it.

7. International transfers

Where personal data is transferred outside the European Economic Area, DUTT will use an applicable lawful transfer mechanism and supplementary safeguards required by data-protection law.

8. Data-subject requests

Taking into account the nature of processing, DUTT will reasonably assist the merchant with access, correction, deletion, restriction, portability and objection requests. DUTT will not independently answer a merchant-controlled request unless authorised or legally required.

9. Security incidents

DUTT will notify the merchant without undue delay after becoming aware of a personal-data breach affecting merchant-controlled data and will provide available information reasonably required for the merchant's GDPR obligations.

10. Assistance and compliance

DUTT will provide information reasonably necessary to demonstrate compliance with this Addendum and assist with security, breach, impact-assessment and supervisory-authority obligations, considering the nature of processing and information available to DUTT.

11. Deletion and return

At the end of the service, DUTT will delete or return merchant-controlled personal data on request, unless retention is required by law or needed for legitimate legal records. Data in backups is removed through the normal secure backup lifecycle.

12. Audit

The merchant may request relevant compliance information. Any additional audit must be reasonable, protect other customers and security, avoid service disruption and be subject to confidentiality. The parties will first use available reports and documentation.

13. Merchant obligations

The merchant is responsible for lawful collection, transparency, data accuracy, purpose limitation, checkout notices and responding to its data subjects. The merchant must not submit unnecessary special-category data in delivery notes.

14. Priority and contact

If this Addendum conflicts with the Merchant Agreement on processor obligations, this Addendum controls. General privacy information is available in the DUTT Privacy Notice. Data-protection questions may be sent to info@dutt.gr.