1. Purpose and applicability
This DPA governs the processing of personal data by Total Print Hub Inc. ("Total Print Hub", "we", "us", "our") on behalf of a merchant in connection with Total Print Hub. Total Print Hub Inc. is a corporation; all of its shares are held by ITLOX, Inc., a Delaware corporation. The merchant is the business that subscribes to Total Print Hub under our Terms of Service.
This DPA is intended to meet the requirements of Article 28 of the UK GDPR and of Article 28 of the EU GDPR for a contract between a controller and a processor. It applies where:
- the merchant is subject to the UK GDPR, the EU GDPR, or another data protection law that requires terms of this kind;
- we process personal data on the merchant's behalf in the course of providing Total Print Hub; and
- the merchant and we have not signed a separate data processing agreement.
Where the merchant and we have signed a separate data processing agreement, that agreement governs to the extent that it differs from this DPA.
This DPA forms part of the agreement made by the Terms of Service. For the processing of personal data it takes precedence over the Terms of Service; in every other matter the Terms of Service apply. It takes effect when the merchant installs, connects, or starts to use Total Print Hub.
This DPA does not cover the processing for which we are a controller in our own right: administering merchant accounts, keeping billing records, security, preventing fraud, support, operating the product, complying with the law, and protecting our rights. Our Privacy Policy covers that processing.
2. Definitions
In this DPA:
"merchant" means the business that subscribes to Total Print Hub. For merchant personal data, the merchant is the controller."shopper" means a customer of the merchant, including a member who orders from a Branded Store."controller" ,"processor" ,"data subject" ,"personal data" , and"processing" have the meanings given in Article 4 of the UK GDPR and of the EU GDPR."merchant personal data" means the personal data that we process on the merchant's behalf under this DPA, as section 3 describes it."subprocessor" means another processor that we engage to process merchant personal data."Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR where it applies, and any other data protection or privacy law that applies to the processing, including the California Consumer Privacy Act."security incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, merchant personal data that we transmit, store, or otherwise process."Subprocessors page" means the list that we publish at Subprocessors.
3. Subject matter and nature of the processing
| Item | Description |
|---|---|
| Subject matter | The processing of personal data in the course of providing Total Print Hub to the merchant |
| Duration | For as long as the merchant uses Total Print Hub, and after that until the merchant personal data is deleted as section 10 sets out |
| Nature of the processing | Collecting data through the merchant's store and through the tools that shoppers use in it; storing and hosting it; turning designs into previews and print-ready files; showing it to the merchant and its staff; sending it, on the merchant's instruction, to the suppliers and the AI providers that the merchant chooses to use; and deleting it |
| Purpose | To let the merchant's shoppers design personalised products, to carry each design into the cart and the order, to produce print-ready files, and to run the merchant's production, as the Terms of Service describe and as the merchant directs |
| Categories of data subjects | The merchant's shoppers, including the members of a Branded Store; a person to whom an order is shipped, where the merchant enters a ship-to address; a person who is shown or named in artwork, text, or pictures that the merchant or a shopper uploads; and the merchant's staff, as far as their data forms part of the merchant's content |
| Types of personal data | Design drafts and saved designs, typed text, uploaded artwork and pictures, and previews; the store platform's customer reference; the first name, last name, and email address of the person who ordered, where the store platform passes them to us; a ship-to name and address, where the merchant enters one on a purchase order; cart and order references, price quotes, proof answers and comments, and production job records; upload-rights confirmations; privacy requests that the store platform passes to us; and the cookies and browser storage that the shoppers' tools need |
| Special categories of data | None is intended. Total Print Hub is not designed for payment card data, government identity numbers, health information, or other special-category data, and the merchant must not submit them |
4. Our duties as processor
4.1 Instructions
We process merchant personal data only on the merchant's documented instructions. These are: the Terms of Service and this DPA; the settings that the merchant chooses and the actions that the merchant and its staff take in the product, for example switching on an AI feature, connecting a supplier, sending a purchase order, or setting a retention period; and any further written instruction that we accept.
This also applies to a transfer of merchant personal data to another country. Where a law that applies to us requires us to process merchant personal data in another way, we tell the merchant of that requirement before we do so, unless the law forbids it.
4.2 Confidentiality
We allow access to merchant personal data only to people who need it to provide, secure, and support the service, and we bind each of them to confidentiality, by contract or by law.
4.3 Security
We maintain technical and organisational measures that protect merchant personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. Section 8 describes them.
4.4 Subprocessors
We engage subprocessors only as section 6 allows.
4.5 Requests from data subjects
Taking into account the nature of the processing, we help the merchant, by technical and organisational means, to answer the requests of data subjects who use their rights of access, rectification, erasure, restriction, portability, and objection. In particular:
Shopify stores: we handle the three privacy requests that Shopify sends, namely a shopper's data request, a shopper's deletion request, and a store's deletion request. A data request produces a private file that only the signed-in merchant can download, from the list of customer privacy requests in the Admin. A request that arrives with an email address but no customer number is kept for the merchant as a manual request; its contents are stored encrypted and are erased when the request is resolved or the store is deleted.Shopper deletion on Shopify: once a deletion request goes through, the shopper's uploads, own artwork, cart references, and price quotes are deleted, saved designs and drafts are emptied, and the links between the shopper's orders and their design files are cut. The request is not carried out while the shopper still has an order in production, a shipment on its way, an open cart, or an active session. It is carried out when Shopify sends the request again after that work is finished.WooCommerce stores: when the merchant runs its store's tool for erasing personal data, we delete the name and the email address that we keep for that shopper's orders. The order lines and the production records stay.Saved designs and retention: a shopper can delete a saved design from "My designs", and the merchant controls the retention settings of section 10.1.Everything else: the merchant writes to dpo@totalprinthub.com, and we help the merchant answer the request.
Privacy requests are still handled while a store is paused. If a data subject sends us a request about merchant personal data, we ask the person to name the store, we pass the request to the merchant, and we do not answer it ourselves unless the law requires us to.
4.6 Help with the merchant's own duties
Taking into account the nature of the processing and the information available to us, we help the merchant to meet its duties under Data Protection Law on the security of processing, on the notification of a personal data breach, on data protection impact assessments, and on prior consultation with a supervisory authority.
4.7 Deletion and return
At the end of the service we delete merchant personal data, and we help the merchant to take out the data it needs, as section 10 sets out.
4.8 Information and audits
We make available to the merchant the information that is needed to show that we meet the duties of this DPA, and we allow for and contribute to audits, as section 11 sets out.
4.9 Unlawful instructions
We tell the merchant at once if, in our opinion, an instruction infringes Data Protection Law.
4.10 What we do not do with merchant personal data
We do not sell merchant personal data, we do not use it for advertising, and we do not let one merchant reach another merchant's private content.
We do not use a merchant's content, its shoppers' content, or its requests to Inky AI to train AI models, and we do not build AI models of our own. We send content to an AI provider only to produce the result that was asked for.
4.11 California
Where the California Consumer Privacy Act applies to merchant personal data, we act as the merchant's service provider. We do not sell or share that personal information. We keep, use, and disclose it only to provide and secure Total Print Hub for the merchant, and for the other purposes that the law allows to a service provider.
5. The merchant's duties
The merchant confirms and undertakes that:
- it has a lawful basis for the processing, and it has given its shoppers the notices and obtained the permissions that Data Protection Law requires, before personal data reaches Total Print Hub;
- its instructions comply with Data Protection Law, and it has the authority to give them;
- it alone is responsible for the purposes for which it uses merchant personal data, and for the lawfulness of the personal data that it and its shoppers submit;
- it carries out a data protection impact assessment where the law requires one;
- it does not submit, and does not ask its shoppers to submit, payment card data, government identity numbers, health information, or other special-category data;
- where it switches on an AI feature, it tells its shoppers that a description or a picture they submit to the AI tools is sent to an AI provider;
- it uses shoppers' and suppliers' data only for the order, support, fulfilment, or production purpose for which the data was given;
- it chooses its own retention settings, and it downloads the production files it needs before it stops using Total Print Hub;
- it protects the credentials of its store, its staff, its suppliers, and its devices, gives each member of staff only the role that the member needs, and writes to security@totalprinthub.com if it suspects that someone else has used its account.
6. Subprocessors
6.1 General authorisation and the list
The merchant gives us a general authorisation to engage subprocessors. The subprocessors that we use are listed on the Subprocessors page. We keep that page up to date and give notice of every change (section 6.3).
6.2 AI providers
To run the AI features, we may use one or more of: OpenAI, Anthropic, Microsoft Azure, Amazon Web Services. We give notice before a new AI provider is added, as section 6.3 sets out.
An AI provider receives merchant personal data only when the merchant has switched on an AI feature and someone uses it. No shopper's name, email address, or order goes with a request from the Design Studio.
An AI provider that we use on a provider account of our own, as for Inky AI, is our subprocessor, and section 6.4 applies to it. Each AI provider handles what it receives under its own terms. For the AI tools in the Design Studio, the provider account is the one the merchant connects, and that provider's terms with the merchant apply to the content.
6.3 Changes and the right to object
We give at least 30 days' notice of an intended addition or replacement of a subprocessor. We give the notice by updating the Subprocessors page, and by email to each merchant that has asked us at dpo@totalprinthub.com to be told of changes.
The merchant may object to the change, on reasonable grounds of data protection, by writing to dpo@totalprinthub.com before the change takes effect. We then look for a solution with the merchant in good faith. If we cannot offer the service without the new subprocessor, the merchant may end its subscription. Our Refund and Cancellation Policy applies to the fees.
6.4 Our responsibility for subprocessors
We engage a subprocessor only under a written agreement that imposes data protection duties no less protective than those of this DPA. We remain responsible to the merchant for what our subprocessors do with merchant personal data.
ITLOX LTD, a group company in England and Wales, supports development, operations, and support. Where a company of our group handles merchant personal data for us, it does so as our subprocessor and under the same duties.
6.5 Services that the merchant chooses itself
The following are not our subprocessors. They act under the merchant's own agreement with them:
- the merchant's store platform, Shopify or WordPress with WooCommerce;
- the suppliers, fulfilment services, printers, and shipping tools that the merchant connects. A supplier receives data only when the merchant connects it or sends it an order: the order lines and, where the merchant enters one, a ship-to name and address on the purchase order;
- a video service from which the merchant shows a tutorial video inside the Design Studio.
7. International transfers
7.1 Where merchant personal data is hosted
Merchants in Europe and the United Kingdom are hosted in Sweden. Merchants in the United States are hosted in the central United States. Total Print Hub runs in these two regions and in no other, so a merchant in another country is hosted in one of them. A second copy of the database backups is kept in another region.
7.2 Transfers to subprocessors
We transfer merchant personal data out of the United Kingdom or the European Economic Area to a subprocessor only where Chapter V of the UK GDPR or of the EU GDPR allows it. We rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another mechanism that the law accepts.
7.3 Transfers from the merchant to us
Where the merchant's use of Total Print Hub involves a transfer of personal data to us, or to a company of our group, that needs a safeguard under the UK GDPR or the EU GDPR, we enter into the European Commission's Standard Contractual Clauses and, for the United Kingdom, the UK International Data Transfer Addendum with the merchant. The merchant can ask for them with the signed copy of this DPA (section 15).
7.4 Copies
The merchant can ask at dpo@totalprinthub.com for a copy of the safeguards that apply, and for the countries in which a subprocessor processes merchant personal data.
8. Security measures
We maintain the following measures. They are described in plain words, as on our Security page.
Hosting and network: Total Print Hub runs in two regions and in no other. The places where data is stored cannot be reached from the public internet, and traffic is screened for attacks before it reaches the application.Separation of merchants: every record carries the store it belongs to. The store is checked on every request and enforced a second time where the data is stored, so that a request cannot switch from one store to another. Files are kept by store. The Dedicated plan has a database and file storage of its own.Encryption: every connection to Total Print Hub is encrypted, and browsers are told to use the secure connection only. Files, the database, and its backups are stored encrypted. Store access, supplier logins, and sign-in secrets are encrypted once more before they are saved. A password is never stored in a form that can be read back.Access control: inside Shopify, the Admin opens only for the store and the member of staff that Shopify has signed in. Every message between a WooCommerce store and Total Print Hub is signed and cannot be used again. A Total Print Hub account needs a long password and an authenticator app, repeated failed sign-ins lock the account for a time, and a session ends by itself.Checks on uploads: a file's real type and size are checked, not its name. A drawing that carries a script is rejected. Every file is scanned for malware before it is stored, and it is refused if the scan cannot run. Stored files have no public address.Data minimisation: for the person who ordered, we keep only the name and the email address, and we do not ask Shopify for a store's customer list. Sign-in events keep the network address and the browser name only as one-way fingerprints. Our application's logs leave out sign-in headers, cookies, and secrets.Backups: the database is backed up automatically, and its backups are kept for 35 days, with a second copy in another region. Files are stored in more than one place, earlier versions are kept, and a deleted file can be recovered for 30 days.Incident response: our incident plan has seven steps: triage, contain, replace the secrets that may be exposed, preserve the evidence, notify affected merchants where that is required, fix, and review.Vulnerability reports: we take reports of a weakness at security@totalprinthub.com. The list of the third-party software that Total Print Hub is built on is available to customers on request.
We may change these measures, provided that a change does not materially lower the overall level of security.
9. Security incident notification
If a security incident affects merchant personal data, we notify the merchant without undue delay, and in any event within 72 hours of becoming aware of the incident, or as soon as reasonably practicable where 72 hours cannot be met. We send the notice by email to the registered contact of the merchant's account.
The notice describes, as far as we know it at the time: the nature of the incident; the categories and the approximate number of the data subjects and of the personal data records concerned; the likely consequences; and the measures that we have taken or propose to take. We add what we learn later without undue delay.
We cooperate with the merchant in handling the incident and in meeting the merchant's duties to notify the supervisory authority and the data subjects concerned. Whether to notify them is the merchant's decision and the merchant's duty. A merchant that suspects an incident writes to security@totalprinthub.com.
10. Return and deletion
10.1 While the merchant uses Total Print Hub
The merchant decides, in its retention settings, how long production exports, customer images that are in no saved design, open draft, or order, and privacy response files are kept. Saved designs, orders, and production records are kept while the merchant uses the product, or until they are deleted.
10.2 Taking data out
The merchant can download its production files order by order and, for a shopper's data request, the file that the product prepares. Total Print Hub has no export of a whole account. While a store is paused, production exports are not available; privacy requests still are. Before the merchant stops using Total Print Hub, it should download the production files it needs.
If the merchant needs merchant personal data to be returned in another way, it writes to dpo@totalprinthub.com before it asks for deletion, and we agree with the merchant what can be handed over and in which form.
10.3 When the subscription ends
When a subscription ends, the store is paused. The pause deletes nothing, and the merchant's data returns when the subscription is active again.
Shopify stores: when the merchant uninstalls the app, we delete our access to the store and its subscription records at once, and we keep the merchant's content. When Shopify then sends us its request to delete the store's data, the store is closed to new changes and its data is deleted after a retention period.WooCommerce and direct customers: disconnecting the store or removing the plugin does not delete the data that we hold. It is kept until the merchant asks us to delete it.
10.4 Deletion on request
On the merchant's written request we delete its store's data, except what the law requires us to keep. Copies in backups are overwritten as the backups expire.
Where the law requires us to keep merchant personal data, we keep it only for as long as the law requires, we tell the merchant, and we process it for no other purpose.
11. Audit rights
We make available to the merchant the information that is needed to show that we comply with this DPA. We permit audits, including inspections, by the merchant or by an auditor that the merchant appoints, on at least 30 days' written notice, during normal business hours, at the merchant's cost, and without materially disrupting our operations. The auditor must be bound by confidentiality, and an audit gives no access to the data of another merchant.
Total Print Hub holds no security certification today: no SOC 2 report and no ISO 27001 certificate. If we obtain a certification that covers the processing, we may offer the certificate and its summary report in place of an on-site audit, unless the merchant has reasonable grounds to require otherwise.
12. Liability
Each party's liability under this DPA is subject to the limits and exclusions of liability in the Terms of Service. Nothing in this DPA limits either party's liability for death or personal injury caused by negligence, for fraud, or for any matter for which liability cannot lawfully be limited. Nothing in this DPA takes away a right that Data Protection Law gives to a data subject.
13. Governing law
This DPA is governed by the same law as the Terms of Service: the laws of the State of Delaware, without regard to its conflict-of-law rules. The courts named in the Terms of Service decide a dispute about this DPA. Both rules are subject to any mandatory requirement of Data Protection Law. Where Standard Contractual Clauses apply between the merchant and us, the law and the courts named in those clauses apply to them.
14. Term and changes
This DPA applies for as long as we process merchant personal data. The duties of confidentiality, deletion, and liability continue after the subscription ends, for as long as we hold merchant personal data.
We may change this DPA when the law, our subprocessors, or the service changes. We post the new version with a new "Last updated" date. For a material change we give at least 30 days' notice, by email or in the product. No change lowers the protection of merchant personal data below what Data Protection Law requires.
15. Signed copy and contact
A merchant that needs a signed copy of this DPA, for example for its own procurement, to record specific instructions, or to add the Standard Contractual Clauses, writes to our data protection team.
Total Print Hub Inc.
- Data protection questions, signed copies, and objections to a subprocessor: dpo@totalprinthub.com
- Legal questions: legal@totalprinthub.com
- Security incidents and reports: security@totalprinthub.com
The merchant finds our postal address for formal notices on its order or invoice. If none is shown there, the merchant asks at legal@totalprinthub.com for the address.
Related documents: Terms of Service, Privacy Policy, Subprocessors, Security, AI Disclaimer, and Refund and Cancellation Policy.
