Based on the 4 September 2026 documents, with the brand spelling corrected to Printi. Launch domains, contact details and the publication checks remain to be finalised.
This is Schedule 1 of the Printi SaaS Subscription Agreement. Read it together with the full agreement; its defined terms and contractual context apply.
A. Status and instructions
In this Schedule, Data Protection Law means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, and binding replacement or amending legislation. Controller, processor, personal data, processing, data subject and personal data breach have their statutory meanings. The Customer instructs us to process Customer Personal Data to provide, secure, support and improve the subscribed Service, follow account configuration and documented instructions, and comply with law. If we believe an instruction infringes Data Protection Law, we will notify the Customer unless prohibited.
B. Processor obligations
- Process Customer Personal Data only on documented instructions, including approved international transfers, unless law requires otherwise.
- Ensure authorised personnel are bound by confidentiality and receive appropriate training.
- Maintain measures appropriate to risk and regularly assess their effectiveness.
- Taking account of the nature of processing, assist the Customer through Service features and reasonable support with data-subject requests, DPIAs, regulator consultation, security and breach duties.
- Notify the Customer without undue delay after becoming aware of a Customer Personal Data breach, providing available information about nature, likely consequences, affected data/people and mitigation. Notification is not an admission of fault.
- At the Customer’s choice on termination, return/export or delete Customer Personal Data, except where law requires retention and subject to secure backup rotation.
- Make information reasonably necessary to demonstrate compliance available. No more than once annually, unless a breach/regulator requires more, the Customer may request an independent report or conduct a proportionate audit on 30 days’ notice, under confidentiality, without accessing other customers’ data or disrupting systems.
C. Subprocessors and transfers
The Customer gives general authorisation for subprocessors needed to provide the Service. We will maintain a current list at a published location or in the account and give at least 15 days’ notice of a new subprocessor where reasonably practicable. The Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith; if no reasonable alternative exists, either may terminate the materially affected Service with a pro-rata refund of unused prepaid fees.
We will impose materially equivalent data-protection obligations and remain responsible for subprocessors. Restricted transfers will use a lawful mechanism, including UK adequacy regulations or the ICO International Data Transfer Agreement/Addendum, plus supplementary measures where required.
D. Processing details
| Item | Details |
|---|---|
| Subject matter and duration | Hosting and operation of Printi for the Subscription Term, plus agreed export, legal retention and backup deletion periods. |
| Nature and purpose | Collection, storage, organisation, retrieval, transmission, support, security, backup, analytics configured by the Customer, communications, order/production workflows and deletion. |
| Data subjects | Customer personnel, authorised users, prospects, customers, portal users, suppliers, subcontractors, delivery contacts and other individuals entered by the Customer. |
| Data types | Identity and contact data; account/role data; quotes, orders, invoices and correspondence; artwork/design and approval data; product, sizing and personalisation details; delivery data; staff/workflow records; technical, audit and support data; integration identifiers. |
| Special data | Not intended as standard. The Customer must not submit special-category/criminal-offence data unless a supported feature, lawful basis, safeguards and written instructions are in place. |
| Frequency | Continuous or as initiated by the Customer and its users. |
| Controller obligations | Lawful basis, transparency, minimisation, accuracy, retention, access control, responding to individuals and legality of instructions/content. |
E. Security baseline
- Role-based logical access and authentication controls; privileged-access restriction and review.
- Encryption in transit and appropriate encryption at rest or equivalent controls.
- Secure software development, change control, dependency and vulnerability management.
- Logging, monitoring, malware protection and incident-response procedures.
- Resilience, backups, restoration testing and business-continuity arrangements proportionate to the Service.
- Supplier due diligence, contractual controls, personnel confidentiality and data-protection/security training.
- Tenant separation and measures designed to prevent unauthorised cross-customer access.