Data Processing Agreement

Last updated: May 26, 2026 · Version 1.0 · Questions: legal@restock.supply

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between Restock, Inc. ("Restock", "Processor"), and the Customer ("Controller"). It governs the Processing of Personal Data by Restock on the Controller's behalf and is designed to satisfy Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR. Capitalized terms not defined here have the meaning in the GDPR or the Agreement.

Contents 1. Parties and roles 2. Subject matter, duration, nature, and purpose 3. Processing on documented instructions 4. Confidentiality of personnel 5. Security of processing (Art. 32) 6. Sub-processors 7. Assistance with data subject requests 8. Assistance with obligations (Art. 32–36) 9. Personal data breach notification 10. Deletion or return of data 11. Audits and inspections 12. International transfers 13. General Annex I — Details of processing Annex II — Technical and organizational measures Annex III — Sub-processors Signatures

1. Parties and roles

With respect to Personal Data contained in Customer Data, the Customer is the Controller and Restock is the Processor. Where the Customer acts as a processor for a third-party controller, Restock is a sub-processor and the Customer warrants it has authority to engage Restock on those terms.

2. Subject matter, duration, nature, and purpose

The subject matter is the provision of the Service. The duration is the term of the Agreement plus any post-termination period described in Section 10. The nature and purpose of Processing is to host, store, transmit, and otherwise process Customer Data as necessary to provide the Service to the Controller. Further detail is in Annex I.

3. Processing on documented instructions

Restock will Process Personal Data only on the Controller's documented instructions, including with regard to international transfers, unless required by applicable law (in which case Restock will inform the Controller unless the law prohibits it). The Agreement, this DPA, and the Controller's use of the Service's features constitute the Controller's complete and documented instructions. Restock will inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law.

4. Confidentiality of personnel

Restock will ensure that persons authorized to Process Personal Data are bound by appropriate confidentiality obligations and are subject to access controls under the principle of least privilege.

5. Security of processing (Art. 32)

Restock will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II and our Security Overview. Restock may update these measures provided the level of security is not materially reduced.

6. Sub-processors

The Controller provides general written authorization for Restock to engage sub-processors to Process Personal Data. The current list of sub-processors is maintained in the Trust Center and in Annex III. Restock will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors' performance. Restock will give the Controller at least 30 days' notice of the addition or replacement of a sub-processor (for example, via the Trust Center or email). The Controller may object on reasonable data protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, the Controller may terminate the affected Service.

Annex III also lists, separately, third parties that receive data directly from the User's browser but that Restock uses under their own public terms rather than under a negotiated agreement. The commitments in this Section do not currently extend to those recipients, and the Annex says so on its face rather than presenting them as contracted sub-processors.

7. Assistance with data subject requests

Taking into account the nature of the Processing, Restock will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR (access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts Restock directly regarding Personal Data Processed on a Controller's behalf, Restock will promptly forward the request to the Controller and will not respond directly except on the Controller's instruction or as required by law.

8. Assistance with obligations (Art. 32–36)

Restock will assist the Controller, taking into account the nature of Processing and the information available to Restock, in ensuring compliance with the Controller's obligations relating to security of Processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.

9. Personal data breach notification

Restock will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA, and will provide information reasonably available to assist the Controller in meeting its own notification obligations. Restock will take reasonable steps to mitigate and remediate the breach.

10. Deletion or return of data

Upon termination or expiry of the Agreement, Restock will, at the Controller's choice, delete or return all Personal Data that Restock holds on its own systems, and delete existing copies, unless retention is required by applicable law. For that data, the Service allows the Controller to export Customer Data for a limited period (around 30 days) after termination, after which it is deleted in the ordinary course, subject to backup rotation cycles.

Data held only on the Controller's devices. Restock runs local-first. Some categories of Customer Data are written to browser storage on the Users' own devices and are never transmitted to Restock — today this includes proof-of-service visit records, and records created in parts of the product that have no server-side store at all (routes, drop-offs, key-account contacts, reports and team lists). Contracts and invoices are a mixed case rather than a device-only one: tables for them exist on Restock's systems and some screens write through to them, while the contract builder and the invoice screens write to browser storage only, so a given record may sit in either place or both. Restock cannot read, export, or delete data that never left the device, and it is not covered by the commitments in the paragraph above. The Controller retains it, and deletes it, by clearing site data on the devices concerned. The in-product backup feature writes a file to the User's own device; it does not send a copy to Restock. Where a category is durable on Restock's systems it is stated as such: proof-of-delivery photographs and signature images, for example, are uploaded to Restock's file storage as well as being held on the device, and the uploaded copies are within the first paragraph.

This section previously promised deletion or return of all Personal Data without that distinction. It was narrowed to what Restock can actually do rather than dropping the local-first categories from the Agreement. Making them durable requires server-side storage that does not exist yet; until it does, do not restore the broader wording.

11. Audits and inspections

Restock will make available to the Controller information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. The parties will agree on the scope, timing, and confidentiality of any audit in advance; audits will occur no more than once per year (absent a regulator requirement or a breach), during business hours, with reasonable notice, and without unduly disrupting Restock's operations. Restock may satisfy audit requests by providing third-party certifications, reports (such as a SOC 2 report under NDA — see the Trust Center), and responses to reasonable questionnaires.

12. International transfers

To the extent Restock Processes Personal Data subject to the GDPR or UK GDPR in a country that does not provide an adequate level of protection, the parties agree that the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor, and Module Three where Restock acts as sub-processor) are incorporated into this DPA by reference and completed by reference to the Annexes hereto. For UK transfers, the UK International Data Transfer Addendum applies. In the event of a conflict, the SCCs prevail over other terms of this DPA with respect to such transfers.

13. General

This DPA is subject to the limitation of liability provisions of the Agreement. If any provision conflicts with the Agreement, this DPA controls with respect to Processing of Personal Data. This DPA is governed by the law specified in the Agreement, except where the GDPR or SCCs require otherwise.

Annex I — Details of processing

A. List of parties

Data exporter (Controller): The Customer identified in the Agreement. Data importer (Processor): Restock, Inc.; contact privacy@restock.supply.

B. Categories of data subjects

C. Categories of personal data

These last four categories were absent from earlier versions of this Annex while the product was already processing them. They are listed here so the Controller's own records of processing can be accurate. Continuous location monitoring of employees is an area with notice obligations that vary by jurisdiction; the Controller decides whether and how to enable the driver application, and should take its own advice on notice to its drivers.

Special categories of data: The Service is not intended to Process special categories of Personal Data. The Controller should not upload such data.

D. Frequency, nature, and purpose

Continuous, for the duration of the Agreement, to provide, secure, and support the Service as instructed.

E. Retention

For the term of the Agreement plus the post-termination period in Section 10, subject to legal retention requirements and backup cycles. Three exceptions: live driver position fixes are held in device memory for the current session only (roughly the last twenty minutes) and are not written to Restock's database; proof-of-service visit records are held only on the device that produced them, with no expiry and no copy on Restock's systems; and uploaded proof-of-delivery images have no deletion schedule of their own and are retained until the Controller's data is deleted or returned under Section 10. See Privacy Policy §7.

Annex II — Technical and organizational measures

Restock implements the measures described in our Security Overview, including:

Certain measures are on our roadmap and are marked accordingly in the Security Overview; the Annex reflects current and planned controls as the product approaches launch.

Annex III — Sub-processors

The authorized sub-processors are listed and kept current in the Trust Center. As of the date of this DPA they include the following:

Sub-processorPurposeLocation
SupabaseManaged database, authentication, hostingUnited States
StripePayment processingUnited States
NetlifyStatic hosting and CDNUnited States
Resend / PostmarkTransactional email deliveryUnited States
CloudflareDNS and CDNUnited States
AnthropicAI document extraction — an uploaded document is sent to Anthropic's API to be classified and have its fields extracted (Privacy Policy §3.1)United States
SentryApplication error monitoringUnited States

Other third parties that receive data

The following are contacted directly by the User's browser while the Service runs. They receive the User's IP address and the contents of the request described below. Restock uses them under their publicly available terms and has not entered into a negotiated data protection agreement with them, so the commitments in Section 6 do not currently extend to them. They are listed here so the Controller can see every destination that receives data and decide whether that is acceptable.

RecipientWhat it receivesNotes
OSRM public routing service (router.project-osrm.org)The coordinates being routed, in the request address: a driver's live position and the coordinates of the stops on the routeA free public instance operated by the OSRM project. No contract, no stated data location, and the coordinates land in that operator's request logs. Self-hosting this service would remove the recipient entirely.
OpenFreeMap; MapTiler or Mapbox where a key is configuredThe map area being viewed, as tile requestsBasemap imagery.
rsms.me; Google FontsPage load requests for web fontsFires on every page, including the legal pages.
unpkg; jsDelivr; cdnjs; esm.sh; Sentry CDNRequests for JavaScript libraries used by specific featuresLoaded without subresource integrity, so a change at the CDN reaches the browser. See the Security Overview §8.
Brandfetch; ClearbitA company domain typed by a workspace administrator into the branding importerOnly when that importer is used.

Signatures

This DPA is entered into by the parties as of the effective date of the Agreement and may be executed electronically.

Controller (Customer)

Signature

Name / Title

Date

Processor (Restock, Inc.)

Signature

Name / Title

Date