Privacy Policy – Mission Logix Data Processing Addendum
This Addendum forms part of the Conditions of Service agreed between the Customer and Mission Logix and applies to all Personal Data processed under those Conditions.
Part A – Data Protection Framework
1. Definitions
Unless otherwise stated, terms used in this Addendum have the meanings set out in applicable Data Protection Laws. The following definitions apply:
Controller: As defined under Data Protection Laws.
Processor: As defined under Data Protection Laws.
Data Protection Laws: Includes the GDPR, the Data Protection Act 2018, and any other laws that implement, extend, or amend them.
GDPR: General Data Protection Regulation (EU Regulation 2016/679).
Data Subject: An individual whose Personal Data is processed.
Personal Data: Information about a Data Subject as defined in Data Protection Laws.
Processing: Any operation on Personal Data, as defined in Data Protection Laws.
Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access to Personal Data.
Protected Data: Personal Data received by Mission Logix from or on behalf of the Customer in connection with the Services.
Sub-Processor: Any subcontractor engaged by Mission Logix to process Protected Data, excluding Mission Logix employees.
2. Roles and Responsibilities
The Customer acts as Controller;
Mission Logix acts as Processor.
The Customer shall comply with all applicable Data Protection Laws and ensure that all instructions to Mission Logix are lawful.
3. Processor Obligations
Mission Logix shall process Protected Data only:
As instructed by the Customer in this Addendum or Agreement;
As necessary to fulfil its contractual obligations;
As required by law (where applicable).
Mission Logix will notify the Customer if it believes an instruction may breach Data Protection Laws and will pause processing until lawful instructions are received.
4. Security Measures
Mission Logix shall maintain appropriate technical and organisational measures to protect Protected Data from accidental, unauthorised, or unlawful access, loss, or destruction, in accordance with Part B of this Addendum and Article 32 of the GDPR.
5. Sub-Processing
Mission Logix shall:
Not allow any third-party to process Protected Data without prior written authorisation from the Customer (except internal authorised employees);
Ensure all Sub-Processors sign enforceable contracts containing the same data protection obligations;
Remain fully liable for the actions or omissions of any authorised Sub-Processor;
Ensure all individuals authorised to access Protected Data are under confidentiality obligations.
6. Approved Sub-Processors
The Customer authorises the following Sub-Processors:
Couriers: DHL, DPD, FedEx, Norsk Global, UK Mail, UPS, Yodel
Technology: MintSoft Ltd (for provision of e-commerce tools)
Fulfilment: Mission Logix Ltd (for internal warehousing and operational support)
7. Assistance and Rights
Mission Logix will (at the Customer’s expense):
Assist with obligations under Articles 32–36 of the GDPR;
Help the Customer respond to Data Subject rights requests, as required by Chapter III of the GDPR.
8. International Transfers
Mission Logix shall not transfer Protected Data outside the UK or to any International Organisation without prior written consent from the Customer.
9. Audits and Demonstration of Compliance
Mission Logix will:
Provide relevant documentation to demonstrate GDPR compliance;
Allow one audit per 12-month period by the Customer or authorised third-party, on reasonable notice and during business hours.
10. Personal Data Breach
Mission Logix shall notify the Customer without undue delay if it becomes aware of any Personal Data Breach involving Protected Data.
11. Data Deletion or Return
Upon termination of the Services:
The Customer may request the return or secure deletion of all Protected Data (at their expense);
Mission Logix shall delete all copies unless retention is legally required.
Part B – Data Processing and Security Measures
Section 1 – Data Processing Details
| Aspect | Description |
|---|---|
| Subject-Matter | Fulfilment and e-commerce services provided by Mission Logix |
| Duration | For the duration of the Customer’s contract |
| Nature & Purpose | To enable Mission Logix to pick, pack, store, and dispatch Customer orders |
| Types of Personal Data | Name, delivery address, email address, phone number |
| Categories of Data Subjects | Individuals placing orders via ecommerce or wholesale channels |
Section 2 – Technical & Organisational Security Measures
Mission Logix shall implement and maintain appropriate security controls to protect Protected Data, including:
Risk-based measures aligned with Article 32 GDPR
Access controls and role-based permissions
Secure data storage and encrypted backups
Regular audits and staff training
Network and infrastructure security (e.g., firewalls, endpoint protection)
Procedures for managing and reporting Personal Data Breaches
Data minimisation and retention controls
These controls are reviewed regularly and updated to reflect evolving best practices and legal requirements.
