Privacy Policy – Mission Logix Data Processing Addendum

This Addendum forms part of the Conditions of Service agreed between the Customer and Mission Logix and applies to all Personal Data processed under those Conditions.


Part A – Data Protection Framework

1. Definitions

Unless otherwise stated, terms used in this Addendum have the meanings set out in applicable Data Protection Laws. The following definitions apply:

  • Controller: As defined under Data Protection Laws.

  • Processor: As defined under Data Protection Laws.

  • Data Protection Laws: Includes the GDPR, the Data Protection Act 2018, and any other laws that implement, extend, or amend them.

  • GDPR: General Data Protection Regulation (EU Regulation 2016/679).

  • Data Subject: An individual whose Personal Data is processed.

  • Personal Data: Information about a Data Subject as defined in Data Protection Laws.

  • Processing: Any operation on Personal Data, as defined in Data Protection Laws.

  • Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access to Personal Data.

  • Protected Data: Personal Data received by Mission Logix from or on behalf of the Customer in connection with the Services.

  • Sub-Processor: Any subcontractor engaged by Mission Logix to process Protected Data, excluding Mission Logix employees.


2. Roles and Responsibilities

  • The Customer acts as Controller;

  • Mission Logix acts as Processor.

  • The Customer shall comply with all applicable Data Protection Laws and ensure that all instructions to Mission Logix are lawful.


3. Processor Obligations

Mission Logix shall process Protected Data only:

  • As instructed by the Customer in this Addendum or Agreement;

  • As necessary to fulfil its contractual obligations;

  • As required by law (where applicable).

Mission Logix will notify the Customer if it believes an instruction may breach Data Protection Laws and will pause processing until lawful instructions are received.


4. Security Measures

Mission Logix shall maintain appropriate technical and organisational measures to protect Protected Data from accidental, unauthorised, or unlawful access, loss, or destruction, in accordance with Part B of this Addendum and Article 32 of the GDPR.


5. Sub-Processing

Mission Logix shall:

  • Not allow any third-party to process Protected Data without prior written authorisation from the Customer (except internal authorised employees);

  • Ensure all Sub-Processors sign enforceable contracts containing the same data protection obligations;

  • Remain fully liable for the actions or omissions of any authorised Sub-Processor;

  • Ensure all individuals authorised to access Protected Data are under confidentiality obligations.


6. Approved Sub-Processors

The Customer authorises the following Sub-Processors:

  • Couriers: DHL, DPD, FedEx, Norsk Global, UK Mail, UPS, Yodel

  • Technology: MintSoft Ltd (for provision of e-commerce tools)

  • Fulfilment: Mission Logix Ltd (for internal warehousing and operational support)


7. Assistance and Rights

Mission Logix will (at the Customer’s expense):

  • Assist with obligations under Articles 32–36 of the GDPR;

  • Help the Customer respond to Data Subject rights requests, as required by Chapter III of the GDPR.


8. International Transfers

Mission Logix shall not transfer Protected Data outside the UK or to any International Organisation without prior written consent from the Customer.


9. Audits and Demonstration of Compliance

Mission Logix will:

  • Provide relevant documentation to demonstrate GDPR compliance;

  • Allow one audit per 12-month period by the Customer or authorised third-party, on reasonable notice and during business hours.


10. Personal Data Breach

Mission Logix shall notify the Customer without undue delay if it becomes aware of any Personal Data Breach involving Protected Data.


11. Data Deletion or Return

Upon termination of the Services:

  • The Customer may request the return or secure deletion of all Protected Data (at their expense);

  • Mission Logix shall delete all copies unless retention is legally required.


Part B – Data Processing and Security Measures


Section 1 – Data Processing Details

AspectDescription
Subject-MatterFulfilment and e-commerce services provided by Mission Logix
DurationFor the duration of the Customer’s contract
Nature & PurposeTo enable Mission Logix to pick, pack, store, and dispatch Customer orders
Types of Personal DataName, delivery address, email address, phone number
Categories of Data SubjectsIndividuals placing orders via ecommerce or wholesale channels

Section 2 – Technical & Organisational Security Measures

Mission Logix shall implement and maintain appropriate security controls to protect Protected Data, including:

  • Risk-based measures aligned with Article 32 GDPR

  • Access controls and role-based permissions

  • Secure data storage and encrypted backups

  • Regular audits and staff training

  • Network and infrastructure security (e.g., firewalls, endpoint protection)

  • Procedures for managing and reporting Personal Data Breaches

  • Data minimisation and retention controls

These controls are reviewed regularly and updated to reflect evolving best practices and legal requirements.