Ownprint's Policies

Data Processing Agreement

Pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR). Last updated 1 October 2026.

1. Parties

Controller: any person or business with an Ownprint account who uses the Ownprint platform to have personalized jewelry produced and shipped to its customers (the "Seller").

Processor: Ownprint Fulfillment, Groene Hilledijk 211A, 3073 AE Rotterdam, the Netherlands, Chamber of Commerce (KvK) 83712216, operator of ownprint.co and app.ownprint.co ("Ownprint").

How this Agreement is concluded. This Agreement forms part of the Ownprint Terms of Service. By creating an Ownprint account, or by continuing to use the platform after this Agreement was published, the Seller accepts it. No separate signature is required. It is governed by the same law and forum as the Terms of Service. Where this Agreement and the Terms of Service conflict on the processing of personal data, this Agreement prevails.

2. Subject matter, duration, nature and purpose

Subject matter. Ownprint processes personal data of the Seller's customers on the Seller's behalf for the sole purpose of producing, packing, shipping and supporting orders the Seller places through the Ownprint platform, including orders synced from the Seller's connected store.

Duration. For as long as the Seller has an Ownprint account, and afterwards only as set out in section 10.

Nature of processing. Receiving order data from the Seller or the Seller's connected store, storing it, engraving the personalization onto the product, printing shipping labels and message cards, handing the parcel to a carrier, providing tracking, handling remakes and support requests, and issuing invoices to the Seller.

3. Categories of data and data subjects

Data subjects. Customers of the Seller (recipients of orders); the Seller and the Seller's staff.

Personal data. Recipient name, shipping address, email address and phone number where the Seller or the store provides them; order contents; personalization content (engraving text, names, dates, uploaded photos or artwork, message card text); order number and tracking number; the Seller's account and billing details.

Special categories. None are required. Personalization content chosen by the customer may incidentally contain such data (for example a religious symbol or a memorial text); Ownprint processes it only to produce the ordered item.

4. Ownprint's obligations

Ownprint shall:

  1. process personal data only on the Seller's documented instructions, which are the order data and settings the Seller submits through the platform, unless required to do otherwise by EU or Member State law, in which case Ownprint informs the Seller before processing where the law permits;
  2. ensure that persons authorised to process the personal data are bound by confidentiality;
  3. implement the technical and organisational measures in Annex 2;
  4. engage sub-processors only as set out in section 6;
  5. taking into account the nature of the processing, assist the Seller with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under Chapter III GDPR;
  6. assist the Seller in meeting its obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to Ownprint;
  7. delete or return the personal data as set out in section 10;
  8. make available to the Seller the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as set out in section 8;
  9. inform the Seller without undue delay if, in Ownprint's opinion, an instruction infringes the GDPR or other EU or Member State data protection law.

5. The Seller's obligations

The Seller is responsible for the lawfulness of the personal data it submits, for informing its customers about the processing in its own privacy policy, for the accuracy of order data, and for not submitting personal data that is not needed to produce and ship the order.

6. Sub-processors

The Seller gives Ownprint general authorisation to engage the sub-processors listed in Annex 1. Ownprint imposes on each sub-processor data protection obligations equivalent to those in this Agreement by way of a contract, and remains fully liable to the Seller for the performance of the sub-processor's obligations.

Ownprint informs the Seller of any intended addition or replacement of a sub-processor at least 14 days in advance by email to the Seller's account email address or by notice in the platform. The Seller may object in writing within that period on reasonable data protection grounds. If the objection cannot be resolved, the Seller may terminate the account without penalty for orders not yet placed.

7. International transfers

All personal data processed under this Agreement is stored on Ownprint's systems in the Netherlands. Personal data of customers whose orders are delivered inside the European Economic Area does not leave the EEA.

For orders delivered to the United States, Canada, Australia or New Zealand, the order details needed to produce and ship that specific order (recipient name and address, order contents and personalization) are forwarded to Ownprint's production facility in California, United States. The data remains stored in the Netherlands. This forwarding is necessary for the performance of the order placed in the interest of the customer (Article 49(1)(c) GDPR).

Where a sub-processor in Annex 1 is established outside the EEA, the safeguard listed for it in Annex 1 applies.

8. Audits

On written request, no more than once per year unless a supervisory authority requires otherwise or a personal data breach has occurred, Ownprint provides the Seller with the information reasonably necessary to demonstrate compliance with this Agreement. Where that information is not sufficient, the Seller or an independent auditor bound by confidentiality may audit Ownprint's relevant processing during business hours, on 30 days' notice, in a manner that does not disrupt Ownprint's operations. Each party bears its own costs.

9. Personal data breach

Ownprint notifies the Seller without undue delay after becoming aware of a personal data breach affecting the Seller's customer data, by email to the Seller's account email address. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Ownprint provides further information as it becomes available.

10. Deletion and return

Ownprint retains order data for as long as the Seller has an Ownprint account, so the Seller can view order history, reorder and request remakes, and afterwards only as long as EU or Member State law requires, in particular the Dutch retention period for accounting records. On the Seller's written request, or when the Seller's account is closed, Ownprint deletes the personal data of the Seller's customers except for the data in invoices and accounting records that must be retained by law, and confirms deletion in writing. The Seller can export its order data from the platform at any time before closing the account.

11. Liability and term

Liability under this Agreement is governed by the liability provisions of the Terms of Service, without prejudice to the parties' liability under Article 82 GDPR. This Agreement applies from the moment the Seller accepts the Terms of Service and remains in force for as long as Ownprint processes personal data on the Seller's behalf. Ownprint may update this Agreement to reflect changes in law or in its sub-processors; the date at the top shows the latest update, and changes to sub-processors follow the notice procedure in section 6.

Annex 1. Sub-processors (last updated 1 October 2026)

  • GoDaddy. Hosting of the Ownprint platform and database. Location: Netherlands. Safeguard: none required, EEA.
  • Google Cloud. Storage of order files (designs, uploaded images, message cards). Location: Netherlands. Safeguard: none required, EEA.
  • Ownprint production facility, California. Receives the order details needed to produce and ship orders delivered to the US, Canada, Australia and New Zealand only. No storage of EU customer data. Location: United States. Safeguard: Article 49(1)(c) GDPR, necessary to perform the order.
  • Shipping carriers used for the order. Transport and delivery of parcels; receive recipient name, address, and phone number or email where provided, for delivery and tracking. Location: country of dispatch and delivery. Safeguard: carriers act under their own legal obligations for postal and transport services.
  • Zendesk, Inc. Support ticketing. Holds the Seller's contact details, and end-customer details only where the Seller includes them in a ticket about an order. Location: United States. Safeguard: EU-U.S. Data Privacy Framework certification and Zendesk's Data Processing Agreement with Standard Contractual Clauses.

Annex 2. Technical and organisational measures

  • Encryption. All data is encrypted in transit using TLS and at rest on the hosting infrastructure in the Netherlands.
  • Access control. Access to personal data is restricted to staff who need it to produce orders or provide support, on a least-privilege basis, protected by multi-factor authentication. Access is reviewed and revoked when no longer needed.
  • Data minimisation. Only the data needed to produce and ship an order is collected. Shipping labels and message cards carry the Seller's shop name, not Ownprint's.
  • Logging and monitoring. Access to the production systems is logged and monitored.
  • Backups. Regular backups of the platform data are kept.
  • Incident response. A documented incident response and breach notification procedure is in place.
  • Staff. Staff and contractors with access are bound by confidentiality and receive data protection instructions.