LastFolk — Data Processing Agreement (DPA)

    Last updated: July 15, 2026

    This Data Processing Agreement ("DPA") forms part of and is incorporated by reference into the LastFolk Terms & Conditions (the "Agreement") between Pictorica Devs LLC, a Wyoming limited liability company doing business as LastFolk ("LastFolk", "Processor"), and the Merchant that uses the Service ("Merchant", "Controller"). It governs LastFolk's processing of personal data on the Merchant's behalf. If there is a conflict between this DPA and the Agreement on data-protection matters, this DPA controls.

    1. Definitions

    • Data Protection Laws — all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended ("CCPA/CPRA"), the Brazilian LGPD, and other applicable privacy laws.
    • Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach — as defined in the EU GDPR.
    • End Customer Data — personal data relating to a Merchant's End Customers that LastFolk processes to provide the Service.
    • Subprocessor — any third party engaged by LastFolk to process personal data on the Merchant's behalf.
    • Standard Contractual Clauses (SCCs) — the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
    • UK IDTA — the UK International Data Transfer Addendum issued by the UK Information Commissioner.

    Terms not defined here have the meaning given in the Agreement.

    2. Roles and scope

    2.1 As between the parties, the Merchant is the Controller and LastFolk is the Processor of End Customer Data processed to provide the Service. LastFolk may act as an independent controller for its own operational purposes (security, billing, product operation), which are governed by the LastFolk Privacy Policy, not this DPA.

    2.2 This DPA applies to LastFolk's processing of Personal Data on the Merchant's behalf for the duration of the Agreement. The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex I.

    3. Processing on documented instructions

    3.1 LastFolk will process Personal Data only on the Merchant's documented instructions, including as set out in the Agreement, this DPA, and the Merchant's use of the Service, unless required to process by applicable law (in which case LastFolk will, where legally permitted, inform the Merchant beforehand).

    3.2 LastFolk will inform the Merchant if, in its opinion, an instruction infringes Data Protection Laws.

    3.3 The Merchant is responsible for ensuring it has a lawful basis and has provided all required notices and, where necessary, obtained consents to have End Customer Data processed through the Service and shared with Courier Partners.

    4. Confidentiality

    LastFolk ensures that personnel authorized to process Personal Data are bound by a duty of confidentiality and are granted access on a least-privilege, need-to-know basis.

    5. Security

    5.1 LastFolk implements appropriate technical and organizational measures to protect Personal Data against a Personal Data Breach, taking into account the state of the art, costs, and the risks to Data Subjects, in accordance with Article 32 of the EU GDPR. A summary of these measures is set out in Annex II.

    5.2 Current measures include encryption of Personal Data in transit (TLS/HTTPS) and at rest, role-based access controls, least-privilege practices, logging and monitoring, and secure development practices.

    6. Subprocessors

    6.1 The Merchant grants LastFolk general authorization to engage Subprocessors to process Personal Data, provided LastFolk: (a) enters into a written agreement imposing data-protection obligations no less protective than this DPA; and (b) remains liable to the Merchant for each Subprocessor's performance.

    6.2 The current categories of Subprocessors are: third-party courier networks; payment processor; cloud hosting and infrastructure; address and mapping services; and analytics, communications, and error-monitoring providers. A current list of specific Subprocessors is available on request via contact@lastfolk.com.

    6.3 LastFolk will give the Merchant at least thirty (30) days' advance notice of any intended addition or replacement of a Subprocessor. The Merchant may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Merchant may terminate the affected part of the Service.

    7. Assistance to the Controller

    7.1 Data Subject requests. Taking into account the nature of the processing, LastFolk will assist the Merchant by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests to exercise their rights. If LastFolk receives a request directly, it will not respond except to acknowledge and direct the Data Subject to the Merchant, unless legally required otherwise, and will promptly notify the Merchant.

    7.2 Security, breach, and DPIAs. LastFolk will assist the Merchant in ensuring compliance with its obligations regarding security of processing, Personal Data Breach notification, data protection impact assessments, and prior consultation, taking into account the information available to LastFolk.

    8. Personal Data Breach notification

    LastFolk will notify the Merchant without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting the Merchant's Personal Data, and will provide information reasonably available to enable the Merchant to meet its own notification obligations (including the 72-hour supervisory-authority deadline under the EU/UK GDPR).

    9. Deletion or return

    On termination of the Agreement, LastFolk will, at the Merchant's choice, delete or return all Personal Data processed on the Merchant's behalf and delete existing copies, unless applicable law requires continued storage. Absent instruction, LastFolk will delete or anonymize the Personal Data within ninety (90) days of termination, subject to legal retention requirements.

    10. Audit

    LastFolk will make available to the Merchant information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor it mandates. The Merchant may exercise audit rights no more than once per year (absent a Personal Data Breach or regulatory requirement), on reasonable prior notice, during business hours, subject to confidentiality, and LastFolk may satisfy audit requests by providing relevant third-party audit reports or certifications where available.

    11. International transfers

    11.1 Where LastFolk processes Personal Data originating in the EEA, the United Kingdom, or Switzerland in a country without an adequacy decision, the parties enter into the applicable SCCs, which are incorporated by reference:

    • Module Two (Controller-to-Processor) applies where the Merchant is a controller and LastFolk is a processor;
    • Module Three (Processor-to-Processor) applies where the Merchant is itself a processor.

    11.2 For transfers of UK Personal Data, the UK IDTA (or the UK Addendum to the EU SCCs) applies. For Swiss data, the SCCs apply with Swiss-specific adaptations.

    11.3 Where required, the parties will complete a transfer impact assessment and apply supplementary measures. The docking clause and the parties' details are completed in Annex III.

    12. Liability

    Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party's liability to Data Subjects or supervisory authorities to the extent such liability cannot be limited under Data Protection Laws.

    13. Term

    This DPA takes effect when the Merchant accepts the Agreement and continues until LastFolk has ceased all processing of Personal Data on the Merchant's behalf and completed deletion or return under Section 9.

    Annex I — Details of processing

    • Subject matter: provision of the LastFolk delivery-operations platform (rating, dispatch, tracking, reconciliation).
    • Duration: the term of the Agreement, plus any legally required retention period.
    • Nature and purpose: processing End Customer Data to rate, dispatch, track, and reconcile local deliveries on the Merchant's behalf, and to provide related support.
    • Types of Personal Data: recipient and sender names; delivery and pickup addresses; contact phone numbers; package attributes (size/weight); order identifiers; delivery status and tracking events; and, for Merchant users, account and contact details and billing identifiers. No special categories of data are intended to be processed.
    • Categories of Data Subjects: the Merchant's End Customers; the Merchant's authorized users; and, where applicable, senders/pickup contacts.

    Annex II — Technical and organizational measures

    Encryption in transit (TLS/HTTPS) and at rest; role-based and least-privilege access controls; authentication controls; logging, monitoring, and alerting; secure software development and change management; segregation of environments; backup and recovery; vendor/subprocessor due diligence; and incident-response procedures. Measures are reviewed and updated periodically.

    Annex III — Transfer mechanism details

    • Data exporter: the Merchant (name and address as provided at sign-up).
    • Data importer: Pictorica Devs LLC (LastFolk), 30 North Gould Street, Sheridan, Wyoming, United States.
    • Competent supervisory authority: as determined under Clause 13 of the SCCs / the relevant Data Protection Law.
    • Signature / acceptance: entering into the Agreement and this DPA constitutes signature of the applicable SCC modules and the UK IDTA.

    Contact

    Pictorica Devs LLC (LastFolk) — Data Protection Officer / privacy contact: contact@lastfolk.com — 30 North Gould Street, Sheridan, Wyoming, United States.