POD Hut Data Processing Addendum

Data Processing Addendum

Last updated: October 7, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Custom Hut LLC, a Nevada limited liability company doing business as POD Hut ("POD Hut", "we", "us") and the member who accepts the POD Hut Terms and Conditions ("you", "Member"). It applies whenever POD Hut processes personal information about your customers in order to provide our services to you.

If any term of this DPA conflicts with the rest of the Terms and Conditions, this DPA controls on the subject of personal data processing.


1. Roles

You are the controller of your customers' personal information. You decide why it is collected and what happens to it.

POD Hut is a processor acting on your instructions when we handle that information to print and ship your orders.

POD Hut is a controller in its own right for your own business and account information, for our billing records, and for our security and audit logs.

Each party will comply with the data protection laws that apply to it.


2. What we process, and why

Categories of individual Your customers who buy products we fulfill
Categories of data Name, shipping address, email address, phone number, order contents, order number, delivery and tracking information
Purpose Producing, quality-checking, packing, labeling and shipping the order; providing tracking back to your store; handling reprints, returns and delivery problems
Duration As described in section 8
Special category data None. Do not send us health, biometric, financial account, government ID or other special category data. If your product or artwork would require it, contact us first.

3. Your instructions

We process your customers' personal information only to provide the services described in the Terms and Conditions, on your documented instructions including instructions given through the POD Hut app, and as required by law.

We will tell you if we believe an instruction you give us breaks data protection law. We will not use your customers' personal information for our own purposes, will not sell it, will not share it for advertising, and will not use it to market to your customers.


4. Confidentiality and staff

We limit access to your customers' personal information to staff and contractors who need it to do their job. Everyone with access is bound by confidentiality obligations that survive the end of their engagement, and we keep a log of access to this data.


5. Security

We maintain technical and organizational measures appropriate to the risk, including encryption of personal data in transit and at rest, encrypted backups, separation of test and production environments, restricted administrative access with multi-factor authentication, access logging, and a documented security incident response policy. A current description of these measures is available on request.


6. Sub-processors

You authorize us to use sub-processors to provide the services. Our current sub-processors, what they do, and what data they handle are listed in the POD Hut App Privacy Policy.

We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible to you for their performance.

We will give you at least 30 days' notice before adding or replacing a sub-processor that handles your customers' personal information. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative. If we cannot, you may terminate the affected service without penalty for the unused portion of any prepaid period.


7. Requests from your customers, and from authorities

If one of your customers contacts us about their personal information, we will not respond on your behalf. We will tell them to contact you, and we will tell you about the request.

We will help you respond to your customers' requests for access, correction, deletion, portability, restriction or objection, and we will help you with data protection impact assessments and consultations with regulators, at no additional charge for reasonable assistance.

If a public authority demands your customers' personal information from us, we will tell you before disclosing anything unless the law forbids us from telling you.


8. Retention and deletion

We keep your customers' name, address, phone number and email address for 120 days after the order has been fulfilled and delivered, or after the delivery window has closed, and then delete or irreversibly anonymize it.

We keep order and production records without those contact details for 7 years, for tax, warranty and reprint-dispute purposes.

When you uninstall the app or your membership ends, our access to your store ends immediately. We delete or anonymize your customers' personal information within 90 days, except where law requires us to keep it. On request, we will confirm deletion in writing.


9. Personal data breaches

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your customers' personal information, we will notify you without undue delay and in any case within 48 hours of becoming aware. The notice will describe what happened, what data and roughly how many individuals are affected, what we are doing about it, and who to contact for more information. We will not make a public statement naming you without consulting you first, unless we are legally required to.


10. Audits

On reasonable written notice, not more than once a year unless a breach or a regulator requires it, we will provide the information you reasonably need to confirm we are meeting this DPA. We may satisfy an audit request by providing a current third-party report, a completed security questionnaire, or a written description of our measures, before granting any on-site access. Audits must not disrupt our operations or reveal another member's information.


11. International transfers

We process personal information in the United States. Where you are established in the European Economic Area, the United Kingdom or Switzerland, or where you send us personal information protected by their laws, the European Commission's Standard Contractual Clauses (Module Two, controller to processor) apply and are incorporated into this DPA, with the UK Addendum where relevant. The details in section 2 populate the Annexes. In the event of a conflict, the Standard Contractual Clauses control.


12. Term

This DPA takes effect when you accept the POD Hut Terms and Conditions and continues for as long as we process your customers' personal information, and then until that information is deleted or returned.


Contact

Custom Hut LLC
7195 Bermuda Rd, Las Vegas, NV 89119
Email: contact@podhut.com