When a merchant instructs EasyPrepForYou Ltd to fulfil orders for its customers, the merchant is normally the controller of recipient/order data and EasyPrepForYou Ltd is its processor for the agreed service. This page sets out the framework to include in a signed merchant agreement. It does not replace the need to agree the actual processing schedule and subprocessors with each merchant.
Processing schedule
Subject and duration: receiving, preparing, storing, dispatching and handling returns for the merchant’s goods during the service relationship and agreed wind-down/retention period. Nature and purpose: using order and delivery instructions only to provide the contracted 3PL service. People: merchant staff and buyers, recipients and return senders. Data: names, business/contact details, delivery and return addresses, order identifiers, item/SKU and shipment information and relevant instructions. The merchant must identify any additional or sensitive data before sharing it.
Documented instructions and confidentiality
We will process merchant-controlled personal data only on the merchant’s documented instructions, including any international transfer, unless UK law requires otherwise; where legally permitted we will tell the merchant of that requirement. We will promptly tell the merchant if an instruction appears to breach data-protection law. People authorised to process the data must be bound by confidentiality.
Security and assistance
We will use appropriate technical and organisational measures proportionate to the service and risks, and provide the merchant with information needed to assess them. We will assist, taking account of the processing and information available, with data-subject requests, security incidents, breach notifications, impact assessments and regulator consultations. The incident contact and detailed response arrangements should be recorded in the merchant agreement. We do not claim a security certification that has not been verified.
Subprocessors and transfers
Where a courier, hosting/email provider, platform integration or other provider will process merchant-controlled recipient data for us, the merchant agreement must identify the relevant provider or category, the required authorisation/change process and equivalent data-protection obligations. We remain responsible for an authorised subprocessor’s performance of those obligations. Transfers outside the UK require the merchant’s instructions and an applicable lawful transfer basis. The actual provider list and locations must be confirmed for each workflow; a logo alone is not a subprocessor list.
End of service, records and audit
At the merchant’s choice after the service ends, we will return or delete merchant-controlled personal data, unless applicable law requires retention. The agreed schedule should account for operational records, invoices, backups and any lawful exception. We will make reasonably necessary compliance information available and allow or contribute to proportionate audits or inspections under agreed confidentiality and security arrangements. Our internal retention policy normally keeps recipient operational data for 12 months after completion, subject to the merchant agreement and lawful exceptions; automated deletion is not claimed.
Agreeing these terms
The merchant and EasyPrepForYou Ltd should attach a completed processing schedule and approved subprocessor list to their written service agreement before live recipient data is exchanged. For a copy or to discuss the terms, contact admin@easyprepforyou.co.uk. Last reviewed 30 September 2026.
