Data Processing Addendum
Version 1.0 — effective 26 July 2026
This Data Processing Addendum (the DPA) forms part of the agreement governing the Customer's use of any service provided by Ingram Technologies SRL that refers to this DPA (the Agreement).
The parties to this DPA are:
- Ingram Technologies SRL, a Belgian private limited liability company with enterprise and VAT number BE 0766.280.697 and registered office at Rue du Poinçon 51A, 1000 Brussels, Belgium (Ingram, we, us); and
- the person or entity that has entered into the Agreement with Ingram (Customer, you).
This DPA takes effect when the Customer accepts it electronically, enters into an Agreement that incorporates it, or begins using a Service whose terms incorporate it. A person accepting this DPA for an entity represents that they have authority to bind that entity.
Each Service is described in a product annex referenced by its terms or account interface. The applicable product annex forms part of this DPA and describes the processing required by Article 28(3) GDPR.
1. Definitions
In this DPA:
- Applicable Data Protection Law means the GDPR, the Belgian Act of 30 July 2018 concerning the protection of natural persons with regard to the processing of personal data, and any other privacy or data-protection law applicable to processing under the Agreement.
- Customer Personal Data means Personal Data contained in Customer Data that Ingram processes on the Customer's behalf in providing a Service.
- Data Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data on systems controlled by Ingram or its Subprocessors. It does not include unsuccessful attempts that do not compromise Customer Personal Data.
- GDPR means Regulation (EU) 2016/679.
- Product Annex means the service-specific processing annex identified in the Agreement or Service.
- Restricted Transfer means a transfer of Personal Data for which Applicable Data Protection Law requires an approved transfer mechanism.
- SCCs means the European Commission's standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
- Service means a product or service supplied by Ingram under the Agreement.
- Subprocessor means a third party appointed by or on behalf of Ingram to process Customer Personal Data in connection with a Service.
The terms Controller, Data Subject, Personal Data, Personal Data Breach, Process, Processor, and Supervisory Authority have the meanings given in the GDPR.
2. Scope and roles
2.1. This DPA applies only where Ingram processes Customer Personal Data as a Processor on behalf of the Customer.
2.2. The Customer is the Controller of Customer Personal Data or a Processor validly acting on behalf of another Controller. Ingram is the Customer's Processor or, where the Customer is itself a Processor, its Subprocessor.
2.3. Each party shall comply with the obligations that apply to it under Applicable Data Protection Law.
2.4. If the Customer acts as a Processor, it warrants that the relevant Controller has authorized the Customer's instructions, Ingram's appointment, and the appointment of the Subprocessors authorized under this DPA. The Customer will act as Ingram's sole point of contact for that Controller unless Applicable Data Protection Law requires otherwise.
2.5. Ingram may process information as an independent Controller for its own account administration, billing, fraud prevention, network and service security, legal compliance, and business communications. This DPA does not govern that processing, which is described in Ingram's Privacy Policy.
3. Documented instructions
3.1. Ingram shall process Customer Personal Data only on the Customer's documented instructions, unless Union or Member State law requires otherwise. The Agreement, this DPA, the applicable Product Annex, the Customer's configuration and use of the Service, and other written instructions accepted by Ingram constitute the Customer's complete documented instructions.
3.2. The Customer instructs Ingram to process Customer Personal Data as necessary to provide, maintain, secure, troubleshoot, and support the Service; to perform the Agreement; and to comply with other documented instructions consistent with the Agreement.
3.3. If law requires processing outside those instructions, Ingram shall inform the Customer before processing unless the law prohibits that information on important grounds of public interest.
3.4. Ingram shall promptly inform the Customer if, in Ingram's opinion, an instruction infringes Applicable Data Protection Law. Ingram may suspend the affected processing until the Customer confirms or modifies the instruction.
3.5. The Customer is responsible for the lawfulness, accuracy, quality, and content of Customer Personal Data and its instructions. It shall provide required notices, establish a lawful basis, and obtain any authorization needed for Ingram and its Subprocessors to process Customer Personal Data.
3.6. Unless a Product Annex expressly provides otherwise, the Customer shall not intentionally submit special categories of Personal Data under Article 9 GDPR or Personal Data relating to criminal convictions and offences under Article 10 GDPR.
4. Processing details
The applicable Product Annex states:
- the subject matter, nature, and purpose of processing;
- the duration and frequency of processing;
- the categories of Data Subjects;
- the categories of Customer Personal Data;
- any special-category restrictions;
- service-specific retention and deletion arrangements;
- relevant international transfers; and
- the location of the current Subprocessor list.
5. Confidentiality and personnel
Ingram shall ensure that each person authorized to process Customer Personal Data:
- is bound by an appropriate contractual or statutory duty of confidentiality;
- receives access only where necessary for their duties; and
- receives appropriate privacy and security guidance.
Ingram remains responsible for its personnel's compliance with this DPA.
6. Security
6.1. Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks to Data Subjects, Ingram shall implement and maintain appropriate technical and organizational measures designed to provide a level of security appropriate to the risk.
6.2. Those measures include, as appropriate:
- encryption in transit and at rest;
- access control, least privilege, and authentication controls;
- separation of customer environments or data;
- secure software development and change management;
- vulnerability, dependency, and patch management;
- logging, monitoring, and incident response;
- backup, resilience, and recovery arrangements;
- data minimization and retention controls;
- confidentiality and security requirements for personnel; and
- risk-based assessment and contractual control of Subprocessors.
6.3. A Product Annex may describe additional service-specific measures. Ingram may update its measures to reflect technical development, provided the overall protection of Customer Personal Data is not materially reduced.
6.4. The Customer is responsible for securing its credentials, accounts, systems, devices, and integrations; controlling its authorized users; and configuring and using the Service in a manner appropriate to its risk.
7. Data Incidents
7.1. Ingram shall notify the Customer without undue delay after becoming aware of a Data Incident affecting Customer Personal Data. Notice will be sent to the Customer's designated privacy contact or account email.
7.2. To the extent known and available, the notice shall describe:
- the nature of the Data Incident;
- the affected categories and approximate numbers of Data Subjects and records;
- the likely consequences;
- the measures taken or proposed to address and mitigate it; and
- a contact point for further information.
Ingram may provide information in phases without undue further delay.
7.3. Ingram shall take reasonable steps to contain, investigate, mitigate, and remediate the Data Incident and shall reasonably cooperate with the Customer. Notification is not an admission of fault or liability. The Customer remains responsible for notifications it must make as Controller.
8. Data Subject requests
8.1. Taking into account the nature of the processing, Ingram shall assist the Customer through appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise Data Subject rights.
8.2. If Ingram receives a request relating to Customer Personal Data directly, it shall promptly refer the request to the Customer and shall not respond substantively unless instructed by the Customer or required by law.
9. Compliance assistance
Taking into account the nature of processing and the information available to Ingram, Ingram shall provide reasonable assistance with the Customer's obligations under Articles 32 to 36 GDPR, including security assessments, Personal Data Breach notifications, data protection impact assessments, and prior consultations.
If assistance requires material work beyond ordinary support, the parties may agree reasonable fees in advance, except where the assistance is required because Ingram breached this DPA.
10. Subprocessors
10.1. The Customer gives Ingram general written authorization to appoint Subprocessors in accordance with this section. The current Subprocessors for each Service are identified on the page referenced by the applicable Product Annex.
10.2. Ingram shall enter into a written agreement with each Subprocessor imposing data-protection obligations that are no less protective in substance than the obligations imposed on Ingram by this DPA, to the extent relevant to the Subprocessor's services.
10.3. For a planned appointment or replacement, Ingram shall provide at least 30 days' advance notice by updating the relevant Subprocessor page and sending notice to the Customer's account email before the new Subprocessor begins processing Customer Personal Data.
10.4. Where an urgent replacement is reasonably necessary to address a security risk, service failure, legal requirement, or material threat to service continuity, Ingram may appoint the replacement before the 30-day period expires. Ingram shall notify the Customer as soon as reasonably practicable, explain the reason for the urgent change, and preserve the Customer's objection right under section 10.5.
10.5. The Customer may object to a new or replacement Subprocessor on reasonable, documented data-protection grounds. The parties shall work in good faith to resolve the objection. If no commercially reasonable solution is available, the Customer may terminate only the affected Service by written notice. Where applicable, Ingram shall refund prepaid fees for the unused terminated period.
10.6. Ingram remains responsible to the Customer for a Subprocessor's performance of its data-protection obligations to the same extent Ingram would be responsible if performing the relevant processing itself.
11. International transfers
11.1. Ingram shall not make a Restricted Transfer unless it has implemented a lawful transfer mechanism and any supplementary measures required by Applicable Data Protection Law. Mechanisms may include an adequacy decision, the EU-US Data Privacy Framework for a certified recipient, or the SCCs.
11.2. Where the SCCs are required for a transfer from the Customer to Ingram, they are incorporated by reference and completed as follows:
- Module Two applies where the Customer is a Controller and Ingram is a Processor.
- Module Three applies where the Customer is a Processor and Ingram is a Subprocessor.
- Module Four applies where Ingram, acting as a Processor in the EEA, transfers or returns Personal Data to a Customer acting as a Controller in a third country and the transfer requires the SCCs.
- Clause 7, the docking clause, applies.
- Option 2 in Clause 9(a) applies, with the notice arrangements in section 10.
- The optional language in Clause 11 does not apply.
- In Clause 17, Option 1 applies and Belgian law governs.
- The courts of Brussels, Belgium are selected under Clause 18(b).
- This DPA and the applicable Product Annex complete Annexes I and II of the SCCs; the relevant Subprocessor page completes Annex III.
11.3. Where Ingram transfers Customer Personal Data onward to a Subprocessor in a manner requiring safeguards, Ingram shall implement an appropriate Chapter V GDPR mechanism and assess whether supplementary measures are required.
12. Return and deletion
12.1. During the Agreement, the Customer may request export or deletion to the extent supported by the Service.
12.2. Upon termination of the affected Service or the Customer's written request, Ingram shall, at the Customer's choice, delete or return Customer Personal Data and delete remaining copies, unless applicable law requires retention. Service-specific implementation periods and exceptions are stated in the applicable Product Annex.
12.3. Where retention is legally required, Ingram shall isolate and protect the retained Customer Personal Data, process it only for the legally required purpose, and delete it when the requirement ends.
12.4. Customer Personal Data in backups shall be deleted or rendered inaccessible through Ingram's ordinary backup lifecycle, as described in the Product Annex.
13. Information and audits
13.1. Ingram shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, including relevant policies, security summaries, and responses to reasonable questionnaires, subject to confidentiality and security restrictions.
13.2. The Customer may request an audit no more than once in any 12-month period, unless a Supervisory Authority requires otherwise or a Data Incident reasonably warrants an additional audit. The parties shall first seek to satisfy the request through documents and remote review.
13.3. If an on-site or independent audit remains reasonably necessary, it shall take place on reasonable prior notice, during normal business hours, without unreasonable disruption, under confidentiality obligations, and with scope limited to systems and records relevant to Customer Personal Data.
13.4. The Customer bears its audit costs unless the audit identifies a material breach by Ingram. An audit may not expose another customer's data, trade secrets, or information that would create a security risk.
14. Liability and precedence
14.1. The liability provisions of the Agreement apply to this DPA, except to the extent prohibited by Applicable Data Protection Law or the SCCs. Nothing in the Agreement or this DPA limits a Data Subject's rights under Applicable Data Protection Law.
14.2. If this DPA conflicts with the Agreement concerning the processing or protection of Customer Personal Data, this DPA prevails. If the SCCs apply and conflict with this DPA or the Agreement, the SCCs prevail.
14.3. This DPA supersedes any earlier data processing addendum between the parties concerning the same Service, unless a later bilateral addendum expressly states otherwise.
15. Term, changes, and general terms
15.1. This DPA continues for as long as Ingram processes Customer Personal Data and survives termination to the extent necessary to protect that data.
15.2. Ingram may amend this DPA where reasonably necessary to comply with Applicable Data Protection Law, a binding decision, or a material change to a Service. Ingram shall provide advance notice of a material change where practicable. No amendment will materially reduce the protection of Customer Personal Data without a lawful basis.
15.3. This DPA is in writing in electronic form for the purposes of Article 28(9) GDPR. Electronic acceptance records are evidence of agreement. The parties may execute a bilateral counterpart on request without changing the canonical terms unless expressly agreed.
15.4. This DPA is governed by Belgian law, and disputes are subject to the courts specified in the Agreement, without prejudice to mandatory rights under Applicable Data Protection Law or the SCCs.
16. Contact
Privacy and data-protection enquiries: privacy@ingram.tech
Legal notices: legal@ingram.tech
Security reports: security@ingram.tech
