Data Processing Addendum

Last updated on May 1, 2026

This Data Processing Addendum (the DPA) forms part of the agreement governing the Customer's use of any service provided by Ingram Technologies SRL that refers to this DPA (the Agreement). The parties are:

  • Ingram Technologies SRL, a Belgian private limited liability company with company number 0766280697, VAT number BE0766280697, and registered office at Rue du Poinçon 51A, 1000 Brussels, Belgium (Ingram, we, us); and
  • the person or entity that has entered into the Agreement with Ingram (Customer, you).

This DPA takes effect when the Customer accepts it electronically, enters into an Agreement that incorporates it, or begins using a Service whose terms incorporate it. A person accepting for an entity represents that they have authority to bind it.

This DPA applies to every Ingram Service. Each Service publishes its own Product Annex, linked from that Service's terms or legal pages, setting out the service-specific processing detail Article 28(3) GDPR requires. The applicable Product Annex forms part of this DPA.

The Privacy Policy describes the personal data Ingram processes as an independent Controller for its own account, and the rights of the individuals concerned. The Security & Compliance page describes Ingram's technical and organizational measures, and is incorporated as set out in section 6.2.

1. Definitions

  • Applicable Data Protection Law — the GDPR, the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, and any other privacy or data-protection law applicable to processing under the Agreement.
  • Customer Personal Data — Personal Data that Ingram processes on the Customer's behalf in providing a Service.
  • Data Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data on systems controlled by Ingram or its Subprocessors. Unsuccessful attempts that do not compromise Customer Personal Data are not Data Incidents.
  • GDPR — Regulation (EU) 2016/679.
  • Product Annex — the service-specific processing annex published for a Service, or that the Agreement otherwise identifies.
  • SCCs — the European Commission's standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
  • Service — a product or service supplied by Ingram under the Agreement.
  • Subprocessor — a third party appointed by or on behalf of Ingram to process Customer Personal Data in connection with a Service.

Controller, Data Subject, Personal Data, Personal Data Breach, Process, Processor, and Supervisory Authority have the meanings given in the GDPR.

2. Scope and roles

2.1. This DPA applies only where Ingram processes Customer Personal Data as a Processor on the Customer's behalf. The Customer is the Controller of that data, or a Processor acting for another Controller. Where the Customer is a Processor, Ingram is its Subprocessor. Each party complies with the obligations that apply to it under Applicable Data Protection Law.

2.2. A Customer acting as a Processor warrants that the relevant Controller has authorized its instructions, Ingram's appointment, and the Subprocessors authorized under this DPA, and will act as Ingram's sole point of contact for that Controller unless the law requires otherwise.

2.3. Ingram also processes information as an independent Controller, for account administration, billing, fraud prevention, security, legal compliance, and business communications. That processing is outside this DPA and is described in the Privacy Policy.

3. Documented instructions

3.1. Ingram processes Customer Personal Data only on the Customer's documented instructions, unless Union or Member State law requires otherwise. Those instructions are the Agreement, this DPA, the applicable Product Annex, the Customer's configuration and use of the Service, and any further written instruction Ingram accepts. They authorize Ingram to process Customer Personal Data as necessary to provide, maintain, secure, troubleshoot, and support the Service and to perform the Agreement.

3.2. If law requires processing outside those instructions, Ingram will inform the Customer beforehand unless the law prohibits it on important grounds of public interest.

3.3. Ingram will promptly tell the Customer if an instruction appears to infringe Applicable Data Protection Law, and may suspend the affected processing until the Customer confirms or modifies it.

3.4. The Customer is responsible for the lawfulness, accuracy, and content of Customer Personal Data and its instructions, including giving required notices, establishing a lawful basis, and obtaining any authorization Ingram and its Subprocessors need.

3.5. Unless a Product Annex says otherwise, the Customer will not intentionally submit special categories of Personal Data under Article 9 GDPR, or data relating to criminal convictions and offences under Article 10 GDPR.

3.6. Where a Service uses AI-assisted processing, Ingram warrants that its agreement with each AI provider prohibits the provider from using Customer Personal Data to train, fine-tune, or otherwise develop or improve its models. Ingram will not use Customer Personal Data for those purposes itself.

4. Processing details

The applicable Product Annex sets out the subject matter, nature, purpose, duration and frequency of processing; the categories of Data Subjects and of Customer Personal Data; any special-category restrictions; the retention and deletion arrangements; the relevant international transfers; and where to find the current Subprocessor list.

5. Confidentiality and personnel

Everyone Ingram authorizes to process Customer Personal Data is bound by a duty of confidentiality, gets access only where their duties require it, and is trained on Ingram's security and privacy practices. Ingram remains responsible for its personnel's compliance with this DPA.

6. Security

6.1. Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Ingram implements and maintains technical and organizational measures designed to provide a level of security appropriate to the risk, as Article 32 GDPR requires.

6.2. Those measures are described on the Security & Compliance page. That page, with any additional measures in the applicable Product Annex, is Ingram's description of its technical and organizational measures for the purposes of Article 28(3)(c) GDPR and Annex II of the SCCs, as it reads on the date this DPA takes effect. Ingram may update them to reflect technical development or changes to a Service provided the overall level of protection is not materially reduced, and will supply a point-in-time copy of the measures then in force on request.

6.3. The Customer is responsible for securing its own credentials, accounts, systems, devices, and integrations, controlling its authorized users, and configuring the Service appropriately for its risk.

7. Data Incidents

7.1. Ingram notifies the Customer without undue delay after becoming aware of a Data Incident affecting Customer Personal Data, at the Customer's designated privacy contact or account email. The notice contains the information listed in Article 33(3) GDPR to the extent known, and a contact point; Ingram may provide it in phases without undue further delay.

7.2. Ingram takes reasonable steps to contain, investigate, mitigate, and remediate the Data Incident, and cooperates reasonably with the Customer. Notification is not an admission of fault or liability, and the Customer remains responsible for the notifications it must make as Controller.

8. Data Subject requests

Taking into account the nature of the processing, Ingram assists the Customer through appropriate technical and organizational measures, insofar as possible, in responding to requests to exercise Data Subject rights. If Ingram receives such a request directly, it promptly refers it to the Customer and does not respond substantively unless the Customer instructs it to or the law requires it.

9. Compliance assistance

Taking into account the nature of processing and the information available to it, Ingram provides reasonable assistance with the Customer's obligations under Articles 32 to 36 GDPR, including security assessments, Personal Data Breach notifications, data protection impact assessments, and prior consultations.

If assistance requires material work beyond ordinary support, the parties may agree reasonable fees in advance. No fee applies where the assistance is needed because Ingram breached this DPA.

10. Subprocessors

10.1. The Customer gives Ingram general written authorization to appoint Subprocessors in accordance with this section. The current Subprocessors for each Service are identified on the page the applicable Product Annex references.

10.2. Ingram enters into a written agreement with each Subprocessor imposing data-protection obligations no less protective in substance than those this DPA imposes on Ingram, to the extent relevant to that Subprocessor's services.

10.3. For a planned appointment or replacement, Ingram gives at least 30 days' advance notice, by updating the relevant Subprocessor page and sending notice to the Customer's account email, before the new Subprocessor begins processing Customer Personal Data.

10.4. Where an urgent replacement is reasonably necessary to address a security risk, service failure, legal requirement, or material threat to service continuity, Ingram may appoint it sooner. Ingram will notify the Customer as soon as reasonably practicable, explain the reason, and preserve the objection right in section 10.5.

10.5. The Customer may object to a new or replacement Subprocessor on reasonable, documented data-protection grounds. The parties will work in good faith to resolve the objection; if no commercially reasonable solution is available, the Customer may terminate the affected Service by written notice, and Ingram will refund prepaid fees for the unused period where applicable.

10.6. Ingram remains responsible to the Customer for a Subprocessor's performance of its data-protection obligations to the same extent Ingram would be if it performed the processing itself.

11. International transfers

11.1. Ingram does not transfer Customer Personal Data outside the EEA unless it has a transfer mechanism valid under Chapter V GDPR and any supplementary measures the assessment shows to be required. The mechanisms Ingram relies on are described under "International Data Transfers" in the Privacy Policy; transfers specific to a Service are identified in its Product Annex. The same applies to onward transfers to a Subprocessor.

11.2. Where the SCCs are required for a transfer from the Customer to Ingram, they are incorporated by reference and completed as follows:

  • Module Two applies where the Customer is a Controller and Ingram is a Processor.
  • Module Three applies where the Customer is a Processor and Ingram is a Subprocessor.
  • Module Four applies where Ingram, acting as a Processor in the EEA, transfers or returns Personal Data to a Customer acting as a Controller in a third country and the transfer requires the SCCs.
  • Clause 7, the docking clause, applies.
  • Option 2 in Clause 9(a) applies, with the 30 days' notice period set out in section 10.3.
  • The optional language in Clause 11 does not apply.
  • For the purposes of Clause 13(a), the competent supervisory authority is the Belgian Data Protection Authority.
  • In Clause 17, Option 1 applies and Belgian law governs.
  • The courts of Brussels, Belgium are selected under Clause 18(b).
  • Annex I is completed by this DPA and the applicable Product Annex; Annex II by the measures referenced in section 6.2; and Annex III by the relevant Subprocessor page.

12. Return and deletion

12.1. During the Agreement, the Customer may request export or deletion to the extent the Service supports it.

12.2. On termination of the affected Service or the Customer's written request, Ingram will, at the Customer's choice, delete or return Customer Personal Data and delete remaining copies, unless the law requires retention. The periods within which deletion takes effect, including for backups, are those published under "Data Retention" and "Data Removal" on the Security & Compliance page as it reads on the date this DPA takes effect, as varied by the applicable Product Annex. Ingram may update those periods to reflect technical development or changes to a Service provided the overall level of protection is not materially reduced.

12.3. Where retention is legally required, Ingram isolates and protects the retained data, processes it only for that purpose, and deletes it when the requirement ends.

13. Information and audits

13.1. Ingram makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. That includes the published Security & Compliance documentation, a summary of Ingram's most recent independent penetration test findings on request, an overview of Ingram's security policies on request for enterprise customers, and responses to reasonable questionnaires, subject to confidentiality and security restrictions.

13.2. The Customer may request an audit once in any 12-month period, unless a Supervisory Authority requires otherwise or a Data Incident reasonably warrants another. The parties will first seek to satisfy the request through documents and remote review.

13.3. If an on-site or independent audit remains reasonably necessary, it takes place on reasonable prior notice, during business hours, without unreasonable disruption, under confidentiality obligations, and limited in scope to systems and records relevant to Customer Personal Data. The Customer bears its audit costs unless the audit identifies a material breach by Ingram. An audit may not expose another customer's data, trade secrets, or anything that would create a security risk.

14. Liability and precedence

14.1. The liability provisions of the Agreement apply to this DPA, except to the extent Applicable Data Protection Law or the SCCs prohibit limiting or excluding liability. Nothing here limits a Data Subject's rights.

14.2. On the processing or protection of Customer Personal Data, this DPA prevails over the Agreement, and over any page it incorporates, to the extent of a conflict. The applicable Product Annex prevails over this DPA where it expressly varies it. Where the SCCs apply, they prevail over all of them.

14.3. This DPA supersedes any earlier data processing addendum between the parties for the same Service, unless a later bilateral addendum expressly says otherwise.

15. Term and changes

15.1. This DPA continues for as long as Ingram processes Customer Personal Data, and survives termination to the extent necessary to protect that data.

15.2. Ingram may amend this DPA where reasonably necessary to comply with Applicable Data Protection Law, a binding decision, or a material change to a Service, giving advance notice of a material change where practicable. No amendment will materially reduce the protection of Customer Personal Data.

15.3. This DPA is in writing in electronic form for the purposes of Article 28(9) GDPR, and electronic acceptance records are evidence of agreement. The parties may execute a bilateral counterpart on request; the counterpart does not change the terms of this DPA unless it expressly says so.

15.4. This DPA is governed by Belgian law, and disputes go to the courts specified in the Agreement, without prejudice to mandatory rights under Applicable Data Protection Law or the SCCs.

16. Contact

Privacy and data-protection enquiries, including Data Subject requests: privacy@ingram.tech

Contractual notices under this DPA: legal@ingram.tech

Data Incident and vulnerability reports: security@ingram.tech