Data Processing Agreement
Last updated: July 28, 2026
This page is maintained by MS Solutions ("we", "us") to describe how Easyexports processes personal data on behalf of customers ("Controllers"). It is app-owner editable content, not an independent certification.
1. Parties and role
MS Solutions, operator of the Easyexports platform, acts as a Processor of the personal data that Customers upload, generate or store while using the service. The Customer is the Controller of that data and remains responsible for the lawful basis of processing.
2. Subject-matter and duration
We process personal data solely to provide the Easyexports service (AI export tooling, document generation, buyer discovery, workflow automation) for the duration of the Customer's subscription and for a limited retention window after termination as described in our Privacy Policy.
3. Categories of data and data subjects
- Data subjects: Customer's employees, contractors, buyers, suppliers and other business contacts entered into the platform.
- Categories: contact details (name, email, phone, company), business documents (invoices, packing lists, contracts), product and shipment metadata, usage logs.
- The platform is not intended for special-category data (health, biometrics, etc.). Customers agree not to upload such data.
4. Processor obligations
- Process personal data only on documented instructions from the Controller, including as configured through the platform UI.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement the technical and organisational measures described on the Security page.
- Assist the Controller, taking into account the nature of processing, with data-subject requests and with obligations under applicable data-protection laws.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the service, subject to backup retention and legal-hold requirements.
5. Sub-processors
We use vetted sub-processors to deliver the service. The current list is published on the Security page. Customers may object to a new sub-processor by writing to us within 14 days of notice; we will work in good faith to address material objections.
6. International transfers
Where personal data is transferred outside the Controller's jurisdiction, we rely on appropriate safeguards offered by our sub-processors (for example, Standard Contractual Clauses where applicable). Customers must ensure their own onward transfers comply with the laws that apply to them.
7. Audit and information rights
On reasonable written request, we will provide the information necessary to demonstrate compliance with this DPA, such as our security overview and sub-processor list. Where a Customer requires an on-site audit, the parties will agree scope, timing and cost in advance.
8. Return and deletion
On termination, Customers may export their data through in-product tools. After the retention window described in our Privacy Policy, remaining personal data is deleted from active systems; residual copies in encrypted backups are overwritten on the standard backup rotation.
9. Contact
Data-protection requests and DPA queries: support@exporteasy.online.