Skip to main content

PackNet Online Documentation

PackNet Software Platform GDPR Guidance

PackNet Software Platform GDPR Guidance

Purpose

This document details how Packsize complies with General Data Protection Regulation (GDPR) and protects customer data. This document also outlines how Packsize processes PackNet Software Platform data.

GDPR Compliance

Packsize as an organization is working to ensure that products and services meet customers' expectations for GDPR compliance. This endeavor to comply with one of the world’s strictest data privacy laws also advances Packsize's effort to comply with other applicable data privacy laws.

Packsize helps customers comply with GDPR by:

  • Continuing to build upon the security features in our products and the security posture of our enterprise and infrastructure.

  • Ensuring that the data processing agreements with our customers meet the GDPR requirements for deployment of processors.

  • Ensuring selection of sub-processors that meet our high standards regarding data privacy compliance and that have implemented robust technical and organizational measures.

  • Supporting compliance of our customer’s international data transfers by providing guidance by and close collaboration with our data privacy experts.

  • Continuously monitoring the regulatory guidance around GDPR compliance in general, and adjusting our solutions accordingly if and where necessary.

Protecting Personal Data

The PackNet Software Platform, Packsize’s cloud hosted application that supports right-sized packaging solutions, has security capabilities that are available to customers by default. Communication to the cloud hosted environment is encrypted by default. 

Data is encrypted at-rest within external cloud environments. All security-specific updates to the software are automatically applied to all PackNet tenants when the changes are incorporated into the production environment.

Packsize provides security training for all of its employees and selects its sub-processors in accordance with strict criteria that particularly take into account the requirements of information security and data privacy compliance. This ensures that only trustworthy sub-processors come into contact with customer data. At a minimum, Packsize expects cloud vendors to be certified under ISO 27001 or SOC2 security compliance standards.

Read the PackNet Software Platform Security Guide for more information around the protective measures in place within the PackNet Software Platform and an overview of the security controls posture of Packsize.

Data Subject Requests

If customers are contacted by individuals affected by their data processing with a request to exercise his or her rights under GDPR (e.g., access, erasure, restriction of processing), they should reach out to privacy@packsize.com.

In accordance with Packsize obligations under the customer's Data Processing Agreement, Packsize's appropriate teams will work with customers to ensure proper processing of the data subject request within the statutory time limits.

Packsize's GDPR Commitments

Packsize is aware of its role and obligations as a processor under the GDPR. In order to meet these obligations, Packsize offers each customer the possibility to enter into a data processing agreement that has been adapted by Packsize's team to cover provision of our solution and the contents of Art. 28 of the GDPR, while taking into account the respective current regulatory requirements in the EU/EEA.

To receive this digital data processing agreement and enter into the contracting process with Packsize, please send an email to privacy@packsize.com.

Data Processing Within the PackNet Software Platform

Methods of Collection

Data can only be inducted into the PackNet Software Platform through the predefined integration methods. See the PackNet Integration Requirements for more information around the integration into the PackNet Software Platform.

Types of Data

PackNet requires information to create a right-sized packaging solution based on customer configurations and priority settings. The data consumed can differ based on the solution but typically includes:

  • Product dimensions

  • Product quantity

  • Fulfillment tracking ID

If PackNet requires the ingestion of label data in order to print and apply a label, the following information may be collected:

  • End customer name

  • End customer address

  • Depending on the label data specified, further personal data may be processed

Location of Data

In order to provide its services, Packsize has engaged with third party cloud infrastructure providers which will allow access to personal data. These organizations are identified below with their locations and the types of services they provide to Packsize.

Vendor

Location

Description of Data-Processing Activities

Links to Compliance Information

Microsoft Azure

Azure (IoT) West 2 - Moses Lake, Washington, US

Azure East 2 Richmond, Virgina. US

Hosting of application services and managing the flow of work to an Azure IOT edge module

Microsoft Azure

MongoDB

Azure US East 2  Richmond, Virginia US

Azure US West 3El Mirage, Arizona, US

Database as a service that supports the PackNet Solution

MongoDB

CloudAMQP

The CloudAMQPAzure US West 3El Mirage, Arizona, US

Event messaging platform

CloudAMQP

Data Processing

Processing Activities:

  • Box Data: Processing box dimensions and job IDs to create and track right sized packaging solutions.

  • Label Information: Processing personal information (e.g., name, address, phone number, email) for label printing. Label data is not included in any operation logs, however, it is included in the objects. Customers are encouraged to use Secure Print to encrypt information.

  • Third-Party Sharing: Packsize does not share personal data with any third parties.

Data Retention

Job production data that is stored in a cloud environment is encrypted at rest by Packsize's cloud vendors. This data is available for 30 days in order to triage jobs that have been sent to the PackNet environment. Following this time period, the data it automatically removed through a secure deletion process. Depending on the timing of backup snapshots, the data may be retained within MongoDB backup for one year if the snapshot was taken before auto-delete. This data retention period may be shortened by adjusting the settings in Secure Print.

Packsize captures metadata around quality and efficiency to support PackNet reporting which provides metrics and dashboards for customers. This data is captured and stored in an encrypted format indefinitely.

Technical and Organizational Measures

Packsize maintains an Information Security Program that establishes robust administrative, technical, and physical safeguards to protect customer data and ensures the capability to identify, detect, respond to, and recover from security incidents effectively.

Encryption

All data transmitted between PackNet Software Platform environments and Packsize customers is protected by Transport Layer Security (TLS), which is enabled by default and cannot be disabled. Communication between the PackNet Software Platform and IoT edge device requires TLS 1.2 encryption and a minimum key length of 64 bits for the initial connection. Subsequent traffic is encrypted with a 2048 bit certificate. For integration points, PackNet Software Platform TLS 1.3 is required for encryption of data flowing into the environment.

Encryption at rest serves as a safeguard, ensuring that any stored files or data can only be accessed by an authorized process or application through decryption. Encryption for data at rest is automated using Azure's transparent disk encryption, which uses industry-standard AES-256 encryption to secure all volume (disk) data. All keys are fully managed by Azure (see Azure Transparent Encryption).

The PackNet Software Platform leverages Atlas Mongo DB for cloud data storage to support the PackNet Software Platform. Customer data is encrypted at rest by default using AES-256 to secure all volume (disk) data. The process is automated by the transparent disk encryption of the customer's selected cloud provider, and the cloud provider fully manages the encryption keys.

Penetration Testing

Regular reviews are conducted through the PackNet Software Platform by both internal and external security teams. Internally, the platform undergoes periodic risk assessments and threat modeling, which involves technical vulnerability discovery and evaluation of business risks and concerns. Third parties are engaged on at least an annual basis to conduct application penetration tests and cloud security reviews.

Code Scanning

Packsize Information Security and PackNet Product teams work proactively together on security initiatives in their Software Development Lifecycle (SDLC). Packsize has implemented tooling and practices to ensure operational security within the PackNet Software Platform. Packsize leverages third-party security tools to conduct source code scans, detecting and addressing known security vulnerabilities and preventing unsecure code from being pushed to production. Additionally, Packsize tests its code against government benchmarks, including Common Vulnerability and Exposure (CVE) and Common Weakness Enumeration (CWE).

Least Privilege Access

In general, Packsize personnel do not have access to customer production data. Only a small group of privileged users have the authority to access production infrastructure.

Packsize adheres to the principle of least privilege for these users, ensuring that access is limited to the minimum scope necessary for resolving the critical issue. The access process for privileged users requires MFA. Additionally, Packsize revokes a privileged user's access when leaving the company.

Cloud Security Posture Management

Packsize is continuously monitoring, auditing, and improving the design and operating effectiveness of all security controls. Packsize has an established process for the identification and closure of configuration issues or vulnerabilities within defined SLAs.

Multi-Zone Availability

Packsize has established multiple availability zones for redundancy of critical resources in case of outages.

Backups

Incremental backups are performed daily using an automated system and replicated to an offsite location. Backups are monitored for failure using an automated system. Details on providers and resiliency control documentation for our vendors can be found in the PackNet Cloud Security Guide [GUIDE-00006].

Incident Response

Packsize has an established incident response plan that outlines steps to notify stakeholders and customers within agreed time frames in the event of a data breach of other security incidents. The incident response plan is reviewed annually.

Compliance and Accountability

Packsize team members undergo annual training to ensure ongoing compliance with GDPR standards. Packsize has established internal policies and procedures to maintain accountability and adhere to GDPR standards.

Support for Cases of International Transfer of Personal Data

Packsize operates globally. As a result, customer personal data may be transferred to and processed in countries where Packsize or where vendors of Packsize operate.

Where a transfer of personal data takes place in absence of an adequacy decision by the relevant authorities, controllers and processors in the EEA, UK, or Switzerland are required to implement appropriate safeguards to legitimize this transfer. Depending on the applicable law, it may also be necessary to conduct a Transfer Impact Assessment (TIA) and review the technical and organizational measures applied to ensure the additional security of the transfer.

Packsize is aware of these requirements and will assist customers in meeting them. For this purpose, Packsize will, where applicable, complete the EU Standard Contractual Clauses, including any supplementary agreements required under national law and will contribute to the customer's TIA.

For this purpose, please contact the Packsize privacy team at privacy@packsize.com.

For more information about Packsize's supplementary measures, technical and organizational security measures are available upon request.