Labelixa Data Processing Addendum
Effective Date: August 7, 2026
Last updated: August 7, 2026
This Data Processing Addendum ("DPA") supplements the agreement between Newempo LLC ("Newempo") and the business customer ("Customer") under which Newempo provides the Labelixa service (the "Service"). It applies where Newempo processes personal data contained in content the Customer submits to the Service, on the Customer's behalf.
Newempo LLC legal notice and mailing address:
Newempo LLC 30 N Gould St #40045 Sheridan, WY 82801, USA
Contact email: [email protected]
The address above is provided solely as Newempo LLC's legal notice and mailing address.
1. Purpose and Scope
1.1 This DPA sets out the terms on which Newempo processes Customer Personal Data as a processor on the Customer's behalf. It forms part of the agreement between the parties for the Service (the "Agreement") and applies only to the extent that Data Protection Law requires processor terms for the relevant processing.
1.2 It applies where the Customer submits personal data contained in ZPL, barcode, label, shipping, recipient, order, product, or similar content, and Newempo processes that data on the Customer's documented instructions.
1.3 This DPA is a self-service general DPA. Additional or different terms for larger deployments may be agreed in a signed Enterprise agreement or privacy schedule (Section 16).
2. Definitions
2.1 Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.
2.2 "Data Protection Law" means the data-protection and privacy laws that apply to a party's processing under this DPA, which may include, where applicable, the EU General Data Protection Regulation ("EU GDPR"), the UK GDPR, and national laws implementing or supplementing them. Applicability depends on each law's own scope and thresholds; this DPA does not assert that any particular law applies.
2.3 "Customer Personal Data" means personal data contained in content the Customer submits to the Service and that Newempo processes on the Customer's documented instructions.
2.4 "Subprocessor" means a third party engaged by Newempo to process Customer Personal Data in connection with providing the Service.
2.5 "Controller," "Processor," "processing," "personal data," "data subject," and "Personal Data Breach" have the meanings given in applicable Data Protection Law.
3. Roles
3.1 For the processing described in Section 1, the Customer acts as Controller and Newempo acts as Processor. The actual role depends on the processing context; Newempo does not represent that it is always a processor.
3.2 Processing that is necessary to perform and secure the Customer's instructed rendering and generation of label and barcode output is processor activity under this DPA.
3.3 Platform-wide account security, fraud prevention, quota enforcement, legal compliance, and the establishment, exercise, or defense of legal claims are controller-side activities that Newempo carries out for its own purposes. They are outside this DPA and are described in the Privacy Policy.
4. Processing on Documented Instructions
4.1 Newempo will process Customer Personal Data only on the Customer's documented instructions, including as necessary to receive submitted content, transiently process it, render or generate the requested output, transmit that output, secure and troubleshoot the relevant Service, and comply with applicable law.
4.2 The Customer's use of the Service, its API requests, its configuration, and its written instructions constitute documented instructions. Additional instructions must be agreed in writing and may be subject to reasonable fees where they require work beyond the standard operation of the Service.
4.3 Newempo will not process Customer Personal Data for advertising, data brokerage, unrelated analytics, resale, training machine-learning or AI models, unrelated product development, or independent profiling.
4.4 Newempo will inform the Customer where, in its reasonable opinion, an instruction appears to infringe applicable Data Protection Law, unless prohibited by law from doing so.
4.5 Newempo may process Customer Personal Data as required by law to which it is subject; where permitted, it will inform the Customer of that requirement first.
5. Confidentiality
5.1 Newempo will ensure that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality, are granted access only where operationally necessary, and process Customer Personal Data only under authorized instructions.
6. Security
6.1 Newempo implements and maintains the technical and organizational measures set out in Annex 2, appropriate to the nature of the processing, the risks involved, and applicable law. Newempo may update its measures over time, provided the overall level of protection is not materially reduced.
6.2 No method of transmission or storage is completely secure, and Newempo does not provide an absolute guarantee of security.
7. Subprocessors
7.1 The Customer gives Newempo general written authorization to engage Subprocessors to provide the Service.
7.2 Newempo will impose on each Subprocessor, by written contract, the same data-protection obligations that apply to Newempo under this DPA, to the extent relevant to the Subprocessor's processing, and will remain responsible for the Subprocessor's performance to the extent required by applicable Data Protection Law.
7.3 Newempo will give the Customer prior notice of the addition or replacement of a Subprocessor. The Customer may object on reasonable data-protection grounds within fifteen (15) days of that notice.
7.4 If the parties cannot resolve a reasonable objection, Newempo will offer a commercially reasonable alternative where feasible or permit the Customer to terminate the affected Service in accordance with the Agreement. No refund is created by this Section beyond mandatory law and the applicable billing policy.
8. Subprocessor List
8.1 Newempo maintains a current, named list of Subprocessors used to process Customer Personal Data, available to Customers at:
8.2 Individual Subprocessor names, roles, and locations are set out in that list and are not reproduced in this DPA.
9. Data-Subject Requests
9.1 Where Newempo receives a request from a data subject relating to Customer Personal Data that Newempo processes as Processor, Newempo will, unless prohibited by law, direct the requester to the Customer and will not respond directly except on the Customer's instruction or as required by law.
9.2 Taking into account the nature of the processing, Newempo will provide the Customer with reasonable assistance to help the Customer respond to data-subject requests. The Customer remains responsible for responding as Controller. Assistance requiring disproportionate custom work may be subject to reasonable fees where legally permitted and agreed in advance.
10. Personal Data Breach
10.1 Newempo will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed under this DPA.
10.2 The notice will include the information then available that is reasonably necessary for the Customer to meet its legal obligations, such as the nature of the incident, the categories of affected data and data subjects where known, the likely consequences where known, the measures taken or proposed, and a contact channel for follow-up. Information may be provided in phases as it becomes available.
10.3 A notification under this Section is not by itself an admission of fault or liability.
11. DPIAs and Prior Consultation
11.1 Taking into account the nature of the processing and the information available to it, Newempo will provide the Customer with reasonable information and assistance where the Customer is required to carry out a data-protection impact assessment or to engage in prior consultation with a supervisory authority, in each case in relation to the processing Newempo performs under this DPA. Newempo does not provide legal advice or undertake to complete the Customer's assessment.
12. Deletion or Return
12.1 At the Customer's choice, Newempo will delete or return Customer Personal Data that it processes as Processor after the relevant processing ends, and will delete existing copies unless applicable law requires retention.
12.2 Because Customer Personal Data is generally processed transiently for rendering and is not maintained as a persistent content store, return may not be technically applicable to data that was only processed transiently.
12.3 Residual copies may remain in rolling provider-controlled backups until those backups expire. Newempo does not promise immediate deletion from backups. Account data and other controller-side records are handled under the Privacy Policy and the Terms.
13. Audit and Information Rights
13.1 Newempo will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, to the extent required by applicable Data Protection Law.
13.2 Ordinarily, Newempo will first provide available written information and current independent reports (for example, responses to a reasonable data-protection questionnaire).
13.3 Where that information is insufficient, Newempo will permit a proportionate remote or on-site audit, on reasonable advance notice and with confidentiality and security protected, following a Personal Data Breach, a regulator's request, or reasonable evidence of material non-compliance.
13.4 Ordinary audits may be limited to once in any 12-month period, subject to the exceptions in Section 13.3. Third-party facilities are subject to their own security and access restrictions.
14. International Transfers
14.1 Newempo LLC is established in the United States, and Customer Personal Data may be processed in the United States and other countries where Newempo or its Subprocessors operate.
14.2 Where applicable Data Protection Law requires a safeguard for an international transfer, the parties will put the applicable transfer mechanism in place before the regulated transfer is carried out. Newempo does not represent that any transfer mechanism is already in place.
14.3 No transfer mechanism is currently in place. Newempo has not executed Standard Contractual Clauses, a UK International Data Transfer Addendum, or any other transfer safeguard, and does not currently offer processing that relies on one. A Customer that requires a safeguard for a regulated transfer must contact [email protected] before submitting Customer Personal Data subject to that requirement, so that the applicable terms can be agreed and executed first. This Section states the present position and will be updated when that changes.
15. Liability
15.1 Each party's liability arising out of or related to this DPA is subject to, and counts toward, the limitations and exclusions of liability in the Terms or in an applicable signed Enterprise agreement. This DPA does not create a separate liability cap or an unlimited liability regime.
15.2 Nothing in this DPA limits or excludes any liability that cannot lawfully be limited or excluded, and the allocation of statutory liability remains governed by applicable Data Protection Law.
16. Enterprise Agreements
16.1 Additional or different audit, security, service-level, transfer, or liability terms may be agreed in a signed Enterprise agreement or privacy schedule. Those detailed terms are not part of this general DPA, and where a signed Enterprise agreement expressly overrides this DPA, it prevails (Section 18).
17. Term and Termination
17.1 This DPA takes effect on acceptance (Section 19) and remains in force for as long as Newempo processes Customer Personal Data as Processor under the Agreement. Provisions that by their nature should survive — including confidentiality, deletion or return, and liability — survive to the extent necessary.
18. Governing Law and Order of Precedence
18.1 This DPA is governed by the law that governs the Agreement, except where mandatory Data Protection Law requires otherwise; mandatory Data Protection Law prevails where it cannot be contractually limited.
18.2 In the event of a conflict, the following order of precedence applies (highest first): (1) a signed Enterprise agreement or MSA, where it expressly overrides this DPA; (2) this DPA, for data-processing obligations; (3) the Terms of Service, for general commercial terms; (4) the Privacy Policy, as a transparency notice.
18.3 The Privacy Policy is not a substitute for this DPA, and this DPA does not convert Privacy Policy statements into contractual warranties.
19. Electronic Acceptance
19.1 This DPA becomes effective only when it is accepted by an authorized representative of the Customer, by signature, order form, or supported electronic acceptance.
19.2 An electronic acceptance record must capture the Customer's legal entity name, the authorized representative, the account identifier, the DPA version, the effective date, and the acceptance timestamp.
20. Notices
20.1 Notices to Newempo under this DPA may be sent to [email protected] or to the legal notice and mailing address stated above. Notices to the Customer may be sent to the contact associated with the Customer's account. Each party is responsible for keeping its contact details current.
Annex 1 — Processing Details
Subject matter. Processing of personal data contained in label, barcode, ZPL, shipping, recipient, order, product, or similar content submitted by the Customer to the Service.
Duration. For the duration of the relevant processing and the Service relationship, subject to transient application-level rendering, implemented retention, deletion requests, legal obligations, provider-controlled rolling backups, and any applicable signed agreement. Customer Personal Data is not maintained as a persistent content store.
Nature and purpose. Receiving submitted content; transient processing; rendering and barcode generation; returning or transmitting output; securing and troubleshooting the Service; and supporting Customer requests.
Categories of data subjects (as determined by the Customer's content; not all always apply). May include the Customer's employees and users, the Customer's customers, recipients, purchasers, suppliers, business contacts, and other individuals whose personal data the Customer includes in a label.
Types of personal data (as determined by the Customer; not all always apply). May include names, postal or shipping addresses, order and product identifiers, recipient and contact information, barcode values, and other identifiers the Customer deliberately includes.
Sensitive data restriction. The Customer must not submit special-category data, criminal-conviction data, national-identification numbers, full payment-card data, authentication secrets, health data, or biometric data, unless expressly agreed in writing with appropriate safeguards.
Annex 2 — Technical and Organizational Measures
Newempo implements and maintains the following measures, appropriate to the risk:
- access controls and least-privilege access to Customer Personal Data;
- authentication controls for the Service;
- secure network transport;
- data minimization in what is collected and retained;
- logging minimization, including reduction of sensitive values in request logs;
- confidentiality controls for authorized personnel;
- deletion controls, including account-deletion functionality;
- reasonable vulnerability and dependency management; and
- incident handling, once operationally implemented.
Newempo does not represent, unless separately agreed in writing, any security certification (such as SOC 2 or ISO 27001), encryption at rest, 24/7 monitoring, a penetration-testing schedule, recovery-time or recovery-point objectives, any service level, or absolute security.
*End of Data Processing Addendum.*