This Data Processing Agreement (“DPA”) forms part of the Reseller Terms between HIGHLIVING LTD, trading as Dropora (“Dropora”, “we”, the “Processor”), and the business that has accepted the Reseller Terms (“you”, the “Controller”). It applies whenever you give us personal data about your own customers so that we can fulfil and deliver orders on your behalf. By registering as a reseller, or by continuing to use the service, you accept this DPA. Version 1.0, effective 8 October 2026.
- Company
- HIGHLIVING LTD
- Company number
- 16758087
- Registered office
- 20 Wenlock Rd
London
England
N1 7GU
1. Definitions
- Data Protection Law: the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and any other data protection law that applies to the processing.
- Customer Data: personal data about your customers (and anyone else named as a delivery recipient) that you give us, or that we collect from a store you have connected, to fulfil an order.
- Controller, Processor, processing, personal data, data subject and personal data breach have the meanings given in Data Protection Law.
- Sub-processor: a third party we engage to process Customer Data on your behalf, for example a courier or our hosting provider.
- Services: the wholesale dropshipping services described in the Reseller Terms, including order fulfilment, delivery, returns handling and the store integrations, feeds, API and webhooks offered through your dashboard.
2. Roles and scope
You are the Controller of Customer Data: you decide why and how your customers’ details are used, and you have the direct relationship with them. We are your Processor: we use Customer Data only to perform the Services for you. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
We are a separate Controller of the personal data we hold about you and your staff as our customer (your account, wallet and order history). That processing is covered by our Privacy Policy, not by this DPA.
3. Our obligations as Processor
- Instructions. We process Customer Data only on your documented instructions, which are: to fulfil, pack and deliver the orders you place, to handle delivery problems and returns for those orders, and to pass tracking information back to you or your connected store. Placing an order, uploading a bulk file, importing an order from a connected store or creating an order through the API is an instruction. We will tell you if we believe an instruction breaches Data Protection Law, and if a law requires us to process Customer Data differently we will tell you first unless the law prevents it.
- Confidentiality. Everyone we authorise to handle Customer Data is bound by a duty of confidentiality and has access only to what their role requires.
- Security. We implement the technical and organisational measures in Annex 2 and keep them under review so that security remains appropriate to the risk.
- Sub-processors. You give us general authorisation to use the Sub-processors listed in Annex 3, each of which is bound by written terms that protect Customer Data to a standard at least as high as this DPA. Section 5 explains how changes are notified.
- Data subject rights. If one of your customers contacts us directly about their personal data we will refer them to you, and we will help you respond to requests to access, correct, delete or restrict Customer Data within the time Data Protection Law allows.
- Assistance. Taking into account the nature of the processing and the information available to us, we will help you meet your own obligations on security, breach notification, data protection impact assessments and consultation with the Information Commissioner’s Office.
- Deletion and return. When the Services end, or earlier at your written request, we delete Customer Data or return it to you in a common machine-readable format, except where UK tax, accounting or other law requires us to keep order records (see section 8).
- Information and audits. We will give you the information reasonably needed to show that we meet this DPA, and allow audits or inspections by you or an independent auditor you appoint, on reasonable written notice (at least 30 days unless a supervisory authority requires otherwise), no more than once a year unless a personal data breach has occurred, during business hours and in a way that does not disrupt the Services or expose other resellers’ data.
4. Your obligations as Controller
- You are responsible for the lawfulness of the Customer Data you give us: you have a lawful basis to collect it and to pass it to us for delivery, and your own privacy notice tells your customers that their details are shared with a fulfilment partner.
- You give us only the Customer Data needed to deliver the order: name, delivery address and, where helpful for the courier, a phone number and email address. Do not send us special category data or payment card details.
- Your instructions must comply with Data Protection Law. You are responsible for the accuracy of the delivery details you enter or that we import from your store on your instruction.
- If you connect a store or marketplace, you authorise us to read orders that contain Dropora products from it and to write tracking and fulfilment status back to it. That platform is your own provider, not our Sub-processor.
- You will keep accurate records of your processing and respond to your customers’ requests about their personal data.
5. Sub-processors
Our current Sub-processors are listed in Annex 3 and the list on this page is kept up to date. Before a new Sub-processor starts to process Customer Data we will update this page and email the registered address of every active reseller account at least 14 days in advance. If you have a reasonable, data-protection-related objection and we cannot resolve it, you may close your account without penalty before the change takes effect; otherwise the change is deemed accepted. We remain responsible to you for everything our Sub-processors do with Customer Data.
6. International transfers
Customer Data is stored and processed in the United Kingdom, or in a country covered by UK adequacy regulations, unless Annex 3 says otherwise. Where a Sub-processor processes Customer Data outside those countries we rely on a transfer mechanism recognised under Data Protection Law, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and on the Sub-processor’s own security commitments.
7. Personal data breaches
If we become aware of a personal data breach affecting Customer Data we will notify you without undue delay, and in any event within 48 hours of becoming aware, at the email address on your account. The notification will describe what happened, the categories and approximate number of customers and records involved, the likely consequences and the measures taken or proposed, and we will update you as more information becomes available so that you can meet your own notification duties.
8. Retention, deletion and return
Customer Data forms part of the order record. Order records, including the delivery name and address, are kept for as long as your account is open and for six years after the end of the tax year in which the order was placed, as required for UK tax and accounting purposes, after which they are deleted or anonymised. Customer Data held outside the order record, such as draft orders, imported-order queues and courier manifests, is deleted when it is no longer needed to fulfil the order, and at the latest 90 days after dispatch. On written request we will return a copy of the Customer Data held for your account in CSV format.
9. General
- Term. This DPA applies for as long as we hold any Customer Data for you.
- Liability. Each party’s liability under this DPA is subject to the limits and exclusions in the Reseller Terms, except that nothing limits a party’s liability for a breach of Data Protection Law that cannot lawfully be limited.
- Changes. We may update this DPA to reflect changes in law, in our Sub-processors or in the Services. Material changes are notified by email at least 14 days before they take effect; the current version is always available at this address.
- Precedence. If this DPA conflicts with the Reseller Terms on a data protection matter, this DPA applies.
- Law. This DPA is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction.
- Contact. Data protection questions and requests should be sent to the email address shown above, with “Data protection” in the subject line.
Annex 1 – Processing details
- Subject matter: fulfilment and delivery of dropship orders placed by you for your customers, and related delivery support and returns.
- Duration: for as long as you hold a reseller account and until Customer Data is deleted or returned under section 8.
- Nature of processing: receiving, storing, printing on dispatch documents, transmitting to couriers, and deleting.
- Purpose: to pick, pack and deliver the products you order to your customer; to resolve delivery problems and returns; to provide tracking information to you or your connected store.
- Data subjects: your customers and any other person named as the recipient of an order.
- Personal data: name; delivery address; phone number and email address where you provide them; the products ordered and your order reference. We do not receive your customers’ payment details.
- Special category data: none is requested or intentionally processed.
Annex 2 – Security measures
- All traffic to and from this site is encrypted (HTTPS with HSTS), including dashboard, API, feed and webhook traffic; webhook deliveries are signed so your systems can verify them.
- Credentials for connected stores are encrypted at rest with a key derived from the site’s secret keys; API keys are stored only as hashes and shown once.
- Role-based access: only administrators and named fulfilment staff can see order and delivery details; resellers see only their own orders. Login attempts are rate limited and administrative actions are logged.
- Data minimisation: we ask only for the delivery details a courier needs, and blind dispatch is available so that parcels carry no more information than necessary.
- Security headers, software updates and vulnerability fixes are applied promptly; the site runs on a managed hosting platform with physical and network security controls provided by the hosting provider.
- Staff and contractors who handle Customer Data are bound by confidentiality obligations and trained on these procedures; these measures are reviewed regularly and after any incident.
Annex 3 – Sub-processors
The list below is generated from our current configuration, so it always reflects the couriers and providers in use.
| Sub-processor | What it does with Customer Data | Location |
|---|---|---|
| Royal Mail | Parcel delivery: receives the recipient name, address and contact details printed on the label | United Kingdom |
| Evri | Parcel delivery: receives the recipient name, address and contact details printed on the label | United Kingdom |
| DPD | Parcel delivery: receives the recipient name, address and contact details printed on the label | United Kingdom |
| DHL | Parcel delivery: receives the recipient name, address and contact details printed on the label | United Kingdom |
| Yodel | Parcel delivery: receives the recipient name, address and contact details printed on the label | United Kingdom |
| Parcelforce | Parcel delivery: receives the recipient name, address and contact details printed on the label | United Kingdom |
| Namecheap, Inc. (web hosting) | Hosts this website, its database and outgoing email; stores order records including delivery details | Hosting provider data centres (United Kingdom / United States); contractual safeguards for any transfer outside the UK |
| Cloudflare, Inc. | DNS, content delivery network and security proxy in front of the website; passes traffic to and from the site | Global network; UK adequacy and standard contractual clauses |
| Revolut Ltd | Takes card payments from resellers for wallet top-ups and orders; does not receive customer delivery details | United Kingdom |
Stores and marketplaces you connect yourself (Shopify, WooCommerce, BigCommerce, eBay) are your own providers, not our sub-processors: we read orders from them and write tracking back on your instruction. Current as of 9 October 2026.












