Data Processing

Data Processing Schedule

Part 1 - Data Processing Information

Service Provider''s name: DecoPac, Inc.

Service Provider's commercial address: 3500 Thurston Avenue, Anoka, MN 55303.

Service Provider's contact person and email/ fax/ telephone number: web customer support at [email protected].

Service Agreement (title): CelebrationIQ Platform Services Agreement.

Business Purpose of processing Personal Information: As described in Service Agreement.

Duration of the processing of Personal Information: The term of the Service Agreement and any time thereafter permitted or required by law.

Categories of Personal Information to be processed:

  1. Identity Data. Name, phone number, email address, IP address.
  2. Transaction Data. Products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
  3. Device/Network Data. Information related to a user’s device, browser, or application (e.g., device identifiers, identifiers from cookies, session history and website navigation metadata, and other data generated through applications and browsers, including cookies and similar technologies).
  4. Visual Data. Photographs and cake messages submitted by data subjects.

Categories of Data Subjects whose Personal Information is to be processed: Business’s customers and Platform users.

Data sources: Business’s customers and Platform users.

Part 2 - Data Security Measures

DecoPac, Inc., together with its subsidiaries and affiliated companies (“DecoPac”) strive to deliver a consistently high level of information security to protect customer and consumer personal information. DecoPac is committed to implementing and maintaining compliance with industry standards and continuously improve its information security practices. Wedesignate adequate resources to maintain administrative, technical, and physical safeguards to protect our customer and consumer personal information. DecoPac’s approach to achieving best security practices include:

  1. Understanding the classification of information.
  2. Adhering to regulatory requirements and expectations for maintaining information security.
  3. Risk assessments including internal and external vulnerability testing and periodic audits by outside partners.
  4. Employee information security awareness and user responsibility, including two-factor authentication when appropriate.
  5. Accessing information only as needed to meet legitimate business needs.
  6. Customer and consumer opt-out options for collection or storage of personal information.
  7. Anonymizing personal information, when applicable.

By implementing controls to maintain confidentiality and integrity, and ensure availability of information is not compromised, DecoPac improves the way our business is managed and delivery of our services.