Data Collection Purpose and Justification Records

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document records the specific purposes for which personal information is collected via DCKAP Integrator and the rationale justifying such collection as necessary to fulfil the platform’s integration service objectives and legal obligations.

2. Categories of Personal Data Collected and Purpose

Data CategorySpecific ElementsPurposeLegal Basis
Customer Contact DataName, business email, phoneAccount management, support, billing notificationsContract performance
End-User Order DataConsumer name, shipping address, emailOrder fulfilment sync (eComm → ERP)Legitimate interest / DPA instruction
Portal User DataName, work email, login activityPortal access, audit trail, security monitoringContract performance
Integration MetadataAPI endpoint names, field mapping labelsConfigure and operate integration flowsContract performance
Error / Log DataTruncated field values (PII masked), error codesDebugging, support, quality improvementLegitimate interest
Usage AnalyticsFeature usage patterns, sync volumes (anonymised)Product improvement, capacity planningLegitimate interest

3. Justification for Each Collection Purpose

3.1  Order and Shipment Sync

Justification: Customer organisations contract DCKAP Integrator specifically to transfer order, customer, and shipment data between their eCommerce and ERP systems. Without collecting this data (even transiently), the contracted service cannot be delivered. The Data Controller (customer) has obtained the appropriate consent or established the lawful basis with end consumers.

3.2  Portal User Identity

Justification: User identity (email, name, role) is required to provide authenticated access to the DCKAP portal, to enforce role-based access controls, and to maintain an audit trail of configuration changes as required by SOC 2. This is directly necessary for secure service delivery.

3.3  Operational Logs

Justification: Operational and error logs are required to diagnose integration failures, meet SLA commitments, and respond to customer support requests. PII is masked before log storage. Retention is limited to 30-90 days, the minimum needed for operational support.

3.4  Usage Analytics

Justification: Anonymised usage data (not linked to individuals) is collected to understand platform usage patterns and improve product quality. No personal information is used for analytics — data is aggregated and anonymised before analysis.

4. Data Not Collected

  • DCKAP Integrator does NOT collect: payment card numbers, bank account details, government-issued ID numbers, health information, or biometric data.
  • DCKAP does NOT use personal data transiting through the platform for its own marketing, profiling, or advertising purposes.
  • DCKAP does NOT sell personal data to any third party.

5. Placement in Product

Product LocationScreen / PageAudience
Privacy Policydckap.com/privacy → Data We Collect and WhyAll Data Subjects
Trust CenterLegal → Privacy & Data UseEnterprise DPOs, Auditors
DPASchedule 1 — Processing Activities and PurposesCustomer Legal Teams
Compliance FolderSOC 2 Evidence → Privacy ControlsExternal Auditors