Data Collection Purpose and Justification Records
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II |
1. Purpose
This document records the specific purposes for which personal information is collected via DCKAP Integrator and the rationale justifying such collection as necessary to fulfil the platform’s integration service objectives and legal obligations.
2. Categories of Personal Data Collected and Purpose
| Data Category | Specific Elements | Purpose | Legal Basis |
|---|---|---|---|
| Customer Contact Data | Name, business email, phone | Account management, support, billing notifications | Contract performance |
| End-User Order Data | Consumer name, shipping address, email | Order fulfilment sync (eComm → ERP) | Legitimate interest / DPA instruction |
| Portal User Data | Name, work email, login activity | Portal access, audit trail, security monitoring | Contract performance |
| Integration Metadata | API endpoint names, field mapping labels | Configure and operate integration flows | Contract performance |
| Error / Log Data | Truncated field values (PII masked), error codes | Debugging, support, quality improvement | Legitimate interest |
| Usage Analytics | Feature usage patterns, sync volumes (anonymised) | Product improvement, capacity planning | Legitimate interest |
3. Justification for Each Collection Purpose
3.1 Order and Shipment Sync
Justification: Customer organisations contract DCKAP Integrator specifically to transfer order, customer, and shipment data between their eCommerce and ERP systems. Without collecting this data (even transiently), the contracted service cannot be delivered. The Data Controller (customer) has obtained the appropriate consent or established the lawful basis with end consumers.
3.2 Portal User Identity
Justification: User identity (email, name, role) is required to provide authenticated access to the DCKAP portal, to enforce role-based access controls, and to maintain an audit trail of configuration changes as required by SOC 2. This is directly necessary for secure service delivery.
3.3 Operational Logs
Justification: Operational and error logs are required to diagnose integration failures, meet SLA commitments, and respond to customer support requests. PII is masked before log storage. Retention is limited to 30-90 days, the minimum needed for operational support.
3.4 Usage Analytics
Justification: Anonymised usage data (not linked to individuals) is collected to understand platform usage patterns and improve product quality. No personal information is used for analytics — data is aggregated and anonymised before analysis.
4. Data Not Collected
- DCKAP Integrator does NOT collect: payment card numbers, bank account details, government-issued ID numbers, health information, or biometric data.
- DCKAP does NOT use personal data transiting through the platform for its own marketing, profiling, or advertising purposes.
- DCKAP does NOT sell personal data to any third party.
5. Placement in Product
| Product Location | Screen / Page | Audience |
|---|---|---|
| Privacy Policy | dckap.com/privacy → Data We Collect and Why | All Data Subjects |
| Trust Center | Legal → Privacy & Data Use | Enterprise DPOs, Auditors |
| DPA | Schedule 1 — Processing Activities and Purposes | Customer Legal Teams |
| Compliance Folder | SOC 2 Evidence → Privacy Controls | External Auditors |