Data Use and Purpose Documentation

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document defines the specific purposes for which personal information is collected, used, and processed by DCKAP Integrator — and establishes controls ensuring that data use is restricted to these stated purposes only.

2. Permitted Uses of Personal Data

Data ElementPermitted UseWho Uses ItRestriction
Consumer name & addressOrder sync from eCommerce to ERP for fulfilmentIntegration EngineNot used for marketing
Consumer emailOrder confirmation relay to ERPIntegration EngineNot stored beyond 24h
Portal user emailAuthentication, audit trail, notificationsDCKAP PlatformNot shared with third parties
Portal user activity logSecurity monitoring, audit complianceDCKAP Security TeamRead-only; 1 year retention
API credentials (customer)Authenticate to source/destination systemsCredential VaultEncrypted; never logged
Sync metadata (counts, timestamps)SLA monitoring, support, invoicingDCKAP OperationsAnonymised for analytics
Error logs (PII masked)Debugging, support resolutionDCKAP Support / EngineeringPII stripped before storage

3. Prohibited Uses

  • Personal data transiting through integration flows must NOT be used by DCKAP for its own marketing, advertising, profiling, or analytics purposes.
  • Consumer data (orders, addresses) must NOT be retained beyond the 24-hour processing window.
  • API credentials must NOT be used by DCKAP staff to access customer systems outside the scope of the contracted service.
  • Personal data must NOT be transferred to countries without an adequate level of data protection unless appropriate safeguards are in place (SCCs, BCRs, adequacy decision).

4. Purpose Limitation Controls

ControlDescriptionVerification
Data minimisationOnly fields required by the integration flow are extracted from sourceField mapping audit
PII masking in logsPersonal fields masked before log storage — purpose: debug, not PII storageLog content review
Short retention for transit dataConsumer data auto-purged within 24 hours of sync completionAutomated purge job
Access controlsDCKAP staff access to customer data restricted to support cases with customer consentAccess log review
Sub-processor controlsSub-processors contractually restricted to processing data only for DCKAP’s service deliverySub-processor DPAs

5. Placement in Product

Product LocationScreen / PageAudience
Privacy Policydckap.com/privacy → How We Use Your DataAll Data Subjects
DPASchedule 1 — Permitted Processing ActivitiesCustomer DPOs, Legal
Trust CenterLegal → Data Use PolicyEnterprise Customers, Auditors
Compliance FolderSOC 2 Evidence → Purpose LimitationExternal Auditors