MHR.lt Data Processing Agreement (DPA)
Version: 2026-09-17 | Applies upon acceptance
1. Parties, roles and application
Processor: MB “MHR Solutions”, company code 307156791, Draugystės g. 8A, LT-68261 Marijampolė, Lithuania, info@mhr.lt (“MHR” or “Processor”).
The Controller is the Customer ordering the MHR.lt Service for its organisation (“Customer” or “Controller”). This DPA takes effect when the Customer accepts it as part of the MHR.lt agreement and continues for as long as MHR processes personal data on the Customer's behalf.
GDPR-defined terms have the meaning given in Regulation (EU) 2016/679 (“GDPR”).
2. Subject matter, nature, purposes and duration
MHR processes personal data only as necessary to provide the MHR.lt WMS Service under documented Customer instructions. Processing may include collection, recording, structuring, storage, consultation, retrieval, use, import, export, disclosure to Customer-authorised recipients, backup, restoration, correction, restriction and deletion.
Purposes include accounts and access, warehouse, product, inventory, inbound, outbound, transfer, stock-count, order, invoice and other selected WMS functions, Customer-initiated integrations, support, security, backups and business continuity.
Processing continues during the agreement and afterwards only as necessary for lawful return, export, deletion, backup overwrite or legal obligations.
3. Data subjects and categories of personal data
Depending on the modules used, data subjects may include Customer employees and users, warehouse personnel, employees or representatives of Customer customers and suppliers, recipients, senders, contacts and other individuals whose data the Customer lawfully submits.
Data may include name, email, phone, position, role, company information, user identifiers, login and audit information, IP address, warehouse-operation information, customer and supplier contacts, order, inbound, outbound and invoice information, personal data in Customer-uploaded files, and other data lawfully submitted by the Customer.
The Service is not specifically designed for systematic processing of GDPR Article 9 special-category data or Article 10 criminal-offence data. The Customer should not submit such data unless it has a lawful basis and any necessary additional safeguards have been agreed with MHR.
4. Documented Controller instructions
MHR processes personal data only on documented Customer instructions, including transfers to a third country or international organisation, unless Union or Member State law applicable to MHR requires processing. Where legally permitted, MHR informs the Customer of that legal requirement before processing.
This DPA, the Terms, Customer configuration and use of functions, lawful administrator actions and documented support requests constitute documented instructions.
If MHR considers an instruction to infringe GDPR or other applicable Union or Member State data-protection law, MHR will immediately inform the Customer and may suspend the instruction until it can be lawfully resolved.
5. Confidentiality and access limitation
MHR ensures that employees, contractors and other persons authorised to process personal data are committed to confidentiality or are under an appropriate statutory confidentiality obligation. Access is limited to what is necessary for assigned functions, support, Service security or lawful Customer instructions.
6. Technical and organisational security measures
Taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing and risks to individuals, MHR applies measures appropriate to risk in accordance with GDPR Article 32.
- HTTPS/TLS protection for data in transit;
- user authentication and cryptographic password hashing rather than plaintext password storage;
- role-, company-, warehouse- and permission-based access controls and logical customer-data segregation;
- CSRF and other web-application controls appropriate to the Service;
- system logging and operational/security monitoring according to Service functions;
- regular backups, backup encryption and recovery procedures;
- restricted administrative access on a need-to-access basis;
- security updates, system maintenance and incident management appropriate to risk.
MHR may change specific measures provided the overall level of protection is not materially reduced. No information system can guarantee absolute security, which does not reduce MHR's obligation to apply appropriate safeguards.
7. Personal data breaches
After becoming aware of a personal data breach affecting personal data processed for the Customer, MHR notifies the Customer without undue delay.
To the extent known, MHR provides the nature of the breach, affected data and data-subject categories and approximate scale, likely consequences, measures taken or proposed and a contact for cooperation. Information may be provided in phases without undue further delay where it cannot be provided at once.
MHR reasonably assists the Customer with GDPR Articles 33 and 34 obligations, taking into account the nature of processing and information available to MHR.
8. Data subject rights
Taking into account the nature of processing, MHR assists the Customer through appropriate technical and organisational measures with requests for access, rectification, erasure, restriction, portability, objection and other applicable GDPR rights.
If MHR receives a request directly concerning Customer-controlled data, MHR forwards it to the Customer without undue delay and does not independently respond on the Customer's behalf unless instructed by the Customer or required by law.
9. Assistance under GDPR Articles 32–36
Taking into account the nature of processing and information available, MHR reasonably assists the Customer with obligations concerning security, breaches, data protection impact assessments and, where required, prior consultation with a supervisory authority.
10. Subprocessors
The Customer grants MHR general written authorisation to engage subprocessors necessary to provide the Service. MHR imposes substantially equivalent applicable data-protection obligations on subprocessors and remains responsible to the Customer for subprocessor performance to the extent required by GDPR.
MHR gives advance notice of a new subprocessor or material replacement, normally at least 30 days in advance, by email, in-Service notice or another documented method. The Customer may make a reasoned objection based on a genuine personal-data protection risk. The parties will seek a reasonable alternative in good faith; if none is feasible, only the affected Service component may be terminated.
| Provider | Purpose | Primary location |
|---|---|---|
| UAB “Esnet” (VPSnet) | Server, infrastructure and hosting services | Vilnius, Lithuania / EEA |
| Hetzner Online GmbH | Encrypted remote backup infrastructure | Helsinki, Finland / EEA |
| Zoho Corporation B.V. and subprocessors applicable to the Zoho service | Email infrastructure and Service-message delivery | Zoho EU region; safeguarded access or subprocessors may apply under Zoho's DPA |
| Microsoft Ireland Operations Limited / Microsoft Azure | Azure AI Document Intelligence document analysis and OCR when the Customer uses the applicable inbound document-recognition feature | The region configured for MHR's Azure resource; Document Intelligence temporarily processes and stores input and analysis results in that same region under Microsoft's service terms |
A third-party integration enabled by the Customer and selected by the Customer as recipient does not automatically become an MHR subprocessor; the applicable roles and third-party terms govern that transfer.
11. International transfers
MHR does not transfer Customer personal data outside the EEA without a lawful basis under GDPR Chapter V. Where a transfer or remote access outside the EEA is necessary, MHR ensures an applicable mechanism such as an adequacy decision, European Commission Standard Contractual Clauses or another GDPR-permitted mechanism and supplementary safeguards where required.
12. Government requests
MHR discloses Customer personal data to public authorities only to the extent lawfully required. Where legally permitted, MHR informs the Customer of a compulsory request and seeks to limit disclosure to the legally necessary scope.
13. Audits and compliance information
MHR makes available information reasonably necessary to demonstrate compliance with this DPA and GDPR Article 28 and allows for and contributes to reasonable audits, including inspections, conducted by the Customer or its mandated auditor.
Under normal circumstances an audit is no more frequent than once in 12 months, is notified at least 30 days in advance, occurs during business hours and does not unreasonably disrupt the Service or compromise other customers' confidentiality or security. These restrictions do not apply where an additional audit is reasonably required following a material incident, supervisory-authority requirement or reasonable suspicion of a material DPA breach.
MHR may provide documentary or independent assurance evidence instead of direct access where sufficient for the audit purpose. MHR is not required to disclose other customers' data, security secrets or information whose disclosure would itself create an unreasonable security risk.
14. Return and deletion
At the end of processing services, at the Customer's choice, MHR returns and/or deletes personal data processed on the Customer's behalf unless Union or Member State law requires retention. The Data Act switching and retrieval process in the Terms also applies to service exit and export.
After the applicable retrieval period, MHR deletes or irreversibly anonymises remaining Customer personal data in active systems that need not be retained. Deleted data may remain for a limited period in protected backups until overwritten; it is not used for ordinary operations and is restored only for lawful disaster recovery, security or legal obligations.
15. Controller obligations
The Customer is responsible for lawful collection and processing, an appropriate legal basis, transparency to data subjects, legality of its instructions, administration of user access and ensuring data submitted to the Service is appropriate for the Customer's purposes.
16. Liability and mandatory rights
Contractual liability is governed by the lawful liability provisions of the Terms, but nothing in this DPA limits rights of data subjects or supervisory authorities that cannot be limited under GDPR or other mandatory law.
17. Priority and duration
If this DPA conflicts with the Terms on personal-data processing, this DPA prevails. The Terms apply to other matters.
This DPA remains effective for as long as MHR processes personal data for the Customer. Provisions that by their nature must survive, including confidentiality, return and deletion, continue after termination.
18. Governing law and contact
This DPA is governed by Lithuanian law, GDPR and directly applicable European Union law. Data-protection questions may be sent to info@mhr.lt.