Data Processing Agreement
Last updated: 5 August 2026 · Version 1.0
1. When this applies
This Data Processing Agreement ("DPA") forms part of the Terms of Service between [LEGAL ENTITY NAME] ("Processor", "we") and the customer ("Controller", "you"), and applies wherever we process personal data on your behalf under Article 28 GDPR. Accepting the Terms accepts this DPA; no separate signature is needed, though we will sign a countersigned copy on request at [PRIVACY CONTACT EMAIL].
Personal data about you - your account, your billing - is processed by us as a controller and is covered by the Privacy Policy, not this DPA. This DPA covers personal data about other people that reaches the Service because of how you use it.
2. Subject matter and details of processing
| Subject matter | Providing the Omnidara cross-listing service to you. |
|---|---|
| Duration | For as long as your account exists, plus the deletion window in clause 9. |
| Nature and purpose | Storing, transmitting, and displaying listing and order data; publishing listings to marketplaces you connect; detecting sales and removing listings elsewhere; producing your analytics. |
| Types of personal data | Identifiers and content that appear in marketplace order and listing data - typically buyer usernames, order identifiers, order values and timestamps, and any personal data you choose to put into listing titles, descriptions or photographs. |
| Categories of data subject | Your buyers, and anyone whose personal data you include in listing content. |
| Special categories | None are required by the Service. Do not enter special-category data (Art. 9) into listing content. |
3. Our obligations as processor
- We process personal data only on your documented instructions. Your use of the Service - which listings to publish, to which marketplaces - is your instruction. We will tell you if an instruction appears to breach data protection law.
- We do not process it for our own purposes, do not sell it, and do not use it to train machine-learning models.
- Everyone we authorise to access it is bound by confidentiality.
- We implement the technical and organisational measures in clause 6.
- We assist you, taking into account the nature of the processing, with data subject requests, with Art. 32-36 obligations (security, breach notification, impact assessments and prior consultation), and with supervisory-authority enquiries.
4. Your obligations as controller
- You have a lawful basis for the personal data you put into the Service and for our processing it.
- You give the privacy information your data subjects are entitled to.
- Your instructions to us comply with data protection law.
5. Sub-processors
You give general authorisation for us to use sub-processors, on condition that we impose data protection obligations on them no less protective than these, and remain fully liable to you for their performance. Our current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| [HOSTING PROVIDER] | Application and database hosting | [REGION] |
| [OBJECT STORAGE PROVIDER] | Listing photograph storage | [REGION] |
| [EMAIL PROVIDER] | Transactional and notification email | [REGION] |
| Stripe | Payments and subscription billing | [REGION] |
Marketplaces you connect (eBay and others) are not our sub-processors. They are independent controllers, and you instruct us to send them your listing content. What they do with it is governed by their own terms.
We will give at least 30 days' notice at [SUBPROCESSOR NOTICE URL/EMAIL] before adding or replacing a sub-processor. You may object on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected part of the Service with a pro-rata refund.
6. Security measures
- Encryption in transit (HTTPS) and encryption at rest for stored marketplace credentials.
- Passwords stored as bcrypt hashes.
- Strict tenant scoping: every query for listings, placements, sales and jobs is scoped by account, and background jobs re-check ownership before acting.
- CSRF protection on every form; a content security policy that permits no third-party scripts.
- Least-privilege access to production data, with access reviewed [FREQUENCY].
- Backups with [BACKUP RETENTION PERIOD] retention and restore testing [FREQUENCY].
- An auditable activity log of actions taken in each account.
We may update these measures provided the level of protection is not reduced.
7. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data we process for you, with the information you need to meet your own Art. 33 obligations, and updates as the investigation progresses.
8. Data subject requests
If a data subject contacts us directly about data we process for you, we will not respond substantively; we will refer them to you and tell you promptly. The export and deletion tools in the Service let you satisfy most requests yourself without contacting us.
9. Deletion and return
On termination you may export your data using the in-product export at any time before the account is deleted. When you delete your account, the data is erased immediately. If you close your account without deleting it, we erase it [N] days after termination, except where storage is required by law (for example billing records).
10. Audits
We will make available the information needed to demonstrate compliance with Art. 28 and allow for audits, including inspections, conducted by you or an auditor you mandate. Audits are at most once every 12 months (unless a breach or an authority requires otherwise), on 30 days' notice, during business hours, subject to confidentiality, and must not disrupt the Service or compromise other customers' data. Where available, current third-party certifications or reports may be provided instead.
11. International transfers
Personal data is processed in [PRIMARY REGION]. Where a sub-processor processes data outside the EEA, transfers rely on an adequacy decision or on the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference, together with any supplementary measures a transfer impact assessment identifies.
12. Liability and precedence
Liability under this DPA is subject to the limits in the Terms of Service. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, those clauses prevail.