Parties#
This Data Processing Agreement (DPA) applies between the customer as controller and ProductTickler B.V., trading as Sellgrip, Meerwijkselaan 5, 6571 CM Berg en Dal, Netherlands, KvK 98314696, as processor ("we").
It forms part of the contract for the use of Sellgrip under the Terms and Conditions (Terms). It is concluded when the customer accepts it on registration. It sets out the obligations under Art. 28 GDPR.
1. Subject matter and duration#
- We process data from the customer's Kaufland seller account on behalf of the customer. This includes order, return and ticket data and, for invoices, buyers' names and addresses.
- This DPA applies for as long as the service contract is in force and thereafter until the data has been deleted in accordance with clause 9.
2. Nature and purpose of the processing#
- Purpose: the customer uses Sellgrip to handle their orders, returns, tickets and invoices and to analyse the profit, costs, payouts and performance metrics of their Kaufland business.
- Nature: retrieval via the Kaufland Seller API, storage, analysis, display, export and deletion. When a user clicks, we transmit individual transactions to Kaufland: shipment confirmation and tracking number, cancellation, refund, decision on a return, reply to or closure of a ticket, upload of an invoice, purchase of a paid shipping label through Kaufland, transmission of missing product data, and change of the price, minimum price, stock, handling time or status of an offer.
- Invoices: when the customer issues an invoice, we retrieve the buyer's billing address from Kaufland for that single order, create the invoice as a PDF, keep the PDF as the customer's copy and upload it to Kaufland.
- Tickets: we retrieve ticket messages from Kaufland to display them. We do not store their text.
3. Categories of data and data subjects#
Categories of data:
- Order data: order and order item numbers, items (title, EAN, SKU), prices, fees, VAT, status, Kaufland country, timestamps, delivery details, tracking numbers, cancellation reasons. We do not import buyers' names, addresses, email addresses or telephone numbers; an allowlist at the interface to Kaufland lets through only the fields required.
- Invoice data: name or company name and billing address (street, house number, postcode, town or city, country) of a buyer, only if the customer issues an invoice for that buyer's order, and only in the invoice PDF.
- Return data: return items, products, status, reason and timestamps.
- Ticket data: ticket number, order items concerned, status, reason, topic and the timestamps of the last message from the buyer and from the seller. The text of the messages is only displayed, not stored.
- Product, offer, transaction and payout data of the customer.
- Action log: which of the customer's users triggered which action, when, and with what result, without the text of messages.
Data subjects:
- the customer's buyers on the Kaufland marketplace
- the customer's users in Sellgrip (owner, staff, accounting)
- the customer, where the customer is a natural person
We process users' account data (name, email address, password hash) and billing data as an independent controller. This is described in the Privacy Policy.
4. Instructions#
- We process the data only on documented instructions from the customer. The instructions are set out in this DPA and in the Terms. Each action a user triggers in Sellgrip is an individual instruction.
- The customer gives any further instructions in text form to privacy@sellgrip.com.
- If we believe an instruction is unlawful, we inform the customer without undue delay. We may suspend carrying it out until the matter has been resolved.
- We do not use the data for our own purposes and do not disclose it to third parties, except in accordance with this DPA or where required by law.
- We do not analyse data across multiple customers, including in anonymised form. If this is planned in the future, it will only take place after this DPA has been amended.
5. Confidentiality#
We require all persons with access to the data to commit to confidentiality in writing, unless they are already under a statutory obligation of confidentiality. This obligation continues after their work for us ends. Access is given only to persons who need it to operate Sellgrip.
6. Security#
We implement the technical and organisational measures under Art. 32 GDPR set out in Annex 1. We update them as technology develops. A measure may be replaced by an equivalent one, provided the level of protection is not reduced.
7. Sub-processors#
- The customer authorises the sub-processors listed in Annex 2.
- If we intend to add or replace a sub-processor, we notify the customer by email at least 30 days in advance. The customer may object within 14 days for good cause relating to data protection. If we cannot reach agreement, either party may terminate the service contract with effect from the date on which the change would take effect.
- We contractually bind every sub-processor to the same data protection obligations as set out in this DPA.
- Data is transferred to a country outside the European Economic Area only if the conditions of Art. 44 to 49 GDPR are met.
8. Assistance to the customer#
- Data subject rights: we assist the customer with requests under Art. 12 to 22 GDPR. The customer can export (JSON) and delete data directly in the settings. If a data subject contacts us, we forward the request to the customer.
- Obligations under Art. 32 to 36 GDPR: we assist the customer, taking into account the nature of the processing and the information available to us, for example with a data protection impact assessment.
- Personal data breaches: we notify the customer of a personal data breach without undue delay, and no later than 48 hours after becoming aware of it, by email to the account owner. The notification contains, where known, the information referred to in Art. 33(3) GDPR; we provide any missing information as soon as it becomes available. This allows the customer to meet their own 72-hour notification deadline. We take the measures necessary to secure the data and mitigate possible adverse effects without undue delay.
9. Deletion and return#
- During the term, the customer can export their data in JSON format at any time and delete their account with all its data. Deleting the account counts as an instruction to delete all data processed on the customer's behalf. We carry this out immediately and in a single step.
- If the service contract ends in any other way, the customer can still export their data for 30 days. We then delete it, unless we are required by law to retain it.
- Backups are deleted automatically after 30 days. Separately, Cloudflare can reset the databases to any point in the last 30 days; deleted data remains there for no longer than that. If a backup is restored, we automatically repeat any deletions made since the backup was created.
- Automatic deletion of individual order data after a fixed period is not set up. The data remains stored until paragraph 1 or 2 applies. If we introduce such a period, we will inform the customer in advance.
- Invoices the customer has issued through Sellgrip are deleted together with the account. The customer downloads them beforehand to meet their own retention obligations.
10. Information and audits#
- On request, we provide the customer with the information they need to demonstrate compliance with the obligations under Art. 28 GDPR, in particular the measures in Annex 1 and the list in Annex 2.
- Once a year, with reasonable notice and during normal business hours, the customer may carry out an audit themselves or have it carried out by an auditor bound by confidentiality. We may require that documents and information are reviewed first. Where there is a specific reason, for example after a personal data breach, audits may also take place more often.
11. Liability and final provisions#
- Clause 12 of the Terms applies to liability. Art. 82 GDPR remains unaffected.
- If this DPA and the Terms conflict on matters of data protection, this DPA prevails.
- In all other respects, the Terms apply, including as to governing law and jurisdiction. The German version is binding.
Annex 1: Technical and organisational measures#
Physical access to the servers#
- Data is stored only in data centres in the European Union: Cloudflare Durable Objects, D1 and R2 with the EU as storage location. The operator (Annex 2) uses access control and is certified to ISO/IEC 27001.
- Administrative access to the Cloudflare account only for management, with two-factor authentication. Administrative functions of the application only behind Cloudflare Access and additionally with a secret key. There is no server of our own with SSH access.
Access to Sellgrip#
- Passwords of at least 12 characters, stored only as a scrypt hash with a unique salt for each user.
- Sessions via a cookie that scripts cannot read (HttpOnly, SameSite=Lax, Secure). Only a hash of the session key is stored.
- Sessions are extended by 14 days with use and end after 90 days at the latest. Logging out and changing the password end them immediately; all sessions can be ended at once.
- Password reset links are valid for one hour and can be used only once.
- Rate limiting for login, registration, password reset and invitations, per IP address and per account.
Access to data#
- Strict separation of customers: the account a request relates to is determined only by the session. Requests for another customer's data are rejected. Automated tests check this for every endpoint.
- Three roles, enforced on the server: owner (everything, including credentials, team, billing, export and deletion), staff (orders, returns, tickets, invoices, costs) and accounting (read only).
- Test and demo accounts never connect to Kaufland.
Encryption#
- Transmission only via TLS, with HSTS.
- Kaufland API keys encrypted with AES-256-GCM. The encryption key is derived from a secret held outside the database. Key rotation is supported.
- Requests to Kaufland are sent via HTTPS and signed with HMAC-SHA256.
Data minimisation#
- Allowlist at the interface to Kaufland: buyers' names, addresses, email addresses and telephone numbers are not imported from orders or tickets.
- A buyer's billing address is retrieved only when an invoice is issued and is stored only in the invoice.
- Logs contain no credentials, no session keys and no buyer data; one-time tokens are removed from logged URLs.
- The usage statistics store no IP addresses and no browser information.
Traceability#
- Action log for every action towards Kaufland (user, action, time, result) and for every change to the team (invitation, role, removal).
- Notifications from Stripe are accepted only with a valid signature.
Availability and recovery#
- Daily, consistent backup of the databases, encrypted with AES-256-GCM. The backups of the last 30 days are kept. The backups are kept at Cloudflare (Annex 2) in R2 storage with the European Union as storage location. In addition, Cloudflare can reset the databases to any point in the last 30 days.
- Documented recovery procedure. An automated test runs through it with every change, including repeating deletions.
Secure application#
- Content Security Policy with a new nonce for each request, no third-party scripts.
- Protection against embedding in other sites (X-Frame-Options DENY), nosniff, restrictive Referrer Policy and Permissions Policy.
- Automated type checks and tests with every change.
Annex 2: Sub-processors#
- Cloudflare, Inc., USA. Service: operation of the application, databases and backups (Cloudflare Workers, Durable Objects, D1 and R2), DNS and proxy. Place of storage: European Union. Cloudflare receives requests in the data centres of its global network and in doing so sees IP addresses and request data, including the content Sellgrip delivers to the browser. Cloudflare also receives emails sent to our addresses (info@, support@, privacy@sellgrip.com) and forwards them (Cloudflare Email Routing). Transfer to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR) and standard contractual clauses (Art. 46(2)(c) GDPR).
- Sendinblue SAS (Brevo), 9-17 rue Salneuve, 75017 Paris, France. Service: sending of emails to the customer and their users (recipient address, subject, text). Place of processing: European Union.
A contract under Art. 28(4) GDPR is in place with each sub-processor.
The following are not sub-processors:
- Stripe: Stripe processes the customer's payments to us and for this receives only data about the customer, no data from the Kaufland seller account and no buyer data.
- Kaufland: Kaufland is the source of the data and receives the transactions the customer triggers. The customer has their own contract with Kaufland.
- Google: Google Analytics runs only on the website; the Sellgrip application does not load it. With consent, the application reports to Google Analytics only the registration, the start of a trial and the first paid invoice. These are account and billing data that we process as an independent controller (section 3). Google receives no data processed on the customer's behalf.
Planned, not yet in use: a translation service (DeepL or Anthropic) for replies in the buyer's language. It would process ticket messages. Before it is used, we will add it to this list in accordance with clause 7.