Legal
Data Processing Agreement
The agreement under Art. 28 GDPR. During registration it is generated with your details; the version here carries the same wording with the customer not yet named.
Use of IT Systems of SELLERLOGIC GmbH by its Customers
Data Processing Agreement with the Controller according to Art. 28 GDPR
between
SELLERLOGIC GmbH
Willicher Str. 23-25
40547 Düsseldorf
Germany
Signatory: Igor Branopolski
– SELLERLOGIC –
and
[not yet provided]
[not yet provided]
[not yet provided]
[not yet provided]
Signatory: [not yet provided]
E-mail: [not yet provided]
Customer account: [not yet provided]
– Customer –
Conclusion of this agreement
This Agreement has already been pre-completed by SELLERLOGIC. The Agreement is concluded in digital form and is valid without a signature.
Please note that SELLERLOGIC will not provide any services unless a Data Processing Agreement with the controller of personal data has been concluded. The functions of SELLERLOGIC will for this reason otherwise not be available to you.
Preamble
The Customer uses the internet-based service operated by SELLERLOGIC for sales support on platforms. In this context, it is not precluded that the Customer processes personal data. Since the Customer assigns SELLERLOGIC with services that are or may be regarded as assigned data processing within the meaning of the EU General Data Protection Regulation (GDPR), the conclusion of a Data Processing Agreement with the controller of personal data is required for this purpose pursuant to Art. 28 GDPR.
A prerequisite for the admissibility of such assigned data processing within the meaning of Art. 28 GDPR is that the Customer (as the controller) assigns this task to SELLERLOGIC (as the processor). This Agreement contains this assignment of the Customer to SELLERLOGIC and regulates the rights and obligations of the parties in connection with this data processing as well as the resulting special obligations with regard to data protection and data security.
In principle, the Customer is and remains responsible for compliance with the provisions of the GDPR and other provisions on data protection and in this respect retains control over the data to be processed. SELLERLOGIC will support the Customer in this respect in an appropriate manner.
1. General
a) SELLERLOGIC processes personal data on behalf of the Customer within the meaning of Art. 4 No. 8 and Art. 28 of Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR). This Agreement regulates the rights and obligations of the parties in connection with the processing of personal data.
b) Insofar as the term "data processing" or "processing" (of data) is used in this Agreement, the definition of "processing" within the meaning of Art. 4 No. 2 GDPR shall apply.
2. Subject Matter of the Agreement
This Agreement shall apply to all activities which are related to the underlying assignment and during which employees of SELLERLOGIC or third parties contracted by SELLERLOGIC may come into contact with the personal data processed by the Customer. The Customer's assignment to SELLERLOGIC comprises the work and/or services set out in Annex 1.
The Annex also states the object of the processing, the type and purpose of the processing, the categories of personal data and the categories of data subjects.
3. Rights and Obligations of the Customer
a) The Customer is the Controller within the meaning of Art. 4 No. 7 GDPR regarding the processing of data as processed by SELLERLOGIC. Pursuant to clause 4 c) of this Agreement, SELLERLOGIC shall have the right to notify the Customer if data processing which it considers to be legally unpermitted is the subject of the assignment and/or an instruction from the Customer.
b) As the Controller, the Customer shall be responsible for safeguarding the rights of the data subject. SELLERLOGIC shall inform the Customer without delay if data subjects assert their data subject rights against SELLERLOGIC.
The Customer has the right to issue supplementary instructions to SELLERLOGIC at any time regarding the type, scope and procedure of data processing. Instructions may be given in text form (e.g. e-mail).
c) The provisions regarding any remuneration of additional expenses incurred by SELLERLOGIC as a result of supplementary instructions issued by the Customer shall remain unaffected.
d) The Customer shall inform SELLERLOGIC without delay if he discovers errors or irregularities in connection with the processing of personal data by SELLERLOGIC.
e) In the event that there is an obligation to inform third parties pursuant to Articles 33, 34 GDPR or any other statutory notification obligation applicable to the Customer, the Customer shall be responsible for compliance therewith.
4. Obligations of SELLERLOGIC
a) SELLERLOGIC processes personal data exclusively within the framework of the agreements made and/or in compliance with any supplementary instructions issued by the Customer. This does not apply to legal requirements which may oblige SELLERLOGIC to process the data in a different manner. In such a case, SELLERLOGIC shall inform the Customer of these legal requirements prior to processing, unless the relevant law prohibits such notification due to an important public interest.
The purpose, type and scope of data processing shall otherwise be governed exclusively by this Agreement and/or Customer's instructions. SELLERLOGIC is prohibited from processing data in a manner deviating from this unless the Customer has consented to this in writing.
b) SELLERLOGIC undertakes to carry out data processing on behalf only in member states of the European Union (EU) or the European Economic Area (EEA).
c) SELLERLOGIC shall inform the Customer without delay if, in its opinion, an instruction issued by the Customer violates statutory provisions. SELLERLOGIC shall be entitled to suspend the execution of the relevant instruction until it is confirmed or modified by the Customer. If SELLERLOGIC can demonstrate that processing in accordance with the Customer's instructions may lead to SELLERLOGIC's liability under Article 82 GDPR, SELLERLOGIC shall be entitled to suspend further processing in this respect until the liability between the parties has been clarified
5. Reporting Obligations of SELLERLOGIC
a) SELLERLOGIC is obliged to notify the Customer immediately of any breach of legal provisions on data protection or of the contractual agreements made and/or the instructions given by the Customer, which has occurred in the course of the processing of data by the Customer or other persons involved in the processing. The same applies to any violation of the protection of personal data that SELLERLOGIC processes on behalf of the Customer.
b) Furthermore, SELLERLOGIC shall inform the Customer without delay if a supervisory authority takes action against SELLERLOGIC pursuant to Art. 58 GDPR and this may also concern a control of the processing that SELLERLOGIC performs on behalf of the Customer.
c) SELLERLOGIC is aware that the Customer may be subject to a notification obligation pursuant to Articles 33, 34 GDPR, which provides for notification to the supervisory authority within 72 hours of becoming aware of the matter. SELLERLOGIC will support the Customer in implementing the notification obligations. In particular, SELLERLOGIC shall notify the Customer of any unauthorised access to personal data processed on behalf of the Customer without undue delay from the time it becomes aware of the access. SELLERLOGIC's notification to the Customer shall in particular include the following information: (aa) a description of the nature of the personal data breach, including, to the extent possible, the categories and approximate number of individuals affected, the categories and approximate number of personal data records affected, and the likely consequences of a data breach; (ab) a description of the measures taken or proposed by SELLERLOGIC to address the personal data breach and, where applicable, measures to mitigate its possible adverse effects.
6. Cooperation Obligations of SELLERLOGIC
a) SELLERLOGIC shall support the Customer in his duty to respond to requests for the exercise of data subject rights pursuant to Articles 12-23 GDPR.
b) SELLERLOGIC shall cooperate in the creation of inventories of processing operations by the Customer.
c) SELLERLOGIC shall support the Customer in complying with the obligations set out in Articles 32-36 GDPR, taking into account the type of processing and the information available to it.
7. Controlling Rights
a) The Customer shall have the right to control SELLERLOGIC's compliance with the statutory provisions on data protection and/or compliance with the contractual provisions made between the parties and/or compliance with the Customer's instructions to the necessary extent.
b) SELLERLOGIC shall be obliged to provide the Customer with information insofar as this is necessary to carry out the control within the meaning of paragraph a).
c) The Customer may carry out the inspection within the meaning of paragraph a) at SELLERLOGIC's premises during normal business hours after prior notification with a reasonable period of notice. In doing so, the Customer shall ensure that the inspections are only carried out to the extent necessary in order not to disproportionately disrupt SELLERLOGIC's business operations by the inspections. The parties assume that an inspection is necessary at most once a year. Further inspections shall be justified by the Customer stating the reason. In the event of on-site inspections, the Customer shall reimburse SELLERLOGIC to a reasonable extent for the expenses incurred, including the personnel costs for the supervision and accompaniment of the inspection persons on site. SELLERLOGIC shall inform the Customer of the basis of the cost calculation before the inspection is carried out.
d) At SELLERLOGIC's discretion, proof of compliance with the technical and organisational measures may also be provided instead of an on-site inspection by submitting an appropriate, current audit certificate, reports or report extracts from independent bodies (e.g. auditors, auditing, data protection officer, IT security department, data protection auditors or quality auditors) or an appropriate certification, if the audit report enables the Customer to reasonably satisfy itself of compliance with the technical and organisational measures in accordance with Annex 3 to this Agreement.
If the Customer has reasonable doubts about the appropriateness of the audit document within the meaning of sentence 1 of this paragraph, an on-site inspection may be carried out by the Customer. The Customer is aware that an on-site inspection in data centres is not possible or only possible in justified exceptional cases.
e) SELLERLOGIC is obliged to provide the Customer with the necessary information in the event of measures taken by the supervisory authority vis-à-vis the Customer within the meaning of Art. 58 GDPR, in particular with regard to information and control obligations, and to enable the respective competent supervisory authority to carry out an on-site inspection. The Customer is to be informed by SELLERLOGIC about any planned measures.
8. Subcontracting Relationships
a) SELLERLOGIC is entitled to use the subcontractors specified in Annex 2 to this Agreement for the processing of data on behalf of SELLERLOGIC. The change of subcontractors or the assignment of additional subcontractors is permissible under the conditions stated in paragraph b).
b) SELLERLOGIC shall carefully select the subcontractor and, prior to the assignment, check that the subcontractor can comply with the agreements made between the Customer and SELLERLOGIC. In particular, SELLERLOGIC shall check in advance and regularly during the term of the Agreement that the subcontractor has taken the technical and organisational measures required in accordance with Article 32 GDPR to protect personal data. In the event of a planned change of a subcontractor or in the event of the planned assignment of a new subcontractor, SELLERLOGIC shall inform the Customer in text form in good time, but no later than 4 weeks before the change or the new assignment ("Information").
The Customer has the right to object to the change or the new assignment of the subcontractor in text form within three weeks after receipt of the "Information", stating the reasons. The objection can be withdrawn by the Customer in text form at any time.
In the event of an objection, SELLERLOGIC may terminate the contractual relationship with the Customer with a notice period of at least 14 days to the end of a calendar month. SELLERLOGIC will take the interests of the Customer into account when determining the period of notice. If no objection is raised by the Customer within three weeks of receipt of the "Information", this shall be deemed to be the Customer's consent to the change or to the new assignment of the subcontractor in question. The Customer will be explicitly informed before about the meaning of his silence in the "Information".
c) SELLERLOGIC is obliged to obtain confirmation from the subcontractor that the latter has appointed a company data protection officer in accordance with Article 37 GDPR, insofar as the subcontractor is legally obliged to appoint a data protection officer.
d) SELLERLOGIC shall ensure that the provisions agreed in this Agreement and, if applicable, supplementary instructions of the Customer also apply to the subcontractor.
e) SELLERLOGIC shall conclude a Data Processing Agreement with the subcontractor which complies with the requirements of Art. 28 GDPR. In addition, SELLERLOGIC shall impose the same personal data protection obligations on the subcontractor as are laid down between the Customer and SELLERLOGIC. The Customer shall be provided with a copy of such Data Processing Agreement upon request.
f) SELLERLOGIC is in particular obliged to ensure by contractual provisions that the control powers of the Customer and of supervisory authorities also apply to the subcontractor and that corresponding control rights of the Customer and of the supervisory authorities are agreed. It must also be contractually agreed that the subcontractor must tolerate these control measures and any on-site inspections.
g) Services which SELLERLOGIC uses from third parties as a purely ancillary service in order to carry out its business activity are not to be regarded as subcontracting relationships within the meaning of paragraphs a) to f). These include, for example, cleaning services, pure telecommunication services without specific reference to services which SELLERLOGIC provides for the Customer, postal and courier services, transport services, guarding services. SELLERLOGIC is nevertheless obliged, also in the case of ancillary services provided by third parties, to ensure that appropriate precautions and technical and organisational measures have been taken to guarantee the protection of personal data.
The maintenance and servicing of IT systems or applications constitutes a subcontracting relationship requiring consent and data processing within the meaning of Art. 28 GDPR if the maintenance and testing concerns such IT systems that are also used in connection with the provision of services for the Customer and personal data processed on behalf of the Customer can be accessed during the maintenance.
9. Non-disclosure Obligation
a) When processing data for the Customer, SELLERLOGIC is obliged to observe confidentiality with regard to data which it receives or becomes aware of in connection with the assignment.
b) SELLERLOGIC has familiarised its employees with the data protection provisions applicable to them and obliged them to observe confidentiality.
c) The obligation of the employees according to paragraph b) shall be verified to the Customer upon request.
10. Safeguarding of Data Subject Rights
a) The Customer is solely responsible for safeguarding data subject rights. SELLERLOGIC is obliged to support the Customer in his duty to process requests from data subjects according to Articles 12-23 GDPR. In doing so, SELLERLOGIC shall in particular ensure that the information required in this respect is provided to the Customer without delay so that the Customer can in particular comply with his obligations under Art. 12 Para. 3 GDPR.
b) Insofar as SELLERLOGIC's cooperation is required for the safeguarding of data subjects' rights - in particular to access, rectification, suppression or erasure - by the Customer, SELLERLOGIC shall take in each case the measures required in accordance with the Customer's instructions. SELLERLOGIC will support the Customer as far as possible with appropriate technical and organisational measures in fulfilling his obligation to respond to requests for the exercise of data subject rights.
c) Provisions regarding any remuneration of additional expenses incurred by SELLERLOGIC due to cooperation services in connection with the assertion of data subject rights vis-à-vis the Customer shall remain unaffected.
11. Remuneration
SELLERLOGIC's fees shall be agreed separately.
12. Technical and Organisational Measures for Data Security
a) SELLERLOGIC undertakes towards the Customer to comply with the technical and organisational measures required to comply with the applicable data protection legislation. This includes in particular the requirements of Art. 32 GDPR.
b) The status of the technical and organisational measures existing at the time of the conclusion of this Agreement is attached as Annex 3 to this Agreement. The Parties agree that changes to the technical and organisational measures may be necessary in order to adapt to technical and legal circumstances. SELLERLOGIC shall coordinate with the Customer in advance significant changes that may affect the integrity, confidentiality, availability or robustness of the data processing systems.
Measures that involve only minor technical or organisational changes and do not negatively affect the integrity, confidentiality and availability of the personal data may be implemented by SELLERLOGIC without consultation with the Customer.
The Customer may request an up-to-date version of the technical and organisational measures taken by SELLERLOGIC once a year or on justified occasions.
13. Term of the Agreement
a) The Agreement shall be deemed to commence upon signature and shall run for the duration of the Main Agreement existing between the parties concerning the use of SELLERLOGIC's services by the Customer.
b) The Customer may terminate the Agreement at any time without notice in the event of a serious breach by SELLERLOGIC of the applicable data protection legislation or of obligations under this Agreement, if SELLERLOGIC is unable or unwilling to carry out an instruction from the Customer or if SELLERLOGIC refuses access by the Customer or the competent supervisory authority in breach of the Agreement.
14. Termination
After termination of the Agreement SELLERLOGIC shall, at the Customer's discretion, return to the Customer or delete all documents, data and processing or usage results produced in its possession which are connected with the contractual relationship. The deletion shall be documented in an appropriate manner. Any statutory retention obligations or other obligations to store the data shall remain in effect. The right of storage for the assertion, exercise or defence of legal claims shall also remain as unaffected.
15. Final Provisions
a) This Agreement is subject to German law.
b) The written form is required for supplementary agreements.
c) Should some parts of this Agreement be invalid, this shall not affect the validity of the remaining provisions of the Agreement.
Annex 1
Services provided by SELLERLOGIC: Scope, nature and purpose: Sales support on platforms. Types of Data: Any data stored by the Customer in the Service, in particular from its end customers, namely name, address, e-mail address, telephone number (if applicable) as well as details of orders placed and payments Data subjects: End customers
Annex 2
SELLERLOGIC currently uses the following subcontractors:
Web hosting of the SELLERLOGIC application:
AMAZON WEB SERVICES, INC. 410 Terry Avenue North Seattle, WA 98109-5210
Hetzner Online GmbH Industriestraße 25 91710 Gunzenhausen
OVH GmbH Oskar-Jäger-Str. 173/K6 50825 Köln
Annex 3
Technical and organisational measures of SELLERLOGIC
SELLERLOGIC takes the following technical and organisational measures for data security within the meaning of Art. 32 GDPR
1. Confidentiality
Control of Access to the Data Processing Facilities
Unauthorised persons must be denied access to data processing facilities with which personal data are processed or used.
Storage of data in a data processing centre, there:
- electronic access control system with logging - documented handing out of keys to staff - Guidelines for escorting and identifying guests in the building - 24/7 staffing of the data processing centres- Video surveillance at entrances and exits
Control of Access to the Data Processing Systems
Data processing systems must be prevented from being used by unauthorised persons.Data processing systems must be prevented from being used by unauthorised persons.
Implementation through user account control, access to EDP systems only possible with user name/password. Customers of SELLERLOGIC assign passwords themselves, which can be changed again after the first start-up and which are not known to SELLERLOGIC.
Control of Access to Data
It must be ensured that those authorised to use a data processing system can only access the data subject to their access authorisation and that personal data cannot be read, copied, changed or removed without authorisation during processing, use and after storage.
Establishment of an authorisation concept in which individual Customers of SELLERLOGIC are exclusively assigned access to their own areas and data. Recording of access in log files. The Customer is responsible for maintaining the confidentiality of access data and, if necessary, for passing it on to employees.
Separation control
It must be ensured that data collected for different purposes can be processed separately.
Customer data shall be stored physically or logically separate from other data. Data backup shall also be physically or logically separated.
2. Integrity
Input control
It must be ensured that it can be subsequently checked and determined whether and by whom personal data have been entered into data processing systems, changed or removed.
The data shall be entered and processed by the Customer himself. Access by the Customer shall be logged.
Disclosure control
It must be ensured that personal data cannot be read, copied, altered or removed without authorisation during electronic transmission or during their transport or storage on data carriers, and that it is possible to check and establish to which units personal data are to be transmitted by data transmission systems.
Pursuant to Art. 28 Para. 3 b) GDPR, employees are obliged to maintain confidentiality and have been instructed on the data protection provisions of the GDPR. Such obligation shall continue to exist even after termination of the employment relationship. The transmission of data from and to the Customer areas is only TSL-encrypted; the Customer himself is responsible for setting up transmission channels to external systems (data export).
3. Availability and Robustness
Availability control
It shall be ensured that personal data are protected against accidental destruction or loss.
- The Customer's data shall be backed up regularly - Use of redundant systems - Use of uninterruptible power supply.
4. Procedures for Regular Review, Assessment and Evaluation
We will conduct regular reviews of the aforementioned technical and organisational measures, and adapt the measures to new requirements as necessary.
Our employees receive regular training on the processing of personal data.
Any translation from German into another language is a mere courtesy of SELLERLOGIC Should any dispute arise on the interpretation of any provision of this Agreement, the German version shall prevail exclusively.
Copyright © 2026 SELLERLOGIC. All rights reserved.
Version: 2026-08-2