Model agreement pursuant to Art. 28 GDPR · Version 2025
Processor (Provider):
Diar Yousefi (ShopManage)
Im Bans 15, 25421 Pinneberg, Germany
Email: [email protected]
Phone: +49 155 65444829
VAT ID: DE457240251
Controller (Customer):
Name: ______________________________
Company: ______________________________
Address: ______________________________
Email: ______________________________
VAT ID: ______________________________
The parties have entered into a data processing relationship through the usage agreement for the ShopManage SaaS platform. To specify the rights and obligations arising from this in accordance with the requirements of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG), the parties conclude this agreement.
(1) This agreement applies to the processing (Art. 4(2) GDPR) of all personal data arising from the controller's use of the ShopManage SaaS platform and processed on the controller's instructions. Data of the processor's employees relating exclusively to the employment relationship are not covered.
(2) This agreement takes precedence over other agreements between the parties unless expressly agreed otherwise.
(1) Subject and duration: Data processing occurs for the duration of the usage agreement for the ShopManage SaaS platform and ends with its termination.
(2) Purpose of processing: Provision of SaaS functions (eBay synchronization, AI-supported message handling, order management, shipping label creation).
(3) Types of personal data:
(4) Categories of data subjects: End customers (buyers) of the controller who enter into business relationships with the controller via eBay.
(5) No special categories of personal data under Art. 9 GDPR are processed.
(6) The personal data have a normal protection requirement.
(1) The parties shall comply with their obligations under data protection law (especially GDPR). The controller may at any time request the release, correction, adjustment, deletion, or restriction of processing of the data.
(2) The processor shall provide appropriate technical and organizational measures to support the controller in safeguarding data subject rights.
(3) If a data subject contacts the processor directly to exercise their rights, the processor shall promptly forward the request to the controller.
(4) The processor shall process data only on the documented instructions of the controller. Initial instructions arise from the usage agreement and the SaaS platform functions. Subsequent instructions may be given in documented form by email or through the customer account.
(5) The processor shall immediately inform the controller if it believes an instruction violates data protection law. Execution may be suspended until clarification.
(6) The processor shall provide information to third parties or the data subject only with prior express written consent of the controller.
(7) No copies or duplicates of the data shall be made without the controller's knowledge.
(8) Data processing takes place exclusively within the European Union (EU) or European Economic Area (EEA). Where subprocessors based in third countries (e.g. USA) are used (see § 8), this is secured by the EU-U.S. Data Privacy Framework or standard contractual clauses.
(9) The processor maintains a record of all categories of processing activities carried out on behalf of the controller pursuant to Art. 30(2) GDPR.
(1) The processor ensures that all persons authorized to process data are contractually bound to confidentiality or subject to statutory confidentiality.
(2) The processor is not required to appoint a data protection officer (threshold under § 38 BDSG not reached). Contact for data protection inquiries: Diar Yousefi, [email protected].
(3) The processor shall immediately inform the controller of supervisory authority inspections or inquiries concerning processing on behalf of the controller.
The specific technical and organizational measures are set out in the TOM Annex at the end of this agreement and form part of this agreement. The processor shall provide all necessary information on request to demonstrate compliance. Audits may be conducted after prior notice during normal business hours.
The processor shall promptly notify the controller (within 24 hours of knowledge) of any breach of personal data protection and support compliance with the notification obligations under Art. 33 and 34 GDPR. Notification is sent by email to the address stored in the customer account.
(1) Upon termination of the usage agreement, the processor shall, upon request, return all personal data processed on behalf of the controller (e.g. as CSV export) or delete it in a data protection-compliant manner.
(2) Data are deleted within 30 days after termination, unless statutory retention obligations apply (e.g. tax law: 10 years for invoice data).
(3) Backups containing personal data are automatically overwritten within the backup rotation cycle (max. 14 days).
(1) The controller grants general authorization for the use of the subprocessors listed in the „Subprocessors" Annex. The processor will notify the controller at least four weeks in advance of any intended changes.
(2) The processor ensures that all subprocessors guarantee a data protection level at least equivalent to this agreement.
The processor enables the controller or an authorized auditor to carry out inspections during normal business hours after at least two weeks' prior notice. Such audits may also be conducted by presenting current certifications, attestations, or reports from independent auditors.
Liability follows the provisions of Art. 82 GDPR and the liability limitations of the usage agreement / processor's terms.
(1) Amendments and supplements to this agreement require written form (electronic accepted).
(2) Should individual provisions be invalid, the validity of the remaining provisions is unaffected.
(3) German law applies. Exclusive jurisdiction is Pinneberg.
Pursuant to Art. 32 GDPR, the processor implements the following measures:
| Measure | Implementation |
|---|---|
| Pseudonymization and encryption | Passwords via bcrypt hash · OAuth tokens AES-256 encrypted · HTTPS/TLS 1.2+ transmission · Cloudflare TLS proxy |
| Confidentiality, integrity, availability, resilience | Strict tenant separation via user_id filtering on all DB queries · Pool pre-ping against poisoned connections · systemd auto-restart on crash |
| Recoverability | Daily PostgreSQL backups (pg_dump) · 14-day rotation · Restore tested |
| Regular effectiveness review | Code reviews on schema changes · Multi-tenancy audits · Versioned Alembic migrations |
| Identification and authorization | Email/password login · CSRF protection · Session cookies with Secure/HttpOnly/SameSite=Lax · Audit log of sensitive access |
| Protection during transmission | HTTPS enforced (HSTS max-age 1 year + preload) · HTTP→HTTPS 301 redirect · TLS for third-party APIs |
| Protection during storage | PostgreSQL with database-level access restrictions · Tokens encrypted · Backups compressed and encrypted |
| Physical security | Hosting on server in Germany · Access restricted · Cloudflare CDN/DDoS protection |
| Event logging | Server log files (14 days) · Audit log for sensitive data access (90 days) · Error log with stack traces in admin panel |
| System configuration | Versioned migrations (Alembic) · Environment variables for secrets · Reproducible deployments via systemd |
| IT governance | Sole proprietor (Diar Yousefi) responsible for IT security · Clear escalation email |
| Data minimization | Only required data stored · No buyer emails beyond eBay anonymization · No third-party trackers |
| Data quality | Real-time sync with eBay · Input validation · Periodic order sync every 15 min |
| Limited storage duration | Server logs 14 days · Audit log 90 days · User data 30 days after termination · Tax-relevant data 10 years |
| Accountability | Record of processing activities maintained · Privacy policy documented · This DPA available at /avv |
| Data portability / erasure | CSV export of all data possible · Account deletion via contact request |
The controller generally authorizes the use of the following subprocessors:
| Provider | Purpose / data category |
|---|---|
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA, USA | CDN, DDoS protection, TLS termination. IP addresses, HTTP headers. Secured by EU-U.S. Data Privacy Framework + SCC. |
| Stripe, Inc. 510 Townsend St, San Francisco, CA, USA | Payment processing. Customer payment data. EU-U.S. DPF certified. |
| eBay GmbH Albert-Einstein-Ring 2–6, 14532 Kleinmachnow, DE | Platform integration. Acting on controller's instruction. |
| Resend, Inc. 2261 Market Street #5039, San Francisco, CA, USA | Transactional email delivery (verification, payment notices). Recipient email address. SCC. |
| Google LLC (Google Cloud / Gemini API) 1600 Amphitheatre Parkway, Mountain View, CA, USA | AI interface (Gemini). EU-U.S. DPF + SCC. |
| Anthropic PBC 548 Market St, San Francisco, CA, USA | AI interface (Claude). Message content. Contractually no training. SCC. |
| Groq, Inc. 400 Castro St, Mountain View, CA, USA | AI interface (Llama inference). Message content. Contractually no training. SCC. |
| Deutsche Post AG Charles-de-Gaulle-Str. 20, 53113 Bonn, DE | Internetmarke shipping labels. Recipient address data. |
| DHL Paket GmbH Sträßchensweg 10, 53113 Bonn, DE | Package shipping and tracking. Recipient address data. |
Changes to this list will be announced by email with a four-week notice period. Failure to object within this period constitutes approval.
Date, location · Controller
Name, function
Pinneberg, ____________
Date, location · Processor
Diar Yousefi, Owner
Name, function