Data processing agreement (DPA)
Agreement under Art. 28 GDPR between the business customer as controller and PHU Artcom ŁUKASZ ZIEMIAŃSKI as processor. Version 2026-07-21.
Version: 2026-07-211. Subject and duration
The subject is processing personal data while providing VersandFaktur. The DPA applies from electronic acceptance for the service contract term and until commissioned data is returned or deleted.
2. Nature and purpose
Processing includes import, storage, organisation, display, modification, transmission and deletion of eBay orders, recipient addresses, DHL shipments and tracking, invoices and email delivery. It serves only the customer-controlled sales, shipping and invoicing workflow.
3. Data and individuals
Data includes names, addresses, emails, phone numbers, eBay identifiers, order and item data, prices and payment status, invoice and tax data, shipping and tracking data and communication and log data.
Individuals include buyers, recipients, invoice recipients, contacts and, where applicable, customer staff or agents.
4. Instructions and customer responsibility
The customer is controller and ensures lawful collection, processing and transfer. Functions and settings used in VersandFaktur are documented instructions. Additional instructions must be sent in text form to artcom04@o2.pl.
If an instruction appears unlawful, the processor informs the customer and may pause it pending clarification.
5. Processor duties
The processor acts only on documented instructions, binds authorised personnel to confidentiality, provides appropriate security, assists with data subject rights, impact assessments and authority enquiries and provides information needed to demonstrate compliance.
6. Technical and organisational measures
Measures include TLS, secure password hashing, separated accounts and ownership checks, role- and session-based access, CSRF protection, protected document paths, expiring download links, minimised logs, backups, controlled releases, security updates and recovery procedures.
Measures may evolve with technology provided the level of protection is not reduced.
7. Sub-processors
The customer gives general authorisation for sub-processors. These currently include Hetzner Online GmbH for hosting and Mailgun Technologies, Inc. or Sinch Email for transactional email. Mailgun’s EU region is selected; recipient and sender addresses, content, attachments or download link and delivery and error data may be processed. Technical CDN providers may deliver static libraries.
Customers are informed of material changes and may object for important data protection reasons. Sub-processors are bound to an appropriate protection level.
Where Mailgun/Sinch or its approved sub-processors process data in third countries, the safeguards in the applicable data processing agreement apply, particularly adequacy decisions or standard contractual clauses.
8. Data subject assistance
Requests concerning commissioned data are forwarded to the customer. VersandFaktur assists reasonably through available search, export, correction and deletion functions or technical support.
9. Personal data breaches
Breaches affecting commissioned data are reported to the customer without undue delay after discovery, with available information about nature, scope, likely consequences and measures. The customer remains responsible for statutory notifications.
10. Return and deletion
At contract end, commissioned data is deleted or made available in an existing standard format as instructed, unless retention is legally required. Backups are overwritten in the normal cycle and remain protected and unused for production until then.
11. Evidence and audits
The customer may request reasonable evidence annually and for a concrete cause. On-site audits require advance coordination, must be proportionate and may not compromise security, other customers’ confidentiality or operations. Disproportionate extra work may be charged by prior agreement.
12. International transfers and final terms
International transfers occur only under Art. 44 et seq. GDPR. This DPA supplements the terms and prevails for processing matters. The law chosen in the terms applies unless the GDPR requires otherwise.