Appendix 1 Data Processing Appendix
Terms and Notices — Sellforte Solutions Oy — 2026-09
EU/rest of the world (excluding the US). The contracting entity in the Order Form determines the applicable terms.
Appendix 1 Data Processing Appendix
Version 2026-09-22
- 1 Scope of Application and Roles of the Parties
- 2 Duration and Termination of the Processing
- 3 Processing of Personal Data
- 4 Categories of Personal Data and Data Subjects
- 5 Personnel
- 6 Security Measures
- 7 Subprocessing
- 8 Data Subject Rights
- 9 Personal Data Breach
- 10 Data Protection Impact Assessments and Prior Consultation
- 11 Deletion or Return of Personal Data
- 12 Audit Rights
- 13 International Transfers
- 14 Liability
- 15 Notices
- 16 Annexes
1 Scope of application and roles of the Parties
1.1 Applicability. This Data Processing Appendix, including Annexes A–D, governs Personal Data processed by Sellforte on the Customer's behalf under the Agreement (“Customer Personal Data”). It forms part of the Agreement and meets Article 28 GDPR requirements.
1.2 Roles. The Customer is controller, or a processor authorized by its controller, for Customer Personal Data, including Personal Data in Customer Content and User account, access, and service-use data processed on the Customer’s behalf. Sellforte acts as processor or subprocessor for that processing. Sellforte separately acts as controller for its own processing purposes described in the Online Service Privacy Notice.
Where the Customer deploys Tracking Technology and the Parties jointly determine the purposes and essential means of its collection and transmission of Personal Data, this paragraph forms their Article 26 arrangement for that step only. The Customer manages deployment, lawful basis, consent, visitor notices, and the initial contact point for individuals. Sellforte manages its collection and transmission design, security, implementation of configured consent signals, and accurate technical information. Each Party is responsible for the lawfulness, security, retention and deletion, processors, and international transfers within its control. They will cooperate on rights requests, incidents, impact assessments, and required authority notifications; each remains responsible for its own duties. The Customer will include the essence of this arrangement in its visitor notice using information supplied by Sellforte. Requests received by either Party are forwarded promptly, and individuals may exercise rights against either Party. Subsequent processing solely for the Customer is governed by the processor provisions of this DPA. If the Customer acts for another controller, it must identify that controller and obtain authority to agree this arrangement on its behalf before deployment. Roles depend on actual activities; deployment alone does not establish joint controllership.
1.3 Other providers. External Services independently obtained by the Customer are outside this DPA for their own processing. A supplier is a Sellforte subprocessor where Sellforte engages it to process Customer Personal Data, regardless of the supplier’s product label.
1.4 Purpose. This DPA applies only to the processing described in Annex B and agreed instructions.
1.5 Affiliates. Access to Customer Personal Data by an Affiliate of Sellforte requires authorization under Section 7 (Subprocessing) and the applicable transfer safeguards under Section 13 (International transfers). Sellforte remains responsible for that Affiliate's performance. This does not make the Affiliate a contracting party to the Customer's Order Form.
1.6 Interpretation. Terms have the meanings in the ToS or applicable Data Protection Legislation. GDPR means Regulation (EU) 2016/679, as amended. UK GDPR means that Regulation as incorporated into UK law and amended. Personal Data Breach has the meaning in Article 4(12) of the applicable GDPR regime. References within this DPA are to its own sections unless stated otherwise.
1.7 Precedence within the Agreement. Applicable standard contractual clauses for international Personal Data transfers (SCCs) and the UK Addendum to those clauses prevail over conflicting provisions of the Agreement. Subject to those terms, this DPA prevails for Personal Data processing. Other conflicts follow ToS Section 18.3 (Document priority).
2 Duration and termination of processing
2.1 Duration. This DPA applies from the first processing of Customer Personal Data until its return or erasure, including after the Services end.
2.2 Post-termination use. After termination, processing is limited to lawful return, retrieval, erasure, and mandatory retention under Section 11 (Deletion or return of Personal Data).
2.3 Processing noncompliance. Sellforte will promptly inform the Customer if it cannot comply with this DPA. The Customer may instruct Sellforte to suspend affected processing while a failure is resolved. The Customer may terminate the affected Services by written notice if compliance is not restored within a reasonable time, and in any event within one month after that suspension; if Sellforte substantially or persistently breaches this DPA or applicable Data Protection Legislation; or if Sellforte fails to comply with a binding court or supervisory-authority decision concerning that processing.
2.4 Unlawful instructions. If, after Sellforte explains why an instruction is unlawful and allows a reasonable opportunity to correct it where lawful and practical, the Customer insists on that instruction, Sellforte may terminate the affected Services by written notice. Sellforte need not carry out unlawful processing.
2.5 Effect of termination. Termination under Sections 2.3 or 2.4 ends only the affected Services and related processing. It ends the affected Order Form only where the remaining Services cannot reasonably operate independently; other Order Forms continue. Fees remain payable through the effective termination date but not beyond it, with a pro rata refund of prepaid fees for later periods under ToS Section 17.8 (Fees and refunds on termination). If Sellforte terminates for the Customer’s material breach, the remaining committed fees instead follow that Section. Return, erasure, and continuing protection follow Section 11 (Deletion or return of Personal Data).
3 Processing of Personal Data
3.1 Instructions. Sellforte processes Customer Personal Data, including transfers, only on documented instructions in the Agreement, authorized settings, or later written instructions. An exception applies where processing is required by EU or Member State law to which Sellforte is subject. Sellforte will inform the Customer before that processing unless the law prohibits this on important grounds of public interest. Where UK GDPR applies, the corresponding UK-law requirements apply. Sellforte will immediately inform the Customer if it considers an instruction unlawful and suspend the affected processing pending resolution under Section 2.4 (Unlawful instructions).
Sellforte will not use Customer Personal Data to train or improve general-purpose or generative models, or permit its suppliers to do so. Customer-specific analytical modeling is permitted for the agreed Services.
3.2 Customer duties. The Customer remains responsible for its own controller or processor duties and for obtaining authority from any controller it represents.
3.3 Lawful inputs. The Customer must have a lawful basis for providing data and issuing instructions, including any required notices, consents, and source-provider permissions.
3.4 Data quality. The Customer determines the lawfulness and accuracy of its inputs. Sellforte will notify it of material issues Sellforte identifies and assist with corrections within its processing responsibilities.
4 Categories of Personal Data and Data Subjects
4.1 Restricted data. The Customer must not intentionally submit special-category or criminal-offense Personal Data without prior written agreement on necessity, lawful basis, and safeguards. Properties directed primarily to children follow ToS Section 3.6 (Tracking Technology); the Services must not be used to identify, profile, or target children, but lawful purchase data involving children is not prohibited solely because of their age. Accidental receipt of restricted data remains protected by this DPA and must be contained and remedied promptly.
4.2 Processing details. The nature and purposes of the processing, the categories of Personal Data and data subjects, and the duration of the processing are further described in Annex B (Data Processing details), which forms an integral part of the DPA (Appendix 1 to the Terms of Service).
5 Personnel
5.1 Personnel. Sellforte limits access to authorized personnel who need it, are trained in privacy and security, and are bound by written or statutory confidentiality duties. Access is reviewed and removed when no longer needed.
6 Security measures
6.1 Security controls. Sellforte will implement and maintain technical and organizational measures appropriate to the risk, in accordance with Article 32 GDPR. In setting these measures, Sellforte considers the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks to data subjects' rights and freedoms (including risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data).
6.2 Security schedule. Annex A states the contractual security measures. Sellforte may update their implementation without materially reducing overall protection; changes to processing scope or subprocessors follow this DPA.
7 Subprocessing
7.1 Authorization to use subprocessors. The Customer hereby provides a general authorization for Sellforte to engage subprocessors, including its Affiliates, to process Personal Data in connection with the provision of the Services, provided that Sellforte remains responsible for compliance with this DPA in accordance with applicable Data Protection Legislation.
7.2 List and changes. Annex C lists authorized subprocessors and activities. Sellforte will give 30 days' prior written notice of additions or replacements. Posting alone is insufficient. The Customer may object on reasonable data-protection grounds within 30 days of notice.
Access may begin only after the applicable advance notice period, unless the Customer gives prior specific written authorization for earlier access and applicable transfer terms permit it. On a timely, substantiated objection, Sellforte will withhold or stop access while the Parties seek an alternative for up to 30 days, using existing arrangements or proportionate suspension. If none is feasible, either Party may terminate the affected Services, and the proposed processing must not begin or must stop. Fees remain payable through the effective termination date but not beyond it. Sellforte will refund prepaid fees for the period after that date pro rata under ToS Section 17.8 (Fees and refunds on termination).
7.3 Flow-down. Sellforte will assess each subprocessor’s guarantees and impose equivalent applicable Article 28 obligations by written agreement. It remains fully liable to the Customer for their performance, subject to lawful contractual limits. Subprocessor agreements do not reduce Sellforte’s obligations under this DPA. Sellforte will promptly notify the Customer of a subprocessor’s failure to fulfill its data-protection obligations affecting the Customer’s processing.
7.4 Evidence. Sellforte will provide relevant information about subprocessor safeguards and the applicable processing obligations on reasonable request, including relevant portions of subprocessor agreements and amendments. Confidential information may be redacted where lawful. Disclosure required by law or applicable SCCs remains available. Recipient identities, functions, and processing locations are supplied as described in Annex C.
8 Data Subject rights
8.1 Assistance with Data Subject requests. Taking into account the nature of the processing and the information available, Sellforte will reasonably assist the Customer in responding to data subject requests under Data Protection Legislation — including access, rectification, erasure, restriction, portability, and objection.
8.2 Direct Data Subject requests. If Sellforte receives a request directly from a data subject regarding Customer Personal Data, it will notify the Customer without undue delay and not respond except on the Customer's documented instructions or as required by law.
8.3 Cooperation with authorities. Sellforte will reasonably cooperate with the Customer on inquiries, assessments, audits, or investigations by supervisory authorities, to the extent they relate to Sellforte's processing of Customer Personal Data.
8.4 Costs. Sellforte will provide reasonable assistance under this Section 8 (Data Subject rights) as part of the Services. The Customer will reimburse Sellforte for reasonable and documented costs only where the assistance materially exceeds standard support efforts (for example, ad-hoc engineering work or extensive data extractions). No reimbursement is due where the assistance is required due to Sellforte's breach of this DPA or applicable Data Protection Legislation.
9 Personal Data Breach
9.1 Notification. Sellforte will notify the Customer of a Personal Data Breach without undue delay after becoming aware of it, aiming to provide initial notice within 24 hours. It will not wait for a complete investigation. Notice will include available Article 33(3) information, a contact point, and phased updates sufficient to assist the Customer's own deadlines. Notification is not an admission of liability.
9.2 Response. Sellforte will investigate, contain, mitigate, and remediate breaches within its responsibilities and cooperate with the Customer. It will not notify individuals or authorities on the Customer’s behalf without instructions unless law requires it.
9.3 Costs. Sellforte bears its own costs of fulfilling its incident-response obligations. Claims for the Customer’s costs and losses are governed by Section 14 (Liability) and ToS Section 16 (Warranties and liability). If the Customer’s breach causes additional response work, Sellforte may charge reasonable, documented costs after consulting the Customer, subject to those provisions. Cost discussions must not delay urgent or legally required action.
10 Data protection impact assessments and prior consultation
10.1 Assistance with DPIAs and prior consultation. Taking account of the processing and information available, Sellforte will reasonably assist with the Customer's data protection impact assessments (Article 35 GDPR) and prior supervisory consultations (Article 36 GDPR) concerning its processing of Customer Personal Data.
10.2 Costs. Reasonable DPIA and prior-consultation assistance is included in the Services. The Customer reimburses reasonable, documented costs only for assistance materially exceeding standard support, unless required by Sellforte's breach of this DPA or Data Protection Legislation.
11 Deletion or return of Personal Data
11.1 Return or erasure. At the Customer’s choice, Sellforte will return or delete all Customer Personal Data and existing copies, including relevant support records and logs, using the timetable in ToS Section 17.6 (Return and erasure), whether or not the data is Exportable Data. Earlier lawful Customer instructions and shorter mandatory deadlines prevail. Any legally required retention must meet Article 28(3)(g): EU or Member State law under EU GDPR, and UK law under UK GDPR, as applicable. Retained copies remain protected, are restricted to permitted retention purposes, and remain subject to this DPA until deletion. Sellforte will confirm deletion in writing on request and identify any remaining lawful retention, its basis, and expected expiry.
12 Audit rights
12.1 Information and audits. Sellforte will provide Article 28 compliance information and allow and contribute to audits and inspections by the Customer or its independent auditor. A third-party auditor must not be a Sellforte competitor and must sign a reasonable confidentiality undertaking acceptable to Sellforte. Approval may not be unreasonably withheld. These arrangements must allow the Customer to exercise its statutory audit rights.
12.2 Procedure. The Parties will first use relevant reports and documentation where sufficient. Additional inspection remains available where needed. Ordinarily, audits occur once annually on 30 days' notice during business hours and avoid unnecessary disruption and disclosure of other customers' data or trade secrets. Shorter notice or additional audits are allowed for a material incident, credible compliance concerns, or a legal or regulatory requirement. No certification is promised unless expressly identified in the Agreement.
12.3 Costs. Each Party bears its ordinary audit-support costs. The Customer pays its auditor and additional assistance beyond ordinary audit support at charges agreed in advance. Sellforte bears reasonable costs attributable to an audit establishing its material breach. Costs must not obstruct statutory audit rights.
12.4 Regulatory and supervisory audits. This Section 12 (Audit rights) does not limit competent supervisory authorities' statutory rights. Sellforte must permit legally required audits and inspections of its processing and require authorized subprocessors to provide necessary assistance, subject to appropriate confidentiality and security safeguards.
13 International transfers
13.1 Transfers. Customer Personal Data may be processed outside the EEA only within the authorized service arrangements and under a valid adequacy decision or safeguards under Article 46 GDPR (Transfers subject to appropriate safeguards), with any required assessments and supplementary measures. The agreed primary hosting region and Annex C apply.
13.2 SCCs. Annex D identifies transfer safeguards for Sellforte's suppliers and Affiliates. Sellforte ensures that the required SCCs bind each relevant exporter and importer.
13.3 Transparency. Sellforte will provide processing locations, recipient details, safeguards and relevant transfer-assessment information on reasonable request, with lawful confidentiality redactions. It will implement a valid replacement mechanism or suspend an affected transfer if its safeguard ceases to be valid.
13.4 Precedence. Applicable SCCs and the UK Addendum prevail as stated in Section 1.7 (Precedence within the Agreement).
14 Liability
14.1 Data Subject claims. Each Party's liability to data subjects is determined under Article 82 GDPR (Right to compensation and liability) or corresponding mandatory Data Protection Legislation.
14.2 Allocation. Between the Parties, responsibility follows each Party’s breach and causal contribution, including Sellforte’s responsibility for subprocessors. ToS Section 16 (Warranties and liability) governs contractual remedies and lawful caps, including the special cap for DPA breaches. Nothing limits mandatory Article 82 recourse, data-subject or supervisory-authority rights, or liability under applicable SCCs to the extent their terms prohibit limitation. The conditional joint-controller arrangement does not transfer either Party’s own statutory duties.
15 Notices
15.1 Privacy notices. Send DPA notices to privacy@sellforte.com and the Customer's designated contact in the Order Form, unless a Party gives written notice of another contact.
16 Annexes
16.1 Annexes. Annex A sets out security measures; Annex B processing details; Annex C subprocessors; and Annex D transfer safeguards. All form part of this DPA.
16.2 Updates. Subprocessor changes follow Section 7.2 (List and changes). Other changes follow ToS Section 18.4 (Amendments). Changes requiring new or amended Customer instructions take effect only once those instructions are documented. All changes must comply with Data Protection Legislation and applicable transfer safeguards. Sellforte will maintain a current reproducible version.
