Appendix 1 Data Processing Appendix
Terms and Notices — Sellforte Solutions Oy — 2026-09
EU/rest of the world (excluding the US)
Appendix 1 Data Processing Appendix
- 1 Scope of Application and Roles of the Parties
- 2 Duration and Termination of the Processing
- 3 Processing of Personal Data
- 4 Categories of Personal Data and Data Subjects
- 5 Personnel
- 6 Security Measures
- 7 Subprocessing
- 8 Data Subject Rights
- 9 Personal Data Breach
- 10 Data Protection Impact Assessments and Prior Consultation
- 11 Deletion or Return of Personal Data
- 12 Audit Rights
- 13 International Transfers
- 14 Liability
- 15 Notices
- 16 Annexes
1 Scope of Application and Roles of the Parties
1.1 Applicability. This Data Processing Appendix, including Annexes A–D, governs Personal Data processed by Sellforte on the Customer's behalf under the Agreement (“Customer Personal Data”). It forms part of the Agreement and meets Article 28 GDPR requirements.
1.2 Roles. The Customer is controller, or a processor authorized by its controller, for Customer Personal Data. This includes User account, access, and service-use data processed to operate the Customer's workspace. Sellforte acts as processor or subprocessor for that processing. Sellforte separately acts as controller for limited platform security, product-usage analytics, Feedback, and other own-purpose processing described in the applicable privacy notices. Any Customer Content in those systems remains subject to this DPA where processed on the Customer's behalf.
Where the Parties jointly determine the purposes and essential means of Tracking Technology collection and transmission, they are joint controllers for that step only. The Customer manages deployment, lawful basis, consent, notices, and the initial contact point for individuals. Sellforte is responsible for its collection and transmission design, security, honoring the configured consent signals, and supplying accurate technical information. Each must establish its own legal basis, cooperate on rights requests, breaches and impact assessments, and make the essence of this arrangement available. Requests received by either are forwarded promptly; individuals may exercise rights against either Party. Each handles required authority notifications for its responsibilities and cooperates to avoid inconsistent responses. Subsequent processing solely for the Customer is governed by this DPA. Joint controllership depends on actual activities, not merely the presence of a pixel.
1.3 Other providers. Providers independently selected by the Customer, including advertising platforms and external AI tools, are outside this DPA for their own processing. A supplier is a Sellforte subprocessor where Sellforte engages it to process Customer Personal Data, regardless of the supplier's product label.
1.4 Purpose. This DPA applies only to the processing described in Annex B and agreed instructions.
1.5 Affiliates. Customer-data access by an Affiliate requires authorization under Section 7 (Subprocessing) and the transfer safeguards in Section 13 (International Transfers). Sellforte remains responsible and this does not make that Affiliate a contracting party to the Customer's Order Form.
1.6 Interpretation. Terms have the meanings in the ToS or applicable Data Protection Legislation. “Personal Data Breach” has the meaning in Article 4(12) GDPR. References within this DPA are to its own sections unless stated otherwise.
1.7 Precedence within the Agreement. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to matters relating to the processing of Personal Data.
2 Duration and Termination of the Processing
2.1 Duration. This DPA applies from the first processing of Customer Personal Data until its return or erasure, including after the Services end.
2.2 Post-termination use. After termination, processing is limited to lawful return, retrieval, erasure, and mandatory retention under Section 11 (Deletion or Return of Personal Data).
3 Processing of Personal Data
3.1 Instructions. Sellforte processes Customer Personal Data, including transfers, only on documented instructions in the Agreement, authorized settings, or later written instructions. Processing required by law outside those instructions needs prior Customer notice unless prohibited. The exception covers only EU or Member State law. Where UK GDPR also applies, its requirements must also be met. Sellforte will flag instructions it considers unlawful and suspend affected processing pending resolution. Extra work outside the agreed Services may be charged. Mandatory data-protection duties still apply.
Sellforte will not use Customer Personal Data to train or improve general-purpose or generative models, or permit its suppliers to do so. Customer-specific analytical modeling is permitted for the agreed Services. Creating anonymous Aggregate Data requires the instruction and conditions in ToS Section 11.3 (Anonymous Aggregate Data). Security and abuse-detection processing by authorized suppliers must remain within their applicable processing terms and this DPA; it is not permission for general model training.
3.2 Customer duties. The Customer remains responsible for its own controller or processor duties and for obtaining authority from any controller it represents.
3.3 Lawful inputs. The Customer must have a lawful basis for providing data and issuing instructions, including any required notices, consents, and source-provider permissions.
3.4 Data quality. The Customer determines the lawfulness and accuracy of its inputs. Sellforte will notify it of material issues Sellforte identifies and assist with corrections within its processing responsibilities.
4 Categories of Personal Data and Data Subjects
4.1 Restricted data. The Customer must not intentionally submit special-category or criminal-offense Personal Data without prior written agreement on necessity, lawful basis, and safeguards. Properties directed primarily to children follow ToS Section 3.6 (Tracking Technology); the Services must not be used to identify, profile, or target children, but lawful purchase data involving children is not prohibited solely because of their age. Accidental receipt of restricted data remains protected by this DPA and must be contained and remedied promptly.
4.2 Processing Details. The nature and purposes of the processing, the categories of Personal Data and data subjects, and the duration of the processing are further described in Annex B (Data Processing Details), which forms an integral part of the DPA (Appendix 1 to the Terms of Service).
5 Personnel
5.1 Personnel. Sellforte limits access to authorized personnel who need it, are trained in privacy and security, and are bound by written or statutory confidentiality duties. Access is reviewed and removed when no longer needed.
6 Security Measures
6.1 Security Controls. Sellforte shall implement and maintain technical and organizational measures appropriate to the risk, in accordance with Article 32 GDPR. In setting these measures, Sellforte considers the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks to data subjects' rights and freedoms (including risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data).
6.2 Security schedule. Annex A states the contractual security measures. Sellforte may update their implementation without materially reducing overall protection; changes to processing scope or subprocessors follow this DPA.
7 Subprocessing
7.1 Authorization to Use Subprocessors. The Customer hereby provides a general authorization for Sellforte to engage subprocessors, including its Affiliates, to process Personal Data in connection with the provision of the Services, provided that Sellforte remains responsible for compliance with this DPA in accordance with applicable Data Protection Legislation.
7.2 List and changes. Annex C lists authorized subprocessors and activities. Sellforte will give 30 days' prior written notice of additions or replacements. Posting alone is insufficient. The Customer may object on reasonable data-protection grounds within 30 days of notice.
For urgent incident response, Sellforte will use an authorized provider where reasonably possible. Otherwise, it may give shorter advance notice, explaining why and allowing a reasonable opportunity to object before access. The objection window and remedies below remain. Longer notice required by binding SCCs still applies.
Access may begin only after the applicable advance notice period. On a timely, substantiated objection, Sellforte will withhold or stop access while the Parties seek an alternative for up to 30 days, using existing arrangements or proportionate suspension. If none is feasible, either Party may terminate the affected Services, and the proposed processing must not begin or must stop. No future fees or early-termination charge apply. Unused prepaid fees are refunded under ToS Section 17.8 (Fees and refunds on termination). General authorization does not cover unlisted entities.
7.3 Flow-down. Sellforte will assess each subprocessor's guarantees and impose equivalent applicable Article 28 obligations by written agreement. It remains fully liable to the Customer for their performance, subject to lawful contractual limits. Subprocessor agreements do not reduce Sellforte's obligations under this DPA.
7.4 Evidence. Sellforte will supply relevant information about subprocessor safeguards and contractual obligations on reasonable request, with permitted redactions for confidential matters, without limiting disclosure required by law or SCCs.
8 Data Subject Rights
8.1 Assistance with Data Subject Requests. Taking into account the nature of the processing and the information available, Sellforte shall reasonably assist the Customer in responding to data subject requests under Data Protection Legislation — including access, rectification, erasure, restriction, portability, and objection.
8.2 Direct Data Subject Requests. If Sellforte receives a request directly from a data subject regarding Customer Personal Data, it shall notify the Customer without undue delay and not respond except on the Customer's documented instructions or as required by law.
8.3 Cooperation with Authorities. Sellforte shall reasonably cooperate with the Customer on inquiries, assessments, audits, or investigations by supervisory authorities, to the extent they relate to Sellforte's processing of Customer Personal Data.
8.4 Costs. Sellforte shall provide reasonable assistance under this Section 8 (Data Subject Rights) as part of the Services. The Customer shall reimburse Sellforte for reasonable and documented costs only where the assistance materially exceeds standard support efforts (for example, ad-hoc engineering work or extensive data extractions). No reimbursement is due where the assistance is required due to Sellforte's breach of this DPA or applicable Data Protection Legislation.
9 Personal Data Breach
9.1 Notification. Sellforte will notify the Customer of a Personal Data Breach without undue delay after becoming aware of it, aiming to provide initial notice within 24 hours. It will not wait for a complete investigation. Notice will include available Article 33(3) information, a contact point, and phased updates sufficient to assist the Customer's own deadlines. Notification is not an admission of liability.
9.2 Response. Sellforte will investigate, contain, mitigate, and remediate breaches within its responsibilities and cooperate with the Customer. It will not notify individuals or authorities on the Customer's behalf without instructions unless law requires it. Incident-response providers with data access must comply with applicable confidentiality, subprocessing, and transfer requirements.
9.3 Costs. Sellforte bears ordinary incident-response costs and costs caused by its or its subprocessors' breach. If the Customer's breach causes extra work, Sellforte may charge reasonable, documented costs after consulting the Customer. This must not delay urgent or legally required action.
10 Data Protection Impact Assessments and Prior Consultation
10.1 Assistance with DPIAs and Prior Consultation. Taking account of the processing and information available, Sellforte will reasonably assist with the Customer's data protection impact assessments (Article 35 GDPR) and prior supervisory consultations (Article 36 GDPR) concerning its processing of Customer Personal Data.
10.2 Costs. Reasonable DPIA and prior-consultation assistance is included in the Services. The Customer reimburses reasonable, documented costs only for assistance materially exceeding standard support, unless required by Sellforte's breach of this DPA or Data Protection Legislation.
11 Deletion or Return of Personal Data
11.1 Return or erasure. At the Customer's choice, Sellforte will return or delete Customer Personal Data under ToS Section 17.6 (Return and erasure), honoring earlier lawful instructions. Legally required retention must satisfy Article 28(3)(g) of each applicable GDPR regime: EU or Member State law under EU GDPR, and UK law under UK GDPR. This DPA continues until deletion.
11.2 Anonymous data. Anonymization of Customer Personal Data on the Customer's behalf is processing under this DPA and requires the documented instruction and conditions in ToS Section 11.3 (Anonymous Aggregate Data). The DPA does not apply to the resulting genuinely anonymous Aggregate Data. Identifiable or pseudonymized inputs and intermediate data remain Personal Data. Processing roles follow actual purposes and activities; Sellforte's limited independent-controller activities are described in the Online Service Privacy Notice.
12 Audit Rights
12.1 Information and audits. Sellforte will provide Article 28 compliance information and allow and contribute to audits and inspections by the Customer or its independent auditor. A third-party auditor must not be a Sellforte competitor and must sign a reasonable confidentiality undertaking acceptable to Sellforte. Approval may not be unreasonably withheld; confidentiality and security conditions must not prevent a necessary statutory audit.
12.2 Procedure. The Parties will first use relevant reports and documentation where sufficient. Additional inspection remains available where needed. Ordinarily, audits occur once annually on 30 days' notice during business hours and avoid unnecessary disruption and disclosure of other customers' data or trade secrets. Shorter notice or additional audits are allowed for a material incident, credible compliance concerns, or a legal or regulatory requirement. No certification is promised unless expressly identified in the Agreement.
12.3 Costs. Each Party bears its ordinary audit-support costs; the Customer pays its auditor and agreed reasonable exceptional assistance. Sellforte bears reasonable costs attributable to an audit establishing its material breach. Costs must not obstruct statutory audit rights.
12.4 Regulatory and Supervisory Audits. This Section 12 (Audit Rights) does not limit competent supervisory authorities' statutory rights. Sellforte must permit legally required audits and inspections of its processing and require authorized subprocessors to provide necessary assistance, subject to appropriate confidentiality and security safeguards.
13 International Transfers
13.1 Transfers. Customer Personal Data may be processed outside the EEA only within the authorized service arrangements and under a valid adequacy decision or safeguards under Article 46 GDPR (Transfers subject to appropriate safeguards), with any required assessments and supplementary measures. The agreed primary hosting region and Annex C apply.
13.2 SCCs. Annex D identifies transfer safeguards for Sellforte's suppliers and Affiliates. Sellforte ensures that the required SCCs bind each relevant exporter and importer.
13.3 Transparency. Sellforte will provide processing locations, recipient details, safeguards and relevant transfer-assessment information on reasonable request, with lawful confidentiality redactions. It will implement a valid replacement mechanism or suspend an affected transfer if its safeguard ceases to be valid.
13.4 Precedence. The SCCs prevail over conflicting DPA terms to the extent required by applicable Data Protection Legislation.
14 Liability
14.1 Data Subject Claims. Each Party's liability to data subjects is determined under Article 82 GDPR (Right to compensation and liability) or corresponding mandatory Data Protection Legislation.
14.2 Allocation. Between the Parties, responsibility follows each Party's breach and causal contribution, including Sellforte's responsibility for subprocessors. ToS Section 16 (Warranties and Liability) governs contractual remedies and lawful caps, including the special cap for DPA breaches. Nothing limits mandatory Article 82 recourse, data-subject or supervisory-authority rights, or SCC liability. The conditional joint-controller arrangement does not transfer either Party's own statutory duties.
15 Notices
15.1 Privacy Notices. Send DPA notices to privacy@sellforte.com and the Customer's designated contact in the Order Form, unless a Party gives written notice of another contact.
16 Annexes
16.1 Annexes. Annex A sets out security measures; Annex B processing details; Annex C subprocessors; and Annex D transfer safeguards. All form part of this DPA.
16.2 Updates. Subprocessor changes follow Section 7.2 (List and changes). Other updates follow ToS Section 18.4 (Amendments) and may not expand processing purposes or materially reduce protection without lawful agreement. Sellforte will maintain a current reproducible version.
