Data Processing Agreement — Selling Partners
This agreement forms part of the WinkelFactuur Terms of Service. Where the Controller is established in the European Economic Area and the Processor processes personal data outside it, the Standard Contractual Clauses in Annex IV apply and prevail over any conflicting term.
Summary
- Version 1.0. In force from 4 September 2026 for accounts created on or after that date, and from 4 October 2026 for accounts that existed on it.
- This agreement forms part of the Terms of Service. Accepting the Terms means accepting it.
- You are the controller of the personal data in your orders; we are your processor and act only on your instructions.
- Annex IV contains the European Commission's Standard Contractual Clauses, Module Two, which cover the transfer to Türkiye.
- Questions: [email protected]
Parties
the WinkelFactuur customer identified in the account (the Controller / data exporter) and FOR KIVANC BILISIM EV DEKORASYON VE DIS TICARET SANAYI TICARET LIMITED SIRKETI, trading as WinkelFactuur, Pınar Mah. 74229 Sok. Safir Life Sit. A Blok No:16/6, Seyhan/Adana, Türkiye (the Processor / data importer).
Version 1.0 · Owner: Founder (Data Protection Officer) · Review: annually · Published at https://winkelfactuur.nl/en/data-processing-agreement/
1. Subject matter and duration
The Processor produces, delivers and archives invoices and related documents for orders the Controller receives on connected marketplaces (bol.com, Amazon, Shopify, WooCommerce and others), and exports them to the Controller's accounting software. Processing lasts for the term of the account and the retention periods in Annex I.
2. Nature and purpose
Retrieval of order data from the marketplaces the Controller connects (for Amazon: through the Selling Partner API), generation of invoices and credit notes with the applicable VAT treatment, delivery of those documents to the buyer or the marketplace, export to accounting software, and the support needed to do so. Nothing else: no marketing, no contacting buyers, no analytics beyond the service, no sale or sharing, no training of AI or machine-learning models.
3. Categories of data and data subjects
Annex I.
4. Processor obligations (Article 28(3) GDPR)
The Processor shall:
- process personal data only on the Controller's documented instructions — which are this agreement, the Terms of Service and the configuration the Controller sets in the application — unless required by Union or Member State law, in which case it informs the Controller before processing where the law allows;
- ensure that persons authorised to process the data are bound by confidentiality (the Acceptable Use Policy and the Approved User designation);
- implement the technical and organisational measures in Annex II;
- respect the conditions in section 6 for engaging sub-processors;
- assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests (the Data Subject Rights Procedure applies; a buyer who contacts the Processor is referred to the Controller);
- assist the Controller in meeting its obligations on security, breach notification, impact assessments and prior consultation, taking into account the nature of the processing and the information available to it;
- at the Controller's choice, delete or return all personal data at the end of the service and delete existing copies, unless Union or Member State law requires storage — invoices already issued are retained for the statutory period and for no other purpose;
- make available all information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice and no more than once a year unless a breach or a supervisory authority requires otherwise;
- inform the Controller immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.
5. Personal data breach
The Processor notifies the Controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the information Article 33(3) GDPR requires as far as it is available, and updates it as the investigation proceeds (Incident Response Plan). For Amazon Information the Processor also meets the notification duty in the Amazon Data Protection Policy (24 hours).
6. Sub-processors
The Controller gives general authorisation for the sub-processors in Annex III. The Processor informs the Controller of any intended addition or replacement at least 30 days in advance through the application or by e-mail; the Controller may object on reasonable data protection grounds, in which case the parties seek a solution and, failing one, the Controller may terminate the affected service. The Processor imposes the same data protection obligations on each sub-processor by written contract and remains fully liable to the Controller for the sub-processor's performance.
7. International transfers
Personal data is stored and processed in the European Union (Germany, AWS region eu-central-1). Remote administrative access by the Processor's personnel from Türkiye is a transfer to a third country without an adequacy decision; it is covered by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), incorporated in Annex IV, with the Controller as data exporter and the Processor as data importer. The Processor does not transfer the data to any other third country.
8. Liability, term and law
Liability follows the Terms of Service, without limiting either party's liability to data subjects under Article 82 GDPR. The agreement ends with the account; sections 4(7) and 5 survive until the data is deleted or returned. The law and courts of the Terms of Service apply, subject to Annex IV.
---
Annex I — Description of the processing
- Data subjects — Description: Buyers on the Controller's connected marketplaces; the Controller's own users
- Categories of personal data (buyers) — Description: Name, billing and shipping address, e-mail address where the marketplace provides it, order number, items, amounts and VAT, marketplace order identifiers
- Categories of personal data (Controller's users) — Description: Name, e-mail address, role, sign-in and audit records
- Special categories — Description: None
- Frequency — Description: Continuous, driven by orders
- Retention — Description: Buyer personal data on marketplace orders: 30 days from the order date (Amazon orders: automatic deletion by the retention job); invoices and credit notes: the statutory retention period (seven years, Dutch tax law) in an archive not accessible through the application after account deletion; account data: until account deletion plus the 30-day grace period
- Deletion on request — Description: Amazon Information: `amazon:delete-information` within 30 days of the request; all other data: the account deletion flow
Annex II — Technical and organisational measures
- Hosting in AWS eu-central-1 in a private VPC; database not publicly reachable; object storage with public access blocked and TLS-only policy.
- Encryption in transit (TLS 1.2+ at the edge, origin and database) and at rest (AES-256: RDS with KMS, S3 SSE-S3, EBS); platform credentials encrypted at field level.
- Access control: single named operator with key-based SSH from an allow-listed address; MFA on all administrative and cloud identities; role-based access in the application; support access logged.
- Web application firewall (OWASP CRS) and edge DDoS protection; malware scanning of uploaded files; automatic security patching.
- Logging to a central store with 13-month retention; alarms on security events; daily alert review; fortnightly log review; GuardDuty threat detection.
- Secure development: code review by automated gates, dependency and secret scanning on every change, annual external penetration test.
- Backups: automated, encrypted, 30-day point-in-time recovery, restore tested.
- Retention automation and on-request deletion tooling (Annex I).
- Policies: Information Security Policy set including Acceptable Use, Access Control, Incident Response, Data Protection and Retention, Data Subject Rights.
Annex III — Sub-processors
- Amazon Web Services EMEA SARL — Purpose: Hosting, database, storage, e-mail delivery, queues, logging · Location: Germany (eu-central-1) · Safeguard: AWS GDPR DPA incl. SCCs
- Cloudflare, Inc. — Purpose: TLS termination, DDoS and WAF at the edge · Location: EU points of presence; global network for traffic data · Safeguard: Cloudflare Customer DPA incl. SCCs
- Functional Software, Inc. (Sentry) — Purpose: Error telemetry (personal data removed before sending) · Location: Per Sentry DPA · Safeguard: Sentry DPA incl. SCCs
Transfer impact summary for Annex IV: the data at rest never leaves the EEA; the Türkiye leg is remote administrative access only, over TLS, with no local copy; Turkish law does not, to the Processor's knowledge, give public authorities access to data held in the EU by the sub-processors above; the measures in Annex II apply throughout.
Annex IV — Standard Contractual Clauses, Module Two (controller to processor)
The Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two, are incorporated by reference with the following selections: Clause 7 (docking clause) included; Clause 9(a) Option 2 (general authorisation, 30 days' notice); Clause 11 (redress) without the optional independent dispute resolution; Clause 13 — the supervisory authority of the Member State in which the data exporter is established; Clause 17 Option 1 — the law of the Netherlands; Clause 18 — the courts of the Netherlands. Annex I.A (parties) is the account record; Annex I.B is Annex I above; Annex I.C is the competent supervisory authority under Clause 13; Annex II is Annex II above; Annex III is Annex III above. The full text of the Clauses is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj and is provided to the Controller on request.
Acceptance
The Controller accepts this agreement by accepting the Terms of Service; the acceptance record (account, user, timestamp, version) is kept with the account. The Processor's signatory: Mehmet Karabulut, Founder and Managing Director.