AutoDeck DMS
Data Processing Agreement
Template agreement under Article 28 of Regulation (EU) 2016/679
Review template — not ready for signature
Before signature, the AutoDeck owner and legal counsel must review this text, confirm the provider list, and complete every field in square brackets.
Version 0.1 — 8 September 2026
Controller: [Dealership legal name], registered at [Address], company/tax number [Number], represented by [Name and title] (the “Controller”).
Processor: [AutoDeck operator legal name], registered at [Address], company/tax number [Number], represented by [Name and title] (the “Processor”).
This agreement supplements the AutoDeck DMS services agreement (the “Main Agreement”). It prevails where the documents conflict on personal-data protection.
1. Subject matter, duration, nature and purpose
The Processor processes personal data solely to provide, secure, maintain and support AutoDeck DMS, including CRM, inventory, sales, documents, communications, reporting and the dealership public website. Processing lasts for the Main Agreement and the limited return, deletion or legally required retention period. Operations include collection through Controller-configured interfaces, organisation, storage, retrieval, authorised transmission, export, restriction, anonymisation and deletion.
2. Personal-data and data-subject categories
Data is limited to information entered or generated through the Controller’s configured use.
- Data: identity and contact details, addresses, fiscal or identity identifiers where required, preferences and consent records, CRM communications and notes, appointments, vehicle and transaction data, contractual/fiscal documents, billing data, user accounts and roles, access/security logs, device identifiers and IP addresses.
- Data subjects: dealership customers and prospects, contacts and representatives of corporate customers, dealership staff, contractors and users, and visitors to the dealership public website.
- Special-category or criminal-offence data must not be entered unless the Controller documents necessity, lawful basis and additional instructions.
3. Documented instructions and Controller obligations
The Processor acts only on documented Controller instructions, including for international transfers. The Main Agreement, authorised configuration and actions in the service, support tickets and agreed written directions are instructions. If Union or Romanian law requires other processing, the Processor informs the Controller first unless legally prohibited. The Processor promptly flags an instruction it believes infringes data-protection law and may suspend it pending clarification.
- The Controller determines purposes and lawful bases, provides notices, handles data-subject requests and sets lawful retention periods.
- The Controller grants access only to authorised users, protects credentials and does not request unlawful or disproportionate processing.
4. Confidentiality and access
Access is limited to authorised people who need it to provide the service and who are bound by statutory or contractual confidentiality. Access rights are role-based and removed when no longer needed; confidentiality survives termination.
5. Security of processing — GDPR Article 32
The Processor maintains risk-appropriate technical and organisational measures described in Annex 2 to protect confidentiality, integrity, availability and resilience, restore availability, and assess control effectiveness. The Controller applies the controls within its responsibility, including user administration, multi-factor authentication and secure endpoints.
6. Sub-processors and notice period
The Controller gives general written authorisation for Annex 1 sub-processors. The Processor gives at least 30 days’ written notice before adding or replacing a sub-processor that will process Controller data, allowing a reasoned data-protection objection. Equivalent relevant obligations are imposed by contract, and the Processor remains liable to the Controller for sub-processor performance. If a justified objection cannot reasonably be resolved, the parties limit the affected service or use termination rights under the Main Agreement.
7. Assistance with data-subject rights
Taking account of the processing, the Processor assists through product functions and reasonable measures with access, rectification, erasure, restriction, portability and objection requests. A request received directly is forwarded promptly; the Processor does not answer for the Controller without instruction or legal duty.
8. Assistance under Articles 32–36 and incidents
The Processor reasonably assists with processing security, breach notification, notices to data subjects, impact assessments and prior consultation. It notifies the Controller without undue delay after becoming aware of a breach affecting Controller data and supplies available details on nature, approximate categories/volumes, likely consequences, mitigation and a contact point. It documents the incident and cooperates with applicable deadlines.
9. Return, deletion and service termination
At the Controller’s choice after termination, the Processor returns data in an available export format or deletes it and its copies, except where Union or Romanian law requires retention. Annex 3 records the choice and operational period. Backup deletion follows the documented retention cycle; isolated copies are not used for another purpose. Fiscal, accounting or other legally held evidence is retained only for the required period with restricted access.
10. Information, audits and inspections
The Processor provides information needed to demonstrate Article 28 compliance and permits reasonable audits by the Controller or its independent auditor. Ordinarily, audits receive 30 days’ notice, occur during business hours, protect other customers and security, and have exceptional reasonable costs agreed in advance. These limits do not prevent an urgent post-incident or supervisory-authority audit.
11. International transfers
Romanian tenant operational data is hosted in the EU region. Any EEA export requires documented Controller instructions and a valid Articles 44–49 mechanism, such as adequacy, applicable Standard Contractual Clauses or Binding Corporate Rules, with supplementary measures where a transfer assessment requires them. Global email, SMS, payment or legacy-storage providers may involve international access or transfers; the owner must confirm active providers and safeguards before signature.
12. Governing law, authority and final terms
Romanian and applicable EU law govern this agreement. The Romanian supervisory authority is ANSPDCP, without limiting another authority’s competence under GDPR. Amendments must be written. If a provision is unenforceable, the remainder continues and the parties replace it with a lawful provision of equivalent purpose.
Annex 1 — Authorised sub-processors
| Provider | Service | Data / subjects | Location / transfer |
|---|---|---|---|
| Hetzner Online GmbH | Application, database and local storage hosting | Hosted data as applicable | Germany, EU |
| Plus Five Five, Inc. (Resend) | Transactional email | Names, email addresses and message content | United States; owner must confirm the transfer mechanism |
| Twilio Ireland Limited / Twilio Inc. | SMS, only when enabled | Phone number, content and delivery metadata | EU and US; confirm regional setup and safeguard |
| Meta Platforms Ireland Limited | WhatsApp Business, only when enabled | Phone number, content and delivery metadata | EEA and Meta global network; confirm safeguard |
| SmartBill / applicable contracting entity | Invoicing, only on dealership instruction and credentials | Billing, customer and transaction data | Romania/EEA; confirm the contractual role |
| Stripe Payments Europe, Limited and applicable Stripe entities | Subscription payment and billing | Payer representative, billing and transaction data; AutoDeck does not store card data | Ireland / Stripe global network under Stripe terms |
| UploadThing | Legacy document storage where unmigrated records remain | Documents and metadata, only if legacy records exist | Confirm location and safeguard before signature |
Annex 2 — Technical and organisational measures
- Tenant isolation: tenant models are scoped by tenant context and fail closed without it; system paths are separate and explicitly parameterised.
- Residency: Romanian tenants use the EU data region and its regional database; unprovisioned regions fail closed.
- Transport and backup protection: TLS in transit; backup archives are encrypted and authenticated by the application where the backup service is configured. The owner must confirm production configuration and scheduling before signature.
- Access control: authentication, optional multi-factor authentication, roles and permissions, revocable sessions and separated platform administration.
- Logging: tenant-scoped security, access, change and administrative audit records.
- Minimisation and retention: relevant log IPs are anonymised after 30 days; Romanian audit retention is configured for 7 years and legally held documents for 10 years. Other data follows Controller instructions and legal limits.
- Continuity and integrity: regional backups, document integrity checks and controlled restore processes; production operating evidence must be confirmed before signature.
- Incident response: log-led detection, containment, evidence preservation, risk assessment, notice without undue delay and cooperation with the Controller’s 72-hour duties.
- Review: security updates, automated isolation/control tests, access review and risk-proportionate remediation.
Annex 3 — Instructions and selections to complete
- Additional approved purposes or flows: [Description / not applicable].
- Additional data or subject categories: [Description / not applicable].
- At termination: [return then delete / delete directly] within [number] days, subject to legal holds.
- Controller instruction and incident contact: [Name, title, email, phone].
- AutoDeck privacy and incident contact: [Name/role, email, phone].
- Optional sub-processors active for this tenant: [SMS], [alternative email], [legacy storage], [others].
Signatures
- For the Controller: [Name, title, date, signature]
- For the Processor: [Name, title, date, signature]
