AutoDeck DMS

Data Processing Agreement

Template agreement under Article 28 of Regulation (EU) 2016/679

Template agreement

This agreement forms an integral part of the AutoDeck Terms and is concluded when the Customer accepts the Terms. The platform records who accepted, when, from which IP address, and the versions of the Terms and of this agreement accepted.

Version 1.1 — 26 September 2026

Controller: the Customer that accepts the AutoDeck Terms, identified by the company details in its account (the “Controller”).

Processor: AutoDeck.ro, private individual resident in Romania (the “Processor”).

This agreement supplements the AutoDeck Terms of Service; together they form the contract for AutoDeck DMS services (the “Main Agreement”). It prevails where the documents conflict on personal-data protection.

1. Subject matter, duration, nature and purpose

The Processor processes personal data on the Controller’s behalf solely to provide, secure, maintain and support AutoDeck DMS: CRM, inventory, sales, documents, communications, reporting and the dealership public website.

Processing starts at service activation and lasts for the Main Agreement plus the return and deletion period in Annex 3. Operations include collection through the interface provided to the Controller, storage, retrieval, transmission to authorised destinations, export, restriction and deletion.

2. Personal-data and data-subject categories

The data processed is the data entered or generated through the Controller’s configured use.

  • Data: names, contact details, addresses, preferences and consent records, CRM communications and notes, appointments, vehicle and transaction data, contractual and fiscal documents, user accounts, roles, access logs and IP addresses.
  • The personal numeric code (CNP) and identity-document data are processed only where a legal obligation of the Controller requires them, for example the vehicle transfer contract and registration or anti-money-laundering checks, on the basis of GDPR Art. 6(1)(c) and Article 4 of Romanian Law 190/2018.
  • Data subjects: dealership customers and prospects, representatives of corporate customers, dealership staff, contractors and users, and visitors to the dealership public website.
  • Special-category or criminal-offence data is not entered unless the Controller documents necessity, lawful basis and additional instructions.

3. Documented instructions and Controller obligations

The Processor processes the data only on documented Controller instructions, including for international transfers. The Main Agreement, authorised configuration and actions in the platform, and agreed written directions are documented instructions.

If Union or Romanian law requires other processing, the Processor informs the Controller first unless the law prohibits it. If an instruction appears to infringe data-protection law, the Processor informs the Controller immediately and may suspend it pending clarification.

  • The Controller determines purposes and lawful bases, informs data subjects, answers their requests and sets retention periods.
  • The Controller gives access only to authorised users and keeps credentials confidential.

4. Confidentiality and access

The Processor gives access to the data only to people who need it for the service and who are bound by confidentiality, which continues after their access ends.

5. Security of processing — GDPR Article 32

The Processor applies the technical and organisational measures in Annex 2. The Controller applies the measures within its control, including user administration and multi-factor authentication.

6. Sub-processors and notice period

The Controller gives general written authorisation for the sub-processors in Annex 1A. The Processor gives at least 30 days’ written notice before adding or replacing a sub-processor, and the Controller may raise a reasoned objection.

Each sub-processor is bound by contract to equivalent data-protection obligations, and the Processor remains liable to the Controller for their performance. If a justified objection cannot be resolved, the Controller may terminate the Main Agreement.

7. Assistance with data-subject rights

The Processor helps the Controller, through platform functions and reasonable measures, to answer requests for access, rectification, erasure, restriction, portability and objection. A request received directly is forwarded to the Controller without delay.

8. Assistance under Articles 32–36 and incidents

The Processor assists the Controller with security of processing, breach notification, informing data subjects, impact assessments and prior consultation.

The Processor notifies the Controller of any breach affecting the Controller’s data without undue delay after becoming aware of it, with the nature of the incident, approximate categories and volumes, likely consequences, measures taken and a contact point, so that the Controller can notify the authority within 72 hours.

9. Return, deletion and service termination

After the service ends, the Processor returns or deletes the data as set out in Annex 3, except data that Union or Romanian law requires it to keep. Backups expire as set out in Annex 3 and are not used for any other purpose meanwhile.

10. Information, audits and inspections

The Processor provides the information needed to demonstrate compliance with Article 28 and allows audits, including inspections, by the Controller or an auditor it mandates. Audits are ordinarily announced 30 days in advance and must not compromise other customers’ data; this does not prevent an urgent audit after an incident or at the authority’s request.

11. International transfers

The Controller’s data, files and backups stay in the deployment of its account’s region, hosted in Germany (EU). An international transfer takes place only on documented Controller instructions and with a valid mechanism under GDPR Articles 44–49. Annex 1 states the location and basis of each transfer; Standard Contractual Clauses are those adopted by the European Commission.

12. Governing law, authority and final terms

Romanian and applicable EU law govern this agreement. The competent supervisory authority in Romania is ANSPDCP. Amendments are valid only in writing.

Annex 1A — Authorised sub-processors

ProviderServiceLocationTransfer basis
Hetzner Online GmbHHosting of the application, databases, files and backups for the account’s regionGermany (EU)Not applicable
Functional Software, Inc. (Sentry)Error monitoring; email, IP address and user identifier are removed before sendingEU (Sentry’s EU data region)Standard Contractual Clauses, for access from the US
Plus Five Five, Inc. (Resend)Email sent by the platform when the Controller has not configured its own email serviceUnited StatesStandard Contractual Clauses
Ping Labs, Inc. (UploadThing)Storage of older documents not yet moved to the region’s storageUnited StatesStandard Contractual Clauses

Annex 1B — Destinations chosen by the Controller

The Controller activates these services with its own account; they receive data only once activated and are the Controller’s providers, not sub-processors.

ProviderServiceLocationTransfer basis
Google (Google Drive)Backup copy of the Controller’s dataPer the Controller’s accountThe Controller’s contract with the provider
Apple (iCloud Drive)Backup copy of the Controller’s dataPer the Controller’s accountThe Controller’s contract with the provider
OLX and Autovit.roPublishing vehicle listingsPer the Controller’s accountThe Controller’s contract with the provider
SmartBillIssuing invoicesPer the Controller’s accountThe Controller’s contract with the provider
Twilio, Vonage or another SMS providerSending SMSPer the Controller’s accountThe Controller’s contract with the provider
Meta (WhatsApp Business)WhatsApp messagesPer the Controller’s accountThe Controller’s contract with the provider
Gmail, Outlook, Resend or the Controller’s SMTP serverSending emailPer the Controller’s accountThe Controller’s contract with the provider

Annex 2 — Technical and organisational measures

  1. Isolation: each dealership’s data is scoped to that dealership, and missing authorised context blocks access.
  2. Encryption: TLS in transit; daily backups are encrypted and authenticated.
  3. Access: authentication, available multi-factor authentication, roles and permissions, revocable sessions; new passwords are checked against the Have I Been Pwned list of compromised passwords, which receives only the start of the password’s cryptographic hash.
  4. Logs: security, access and audit logs for relevant actions.
  5. Incidents: containment, evidence preservation, risk assessment and notice to the Controller under section 8.

Annex 3 — Instructions

  1. Additional purposes, flows or data categories: only those the parties agree in writing.
  2. On termination: on the Controller’s written request made within 30 days of termination, the Processor returns the data by export. On the Controller’s written request, the Processor then deletes the data within 30 days of the request.
  3. Backups containing the data expire 30 days after they are created.
  4. The destinations in Annex 1B are active only if the Controller configures them in the platform.
  5. Controller contact point: ______________________ (name, title, email, phone).
  6. Processor contact point: contact@autodeck.ro.

Conclusion of the agreement

  1. The agreement is concluded in electronic form (GDPR Art. 28(9)) when the Customer accepts the Terms.
    Data Processing Agreement | AutoDeck | AutoDeck