AutoDeck DMS
Data Processing Agreement
Template agreement under Article 28 of Regulation (EU) 2016/679
Template agreement
This agreement forms an integral part of the AutoDeck Terms and is concluded when the Customer accepts the Terms. The platform records who accepted, when, from which IP address, and the versions of the Terms and of this agreement accepted.
Version 1.1 — 26 September 2026
Controller: the Customer that accepts the AutoDeck Terms, identified by the company details in its account (the “Controller”).
Processor: AutoDeck.ro, private individual resident in Romania (the “Processor”).
This agreement supplements the AutoDeck Terms of Service; together they form the contract for AutoDeck DMS services (the “Main Agreement”). It prevails where the documents conflict on personal-data protection.
1. Subject matter, duration, nature and purpose
The Processor processes personal data on the Controller’s behalf solely to provide, secure, maintain and support AutoDeck DMS: CRM, inventory, sales, documents, communications, reporting and the dealership public website.
Processing starts at service activation and lasts for the Main Agreement plus the return and deletion period in Annex 3. Operations include collection through the interface provided to the Controller, storage, retrieval, transmission to authorised destinations, export, restriction and deletion.
2. Personal-data and data-subject categories
The data processed is the data entered or generated through the Controller’s configured use.
- Data: names, contact details, addresses, preferences and consent records, CRM communications and notes, appointments, vehicle and transaction data, contractual and fiscal documents, user accounts, roles, access logs and IP addresses.
- The personal numeric code (CNP) and identity-document data are processed only where a legal obligation of the Controller requires them, for example the vehicle transfer contract and registration or anti-money-laundering checks, on the basis of GDPR Art. 6(1)(c) and Article 4 of Romanian Law 190/2018.
- Data subjects: dealership customers and prospects, representatives of corporate customers, dealership staff, contractors and users, and visitors to the dealership public website.
- Special-category or criminal-offence data is not entered unless the Controller documents necessity, lawful basis and additional instructions.
3. Documented instructions and Controller obligations
The Processor processes the data only on documented Controller instructions, including for international transfers. The Main Agreement, authorised configuration and actions in the platform, and agreed written directions are documented instructions.
If Union or Romanian law requires other processing, the Processor informs the Controller first unless the law prohibits it. If an instruction appears to infringe data-protection law, the Processor informs the Controller immediately and may suspend it pending clarification.
- The Controller determines purposes and lawful bases, informs data subjects, answers their requests and sets retention periods.
- The Controller gives access only to authorised users and keeps credentials confidential.
4. Confidentiality and access
The Processor gives access to the data only to people who need it for the service and who are bound by confidentiality, which continues after their access ends.
5. Security of processing — GDPR Article 32
The Processor applies the technical and organisational measures in Annex 2. The Controller applies the measures within its control, including user administration and multi-factor authentication.
6. Sub-processors and notice period
The Controller gives general written authorisation for the sub-processors in Annex 1A. The Processor gives at least 30 days’ written notice before adding or replacing a sub-processor, and the Controller may raise a reasoned objection.
Each sub-processor is bound by contract to equivalent data-protection obligations, and the Processor remains liable to the Controller for their performance. If a justified objection cannot be resolved, the Controller may terminate the Main Agreement.
7. Assistance with data-subject rights
The Processor helps the Controller, through platform functions and reasonable measures, to answer requests for access, rectification, erasure, restriction, portability and objection. A request received directly is forwarded to the Controller without delay.
8. Assistance under Articles 32–36 and incidents
The Processor assists the Controller with security of processing, breach notification, informing data subjects, impact assessments and prior consultation.
The Processor notifies the Controller of any breach affecting the Controller’s data without undue delay after becoming aware of it, with the nature of the incident, approximate categories and volumes, likely consequences, measures taken and a contact point, so that the Controller can notify the authority within 72 hours.
9. Return, deletion and service termination
After the service ends, the Processor returns or deletes the data as set out in Annex 3, except data that Union or Romanian law requires it to keep. Backups expire as set out in Annex 3 and are not used for any other purpose meanwhile.
10. Information, audits and inspections
The Processor provides the information needed to demonstrate compliance with Article 28 and allows audits, including inspections, by the Controller or an auditor it mandates. Audits are ordinarily announced 30 days in advance and must not compromise other customers’ data; this does not prevent an urgent audit after an incident or at the authority’s request.
11. International transfers
The Controller’s data, files and backups stay in the deployment of its account’s region, hosted in Germany (EU). An international transfer takes place only on documented Controller instructions and with a valid mechanism under GDPR Articles 44–49. Annex 1 states the location and basis of each transfer; Standard Contractual Clauses are those adopted by the European Commission.
12. Governing law, authority and final terms
Romanian and applicable EU law govern this agreement. The competent supervisory authority in Romania is ANSPDCP. Amendments are valid only in writing.
Annex 1A — Authorised sub-processors
| Provider | Service | Location | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the application, databases, files and backups for the account’s region | Germany (EU) | Not applicable |
| Functional Software, Inc. (Sentry) | Error monitoring; email, IP address and user identifier are removed before sending | EU (Sentry’s EU data region) | Standard Contractual Clauses, for access from the US |
| Plus Five Five, Inc. (Resend) | Email sent by the platform when the Controller has not configured its own email service | United States | Standard Contractual Clauses |
| Ping Labs, Inc. (UploadThing) | Storage of older documents not yet moved to the region’s storage | United States | Standard Contractual Clauses |
Annex 1B — Destinations chosen by the Controller
The Controller activates these services with its own account; they receive data only once activated and are the Controller’s providers, not sub-processors.
| Provider | Service | Location | Transfer basis |
|---|---|---|---|
| Google (Google Drive) | Backup copy of the Controller’s data | Per the Controller’s account | The Controller’s contract with the provider |
| Apple (iCloud Drive) | Backup copy of the Controller’s data | Per the Controller’s account | The Controller’s contract with the provider |
| OLX and Autovit.ro | Publishing vehicle listings | Per the Controller’s account | The Controller’s contract with the provider |
| SmartBill | Issuing invoices | Per the Controller’s account | The Controller’s contract with the provider |
| Twilio, Vonage or another SMS provider | Sending SMS | Per the Controller’s account | The Controller’s contract with the provider |
| Meta (WhatsApp Business) | WhatsApp messages | Per the Controller’s account | The Controller’s contract with the provider |
| Gmail, Outlook, Resend or the Controller’s SMTP server | Sending email | Per the Controller’s account | The Controller’s contract with the provider |
Annex 2 — Technical and organisational measures
- Isolation: each dealership’s data is scoped to that dealership, and missing authorised context blocks access.
- Encryption: TLS in transit; daily backups are encrypted and authenticated.
- Access: authentication, available multi-factor authentication, roles and permissions, revocable sessions; new passwords are checked against the Have I Been Pwned list of compromised passwords, which receives only the start of the password’s cryptographic hash.
- Logs: security, access and audit logs for relevant actions.
- Incidents: containment, evidence preservation, risk assessment and notice to the Controller under section 8.
Annex 3 — Instructions
- Additional purposes, flows or data categories: only those the parties agree in writing.
- On termination: on the Controller’s written request made within 30 days of termination, the Processor returns the data by export. On the Controller’s written request, the Processor then deletes the data within 30 days of the request.
- Backups containing the data expire 30 days after they are created.
- The destinations in Annex 1B are active only if the Controller configures them in the platform.
- Controller contact point: ______________________ (name, title, email, phone).
- Processor contact point: contact@autodeck.ro.
Conclusion of the agreement
- The agreement is concluded in electronic form (GDPR Art. 28(9)) when the Customer accepts the Terms.