Effective date: ‹effective_date›
1. Background and Roles
This Data Processing Addendum (the "DPA") forms part of the Terms of Use between:
‹controller_name›, ‹registered_address›, contact: ‹contact_email› (the "Platform", "we"), operator of the WAW365 B2B auto-parts marketplace at waw365.com; and
the business user of the Platform (a supplier or a buyer organisation) that enters personal data of other people into the Platform (the "Customer", "you").
Data-protection contact: ‹contact_email› or the contact form at /contact (topic "Data-protection request").
Conditional section — shown only when this is set: ‹dpo_email›
Data Protection Officer: ‹dpo_name›, ‹dpo_email›.
1.1 When this DPA applies. For most processing on the Platform — your own account, security logs, catalogue publication, analytics — the Platform is an independent controller, and that processing is described in our Privacy Policy, not here. This DPA applies only where the Platform processes personal data on your behalf and under your instructions as a processor within the meaning of Article 28 GDPR, namely personal data of third parties that you enter into, or upload to, the Platform ("Customer Personal Data"). Typical examples:
- client records you keep in the built-in CRM;
- contact details of delivery recipients and other contacts you enter into orders, requests and deal threads;
- personal data of your own staff that you add as members of your organisation or that appears in files you upload (e.g. contact rows in price lists);
- files and photos that buyers attach to requests, orders and messages.
1.2 Roles. In respect of Customer Personal Data, you are the controller (or a processor acting for another controller, in which case you warrant that your instructions to us are covered by that controller's authorisation), and the Platform is your processor. In respect of the platform accounts of your staff members (credentials, sessions, security logs), the Platform remains an independent controller as described in the Privacy Policy; this DPA covers the membership and role data you manage for your organisation.
1.3 Acceptance. This DPA is accepted together with the Terms of Use and applies automatically whenever you use Platform features that involve Customer Personal Data. No signature is required; a countersigned copy is available on request via ‹contact_email›.
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"). "Sub-processor" means a third party engaged by the Platform to process Customer Personal Data on your behalf.
3. Subject Matter and Duration
3.1 Subject matter. The processing of Customer Personal Data necessary to provide the Platform services described in the Terms of Use: CRM, order and request management, deal threads and messaging, organisation membership management, price-list ingestion, and file storage.
3.2 Duration. This DPA applies for as long as your account exists and the Platform holds Customer Personal Data, and until that data is deleted or anonymised in accordance with Section 13.
4. Nature and Purpose of Processing
The Platform processes Customer Personal Data by hosting, storing, structuring, displaying back to you and your authorised members, transmitting between transaction counterparties, backing up, and deleting it — solely to operate the marketplace features you use. Specifically:
- CRM: storing and displaying the client profiles you create (names, phone numbers, free-text notes, tags) to you and your organisation members;
- Orders, requests and deal threads: storing delivery-recipient details and other contact data you enter, and making them available to your transaction counterparty to the extent needed to fulfil the transaction;
- Messaging: storing and delivering messages and attachments exchanged in deal threads;
- Organisation management: maintaining the member list, roles and invitations of your organisation;
- Price-list ingestion: parsing files you upload to extract catalogue data (such files sometimes contain contact details of your staff). Parsing is performed by the Platform's own parsers on the Platform's own servers (Hetzner, Germany, EEA); no third party receives the files or the parsing results;
- File storage: storing photos and documents attached to requests, orders and messages.
The Platform does not use Customer Personal Data for its own purposes, does not sell it, and does not use it for advertising or profiling. No money for orders passes through the Platform: buyers pay suppliers directly, and the Platform does not process payment-card data.
AI processing. The Platform uses external AI services only for catalogue content (part descriptions, category texts, translations, generated category images), working from catalogue data. Customer Personal Data is not sent to AI providers, and Customer Personal Data is not used to train any model.
5. Categories of Data Subjects and Personal Data
5.1 Data subjects:
- your clients and prospective clients (persons recorded in your CRM);
- delivery recipients and contact persons named in orders, requests and deal threads (who may be third parties who are not Platform users);
- your employees and other members of your organisation;
- employees or representatives of your business whose contact details appear in uploaded files (e.g. price lists);
- buyers' contacts appearing in files or photos attached to requests and messages.
5.2 Categories of personal data:
- identification and contact data: names, phone numbers, email addresses, delivery addresses;
- free-text content you enter: CRM notes, tags, order and delivery notes, request descriptions, messages;
- role and membership data of organisation members (role, invitation email, activity within your organisation);
- vehicle identifiers (VIN, registration plate) you enter into requests or orders, where they can be linked to an identifiable vehicle owner;
- content of uploaded files and photos to the extent they contain personal data (e.g. a phone number in a price-list header, a person visible in a photo).
5.3 Special categories. The Platform services are not designed for, and you must not upload, special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). Uploaded photos are automatically stripped of EXIF metadata (including embedded GPS coordinates).
6. Instructions
6.1 The Platform processes Customer Personal Data only on your documented instructions, including with regard to transfers to third countries, unless required to do otherwise by Union or Member State law applicable to the Platform; in that case the Platform will inform you of that legal requirement before processing, unless the law prohibits it (Article 28(3)(a) GDPR).
6.2 Your instructions are given through your use of the Platform: creating, editing, sharing and deleting records via the interfaces and APIs constitutes a documented instruction to process the data accordingly. The Terms of Use and this DPA together are your complete initial instructions.
6.3 The Platform will inform you if, in its opinion, an instruction infringes the GDPR or other applicable data protection law (Article 28(3) final sentence).
7. Confidentiality
The Platform ensures that persons authorised to process Customer Personal Data (staff and contractors) are bound by contractual or statutory confidentiality obligations (Article 28(3)(b) GDPR). Access to production data is restricted by role-based access control to persons who need it to operate the service.
8. Security Measures (Article 32 GDPR)
Taking into account the state of the art, costs, and the nature, scope, context and purposes of processing, the Platform implements the following technical and organisational measures. The Privacy Policy contains further detail; this list reflects measures actually in operation:
- Encryption in transit. All traffic is served over TLS; HTTP is redirected to HTTPS; HSTS is enforced with a two-year policy including subdomains and preload.
- Credential protection. Passwords are stored only as salted PBKDF2-SHA256 hashes; API keys and device identifiers are stored only as hashes; plaintext credentials are never stored.
- Secret encryption. Application secrets held in the database (two-factor seeds, integration API keys) are encrypted with symmetric encryption (Fernet) with key-rotation support.
- Access control. Role-based access control across the Platform; organisation-level roles restrict what your members can see; administrative surfaces are separated from user surfaces.
- Session security. A per-device session registry with self-service remote revocation of any or all sessions; all other sessions are revoked automatically on password change and on account deletion.
- Two-factor authentication. TOTP-based 2FA with one-time recovery codes is available for accounts.
- Abuse protection. Global API rate limiting; login lockout after repeated failed attempts; throttling of registration, password reset and data-export endpoints.
- Upload hygiene. EXIF/GPS metadata is stripped from uploaded photos; data exports are protected against CSV-injection.
- Export protection. Personal-data export archives are stored in a dedicated storage bucket, downloadable only through the authenticated backend (no public links), with ownership checks, and expire automatically after 7 days.
- Backups and availability. Nightly database and media backups with a short rotation cycle (three most recent copies) plus an off-site replica within the EEA (Hetzner Storage Box, SFTP), supporting restoration of availability after an incident (Article 32(1)(c)).
- Operational monitoring. Automated health monitoring and failure alerting for the production stack; destructive data operations (account/data deletion, exports) are logged.
The Platform keeps its measures under review and will not materially degrade the overall level of security during the term of this DPA.
9. Sub-processors
9.1 General authorisation. You give general written authorisation (Article 28(2) GDPR) for the engagement of the sub-processors listed below. The Platform will inform you of intended additions or replacements — by notice on the Platform or by email — giving you the opportunity to object on reasonable data-protection grounds before the change takes effect. If an objection cannot be resolved, you may terminate your account under Section 13.
9.2 Current sub-processors for Customer Personal Data:
| Sub-processor | Role | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of all production infrastructure (application, databases, object storage, price-list parsing) on a dedicated server | Germany (EEA) | Not required (EEA) |
| Hetzner Online GmbH — Storage Box | Off-site backup storage (nightly encrypted-transport SFTP replica) | Germany/Finland (EEA) | Not required (EEA) |
| Cloudflare, Inc. | Reverse proxy, CDN and DDoS protection for all Platform traffic; TLS is terminated at Cloudflare's edge, so data in transit (including form content) transits Cloudflare's network | USA / global network | Cloudflare's data processing terms incorporating the EU Standard Contractual Clauses; EU–US Data Privacy Framework to the extent Cloudflare is certified |
| Browser push services (Google, Mozilla, Apple) | Delivery of web-push notifications to members who have opted in. Payloads are end-to-end encrypted (RFC 8291): the push services see only the delivery endpoint and metadata, never message content | USA / global | Encrypted payload; only routing metadata is exposed |
9.3 Not sub-processors. The following are part of the Platform's own self-hosted stack on the Hetzner infrastructure and are not third parties: PostgreSQL, ClickHouse, Redis, Manticore search, MinIO object storage, the Platform's own document and price-list parsers, and the Mailu mail server (mail.waw365.com — transactional email is sent from our own server, without an external email service provider; the recipient's own mailbox provider necessarily receives the content of emails addressed to it). No external document-parsing service is used.
9.4 AI providers. The Platform's AI providers (Abacus.AI and an AI translation gateway, used for catalogue content) receive only catalogue data — never Customer Personal Data — and are therefore not sub-processors under this DPA. The Platform commits not to route Customer Personal Data (CRM records, messages, uploaded files) through AI providers without first updating this DPA and the sub-processor list.
9.5 Operational alerting. Internal operational alerts delivered via the Telegram Bot API contain only technical data and numeric identifiers; they do not contain names, email addresses or other Customer Personal Data.
9.6 Sub-processor obligations. The Platform imposes on each sub-processor, by way of contract, data-protection obligations providing at least the same level of protection as this DPA, and remains fully liable to you for the performance of each sub-processor's obligations (Article 28(4) GDPR).
10. International Transfers
Customer Personal Data is stored and processed at rest exclusively within the EEA (Hetzner, Germany, with EEA off-site backups). The only routine third-country exposure is transit through Cloudflare's global network (Section 9.2), safeguarded as described there. The Platform does not transfer Customer Personal Data to Ukraine; where your own counterparty is located in Ukraine (or another third country), the counterparty's access to the transaction data you choose to share with it takes place at your instruction and for the performance of your contract with that counterparty. The Platform will not otherwise transfer Customer Personal Data outside the EEA without ensuring an Article 44–49 GDPR transfer mechanism and updating this DPA.
11. Assistance with Data Subject Rights
11.1 Taking into account the nature of the processing, the Platform assists you, by appropriate technical and organisational measures, in fulfilling your obligation to respond to data subjects' requests under Chapter III GDPR (Article 28(3)(e)).
11.2 Self-service first. You can handle most requests yourself, without our involvement:
- Access / rectification / erasure of CRM records: you create, edit and delete CRM client profiles, notes and tags directly in the CRM interface; changes take effect immediately in the live system.
- Orders, requests, threads: contact details you entered can be reviewed in the respective records; message threads preserve the transaction history.
- Organisation members: you add, change roles of, and remove members in the organisation settings.
- Export: the built-in data export produces a machine-readable archive of your account data (rate-limited to one request per 24 hours; download links expire after 7 days).
11.3 If a data subject contacts the Platform directly about data for which you are the controller, the Platform will (to the extent legally permitted) forward the request to you without undue delay and will not respond on the merits without your instruction, except to direct the person to you.
11.4 For requests that cannot be completed via self-service (for example, erasure of data embedded in counterparty-shared records), contact ‹contact_email› or use the contact form at /contact; the Platform will provide reasonable assistance.
11.5 DPIA assistance. The Platform will provide reasonable assistance with data protection impact assessments and prior consultations (Articles 35–36) relating to processing under this DPA, primarily by making available the information in this DPA and the Privacy Policy (Article 28(3)(f)).
12. Personal Data Breach Notification
12.1 The Platform will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data ⚠ owner/counsel — commit to a fixed maximum, e.g. 48 hours.
12.2 The notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available.
12.3 The Platform will document breaches and reasonably cooperate with your own notification obligations under Articles 33–34 GDPR. Notification to your supervisory authority and to data subjects is your responsibility as controller.
13. Return and Deletion of Data
13.1 During the term. You can delete individual records (CRM profiles, members, files) at any time through the Platform interfaces; deletion via the interface is your instruction to erase that data from the live system.
13.2 Account closure by you. You can close your account yourself (password-confirmed self-service deletion) or by written request to ‹contact_email›. On account deletion the Platform, in a single transaction: deletes your operational data sets (including price sources, warehouses, uploads, mapping rules, invitations and analytics rows), anonymises the account and profile records, and revokes all active sessions.
13.3 Account closure by the Platform. Where the Platform closes your account under the Terms of Use, it gives at least 30 days' prior notice (except in the cases of immediate closure listed in the Terms of Use), you may export your data before closure, and Customer Personal Data is deleted or anonymised no later than 90 days after closure, subject to Section 13.5.
13.4 Export before deletion. Use the built-in data export (Section 11.2) before closing the account; export archives themselves expire after 7 days.
13.5 What is retained. The following survive account deletion, as permitted by Article 28(3)(g) GDPR in conjunction with Union/Member State law:
- transaction records (orders and related fiscal data) — retained for 5 years from the end of the calendar year in which they were created, to comply with accounting, tax and audit obligations, and for the establishment, exercise or defence of legal claims (Article 17(3)(b) and (e) GDPR);
- deal threads and messages — these are records shared with your transaction counterparty, who has an independent right to retain their copy of the correspondence; your identity in them is anonymised to the extent it is not part of the counterparty's transaction record;
- consent and legal-evidence records — retained for the life of the account plus 3 years, as evidence of consent and contract acceptance.
13.6 Backups. Deleted data ceases to be restorable through normal operations immediately, and disappears from backup media through the short rotation cycle described in Section 8 (a limited number of recent nightly copies), after which it is unrecoverable.
14. Audit and Information
14.1 The Platform will make available to you all information necessary to demonstrate compliance with Article 28 GDPR — starting with this DPA, the Privacy Policy and the sub-processor list — and will answer reasonable written audit questionnaires within a reasonable period (Article 28(3)(h)).
14.2 Where the information provided is insufficient to demonstrate compliance, you (or an independent auditor mandated by you and bound by confidentiality) may conduct an audit, subject to: at least 30 days' written notice, at most once per 12 months (except after a personal data breach affecting your data or where required by a supervisory authority), during business hours, without access to other customers' data, and at your cost. Audits of physical data-centre infrastructure are satisfied by the hosting provider's own certifications and audit reports.
15. Your Obligations as Controller
You warrant and undertake that:
- you have a lawful basis (Article 6 GDPR) for every category of Customer Personal Data you enter into the Platform, including CRM records about your clients and contact details of delivery recipients who are third parties;
- you provide data subjects with the information required by Articles 13–14 GDPR regarding your use of the Platform as your processor;
- you do not upload special-category data, criminal-offence data, or data of persons under 18, and you keep the data you enter accurate and up to date;
- where you act as a processor for another controller, your instructions to the Platform are authorised by that controller;
- you use the available security features appropriately (member roles, session management, two-factor authentication) and keep your credentials confidential.
The Platform is not responsible for the lawfulness of your collection of Customer Personal Data outside the Platform.
16. Liability and Precedence
16.1 The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Use (Section 16 — cap equal to the Operator Fees paid in the preceding 12 months, with no limitation for wilful misconduct, gross negligence or where mandatory law forbids it). Nothing in this DPA limits the rights of data subjects under Article 82 GDPR.
16.2 In case of conflict between this DPA and the Terms of Use regarding the processing of Customer Personal Data, this DPA prevails. Nothing in this DPA limits either party's obligations under the GDPR itself.
17. Governing Law and Jurisdiction
This DPA is governed by the laws of Poland and is subject to the same jurisdiction and dispute-resolution provisions as the Terms of Use (Section 19). Mandatory data protection law (GDPR; for Ukrainian data subjects, the Law of Ukraine "On Personal Data Protection") applies regardless of the chosen law.
18. Changes to This DPA; Language
The Platform may update this DPA to reflect changes in the services, sub-processors or the law. Material changes — in particular changes to the sub-processor list — will be notified in advance as described in Section 9.1 and, for other material changes, in accordance with the notice periods of the Terms of Use (Section 22). The version in force is identified by the Effective Date above; previous versions are available on request.
This DPA is drawn up in English; translations are provided for convenience. In case of any inconsistency, the English version prevails.
Questions about this DPA: ‹contact_email› or the contact form at /contact. Complaints may also be addressed to ‹supervisory_authority›.