This Data Processing Agreement ("DPA") forms part of the agreement between:
Controller:
The merchant, client, webshop owner or business entity using the services of SP Lite Platform B.V. ("Controller").
This DPA is concluded pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR").
Processor provides software infrastructure, fulfillment facilitation services, supplier coordination and operational tooling for e-commerce businesses.
Processor processes personal data solely on behalf of the Controller and only for purposes necessary to:
Processor acts solely as a facilitator and processor and does not independently determine the purposes or means of processing personal data.
Processing activities may include:
Processing is performed electronically through the Service Points Lite platform infrastructure and integrated fulfillment systems.
Processor may process the following categories of personal data:
No special categories of personal data are intentionally processed.
The processed personal data relates to:
Processor shall:
Controller represents and warrants that:
Processor implements appropriate technical and organizational measures, including but not limited to:
Further details are included in Annex II.
Controller grants Processor general authorization to engage subprocessors for operational, infrastructure, communication, analytics and fulfillment purposes.
A current list of subprocessors is included in Annex III.
Processor shall ensure that subprocessors are subject to data protection obligations substantially similar to those set forth in this DPA.
Processor shall remain responsible for the performance of its subprocessors under applicable law.
Certain processing activities may involve transfers of personal data outside the European Economic Area ("EEA"), including but not limited to:
Where personal data is transferred to countries not subject to an adequacy decision under GDPR, Processor shall ensure appropriate safeguards are implemented, including:
Chinese fulfillment suppliers engaged by Processor are contractually restricted to using personal data solely for fulfillment and shipping purposes and may not use such data for independent commercial purposes.
Processor shall notify Controller without undue delay after becoming aware of a confirmed personal data breach affecting Controller Data.
Such notification shall include, where reasonably available:
Controller may request reasonable information necessary to demonstrate compliance with this DPA.
Any audit or inspection:
The liability provisions contained in the master agreement between the parties shall apply equally to this DPA.
This DPA remains effective for the duration of the underlying services agreement between the parties.
This DPA shall be governed by Dutch law.
Any disputes arising under this DPA shall be submitted exclusively to the competent court in Oost-Brabant, the Netherlands.
Subject Matter:
Provision of fulfillment facilitation, supplier coordination, order synchronization and operational software infrastructure.
Duration:
For the duration of the services agreement and any applicable statutory retention periods.
Nature & Purpose:
Categories of Personal Data:
Categories of Data Subjects:
SP Lite Platform B.V. maintains commercially reasonable technical and organizational security measures, including:
Infrastructure Security:
Access Management:
Operational Security:
Data Minimization:
Chinese fulfillment suppliers receive only the minimum order-related personal data necessary to process shipments.
Suppliers are contractually prohibited from:
Where personal data is transferred outside the EEA, Processor shall implement appropriate safeguards in accordance with Chapter V GDPR.
Such safeguards may include:
Primary customer infrastructure is hosted within the European Union.
Certain supporting infrastructure and operational services may process limited data outside the EEA where necessary for platform functionality, communications, analytics, fraud prevention, payment processing or fulfillment operations.
Processor implements commercially reasonable measures to ensure that any international transfer is proportionate, limited and protected.
SP Platform B.V.
Emmasingel 33
5611 AZ Eindhoven
The Netherlands
KvK: 86013394
Privacy inquiries: info@servicepoints.eu
Website: https://www.servicepoints.eu