Data Processing Agreement under Article 28 GDPR
Processor
Business name: e-Trading, s.r.o.
Registered office: Jelšová 4951/26, 949 01 Nitra, Slovak Republic
Company ID (IČO): 43 916 309
Tax ID (DIČ): 2022614913
Register: Commercial Register of the District Court Nitra, Section Sro, Insert No. 21920/N
Public contact: via the contact form on the Feedify website at /en/contact.
1. Parties and roles
1.1. This Data Processing Agreement ("DPA") is entered into between the Feedify Client as controller of personal data ("Client" or "Controller") and e-Trading, s.r.o. as the operator of Feedify and processor ("Feedify" or "Processor").
1.2. This DPA applies only to personal data that Feedify processes on behalf of the Client and in accordance with the Client's instructions when providing Feedify. It does not apply to data that Feedify processes for its own purposes as an independent controller (for example, its own account, billing, security and legal obligations); such processing is governed by the Feedify Privacy Policy.
1.3. The DPA forms part of the Feedify contractual framework. In the event of a conflict concerning the processing of data on behalf of the Client, the DPA takes precedence over a general provision of the Terms and Conditions.
2. Subject matter and duration of processing
2.1. The subject matter of the processing is the technical receipt, storage, review, preparation, product-level transformation and transfer to supported Portals of data contained in the Client's offer, together with related diagnostics, audit and support necessary to provide the service.
2.2. Processing continues for the period during which the relevant Feedify service is used and for the subsequent retention period required for reactivation, secure deletion, audit or compliance with legal obligations. Upon termination, data processed exclusively on behalf of the Client will be deleted or returned, depending on the capabilities of the service and the Client's instructions, unless retention is required by law.
3. Client instructions
3.1. Feedify processes personal data only on documented instructions from the Client arising from selected functions, Portal settings, the contract, this DPA or subsequent demonstrable communication.
3.2. If Feedify believes that an instruction infringes the GDPR or another data protection law, it will inform the Client without undue delay unless prohibited from doing so by law.
3.3. The Client is responsible for the lawfulness of its instructions, the legal basis for processing and for ensuring that it is entitled to place personal data in Feedify and distribute it to the selected Portals.
4. Confidentiality and authorized persons
4.1. Feedify will ensure that persons authorized to process personal data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
4.2. Access to personal data is limited to the extent necessary for operations, support, security and performance of this DPA.
5. Security of processing
5.1. Feedify implements appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, costs, nature and purposes of processing, and risks to data subjects.
5.2. Depending on what is appropriate, the measures include in particular protection of communications, access control, isolation of Client data, protection of login credentials and secret values, security logging, recovery mechanisms and operational incident response.
5.3. The detailed implementation of security measures is confidential and may evolve over time without reducing the appropriate level of protection.
6. Additional processors (subprocessors)
6.1. The Client grants Feedify general written authorization to engage additional processors required to provide the service.
6.2. Feedify will make up-to-date information about subprocessors available to the Client through contractual or accompanying documentation, within the authenticated area, or upon request. Feedify will ensure that a subprocessor assumes data protection obligations that are substantially equivalent to those under this DPA to the extent of its processing.
6.3. If Feedify intends to add or replace a subprocessor, it will inform the Client in an appropriate written manner so that the Client has an opportunity to object on data protection grounds within a reasonable period. The parties will seek a reasonable solution.
7. Portals as recipients of data
If the Client activates a Portal Service, the instruction to transfer data to the relevant Portal forms part of the provision of the service. A Portal generally does not act as a Feedify subprocessor, but as an independent recipient and, under its own terms, may act as an independent controller of personal data. The Client is responsible for having the authority to transfer the data to the relevant Portal.
8. Assistance with data subject rights
8.1. Taking into account the nature of the processing, Feedify will assist the Client through appropriate technical and organizational measures in fulfilling obligations relating to data subject requests under the GDPR where the request concerns data processed on behalf of the Client.
8.2. If Feedify receives such a request directly and can identify the relevant Client, it will generally forward the request to the Client and will not decide on it in place of the Client unless required otherwise by law.
9. Personal data breaches
9.1. If Feedify becomes aware of a personal data breach affecting data processed on behalf of the Client, it will notify the Client without undue delay after becoming reliably aware of it.
9.2. Based on the information available, the notification will include the nature of the incident, affected categories of data and data subjects, possible consequences, and measures taken or proposed. Information may be supplemented progressively.
9.3. Notification of an incident does not constitute an admission of fault or liability by Feedify.
10. DPIA, consultations and compliance assistance
10.1. Feedify will provide the Client with reasonable assistance in meeting obligations under Articles 32 to 36 GDPR to the extent that they relate to processing carried out by Feedify and the information is not otherwise available to the Client.
10.2. Extraordinary assistance beyond the ordinary service may be charged by agreement, unless it concerns remedying a breach of Feedify's obligations.
11. Audit and compliance information
11.1. Feedify will provide information reasonably necessary to demonstrate compliance with Article 28 GDPR and will permit a reasonable audit or inspection under conditions that protect security, confidentiality, other clients and Feedify know-how.
11.2. Existing documents, security information, records or remote review are preferred. A physical or extensive individual inspection must be agreed in advance and must not unreasonably disrupt operation of the service.
11.3. The Client bears the costs of an extraordinary audit unless the audit demonstrates a material breach of this DPA by Feedify.
12. Transfers outside the EU/EEA
Feedify will not arrange a transfer of personal data outside the EU/EEA without the legal mechanism required by the GDPR. If a relevant subprocessor involves such a transfer, Feedify will make information about the location and the appropriate mechanism available to the Client through contractual or accompanying documentation.
13. Termination and deletion
13.1. Upon termination of the service, Feedify will, in accordance with the Client's instructions and the capabilities of the product, delete or return in a reasonable format personal data processed exclusively on behalf of the Client, unless retention is required by law.
13.2. Data may remain for a limited period in operational backups or security/audit records if it is protected, is not used for a new purpose and is deleted according to the applicable retention cycle.
13.3. Feedify's own account, billing, tax and legal records are governed by the Privacy Policy and not by this provision of the DPA.
Annex A - description of processing
Subject matter
Processing of data contained in the Client's offer for the purpose of preparing, checking, distributing and regularly updating listings.
Nature of operations
receipt, storage, reading, checking, organization/preparation, transfer to selected Portals, diagnostics, deletion
Purpose
provision of Feedify in accordance with the Client's instructions
Data subjects
in particular the Client's contact persons, persons named in listings or offers, and any other persons whose data the Client lawfully includes in the source
Categories of data
in particular identification and contact data and data contained in an offer/listing; Feedify is not intended for systematic processing of special categories of data under Article 9 GDPR
Duration
for the duration of the service and the related retention/deletion lifecycle
Annex B - general technical and organizational measures
- encrypted communication and appropriate protection of data in transit,
- access control and authentication, including the option of two-factor authentication,
- separation and authorization of Client access,
- protection of secret values and login credentials using appropriate cryptographic mechanisms,
- operational, audit and security logging to an appropriate extent,
- monitoring, maintenance and an incident response process,
- appropriate backup/recovery and continuity measures according to the infrastructure used,
- regular assessment and updating of security measures according to risk.
DPA effective from: 10 September 2026.