Data Processing Agreement

Article 28 GDPR · effective 18 September 2026

This Data Processing Agreement (“DPA”) is part of the Terms of Service between the UltraFeeds customer (“Controller”) and BS Management, VAT BG207472831, 19 Georgi Benev St., 6000 Stara Zagora, Bulgaria (“Processor”). It applies automatically when the Controller accepts the Terms.

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller to provide UltraFeeds: syncing product feeds to eBay, Shopify and Kaufland and showing the Controller's orders from these channels. The DPA lasts as long as the Controller uses UltraFeeds and ends with the deletion of the account.

2. Nature, purpose, data and data subjects

Data subjectsPersonal dataProcessing
Buyers of the Controller on eBay, Shopify and KauflandUsername or name, shipping address, phone number and e-mail address as provided by the channel, ordered items, amountsRetrieval from the channel, storage, display to the Controller
People named in the Controller's feeds (if any)Whatever the Controller includes in feed dataRetrieval, storage, transmission to the channel

3. Instructions

The Processor processes the data only on documented instructions of the Controller. The Terms, the Controller's settings in UltraFeeds (connecting channel accounts, feeds, syncs) and written requests are the instructions. If the Processor believes an instruction breaks data protection law, it informs the Controller.

4. Confidentiality

Persons authorised to process the data are bound to confidentiality.

5. Security (Article 32)

The Processor applies the measures in Annex 1 and keeps them up to date.

6. Sub-processors

The Controller authorises the sub-processors listed in Annex 2. The Processor informs the Controller by e-mail at least 30 days before adding or replacing a sub-processor that processes Controller data; the Controller may object on reasonable grounds and, if no solution is found, end the contract. The Processor imposes the same data protection obligations on each sub-processor and remains responsible for them.

7. International transfers

Controller data processed in UltraFeeds is stored in the EU (Frankfurt, Germany). Any transfer outside the EEA is made only under Chapter V GDPR safeguards (adequacy decision or Standard Contractual Clauses).

8. Assistance

The Processor helps the Controller, taking into account the nature of processing, to answer data subject requests, and with security, breach notification, data protection impact assessments and prior consultation (Articles 32–36). The Processor forwards requests it receives from data subjects to the Controller.

9. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting Controller data, with the information available at that time.

10. eBay account deletion notifications

When eBay notifies the Processor that an eBay user has deleted their eBay account, the Processor deletes or anonymises that user's personal data in UltraFeeds without further instruction, as the eBay API License Agreement requires. The Controller accepts this as an instruction.

11. Deletion and return

When the Controller disconnects a channel account or deletes its UltraFeeds account, the related personal data is deleted immediately. The Controller can export its orders from the channels at any time; on request before deletion the Processor provides stored order data in a machine-readable format.

12. Audits

The Processor makes available all information necessary to demonstrate compliance with Article 28 GDPR and allows audits by the Controller or an auditor it mandates, with reasonable notice and at the Controller's cost, not more than once a year unless a breach occurred.

Annex 1 — Technical and organisational measures

  • Hosting on a dedicated virtual server in an EU data centre (Frankfurt, Germany); firewall allowing only the web entry points.
  • TLS encryption for all connections to the service and to the channels.
  • Channel tokens and API keys and mailbox passwords encrypted at rest (AES-256-GCM, key stored separately from the database).
  • User passwords hashed with bcrypt; server-side sessions that end on password change or account disablement.
  • Strict separation of customers: every database query is limited to the signed-in customer.
  • Rate limiting of sign-in attempts; activity log of refusals and important actions.
  • Immediate deletion on disconnection or account deletion; processing of eBay account deletion notifications with verification of eBay's signature.
  • Access to production systems limited to authorised staff of the Processor.

Annex 2 — Sub-processors

Sub-processorServiceLocation
Hostinger International Ltd.Server hosting of the application and databaseFrankfurt, Germany (EU)

Controller data (buyer data in orders and feed data) is not sent to any other sub-processor.