FurtherSales
FurtherSales
|

Data Processing Agreement (DPA)

Data Processing Agreement (DPA Framework)

For the operation of the FurtherSales auction solution, we process personal data on behalf of our customers, for example from bidders or users of the platform. To govern this processing, we conclude a Data Processing Agreement framework (DPA) with our customers in accordance with Art. 28 GDPR.

1. Subject Matter and Scope of Processing

The DPA governs in particular the processing of personal data on behalf of the customer, the use of our technical infrastructure, the obligations of FurtherSales as a processor, the duties of the customer as controller, and technical and organisational measures (TOMs).

2. Categories of Data Subjects and Data Categories

Data subjects: platform users, bidders, customer employees.

Data categories: master data, contact data, bid data, transaction data and log data.

3. Technical and Organisational Measures (TOMs)

We undertake to maintain appropriate technical and organisational measures pursuant to Art. 32 GDPR in order to ensure a level of security appropriate to the risk for data processed on behalf of customers. These measures include safeguards in the following areas:

• Physical and logical access control: securing systems and server infrastructures against unauthorised physical and logical access, for example through secured administrative access and modern IT infrastructures.

• Access rights control: authorised use of data only within established permission concepts and system-side logging of relevant system events.

• Transfer control: encryption of data transmissions over the network, for example through modern transport encryption such as HTTPS/TLS.

• Availability and resilience: measures for timely restoration of systems and data structures, for example through backup procedures and redundant storage.