Data processing agreement
pursuant to Art. 28(3) GDPR
between the user of Resellize as controller and
Mathias Jehle Schubertweg 9/1 8141 Premstätten Austria Email: support@resellize.com
as processor.
This agreement is concluded by accepting the general terms and conditions at registration. It applies in addition to them and, on questions of processing on a controller's behalf, takes precedence over them in the event of any conflict.
1. When this agreement applies
The processor processes data in two separate roles:
As its own controller for all data needed to operate the customer account, to bill for the service and to run the website. This agreement does not apply to that processing; the privacy notice does.
As a processor for personal data of third parties that the user brings into the tool in the course of their own sales activity. For that data the user is the controller. This agreement relates to that data alone.
2. Subject matter, nature and purpose of the processing
The subject matter is the provision of the software available at resellize.com as a service.
Nature of the processing: collection, recording, storage, retrieval, use, transfer to the sub-processors named in point 7, and erasure.
Purpose: performance of the contractually agreed services, in particular
- generating suggested replies to messages from buyers,
- creating and managing sales listings,
- maintaining the user's inventory and bookkeeping.
3. Categories of data subjects and types of data
Data subjects: buyers and other contacts of the user, and persons identifiable in uploaded photographs.
Categories of personal data:
- the content of buyer messages, insofar as the user pastes them into the tool. These may contain names, addresses, order details and communication data.
- entries the user makes in free-text fields, for example in notes on an item.
- the image content of uploaded photographs.
Special categories of personal data under Art. 9 GDPR are not the subject of this engagement. The user will not bring such data into the tool.
4. Duration
Processing lasts for the term of the service contract. It ends when that contract ends; point 10 governs erasure.
5. A particular feature: buyer messages are not stored
Messages the user pastes into the reply function are not stored permanently. They are transmitted with the request, passed to the AI provider named in point 7 in order to generate the suggested reply, and then discarded. Neither the content of the message nor the generated reply is written to the database.
All that remains in the usage log is the timestamp, the type of action, the language model used, the number of tokens processed and the cost incurred. None of these entries contains content.
This arrangement considerably reduces the risk to the data subjects, but it does not alter the fact that processing within the meaning of Art. 4(2) GDPR takes place.
6. Instructions of the controller
The processor processes the data solely on the documented instructions of the controller. This agreement, the general terms and conditions, and every use the controller makes of the tool's functions constitute such instructions.
Individual instructions are to be sent in text form to support@resellize.com. The processor shall inform the controller without delay if, in its opinion, an instruction infringes data protection law.
A transfer to a third country takes place only in accordance with point 8 or on the basis of a legal obligation. Where such an obligation exists, the processor shall notify the controller before processing, unless the law prohibits that notification.
7. Sub-processors
The controller hereby gives general authorisation for the use of the following sub-processors:
| Company | Location | Service |
|---|---|---|
| Vercel Inc. | USA | hosting of the application, server logs |
| Supabase Pte. Ltd | Singapore, storage in eu-central-1 (Frankfurt) | database and user accounts |
| Cloudflare, Inc. | USA, storage in the Eastern Europe region | photo storage, domain and delivery |
| Anthropic PBC | USA | image analysis and text generation |
| Plus Five Five, Inc. (Resend) | USA, delivery via Amazon SES in eu-west-1 | system emails |
| GitHub, Inc. | USA | encrypted database backup, 90 days |
| Stripe, Inc. / Stripe Payments Europe Ltd. | USA / Ireland | payment processing |
The processor has concluded contracts with these companies that meet the requirements of Art. 28 GDPR.
If the processor intends to engage a further sub-processor or to replace an existing one, it shall notify the controller in text form at least four weeks in advance. The controller may object to the change within that period on serious data protection grounds. If the controller objects, the processor may terminate the service contract with extraordinary notice effective on the date of the intended change.
The current list is available at https://resellize.com/legal/dpa.
8. Transfers to third countries
Some of the companies named in point 7 are established outside the European Economic Area or process data there.
Where the recipient is certified under the EU-U.S. Data Privacy Framework, the transfer is based on the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR.
Where there is no such certification, in particular for recipients established in Singapore, the transfer is based on the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures.
The processor will provide copies of the standard contractual clauses on request.
9. Technical and organisational measures
The processor takes the measures required by Art. 32 GDPR, in particular:
- Encrypted transmission between device and server over TLS.
- Encryption at rest of particularly sensitive fields using AES-256-GCM, where such fields arise, for example access tokens for selling platforms.
- Separation of data by account at database level through row-level access rules, backed by a second check in the application. One account cannot read another account's data even if one of the two layers fails.
- Passwords are stored only as a cryptographic hash.
- Restricted access: only the processor has access to production systems.
- Encrypted backups of the database, retained for 90 days.
- Limiting the processing to what is necessary: buyer messages are not stored (point 5).
- Checking uploaded files against their actual content rather than against what the sender declares.
The processor may develop these measures further, provided the level of protection is not reduced.
10. Erasure and return
The controller can download their data at any time through the export function in the account settings, in a structured, commonly used and machine-readable format.
After the service contract ends, the data is erased within 30 days. The controller can trigger erasure earlier at any time by deleting their account in the account settings.
Encrypted backups persist for up to 90 days and are then erased by expiry. Records subject to statutory retention obligations, in particular invoicing records under § 132 of the Austrian Federal Fiscal Code, are unaffected.
11. Confidentiality
The processor processes the data in confidence. As the processor operates the service alone and no other persons have access to production systems, there are no further staff to place under an obligation. Should the processor engage staff in future, they will be bound to confidentiality in writing before starting work.
12. Assistance to the controller
The processor shall assist the controller, so far as can reasonably be expected,
- in responding to requests from data subjects under Art. 15 to 22 GDPR,
- in complying with the obligations under Art. 32 to 36 GDPR,
- with a data protection impact assessment, where one is required.
If a data subject approaches the processor directly, the processor shall forward the request to the controller without delay and shall not answer it itself.
13. Notification of personal data breaches
The processor shall notify the controller of any personal data breach that comes to its attention without delay and at the latest within 48 hours of becoming aware of it, in text form to the email address held in the account.
The notification shall state, so far as known: the nature of the breach, the categories of data affected, the approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
14. Evidence and audits
On request, the processor shall make available to the controller the information necessary to demonstrate compliance with this agreement.
The controller is entitled to verify compliance. Any audit shall take place by appointment, at reasonable intervals and without disrupting operations. It may be satisfied by the submission of suitable evidence or reports. The controller bears the cost of an audit going beyond the submission of evidence, unless the audit uncovers an infringement.
15. Liability
Art. 82 GDPR applies. As between the parties, the liability provisions of the general terms and conditions apply in addition.
16. Final provisions
Amendments to this agreement require text form. Austrian law applies.
Should any provision be invalid, the validity of the remainder is unaffected. The statutory rule takes the place of the invalid provision.
17. Language
This is a translation provided for convenience. The German version is the binding one and prevails in the event of any discrepancy.
Version: 7 September 2026