Data Processing Agreement (DPA)

Last updated: 1 July 2026

This Data Processing Agreement forms an integral part of the Stocklane Terms of Service and applies whenever Stocklane B.V. ("Processor") processes personal data on behalf of a Seller ("Controller"). It is designed to satisfy Article 28 of the GDPR.

1. Subject matter and duration

Processor processes personal data of the Controller's B2B buyers (company name, work email, order data) for as long as the Controller maintains an active account, plus a 30-day retention window after Portal closure.

2. Nature and purpose of processing

Storage, retrieval, transmission, aggregation, anonymisation and deletion, exclusively for the purpose of operating the Portal and providing the Platform features enabled by the Controller.

3. Categories of data subjects

B2B buyers ("inkopers") who place orders via a Portal published by the Controller, and the Controller's own staff users of the Platform.

4. Processor obligations

Processor shall (a) process personal data only on documented instructions from the Controller, including these Terms and any explicit written instruction; (b) ensure that persons authorised to process the personal data are bound by confidentiality; (c) implement the technical and organisational measures listed in Annex II; (d) engage sub-processors only under equivalent written obligations and with prior general authorisation (see §7); (e) assist the Controller with data subject requests; (f) assist with Art. 32–36 obligations, and (g) at the Controller's choice, delete or return all personal data at the end of the service.

5. Security measures (Annex II)

Encryption in transit (TLS 1.2+) and at rest (AES-256); row-level security enforcement in the database; single-sign-on with 2FA for staff production access; principle of least privilege; audit logging retained for 90 days; incident response plan with 72-hour breach notification to the Controller.

6. Personal data breach notification

Processor notifies the Controller without undue delay, and in any event within 72 hours after becoming aware of a personal data breach, providing all reasonably available information required for the Controller's Art. 33 notification.

7. Sub-processors

The Controller grants a general written authorisation to Processor to engage the sub-processors listed in the Privacy Policy. Processor will inform the Controller of any intended changes at least 14 days in advance and the Controller may object on reasonable grounds.

8. International transfers

Any transfer of personal data outside the EU/EEA is protected by the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor, Decision 2021/914) with the supplementary measures required by the CJEU Schrems II ruling.

9. Audits

Once per calendar year, and upon a substantiated request, Processor makes available all information necessary to demonstrate compliance with Art. 28 GDPR and allows for audits conducted by the Controller or a mandated auditor, subject to reasonable confidentiality obligations.

10. Return and deletion

At the Controller's option, and in any event within 30 days after termination of the Platform service, Processor deletes or returns all personal data and copies thereof, unless retention is required by EU or Member State law.

11. Liability & governing law

Liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by the laws of The Netherlands.