Back to site

Data Processing Agreement

Last updated: 28 June 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between Deltapp ("Processor") and the customer ("Controller"). It governs the processing of personal data carried out by Deltapp on the Controller's behalf and reflects the requirements of Article 28 of the UK GDPR and EU GDPR. A countersigned copy is available on request at privacy@deltapp.io.

1. Roles of the parties

For the buyer personal data that flows through the Controller's connected eBay store (orders, delivery details, and buyer messages), the Controller is the data controller and Deltapp is the data processor. For the Controller's own account data (the seller's identity, billing, and authentication), Deltapp is the controller; that processing is governed by the Privacy Policy, not this DPA.

2. Subject matter, nature and purpose

Deltapp processes the buyer personal data solely to provide the contracted service: synchronising the Controller's eBay orders and messages, calculating pricing and profit, dispatching order updates and feedback, and the related automation the Controller configures. Deltapp does not sell the data and does not use it for its own purposes.

3. Duration

Processing continues for the term of the Controller's subscription and ceases on termination, subject to the deletion terms in Section 10.

4. Categories of data subjects and personal data

  • Data subjects:the Controller's eBay buyers.
  • Personal data: buyer name and display name, delivery address, eBay username, order and transaction details, and the content of buyer-seller messages.
  • No special-category data (Article 9) is intentionally processed. Buyers should not be asked to provide it.

5. Controller instructions

Deltapp processes the personal data only on the Controller's documented instructions, which comprise the Terms, this DPA, and the Controller's use of the product's features. Deltapp will inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

6. Confidentiality

Deltapp ensures that persons authorised to process the personal data are bound by an obligation of confidentiality and access it strictly on a need-to-know basis.

7. Security measures (Article 32)

  • Encryption in transit (TLS) for all connections, including to the database.
  • Encryption at rest for high-value secrets (eBay OAuth tokens and signing keys) using AES-256-GCM with keys held outside the database.
  • Strict per-tenant isolation: every record is scoped to its owning account and access is authenticated on every request.
  • Least-privilege access controls, audit logging, and error monitoring.
  • Encrypted, access-controlled backups with a 14-day retention window. See the Security page for detail.

8. Sub-processors

The Controller authorises Deltapp to engage the sub-processors listed on the sub-processors page, each bound by a written agreement imposing data protection obligations no less protective than this DPA. Deltapp gives at least 14 days' notice before adding or replacing a sub-processor that materially affects personal data handling, during which the Controller may object.

9. Assistance with data subject rights

Taking into account the nature of the processing, Deltapp assists the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, and objection). Where eBay notifies Deltapp that a buyer has closed their account or requested erasure (the eBay Marketplace Account Deletion notification), Deltapp anonymises that buyer's personal data across all affected accounts automatically.

10. Deletion or return of data

On termination, or on the Controller's account deletion, Deltapp keeps a 30-day recovery window during which the account can be reactivated; after that window Deltapp removes the personal data from live systems without undue delay and clears it from backups within 14 days, save where retention is required by law. A buyer's data is anonymised on an eBay erasure notification as described above.

11. Personal data breach

Deltapp notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, with the information the Controller reasonably needs to meet its own notification obligations.

12. Audits and information

Deltapp makes available the information necessary to demonstrate compliance with Article 28 and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice and subject to confidentiality.

13. International transfers

The primary database is hosted in the UK. Where personal data is transferred outside the UK / EEA via a sub-processor, the transfer is protected by Standard Contractual Clauses, an adequacy decision, or the sub-processor's own approved transfer mechanism, as recorded on the sub-processors page.

14. How to execute

This DPA applies automatically to every customer through the Terms. A countersigned copy for the Controller's records is available on request at privacy@deltapp.io.