Data Processing Agreement (DPA)
Pursuant to Art. 28 Regulation (EU) 2016/679 (GDPR) · Version 1.0 · Effective 2026-08-03
Verify Solutions, S.L. is a Spanish company. The Spanish version of this DPA is legally binding. This English version is a certified translation. In case of discrepancy, the Spanish text prevails. A signed Spanish copy is available on request at dpo@ecomverify.email.
Parties
Controller (hereinafter, the "Client"): the natural or legal person holding the EcomVerify account and contracting the Service.
Processor (hereinafter, "EcomVerify"):
- Verify Solutions, S.L.
- Tax ID B27661099
- Carrer Riera Garrap, 37, 17007 Girona, Spain
- DPO: dpo@ecomverify.email
1. Subject matter
This Agreement governs the conditions under which EcomVerify will process personal data on behalf of the Client within the scope of the contracted Service.
2. Duration
This Agreement has the same duration as the main service agreement. Upon its termination, clause 11 applies.
3. Nature and purpose of the processing
EcomVerify will process personal data for the following purposes:
- Client account and user management, authentication.
- Integration with Amazon Selling Partner API (SP-API) and other Client-authorized platforms.
- Tax calculation, invoicing and bookkeeping.
- Reports and dashboards for the Client.
- Customer support.
- Applicable legal obligations.
4. Types of personal data
- End-buyer identification and contact data (name, shipping and billing address, email when provided by Amazon).
- Transactional data (orders, amounts, SKUs, ASINs).
- Tax data (Tax ID when applicable, country, scheme).
- Technical metadata (logs, IP, events).
No special categories (GDPR Art. 9) and no payment data (card numbers) are processed.
5. Categories of data subjects
- End buyers of the Client on Amazon and other marketplaces.
- Users authorized by the Client to access the Service.
- The Client's suppliers and commercial contacts.
6. Processor obligations
- Process data only following documented instructions from the Client and for the foreseen purposes.
- Ensure authorized personnel is bound by confidentiality.
- Implement the technical and organizational measures of GDPR Art. 32 (Annex I).
- Not engage sub-processors without prior written authorization (see clause 7).
- Assist the Client with data subject rights requests.
- Assist the Client in complying with Arts. 32-36 GDPR.
- Delete or return the data at the end of the service (clause 11).
- Make available to the Client all information necessary to demonstrate compliance and allow audits.
- Notify the Client of any security breach within 72 hours of becoming aware of it.
7. Sub-processors
The Client grants general authorization to EcomVerify to engage the sub-processors publicly listed at ecomverify.com/subencargados.php. EcomVerify will notify the Client of any change with 30 days advance notice, allowing objection. All sub-processors are contractually bound by obligations equivalent to those in this Agreement.
8. International transfers
Data is processed primarily within the European Union. Any transfer outside the EEA is covered by adequate safeguards (Standard Contractual Clauses approved by the European Commission, or equivalent).
9. Amazon Selling Partner API — specific conditions
When processing derives from the Amazon SP-API integration, EcomVerify additionally complies with:
- The Amazon Selling Partner API Data Protection Policies.
- The Acceptable Use Policies and Website Guidelines.
- Incident notification to Amazon within 24 hours.
- PII retention ≤ 30 days except for legal/tax obligations.
- Role-based access (RBAC), MFA and AES-256 at rest / TLS 1.2+ in transit.
10. Data subject rights
EcomVerify will assist the Client in responding to access, rectification, erasure, objection, restriction and portability requests. Data subjects may additionally use ecomverify.com/data-deletion.php.
11. Return and deletion on termination
Upon termination of the service, at the Client's choice, EcomVerify will:
- Return the data in a structured format (CSV/JSON) within a maximum of 30 days; or
- Securely delete it.
Data subject to legal retention obligations (tax, accounting) will be blocked until the legal period expires, at which point it will be deleted.
12. Liability
Each party is liable for damages caused by breach of its respective obligations under GDPR Art. 82.
13. Governing law and jurisdiction
This Agreement is governed by Spanish and European law. The parties submit to the courts of Girona, Spain.
Annex I — Technical and organizational measures (GDPR Art. 32)
A. Confidentiality
- Physical access control to facilities.
- Role-based logical access control (RBAC) and least-privilege principle.
- Multi-factor authentication (MFA) for production access.
- Environment segregation (production, staging, development).
B. Integrity
- Encryption in transit: TLS 1.2+.
- Encryption at rest: AES-256 for sensitive databases and files.
- Credential and secret management outside the source code; periodic rotation.
- Change logs and integrity audit.
C. Availability
- Periodic encrypted backups with defined retention.
- Business continuity and disaster recovery plan.
- 24/7 monitoring and automated alerts.
D. Resilience
- Server redundancy and load balancing.
- DDoS protection and perimeter WAF.
- Periodic patching and vulnerability management.
E. Governance
- Records of processing activities (GDPR Art. 30).
- Incident management procedure (≤ 72h to Client, ≤ 24h to Amazon when applicable).
- Periodic staff training.
- Annual access review and recertification.
Acceptance
Acceptance of this DPA is formalized automatically upon contracting the Service and accepting EcomVerify's Terms and Privacy Policy. A signed copy is issued on request at dpo@ecomverify.email.
For Verify Solutions, S.L.
Date: 2026-08-03
For the Client
Date: _______________
© 2026 Verify Solutions, S.L. · Tax ID B27661099