← BackDATA PROCESSING AGREEMENT (DPA) — Sellexio, Inc.
Version 2026.01 · Effective 2026-01-15
1. DEFINITIONS. "Personal Data", "Data Subject", "Processing", "Controller", "Processor" have the meanings assigned in Regulation (EU) 2016/679 ("GDPR") and the UK Data Protection Act 2018.
2. ROLES. Customer is the Controller. Sellexio is the Processor. Sellexio processes Personal Data only on documented instructions from Customer and as necessary to provide the Services described in the applicable Order Form or MSA.
3. SUBJECT MATTER & DURATION. Sellexio processes Personal Data for the term of the subscription plus 30 days for return/deletion. Categories of Data Subjects: Customer's employees and contractors, Customer's counterparties (carriers, suppliers, port agents). Categories of Personal Data: names, business email addresses, professional titles, business phone numbers, IP addresses, document contents provided by Customer.
4. SUB-PROCESSORS. Customer authorizes the use of the sub-processors listed at /legal/subprocessors. Sellexio will notify Customer of any intended addition or replacement of sub-processors with at least 30 days' notice. Customer may object in writing within 15 days.
5. SECURITY MEASURES. Sellexio implements technical and organizational measures including (a) encryption in transit (TLS 1.2+) and at rest (AES-256), (b) role-based access control with least-privilege enforcement, (c) row-level security in the database layer, (d) audit logging with tamper-evident hashes, (e) least-privilege service accounts, (f) SOC 2 Type I roadmap targeting Q4 2026.
6. DATA SUBJECT RIGHTS. Sellexio will assist Customer in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection) within seven business days of Customer's request.
7. BREACH NOTIFICATION. Sellexio will notify Customer without undue delay, and in any event within 72 hours, upon becoming aware of a Personal Data breach affecting Customer data.
8. INTERNATIONAL TRANSFERS. For transfers of Personal Data from the EEA, UK, or Switzerland to a third country not covered by an adequacy decision, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) Module Two (Controller to Processor) are hereby incorporated by reference, together with the UK International Data Transfer Addendum where applicable. Docking clause: Section II applies. Governing law of the SCCs: Republic of Ireland.
9. AUDIT. Once per twelve-month period, Customer may request evidence of Sellexio's compliance in the form of the most recent SOC 2 report or, prior to certification, a completed CAIQ Lite response and a summary of technical/organizational measures. On-site audits are available to Enterprise-tier Customers at Customer's cost.
10. RETURN & DELETION. Upon termination, Sellexio will delete or return all Personal Data within 30 days, except where retention is required by law. Backups are purged within an additional 90 days.
11. LIABILITY. Liability under this DPA is subject to the limitation of liability in the MSA. Nothing in this DPA excludes liability that cannot be excluded under applicable law.
12. ORDER OF PRECEDENCE. In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the MSA on data-protection matters.
SIGNED electronically via the Sellexio platform. Signature record includes a SHA-256 hash of the signer identity, timestamp, and user agent, retained in the tamper-evident agreements ledger.