Data Processing Addendum

Who this applies to

This DPA applies to all DealerHub customers (dealers) who use our platform to process personal data of their buyers. It forms an integral part of the Terms of Service and the Privacy Policy, in line with the applicable data protection laws, including the Macedonian Personal Data Protection Act and EU GDPR (in particular Article 28) where applicable.

1. Roles

Roles under applicable data protection laws, including GDPR where applicable.

PartyRole
Customer / dealer Data Controller
DealerHub Studio Data Processor
Lemon Squeezy Independent controller for payment and checkout data

The customer determines what data it collects from its buyers via inquiries, lead forms and contact forms. DealerHub processes that data only on behalf of the customer and according to its instructions, except where we are legally required otherwise.

Payment cards and sensitive payment data do not pass through DealerHub infrastructure. Online checkout is performed via Lemon Squeezy as Merchant of Record.

2. Scope of processing

2.1 Type of data

We do not process special categories of sensitive data (health, race, political, religious) for customers; if a dealer inadvertently collects such data, the responsibility lies with the dealer.

2.2 Purposes of processing

2.3 Duration

For as long as the contract with the dealer customer lasts, plus 90 days for export / return / deletion.

3. Obligations of DealerHub as processor

We:

4. Technical and organisational measures

4.1 Encryption

4.2 Access control

4.3 Infrastructure security

4.4 Backup and recovery

5. Sub-processors

We use the following sub-processors. All are within the EEA or have Standard Contractual Clauses:

NamePurposeLocation
Hetzner Online GmbH Hosting + backup Germany (EU)
Cloudflare DDoS protection (optional) Ireland (EU) + global edge
Cloudinary Image hosting + transformations Ireland (EU) / USA (with SCC)
Resend / Postmark Transactional email (confirmations, notifications) USA (with SCC)
Namecheap Domain registrar USA
Meta Platforms Facebook / Instagram Graph API (only content published by the customer) USA (SCC + DPF)

Lemon Squeezy is not our sub-processor — they act as an independent controller for payment and checkout data (see §1). Their list of own processors is available at lemonsqueezy.com/legal/dpa.

We reserve the right to add or replace sub-processors. The customer will be notified 30 days in advance by email. If the customer has a reasonable basis to object to a new sub-processor, the customer may terminate the contract without penalty.

6. International transfers

The primary data is in the EU. For sub-processors outside the EEA (USA):

7. Data subject rights

When a customer's buyer requests access to, correction or deletion of their data:

  1. The customer receives the request directly and decides on the response
  2. If our technical assistance is required (export, deletion), we assist at no extra charge
  3. We respond within 72 hours to your assistance request

The customer is responsible for informing data subjects of the rules and their rights.

8. Incident notification

In the event of a personal data security breach:

9. Audit

The customer has the right to verify our compliance:

10. Upon termination of the contract

Upon termination of the relationship:

  1. 30 days — the customer has full export access
  2. 31–90 days — data is archived; on customer request it is returned or deleted
  3. After 90 days — all personal data is automatically deleted from the production system and backup archives (unless a legal obligation requires retention — e.g. financial records for 10 years)

11. Liability and indemnity

Each party is liable for its own GDPR violations. Our total liability for breaches of this DPA is limited in accordance with the Terms of Service, except where the law does not permit such limitation (e.g. malicious intent, gross negligence).

12. Effect and changes

This DPA enters into force upon activation of the subscription and remains in effect for as long as the relationship lasts. Material changes will be communicated 30 days in advance.

DPO contact

Email: dpo@dealerhub.design

Controller: DealerHub Studio, Skopje, North Macedonia

Competent supervisory authority for our activity: Personal Data Protection Agency.