Legal
Data processing agreement
pursuant to Art. 28 (3) GDPR – version 2026-08-01
Parties and conclusion of the agreement
This data processing agreement is concluded between
the organization (organizer) that confirms this agreement when creating its organization in the MukiBasar app, represented by the confirming person – hereinafter “controller” –
and
Martin Januschke (sole trader, operating under the brand “MukiBasar”), Josef-Karl-Str. 3, 92421 Schwandorf, Germany – hereinafter “processor” –
(both parties hereinafter also referred to as “party” or “parties”).
The agreement is concluded in electronic form pursuant to Art. 28 (9) GDPR: the controller confirms the agreement by ticking the corresponding confirmation box when creating their organization in the MukiBasar app. The processor logs the time, the confirming person and the version of the agreement accepted. The version published at the time of confirmation (stated above) is authoritative.
§ 1 General provisions and subject of the mandate
(1) The subject of this contract is the processing of personal data on behalf of the controller by the processor (Art. 28 GDPR). The content of the mandate, the categories of data subjects and types of data as well as the purpose of the processing are set out in Annex 1.
(2) The controller is the controller within the meaning of Art. 4 no. 7 GDPR. They alone are responsible for assessing the lawfulness of the processing operations pursuant to Art. 6 GDPR and for safeguarding the rights of data subjects.
(3) The processing of the data by the processor takes place exclusively within the territory of the Federal Republic of Germany, a member state of the European Union or a contracting state of the EEA Agreement. Processing outside these states takes place only under the conditions of Chapter 5 of the GDPR (Art. 44 et seq.) and with the prior consent of the controller.
(4) Remuneration is agreed outside this contract.
§ 2 Term and termination
The term of this contract corresponds to the term of the usage contract for the MukiBasar platform between the parties; it ends with the termination of that contract without any separate notice being required. The right to extraordinary termination for good cause remains unaffected.
§ 3 Instructions of the controller
(1) The controller has a comprehensive right to issue instructions to the processor regarding the nature, scope and modalities of the data processing. In this role they may in particular demand the immediate deletion, rectification, blocking or surrender of the data covered by the contract. The processor is obliged to comply with the controller's instructions unless legitimate contractual or statutory interests conflict with them.
(2) The processor informs the controller without undue delay if it considers that an instruction of the controller infringes statutory provisions. If an instruction is issued whose lawfulness the processor substantively doubts, the processor is entitled to suspend its execution temporarily until the controller expressly confirms or changes it.
(3) Instructions are to be issued in writing or in an electronic format (e.g. by email) as a matter of principle. At the processor's request, oral instructions must be confirmed by the controller in writing or in an electronic format. The processor must log the person, date and time of an oral instruction in an appropriate form.
(4) At the processor's request the controller names one or more persons authorised to issue instructions. Changes must be communicated to the processor without undue delay.
§ 4 Audit rights
(1) The controller is entitled to check compliance with the statutory and contractual provisions on data protection and data security regularly and to the extent necessary, before the processing begins and during the term of the contract, or to have this checked by third parties. The processor will tolerate such audits and support them to the extent necessary. In particular, it will provide the controller with the information relevant for the audits completely and truthfully, grant access to the stored data and data processing programmes/systems, and enable on-site audits.
(2) The controller must ensure that the audit measures are proportionate and do not disrupt the processor's operations more than necessary. In particular, on-site audits should as a rule take place during normal business hours and by appointment with reasonable advance notice, unless the purpose of the audit conflicts with prior announcement.
(3) The results of audits and instructions must be logged by both parties in a suitable manner.
§ 5 General obligations of the processor
(1) The processing of the contractual data by the processor takes place exclusively on the basis of the contractual agreements in conjunction with any instructions issued by the controller. Processing deviating from this is only permissible if the processor is required to process the data under the law of the European Union or of the member states. In the case of such processing, the processor informs the controller without undue delay of the intended or already initiated processing, unless the law in question prohibits such notification on important grounds of public interest; in that case the notification is made without undue delay as soon as the legal obstacles no longer apply.
(2) The processor must comply with all statutory provisions when carrying out the mandate. In particular, it must implement the technical and organisational measures required under Art. 32 GDPR.
(3) The processor is currently not obliged to appoint a data protection officer. Should such an obligation arise in the future, the processor will appoint a data protection officer in accordance with the statutory provisions and communicate their contact details to the controller (e.g. by email).
(4) The data processing takes place in the data centres of the sub-processors listed in Annex 3 within the EU as well as at the processor's place of business (including secured remote access). The controller consents to this form of processing.
(5) The processor must ensure that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3) (b) GDPR). Before being placed under the confidentiality obligation, the persons concerned may not be given access to the personal data provided by the controller.
(6) The processor will check the fulfilment of its obligations regularly and independently and document this in a suitable manner.
§ 6 Technical and organisational measures
(1) The processor has defined appropriate technical and organisational measures to ensure an adequate level of protection and set them out in Annex 2 to this contract. The measures described there were selected taking the requirements of Art. 32 GDPR into account.
(2) The processor will review and adjust the technical and organisational measures as required and on an ad-hoc basis. Necessary adjustments are documented by the processor and made available to the controller on request. Material changes that could reduce the level of protection must be agreed with the controller in advance.
§ 7 Duties of the processor to assist
(1) Pursuant to Art. 28 (3) (e) GDPR the processor will assist the controller with their obligations to safeguard the rights of data subjects under Chapter III, Art. 12–22 GDPR. This applies in particular to providing information and to the deletion, rectification or restriction of personal data. The scope of the duty to assist is determined in each individual case taking the nature of the processing into account.
(2) Pursuant to Art. 28 (3) (f) GDPR the processor will further assist the controller with their obligations under Art. 32–36 GDPR (in particular notification duties). The scope of this duty to assist is determined in each individual case taking the nature of the processing and the information available to the processor into account.
§ 8 Engagement of sub-processors
(1) The processor is entitled to engage sub-processors. All sub-processor relationships already existing at the time this contract is concluded are listed exhaustively in Annex 3. Consent to the sub-processors listed in Annex 3 is deemed granted upon conclusion of this contract.
(2) If the processor intends to engage further sub-processors, it will notify the controller in good time – at the latest two weeks – before they are engaged, in written or electronic form (e.g. by email to the administrators of the organization). After this notification the controller has two weeks to object to the engagement of the sub-processor(s). If no objection is raised within this period, the engagement is deemed approved. In urgent cases (e.g. error analysis or defect remedies needed at short notice) the processor may shorten the notification and objection period appropriately. If an objection is raised in time, the sub-processors concerned may not be engaged. Objections are only permissible if the controller has substantiated grounds to believe that engaging the sub-processor would impair data security or data protection, would jeopardise compliance with statutory or contractual provisions and/or that other legitimate interests of the controller conflict with it; the corresponding grounds for suspicion must be attached to the objection.
(3) Sub-processors are selected by the processor in compliance with the statutory and contractual requirements. All contracts between the processor and a sub-processor must satisfy the statutory provisions on processing personal data on behalf of a controller; this concerns in particular the implementation of appropriate technical and organisational measures pursuant to Art. 32 GDPR at the sub-processor's operation. Ancillary services used by the processor to conduct its business (e.g. telecommunications services without a specific connection to the main service, postal and transport services) do not constitute sub-processing relationships within the meaning of Art. 28 GDPR. The processor will nevertheless ensure compliance with statutory data protection standards for these third-party services as well.
(4) All contracts between the processor and the sub-processor must satisfy the requirements of this contract and the statutory provisions on processing personal data on behalf of a controller.
(5) Engaging sub-processors in third countries is only permissible if the statutory conditions of Art. 44 et seq. GDPR are met and the controller has consented.
§ 9 Notification duties of the processor
(1) Breaches of this contract, of the controller's instructions or of other data protection provisions must be reported to the controller without undue delay; the same applies where there is a corresponding substantiated suspicion. This obligation applies regardless of whether the breach was committed by the processor itself, a person employed by it, a sub-processor or another person engaged by it to fulfil its contractual obligations.
(2) The processor is obliged to assist the controller in fulfilling their statutory information obligations under Art. 33 and 34 GDPR. The processor may only make its own notifications to authorities or data subjects under Art. 33 and 34 GDPR after prior instruction by the controller.
(3) If a data subject, an authority or another third party requests information, rectification, blocking or deletion from the processor, the processor will forward the request to the controller without undue delay; under no circumstances will the processor comply with the data subject's request without the controller's consent.
(4) The processor will inform the controller without undue delay if supervisory actions or other measures by an authority are imminent which could also affect the processing, use or collection of the personal data provided by the controller. Beyond that, the processor must inform the controller without undue delay of all events or measures by third parties that could endanger or impair the data covered by the contract.
§ 10 End of the contract, deletion and return of the data
After completion of the contractual data processing or after termination of this contract, the processor must delete or return all personal data at the controller's discretion, provided there is no longer any statutory obligation to store the data concerned (e.g. statutory retention periods). The controller is entitled to verify the processor's measures in a suitable manner; in particular they are entitled to inspect the relevant deletion logs.
§ 11 Data secrecy and confidentiality
(1) The processor is obliged, without time limit and beyond the end of this contract, to treat the personal data obtained in the course of this contractual relationship confidentially and in accordance with the requirements of the GDPR and other data protection laws.
(2) The processor undertakes to familiarise any employees with the relevant data protection provisions and secrecy rules and to place them under an obligation of confidentiality before they take up their work at the processor.
(3) The processor will document compliance with the measures set out in this section in a suitable manner. The documentation must be presented to the controller on request.
§ 12 Final provisions
(1) Amendments to this contract and side agreements require written or electronic form which clearly indicates that and which amendment or addition to these terms is intended.
(2) Should the GDPR or other statutory provisions referred to change during the term of the contract, the references made here also apply to the respective successor provisions.
(3) Should individual parts of this agreement be or become invalid, the validity of the remaining provisions remains unaffected.
(4) All annexes to this contract form part of the contract.
Annex 1 – Details of the processing
Services
In connection with the usage contract for the MukiBasar platform, this contract covers the following services:
- Provision and operation of the MukiBasar platform for organizing and running the controller's bazaars
- Administration of sellers' bazaar registrations (registration, waiting list, confirmation, rejection)
- Administration of sellers' articles, labels and sales data
- Handling of goods receipt (hand-in status)
- Operation of the till system including the allocation of sales and till staff
- Creation of reports and settlements for the bazaar
- Sending transactional emails to sellers on behalf of the controller (e.g. registration confirmations, reminders)
- Data backup and restoration
Types of data
The following types of data are regularly processed in the course of the contractual services:
- First name and last name
- Address (street, postcode, town) and geo-coordinates derived from it
- Email address and phone number
- Profile picture (if voluntarily uploaded)
- Seller number and registration status (including history)
- Article data (name, price, size, category) and sales data (articles sold, revenue, receipts)
- Hand-in and collection information
- Activity data of till staff (till allocation, operating actions)
Categories of data subjects
- Sellers who register for the controller's bazaars
- Team members and till staff of the controller, insofar as they take part in the platform
Purpose of the processing
Organizing, running and settling the controller's bazaars via the MukiBasar platform.
Annex 2 – Technical and organisational measures (Art. 32 GDPR)
I. Purpose limitation and separability
- Logical tenant separation at database level: access is restricted to the respective organization or user by row-level security policies
- Role-based permission concept (administrator, member, till staff)
- Separation of production and test systems (separate projects and databases)
II. Confidentiality and integrity
- Encryption of all data transmissions using TLS (HTTPS)
- Encryption of stored data and backups at rest in the sub-processors' data centres
- Access control: passwordless sign-in via one-time codes/links by email; no access for users who are not signed in (anonymous access to protected functions is technically revoked)
- Authorisation control: rights are granted on the basis of the permission concept; administrative access to the production environment is restricted to the processor and secured by multiple factors
- Profile pictures can only be retrieved via time-limited, signed links by signed-in users
- Input control: logging of security-relevant operations (e.g. history of registration statuses, authentication logs)
- Automated removal of personal details (e.g. email addresses) from error reports produced by error diagnostics
III. Availability, recoverability and resilience
- Daily automatic backups as well as point-in-time recovery of the production database
- Documented backup and restore concept with defined recovery objectives; the recency of the backup is checked automatically before production schema changes
- Operation in professional, certified data centres (AWS eu-central-1)
IV. Special data protection measures
- Deletion concept: users can permanently delete their account themselves (cascading deletion of profile, articles and memberships); the email delivery log is deleted automatically after 90 days
- Processing control: data processing agreements are in place with all sub-processors (Annex 3)
V. Review, evaluation and adjustment
The processor will review, evaluate and, where necessary, adjust the technical and organisational measures set out in this annex every 12 months and on an ad-hoc basis.
Annex 3 – Sub-processors at the time the contract is concluded
Supabase, Inc.
970 Toa Payoh North #07-04, Singapore 318992
Service: operation of the database, authentication and
file storage of the MukiBasar platform.
Place of performance: AWS region eu-central-1
(Frankfurt am Main, Germany). Any third-country access (e.g. support)
is safeguarded by EU standard contractual clauses.
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy, 1855 Luxembourg
Service: sending transactional emails (Amazon SES) as
well as hosting and delivery of the application (AWS
Amplify/CloudFront).
Place of performance: AWS region eu-central-1
(Frankfurt am Main, Germany); delivery of static content via the global
CloudFront network. Data transfers to third countries are safeguarded
by EU standard contractual clauses and certification under the EU-US
Data Privacy Framework.
Functional Software, Inc. dba Sentry
45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
Service: error diagnostics and stability monitoring of
the application.
Place of performance: EU data region
(ingest.de.sentry.io, Frankfurt am Main, Germany). Data transfers to
third countries are safeguarded by EU standard contractual clauses and
certification under the EU-US Data Privacy Framework.