Last updated: 2026-07-23
This Data Processing Agreement forms part of the Terms & Conditions between SIA "eu-food" ("Processor", "we") and the company using eu-food.com ("Controller", "you"), and applies whenever we process personal data on your behalf as part of running the marketplace. It implements Article 28 of the GDPR.
In most of what the marketplace does, each company is itself a controller of the data it enters — your own account and the buyers or suppliers you deal with. This agreement covers the narrower case where we process data on your instructions rather than for our own purposes: for example, the business-contact details of your team members that you store in your account.
1.Subject matter and duration
This agreement governs the processing of personal data by us on your behalf in connection with your use of eu-food.com. It applies for as long as we process that data on your behalf, and ends automatically when your account is closed and the data retention periods described in our Privacy Policy expire.
2.Nature and purpose of processing
We process personal data on your behalf to:
- give your team access to your company's account on the marketplace;
- carry order requests and messages between your company and the other side of a deal;
- provide support when you contact us about your account;
- keep the platform secure and detect misuse.
3.Categories of data and data subjects
The data we may process on your behalf is the account, company, order and technical data described in our Privacy Policy — chiefly the names, work email addresses and phone numbers of the people who act for your company, plus the delivery contact details entered against an order.
The data subjects are your team members, and the contact people you name for a delivery.
4.Our obligations as processor
- We process personal data only on your documented instructions — which, for a self-service platform like this one, are the instructions built into the product: what you enter and configure through the account.
- We keep the people who can access personal data under a duty of confidentiality.
- We apply the technical and organisational security measures described below.
- We help you respond to a data subject request, or to a request from a supervisory authority, so far as the marketplace design allows.
- We tell you without undue delay if we become aware of a personal data breach affecting your data.
- When your account is closed, we delete or return your data as described in "Return or deletion of data" below.
5.Your obligations as controller
- You have a lawful basis for the personal data you enter — including the data of your own team members and of the contacts you name for deliveries.
- You give any required notice to those individuals about how their data is used on the platform.
- You keep the data you enter accurate and up to date.
6.Sub-processors
We use the following sub-processors to run the marketplace, each bound by its own data processing terms. We will give you reasonable notice before adding or replacing one, so you can object on data-protection grounds:
- Auth0 (Okta) — authentication and sign-in.
- MongoDB Atlas — database hosting.
- Vercel — application hosting and storage of uploaded product images.
7.International transfers
We host data in the European Union wherever our sub-processors offer it. Where a sub-processor transfers data outside the EU/EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
8.Security measures
- Encrypted transport (HTTPS) for all traffic.
- Access to an account requires a signed session, and every request is checked against the account it belongs to.
- Access to production data is limited to the personnel who need it to operate the service.
- Uploaded content and stored data are hosted with providers that maintain their own independently audited security programmes.
9.Data subject rights
Where a data subject exercises their GDPR rights — access, rectification, erasure, restriction, portability or objection — directly against us regarding data we process on your behalf, we will pass the request to you without undue delay and give reasonable assistance if you ask for it.
10.Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, with the information reasonably available to us at the time, so you can meet your own notification duties under Art. 33-34 GDPR.
11.Audit rights
You may request the information reasonably necessary to demonstrate our compliance with this agreement. Write to info@eu-food.com.
12.Return or deletion of data
When your account is closed, we delete or return the personal data we process on your behalf, except where we are required by law to keep it — matching the retention periods set out in our Privacy Policy.
13.Governing law
This agreement is governed by the law of the Republic of Latvia, the same law that governs the Terms & Conditions and is applied by SIA "eu-food", registration number 40203451789, Brīvības iela 1, Rīga, LV-1010, Latvia.
14.Changes and contact
We may update this agreement if our processing activities or sub-processors change; the date above shows the current version. Questions: info@eu-food.com.
This document is published in Latvian, English, Russian and Lithuanian. If the versions differ, the Latvian version prevails.