Data Processing Agreement (DPA)
In force from: 28 August 2026
Version 1.0
Concluded under Article 28 of Regulation (EU) 2016/679 (GDPR), between:
THE CONTROLLER — the User of the MASAT platform, identified by the data in their MASAT account (company name, tax ID, registered office, representative), hereinafter “the Controller” or “the Client”;
and
THE PROCESSOR — S.C. MASAT DIGITAL S.R.L., Tax ID (CUI) 52437661, Trade Registry No. J2025066544008, with its registered office in Ilfov County, Bragadiru, 59 Ghidiceni Street, hereinafter “MASAT”.
This Agreement is concluded automatically, as an integral part of the Terms and Conditions, when a MASAT account is created and the first eMAG integration is connected. An electronically signed version can be requested at office@masat.ro.
1. Subject matter and roles of the parties
By using the MASAT Platform and connecting an eMAG seller account through the official API, MASAT processes personal data on behalf of the Controller.
This concerns principally the data of the Controller’s end customers, contained in the orders and documents retrieved from the eMAG account.
- The Controller determines the purposes and means of the processing and is responsible for the lawfulness of the data it makes available.
- MASAT processes that data solely on the Controller’s documented instructions.
For the Controller’s own data as a user (account, billing, support, marketing), MASAT acts as an independent controller, as described in the Privacy Policy. This Agreement does not apply to that processing.
2. Annex 1 — Details of the processing
Subject matter: the provision of analysis, monitoring and reporting services for the Controller’s activity on the eMAG marketplace.
Duration: for the term of the contract between the parties, plus the deletion periods set out in Section 10.
Nature and purpose: collection, structuring, storage, consultation, use, aggregation, display, export and erasure, for the purpose of providing the MASAT features requested by the Controller.
Categories of data subjects: the Controller’s end customers (buyers) on eMAG; the Controller’s representatives, employees and collaborators who use the MASAT account.
Categories of personal data:
- identification data: first name, last name;
- contact data: delivery address, billing address, telephone number, e-mail;
- order data: order number, products purchased, value, date, payment method (excluding card data), delivery status, returns;
- MASAT account usage data for the Controller’s users.
Special categories of data (Art. 9 GDPR): MASAT does not process special categories of data. The Controller undertakes not to introduce such data into the Platform.
Source of the data: the Controller’s eMAG seller account, through the official eMAG API, together with data entered directly by the Controller into the Platform.
3. The Controller’s instructions
MASAT processes the data solely on the Controller’s documented instructions. The following constitute documented instructions: the Terms and Conditions and this Agreement; the Controller’s configurations, settings and actions within the Platform; and written requests sent to office@masat.ro.
MASAT will inform the Controller if it considers that an instruction infringes the GDPR or other data protection provisions.
MASAT may also process the data on the basis of a legal obligation under EU or Romanian law; in that case it will inform the Controller before processing, unless the law prohibits such notification.
4. MASAT’s obligations
- to process the data only on the Controller’s instructions;
- to ensure that persons authorised to process the data have committed themselves to confidentiality in writing or are under a statutory obligation of confidentiality;
- to implement the technical and organisational measures required by Art. 32 GDPR, described in Annex 2;
- to respect the conditions relating to sub-processors set out in Section 6;
- to assist the Controller, insofar as possible, in responding to data subject requests (Section 7);
- to assist the Controller in ensuring compliance with Articles 32–36 GDPR;
- at the Controller’s choice, to delete or return the data at the end of the provision of services (Section 10);
- to make available to the Controller the information necessary to demonstrate compliance, and to allow audits under the conditions of Section 9;
- to maintain a record of the categories of processing activities carried out on behalf of the Controller, in accordance with Art. 30(2) GDPR.
5. The Controller’s obligations
- warrants that it has a valid legal basis for the processing of the data it makes available to MASAT and that it has informed the data subjects;
- is responsible for the accuracy, quality and lawfulness of the data;
- undertakes not to introduce special categories of data, or data unrelated to its activity as an eMAG seller, into the Platform;
- manages its own users’ access to the MASAT account and withdraws access from persons no longer entitled to it;
- is responsible for complying with the terms and conditions applicable to its own eMAG account.
6. Sub-processors
The Controller grants MASAT a general authorisation to engage sub-processors, subject to the conditions below.
The up-to-date list of sub-processors is published at masat.ro/sub-processors and states, for each one, its name, role and place of processing.
MASAT imposes on each sub-processor, by contract, the same data protection obligations as those set out in this Agreement; remains fully liable to the Controller for the performance of those obligations; and notifies the Controller 30 days before adding or replacing a sub-processor, by e-mail and by updating that page.
The Controller may object, with reasons and in writing, within 15 days of the notification. If the parties cannot agree on a solution, the Controller may terminate the contract with a pro-rata refund of the unused subscription.
7. Data subject rights
MASAT provides the Controller with features enabling it to respond to data subject requests: access, rectification, erasure, restriction, portability (data export) and objection.
If a data subject contacts MASAT directly, MASAT will not respond on the merits but will forward the request to the Controller within 5 business days and assist in preparing the response.
8. Personal data breaches
MASAT will notify the Controller without undue delay and within 24 hours at most of becoming aware of a breach affecting data processed on the Controller’s behalf.
The notification will include, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information.
MASAT will not notify the supervisory authority or the data subjects on the Controller’s behalf unless expressly requested to do so in writing.
Specific case. If the breach affects the Controller’s eMAG credentials, MASAT will immediately invalidate the stored credentials, suspend the affected integrations, notify the Controller within 24 hours and recommend that the eMAG account password be changed immediately.
9. Audit and demonstrating compliance
MASAT will make available to the Controller, on request, the information necessary to demonstrate compliance with this Agreement, including any audit reports or certifications it holds.
The Controller may request an audit, itself or through an independent auditor agreed by both parties, on the following conditions: no more than once per calendar year, except where there has been a security breach or an authority so requires; with at least 30 days’ prior notice; during normal business hours and without disrupting MASAT’s operations; subject to a confidentiality agreement; and at the Controller’s expense, unless the audit reveals a significant non-compliance attributable to MASAT.
10. Deletion or return of the data
At the end of the provision of services, MASAT will, at the Controller’s choice, return the data in a structured, commonly used, machine-readable format (the export function remains available in the application for 30 days after termination) and/or delete it.
- eMAG credentials: within a maximum of 30 days of disconnection;
- data retrieved from the eMAG account: within a maximum of 30 days of termination, or immediately on express request;
- backups: overwritten in the normal rotation cycle, within a maximum of 90 days.
MASAT may retain data only to the extent required by EU or Romanian law, principally accounting and tax documents, in which case it archives them with restricted access and solely for that purpose.
MASAT may retain and use aggregated and anonymised data that no longer allows identification of the Controller, its products or the data subjects.
11. International transfers
MASAT processes the data within the European Economic Area. Any transfer to a third country takes place only on the basis of an adequacy decision or the Standard Contractual Clauses approved by the European Commission, following an assessment of any supplementary measures required.
Sub-processors that process data outside the EEA are marked as such in the published list.
12. Liability
The liability of the parties under this Agreement is governed by Art. 82 GDPR and by the limitation of liability provisions in the Terms and Conditions, to the extent the law permits limitation.
13. Term, governing law and final provisions
This Agreement takes effect for the term of the contract between the parties and terminates together with it, except for those obligations which by their nature survive termination (confidentiality, deletion, audit).
This Agreement is governed by Romanian law. In the event of a conflict between this Agreement and the Terms and Conditions, this Agreement prevails in matters of personal data processing.
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
Access control. Individual authentication for every team member, with mandatory two-factor authentication; role-based access following the principle of least privilege; quarterly review of access rights; logging of administrative access to production systems.
Encryption. TLS 1.2+ for all communications; encryption of sensitive data at rest (AES-256); integration credentials stored in a separate secrets store with independently managed keys and periodic rotation.
Environment segregation. Separation of production, testing and development environments, with rules governing the use of real data outside production.
Availability and resilience. Regular encrypted backups, tested restore procedures, monitoring and alerting.
Secure development. Code review before deployment to production; dependency and vulnerability management; periodic security testing.
Organisational measures. Confidentiality undertakings signed by staff and collaborators; periodic data protection training; a documented incident response procedure with defined timeframes; a record of processing activities under Art. 30(2); and an assessment procedure for sub-processors prior to engagement.
Contact
S.C. MASAT DIGITAL S.R.L.
Ilfov County, Bragadiru, 59 Ghidiceni Street
E-mail: office@masat.ro
www.masat.ro