Skip to main content

Bidlogix Data Processing Agreement

Written by Adam Taylor

Version 1.0 · Effective 24th September

This Data Processing Agreement ("DPA") forms part of the Bidlogix Customer Terms of Service (the "Terms") between:

  • Bidlogix Limited, a company registered in England and Wales with company number 06617738, whose registered office is at 168 Church Road, Hove, England, BN3 2DL ("Bidlogix", the "Processor"); and

  • the person or entity identified as the Customer in the applicable account record, online subscription process or Order (the "Customer", the "Controller").

It applies automatically when the Customer accepts the Terms and does not need to be signed. Customers who need a signed copy can request one from [email protected].


1. Definitions

In this DPA:

  • "Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, Regulation (EU) 2016/679 (the "EU GDPR") where applicable, and any other law relating to the processing of personal data that applies to either party.

  • "Personal Data", "Processing", "Data Subject", "Controller", "Processor" and "Personal Data Breach" have the meanings given in the Data Protection Laws. "Personal Data" means only the personal data processed by Bidlogix on behalf of the Customer under the Terms, as described in Schedule 1.

  • "Services" has the meaning given in the Terms.

  • "Sub-processor" means any third party engaged by Bidlogix to process Personal Data on behalf of the Customer.

  • "Hosting Location" means the Amazon Web Services region in the United Kingdom or the European Economic Area in which the Customer's application is hosted, as confirmed to the Customer by Bidlogix on request.

2. Relationship with the Terms

  1. This DPA forms part of the Terms and replaces clause 4.5 of the Terms.

  2. References in the Terms to the Data Protection Act 1998 are to be read as references to the Data Protection Laws.

  3. The Customer's authorisation of Sub-processors under clause 6 of this DPA is its prior written consent to that subcontracting for the purposes of clause 13.5 of the Terms.

  4. If there is any conflict between this DPA and the Terms in relation to the processing of Personal Data, including clause 11.4.3 of the Terms (Customer Data on termination), this DPA prevails. In all other respects the Terms continue in full force and effect.

3. Roles and responsibilities

  1. The Customer is the controller and Bidlogix is the processor of the Personal Data.

  2. The Customer is responsible for having a lawful basis for the processing, for giving Data Subjects appropriate privacy information, and for obtaining and recording any consents it relies on, including consent to marketing and to data analytics or profiling. The Services provide the means for Data Subjects to give and withdraw these consents, and for the Customer to view and export them.

  3. The details of the processing are set out in Schedule 1.

4. Processor obligations

Bidlogix shall:

  1. process the Personal Data only on the Customer's documented instructions, including those in the Terms and this DPA, unless required to do otherwise by law, in which case it shall inform the Customer before processing unless the law prohibits this;

  2. promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Laws;

  3. ensure that everyone authorised to process the Personal Data is bound by a duty of confidentiality;

  4. implement and maintain the technical and organisational measures set out in Schedule 2;

  5. ensure that any copy of production data used for development or testing is anonymised before it is loaded into any local or staging environment; and

  6. taking into account the nature of the processing and the information available to it, provide reasonable assistance to the Customer in meeting its obligations under Articles 32 to 36 of the UK GDPR and EU GDPR.

5. Location of processing and international transfers

  1. Bidlogix shall host and store all production Personal Data in the Hosting Location. The only exceptions are the limited data passed to the Sub-processors in Part A of Schedule 3 to perform their stated function (such as the recipient details and content of system emails), and incidental support access under clause 5.2.

  2. Bidlogix shall not place Personal Data in the support, communication or collaboration tools listed in Part B of Schedule 3 except to the minimum extent necessary to deal with a support request, fault or incident, and shall remove it once it is no longer needed for that purpose.

  3. Bidlogix shall not transfer Personal Data, or permit it to be accessed, outside the United Kingdom and the European Economic Area without appropriate safeguards under Data Protection Laws. The Customer consents to the limited transfers to the Sub-processors identified in Schedule 3, made under the safeguards stated there.

  4. Bidlogix is established in the United Kingdom, and authorised Bidlogix personnel may access Personal Data remotely from the United Kingdom for support, maintenance and incident response. The United Kingdom benefits from an adequacy decision of the European Commission under Article 45 of the EU GDPR.

6. Sub-processors

  1. The Customer gives general authorisation for Bidlogix to engage the Sub-processors listed in Schedule 3 of this DPA.

  2. Bidlogix shall give at least 30 days' notice before adding or replacing a Sub-processor, by updating Schedule 3 on this page and notifying the Customer by email. The Customer may object on reasonable data protection grounds within that period, and the parties shall discuss the objection in good faith. If they cannot resolve it, the Customer may terminate the affected Services without penalty.

  3. Bidlogix shall impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable to the Customer for each Sub-processor's performance of those obligations.

7. Data Subject rights

  1. If Bidlogix receives a request from a Data Subject exercising their rights, it shall not respond directly (other than to refer the Data Subject to the Customer) and shall forward the request to the Customer without undue delay.

  2. Bidlogix shall provide reasonable assistance to the Customer in responding to Data Subject requests. The Services allow the Customer's administrators to view, edit and export user data.

  3. For erasure requests, once the Customer has verified and approved the request it shall send a written request from an administrator account to [email protected] giving the Data Subject's username and email address, the date of their request, and confirmation that the Customer no longer needs the data. Bidlogix shall, within 30 days of receiving the request, anonymise all information that could identify the Data Subject, lock the account and confirm completion in writing. Non-identifying transactional records (such as bid and sales history) are kept so that the Customer's financial records remain accurate, but can no longer be linked to the individual.

8. Personal Data Breaches

  1. Bidlogix manages security incidents under its Data Security Breach Incident Management Policy, which covers confirmed and suspected breaches, severity assessment, containment and recovery, risk assessment, notification and post-incident review, with all actions logged centrally.

  2. Bidlogix shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a confirmed or reasonably suspected Personal Data Breach affecting the Personal Data, whatever its assessed severity.

  3. The notice shall include, as far as is then known, a description of the breach, when and how it was identified, whether it is confirmed or suspected and contained or ongoing, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not yet available shall be provided in phases without further undue delay.

  4. Bidlogix shall take reasonable steps to contain and remedy the breach and shall cooperate with the Customer in any investigation, notification to supervisory authorities or communication to Data Subjects. Bidlogix shall not notify a supervisory authority or Data Subjects about a breach of the Personal Data on the Customer's behalf without the Customer's prior agreement, unless required by law.

  5. The Customer may report a suspected breach to the Bidlogix service desk on +44 (0)845 056 1277 or at [email protected].

9. Audit and information

  1. Bidlogix shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, including relevant security certifications and policies.

  2. Where that information is not reasonably sufficient, the Customer (or an independent auditor bound by confidentiality) may carry out an audit no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours and at the Customer's own cost, in a way that minimises disruption to Bidlogix's business. This limit does not apply following a Personal Data Breach or where required by a supervisory authority.

10. Return and deletion

  1. During the term of the Terms the Customer may export its user data at any time using the Services' export functions.

  2. On termination or expiry of the Terms, Bidlogix shall, at the Customer's choice, return the Personal Data in a commonly used format or make it available for export for 30 days. After that period, Bidlogix shall delete or irreversibly anonymise the Personal Data within 90 days, except where retention is required by law. Personal Data held in backups shall be overwritten in line with Bidlogix's standard 30-day backup rotation and shall not be restored except as required by law.

11. Liability, term and changes

  1. Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms.

  2. This DPA remains in force for as long as Bidlogix processes Personal Data on behalf of the Customer.

  3. Bidlogix may update this DPA in accordance with the Terms. No update shall reduce the overall level of protection given to the Personal Data. Previous versions are available on request.

12. Governing law

This DPA and any dispute arising from it are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.


Schedule 1 — Details of the processing

Item

Details

Subject matter

Provision of the Services under the Terms.

Duration

The term of the Terms plus the return and deletion period in clause 10.

Nature of processing

Collection, storage, organisation, retrieval, use, disclosure to the Customer's administrators, anonymisation and deletion, carried out by automated means in the Hosting Location.

Purpose

Operating the Customer's online auction application: account registration and login, registration for auctions, bidding, notifications, invoicing and reporting, user support, security and service monitoring, and sending marketing or conducting analytics only where the Data Subject has consented.

Categories of Data Subject

Bidders and other users who register for or use the Customer's auction application; the Customer's administrative users.

Types of Personal Data

Account data: username, email address, password (stored only as a one-way hash), title and full name, preferred language, time zone. Contact data: postal address, daytime telephone number and, optionally, mobile and fax numbers. Business data (optional): company name and VAT number. Preferences: marketing consent and categories of interest, partner marketing consent, data analytics consent, notification and lot alert settings. Activity data: auction registrations and approval status, bids, purchases, invoices, and an audit log of system emails. Technical data: IP address, operating system, browser type, activity on application pages, and session authentication cookies.

Special category data

None is intended to be processed. The Customer shall not configure the Services to collect special category data or criminal offence data without agreeing this with Bidlogix in writing.

Schedule 2 — Technical and organisational measures

Bidlogix maintains the following measures, and may update them provided the overall level of security is not reduced:

  • Hosting: production systems and data hosted on Amazon Web Services in the Hosting Location, a provider holding ISO 27001, SOC 2 and related certifications.

  • Passwords: user passwords are stored only as one-way hashes, and are not visible to Bidlogix staff or the Customer's administrators.

  • Encryption in transit: all access to the Services is over HTTPS/TLS.

  • Encryption at rest: production databases, storage and backups are encrypted at rest.

  • Access control: tiered, role-based administrative permissions in the Services, so the Customer decides which of its staff can see user data; Bidlogix access to production is limited to authorised personnel on a need-to-know basis; two-factor authentication is required for staff email accounts.

  • Test data: all personally identifiable information is anonymised before any production data is loaded into a local or staging environment.

  • Erasure: documented anonymisation process with an audit trail recording when personal data was erased.

  • Audit trails: logging of system-generated emails sent to users and of administrative actions.

  • Backups and resilience: nightly backups, held within the Hosting Location and retained on a rolling 30-day basis.

  • Incident management: documented Data Security Breach Incident Management Policy with severity levels, named lead responsible officers, a containment and recovery checklist, and central logging of all incidents.

  • Personnel: staff bound by confidentiality obligations and given data protection awareness.

  • Security management: Bidlogix is implementing an information security management system with the aim of achieving ISO 27001 certification.

  • Registration: Bidlogix is registered with the UK Information Commissioner's Office (reference ZA458585).

Schedule 3 — Authorised Sub-processors

Part A — Sub-processors that host or process production Personal Data

Sub-processor

Purpose

Location of processing

Amazon Web Services EMEA SARL

Hosting, database, storage and backups for the Services

The Hosting Location (UK or EEA)

The Rocket Science Group LLC d/b/a Mailchimp (Mandrill / Mailchimp Transactional)

Sending transactional and notification emails to users (e.g. account activation, password reset, registration status, outbid and lot alerts, invoices). Receives recipient name and email address and the email content only

USA, under the EU–US Data Privacy Framework and its UK Extension, with Standard Contractual Clauses as a fallback under Mailchimp's Data Processing Addendum

Stripe Payments Europe Ltd

Collecting bidder deposits. Applies only where the Customer has enabled deposits; if deposits are not enabled, no Personal Data is passed to Stripe

EEA, with transfers to Stripe, Inc. (USA) under the EU–US Data Privacy Framework and Standard Contractual Clauses

Part B — Support and collaboration tools (incidental access only)

These tools do not host the Services. Personal Data may reach them only incidentally and to the minimum extent necessary when Bidlogix handles a support request, fault or incident, as described in clause 5.2.

Sub-processor

Purpose

Location and safeguards

Freshworks (Freshdesk)

Customer support ticketing

USA, under the EU–US Data Privacy Framework and its UK Extension, and Standard Contractual Clauses

Intercom

Help centre and support messaging

USA, under the EU–US Data Privacy Framework and its UK Extension, and Standard Contractual Clauses

Atlassian (Jira)

Fault and bug tracking

United Kingdom (covered by the EU adequacy decision for the UK)

Slack

Internal communication about support and incidents

USA, under the EU–US Data Privacy Framework and its UK Extension, and Standard Contractual Clauses

Google (Google Workspace / Drive)

Email and document storage, e.g. data exports provided at the Customer's request

United Kingdom (covered by the EU adequacy decision for the UK)

Zoom

Support calls, which may include screen sharing

USA, under the EU–US Data Privacy Framework and its UK Extension, and Standard Contractual Clauses

Did this answer your question?