Data Processing Addendum, DPA
Last updated: August 2026
For customers subject to the GDPR or specific contractual data-protection requirements, OKTee can provide a Data Processing Addendum, DPA.
The DPA governs the processing of personal data carried out by OKTee on behalf of its customers in connection with the subscribed services. Other operational or commercial data processed by the platform remains governed by the applicable contract, confidentiality commitments and OKTee security measures.
In this context, the customer generally acts as data controller and OKTee as data processor within the meaning of Article 28 GDPR. This qualification may differ where OKTee processes data for its own purposes, such as certain data relating to the commercial relationship or website administration.
What the OKTee DPA covers
The DPA covers processing carried out in connection with OKTee Operations, OKTee Finance and OKTee Marketing where those services involve personal data processed on behalf of the customer.
- subject matter, duration, nature and purpose of processing;
- types of personal data and categories of data subjects;
- documented customer instructions and limits on data use;
- confidentiality obligations for persons authorized to process data;
- technical and organizational security measures;
- access management, authentication and user permission controls;
- processing of Amazon Vendor Central data where access has been authorized by the customer;
- processing of data from customer systems, including ERP, WMS, APIs or product catalogs;
- engagement of sub-processors and customer information regarding changes;
- notification of security incidents and personal data breaches;
- assistance with data-subject requests and the customer’s GDPR obligations;
- deletion or return of data at the end of the services;
- information required to demonstrate compliance and audit rights under reasonable and contractually defined conditions.
Nature and purpose of processing
Depending on the enabled modules, OKTee may collect, receive, access, reconcile, structure, analyze, log, transmit or delete data in order to provide the authorized features.
Purposes may include retail-operations automation, order and logistics monitoring, performance analysis, financial-operations processing, data reconciliation, product-performance monitoring, alerts, recommendations and event logs.
Data concerned
The data actually processed depends on the modules enabled, integrations used and permissions granted by the customer.
- professional identification data of authorized users;
- connection, usage, security and logging data;
- organization data, roles and customer settings;
- catalog data and product references;
- order data, statuses, confirmations and order responses;
- inventory, availability, shipment and receipt data;
- pricing, offer, Buy Box or Featured Offer data where available and authorized;
- Brand Analytics data where available and authorized;
- financial data, invoices, payments, deductions, discrepancies, shortages or chargebacks where the corresponding access rights are granted;
- ERP, WMS, customer API or other internal data supplied by the customer to enable the reconciliations required by the services.
Categories of data subjects
Depending on the data made available by the customer, data subjects may include authorized platform users, the customer’s employees and professional contacts, and professional contacts whose data appears in documents, events or operational flows processed by OKTee.
Amazon data
OKTee may process certain data accessible through Amazon SP-API only where the customer has explicitly authorized the connection to its Amazon Vendor Central account and the required roles have been granted.
This data may be used for authorized OKTee Operations, Finance and Marketing features: operational automation, order monitoring, logistics, catalog and product analysis, financial monitoring, reconciliations, alerts, dashboards, recommendations and event logs.
OKTee does not sell Amazon data, share it for advertising purposes or use it for purposes independent from the services authorized by the customer.
Data from customer systems
OKTee may also process data from customer-authorized systems, including ERP, WMS, product catalogs, internal APIs, files or other connected sources.
This data may be used to reconcile retail-platform flows with internal references, inventory, logistics rules, automation settings, accounting data, invoicing data, payments, deductions or information required for financial reconciliations.
Customer instructions and confidentiality
Where OKTee acts as a processor, personal data is processed only on the customer’s documented instructions unless otherwise required by applicable law.
Persons authorized to access data for service delivery, support, maintenance or security are subject to appropriate confidentiality obligations and access only the information required for their responsibilities.
Sub-processors
OKTee uses technical providers to host, synchronize, monitor, secure and improve its services.
They may provide the public website, application interface, database services, synchronization workers, task orchestration, monitoring, cloud services, AI-assisted analysis, status-page services or collection of public product-page signals.
The current list is published on the Third-party vendors page. The DPA sets out the authorization and notification arrangements applicable to additions or replacements of sub-processors.
Transfers outside the European Union
Certain providers or technical services may involve data transfers outside the European Union.
Where required, OKTee ensures that such transfers are covered by a mechanism recognized under applicable data-protection law, including the European Commission Standard Contractual Clauses where relevant.
Additional provisions may be included where required by the customer’s situation or processing location, including for the United Kingdom or Switzerland.
Technical and organizational measures
OKTee applies measures designed to protect the confidentiality, integrity and availability of processed data, including:
- role-based access control and least-privilege principles;
- access limited to authorized users and personnel;
- logical separation of customer data;
- encryption of data in transit;
- protection of data at rest according to the infrastructure and configuration used;
- secure storage of secrets, technical keys and tokens;
- logging of important actions;
- application monitoring and error detection;
- separation of production, staging and development environments;
- limitation of data shared with providers to what is strictly necessary;
- security-incident management procedures;
- ability to revoke access to connected platforms where supported by those platforms.
Security measures are further described on the Trust & Security page and may be supplemented contractually in the DPA or its annexes.
Customer assistance and data-subject rights
Where requests relate to data processed on behalf of the customer, OKTee provides reasonable assistance to enable the controller to respond to requests for access, rectification, erasure, restriction, portability or objection where those rights apply.
OKTee also provides reasonable assistance regarding data-protection impact assessments, prior consultations or other controller obligations where the nature of the processing and the information available to OKTee permit.
Incident notification
In the event of a personal data breach affecting data processed on behalf of a customer, OKTee informs the customer without undue delay after becoming aware of it and targets a maximum initial notification period of 48 hours.
OKTee then provides the information reasonably available to help the customer assess the impact and meet its own regulatory obligations. Where the GDPR requires notification to a supervisory authority, that obligation remains with the entity acting as data controller.
Deletion or return of data
At the end of the contractual relationship, personal data processed on behalf of the customer is deleted or returned according to the applicable contract and DPA, unless applicable law requires its retention.
Certain technical data or logs may be retained for a limited period where required for security, evidence, dispute management or compliance with a legal or contractual obligation.
Audit and demonstration of compliance
OKTee makes available the information reasonably required to demonstrate compliance with its processor obligations. The DPA may also provide for audit, security-questionnaire or documentary-review arrangements under conditions designed to protect security, other customers’ confidentiality and normal operation of the service.
How to obtain the OKTee DPA
To obtain the OKTee DPA, please send a request to:
Please specify:
- the name of your legal entity;
- the address of your registered office;
- the name and email address of your legal, GDPR or DPO contact;
- where applicable, contractual or data-transfer constraints specific to your organization.
OKTee will provide the applicable version of the DPA and any relevant annexes as soon as reasonably possible.
Already a customer?
If you are already an OKTee customer, the DPA may be attached to your existing contract. You may contact your usual OKTee representative or write directly to legal@oktee.io.
OKTee does not sell customer data, does not share Amazon data for advertising purposes and uses processed data only within the services and instructions authorized by the customer.
Contact
See also: Privacy Policy · Third-party vendors · Trust & Security · Amazon Integration
Signed DPA