Data processing agreement
Version 1 (draft) — not yet in effect
This agreement is part of the terms of use. It applies when your gallery records personal data about collectors in Pastil. For that data, the gallery is the controller and Pastil the processor (GDPR, art. 28).
1. What is processed
- Data subjects: collectors and prospective buyers of the gallery.
- Data: name, email, phone, the gallery's notes, the works they hold, bought or asked about, prices and deposits.
- Purpose: letting the gallery record holds, sales and interest at art fairs and follow up afterwards.
- Duration: as long as the gallery keeps the data in Pastil.
The gallery shouldn't record special categories of data (health, political opinions and the like, art. 9) in the notes.
2. Instructions
Pastil processes collector data only to provide the service, as the gallery uses it, and on the gallery's documented instructions, which are these terms and its use of the app. If an instruction seems to break the GDPR, Pastil says so.
3. Confidentiality
Only the people running Pastil can reach the data, only when the service needs it (support the gallery asked for, an incident), and they are bound to confidentiality.
4. Security
The measures in Annex 1 protect the data. Pastil keeps them up to date with the state of the art.
5. Sub-processors
The gallery authorises the sub-processors in Annex 2. Pastil will give 30 days' notice before adding or replacing one, and the gallery may object; if no solution is found, the gallery may close its account. Each sub-processor is bound by obligations at least as protective as these.
6. Helping the gallery
Pastil helps the gallery answer collectors exercising their rights:
- Access and portability: the collectors list exports as CSV.
- Rectification: any collector can be edited.
- Erasure: erasing a collector deletes their details and interest for good; works they bought stay sold, without their name.
A request that reaches Pastil directly is passed on to the gallery without undue delay. Pastil also helps with security, impact assessments and prior consultations where the GDPR asks, as far as it can.
7. Data breaches
Pastil tells the gallery of a personal data breach without undue delay, and within 48 hours of learning of it, with what is known and what is being done.
8. End of the service
When the gallery is deleted, its collector data is deleted with it. The gallery can export it first. Backups roll over within a few weeks.
9. Audits
Pastil makes available what the gallery needs to check these obligations are met, and allows reasonable audits, announced 30 days ahead, at the gallery's cost.
Annex 1. Security measures
- Encryption in transit (TLS) and at rest (database and storage).
- Each gallery's data is reached only through checks that the signed-in user belongs to it, with their role; tested automatically.
- Passwords hashed; passkeys and two-factor authentication available; sign-in rate-limited.
- The database is hosted in the EU (Frankfurt) with point-in-time backups.
Annex 2. Sub-processors
| Sub-processor | Service | Location | | --- | --- | --- | | Neon | database and storage | Frankfurt, Germany | | Vercel | hosting | EU and USA (standard contractual clauses) | | Upstash | live updates, which carry work titles and statuses, not collector data | to be confirmed |
