Data Processing Agreement
This data processing agreement applies to every Agreement between The integrators B.V., with its registered office in Amersfoort, the Netherlands, CoC 64731464 (Processor), and its client (Controller) under which Processor processes personal data on behalf of Controller. It forms part of the Agreement and of Processor's Terms and Conditions. On request, the parties will sign a copy.
Article 1 – Definitions
Terms from the General Data Protection Regulation (GDPR), such as personal data, processing and data subject, have the meaning given to them in the GDPR. Capitalized terms not defined here have the meaning given to them in the Terms and Conditions. In addition:
- Data Breach: a personal data breach as referred to in Article 4(12) GDPR.
- Sub-processor: another processor engaged by Processor to process the personal data.
Article 2 – Subject matter and instructions
2.1Processor processes the personal data only on behalf of Controller and on the basis of Controller's instructions In Writing, as set out in the Agreement and this data processing agreement, unless a legal provision applicable to Processor requires otherwise. In that case, Processor informs Controller in advance, unless the law prohibits this.
2.2The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
2.3Processor immediately informs Controller if, in its opinion, an instruction infringes the GDPR or other data protection law. Processor is not obliged to review instructions legally.
2.4Controller warrants that the processing is lawful, including that there is a valid legal basis and that data subjects have been informed, and indemnifies Processor against claims by third parties and supervisory authorities relating to a breach of this warranty.
Article 3 – Confidentiality
Processor ensures that persons who process personal data under its authority are bound by confidentiality.
Article 4 – Security
4.1Processor takes appropriate technical and organizational measures as referred to in Article 32 GDPR. An overview is set out in Annex 2.
4.2Controller has assessed these measures and considers them appropriate. Processor may change the measures, provided the level of security does not materially decrease.
4.3Processor does not guarantee that the security is effective under all circumstances.
Article 5 – Sub-processors
5.1Controller gives Processor general authorization In Writing to engage Sub-processors. The Sub-processors engaged when this data processing agreement is entered into are listed in Annex 3.
5.2Processor informs Controller in advance of any intended addition or replacement of Sub-processors. Controller may object In Writing on reasonable grounds within fourteen days. If the parties cannot agree on a solution, Controller may terminate the part of the Services concerned; this is its sole remedy.
5.3Processor imposes on Sub-processors at least the same data protection obligations as those set out in this data processing agreement.
Article 6 – Location and transfers
Processor processes the personal data within the European Economic Area, in principle in the Netherlands. Transfers to a country outside the EEA only take place with appropriate safeguards as referred to in Chapter V GDPR.
Article 7 – Assistance
- responding to requests from data subjects exercising their rights;
- complying with the obligations under Articles 32 to 36 GDPR (security, notification of Data Breaches, data protection impact assessments and prior consultation).
7.2Requests from data subjects that Processor receives directly are forwarded to Controller.
7.3Processor may charge reasonable costs for assistance at the applicable rates.
Article 8 – Data Breaches
8.1Processor notifies Controller without undue delay after becoming aware of a Data Breach affecting the personal data, and aims to do so within 48 hours.
8.2Insofar as known, Processor provides information on the nature of the Data Breach, the categories of data and data subjects concerned, the likely consequences and the measures taken or proposed.
8.3Notifying a Data Breach to the supervisory authority and to data subjects is the responsibility of Controller.
Article 9 – Information and audits
9.1Processor makes available to Controller all information necessary to demonstrate compliance with Article 28 GDPR.
9.2Controller may have compliance audited at most once a year, or after a Data Breach, by an independent expert bound by confidentiality. An audit is announced at least four weeks in advance and carried out during business hours, without disproportionately disrupting Processor's operations.
9.3The costs of an audit, including Processor's reasonable costs, are borne by Controller, unless the audit reveals a material failure on the part of Processor.
Article 10 – Term and termination
10.1This data processing agreement applies for as long as Processor processes personal data on behalf of Controller.
10.2After the Agreement ends, Processor deletes or returns the personal data, at Controller's choice. If Controller does not choose within thirty days, Processor deletes the data. This does not apply insofar as Processor is legally required to retain it. Backups are deleted in accordance with the regular backup cycle.
10.3Data is returned in a common format. Processor may charge the reasonable costs of doing so.
Article 11 – Liability
11.1Processor's liability under or in connection with this data processing agreement is limited as set out in Article 10 of the Terms and Conditions. The Agreement and this data processing agreement are treated as a single whole; the limitations do not apply separately.
11.2Fines and penalty payments imposed on Controller are not borne by Processor, except in case of intent or deliberate recklessness on the part of Processor's management.
Article 12 – Final provisions
12.1In case of conflict between this data processing agreement and the Agreement or the Terms and Conditions, this data processing agreement prevails, solely with regard to the processing of personal data.
12.2This data processing agreement is governed by Dutch law. Disputes are submitted exclusively to the competent court of the District Court of Midden-Nederland.
Annex 1 – Description of the processing
Unless otherwise specified in the Agreement:
| Subject matter and nature | Hosting, storage, management, development, maintenance and support of software, systems and infrastructure, as described in the Agreement. |
|---|---|
| Purpose | Solely providing the Services under the Agreement. |
| Types of personal data | The personal data that Controller or its users have processed using the Services, such as names and contact details, account and login details, IP addresses, log data and other content. Controller does not have special categories of personal data or criminal-offense data processed without notifying Processor In Writing in advance. |
| Categories of data subjects | Employees, customers, end users, website visitors and other contacts of Controller. |
| Duration | The term of the Agreement. |
| Location | The Netherlands. |
Annex 2 – Security measures
Processor takes at least the following measures:
- Physical: infrastructure in a locked datacenter in the Netherlands with access control; only authorized persons have access.
- Access: access to systems and data on a need-to-know basis, with personal accounts and strong authentication for administrative access.
- Network: firewalls and network segmentation; encrypted connections for data transport and administration.
- Operations: timely security updates; logging and monitoring of systems.
- Continuity: backups and recovery procedures, where agreed.
- Organization: confidentiality obligations for staff and a procedure for handling incidents and Data Breaches.
Annex 3 – Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| iPublications B.V., Amersfoort (CoC 32115766), sole shareholder of Processor | Datacenter and infrastructure services | The Netherlands |
Additional Sub-processors for specific Services are listed in the Agreement.