This data processing agreement is mandatory under the GDPR when we process personal data on behalf of your company.
Parties
This data processing agreement is entered into between:
- The Controller: the party using LimeDesk's services (you, as the customer).
- The Processor: LimeDesk (KvK: 99420929).
Article 1 — Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, such as collecting, storing, altering, consulting or destroying.
- Data subject: the natural person to whom the personal data relates.
- Data breach: a breach of security leading to the destruction, loss, alteration or unauthorized access to personal data.
Article 2 — Subject matter and duration
This agreement relates to the processing of personal data by the Processor for the purpose of the AI assistant services. The agreement remains in effect for as long as the Processor processes personal data on behalf of the Controller.
Upon termination, all personal data will be deleted within 90 days, unless otherwise legally required.
Article 3 — Data processed
| Category | Examples |
|---|---|
| Contact details | Name, email address, phone number |
| Communication content | Chat conversations, email content, questions |
| Technical data | IP address, browser type, time of contact |
Article 4 — Obligations of the Processor
- Process personal data solely on the basis of written instructions from the Controller.
- Ensure that persons with access are bound by confidentiality.
- Implement appropriate technical and organizational security measures.
- Not engage subprocessors without prior written consent.
- Assist the Controller with requests from data subjects.
- Delete or return all personal data upon completion.
- Make all information available for compliance audits.
Article 5 — Security measures
- SSL/TLS encryption for all data transfer.
- Encryption of stored data (AES-256).
- Access control with strong authentication.
- Regular backups and disaster recovery.
- Logging and monitoring of access.
- Hosting within the European Union.
Article 6 — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| OpenAI | AI processing of messages* | United States |
| Mollie | Payment processing | Netherlands |
| TransIP | Hosting of the server (VPS) and email | Netherlands |
* With appropriate safeguards based on the EU Standard Contractual Clauses (SCCs).
Article 7 — Data breaches
The Processor will notify the Controller of a data breach within 24 hours, including its nature, affected data subjects, consequences and measures taken.
Article 8 — Rights of data subjects
The Processor assists the Controller in handling GDPR requests (access, rectification, erasure, restriction, portability, objection).
Article 9 — Audit
The Controller has the right to conduct audits to verify compliance.
Article 10 — Liability
Liability is limited to the amount paid by the Controller in the 12 months preceding the event.
Article 11 — Final provisions
- Dutch law applies.
- Disputes will be submitted to the court in Amsterdam.
- Changes are only valid in writing.
Questions? Contact us at info@limedesk.ai or via the contact page.