Translation notice: This is an English translation provided for convenience. The original Dutch version is legally binding. In case of any discrepancy, the Dutch text prevails. View the Dutch original →

Parties

This data processing agreement is entered into between:

Article 1 — Definitions

Article 2 — Subject matter and duration

This agreement relates to the processing of personal data by the Processor for the purpose of the AI assistant services. The agreement remains in effect for as long as the Processor processes personal data on behalf of the Controller.

Upon termination, all personal data will be deleted within 90 days, unless otherwise legally required.

Article 3 — Data processed

Article 4 — Obligations of the Processor

  1. Process personal data solely on the basis of written instructions from the Controller.
  2. Ensure that persons with access are bound by confidentiality.
  3. Implement appropriate technical and organizational security measures.
  4. Not engage subprocessors without prior written consent.
  5. Assist the Controller with requests from data subjects.
  6. Delete or return all personal data upon completion.
  7. Make all information available for compliance audits.

Article 5 — Security measures

Article 6 — Subprocessors

* With appropriate safeguards based on the EU Standard Contractual Clauses (SCCs).

Article 7 — Data breaches

The Processor will notify the Controller of a data breach within 24 hours, including its nature, affected data subjects, consequences and measures taken.

Article 8 — Rights of data subjects

The Processor assists the Controller in handling GDPR requests (access, rectification, erasure, restriction, portability, objection).

Article 9 — Audit

The Controller has the right to conduct audits to verify compliance.

Article 10 — Liability

Liability is limited to the amount paid by the Controller in the 12 months preceding the event.

Article 11 — Final provisions