Let op: Onze Verwerkersovereenkomst is op dit moment alleen beschikbaar in het Engels. Een Nederlandse vertaling volgt. Voor vragen over deze tekst kunt u contact opnemen via info@vakwerksysteem.nl.
(Verwerkersovereenkomst)
This Data Processing Agreement ("DPA") forms an integral part of the Service Agreement between VakWerkSysteem and the Client (hereinafter referred to as the "Main Agreement").
Article 1: Definitions
Terms used in this DPA have the same meaning as defined in the Main Agreement. Additionally:
1.1. Personal Data: Any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
1.2. Processing: Any operation performed on Personal Data, as defined in Article 4(2) of the GDPR.
1.3. Data Controller: The Client, who determines the purposes and means of processing Personal Data.
1.4. Data Processor: VakWerkSysteem, who processes Personal Data on behalf of the Data Controller.
1.5. Sub-processor: A third party engaged by the Data Processor to process Personal Data on behalf of the Data Controller.
1.6. Data Subject: The identified or identifiable natural person to whom the Personal Data relates.
1.7. Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
1.8. GDPR: Regulation (EU) 2016/679 (General Data Protection Regulation), also known in the Netherlands as the AVG (Algemene Verordening Gegevensbescherming).
Article 2: Scope and Purpose of Processing
2.1. VakWerkSysteem processes Personal Data exclusively on behalf of and under the instructions of the Client, for the purpose of providing the Services described in the Main Agreement.
2.2. Categories of Data Subjects whose data may be processed:
- Customers and potential customers (leads) of the Client
- Individuals who submit contact forms on the Client's Website
- Individuals who respond to missed call SMS messages
- Individuals who submit reviews or feedback
2.3. Categories of Personal Data that may be processed:
- Full name
- Email address
- Phone number
- Physical address (street, city, postal code, country)
- Messages and communication content
- Review ratings and feedback text
- SMS communication records
- Lead status and activity history
2.4. Processing activities include:
- Storage and management of lead/customer data
- Sending SMS messages (missed call handling, review requests, quote reminders)
- Sending email messages (review requests, quote reminders)
- Collecting and storing customer reviews and feedback
- Generating usage reports and analytics for the Client
- Error and performance monitoring of the Platform (limited to technical diagnostic data; see Article 6)
Article 3: Duration
3.1. This DPA takes effect on the same date as the Main Agreement and remains in force for the duration of the Main Agreement.
3.2. Upon termination of the Main Agreement, the provisions regarding data return and deletion (Article 9) continue to apply.
Article 4: Obligations of VakWerkSysteem (Data Processor)
4.1. VakWerkSysteem will:
- a) Process Personal Data only on documented instructions from the Client, including with regard to transfers of Personal Data to a third country, unless required to do so by EU or Member State law.
- b) Ensure that persons authorized to process Personal Data are bound by confidentiality obligations.
- c) Take all measures required pursuant to Article 32 of the GDPR (security of processing).
- d) Respect the conditions for engaging Sub-processors as set out in Article 6.
- e) Assist the Client, taking into account the nature of processing, in responding to requests from Data Subjects exercising their rights under the GDPR.
- f) Assist the Client in ensuring compliance with the obligations related to security of processing, notification of Data Breaches, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to VakWerkSysteem.
- g) At the choice of the Client, delete or return all Personal Data after the end of the provision of Services, and delete existing copies unless EU or Member State law requires storage.
- h) Make available to the Client all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.
Article 5: Security Measures
5.1. VakWerkSysteem implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Technical measures:
- a) Encryption of data in transit (TLS/SSL)
- b) Encryption of data at rest
- c) Access controls and authentication (role-based access)
- d) Row-Level Security (RLS) ensuring data isolation between Clients
- e) Regular security updates and patches
- f) Secure hosting infrastructure
Organizational measures:
- g) Limiting access to Personal Data to authorized personnel only
- h) Confidentiality obligations for all personnel with access to Personal Data
Article 6: Sub-processors
6.1. The Client grants VakWerkSysteem general authorization to engage Sub-processors for the processing of Personal Data, subject to the conditions in this article.
6.2. As of the date of this agreement, VakWerkSysteem uses the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database hosting, authentication, and data storage | EU (Frankfurt, Germany) |
| Twilio Inc. | SMS message delivery | USA (EU data processing available) |
| Hetzner Online GmbH | Website and application hosting | EU (Germany) |
| Functional Software, Inc. (Sentry) | Error and performance monitoring; limited session replay with default text masking. PII collection is disabled in our SDK configuration. | USA (data ingested via Sentry EU region, Frankfurt, Germany) |
6.3. VakWerkSysteem will inform the Client in writing of any intended changes concerning the addition or replacement of Sub-processors, giving the Client the opportunity to object to such changes. The Client must object within 14 days of being notified. If the Client objects, VakWerkSysteem will make reasonable efforts to make available an alternative solution. If no alternative is available, either party may terminate the Main Agreement.
6.4. VakWerkSysteem ensures that each Sub-processor is bound by data protection obligations no less protective than those set out in this DPA.
6.5. VakWerkSysteem remains fully liable for the performance of its Sub-processors' obligations.
Article 7: Data Breach Notification
7.1. VakWerkSysteem will notify the Client of a Data Breach without undue delay and in any event within 72 hours after becoming aware of the breach.
7.2. The notification will include, at minimum:
- a) A description of the nature of the Data Breach, including where possible, the categories and approximate number of Data Subjects and data records concerned.
- b) The name and contact details of VakWerkSysteem's contact point for further information.
- c) A description of the likely consequences of the Data Breach.
- d) A description of the measures taken or proposed to address the Data Breach, including measures to mitigate its possible adverse effects.
7.3. VakWerkSysteem will cooperate with the Client and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Data Breach.
7.4. The Client is responsible for determining whether the Data Breach must be reported to the supervisory authority (Autoriteit Persoonsgegevens) and/or the Data Subjects.
Article 8: Data Subject Rights
8.1. VakWerkSysteem will assist the Client in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under the GDPR, including:
- a) Right of access (Article 15 GDPR)
- b) Right to rectification (Article 16 GDPR)
- c) Right to erasure / right to be forgotten (Article 17 GDPR)
- d) Right to restriction of processing (Article 18 GDPR)
- e) Right to data portability (Article 20 GDPR)
- f) Right to object (Article 21 GDPR)
8.2. If VakWerkSysteem receives a request directly from a Data Subject, VakWerkSysteem will promptly forward the request to the Client, unless VakWerkSysteem is legally required to respond directly.
8.3. The Client can exercise certain Data Subject rights directly through the Platform's functionality (e.g., viewing, editing, or deleting lead data).
Article 9: Data Return and Deletion
9.1. Upon termination of the Main Agreement, the Client may request an export of their Personal Data within 30 days of the termination date. VakWerkSysteem will provide this export in a commonly used, machine-readable format (CSV or JSON).
9.2. After the 30-day period, or upon the Client's written confirmation that the data has been received, VakWerkSysteem will delete all Personal Data from its systems and those of its Sub-processors, unless:
- a) EU or Member State law requires further storage.
- b) The data has been anonymized and can no longer be linked to identifiable persons.
9.3. VakWerkSysteem will confirm the deletion in writing upon request from the Client.
Article 10: Audit Rights
10.1. The Client has the right to verify VakWerkSysteem's compliance with this DPA.
10.2. VakWerkSysteem will make available to the Client all information reasonably necessary to demonstrate compliance.
10.3. The Client may conduct an audit, or have an audit conducted by an independent third party bound by confidentiality, no more than once per year, with 30 days advance written notice, during regular business hours.
10.4. The costs of such an audit will be borne by the Client, unless the audit reveals material non-compliance by VakWerkSysteem.
Article 11: International Data Transfers
11.1. VakWerkSysteem will not transfer Personal Data to a country outside the European Economic Area (EEA) unless:
- a) The European Commission has decided that the third country ensures an adequate level of protection.
- b) Appropriate safeguards are in place (e.g., Standard Contractual Clauses).
- c) The transfer is otherwise permitted under the GDPR.
11.2. Where Sub-processors are based outside the EEA (e.g., Twilio Inc. and Functional Software, Inc. (Sentry) in the USA), VakWerkSysteem ensures that appropriate transfer mechanisms are in place in accordance with Chapter V of the GDPR. Sentry data is ingested via Sentry's EU region (Frankfurt, Germany) so that primary storage of error events remains within the EEA.
Article 12: Liability
12.1. The liability provisions of the Main Agreement (Article 12) apply to this DPA.
12.2. VakWerkSysteem is liable for damages caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to lawful instructions of the Client.
Signatures
This Data Processing Agreement is entered into as part of the Main Agreement.
VakWerkSysteem (Data Processor)
Name: ____________________________ Date: ____________________________ Signature: ____________________________
Client (Data Controller)
Name: ____________________________ Company: ____________________________ Date: ____________________________ Signature: ____________________________