DATA PROCESSING AGREEMENT ARVID.NL

This is an English translation provided for convenience. The Dutch version is legally binding.

Supplementary arrangements regarding the processing of personal data within the services of ARVID.NL.

This data processing agreement applies to all forms of processing of personal data that Arvid de Jong, trading as ARVID.NL and DARVIS, established at Het Nieuwe Diep 33, 1781 AD in Den Helder and registered with the Chamber of Commerce (KvK) under number 60299703, carries out on behalf of a client or counterparty to whom services are provided, hereinafter referred to as: the controller.

Article 1. Purposes of processing

1.1. ARVID.NL processes personal data solely on the instructions of the controller and only to the extent necessary for the provision, management, maintenance, support and security of the agreed services.

1.2. Processing takes place solely in the context of the performance of the main agreement, activities reasonably related thereto and any additional written instructions of the controller, insofar as these are compatible with the services of ARVID.NL.

1.3. The categories of personal data and data subjects covered by this data processing agreement are set out in Annex 1. The controller remains responsible for the accuracy, lawfulness and proportionality of the data supplied.

1.4. The personal data to be processed on the instructions of the controller remain the property of the controller and/or the data subjects concerned.

Article 2. Obligations of ARVID.NL

2.1. In processing personal data, ARVID.NL complies with the applicable laws and regulations, including the General Data Protection Regulation (GDPR).

2.2. On request, ARVID.NL informs the controller of the technical and organisational measures taken, insofar as this can reasonably be required of ARVID.NL and does not disclose confidential security information of other clients or systems.

2.3. Persons who process personal data under the responsibility of ARVID.NL are bound by appropriate confidentiality obligations.

2.4. If ARVID.NL is of the opinion that an instruction of the controller infringes applicable privacy legislation or conflicts with the agreed services, ARVID.NL will report this as soon as possible.

2.5. Insofar as reasonably possible and appropriate within the services, ARVID.NL cooperates with requests relating to data protection impact assessments and other privacy obligations of the controller.

2.6. Insofar as required by law, ARVID.NL maintains a record of the categories of processing activities carried out on behalf of the controller.

Article 3. Transfer of personal data

3.1. ARVID.NL in principle processes personal data within the European Union or the European Economic Area.

3.2. If a transfer outside the European Union or EEA is necessary for the performance of the services, ARVID.NL may do so only in compliance with the applicable statutory safeguards.

Article 4. Allocation of responsibility

4.1. The controller determines the purpose and means of the processing of personal data. ARVID.NL processes personal data solely on behalf of the controller and in accordance with its instructions, insofar as these fall within the agreed services.

4.2. The controller remains responsible for the lawful basis of the processing, the content of the personal data, the provision of information to data subjects and the assessment of whether a particular processing operation is permitted.

4.3. ARVID.NL is not responsible for processing that takes place outside its systems or outside the agreed services, including processing by the controller itself or by third parties engaged by it.

Article 5. Engagement of third parties and sub-processors

5.1. The controller hereby grants ARVID.NL general authorisation to engage third parties or sub-processors, insofar as reasonably necessary for hosting, infrastructure, security, back-up, email, monitoring, support or other parts of the services.

5.2. ARVID.NL ensures that such sub-processors are contractually bound to an appropriate level of personal data protection that is essentially equivalent to this data processing agreement.

5.3. Upon reasonable request, ARVID.NL can indicate which categories of sub-processors are used. ARVID.NL is not obliged to provide agreements with sub-processors in full where these contain confidential business information.

Article 6. Security

6.1. ARVID.NL takes appropriate technical and organisational measures to protect personal data against loss and unlawful processing, taking into account the state of the art, the nature of the services, the sensitivity of the data and the associated costs.

6.2. ARVID.NL gives no absolute guarantee that the security will be effective under all circumstances. The controller acknowledges that information security depends on several factors, including correct use of systems, up-to-date management and careful user behaviour.

6.3. The controller will only provide personal data to ARVID.NL if it has satisfied itself that this is necessary and permitted and that the agreed measures are appropriate for the intended use.

Article 7. Personal data breach notification obligation

7.1. The controller is responsible for assessing whether a security incident must be reported to the supervisory authority or to data subjects.

7.2. ARVID.NL will inform the controller without undue delay as soon as it has become aware of a personal data breach relating to personal data processed by it on behalf of the controller.

7.3. Insofar as available, ARVID.NL will in doing so provide information on the nature of the incident, the likely impact and the containment measures already taken or proposed.

7.4. ARVID.NL documents personal data breaches to the extent and in the manner required by law.

Article 8. Requests from data subjects

8.1. If ARVID.NL receives a request from a data subject relating to personal data that are processed on behalf of the controller, ARVID.NL will forward this request to the controller, unless ARVID.NL is legally obliged to act otherwise.

Article 9. Secrecy and confidentiality

9.1. All personal data that ARVID.NL receives from the controller or processes on its instructions are subject to a duty of confidentiality.

9.2. This duty of confidentiality does not apply insofar as disclosure is necessary for the performance of the agreement, is required by law or takes place with the consent of the controller.

Article 10. Audit

10.1. The controller may, solely in the event of a specific and substantiated suspicion of non-compliance, have an audit carried out with regard to compliance with this data processing agreement.

10.2. An audit must be announced in writing at least 30 days in advance, takes place during regular office hours and may not unreasonably disrupt the business operations of ARVID.NL.

10.3. ARVID.NL may replace an audit by providing relevant audit reports, certifications or other objective information, if this reasonably meets the same information need.

10.4. The costs of the audit, including internal time spent by ARVID.NL on additional support that goes beyond normal cooperation, shall be borne by the controller.

Article 11. Liability

11.1. The liability of ARVID.NL in connection with this data processing agreement is limited to direct damage and amounts per event to no more than the amount invoiced to the controller for the services concerned in the three months preceding the event giving rise to the damage, with an absolute maximum of €500.

11.2. Direct damage shall consist solely of reasonable costs of establishing the damage and liability, reasonable costs of limiting direct damage and reasonable costs of remedying the shortcoming of ARVID.NL, insofar as these can be attributed to ARVID.NL.

11.3. Indirect damage, consequential damage, loss of profit, loss of data, reputational damage and third-party claims are excluded, unless there is intent or deliberate recklessness on the part of the management of ARVID.NL.

11.4. Any claim for damages lapses if the controller does not give ARVID.NL written notice of default without delay and as completely as possible, and does not offer a reasonable period to remedy the shortcoming, unless performance is permanently impossible.

11.5. Any claim lapses no later than twelve months after the controller has become aware of the damage and the possible liability of ARVID.NL.

Article 12. Term and termination

12.1. This data processing agreement applies for as long as ARVID.NL processes personal data on the instructions of the controller in the context of the main agreement.

12.2. After termination of the services, ARVID.NL will delete personal data or render it inaccessible, unless storage is required by law or remains technically necessary for a reasonable transition or back-up period.

12.3. If the controller requests the return of personal data in good time before termination, ARVID.NL will cooperate insofar as this is technically possible and falls within the agreed services. Additional work may be charged separately.

12.4. ARVID.NL may update this data processing agreement when legislation, services or sub-processor structure so require. Material changes will be communicated in good time.

Article 13. Applicable law and disputes

13.1. This data processing agreement is governed by Dutch law.

13.2. Disputes shall be submitted to the competent court in the district in which ARVID.NL is established, unless mandatory law provides otherwise.

Annex 1. Specification of personal data and data subjects

Personal data

  • email address;
  • telephone number;
  • name and address details;
  • financial and administrative data insofar as necessary for invoicing or services.

Categories of data subjects

  • customers and contact persons of the controller.

The controller warrants that the personal data and categories of data subjects described in this annex are complete, accurate and lawful, and indemnifies ARVID.NL against claims arising from incorrect or unlawful supply.