Data processing agreement
The arrangements for how we process your customers' personal data — under article 28 GDPR. Print it, sign it, done.
1.Parties and definitions
In short: you decide what happens with your customers' data; we execute.
ChatBuild — [[BEDRIJFSNAAM_JURIDISCH]]
Chamber of Commerce [[KVK_NUMMER]] · [[VESTIGINGSADRES]]
Business name: Chamber of Commerce: Address:
Terms such as "personal data", "processing", "data subject" and "data breach" have the meaning given in the GDPR. This data processing agreement belongs to the terms and conditions and prevails in case of conflict regarding data processing.
2.Subject, nature, purpose and duration
In short: we process data of your site visitors and WhatsApp customers, for as long as your subscription runs.
The processor processes, on the controller's instructions, personal data needed to build, host and operate the website and the associated WhatsApp channels. The subject, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in annex 1. This agreement lasts as long as the main agreement lasts.
3.Processing only on instruction
In short: we do nothing with the data outside your instructions.
The processor processes the personal data only on documented instructions from the controller — including the instructions that follow from using the service — unless Union or member-state law requires processing; in that case the processor notifies the controller beforehand, unless that law prohibits it. The processor immediately informs the controller if, in its view, an instruction infringes the GDPR.
4.Confidentiality
In short: everyone working with the data on our side is bound to confidentiality.
The processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and limits access to persons for whom that access is necessary.
5.Security (art. 32 GDPR)
In short: appropriate technical and organisational measures — the overview is in annex 2.
The processor takes appropriate technical and organisational measures as referred to in article 32 GDPR, taking into account the state of the art, the costs, and the nature and risks of the processing. The measures are described in annex 2; the processor may update them as long as the level of protection does not decrease.
6.Sub-processors
In short: you give us general authorisation for sub-processors; you can object to changes.
- The controller hereby gives general written authorisation for engaging the sub-processors in annex 3.
- For an intended addition or replacement, the processor informs the controller in advance. The controller can object in writing within [[TERMIJN]]; the parties then look for a reasonable solution together. If that fails, the controller may terminate the main agreement effective from the date the change takes effect.
- The processor imposes the same obligations as in this agreement on every sub-processor and remains fully liable towards the controller for the sub-processor's performance.
7.Assistance with data subject requests
In short: if your customer asks for access or deletion, we help you arrange it quickly.
The processor assists the controller, insofar as possible and with appropriate technical and organisational measures, in responding to data subject requests (access, rectification, erasure, restriction, objection, portability). If the processor receives such a request directly, it forwards it without delay and does not answer it substantively itself.
8.Assistance with DPIA and consultation
In short: we also assist you with a data protection impact assessment.
Taking into account the nature of the processing and the information available, the processor assists the controller in complying with the obligations of articles 32 to 36 GDPR, including a data protection impact assessment (DPIA) and any prior consultation of the Dutch Data Protection Authority.
9.Data breaches
In short: we notify you of a data breach without undue delay, at the latest within [[UREN]] hours.
The processor informs the controller without unreasonable delay — and at the latest within [[UREN]] hours of discovery — about a personal data breach, including at least: the nature of the breach, the (categories of) data subjects and data, the likely consequences and the measures taken or proposed. The processor documents incidents and cooperates with notification to the supervisory authority and data subjects. Notifying the Dutch Data Protection Authority is and remains the controller's responsibility.
10.Deletion or return
In short: when the agreement ends, you choose: data back or deleted.
After the end of the main agreement, the processor deletes all personal data or returns it in a common file format — at the controller's choice — and deletes existing copies, unless storage is legally required. The processor confirms the deletion in writing on request.
11.Audit and inspection
In short: you may verify that we keep these promises, under reasonable conditions.
The processor makes available all information necessary to demonstrate compliance with article 28 GDPR, and allows for audits and inspections by or on behalf of the controller. Reasonable conditions: at most once a year (more often after a concrete incident), announced at least 30 days in advance, during office hours, without unnecessary disruption of the service, under confidentiality, and each party bears its own costs. Where possible, the processor first answers an audit with existing documentation or reports from independent third parties.
12.Transfers outside the EEA
In short: transfers outside Europe only with a valid mechanism, such as SCCs.
The processor only transfers personal data to countries outside the EEA if chapter V GDPR is satisfied — in practice through the European Commission's standard contractual clauses (SCCs), supplemented with technical measures where needed. Which sub-processors process outside the EEA is listed in annex 3.
13.Liability
In short: the same liability arrangement as in the terms and conditions.
The liability arrangement of article 13 of the terms and conditions applies to this agreement, without prejudice to article 82 GDPR (data subjects' right to compensation). Fines imposed by a supervisory authority on one party for its own violation remain for that party's account.
14.Final provisions
In short: Dutch law; in case of conflict this agreement prevails over the main agreement.
Dutch law governs this agreement; disputes are submitted to the court of [[ARRONDISSEMENT]]. In case of conflict between this data processing agreement and the main agreement, this data processing agreement prevails insofar as it concerns the processing of personal data. Changes are only valid if both parties agree to them in writing, with the exception of annex updates under articles 5 and 6.
Signature
Thus agreed and signed in duplicate:
Name: Role: Date:
SignatureName: Role: Date:
SignatureOverview of the processing
| Subject | Building, hosting and maintaining the customer's website and handling interactions with their (potential) customers. |
|---|---|
| Nature and purpose | Storing, structuring, displaying and forwarding data that visitors and end customers leave via the site and WhatsApp — so the customer can receive and answer requests, bookings and messages. |
| Types of personal data | Name, phone number (WhatsApp), email address, content of chat messages and voice notes, lead and booking details (date, service, remarks), and content the customer places on the site insofar as it contains personal data. |
| Categories of data subjects | Site visitors, (potential) end customers who make contact via the site or WhatsApp, and other persons whose data the customer places on the site. |
| Duration | As long as the main agreement runs, followed by deletion or return under article 10. |
Special categories of personal data are not intended to be processed through the service; the customer sees to it that data subjects don't share them unnecessarily.
Security measures
- Primary data storage within the EU (database in Frankfurt);
- encryption of data in transit (TLS) and at rest;
- access control based on least privilege, with multi-factor authentication (MFA) for internal systems;
- logical separation of customer environments;
- logging and monitoring of system access and processing;
- backups with recovery objectives [[RPO]] (RPO) and [[RTO]] (RTO);
- automated safety scan when publishing sites (incl. Google Web Risk);
- measures against prompt injection and abuse of AI features;
- a documented incident procedure (see article 9);
- confidentiality arrangements with staff and periodic security tests at cadence [[CADANS]].
A plain-language explanation is on GDPR and security.
Approved sub-processors
| Party | Function | Location | Transfer |
|---|---|---|---|
| 360dialog | WhatsApp Business provider (BSP) | EU | n/a (within EEA) |
| Cloudflare | Hosting, CDN and storage (R2/KV) | EU and US | SCCs |
| Supabase | Database (Postgres) | Frankfurt (EU) | n/a (within EEA) |
| Inngest | Background job orchestration | [[REGIO_INNGEST]] | SCCs if outside EEA |
| Anthropic | AI models | US | SCCs |
| Deepgram | Dutch speech recognition | US | SCCs |
| Openprovider | Domain registration (.nl) | NL | n/a (within EEA) |
| Langfuse and Sentry | Logging and observability | [[REGIO_OBSERVABILITY]] | SCCs if outside EEA |
| Google Web Risk | Safety scan at publication | US | SCCs |
Mollie (payments) and Meta/WhatsApp (message delivery) are independent controllers and therefore not sub-processors. The current list is also in article 6 of the privacy policy; changes follow article 6 of this agreement.
Still to fill in
This draft contains placeholders. Replace them all before publication.
- [[BEDRIJFSNAAM_JURIDISCH]]
- ChatBuild's statutory name and legal form
- [[KVK_NUMMER]]
- Chamber of Commerce number
- [[VESTIGINGSADRES]]
- Registered address
- [[TERMIJN]]
- Objection period for new sub-processors (e.g. 30 days)
- [[UREN]]
- Maximum data breach notification period in hours
- [[ARRONDISSEMENT]]
- Competent court
- [[RPO]]
- Recovery Point Objective of the backups
- [[RTO]]
- Recovery Time Objective of the backups
- [[CADANS]]
- Frequency of security tests/pentests
- [[REGIO_INNGEST]]
- Inngest's processing region
- [[REGIO_OBSERVABILITY]]
- Langfuse and Sentry's processing region
- [[DATUM]]
- Date of the latest change
- [[VERSIE]]
- Version number