DutchBSD B.V.
Data Processing Addendum
Version 1.00 · Effective 27 August 2026
Document versions: 1.00 · 1.01
This document is available in English.
This Data Processing Addendum ("DPA") forms part of the agreement between DutchBSD B.V. ("DutchBSD" or "Processor") and the business customer ("Customer" or "Controller") where DutchBSD processes Customer Personal Data to provide DutchBSD Workspace.
1. Instructions and customer duties
DutchBSD processes Customer Personal Data only on documented instructions contained in the agreement, product settings and lawful support requests, unless Union or Member State law requires otherwise. Where lawful, DutchBSD informs the Customer before required processing and informs the Customer if an instruction appears to infringe data-protection law.
The Customer is responsible for lawful instructions, notices, legal bases, consent where required, data-subject requests, accuracy and necessity. The Customer will not submit special-category or criminal-offence data unless a product expressly supports it and appropriate safeguards have been agreed.
2. Confidentiality and security
DutchBSD limits access to people who need it to provide, secure or support the service and binds them to confidentiality. DutchBSD maintains measures appropriate to the risk, state of the art, cost, scope, context and nature of processing. Current minimum technical measures are listed in Annex 2. A measure may be replaced where overall protection does not materially decrease.
3. Subprocessors and transfers
The Customer gives general authorisation for the subprocessors on the public provider list. DutchBSD imposes data-protection obligations appropriate to their role. DutchBSD gives at least 30 days' notice before a new subprocessor begins materially different Customer Personal Data processing. The Customer may object on reasonable data-protection grounds; if the concern cannot be resolved, the Customer may stop the affected service without a penalty for the unused prepaid period.
DutchBSD does not transfer Customer Personal Data outside the EEA without a lawful safeguard. Where required, the applicable European Commission standard contractual clauses form part of the processing chain.
4. Assistance
Taking account of the nature of processing and available information, DutchBSD provides reasonable technical and organisational assistance with data-subject requests, security duties, breach assessment, data-protection impact assessments and prior consultation. A request received directly about Customer Personal Data is referred to the Customer unless law prevents that.
5. Personal-data breaches
DutchBSD informs the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. Available information will cover the nature of the breach, affected people and records, likely effects, measures taken or planned, and a contact. Information may be supplied in stages. The Customer remains responsible for regulatory and data-subject notifications, with DutchBSD's reasonable assistance.
6. Information and audits
DutchBSD provides information reasonably needed to demonstrate Article 28 GDPR compliance. It may first provide policies, summaries or independent reports. If insufficient, the Customer may request an audit no more than annually and additionally after a material incident or regulator request. Audits must protect other customers, security and confidentiality, use reasonable notice and normal business hours, and are at the Customer's cost unless they identify a material DutchBSD breach.
7. Return and deletion
After termination, the Customer may export Customer Personal Data during the 30-day export period. DutchBSD then deletes or returns it, where technically available, unless law requires retention. Active-system deletion is scheduled during the following 30 days. Backup copies are isolated from ordinary use and expire through the rolling cycle. Until automated lifecycle enforcement is deployed, these deadlines are executed through a manual termination register and provider-specific cleanup evidence.
Annex 1 - Processing details
- Subject and purpose: providing, hosting, securing, supporting, backing up and maintaining the selected Workspace products.
- Duration: the agreement term and deletion period described above.
- Nature: collection, receipt, storage, organisation, retrieval, transmission, display, support access, backup and deletion.
- People: customer staff, workspace members, customers, prospects, site visitors, contacts and others whose data the Customer submits.
- Data: contact and account data, content, communications, identifiers, IP/device data, files and other data selected by the Customer.
Annex 2 - Current minimum technical measures
- Server-side workspace membership, role and capability checks protect account, site, domain, release and billing actions.
- Staff and administrative access requires a verified TOTP factor; customers can enable TOTP with recovery codes.
- Production configuration requires HTTPS, HSTS, secure session cookies and secure CSRF cookies.
- Login throttling and authentication, workspace, publication and billing audit events support prevention and investigation.
- Runtime dependencies are pinned; deployment configuration is root-managed; the application runs as a dedicated non-root account.
- Customer site source and release history is versioned; publication uses reviewed immutable release records and bounded provider identities.
- Lifecycle cleanup is site-scoped, report-only by default, preserves canonical source until authorised deletion, and records partial provider cleanup for retry.
Encrypted backup, restore-rehearsal, fixed log-retention, separate security-event retention, vendor-transfer review, production/development separation and end-of-retention deletion controls are governed by operator procedures. They are not represented here as completed production evidence until configured, exercised and recorded.
8. Priority and liability
The Terms' liability provisions apply except where the GDPR or other mandatory law requires otherwise. This DPA controls over the Terms for Customer Personal Data processing.