Data processing agreement (summary)
Last updated: October 2026
Signed before we touch any data. The signed agreement prevails.
Roles
While we process your raw data to de-identify it, we act as your processor under GDPR art. 28, only on your documented instructions. The result is anonymized data, which is no longer personal data; it is licensed under the supplier agreement.
Location
Processing happens in EU data centers in Amsterdam and Frankfurt.
Security
Encryption in transit and at rest, read-only access, least-privilege access for named staff under confidentiality, and full access logging.
Deletion
Raw data is deleted after packaging. Access tokens are revoked when the project ends.
Sub-processors
Scaleway — hosting (Amsterdam) · OVHcloud — backups (Frankfurt) · Brevo — email (Paris). You're notified 30 days before any change and may object.
Assistance
We help with data subject requests, your DPIA and the information for your staff or works council.
Incidents
Notified to you without undue delay, and within 48 hours.
Audits
You may audit our compliance once a year, or after an incident.