Data processing agreement

Last updated: 24 July 2026

Where we process personal data on your organisation’s instruction, for example inside an application on Core, we are the processor and you are the controller. This agreement sets out what we do and do not do in that role, and what you can hold us to.

TO CONFIRM This is a fully worked draft. The marked items are legal commitments that have to be settled and reviewed internally first.

1. Parties and precedence

This data processing agreement forms part of the contract between the customer and Deverence Group B.V. Where the two conflict on the processing of personal data, this agreement takes precedence over the terms and conditions.

2. Roles

The customer is the controller and determines the purpose and the means of the processing. Deverence Group B.V. is the processor and processes only on the customer’s instruction. For the data we process to run our own business we are the controller ourselves; that is covered by our privacy statement.

3. Subject, nature and term of the processing

The processing concerns the personal data that the customer and its users store and process in applications on Core, plus the data the platform records around that, such as users, roles, permissions and logging. This agreement runs for as long as the underlying contract runs and ends with it.

TO CONFIRM The categories of data subjects and personal data differ per customer and belong in an annex to the signed copy. The template for that annex still has to be settled.

4. Instructions

We process personal data only on documented instruction from the customer. If we believe an instruction breaches the law, we say so before carrying it out. Outside that instruction we do not touch customer data, except where it is necessary to deliver or secure the service, or where the law obliges us to. If we are legally required to disclose data, we tell the customer beforehand unless that same law forbids it.

5. Confidentiality

Every employee who may come into contact with customer data is screened by means of a Dutch certificate of conduct (VOG) and is contractually bound to confidentiality. Access to customer environments is given only to people who need it for their work.

6. Security

We take appropriate technical and organisational measures. Core runs on our own hardware in the BIT data centres in Ede, certified for ISO 27001, ISO 9001 and NEN 7510. Permissions are granted per role, administrative actions are logged, automatic alerts go out on sensitive account changes, and security fixes roll out automatically to every environment. What that means in practice is described on the security page.

7. Sub-processors

We engage sub-processors only if they are bound by at least the same obligations as we are, and we remain responsible for their work. Because we run our own hardware ourselves, the number of sub-processors is small.

TO CONFIRM The current list of sub-processors, their role and their country of establishment has to be settled and included as an annex, together with the notice period for a change and the way a customer can object to one.

8. Transfers outside the EEA

The personal data we process as a processor stays in the Netherlands. RUAL and our data centre partner are Dutch companies with no American parent, so the US CLOUD Act does not apply. No transfer outside the European Economic Area takes place unless the customer asks for it and there is a valid basis for it. Where the environments actually run is set out on the hosting page.

9. Personal data breaches

If we identify a personal data breach we report it to the customer with everything we know at that moment: what happened, which data and which data subjects are affected, the likely consequences and the measures we are taking. We keep the customer informed for as long as the investigation runs. Notification to the supervisory authority and, where required, to the data subjects is done by the customer as controller.

TO CONFIRM The window within which we report a breach, the channel we use and which contact person on the customer side receives it still have to be settled.

10. Assistance to the controller

We assist the customer with requests from data subjects, with a data protection impact assessment and with consultation of the supervisory authority, as far as can reasonably be asked of us. If a request from a data subject reaches us directly, we do not act on it ourselves but refer it to the customer and let the customer know the request exists.

11. Audits

The customer may verify that we comply with this agreement. In the first instance we do that with the certifications and reports that already exist. If a question remains after that, we cooperate with an audit by the customer or by an independent auditor bound to confidentiality.

TO CONFIRM How often an audit can take place, what notice period applies and who bears which costs still have to be settled.

12. Return and deletion

At the end of the contract the customer can export their data. After that we delete the personal data from our systems, including the copies in backups, unless the law requires us to keep it. On request we confirm that deletion in writing.

TO CONFIRM How long data stays available for export after termination, how long backups are kept and the point at which they are permanently erased still have to be settled.

13. Liability

Liability is governed by what is agreed in the terms and conditions, taking into account the liability the GDPR places directly on a processor.

A signed copy

Need a signed data processing agreement for your own records, or want us to look at your template? Email support@deverence.com or call +31 (0)10 300 67 78.

Want this agreement signed and on file?

Send us your own template or use ours. We go through it with you, with no legal department in between.