Data Processing Agreement (DPA) Company.info – Customer.

Parties

The Customer, being the Controller, and the Supplier, the private limited liability company Company.info B.V., having its registered office at Abram Dudok van Heelstraat 2, (1096 BE) Amsterdam, the Netherlands, being the Processor, hereinafter each also referred to individually as a “Party” and jointly as the “Parties“; 

Whereas 

  1. In the context of the Customer’s purchase of the Supplier’s Product, as agreed in a supply agreement, hereinafter: the “Agreement“, the Processor processes Personal Data as specified below on behalf of the Customer, being the Controller within the meaning of the General Data Protection Regulation (EU 2016/679) (hereinafter: the “GDPR”); 
  1. In this Data Processing Agreement, and in accordance with Article 28 of the GDPR, the Parties agree as follows, whereby words commencing with a capital letter shall have the same meaning as defined in the GDPR. 

Have agreed as follows:

1. Subject matter of the Data Processing Agreement

1.1 This Data Processing Agreement applies to the processing of Personal Data by the Processor on behalf of the Controller in the context of the Agreement. 

1.2 As a consequence of the Agreement, the Processor processes Personal Data on behalf of and upon the instructions of the Controller. 

1.3 The Processor warrants that it shall process the Personal Data properly and with due care, in accordance with the provisions of the Agreement, the GDPR and other applicable laws and regulations relating to the processing of Personal Data, as well as any instructions or recommendations issued by the Dutch Data Protection Authority or any other supervisory authority. 

1.4 The Processor shall process the Personal Data solely on behalf of and in accordance with the instructions of the Controller. The Processor shall have no independent authority over the Personal Data processed by the Controller. The Processor shall not process the Personal Data for its own purposes and/or disclose such Personal Data to third parties and/or process such Personal Data for any purposes other than those instructed, save where otherwise required by applicable law. 

2. Security and audit rights

2.1 The Processor shall, in accordance with Article 32 of the GDPR, implement appropriate technical and organizational measures to protect the Personal Data against loss or any form of unlawful processing. 

2.2 The Processor maintains a demonstrable and documented information security policy and has developed internal controls arising therefrom regarding the operation of privacy compliance-related production systems, processes and facilities used by the Processor. 

2.3 The internal controls referred to in Article 2.2 shall be carried out by the Processor at least once per year, and records shall be maintained showing the date and time of such controls and the officer(s) responsible for carrying them out. 

2.4 The Controller shall at all times be entitled to have privacy compliance measures implemented by the Processor in general, and compliance with this Data Processing Agreement in particular, including but not limited to the measures implemented by the Processor as described in this Article, examined by an independent expert designated by the Controller. The Controller shall provide reasonable prior notice of such examination to enable the Processor to make the necessary personnel available. The costs of any independent external expert shall be borne by the Controller. The Processor shall not charge the Controller for facilitating and supporting such examination. 

2.5 If the Processor fails to implement appropriate technical and organizational measures within the meaning of Article 2.1 and fails to remedy such deficiency within a period stipulated by the Controller, the Controller shall be entitled to have such measures implemented at the Processor’s expense.

3. Engagement of third parties

3.1 The Processor shall only be entitled to engage a third party in the performance of its activities if the Controller has given its prior written consent and provided that the same conditions applicable under this Agreement apply to such third party in relation to the processing of Personal Data. 

3.2 The Processor shall not engage third parties outside the European Union in the performance of its activities unless the Controller has given its prior written consent and the Processor guarantees that such third party ensures an adequate level of protection and security of Personal Data within the meaning of the GDPR and provides evidence thereof to the Controller. 

3.3 Notwithstanding Articles 3.1 and 3.2, the Processor shall enter into a written sub-processing agreement with each subcontractor (Sub-Processor) approved by the Controller and shall impose on such subcontractor the same obligations as those imposed on the Processor under this Data Processing Agreement. In addition, the Processor shall prohibit the subcontractor from engaging any further (sub-)processors in the relevant sub-processing agreement. Such sub-processing agreements shall be retained at the Processor’s offices and made available to the Controller in digital and/or physical form upon first request. 

3.4 The Controller hereby authorizes the Processor to engage the following Sub-Processors: 

  • AWS Cloud Services, Ireland; 
  • Infosource Ltd, Bulgaria; 
  • Mendix Technology B.V., the Netherlands; 
  • Acuris, United Kingdom; 
  • Solvimon, the Netherlands; and 
  • Salesforce, United States. 

4. Confidentiality

4.1 The Processor shall keep the Personal Data confidential and shall not make such Personal Data available, directly or indirectly, to any third party. 

4.2 The Processor shall ensure that those members of staff and any third party(ies) who necessarily require access to the Personal Data comply with the confidentiality obligations set out herein by requiring them to sign a confidentiality declaration. 

4.3 If the Processor receives a request from a supervisory authority, including but not limited to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the Netherlands Authority for Consumers and Markets (Autoriteit Consument & Markt), to provide access to Personal Data or privacy compliance-related production systems, processes or facilities, the Processor shall only comply with such request after notifying the Controller and under the Controller’s direction. The Processor shall notify the Controller of any such request without delay. 

5. Return/destruction of Personal Data

5.1 The Processor shall make all Personal Data available to the Controller upon first request, but in any event no later than ten Working Days after the termination of this Data Processing Agreement or the termination of the assignment. 

5.2 The Processor shall be required to destroy the Personal Data within a reasonable period after termination of the Agreement between the Parties. 

6. Information exchange and personal data breach notification

6.1 The Processor shall inform the Controller of any facts which it may reasonably expect to have an impact on the processing of Personal Data under the responsibility of the Controller. 

6.2 The Processor shall notify the Controller within 24 hours of any incident, or any previously unidentified risk of incidents, which may reasonably be foreseen to compromise the confidentiality, availability or integrity of the data processing activities. 

6.3 The Processor shall actively assist the Controller in the event of a personal data breach and any resulting obligation on the Controller to notify the Dutch Data Protection Authority and/or the data subjects concerned. 

6.4 The Processor shall ensure that: 

  • upon the Controller’s first request, the Processor enables the Controller to comply with the notification obligations imposed upon the Controller pursuant to Articles 33 and 34 GDPR in the event of a personal data breach, as set out in Article 6 of this Data Processing Agreement; and 
  • the Processor maintains a register of all security incidents and, in particular, every breach of Personal Data protection. Such register shall contain at least the facts and information regarding the nature of the breach as referred to in Articles 33 and 34 GDPR. 

7. Rights of the data subject

7.1 Taking into account the nature of the Processing, the Processor shall implement appropriate technical and organisational measures and appoint a member of staff as a contact person in order to provide adequate assistance to the Controller in responding to requests for the exercise of data subject rights established in Chapter III of the GDPR, and in any event within a period of one week. 

7.2 The Processor shall immediately notify the Controller if the Processor receives a request from a data subject concerning the exercise of any of the rights established in Chapter III of the GDPR. 

7.3 The Processor shall ensure that neither the Processor nor any Sub-Processor engaged by it responds directly to a data subject in relation to requests referred to in Article 7.2 of this Agreement, unless written instructions have been provided to that effect, in which case the Processor shall notify the Controller of the data subject’s request so that the Controller may itself respond to the request or instruct the Processor to respond to the data subject and specify the manner in which such response is to be made. 

8. Data Protection Impact Assessment

8.1 The Processor shall cooperate with the Controller in fulfilling its obligations under Articles 35 and 36 of the GDPR relating to carrying out a data protection impact assessment, where applicable.

9. Liability and Indemnification

9.1 The Controller shall be liable for, and shall indemnify the Processor against, fines, penalty payments and damages arising from the Controller’s act or omission resulting in a failure to comply with this Agreement, as well as fines, penalties and/or damages arising from any breach by the Controller of the GDPR, the Dutch Telecommunications Act (Telecommunicatiewet) and all other applicable European privacy legislation. 

9.2 The Processor shall be liable for, and shall indemnify the Controller against, fines, penalty payments and damages arising from any act or omission of the Processor and/or any (sub-)processor engaged by the Processor resulting in a failure to comply with this Agreement, as well as fines, penalties and/or damages arising from any breach by the Processor and/or any (sub-)processor engaged by the Processor of the GDPR, the Dutch Telecommunications Act (Telecommunicatiewet) and all other applicable European privacy legislation. 

9.3 Without prejudice to any provisions to that effect in the Agreement or this Data Processing Agreement, the liability of each Party arising out of or in connection with this Data Processing Agreement shall be subject to any overall liability limitations set out in the Agreement, unless the liability arises from a fine imposed by an enforcement authority or unless the damage results from willful misconduct or deliberate recklessness on the part of the Party to whom the damage is attributable. 

10. Miscellaneous

10.1 Any amendments to this Data Processing Agreement shall only be valid if agreed in writing by the Parties. 

10.2 This Data Processing Agreement supplements the Agreement between the Parties concerning the supply of the Product by the Supplier to the Customer, shall have the same term as that Agreement and shall terminate if and when that Agreement terminates. The provisions of Articles 4 and 5 of this Data Processing Agreement shall, however, survive termination. 

10.3 Either Party shall be entitled, without prejudice to any provisions to that effect in the Agreement, to suspend performance of this Data Processing Agreement or to terminate it with immediate effect without court intervention if: 

  • the other Party is dissolved or otherwise ceases to exist; 
  • the other Party demonstrably fails to perform its obligations under this Data Processing Agreement and such material breach is not remedied within 30 days after receipt of a notice of default requiring remedy thereof; or 
  • a Party is declared bankrupt or applies for a suspension of payments. 

10.4 This Data Processing Agreement shall be governed exclusively by the laws of the Netherlands. Any disputes arising out of or in connection with this Agreement shall be submitted exclusively to the competent courts of Amsterdam. 

10.5 A Dutch-language version of this Data Processing Agreement is also available. In the event of any conflict between provisions or any uncertainty regarding their interpretation, the Dutch-language version shall prevail at all times over this English-language version. 

1 September 2026 

Do you have any questions?

Please contact us for more info about concerning these Data Processing Agreement.

Contact us