Data Processing Agreement
Last updated: [DATE]
This Data Processing Agreement ("DPA") applies whenever [COMPANY NAME] (registration number [REGISTRATION NUMBER]), referred to as "Processor" or "Tarifi", processes personal data on behalf of the Customer (the "Controller") under the Terms and Conditions, to the extent that data belongs to the Customer's own customers and is processed via Tarifi (for example, within quotes). This DPA implements Article 28 GDPR.
1. Definitions
Terms such as "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them by the General Data Protection Regulation (GDPR).
2. Subject matter and duration
This DPA applies for as long as the Customer uses Tarifi under the Terms and Conditions, and ends automatically when that agreement ends, except for provisions that by their nature continue (such as confidentiality).
3. Nature and purpose of processing
Processor processes personal data solely to deliver the Tarifi service to the Customer: creating, calculating, storing, sending and following up on quotes and related documents, including any AI-assisted features the Customer activates.
4. Categories of data subjects and personal data
- Data subjects: contacts and customers of the Customer who appear in quotes, such as quote recipients.
- Personal data: name, contact details (email address, phone number, address), job title, and the content of quotes and related correspondence. As far as known, no special categories of personal data (such as health or criminal data) are processed within Tarifi's normal operation.
5. Instructions and obligations of the Processor
Processor processes personal data only on documented instructions from the Customer, unless required to do so by law. Processor ensures that persons with access to the data are bound by confidentiality.
6. Sub-processors
The Customer authorises Processor to engage the following sub-processors:
- [HOSTING PROVIDER]: hosting of the application and data storage.
- OpenAI, L.L.C.: processing of quote text and related content for AI text suggestions and follow-up advice, only when the Customer uses those features.
- Anthropic PBC: same, as an alternative or additional provider of AI language models.
Processor will inform the Customer of intended changes to this list, so the Customer can object. Processor imposes the same obligations on sub-processors as set out in this DPA.
7. Security measures
Processor takes appropriate technical and organisational measures, including:
- Logical separation of data per organisation (multi-tenant architecture), so one Customer cannot access another Customer's data.
- Role-based access control within each account, so users only have access to what their role requires.
- Encryption of data in transit. [To be added/confirmed: encryption at rest, backup policy and other concrete measures at the chosen hosting provider.]
8. Personal data breach notification
Processor will inform the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, so the Customer can meet its own legal notification obligations where required.
9. Assistance with data subject rights
Where reasonably possible, Processor assists the Customer in responding to data subject requests exercising their GDPR rights (such as access or erasure), and with data protection impact assessments where applicable.
10. Audit
With reasonable prior notice and no more often than necessary, the Customer may request Processor to provide information demonstrating compliance with this DPA, or have an audit performed by an independent third party, subject to confidentiality and in a manner that does not unreasonably burden Processor's operations.
11. Transfers outside the EEA
To the extent sub-processors process data outside the European Economic Area, Processor puts in place appropriate safeguards such as Standard Contractual Clauses or another valid transfer mechanism. [To be confirmed by a lawyer for each sub-processor actually used.]
12. Return and deletion
After the Customer's agreement ends, Processor deletes the Customer's personal data, or returns it on request, unless a legal retention obligation requires otherwise.
13. Liability
The liability provisions in the Terms and Conditions apply equally to this DPA.
14. Governing law
This DPA is governed by Dutch law, in the same way as set out in the Terms and Conditions.
Contact
Questions about this DPA? Email info@tarifi.nl.