This Data Processing Agreement (“DPA”) forms part of the Agreement (as defined below) between Supplied Technologies B.V. (“Supplied”, “Processor”, “we/us/our”) and the Customer (“Controller”, “you/your”) under which Supplied provides the Services. Capitalized terms not defined here have the meaning in the Agreement or the GDPR.
2.1 Roles. For the Processing described in this DPA, Controller is the Controller and Supplied is the Processor.
2.2 Documented Instructions. Supplied shall Process Personal Data only on documented instructions from Controller (including via the Agreement, this DPA, order forms, and Controller’s written admin settings). If an instruction infringes Data Protection Law, Supplied will inform Controller.
2.3 Purpose & Subject Matter. Processing is limited to providing and supporting the Services for the term of the Agreement (see Annex I).
2.4 Controller Responsibilities. Controller determines the purposes and means of Processing, provides all notices, obtains and records any consents (if used as a legal basis), and ensures lawfulness of Personal Data provided to Supplied.
Supplied ensures its personnel are bound by confidentiality and access Personal Data on a need-to-know basis.
4.1 TOMs. Supplied implements and maintains TOMs appropriate to the risk, including at minimum the controls listed in Annex II (e.g., access control, encryption in transit/at rest, logging/monitoring, vulnerability management, secure development, BCP/DR).
4.2 Assessments & Certifications. Upon request once per year, Supplied will provide a summary of relevant audits/certifications (e.g., ISO/IEC 27001) or equivalent third-party assurance.
5.1 Authorization. Controller authorizes the Sub-processors listed in Annex III and general authorization for Supplied to appoint new Sub-processors.
5.2 Flow-down. Supplied will impose GDPR-equivalent obligations on all Sub-processors and remains fully liable for their performance.
5.3 Notice & Objection. Supplied will notify Controller at least 15 days before replacing/adding Sub-processors (email or portal notice). Controller may object on reasonable data protection grounds; the parties will discuss in good faith. If unresolved, Controller may suspend the affected Service or terminate it for convenience (pro-rata refund of prepaid fees for the terminated portion).
6.1 Supplied will not transfer Personal Data outside the EEA/UK/Switzerland unless appropriate transfer mechanisms are in place (e.g., EU SCCs Module Two, UK Addendum, Swiss Addendum).
6.2 Where required, the parties enter into the EU SCCs (controller-to-processor, Module Two) incorporated by reference with Annexes from this DPA; the governing law and competent authority are as set out in Annex I(C).
6.3 Supplied will conduct transfer impact assessments (TIAs) where applicable and implement supplementary measures where necessary.
7.1 DSR Assistance. Taking into account the nature of Processing, Supplied will assist Controller by appropriate technical and organizational measures in responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection). Target response within 5 business days of a written request from Controller.
7.2 DPIAs & Consultations. Supplied will provide reasonably available information to support Controller’s DPIAs or consultations with Supervisory Authorities regarding the Services.
7.3 Costs. Where assistance is excessive, repetitive, or outside the Services’ standard scope, Supplied may charge reasonable costs.
Supplied will notify Controller without undue delay and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Controller Personal Data, and provide information reasonably available to assist Controller with notifications to authorities and Data Subjects. Notification is not an admission of fault or liability.
9.1 Information & Reports. Supplied will make available information necessary to demonstrate compliance with this DPA (e.g., policy summaries, independent audit reports).
9.2 On-site Audit. Where such information is insufficient, Controller may conduct (or mandate a reputable independent auditor to conduct) an audit no more than once per 12 months with 15 business days’ prior notice, during business hours, limited to facilities and systems used to Process Controller Personal Data, and subject to confidentiality and security requirements.
9.3 Costs. Each party bears its own costs; if an audit reveals material non-compliance attributable to Supplied, Supplied will bear reasonable audit costs.
Within 30 days after termination or expiry of the Agreement, upon Controller request, Supplied will make available a reasonable export of Personal Data (e.g., CSV/JSON). After this export window, Supplied will delete Controller Personal Data from active systems and schedule deletion from backups per Annex II timelines, except as necessary to:
Supplied ensures that any retained data under this section is segregated from live production systems and subject to appropriate technical and organizational measures.
11.1 Liability. Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Agreement, except where prohibited by law.
11.2 Precedence. If there is conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict on data protection matters. If there is conflict between this DPA and the SCCs, the SCCs prevail.
This DPA remains in force while Supplied Processes Personal Data on behalf of Controller under the Agreement.
A. Parties
B. Details of Transfer
C. Competent Supervisory Authority & Governing Law
Supplied maintains an ISO-27001–aligned ISMS including, at a minimum:
The Controller authorizes Supplied to use the following categories of Sub-processors:
Product
Features