CommuniQate
Legal

Data Processing Agreement

Drawn up and applicable as processor and data processor: CommuniQate (part of AppCenter Nederland B.V.), Marssteden 106, 7547TD Enschede.

Structure of the data processing agreement

The client or customer is the customer of CommuniQate (part of AppCenter Nederland B.V.) and user of one or more applications named in this data processing agreement. The processing agreement consists of two parts:

1

Data Pro Statement

Version: August 2022

This Data Pro Statement, together with the Standard Clauses for processing, forms the data processing agreement for the product or service of the company that drew up this Data Pro Statement.

General information

For questions about this Data Pro Statement or data protection, you can contact: Maico Gieteling, maico@communiqate.nl

We regularly adapt this Data Pro Statement and the security measures described in it in order to remain prepared and up to date with regard to data protection. We keep you informed of new versions via our normal channels, such as this website.

Products and services

This Data Pro Statement applies to the following products and services of the data processor:

CommuniQate

The purpose of CommuniQate is a direct personal customer approach via WhatsApp. This digital assistant contributes to approaching existing customers both proactively and reactively.

Intended use

The intended use of the following products is explained here. It indicates which personal data is recorded. This product does not take into account the processing of special categories of personal data, or data relating to criminal convictions and offences, or personal identification numbers issued by the government.

CommuniQate

The personal direct customer approach by a (digital) assistant is carried out on the basis of name and (mobile) phone number. This allows customers to be approached both proactively and reactively. Personal data that is recorded may consist of name, address, place of residence, phone number(s) and email addresses. Collected personal data is used only for the customer and is not used for other customers or third parties.

Processing this data with the product or service described above is at the client's own discretion.

Privacy by Design / Privacy by Default

When designing the product/service, the data processor applied privacy by design/privacy by default in the following way:

  • All collected data is available only to the customer and is not available to other customers or third parties
  • Collected data is available for the purpose of developing the applications of CommuniQate (part of AppCenter Nederland B.V.) and will be used exclusively for this purpose. Collected personal data is never used by the Data Processor.

Third parties: Part of the Data Pro Statement is the collaboration with META (Facebook / WhatsApp owner) for the CommuniQate product. It has been agreed with third parties that substantive data is never used or resold to other parties.

Standard clauses and processing

The data processor uses the Standard Clauses for processing, which can be found as an appendix to the Agreement.

The data processor processes the personal data of its clients within the EU/EEA. The data processor supports the client in the following way with requests from data subjects:

  • Access to collected personal data
  • Deletion of personal data
  • Request to manage collected personal data (adding/deleting/amending personal data)

After termination of the Agreement with a client, the data processor will in principle delete the personal data it processes for the client within three months in such a way that it can no longer be used and is no longer accessible (render inaccessible).

If the customer so wishes: After termination of the Agreement with the client, the data processor returns all personal data it processes for the client within 3 months in the following way: Secure transfer of encrypted personal data by means of a single temporary file that is (automatically) deleted after two weeks.

Security policy

The data processor has taken the following security measures to secure its product or service:

  • Personal data is not pseudonymised.
  • Personal data is stored encrypted.
  • The integrity of the applications mentioned is safeguarded through careful design to make personal data available to the relevant client.
  • In the event of an incident, personal data is immediately made temporarily unavailable to safeguard personal data. After the incident has been resolved, the data is made available again through a careful procedure.

The data processor has committed to the following Information Security Management System (ISMS): All data is stored with NEN-ISO 27001 certified service providers.

Data breach protocol

In case something does go wrong, the data processor applies the following data breach protocol to ensure that the client is informed of incidents:

1

Report of a data breach in a central environment of CommuniQate

2

Notification to relevant customers of CommuniQate

3

Statement on communiqate.nl

4

Mitigating measures taken

Sub-processors

The parties below are engaged by CommuniQate (part of AppCenter Nederland B.V.) in the processing of personal data:

Sub-processorPurposeProcessed dataLocationTransfer
AWS (S3, SES/SNS)Hosting, storage, emailAll customer data, email addressesEUYes
Digital OceanHosting, storage, emailAll customer data, email addressesEUYes
ForgeHosting, storage, emailNameEUPossible
SentryError loggingMetadata, error messagesEUPossible
SlackIncident notificationsMetadata, support infoEUYes
PusherReal-time messagingUser IDs, eventsEUPossible
FirebasePush notificationsDevice tokensEUYes
Meta (WhatsApp/Facebook)Messaging integrationsMessages, contact dataEUYes
Google Dialogflow CXConversational AIChat contentEUPossible
Google OAuthLoginProfile dataEUYes
Microsoft OAuthLoginProfile dataEUPossible
Apple App StoreApp distributionCrash logs, device infoWorldwideLimited
Google Play StoreApp distributionCrash logs, device infoWorldwideLimited
2

Standard Clauses for processing

Version: September 2019

This part, together with the Data Pro Statement, forms the data processing agreement and is an appendix to the Agreement and its associated appendices such as applicable terms and conditions.

Article 1. Definitions

The terms below have the following meaning in these Standard Clauses for processing, in the Data Pro Statement and in the agreement:

1.1 Data Protection Authority (AP): supervisory authority, as described in article 4, sub 21 GDPR.

1.2 GDPR: the General Data Protection Regulation.

1.3 Data Processor: party that, as an ICT supplier in the context of performing the Agreement, processes Personal Data as a processor on behalf of its Client.

1.4 Data Pro Statement: statement of the Data Processor in which it provides, among other things, information regarding the intended use of its product or service, the security measures taken, sub-processors, data breaches, certifications and handling of the rights of Data subjects.

1.5 Data subject: an identified or identifiable natural person.

1.6 Client: party on whose behalf the Data Processor processes personal data. The Client can be both the controller and another processor.

1.7 Agreement: the agreement between Client and Data Processor, on the basis of which the ICT supplier delivers services and/or products to the Client, of which the data processing agreement forms part.

1.8 Personal Data: all information about an identified or identifiable natural person, as described in article 4, sub 1 GDPR, that the Data Processor processes in the context of performing its obligations arising from the Agreement.

1.9 Data processing agreement: these Standard Clauses for processing, which together with the Data Pro Statement (or comparable information) of the Data Processor form the data processing agreement as referred to in article 28, paragraph 3 GDPR.

Article 2. General

2.1 These Standard Clauses for processing apply to all processing of Personal Data that the Data Processor carries out in the context of delivering its products and services and to all Agreements and offers. The applicability of the Client's own data processing agreements is expressly rejected.

2.2 The Data Pro Statement, and in particular the security measures included in it, may be adapted from time to time by the Data Processor to changing circumstances. The Data Processor will inform the Client of significant changes. If the Client cannot reasonably agree to the changes, the Client is entitled to terminate the data processing agreement in writing with reasons within 30 days after notification of the changes.

2.3 The Data Processor processes the Personal Data on behalf of and on the instructions of the Client in accordance with the written instructions of the Client agreed with the Data Processor.

2.4 The Client, or its customer, is the controller within the meaning of the GDPR, has control over the processing of the Personal Data and has determined the purpose of and the means for the processing of the Personal Data.

2.5 The Data Processor is a processor within the meaning of the GDPR and therefore has no control over the purpose of and the means for the processing of the Personal Data and consequently does not make decisions about, among other things, the use of the Personal Data.

2.6 The Data Processor implements the GDPR as set out in these Standard Clauses for processing, the Data Pro Statement and the Agreement. It is up to the Client to assess, on the basis of this information, whether the Data Processor offers sufficient guarantees regarding the application of appropriate technical and organisational measures so that the processing meets the requirements of the GDPR and the protection of the rights of Data subjects is sufficiently safeguarded.

2.7 The Client warrants to the Data Processor that it acts in accordance with the GDPR, that it adequately secures its systems and infrastructure at all times, and that the content, use and/or processing of the Personal Data is not unlawful and does not infringe any right of a third party.

2.8 An administrative fine imposed on the Client by the AP cannot be recovered from the Data Processor.

Article 3. Security

3.1 The Data Processor takes the technical and organisational security measures as described in its Data Pro Statement. In taking the technical and organisational security measures, the Data Processor has taken into account the state of the art, the implementation costs of the security measures, the nature, scope and context of the processing, the purposes and intended use of its products and services, the processing risks and the risks of varying likelihood and severity for the rights and freedoms of Data subjects that it could expect given the intended use of its products and services.

3.2 Unless explicitly stated otherwise in the Data Pro Statement, the Data Processor's product or service is not designed for the processing of special categories of Personal Data or data relating to criminal convictions or offences, or personal identification numbers issued by the government.

3.3 The Data Processor strives to ensure that the security measures it takes are appropriate for the Data Processor's intended use of the product or service.

3.4 The described security measures provide, in the opinion of the Client, taking into account the factors mentioned in article 3.1, a security level tailored to the risk of the processing of the Personal Data it uses or provides.

3.5 The Data Processor may make changes to the security measures taken if, in its opinion, this is necessary to continue to offer an appropriate security level. The Data Processor will record important changes, for example in an adapted Data Pro Statement, and will inform the Client of those changes where relevant.

3.6 The Client may request the Data Processor to take further security measures. The Data Processor is not obliged to implement changes to its security measures in response to such a request. The Data Processor may charge the Client for the costs associated with the changes implemented at the Client's request. Only after the amended security measures desired by the Client have been agreed in writing and signed by the Parties does the Data Processor have the obligation to actually implement these security measures.

Article 4. Personal Data breaches

4.1 The Data Processor does not warrant that the security measures are effective under all circumstances. If the Data Processor discovers a Personal Data breach (as referred to in article 4 sub 12 GDPR), it will inform the Client without unreasonable delay. The Data Pro Statement (under the data breach protocol) sets out how the Data Processor informs the Client about Personal Data breaches.

4.2 It is up to the controller (Client, or its customer) to assess whether the Personal Data breach about which the Data Processor has informed must be reported to the AP or Data subject. Reporting Personal Data breaches that must be reported to the AP and/or Data subjects pursuant to articles 33 and 34 GDPR remains at all times the responsibility of the controller (Client or its customer). The Data Processor is not obliged to report Personal Data breaches to the AP and/or the Data subject.

4.3 The Data Processor will, if necessary, provide further information about the Personal Data breach and will cooperate in the necessary provision of information to the Client for the purpose of a notification as referred to in articles 33 and 34 GDPR.

4.4 The Data Processor may charge the Client the reasonable costs it incurs in this context at its then applicable rates.

Article 5. Confidentiality

5.1 The Data Processor ensures that the persons who process Personal Data under its responsibility are bound by a duty of confidentiality.

5.2 The Data Processor is entitled to provide the Personal Data to third parties, if and insofar as provision is necessary pursuant to a court ruling, a statutory provision or on the basis of a duly given order from a government authority.

5.3 All access and/or identification codes, certificates, information regarding access and/or password policy, and all information provided by the Data Processor to the Client that gives substance to the technical and organisational security measures included in the Data Pro Statement are confidential and will be treated as such by the Client and made known only to authorised employees of the Client. The Client ensures that its employees comply with the obligations of this article.

Article 6. Term and termination

6.1 This data processing agreement forms part of the Agreement and every new or further agreement arising from it, takes effect at the moment the Agreement is concluded and is entered into for an indefinite period.

6.2 This data processing agreement ends by operation of law upon termination of the Agreement or any new or further agreement between the parties.

6.3 In the event of the end of the data processing agreement, the Data Processor will delete all Personal Data received from the Client and in its possession within the period included in the Data Pro Statement, in such a way that it can no longer be used and is no longer accessible (render inaccessible), or, if agreed, return it to the Client in a machine-readable format.

6.4 The Data Processor may charge the Client any costs it incurs in the context of what is stated in article 6.3. Further arrangements about this can be laid down in the Data Pro Statement.

6.5 The provisions of article 6.3 do not apply if a statutory regulation prevents the Data Processor from wholly or partly deleting or returning the Personal Data. In such a case, the Data Processor will only continue to process the Personal Data insofar as necessary under its legal obligations. The provisions of article 6.3 also do not apply if the Data Processor is the controller within the meaning of the GDPR with respect to the Personal Data.

Article 7. Rights of Data subjects, Data Protection Impact Assessment (DPIA) and audit rights

7.1 The Data Processor will, where possible, cooperate with reasonable requests from the Client relating to rights of Data subjects invoked by Data subjects with the Client. If the Data Processor is contacted directly by a Data subject, it will, where possible, refer them to the Client.

7.2 If the Client is obliged to do so, the Data Processor will, following a reasonable request, cooperate with a data protection impact assessment (DPIA) or a subsequent prior consultation as referred to in articles 35 and 36 GDPR.

7.3 The Data Processor will cooperate with requests from the Client to delete personal data insofar as the Client cannot do this itself.

7.4 If desired, the Data Processor can demonstrate compliance with its obligations under the data processing agreement by means of a valid Data Pro Certificate or an at least equivalent certificate or audit report (Third Party Memorandum) from an independent expert, if it has such a certificate or audit report.

7.5 In addition, at the Client's request, the Data Processor will make available all further information reasonably necessary to demonstrate compliance with the arrangements made in this data processing agreement. If the Client nevertheless has reason to believe that the processing of Personal Data does not take place in accordance with the data processing agreement, it may, at most once a year, have an audit carried out at the Client's expense by an independent, certified, external expert who demonstrably has experience with the type of processing carried out on the basis of the Agreement. The audit will be limited to verifying compliance with the arrangements regarding the processing of the Personal Data as laid down in this Data processing agreement. The expert will be bound by a duty of confidentiality with respect to what they find and will report to the Client only that which constitutes a shortcoming in the performance of the obligations the Data Processor has under this data processing agreement. The expert will provide the Data Processor with a copy of their report. The Data Processor may refuse an audit or instruction from the expert if, in its opinion, it conflicts with the GDPR or other legislation or constitutes an impermissible infringement of the security measures it has taken.

7.6 The parties will consult as soon as possible about the outcomes in the report. The parties will follow up the proposed improvement measures laid down in the report insofar as this can reasonably be expected of them. The Data Processor will implement the proposed improvement measures insofar as, in its opinion, they are appropriate, taking into account the processing risks associated with its product or service, the state of the art, the implementation costs, the market in which it operates, and the intended use of the product or service.

7.7 The Data Processor has the right to charge the Client the costs it incurs in the context of what is stated in this article.

Article 8. Sub-Processors

8.1 The Data Processor has stated in the Data Pro Statement whether, and if so which, third parties (sub-processors) the Data Processor engages in the processing of the Personal Data.

8.2 The Client gives the Data Processor permission to engage other sub-processors to carry out its obligations arising from the Agreement.

8.3 The Data Processor will inform the Client about a change in the third parties engaged by the Data Processor, for example by means of an adapted Data Pro Statement. The Client has the right to object to the aforementioned change by the Data Processor. The Data Processor ensures that the third parties it engages commit to the same security level regarding the protection of the Personal Data as the security level to which the Data Processor is bound towards the Client on the basis of the Data Pro Statement.

Article 9. Miscellaneous

These Standard Clauses for processing, together with the Data Pro Statement, form an integral part of the Agreement. All rights and obligations from the Agreement, including the applicable terms and conditions and/or limitations of liability, therefore also apply to the data processing agreement.

Questions about this data processing agreement?

Contact our Data Protection Officer for questions about this data processing agreement or data protection.

Transparency

We value openness

CommuniQate

Part of AppCenter Nederland B.V.

Marssteden 106

7547TD Enschede

Legal questions

legal@communiqate.nl

Data Protection Officer

Maico Gieteling

Chamber of Commerce no.: 77687132 | VAT no.: NL861078766B01

Last updated: 8 March 2026