Data Processing Agreement

The Data Processing Agreement (DPA) of ai-geletterd.nl — we process personal data solely on your instructions as controller, within the EU.

Version:
v1.0 (draft)
Effective from:
Last updated:
Download as a document

Sign-in required. The download is recorded in your audit log.

Draft — this text is still under legal review and not yet final.

This is an informational translation. The Dutch version is legally binding.

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "controller" — the customer) and ai-geletterd.nl (the "processor") and governs the processing of personal data within the meaning of Article 28 of the General Data Protection Regulation (GDPR). Where this DPA and the general terms differ on data protection, this DPA prevails.

1. Roles

You determine the purpose and means of processing your employees' personal data and remain the controller. ai-geletterd.nl processes that data solely on your behalf and on your documented instructions, except where a legal obligation requires otherwise; in that case we notify you in advance unless the law prohibits such notice.

2. Subject matter, nature and duration

  • Subject matter: delivering AI-literacy training and related services with which you discharge your obligations under Article 4 of the EU AI Act.
  • Nature of processing: storing, consulting, organising, recording progress and issuing certificates.
  • Duration: for as long as the underlying agreement runs, plus the retention periods set out in our privacy policy.

3. Categories of data subjects and data

  • Data subjects: the controller's employees and administrators.
  • Categories of personal data: name, work email address, job role, progress and assessment results, and certificate data. We do not process special categories of personal data (Article 9 GDPR) and ask you not to supply them.

4. Security

We implement appropriate technical and organisational measures (Article 32 GDPR), including:

  • encryption at rest and in transit;
  • strict multi-tenant isolation via Row-Level Security on every tenant-scoped table;
  • need-to-know access with mandatory two-factor authentication for administrators;
  • logging of security-relevant events.

A fuller description is available in our security document on request.

5. Subprocessors

You grant general authorisation to engage subprocessors. We maintain a fixed list and bind each subprocessor contractually to at least the same obligations as in this DPA. The current subprocessors are:

  • Vercel — hosting and edge runtime (Frankfurt, fra1).
  • Supabase — database, authentication and storage (Frankfurt, eu-central-1).
  • Anthropic — LLM inference (Claude); EU endpoint where available, with SCC 2021/914 module 2 + DPA for any US fallback.
  • Mollie — payments (Amsterdam).
  • Resend — transactional email (EU).
  • Sentry — error monitoring (EU).
  • PostHog — in-app product analytics, only after consent (Frankfurt).
  • Plausible — cookieless marketing analytics (EU).
  • Upstash — rate limiting (EU).
  • Backblaze B2 — encrypted cold backups (Amsterdam).

We give you at least 30 days' prior notice of any change to this list so you can object. If you object on reasonable grounds and we cannot resolve it, you may terminate the affected part of the underlying agreement.

6. Transfers outside the EEA

All customer data is processed within the EU: primarily in Frankfurt, with cold backups in Amsterdam. Any exceptional transfer to a third country (only possible via the Anthropic fallback) is governed by the standard contractual clauses (SCC 2021/914 module 2), the subprocessor's DPA and a documented Transfer Impact Assessment.

7. Assistance to the controller

Taking into account the nature of the processing, we assist you:

  • in responding to data-subject requests (Articles 12–22 GDPR) — access, rectification, erasure and portability are partly available self-service in the product;
  • with your obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessment).

8. Personal data breaches

We notify you of a personal data breach without undue delay after becoming aware of it, with the information you need to meet your notification duty (Articles 33–34 GDPR). Notification to the Dutch Data Protection Authority and to data subjects remains your responsibility as controller.

9. Return and deletion

On termination of the services we delete or return the personal data at your choice, subject to a statutory retention obligation. The fiscal retention obligation (seven years, Dutch Turnover Tax Act 1968, Article 52) and the evidentiary burden for Article 4 of the AI Act may mean that certain data (such as certificate evidence) is retained longer in pseudonymised form; this is described in our privacy policy.

10. Audits

You may, at most once a year and on reasonable prior notice, audit compliance with this DPA. We satisfy this right primarily by providing current certifications and audit reports of ourselves and our subprocessors.

This DPA is a draft and will undergo legal review before use with a paying customer. No rights can be derived from this text while its status is "draft".

Sources