Data Processing Agreement

Last updated September 9, 202611 articles

This agreement applies whenever we handle personal data on your behalf: your mailboxes, your files, your customer records, anything your system touches. Article 28 GDPR requires it in writing, so here it is, ready to sign. It forms part of our terms and overrides them for anything about processing.

You are the controller: it is your business that decides why this data is processed. Nivoraworks, sole proprietorship of Kamiel Niville, Julius en Maurits Sabbestraat 15, 8000 Brugge, Belgium, company and VAT number BE 1041.516.417, is the processor, and acts only on your instructions.

For our own administration, invoicing and security we are the controller ourselves. Our privacy policy covers that part.

Subject: delivering, securing and supporting the system we built for you. Duration: as long as the engagement runs, plus the wind-down below.

  • Categories of people: your employees, your customers, your suppliers and anyone appearing in the data your system handles.
  • Categories of data: whatever the agreed scope requires. Typically names, contact details, correspondence, documents and the fields your process needs.
  • Special categories: we do not ask for them. They can appear because someone put them in a document or a message; we then process them only to run the agreed feature.

We process personal data only on your documented instructions. The proposal, the agreed scope and your normal use of the system are those instructions. If the law obliges us to do more, we tell you first, unless that notice is itself prohibited. If we believe an instruction breaks data-protection law, we say so.

You confirm that you have a lawful basis for the data you put into the system, that you have informed the people it concerns, and that you answer their requests as the controller.

You decide who on your side gets access, and you withdraw that access promptly when somebody leaves.

Everyone who touches your data is bound by confidentiality, including the freelancers and subcontractors we bring in. Access is limited to whoever needs it for a specific task.

We take appropriate technical and organisational measures: encrypted secrets kept out of the browser, TLS in transit, row-level security on databases, separated environments, logging and restricted access. Measures can evolve as long as the level of protection does not drop.

We use hosting and infrastructure providers to run what we build. Our privacy policy names them and where they operate; we prefer providers inside the European Economic Area, and our databases run in Ireland and Germany, with our own server in Paris.

We impose the same obligations on them and remain responsible to you for their work. We tell you before a new provider starts handling your data, and you can object on reasonable data-protection grounds. Transfers outside the EEA run on the European Commission’s standard contractual clauses; ask us and we send you a copy.

We do not use your data to train or improve AI models, and the model providers we use commit contractually not to train on it either. If we ever want to use real examples from your work to improve something, we ask separately and in writing, and you can refuse without consequence.

If someone contacts us about their data in your system, we pass the request to you and do not answer it ourselves, unless you ask us to.

We help you, in proportion to what we know and what we can see, with answering those requests, with a data protection impact assessment, and with any consultation of the supervisory authority.

We tell you without undue delay after we become aware of a breach affecting your data, with what we know at that point about what happened, which data is involved, the likely consequences and what we are doing about it. We keep you updated as the investigation moves, and we help you meet your own notification duty. Telling you is not an admission of fault.

At the end of the engagement we return your data or delete it, whichever you choose, except where the law requires us to keep something. We give you a reasonable window to export before anything is deleted.

Backups expire on their own rolling schedule and are never restored as live data. As long as they exist they stay under the same security and confidentiality.

On request we give you the information you need to demonstrate compliance with article 28 GDPR: this agreement, our privacy policy, the list of providers, and a description of our measures.

You can ask for one audit per year, or more if a supervisory authority or an incident requires it, with reasonable notice, during office hours, without disrupting the service and under confidentiality. If you organise the audit yourself, you carry its cost.

Where this agreement and our terms disagree about processing, this agreement wins. For everything else the terms continue to apply, including the liability arrangement.

For a signed copy, a question about this agreement, or a request from someone whose data we handle: email kamiel@nivoraworks.com or call +32 489 00 77 37.

Something unclear in here?

Ask us. We would rather explain a clause than have you guess at it.

Go to contact