Legal
Data Processing Agreement
Last updated 3 July 2026
This is Thirvu's standard Data Processing Agreement template. Our own details are completed below; the fields for the other party, and the engagement-specific annexes, are shown in brackets. You are welcome to review it, sign it as-is, or propose your own version. We recommend both parties have it reviewed by a qualified advisor before signing. First published version, 3 July 2026.
Parties
This Data Processing Agreement ("DPA") is entered into by:
- [Client legal name], registered under [Client registration number], with its registered office at [Client address] (the "Controller"); and
- Thirvu Solutions B.V., KvK 96575778, BTW NL867668386B01, with its visiting address at Ceintuurbaan 15, 8022 AW Zwolle, the Netherlands, contact: mail@thirvu.com (the "Processor").
This DPA forms part of the agreement between the parties for [description of services] dated [date] (the "Main Agreement") and governs the processing of personal data by the Processor on behalf of the Controller.
1. Definitions
1.1 "GDPR" means Regulation (EU) 2016/679. The terms "personal data", "processing", "data subject", "controller", "processor", "sub-processor", "personal data breach", and "supervisory authority" have the meanings given to them in the GDPR.
1.2 "Processing Details" means the description of the processing in Annex 1.
2. Scope and roles
2.1 The Processor processes personal data solely on behalf of the Controller for the performance of the Main Agreement, as described in Annex 1.
2.2 The Controller determines the purposes and means of the processing and warrants that it has a valid legal basis for the processing it instructs.
2.3 In case of conflict between this DPA and the Main Agreement regarding the processing of personal data, this DPA prevails.
3. Instructions
3.1 The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law. In that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
3.2 The Processor informs the Controller without delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
4. Confidentiality
4.1 The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2 Access to personal data is limited to persons who need it to perform the Main Agreement.
5. Security
5.1 The Processor implements the technical and organisational measures set out in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, so as to ensure a level of security appropriate to the risk (Article 32 GDPR).
5.2 The Processor may update the measures in Annex 2, provided the updated measures do not reduce the overall level of protection.
6. Sub-processors
6.1 The Controller grants the Processor general written authorisation to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex 3.
6.2 The Processor informs the Controller in writing of any intended addition or replacement of a sub-processor at least 14 days before the change takes effect. The Controller may object in writing within those 14 days on reasonable, data-protection-related grounds. If the parties cannot resolve the objection, the Controller may terminate the affected services.
6.3 The Processor imposes on each sub-processor, by way of contract, data protection obligations equivalent to those in this DPA, and remains fully liable to the Controller for the performance of the sub-processor's obligations.
7. Assistance
7.1 Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR. The Processor forwards any such request it receives directly to the Controller without undue delay and does not respond to it itself, unless instructed otherwise.
7.2 Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations in Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).
8. Personal data breach
8.1 The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the personal data processed under this DPA.
8.2 The notification contains, insofar as known at that moment: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available.
8.3 The Processor does not notify the supervisory authority or data subjects itself; this is the Controller's responsibility.
9. Data location and transfers
9.1 The Processor processes personal data within the European Economic Area, unless the Controller instructs or approves otherwise in writing.
9.2 Any transfer of personal data to a country outside the EEA takes place only in accordance with Chapter V GDPR, such as on the basis of an adequacy decision or standard contractual clauses.
10. Deletion or return
10.1 Upon termination of the Main Agreement, the Processor, at the choice of the Controller, deletes or returns all personal data processed under this DPA, and deletes existing copies, unless Union or Member State law requires storage of the personal data.
10.2 The Processor confirms the deletion in writing at the Controller's request.
11. Audits
11.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and this DPA.
11.2 The Processor first provides available audit reports, certifications, or other relevant documentation. If these are reasonably insufficient, the Controller may conduct or mandate an audit, limited to the processing under this DPA, no more than once per calendar year, with at least 30 days prior written notice, during business hours, and without unreasonable disruption to the Processor's operations.
11.3 The Controller bears the costs of the audit, including the Processor's reasonable internal costs, unless the audit reveals a material breach of this DPA by the Processor.
12. Liability
12.1 The liability of each party under or in connection with this DPA is governed by the liability provisions of the Main Agreement, including any caps and exclusions agreed there.
13. Term and termination
13.1 This DPA takes effect on the effective date of the Main Agreement and remains in force as long as the Processor processes personal data on behalf of the Controller.
13.2 Obligations that by their nature extend beyond termination, including Sections 4, 10, and 12, survive termination.
14. Governing law and court
14.1 This DPA is governed by Dutch law. Disputes arising from or in connection with this DPA are submitted to the competent court of the Rechtbank Overijssel, location Zwolle, the Netherlands.
Signatures
| Controller | Processor | |
|---|---|---|
| Name | [name] | [name] |
| Title | [title] | [title] |
| Date | [date] | [date] |
| Signature |
Annex 1: Processing Details
- Subject matter: [processing of personal data in the context of the services under the Main Agreement]
- Duration: the term of the Main Agreement.
- Nature and purpose of the processing: [e.g. hosting, storage, analysis, and processing necessary to deliver and support the agreed services]
- Categories of personal data: [e.g. names, business contact details, user account data, log data; no special categories unless explicitly listed]
- Categories of data subjects: [e.g. the Controller's employees, customers, and end users]
- Contact point Controller: [name, role, email]
- Contact point Processor: [name, role], mail@thirvu.com
Annex 2: Technical and Organisational Security Measures
- Encryption of personal data in transit (TLS) and at rest.
- Access control: authentication required for all systems processing personal data; multi-factor authentication where supported.
- Least privilege: access rights limited to what each role requires, reviewed periodically, and revoked without delay when no longer needed.
- Logging and monitoring of access to systems processing personal data.
- Regular backups, stored encrypted, with periodic restore testing.
- Timely installation of security updates on systems under the Processor's control.
- Segregation of client environments and of development, test, and production environments.
- Confidentiality commitments for all personnel with access to personal data (Section 4).
- A documented procedure for detecting, handling, and reporting personal data breaches (Section 8).
Annex 3: Sub-processors
The Processor engages sub-processors to deliver the services. All sub-processors are established in the European Union or European Economic Area. The current list, with each sub-processor's name, location, and service, is provided to the Controller as part of the engagement and is available on request. Sub-processors may differ per engagement; the list below is completed in the signed copy.
| Sub-processor | Registered office | Service | Processing location |
|---|---|---|---|
| [provided per engagement] | [EU / EEA] | [service] | [EU / EEA] |