Back to VB Websites

Draft

Processor agreement

This agreement covers processing in which the Customer is controller and VB Websites is processor. The parties conclude it electronically: the Customer accepts it at intake checkout, before the first intake upload, and VB Websites confirms the order. The accepted wording, language, version and acceptance timestamp are recorded with the order; the order confirmation lists this document with its title, version, link and SHA-256 checksum. From acceptance it governs all processing on the Customer’s behalf from intake onwards, including receipt, storage, the making of the designs and later publication of supplied content. Acceptance at annual checkout reaffirms the agreement and does not postpone its start.

1. Parties and scope

Controller: the customer identified in the accepted order (Customer).

Processor: Van Bostelen Software, trading as VB Websites, Emmakade 123, 2411 JH Bodegraven, Netherlands, KVK 42127942, VAT NL005517908B88 (Processor).

The Processor processes personal data only to provide the ordered website, quote-form, hosting, mail, support and correction services described in the order and on the Customer's documented instructions. The Customer decides the purposes and essential means.

This agreement does not cover data for which VB Websites is an independent controller, including its own applications, contract administration, billing, tax records, support administration, fraud prevention and platform security. It does not turn Mollie, SIDN, KVK, a bank or another independent controller into a Processor.

2. Processing details

The Customer must document any additional instruction, retention exception, public claim, special-category processing or international-transfer requirement.

3. Instructions and confidentiality

The Processor follows documented Customer instructions and tells the Customer if an instruction appears to breach applicable data-protection law. The Processor may suspend the disputed processing where necessary to avoid unlawful processing and will seek clarification.

Persons authorised by the Processor to process Customer data are bound by confidentiality. Access is limited to the service need and removed when no longer required.

4. Security measures

The Processor maintains measures appropriate to the risk, including:

5. Subprocessors

The Processor may use only the subprocessors listed in the subprocessor notice accepted alongside this agreement. That notice states each category's purpose, data, location, transfer mechanism, retention and deletion. The Processor provides the names of the suppliers within a category on request, before and after acceptance. Planned or unresolved providers are not authorised.

The Customer gives general written authorisation for the subprocessors within the listed categories. The Processor emails every intended addition or replacement at least 30 days before use. The Customer may object within that period on documented data-protection grounds. The Processor seeks a compliant alternative and does not use the disputed provider for that Customer's data while the objection is unresolved. If no reasonable alternative exists, either party may end the affected service; the paid annual fee is then not refunded, subject to mandatory law, and the agreed return/deletion process applies unchanged. Subprocessors receive equivalent contractual duties; the Processor remains responsible as required by GDPR Article 28. An urgent change is not an exception to lawful authorisation.

Mollie is excluded from this subprocessor list for ordinary payment processing when it acts as an independent controller. Its separate terms and privacy notice apply.

6. Assistance

Taking account of the processing, the Processor assists the Customer with:

Send requests to support@vbwebsites.nl. VB Websites starts routine assistance promptly and supplies available information within ten working days, sooner where a statutory deadline or incident requires it. Routine rights requests, incident cooperation and existing compliance evidence are included. Additional work requires an agreed quote; a cost discussion must not delay mandatory assistance. The Customer may conduct one reasonable audit each year on fourteen days' notice and additional audits where an incident, credible compliance concern or supervisory authority requires them. Use remote evidence first where sufficient. An on-site audit must protect other customers and secrets and avoid unnecessary disruption; confidentiality and ordinary business hours apply unless urgency requires otherwise. Each party bears its ordinary costs; VB Websites bears remediation costs for its own breach. These arrangements do not restrict Article 28 audit rights.

7. Personal-data breach

The Processor notifies the Customer without undue delay after becoming aware of a personal-data breach affecting Customer data, by email to the security contact recorded in the order, otherwise its authorised primary contact. Initial notice must not await a complete investigation; updates follow as facts become available. The notice includes known facts, affected systems/data, likely consequences, containment, remediation and an update owner. The Processor must not notify data subjects or regulators on the Customer's behalf unless instructed or legally required.

8. Return and deletion

At the Customer's choice after service end, the Processor returns the Customer data in the agreed export format and deletes remaining copies, unless law requires retention. The Processor records deletion evidence and applies the same instruction to authorised subprocessors. Backups may expire on their documented cycle, must remain inaccessible for ordinary use, and must not restore deleted data without replaying deletion tombstones.

Request export through support@vbwebsites.nl before service end or within 30 days afterwards. Standard website export includes the paid static site and available Customer content in commonly usable files; our own tooling and non-transferable third-party licences are excluded. Agree and test domain and mailbox transfer before shutting them down; the domain remains the Customer's. Ordinary correction/update rights end with the service term. Delete public build copies within 30 days and remaining Customer content within 90 days of service end unless the Customer requests earlier deletion or law requires retention. Rolling operational backups expire within 35 days; any different provider or recovery-copy schedule is disclosed in the subprocessor notice or the order. Isolate legally retained records, restrict their use to the retention purpose, and delete them when that purpose ends. Supply a deletion record naming systems, dates, exceptions and final backup expiry. Preserve settlement and dispute evidence separately from the working intake.

9. Liability and execution

Dutch law and the customer contract's dispute and liability provisions apply only insofar as permitted by applicable law. This agreement takes precedence on personal-data processing. The commercial liability exclusion does not limit GDPR duties, data-subject compensation rights or other non-excludable liability; no additional Customer indemnity is created. Acceptance is recorded at intake checkout before any intake upload or other processing on the Customer’s behalf begins. The agreement continues to apply through the annual service and the agreed return and deletion of Customer data.