Draft
Processor agreement
This is a content draft, not a final agreement. It requires qualified review of the English legal and commercial wording before publication.
This agreement covers processing in which the Customer is controller and VB Websites is processor. The parties conclude it electronically: the Customer accepts it at intake checkout, before the first intake upload, and VB Websites confirms the order. The accepted wording, language, version and acceptance timestamp are recorded with the order; the order confirmation lists this document with its title, version, link and SHA-256 checksum. From acceptance it governs all processing on the Customer’s behalf from intake onwards, including receipt, storage, the making of the designs and later publication of supplied content. Acceptance at annual checkout reaffirms the agreement and does not postpone its start.
1. Parties and scope
Controller: the customer identified in the accepted order (Customer).
Processor: Van Bostelen Software, trading as VB Websites, Emmakade 123, 2411 JH Bodegraven, Netherlands, KVK 42127942, VAT NL005517908B88 (Processor).
The Processor processes personal data only to provide the ordered website, quote-form, hosting, mail, support and correction services described in the order and on the Customer's documented instructions. The Customer decides the purposes and essential means.
This agreement does not cover data for which VB Websites is an independent controller, including its own applications, contract administration, billing, tax records, support administration, fraud prevention and platform security. It does not turn Mollie, SIDN, KVK, a bank or another independent controller into a Processor.
2. Processing details
- Subject matter: website publication, visitor quote delivery, hosting, domain and mail administration, support and correction processing.
- Duration: the order term plus the agreed export and deletion period.
- Nature: collection, storage, organisation, transformation, publication, transmission, support, deletion and backup.
- Purposes: only the Customer's documented service instructions and this agreement.
- Data subjects: Customer contacts, staff and team members, website visitors, quote senders, suppliers and other persons named in submitted content.
- Personal data: identity and contact details, domain and mail details, content, images, testimonials, quote information, technical and delivery metadata.
- Special categories: not requested; the Customer must not submit them unless a written instruction and legal basis are approved.
- Criminal data: not requested and must not be submitted.
The Customer must document any additional instruction, retention exception, public claim, special-category processing or international-transfer requirement.
3. Instructions and confidentiality
The Processor follows documented Customer instructions and tells the Customer if an instruction appears to breach applicable data-protection law. The Processor may suspend the disputed processing where necessary to avoid unlawful processing and will seek clarification.
Persons authorised by the Processor to process Customer data are bound by confidentiality. Access is limited to the service need and removed when no longer required.
4. Security measures
The Processor maintains measures appropriate to the risk, including:
- strong operator authentication, MFA, role checks and customer isolation;
- encryption in transit and at rest where supported, protected secret storage, and no secrets in logs;
- private quarantine and clean asset storage, malware scanning, type/size checks and metadata removal;
- immutable source and document evidence, audit events, idempotent workflows and provider reconciliation;
- least-privilege provider credentials, environment separation, monitoring, backup and restore tests;
- retention jobs, deletion tombstones, legal-hold controls and post-termination deletion/export procedures;
- incident handling, evidence preservation and notification procedures.
5. Subprocessors
The Processor may use only the subprocessors listed in the subprocessor notice accepted alongside this agreement. That notice states each category's purpose, data, location, transfer mechanism, retention and deletion. The Processor provides the names of the suppliers within a category on request, before and after acceptance. Planned or unresolved providers are not authorised.
The Customer gives general written authorisation for the subprocessors within the listed categories. The Processor emails every intended addition or replacement at least 30 days before use. The Customer may object within that period on documented data-protection grounds. The Processor seeks a compliant alternative and does not use the disputed provider for that Customer's data while the objection is unresolved. If no reasonable alternative exists, either party may end the affected service; the paid annual fee is then not refunded, subject to mandatory law, and the agreed return/deletion process applies unchanged. Subprocessors receive equivalent contractual duties; the Processor remains responsible as required by GDPR Article 28. An urgent change is not an exception to lawful authorisation.
Mollie is excluded from this subprocessor list for ordinary payment processing when it acts as an independent controller. Its separate terms and privacy notice apply.
6. Assistance
Taking account of the processing, the Processor assists the Customer with:
- requests from data subjects;
- security, breach assessment and regulator communication;
- data-protection impact assessments and prior consultation where reasonably needed;
- information needed to demonstrate compliance and reasonable audits.
Send requests to support@vbwebsites.nl. VB Websites starts routine assistance promptly and supplies available information within ten working days, sooner where a statutory deadline or incident requires it. Routine rights requests, incident cooperation and existing compliance evidence are included. Additional work requires an agreed quote; a cost discussion must not delay mandatory assistance. The Customer may conduct one reasonable audit each year on fourteen days' notice and additional audits where an incident, credible compliance concern or supervisory authority requires them. Use remote evidence first where sufficient. An on-site audit must protect other customers and secrets and avoid unnecessary disruption; confidentiality and ordinary business hours apply unless urgency requires otherwise. Each party bears its ordinary costs; VB Websites bears remediation costs for its own breach. These arrangements do not restrict Article 28 audit rights.
7. Personal-data breach
The Processor notifies the Customer without undue delay after becoming aware of a personal-data breach affecting Customer data, by email to the security contact recorded in the order, otherwise its authorised primary contact. Initial notice must not await a complete investigation; updates follow as facts become available. The notice includes known facts, affected systems/data, likely consequences, containment, remediation and an update owner. The Processor must not notify data subjects or regulators on the Customer's behalf unless instructed or legally required.
8. Return and deletion
At the Customer's choice after service end, the Processor returns the Customer data in the agreed export format and deletes remaining copies, unless law requires retention. The Processor records deletion evidence and applies the same instruction to authorised subprocessors. Backups may expire on their documented cycle, must remain inaccessible for ordinary use, and must not restore deleted data without replaying deletion tombstones.
Request export through support@vbwebsites.nl before service end or within 30 days afterwards. Standard website export includes the paid static site and available Customer content in commonly usable files; our own tooling and non-transferable third-party licences are excluded. Agree and test domain and mailbox transfer before shutting them down; the domain remains the Customer's. Ordinary correction/update rights end with the service term. Delete public build copies within 30 days and remaining Customer content within 90 days of service end unless the Customer requests earlier deletion or law requires retention. Rolling operational backups expire within 35 days; any different provider or recovery-copy schedule is disclosed in the subprocessor notice or the order. Isolate legally retained records, restrict their use to the retention purpose, and delete them when that purpose ends. Supply a deletion record naming systems, dates, exceptions and final backup expiry. Preserve settlement and dispute evidence separately from the working intake.
9. Liability and execution
Dutch law and the customer contract's dispute and liability provisions apply only insofar as permitted by applicable law. This agreement takes precedence on personal-data processing. The commercial liability exclusion does not limit GDPR duties, data-subject compensation rights or other non-excludable liability; no additional Customer indemnity is created. Acceptance is recorded at intake checkout before any intake upload or other processing on the Customer’s behalf begins. The agreement continues to apply through the annual service and the agreed return and deletion of Customer data.