Skip to content
SocialMediaGroei.nl

Data processing agreement

Version 1.0 · in force from

The Dutch version is binding

This is a translation for your convenience. Only the Dutch version is legally binding; in case of any difference, the Dutch text prevails.

Read the Dutch version

This is a downloadable model document that is sent along with the signed agreement and sets out the arrangements for processing personal data.

Introduction

This document is a model data processing agreement as referred to in Article 28 of the General Data Protection Regulation (GDPR). It is sent as an annex to, and forms part of, the signed agreement between the client and SocialMediaGroei.nl, to the extent that SocialMediaGroei.nl processes personal data on behalf of the client while delivering the service. This model document is intended as a downloadable, standard starting point; in the agreement itself the parties may agree specific additions or departures from it.

Article 1 - Parties and definitions

1.1 The parties to this data processing agreement are:

  • the client, as named in the underlying agreement, hereinafter the "controller"; and
  • SocialMediaGroei.nl, established in the Netherlands, Chamber of Commerce number 94577056, reachable at info@socialmediagroei.nl, hereinafter the "processor".

1.2 Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "data breach" have the meaning given to them by the GDPR.

Article 2 - Subject matter and duration

2.1 This data processing agreement governs the processing of personal data that the processor carries out on behalf of the controller within the framework of the agreement concluded between the parties for social media management and related services.

2.2 This data processing agreement is entered into for the duration of the underlying agreement and ends by operation of law when that agreement ends, without prejudice to the provisions that by their nature are intended to continue to apply after termination, including Article 9 (return and deletion) and Article 10 (liability).

Article 3 - Nature and purpose of the processing

3.1 The processor processes personal data exclusively within the framework of:

  • managing and securing the controller's social media accounts;
  • creating, scheduling and publishing content on those accounts;
  • community management, including answering messages, comments and direct messages on behalf of the controller;
  • managing advertising campaigns and processing the lead data arising from them, such as contact forms and lead ads.

3.2 The processor processes the personal data exclusively on the basis of written instructions from the controller, including the instructions arising from the underlying agreement, unless a statutory obligation resting on the processor requires it to process.

Article 4 - Types of personal data and categories of data subjects

4.1 Within the framework of the service the following types of personal data may be processed: names, usernames and profile details of followers and people who comment, contact details (such as email address and phone number) from lead forms and advertising campaigns, the content of messages and comments, and other data that data subjects voluntarily provide through social media or the controller's advertising campaigns.

4.2 The categories of data subjects are: the controller's followers and clients on social media, people who respond to content or send messages, and people who leave their details through an advertising campaign or lead form of the controller.

Article 5 - Obligations of the processor

5.1 The processor processes the personal data properly and carefully and in accordance with the GDPR and this data processing agreement.

5.2 The processor will not use the personal data for its own purposes or for the purposes of third parties, and will not process it for longer or differently than necessary for performing the agreement.

5.3 The processor imposes a duty of confidentiality on staff and engaged third parties who have access to the personal data.

5.4 Within the limits of what can reasonably be expected of it, the processor cooperates in carrying out a data protection impact assessment (DPIA) or a prior consultation, if the controller is obliged to do so and this can reasonably be required of the processor.

Article 6 - Sub-processors

6.1 The controller gives the processor general permission to use the following sub-processors for delivering the service, which correspond to the parties also named as recipients and processors in the privacy statement of SocialMediaGroei.nl:

  • Vercel (hosting);
  • Supabase (database);
  • Stripe (payments);
  • Resend (email);
  • the social media publishing tool used;
  • Google Analytics 4 (analytics), which is used as soon as the website visitor gives permission for it through the cookie banner, and to the extent that personal data of the controller's data subjects is processed in doing so.

6.2 The processor informs the controller in advance of intended changes in the use of sub-processors, so the controller has the opportunity to object on reasonable grounds within a reasonable period.

6.3 The processor imposes on every sub-processor obligations that are at least equivalent to the obligations applying to the processor under this data processing agreement, and remains responsible towards the controller for the sub-processor's compliance with them.

Article 7 - Security measures

7.1 The processor takes appropriate technical and organisational measures to protect personal data against loss or any form of unlawful processing, including in any event: encryption of data traffic, role-based restriction of access to systems and accounts, use of strong authentication where possible, and periodic review of access rights.

7.2 The processor keeps these measures up to date in the light of the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing and the risks for data subjects.

Article 8 - Duty to report data breaches

8.1 The processor notifies the controller without unreasonable delay, and in any event within 48 hours of discovering it, of a security breach that has led or could reasonably lead to a data breach concerning the personal data processed by the processor.

8.2 In doing so the processor provides, to the extent known at that moment, information about the nature of the data breach, the categories of personal data and data subjects (possibly) involved, the measures taken and proposed, and works together with the controller so the controller can comply with any duty to report to the Dutch Data Protection Authority and/or to data subjects.

Article 9 - Assistance with the rights of data subjects

9.1 To the extent that the controller cannot reasonably handle it itself, the processor cooperates within a reasonable period with requests from data subjects to exercise their GDPR rights (such as access, rectification, erasure, restriction, portability or objection) relating to the personal data processed by the processor on behalf of the controller.

Article 10 - Audit

10.1 The controller has the right, after prior written notice with a reasonable period and no more than once a year (unless there is specific cause), to have an audit carried out into the processor's compliance with this data processing agreement, or to engage an independent third party for that purpose who is bound by a duty of confidentiality.

10.2 The processor gives reasonable cooperation to such an audit and provides the relevant information, to the extent that this does not lead to unreasonable disruption of the processor's operations or to a breach of confidentiality obligations towards other clients.

Article 11 - Return and deletion after termination

11.1 After the underlying agreement ends, the processor will, at the controller's choice, return and/or delete all personal data it processes on behalf of the controller, and destroy existing copies, unless a statutory provision obliges the processor to store it further.

11.2 To the extent reasonably possible within the platforms and tools used, the processor cooperates in exporting data to a format or system designated by the controller.

Article 12 - Liability

12.1 The processor's liability towards the controller for damage arising from this data processing agreement is subject to the same limitations as set out in the general terms and conditions of SocialMediaGroei.nl that apply to the underlying agreement, unless mandatory law provides otherwise.

12.2 Each party is itself responsible, and liable towards data subjects and supervisory authorities, for compliance with its own obligations under the GDPR.

Article 13 - Applicable law

13.1 This data processing agreement is governed by Dutch law. Disputes are settled in the same way as provided in the general terms and conditions that apply to the underlying agreement.

Article 14 - Final provision

14.1 This model document is deemed to form an integral part of the agreement between the controller and the processor from the moment that agreement is signed, without a separate signing moment for this document being required, unless the parties agree otherwise. Company details of SocialMediaGroei.nl: established in the Netherlands, Chamber of Commerce number 94577056, reachable at info@socialmediagroei.nl.

Newsletter

What works on social media, without the noise

Now and then an email about what we see working at businesses in the Netherlands: costs, choices and concrete examples. Every answer is also in the knowledge base.

Subscribe

You can unsubscribe with one click in every email.