Data Processing Agreement
For the personal data you record in Starting Up about other people: your clients, relationships and contacts.
The Dutch text is the binding version. This translation is here so it can be read; where the two differ, the Dutch text prevails.
There is nothing you need to do. This agreement is part of the terms and conditions and applies automatically as soon as you use Starting Up. There is no copy to sign and no form to request. If you would still like a signed copy for your own records, email —.
1. Parties and roles
You are the controller. You decide what you record about other people and why. We do not know that and decide nothing about it.
We are the processor (—, KvK —). We store and display that data on your behalf and do nothing further with it.
This division applies only to data you enter about third parties. For your own account data we are the controller ourselves — see the privacy statement, section 2.
2. Subject matter, nature and duration
| Question | Answer |
|---|---|
| Subject matter | Delivering Starting Up and the products you admit to it |
| Nature of processing | Storing, organising, displaying, amending, passing to a product you admit, and deleting — all on your instruction |
| Purpose | Your relationship management and the operation of the products you use |
| Categories of data subject | Your clients, prospects, suppliers, contacts, team members, and others you record |
| Categories of data | Name, email address, phone number, company details (including Chamber of Commerce number), role, contact moments, activities, and free text you enter |
| Duration | As long as you use the service, and thereafter as in section 9 |
Special categories. Starting Up is not built for data on health, race, religion, political opinions, sexual orientation, criminal matters, or a Dutch citizen service number (BSN). Do not record those here. The free-text fields make it technically possible; this agreement does not cover it, and the security is not designed for it.
3. Our instructions
We process only on your documented instruction. Your use of the service — what you enter, which products you admit, which connections you make — is that instruction. Additional instructions can be emailed to —.
If the law requires us to process something outside your instruction, we will say so beforehand unless that law forbids it. If we believe an instruction breaches the GDPR, we will say so.
We do not use your data for our own purposes, for product development, for statistics across customers, or to train AI models.
4. Confidentiality
Everyone on our side with access to this data is bound to confidentiality. Access is given to those who need it to deliver the service or resolve a fault, and no wider.
5. Security
We take appropriate technical and organisational measures. Concretely, these currently include:
- separation between workspaces enforced by row-level security in the database, not by a filter in the application;
- an application role without superuser rights, so those policies actually apply;
- encryption of connection access tokens, with a key that exists only in the runtime environment;
- encrypted connections (HTTPS) and encrypted storage at the hosting provider;
- sign-in by email link, rate-limited attempts, and temporary locking after repeated failures;
- an immutable log of actions per workspace;
- periodic backups, to recover from a failure on our side.
The full current description is in section 10 of the privacy statement. Measures may change as long as the level of protection stays equivalent or improves.
6. Sub-processors
You give us general authorisation to engage sub-processors. Who they are, for what and where, is on the sub-processors page. That list forms part of this agreement.
We impose on every sub-processor the same obligations we take on here, and we remain fully liable to you for what they do.
For a new or replacement sub-processor we give at least 30 days' notice by email. If you have a reasoned objection, tell us within those 30 days; if we cannot resolve it, you may terminate the affected component free of charge, with a refund of the prepaid portion.
7. Transfers outside the EEA
The service runs inside the EU. Transfers beyond it happen only as described on the sub-processors page — today that amounts to AI requests, and only when you use an AI feature. We rely on the European Commission's Standard Contractual Clauses and on the relevant party's own processing terms.
8. Assistance with your obligations
Data subject rights
If you receive a request for access, correction, erasure or portability, you can handle most of it yourself in the app — you can view, amend and delete every record. If that does not work, we help within two business days. If such a request reaches us directly, we do not answer it ourselves but refer it to you, and let you know it exists.
Data breaches
If we discover a security breach involving your data, we report it without undue delay and at the latest within 48 hours of discovery, with what we know about its nature, scope, likely consequences and the measures taken. Notifying the supervisory authority and the data subjects is yours to do; we supply what you need for it.
DPIA and prior consultation
If you have to carry out a data protection impact assessment, we provide the information about our processing that you need for it.
9. Return and deletion
When the agreement ends, we delete the personal data within 30 days, unless the law requires us to keep it longer. Within those 30 days you may ask for a copy; we provide it in a common, machine-readable format.
Backups are not searched to remove individual records. They expire on their own cycle and remain secured and unused until then, except to recover from a failure.
10. Audit
On request we give you the information needed to demonstrate that we meet these obligations. You may have an audit carried out at most once a year by an independent expert bound to confidentiality, at your own cost, provided it is announced at least 30 days in advance and arranged so that other customers are not affected. If the audit shows a failure on our part, we bear the cost of putting it right.
11. Liability and closing
The liability regime in section 10 of the terms and conditions applies to this agreement. This agreement ends together with the main agreement; sections 4 and 9 survive.
The Dutch text is binding. This English translation exists for understanding; where they differ, the Dutch prevails.