Please note: this is a template. This template must be reviewed by a lawyer before it is used. It is not legal advice.

Data processing agreement

Last updated: 18 August 2026

This is a translation for your convenience. In case of any discrepancy, the Dutch text prevails.

This data processing agreement (the “Agreement”) supplements the agreement between the parties for the use of TelMaar and governs the processing of personal data in accordance with article 28 GDPR.

Parties

  • Controller: [NAME OF CUSTOMER ORGANISATION], established in [PLACE OF BUSINESS], Chamber of Commerce number [COMMERCE NUMBER] (the “Controller”).
  • Processor: Mega Software, established in The Hague, Chamber of Commerce number 94577056 (the “Processor”).

Article 1: Definitions

  • GDPR: General Data Protection Regulation.
  • Personal Data: any information relating to an identified or identifiable natural person that is processed under this Agreement.
  • Processing: any operation performed on Personal Data, such as collecting, storing, consulting and erasing.
  • Sub-processor: a third party engaged by the Processor to carry out (part of) the Processing.

Article 2: Subject matter and duration

The Processor processes Personal Data solely for and on the instructions of the Controller, in the context of the use of TelMaar. This Agreement runs concurrently with the main agreement and terminates by operation of law upon its termination, without prejudice to the provisions that by their nature remain in force after termination (including article 10 on return and erasure).

Article 3: Nature and purpose of the processing

The Processing comprises storing, managing and processing Personal Data of the Controller's relations (customers, suppliers and their contact persons) for the purposes of financial administration, invoicing and customer relationship management, as further described in the Controller's privacy statement. The categories of data subjects and Personal Data correspond to articles 2 and 4 of that privacy statement.

Article 4: Obligations of the Processor

  • The Processor processes Personal Data solely on the basis of written instructions from the Controller, unless a legal obligation requires otherwise.
  • The Processor ensures that persons authorised to process Personal Data have committed themselves to confidentiality.
  • The Processor provides reasonable assistance with data subject requests for access, rectification or erasure, within the limits of the statutory retention duty.
  • The Processor informs the Controller without delay if, in its opinion, an instruction infringes applicable law.
  • The Processor does not use Personal Data to train or improve its own or anyone else's models, and imposes that obligation on the Sub-processors it engages.

Article 5: Security measures

The Processor takes appropriate technical and organisational measures, including:

  • Encryption of data in transit using TLS 1.3.
  • Encryption of data at rest using AES-256, with additional envelope encryption (a per-organisation data encryption key, encrypted with a master key) for payment provider credentials and other particularly sensitive fields.
  • Role-based access control (RBAC) and row level security in the database, so that data of one organisation is never accessible to another.
  • Mandatory two-factor authentication (2FA) for users with write access to financial data.
  • An append-only audit log of changes to financial data, including time, IP address and user.
  • Periodic, encrypted backups with a retention period of at least 7 and no more than 30 days, so that no copy remains after an erasure under article 10.

Article 6: Sub-processors

The Controller authorises the Processor to engage the following Sub-processors: Supabase (database, authentication, storage), Vercel (hosting), Resend (email), Stripe and Mollie (payment processing), Cloudflare (security and content delivery) and Anthropic (processing the questions and documents the Controller submits through the assistant). The assistant is available only to users with a financial role and processes only what the user submits; the data submitted is not used to train models. The Processor imposes obligations on each Sub-processor comparable to those set out in this Agreement and informs the Controller of any change to this list, with the opportunity to object.

Article 7: Transfers outside the EEA

Processing takes place within the European Economic Area in principle. Insofar as a Sub-processor processes Personal Data outside the EEA, this takes place solely on the basis of an adequacy decision of the European Commission or of the European Commission's standard contractual clauses (SCCs), supplemented by appropriate additional measures such as encryption of data in transit and at rest. On request, the Processor provides the Controller with insight into the transfer basis applicable to each Sub-processor.

Article 8: Data breaches and notification period

The Processor notifies the Controller of any identified personal data breach without undue delay and no later than 48 hours after discovery, so that the Controller can comply in good time with its own notification duty (within 72 hours) towards the Dutch Data Protection Authority. The notification covers at least the nature of the breach, the categories and approximate number of data subjects concerned, and the measures taken or proposed.

Article 9: Audits

The Controller is entitled, after prior written notice with a reasonable period of at least four weeks, to have audits carried out on compliance with this Agreement, or to be informed by means of a report from an independent third party made available by the Processor. The costs of an audit by the Controller are borne by the Controller, except where shortcomings are identified.

Article 10: Return and erasure after termination

Upon termination of the main agreement the Processor makes all Personal Data available in a common export format at the Controller's request, and then erases all Personal Data, with the exception of data that must be retained under a statutory retention duty (including the seven-year retention duty for tax purposes). Erasure takes place within 30 days of the request.

Article 11: Liability

The liability of the parties under this Agreement is governed by the main agreement between the parties, namely article 11 of the terms and conditions.

Article 12: Governing law

This Agreement is governed by Dutch law. Disputes are submitted to the competent court in the district of The Hague, unless mandatory law provides otherwise.

Signatures

Agreed and signed by both parties:

On behalf of the Controller

Name: [NAME]

Date: [DATE]

Signature: [SIGNATURE]

On behalf of the Processor

Name: [NAME]

Date: [DATE]

Signature: [SIGNATURE]

TelMaar uses cookies that are needed to run the site and the app. We would also like to measure how the site is used, with Google Analytics. We only do the latter if you say yes. Read the cookie statement