<!-- cmdz — Data processing agreement. Source: https://www.cmdz.com/dpa -->
# Data processing agreement
> The GDPR article 28 processing agreement, downloadable and readable here without a sales conversation. It forms an integral part of the agreement.

The GDPR article 28 processing agreement, downloadable and readable here without a sales conversation. It forms an integral part of the agreement.

Last updated: 1 August 2026 · Binadit B.V. · KvK 80923216

This data processing agreement forms an integral part of the agreement and is drawn up on the basis of art. 28 GDPR. It applies to the processing of personal data that we carry out as **processor** on behalf of you as **controller** when providing the Services. You can read and copy it here without talking to anyone first.

## Article 1 — Subject matter and duration

We process personal data solely to provide the Services to you, and only for the duration of the agreement, unless a legal obligation requires longer retention.

## Article 2 — Nature and purpose

The processing comprises running, storing and managing the applications and data that you place on the platform. We process solely on your documented instructions, whereby the use of the platform — the configuration you choose — constitutes such instructions.

## Article 3 — Categories of data and data subjects

The categories of personal data and data subjects are determined by you, since you decide which data you place on the platform. Typically this concerns data of your employees and the end users of your applications. You do not place special categories of personal data without a valid legal basis.

## Article 4 — Obligations of the processor

We undertake to: process only on instructions; ensure confidentiality; take appropriate security measures as described in article 6; assist you with requests from data subjects and with your own GDPR obligations, including data protection impact assessments and notifications; and, upon termination, delete or return all personal data at your choice.

## Article 5 — Subprocessors

You grant general authorization for the engagement of subprocessors, provided that we inform you in advance of changes, impose equivalent obligations on those subprocessors, and remain fully liable for their actions.

Current subprocessors: Mollie B.V. (payment processing), WeFact B.V. (billing), Hosting Concepts B.V. / Openprovider (domains), Cloudflare (only where you enable Cloudflare DNS), our transactional email provider, and the data center and hardware supplier for the region you selected. The data resides in the region you chose.

## Article 6 — Technical and organizational measures

We take measures appropriate to the risk, including: encryption in transit (TLS 1.2 or higher) and at rest (LUKS2); isolation of customer workloads in Kata micro-VMs; access based on least privilege with passkeys; append-only audit logging; backup and recovery procedures with point-in-time recovery for databases; and regular security audits. The full description is available on request.

## Article 7 — Data breaches

We report a personal data breach without undue delay, and in any event within 72 hours of becoming aware of it, to you. The report contains at least: the nature of the breach, the categories concerned and the estimated number of data subjects, the likely consequences, and the measures taken or proposed. We document all breaches under art. 33(5) GDPR.

## Article 8 — Transfers outside the EEA

We do not transfer personal data outside the EEA, unless an adequacy decision applies or appropriate safeguards such as standard contractual clauses have been put in place. If you yourself choose a region outside the EEA, that choice constitutes an instruction and we inform you about the implications.

## Article 9 — Right to audit

You may have compliance with this agreement checked by an independent third party, after written notice of at least 30 days. The costs are borne by you. We provide the reasonably required information.

## Article 10 — Termination

Upon termination we delete or return, at your choice, all personal data. Copies are deleted, unless a legal obligation requires retention. We confirm the deletion in writing on request.

## Article 11 — Governing law

This data processing agreement is governed exclusively by Dutch law; article 12 of the [terms and conditions](/terms) applies mutatis mutandis.

---

Binadit B.V. · Seinhuiswachter 2, 3034 KH Rotterdam · Netherlands · KvK 80923216 · VAT NL861852990B01
