Data Processing Addendum

Last Updated: February 1st, 2026

This Data Processing Addendum (“DPA”) forms an integral part of the Master Services Agreement (“Agreement”) between Evidentra Product B.V., a company registered in the Netherlands (Chamber of Commerce: 98455958), hereafter “Evidentra”, and the Customer.

NB. This DPA only applies to the extent that Customer uses Evidentra’s data migration, masking, and customer support, as that is the only situation in which Evidentra Processes Personal Data on behalf of Customer.

1. Definitions

  • 1.1. Terms such as ‘personal data’, ‘processing’, ‘controller’, ‘processor’, and ‘data subject’ shall have the meaning ascribed to them in the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
  • 1.2. “Applicable Data Protection Law” means the GDPR and the Dutch GDPR Execution Act (Uitvoeringswet AVG).
  • 1.3. “Technical and Organisational Measures” means measures aimed at protecting personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.

2. Scope and Role

  • 2.1. This DPA applies to the processing of personal data by Evidentra on behalf of the Customer in the provision of SaaS services.
  • 2.2. The Customer acts as the Controller and Evidentra acts as the Processor.

3. Obligations of Evidentra

Evidentra warrants and agrees:

  • 3.1. Instructions: To process personal data only on behalf of the Customer and in strict compliance with its documented instructions and the terms of this DPA.
  • 3.2. Compliance: To inform the Customer immediately if, in its opinion, an instruction infringes Applicable Data Protection Law.
  • 3.3. Confidentiality: To ensure that all personnel authorised to process personal data are bound by professional duties of confidentiality.
  • 3.4. Security: To implement appropriate technical and organisational security measures.

4. Sub-processing

  • 4.1. The Customer provides a general written authorisation for Evidentra to engage sub-processors.
  • 4.2. Evidentra shall impose the same data protection obligations on any sub-processor as set out in this DPA.
  • 4.3. Evidentra remains fully liable to the Customer for the performance of the sub-processor’s obligations.
  • 4.4. Evidentra shall inform the Customer of any intended changes concerning the addition or replacement of sub-processors, giving the Customer the opportunity to object.

5. Rights of Data Subjects

  • 5.1. Evidentra shall, in so far as possible, assist the Customer by appropriate measures for the fulfilment of the Customer’s obligation to respond to requests from data subjects (e.g., access, rectification, erasure).
  • 5.2. Evidentra shall promptly notify the Customer if it receives a request directly from a data subject.

6. Audit and Cooperation

  • 6.1. Evidentra shall make available to the Customer all information necessary to demonstrate compliance with the obligations in this DPA.
  • 6.2. Evidentra shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor.

7. Incident Management (Data Breaches)

  • 7.1. Evidentra shall notify the Customer without undue delay (and in any event within 24 hours) after becoming aware of a personal data breach.
  • 7.2. The notification shall include the nature of the breach, the categories of data involved, and the measures taken to mitigate its effects.

8. International Transfers

  • 8.1. Any transfer of data to a country outside the EEA shall only take place if that country ensures an adequate level of protection or if appropriate safeguards (such as Standard Contractual Clauses) are in place.

9. Termination

  • 9.1. Upon termination of the Agreement, Evidentra shall, at the choice of the Customer, delete or return all personal data and certify that it has done so, unless law requires storage of the data.

10. Governing Law

  • 10.1. This DPA and any disputes arising from it shall be governed by the laws of The Netherlands.

Appendix 1: Details of the Transfer

  • Categories of Data Subjects: Clients, employees, and authorised users.
  • Categories of Data: Contact details (email, phone), ID data, professional life data, and financial data.
  • Processing Operations: Hosting, cloud services, archiving, and backup.