Legal
Data Processing Agreement — Technovize
Version 1 · Effective June 17, 2026
DRAFT — NOT YET REVIEWED BY LEGAL COUNSEL. This document is a first-pass template based on Dutch and EU legal norms. Review with a lawyer or a service like Termly, iubenda, or Cookiebot before public launch or before accepting paying customers.
Data Processing Agreement (DPA)
Effective date: See document header. Version: 1.
This DPA forms part of the Terms of Service between Technovize (KVK 98119133, the “Processor”, operating Technovize) and any customer (the “Controller”) who uses our Software Dev or Hosting services to process personal data of their own end users. It implements Art. 28 GDPR.
1. Subject matter and roles
Where you (the Controller) use Technovize to host or build an application that processes personal data of your users, Technovize acts as your Processor and processes that data only on your documented instructions.
For the personal data of your own account (billing, login), Technovize is an independent Controller — see our Privacy Policy.
2. Nature and purpose of processing
- Nature: storage, hosting, transmission, backup, and operational maintenance of the application and its data.
- Purpose: delivering the contracted hosting / development service.
- Duration: for the term of the service agreement, plus the retention period in Section 7.
3. Categories of data and data subjects
Determined by the Controller’s application. Typically: the Controller’s end users (names, emails, account data, content they submit). The Controller must not use the service for special-category data (Art. 9 GDPR) without a prior written addendum.
4. Processor obligations
Technovize shall:
- process personal data only on documented instructions from the Controller;
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (Art. 32): encryption in transit and at rest, access controls, logging, and regular backups;
- assist the Controller with data-subject requests and with Art. 32–36 obligations, taking into account the nature of processing;
- notify the Controller without undue delay after becoming aware of a personal-data breach.
5. Sub-processors
The Controller grants general authorisation for Technovize to engage the sub-processors listed in our Privacy Policy (hosting, email, object storage, error monitoring). Technovize will inform the Controller of intended changes and give the Controller the opportunity to object.
6. International transfers
Any transfer outside the EEA is covered by the European Commission’s Standard Contractual Clauses and supplementary measures where required.
7. Return and deletion
On termination, Technovize will, at the Controller’s choice, delete or return all personal data and delete existing copies, unless EU or Member-State law requires retention.
8. Audits
Technovize will make available information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, on reasonable notice and subject to confidentiality.
9. Contact
Data-protection matters under this DPA: info@technovize.com.