Data Processing Agreement
Version 1.0 · Effective 9 September 2026
The Dutch version prevails if this translation conflicts with it.
Between the accounting firm using Boekhoudery (controller) and Outside Boxes, The Hague, KvK 93074735, VAT NL004998159B04, trading as Boekhoudery (processor).
Simple Article 28 GDPR processing terms. Annex to the Terms.
1. Subject
Processor provides the Boekhoudery SaaS (chat, documents, invitations) and processes personal data on behalf of the firm.
2. Duration
While the firm uses the service, then until deletion or export.
3. Nature and purposes
Store, display, transmit and search messages and documents; authentication; notifications; tenant isolation. Purpose: run the service on the firm’s instructions.
4. Data subjects and data
- Subjects: firm staff; firm clients; others appearing in chat or documents.
- Data: names, emails, phone numbers, chat messages, uploaded documents (e.g. financial or ID docs if uploaded), invites, push tokens, technical data (e.g. IP where relevant).
5. Instructions
Processor processes only on the firm’s instructions (use of the app + this agreement), unless law requires otherwise.
6. Confidentiality
People with access on behalf of the processor are bound to confidentiality.
7. Security
Appropriate measures, including TLS in transit, encryption at rest via our host (Supabase / AWS), access control and firm isolation (RLS). No end-to-end encryption: we can technically read data to run the service.
8. Sub-processors
General authorisation for the list at Subprocessors. We will notify changes (site / email). You may object; if unresolved, you may cancel.
9. Data-subject rights
We assist the firm. You can download a JSON export from the app.
10. Breach
We notify the firm of a personal data breach without undue delay, with the information we have. The firm decides on AP / data-subject notification.
11. Deletion or return
On end of service we delete firm data on request, or you export first. While you stay on Free, data remains. We may clean up abandoned accounts after reasonable notice.
12. Information and audit
On reasonable request we provide information to demonstrate Article 28 compliance. Audits by arrangement, reasonable notice, max once per year unless there is a concrete incident.
13. Transfers
Primary storage of chats and documents: EU (AWS eu-west-1, Ireland). Some helpers (email, push, edge hosting) may process data outside the EU — see subprocessors. We rely on those vendors’ DPAs / SCCs where needed.
14. Law
Dutch law. Courts of The Hague.
Electronic acceptance (signup checkbox) counts as a written contract.