Skip to main content

Data processing agreement

Last updated: January 1, 2026

This data processing agreement ("DPA") forms part of the Agreement between:

  • The Customer, being the controller ("Controller"); and
  • Offsoo B.V., established in Utrecht, the Netherlands, Chamber of Commerce number 82696233 ("Processor").

The Controller and the Processor are referred to together as the Parties.

Purpose and scope

The Processor processes Personal Data solely on behalf of the Controller and only to the extent necessary to provide and secure the Software and the supporting services. This DPA is drawn up in accordance with Article 28 GDPR and applies to all processing the Processor carries out as a processor on behalf of the Controller.

Definitions

Terms have the meaning given in Article 4 GDPR, including: Personal Data, Processing, Data Subject, and Personal Data Breach.

Term, return and deletion

This DPA applies for the term of the Agreement. After termination of the Agreement, the Controller's Offsoo environment is no longer accessible to the Controller. The Processor retains Personal Data after termination until the Controller requests deletion, with a maximum retention period of one (1) year after termination, after which the Processor deletes or anonymises the Personal Data unless a statutory retention obligation applies. Export: on request, the Processor can provide reasonable assistance in supplying exports (clients, hours or planning as CSV/Excel, for example) within the retention period. Any additional work may be charged. Backups have a maximum retention of three (3) months. Deletion from backups takes place through expiry of that retention and/or through complete deletion of an environment.

Nature, purpose and instructions

Nature and purpose: hosting, making available, securing, maintaining and supporting the Software, including troubleshooting, monitoring and incident handling. The Processor processes Personal Data solely on the basis of written or electronic instructions from the Controller. Use of the Software, the submission of support requests (by email or Intercom) and the activation of integrations count as instructions. The Processor is entitled to access and process Personal Data for necessary operational purposes (such as updates, maintenance, security, monitoring and support), subject to appropriate access restrictions and confidentiality.

Categories of data subjects and data

Categories of data subjects may include: employees of the Controller, clients and contacts of the Controller, and other people whose data the Controller processes in the Software. Types of Personal Data may include: identification and contact details, account data, planning and task data, time records, notes, log and audit data, and the content of free-text fields. The Controller is responsible for the lawfulness of the content of free-text fields.

The Processor's obligations

The Processor ensures that people acting under its authority are bound by a duty of confidentiality. The Processor provides reasonable assistance with the Controller's requests concerning data subject rights, to the extent that this fits the Processor's role.

The Processor gives the Controller reasonable support with:

  • DPIAs and prior consultation (where relevant);
  • security measures and documentation;
  • incident handling.

Security measures

The Processor takes appropriate technical and organisational measures to protect Personal Data against loss or unlawful processing. An outline of those measures is set out in Annex 1 (TOMs) and on Offsoo's Security and Information Security page.

Subprocessors

The Processor may engage Subprocessors. A current list of Subprocessors is available on the Subprocessors page. The Processor informs the Controller in advance of material changes to Subprocessors (by email or an in-app message, for example). The Controller may object, with reasons, within 14 days. If the Processor cannot resolve the objection, the Controller has the right to terminate the Agreement (and with it this DPA), if necessary with immediate effect. The Processor ensures that Subprocessors are contractually bound by at least the same obligations as those set out in this DPA.

Transfers outside the EEA

Personal Data is in principle processed within the EEA. Where a transfer outside the EEA takes place, it does so solely on the basis of a valid transfer mechanism, such as SCCs, an adequacy decision or the EU-US DPF (where applicable).

Data breaches and incidents

The Processor reports a data breach to the Controller without undue delay, aiming for 72 hours after discovery where reasonably feasible.

The report contains, to the extent available:

  • the nature of the incident;
  • the data and categories of data subjects (likely to be) affected;
  • the measures taken or proposed;
  • a contact point for follow-up.

The Processor provides reasonable support with notifications to supervisory authorities and data subjects. Contact point:

Audit and inspection

The Controller has the right to have an audit carried out at most once a year.

Audits:

  • take place primarily on the basis of documentation, statements and/or (limited) reports;
  • are carried out by an independent, certified auditor;
  • may not unnecessarily disrupt the Processor's operations;
  • are at the Controller's expense.

Where an on-site audit is necessary, it is scheduled by agreement and subject to reasonable conditions (including confidentiality, scope and time window).

Liability

The Processor's liability in connection with this DPA is limited in accordance with the limitations of liability in Offsoo's Terms and Conditions. This DPA does not extend that liability.

Order of precedence and final provisions

In the event of a conflict between this DPA and other arrangements on the processing of Personal Data, this DPA prevails. This DPA is governed by Dutch law. Disputes are submitted to the competent court of the District Court of Midden-Nederland, location Utrecht, unless mandatory law provides otherwise.

Annex 1 - Technical and organisational measures (TOMs)

The Processor applies, among others, the following measures (at a high level):

  • encrypted connections (TLS/HTTPS);
  • hashed passwords (not stored in readable form);
  • access management based on least privilege;
  • logging and monitoring (including errors and availability);
  • periodic backups (databases usually every hour; files usually daily);
  • an incident response procedure and reporting process;
  • MFA available to users and mandatory for Offsoo administrators where possible.

This list may be updated in line with technical developments and risk assessments.