Data Processing Agreement
GDPR processor terms when we process personal data on behalf of your organisation.
1. Status of this document
This is the standard data processing agreement of Branding Guru B.V. under Art. 28 GDPR. It forms part of the contract when we process personal data on behalf of a client (controller), especially for hosting, Nexovix CMS, form notifications on client sites, tracking setup and similar services.
Individual visitors to branding-guru.com: see the privacy policy (we are usually the controller there).
- Company
- Branding Guru B.V.
- Netherlands branch
- Pr. Margrietplantsoen 33, 2595 AM Den Haag
- Belgium branch
- Nieuwstraat 103, 8792 Waregem
- KvK
- 94486700
- VAT ID
- NL866795133B01
- IBAN
- NL38REVO4018289022
- Phone
- +31 70 207 1360
2. Roles
- Controller: the client determining purposes and means of processing
- Processor: Branding Guru B.V., processing personal data only on the client’s documented instructions
3. Subject matter and duration
Processing of personal data via hosted websites, CMS, form notifications, logs and agreed marketing/analytics tools, for the term of the hosting/service agreement and any agreed retention thereafter.
4. Nature and purposes
Hosting, content management, security, backups, support, email notifications, and (if agreed) cookie banner and tracking implementation. No processing for Branding Guru’s own marketing without a separate legal basis.
5. Types of data and data subjects
Depending on the client site: contact details of visitors/customers, editor account data, technical logs, and any other categories the client places in the CMS. The client decides what is collected and is responsible for lawfulness vis-à-vis data subjects.
6. Instructions
We process only on the client’s documented instructions, including this DPA and the main agreement, unless Union or Member State law requires otherwise. If an instruction appears to infringe the GDPR, we will notify the client.
7. Confidentiality and security
Persons with access are bound to confidentiality. We apply appropriate TOMs (access control, encryption in transit, backups, logging). Details on request.
8. Sub-processors
The client grants general authorisation for sub-processors needed for hosting, email and infrastructure (e.g. cloud host, email provider). We remain responsible for sub-processors and conclude GDPR-compliant terms with them. We will notify material changes; the client may object on reasonable grounds.
9. Assistance
We reasonably assist the client with data-subject rights, DPIAs and personal data breach notifications. We notify a (suspected) breach without undue delay after becoming aware of it.
10. Transfers
Transfers outside the EEA only with appropriate safeguards (adequacy decision, SCCs or equivalent).
11. Return and deletion
After the service ends we delete or return personal data per the client’s instructions, except where law requires retention. Content export may be charged at reasonable rates.
12. Audits
With reasonable notice and no more than once per year (unless an incident), the client may verify compliance via questionnaire or, with justified cause, an audit. Confidentiality and proportionality apply.
13. Liability
Liability follows the main agreement / terms & conditions, to the extent the GDPR allows.
14. Contact
service@branding-guru.com — put “Data processing agreement” in the subject line.