Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms part of the Agreement between Aevonix B.V., trading as PrikKlokPlus ("Processor", "we") and the customer ("Controller") and governs the processing of personal data on behalf of the Controller within the PrikKlokPlus SaaS platform. This DPA fulfils the requirements of GDPR art. 28.
1. Parties
| Controller | The organisation that has subscribed to PrikKlokPlus (the Tenant account holder). Identified in the account registration. |
| Processor | Aevonix B.V. (trading as PrikKlokPlus), Netherlands, KvK 42123774, VAT NL869834216B01, privacy@prikklokplus.nl |
2. Subject matter and nature of processing
The Processor processes personal data on behalf of the Controller for the purpose of delivering the PrikKlokPlus service: time tracking, scrum planning, project management, CRM, and invoicing.
| Item | Detail |
|---|---|
| Nature of processing | Storage, retrieval, display, modification, deletion, and transmission of personal data in the course of providing the SaaS service |
| Purpose | Operational delivery of the PrikKlokPlus platform as described in the General Terms and Conditions |
| Duration | For the duration of the subscription agreement, plus 60 days post-termination (data-export retention period) |
| Categories of data subjects | Employees, contractors, and managers of the Controller; clients and contacts in the CRM |
| Types of personal data | Name, email address, work hours, task assignments, project memberships, billing details, IP addresses, session identifiers |
| Special categories | None processed; Controller must not store sensitive categories (art. 9 GDPR) in PrikKlokPlus without explicit written agreement |
3. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, unless required to do so by EU or member state law (GDPR art. 28(3)(a))
- Ensure that authorised personnel are bound by confidentiality obligations (art. 28(3)(b))
- Implement appropriate technical and organisational security measures as described in §5 (art. 28(3)(c), art. 32)
- Respect the conditions for engaging sub-processors as described in §6 (art. 28(2))
- Assist the Controller in responding to data subject rights requests (art. 28(3)(e))
- Assist the Controller with security obligations, breach notification, DPIA, and prior consultation (art. 28(3)(f))
- At the Controller's choice, delete or return all personal data after the end of the provision of services (art. 28(3)(g))
- Make available all information necessary to demonstrate compliance, and allow for and contribute to audits (art. 28(3)(h))
4. Obligations of the Controller
The Controller shall:
- Ensure there is a valid legal basis for processing under GDPR art. 6 (and art. 9 if applicable)
- Provide accurate and up-to-date instructions to the Processor
- Not instruct the Processor to process data in a way that would violate applicable law
- Maintain accurate records of processing activities (art. 30) insofar as required by the Controller's role
5. Security measures
| Category | Measure |
|---|---|
| Encryption in transit | TLS 1.2+ (HTTPS) enforced on all connections |
| Encryption at rest | Database server disk encryption at Contabo infrastructure level |
| Authentication | bcrypt password hashing; TOTP 2FA and passkeys available; rate-limited login |
| Access control | Role-based access per Tenant; staff access on need-to-know basis with MFA required |
| Tenant isolation | All queries scoped by Tenant ID via global Eloquent scope; cross-tenant data access architecturally prevented |
| Monitoring | Error monitoring via self-hosted Grafana/Loki/ Tempo; audit log of key business actions (hours, tasks, sprints, projects, expenses, CRM) for 90 days |
| Backups | Daily automated database backups; retained for 14 days; stored in encrypted form |
| Breach response | Notification to AP within 72 hours; Controller notified without undue delay |
6. Sub-processors
The Controller grants general written authorisation for the use of the following sub-processors. PrikKlokPlus will inform the Controller of intended additions or replacements at least 30 days in advance, giving the Controller the opportunity to object.
| Sub-processor | Service | Location | Transfer basis |
|---|---|---|---|
| Contabo GmbH | Server infrastructure, database hosting; self-hosted transactional email (own SMTP server); self-hosted error tracking and performance monitoring (Grafana, Loki, Tempo, Prometheus); self-hosted analytics (Plausible); self-hosted source code hosting and CI/CD (Forgejo) — all on our own infrastructure | Germany | EEA — no transfer |
| Hetzner Online GmbH | Backup storage | Germany / Netherlands | EEA — no transfer |
| Mollie B.V. | Payment processing | Netherlands | EEA — no transfer |
7. International transfers
Where personal data is transferred to countries outside the European Economic Area (EEA), the Processor shall ensure adequate protection through one of the following mechanisms:
- EU Standard Contractual Clauses (SCCs) adopted by European Commission decision 2021/914
- EU-US Data Privacy Framework (where the sub-processor is certified)
- Any other valid transfer mechanism recognised under GDPR chapter V
8. Data subject rights assistance
The Processor shall, taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures to fulfil obligations to respond to data subject requests:
- Data export: Controllers can export all Tenant data via Settings → Data export (JSON and CSV formats available)
- Account/data deletion: Controllers can close the Tenant account, after which all associated data is purged within 60 days
- Individual user deletion: Manager-role users can delete individual user accounts via admin panel
- Manual assistance: For complex data subject requests not supported by self-service, contact privacy@prikklokplus.nl
9. Audit rights
The Processor shall make available all information necessary to demonstrate compliance with this DPA and GDPR art. 28. The Controller may request an audit of the Processor's data processing activities with at least 30 days advance notice and no more than once per 12-month period. Costs of audits are borne by the Controller unless the audit reveals a material breach by the Processor.
10. Duration and termination
This DPA is effective from the date the Controller accepts the General Terms and Conditions and remains in force for the duration of the subscription agreement. Upon termination, the Processor will retain data for 60 days to allow the Controller to export data, after which all personal data is permanently deleted, except where retention is required by law (e.g. invoice data under the Dutch VAT Act — 7 years).
11. Contact
| Privacy contact | privacy@prikklokplus.nl |
| DPA requests | A signed PDF copy of this DPA is available on request at privacy@prikklokplus.nl |
| Supervisory authority | Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl |
Verwerkersovereenkomst
Deze Verwerkersovereenkomst ("VOK") maakt onderdeel uit van de Overeenkomst tussen Aevonix B.V., handelend onder de naam PrikKlokPlus ("Verwerker") en de Klant ("Verwerkingsverantwoordelijke") en regelt de verwerking van persoonsgegevens conform AVG art. 28.
1. Partijen
Verwerkingsverantwoordelijke: de Klant die het PrikKlokPlus-abonnement heeft afgesloten.
Verwerker: Aevonix B.V. (handelend onder de naam PrikKlokPlus), Nederland, KvK 42123774, BTW NL869834216B01, privacy@prikklokplus.nl.
2. Onderwerp en aard van de verwerking
De Verwerker verwerkt persoonsgegevens namens de Verwerkingsverantwoordelijke ten behoeve van de levering van het PrikKlokPlus-platform: urenregistratie, scrumboard, projectbeheer, CRM en facturatie.
- Categorieën betrokkenen: medewerkers, managers, CRM-contacten van de Klant
- Soorten persoonsgegevens: naam, e-mailadres, uren, taakopdrachten, factuurgegevens, IP-adressen
- Bijzondere categorieën: geen (Klant mag geen art. 9 AVG-gegevens invoeren)
- Duur: looptijd abonnement + 60 dagen na beëindiging
3. Verplichtingen Verwerker
De Verwerker verwerkt uitsluitend op gedocumenteerde instructie van de Verwerkingsverantwoordelijke; borgt geheimhouding; treft passende beveiligingsmaatregelen (§5 EN-versie); hanteert goedgekeurde subverwerkers (§6 EN-versie); assisteert bij rechtenverzoeken, meldplicht datalekken en DPIA's; verwijdert of retourneert gegevens na afloop; en staat audits toe overeenkomstig AVG art. 28(3).
4. Subverwerkers
Goedgekeurde subverwerkers: Contabo GmbH (Duitsland — hosting, database, self-hosted transactionele e-mail (eigen SMTP-server), self-hosted monitoring/foutopsporing, self-hosted Plausible-analytics, self-hosted Forgejo broncode/CI, alles op eigen infrastructuur), Hetzner Online GmbH (EU — back-ups), Mollie B.V. (NL). Er verlaten geen persoonsgegevens de EER. Wijzigingen worden minimaal 30 dagen van tevoren aangekondigd.
5. Contact
Vragen of verzoeken om een ondertekend exemplaar: privacy@prikklokplus.nl. Klachten: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl.