Data processing agreement (DPA)
Last updated: 2026-07-21
This data processing agreement (DPA) forms part of the agreement between BimDossier (processor) and the customer (controller) and applies whenever the customer uses the service to process personal data of others. It is incorporated by reference into our terms of service; a signable PDF version is available on request. While the service is in beta (pre-release), personal data processed in it may be reset, migrated or deleted at any time as part of testing (see “Return and deletion”).
Subject, duration, nature and purpose
The processing concerns personal data that the controller and its project participants enter into the service in order to carry out construction quality-assurance workflows (risk assessments, assurance plans, inspections, findings and dossier preparation), and consists of hosting, storing, displaying and processing that data. The processing continues for the duration of the main agreement, plus the deletion grace period described below.
Categories of data subjects and data
Data subjects: employees of the controller, kwaliteitsborgers, contractors and other project participants, including persons who upload via shared capture links. Data: contact and account details, project content, inspection evidence (photos, which may include time and location metadata) and usage logs.
Instructions
We process personal data only on the documented instructions of the controller, including with regard to any transfer outside the EEA. The main agreement, this DPA and the controller's configuration and use of the service together constitute those instructions. If we believe an instruction infringes the GDPR, we inform the controller immediately. If Union or Dutch law requires us to process otherwise, we inform the controller before processing, unless that law prohibits it.
Confidentiality
Access to personal data is limited to persons who need it to provide the service; all such persons are bound by contractual or statutory confidentiality obligations.
Security
In accordance with Art. 32 GDPR we apply appropriate technical and organisational measures, including encryption in transit, tenant isolation and least-privilege access control, audit logging, and backup and recovery measures appropriate to the service.
Sub-processors
The controller grants general written authorisation for the sub-processors on our current list published at /legal/subprocessors (hosting and object storage, transactional email, product analytics and error monitoring). We notify the controller at least 30 days before adding or replacing a sub-processor; the controller may object on reasonable data-protection grounds within that period, in which case the parties seek a solution and, failing that, the controller may terminate the affected service. Where replacement is urgently required for the security or continuity of the service, we may replace a sub-processor immediately and will notify the controller as soon as reasonably possible, with the same right to object. We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain fully responsible to the controller for their performance.
International transfers
Personal data is hosted and stored within the EU/EEA. We do not transfer personal data outside the EEA without the controller's prior documented instruction or the general authorisation in this DPA; where a sub-processor's non-EEA group entity could incidentally access personal data, that access is covered by an adequacy decision (such as the EU-US Data Privacy Framework) or the EU Standard Contractual Clauses.
Data breaches
If we become aware of a personal data breach affecting the controller's data, we notify the controller without undue delay, with the information known at that time and an initial assessment of impact and mitigation, and we keep the controller informed of relevant developments. Notifying the supervisory authority and data subjects is the controller's responsibility.
Assistance
Taking into account the nature of the processing and the information available to us, we assist the controller with requests from data subjects (access, correction, deletion, restriction, objection and data portability) so the controller can respond within the statutory deadlines, and we provide reasonable assistance with the controller's obligations under Arts. 32-36 GDPR, including data protection impact assessments (DPIAs). Where assistance goes beyond the self-service functions of the service, we may charge reasonable costs at then-current rates, agreed in advance. Informing data subjects (Arts. 13 and 14 GDPR) is the controller's responsibility.
Audits and information
We make available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR. Audit requests are satisfied first through written responses, our security documentation and, where available, third-party audit reports covering our sub-processors. Where these are demonstrably insufficient, the controller (or an auditor mandated by it, not being a competitor) may audit at most once per twelve months, on at least 30 days' written notice, during business hours, at its own cost, and in a manner that does not endanger the confidentiality of other customers' data.
Return and deletion
Upon termination of the main agreement, we return or delete all personal data at the controller's choice; the service's export functions are available for this during a grace period of 30 days after termination, during which the account remains accessible for export. If the controller does not indicate a choice within that period, we securely delete the data, unless Union or Member State law requires us to retain specific data. Statutory dossier-retention obligations (such as the 10-year Wkb retention) rest with the controller; export and retain dossiers before the grace period ends. During the beta (pre-release) phase, personal data processed in the service may additionally be reset, migrated or permanently deleted at any time as part of testing; the controller must keep its own copies and must not use the beta service as its system of record. We do not guarantee retention, recoverability or exportability of beta data unless expressly agreed in writing in advance.
Relationship to the main agreement
This DPA forms part of the main agreement. On the processing of personal data, this DPA prevails over the terms of service. The limitations of liability in the main agreement apply equally, and as one aggregate cap, to claims under this DPA, except where mandatory law provides otherwise. The controller warrants that it has a valid legal basis for the processing it instructs and that data subjects receive the information required under Arts. 13 and 14 GDPR. This DPA is available in Dutch and English; in case of divergence, the Dutch version prevails.
