Data Processing Agreement
This agreement applies when Doublecheck processes personal data on behalf of a customer, as required by article 28 of the General Data Protection Regulation (GDPR). It forms part of the agreement for the use of the Doublecheck service and is accepted together with the Terms and Conditions.
1. Parties and roles
- The Customer that uses the Doublecheck service is the controller.
- Nova Generation B.V., trading as Doublecheck ("Doublecheck"), is the processor.
- Terms such as personal data, processing, controller, processor, sub-processor and personal data breach have the meaning given to them in the GDPR. Other terms have the meaning given in the Terms and Conditions.
2. Subject and duration
- Doublecheck processes personal data only to provide the monitoring service to the Customer, as described in Annex 1.
- This agreement applies for as long as Doublecheck processes personal data on behalf of the Customer, and ends automatically when the agreement for the service has ended and the personal data has been deleted.
3. Instructions
- Doublecheck processes personal data only on documented instructions of the Customer. The configuration of the service by the Customer, such as the Checks it creates and the tenants it connects, counts as such instructions.
- Doublecheck does not process the personal data for its own purposes.
- If Doublecheck is required by law to process personal data in another way, it informs the Customer before doing so, unless the law prohibits this.
- Doublecheck informs the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law.
4. Confidentiality
Doublecheck ensures that everyone who has access to the personal data on its behalf is bound by a duty of confidentiality.
5. Security
Doublecheck takes appropriate technical and organisational measures to protect the personal data against loss and unlawful processing, taking into account the state of the art, the costs and the risks involved (article 32 GDPR). Annex 2 describes these measures. Doublecheck may change them, as long as the level of protection does not decrease.
6. Sub-processors
- The Customer gives Doublecheck general authorisation to engage sub-processors. The sub-processors in use are listed in Annex 3.
- Doublecheck informs the Customer at least 30 days in advance of a new or replaced sub-processor. The Customer may object on reasonable grounds within that period. If the parties cannot reach a solution, the Customer may end the agreement for the service.
- Doublecheck imposes the same data protection obligations on each sub-processor as set out in this agreement, and remains responsible towards the Customer for its sub-processors.
7. Transfers outside the EEA
Doublecheck only transfers personal data to a country outside the European Economic Area if that transfer meets the requirements of chapter V of the GDPR, for example on the basis of an adequacy decision such as the EU-U.S. Data Privacy Framework, or the Standard Contractual Clauses of the European Commission.
8. Assistance
- Doublecheck assists the Customer, as far as reasonably possible, in responding to requests from data subjects who exercise their rights. If a data subject contacts Doublecheck directly, Doublecheck forwards the request to the Customer.
- Doublecheck assists the Customer, taking into account the information available to it, with its obligations regarding security, data protection impact assessments and prior consultation (articles 32 to 36 GDPR).
9. Personal data breaches
- Doublecheck notifies the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach that affects the Customer's personal data.
- The notification contains, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
- The Customer decides whether to notify the supervisory authority and the data subjects. Doublecheck provides the information the Customer needs for that.
10. Deletion at the end of the agreement
When the agreement for the service ends, Doublecheck deletes the personal data it processes on behalf of the Customer, unless the law requires it to keep the data. Before the end, the Customer can export or copy the data it needs through the service or by asking Doublecheck.
11. Information and audits
- Doublecheck provides the Customer with the information needed to demonstrate compliance with this agreement.
- The Customer may have compliance audited, at its own cost, at most once a year, after giving at least 30 days' notice, by an independent auditor bound by confidentiality, without disrupting the operations of Doublecheck more than necessary.
12. Liability and other provisions
- The limitations of liability in the Terms and Conditions also apply to this agreement, insofar as the law allows.
- If this agreement and the Terms and Conditions conflict on the processing of personal data, this agreement prevails.
- This agreement is governed by Dutch law. The competent court in The Hague, the Netherlands, has exclusive jurisdiction.
Annex 1: Description of the processing
| Nature and purpose | Running the Checks the Customer configures, storing their results, showing them in the service and sending alerts. |
|---|---|
| Categories of personal data |
|
| Categories of data subjects | Employees and other users of the Customer and of the tenants the Customer connects; alert recipients designated by the Customer. |
| Special categories | None. The service is not designed to process special categories of personal data. |
| Duration | For the duration of the agreement for the service. Monitoring results are removed automatically after the retention periods in the service, and all data is deleted when the agreement ends. |
The licence, Secure Score and endpoint checks do not, by their nature, process data about individual users.
Annex 2: Security measures
- Encrypted connections (TLS) for the application and its interfaces.
- Credentials for cloud checks stored in a dedicated, encrypted secrets vault, separate from the application database, with access restricted to Doublecheck's own services under strict access policies.
- Cloud checks use read-only permissions: one Microsoft Graph application permission per check, or the Azure Reader role. Doublecheck cannot change anything in a tenant.
- Only the data a check needs is stored. For example, the mailbox usage check keeps names and storage figures, never the content of mailboxes.
- Sign-in through a managed identity provider; sign-ins are logged.
- Endpoint checks refuse private and internal network addresses.
- Separation of customer data by workspace, with access only for users the Customer invites.
- Automatic deletion of monitoring history after fixed retention periods.
- Hosting in data centres in the European Union.
Annex 3: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application, the monitoring agents and their databases | Germany |
| Amazon Web Services (Amazon Cognito) | Sign-in and identity management | Germany (Frankfurt, eu-central-1) |
| Microsoft Ireland Operations Ltd. (Microsoft Azure) | Hosting, and secure storage of the credentials for cloud checks | The Netherlands (West Europe) |
| Twilio (SendGrid) | Sending alert emails and SMS messages | United States |
Nova Generation B.V., trading as Doublecheck
Praagsingel 22, The Hague, the Netherlands
Chamber of Commerce (KvK): 83857753
info@doublecheck.live