Legal

Data Processing Agreement

Last updated: July 11, 2026 · v1.1

This Data Processing Agreement ("DPA") forms part of the agreement between Declogger B.V. ("Processor") and the customer organization ("Controller") using the Declogger Service. It governs the processing of personal data by the Processor on behalf of the Controller, in accordance with Article 28 of Regulation (EU) 2016/679 (the "GDPR").

1. Subject matter & duration

The Processor processes personal data to provide the Declogger Service as described in the main agreement. Processing continues for as long as the Controller has an active subscription and for the retention period set out below.

2. Nature & purpose of processing

Storage, retrieval, organization, search, AI-assisted analysis (conflict and opportunity detection, summarization, natural-language search), notification, and deletion of tasks and task-board placements, decisions, documents, external resources, and related metadata supplied by the Controller's users.

3. Categories of data subjects & data

  • Data subjects: Controller's employees, contractors, and any natural persons named in decisions or documents.
  • Categories of data: account data (name, email, role), task content and comments, decision content, uploaded documents, external-resource URLs and snapshots, attachments, audit-trail metadata, and inbound-source content (Microsoft Teams, WhatsApp, Slack, Jira, Linear, Asana, and generic inbound webhooks) when those integrations are enabled.
  • No special-category data (Art. 9 GDPR) is collected by design. If the Controller chooses to upload it, the Controller remains responsible for the lawful basis.

4. Processor obligations

  • Process personal data only on documented instructions from the Controller, including for transfers to a third country.
  • Ensure that authorized personnel are bound by confidentiality.
  • Implement appropriate technical and organizational measures (Annex A).
  • Assist the Controller with data-subject requests, DPIAs, and prior consultations.
  • Notify the Controller without undue delay (and in any event within 72 hours) of becoming aware of a personal data breach.
  • At the Controller's choice, delete or return all personal data after the end of the Service.
  • Make available all information necessary to demonstrate compliance and allow for audits.

5. Sub-processors

The Controller authorizes the Processor to engage the sub-processors listed at declogger.com/legal/subprocessors. The Processor gives the Controller at least 30 days' prior notice of any intended addition or replacement of a material sub-processor. The Controller may object on reasonable grounds; if the parties cannot agree, the Controller may terminate the affected portion of the Service.

6. International transfers

Primary hosting is in the EU. Any transfer outside the EEA relies on a valid transfer mechanism — typically the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or an adequacy decision — together with supplementary measures where required by the Schrems II ruling.

7. AI processing

Customer Content sent to AI sub-processors is processed only to generate the requested output and is not used to train models. The Processor logs metadata about each AI request (model, tokens, latency, cost) for traceability under Article 12 of the EU AI Act; the request and response bodies are not retained beyond what is necessary to deliver the response. Controllers can disable AI features via the Privacy screen.

8. Retention & deletion

Customer Content is retained for the duration of the subscription. On termination, the Controller has 30 days to export data, after which the Processor deletes it from production systems within 60 days and from backups within 90 days. Controllers may configure automatic anonymization of inactive users on the Privacy screen.

9. Liability & conflicts

The liability regime of the main agreement applies. In the event of conflict between this DPA and the main agreement, this DPA prevails for matters concerning personal data processing.

Annex A — Technical & organizational measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access with row-level security; principle of least privilege.
  • Multi-factor authentication available for all users; required for Client Admins where configured.
  • Daily encrypted backups; tested restore procedure.
  • Centralized logging, monitoring, and alerting.
  • Security reviews of code changes; dependency vulnerability scanning.
  • Documented incident-response process with 72-hour breach-notification SLA.
  • Personnel confidentiality undertakings; security training on onboarding.

For a counter-signed copy of this DPA, email compliance@declogger.com with your organization name and signatory.