Data policy
Last updated 24 July 2026
When you become a customer, you entrust us with your data and systems. This policy describes where that data resides, how it is protected and how you always stay in control.
Data location
All customer data we host resides in datacenters within the European Union and therefore falls entirely under European law. We do not transfer data to countries outside the European Economic Area.
Encryption and access
Data is encrypted in transit and at rest. Access to customer environments is limited to the employees who need it for their work, following the least-privilege principle, and administrative access is additionally secured. We follow the guidelines of the Dutch National Cyber Security Centre in doing so.
Backups and continuity
We make encrypted backups every day and regularly test whether they can actually be restored. That way we know recovery is not an assumption but a practiced routine.
Subprocessors
We only engage subprocessors when necessary to deliver our services, such as European datacenter providers. We sign a data processing agreement with every subprocessor and remain responsible for the chain ourselves. We send customers a current overview of subprocessors on request.
Data processing agreement
When we process personal data on your behalf, we sign a data processing agreement as required by Article 28 of the GDPR. We keep a standard model ready, so this never has to take weeks.
Retention and exit
Your data is and remains yours. At the end of the agreement you receive your data in common standard formats and we help with the handover. After that we delete your data from our systems, except for what we are legally required to retain, and remaining copies expire through the regular backup cycle.
Data breaches and incidents
If we discover a security incident affecting your data, we inform you quickly and completely. We report notifiable data breaches to the Dutch Data Protection Authority within 72 hours, as the GDPR requires, and we support you in any communication towards data subjects.