Data Processing Agreement

1. Parties and Incorporation

This DPA forms part of the Agreement between the Customer as controller (or processor acting for another controller) and elyXion B.V. trading as elyXion, as processor (or subprocessor). It applies only to Customer Personal Data processed by elyXion on the Customer’s documented instructions.

2. Definitions

Terms such as controller, processor, personal data, processing, data subject, personal data breach, supervisory authority, and special categories have the meanings in the GDPR. **Applicable Data Protection Law** means the GDPR, Dutch GDPR Implementation Act, and other mandatory data protection law applicable to the processing.

3. Scope and Instructions

elyXion will process Customer Personal Data only to provide and secure the Services, to follow the Agreement and Customer’s documented instructions, and to comply with the law. The Agreement, service configuration, support requests, and authorised written directions constitute instructions.

If elyXion believes an instruction infringes Applicable Data Protection Law, it will inform the Customer unless prohibited and may pause the affected processing. Additional instructions requiring material work or cost are subject to change control.

4. Customer Obligations

The Customer warrants that:

  • It has lawful authority, transparency, and legal bases for the processing and instructions;
  • Its instructions are complete, lawful, and within the Services;
  • It has assessed whether the Services and agreed measures are appropriate for its risks;
  • It will not provide special-category, criminal-offence, children’s, or other high-risk data unless identified and safeguarded in Annex 1; and
  • Where it acts as processor, its controller has authorised elyXion as subprocessor.

5. Confidentiality and Personnel

elyXion will ensure persons authorised to process Customer Personal Data are bound by confidentiality and receive relevant security and privacy instruction. Access is limited according to role and need.

6. Security

elyXion will implement appropriate technical and organisational measures considering state of the art, implementation cost, processing nature and context, and risk to individuals. Baseline measures are in Annex 2. Specific commitments in the Order Form take precedence.

The Customer acknowledges that security is shared and will implement its allocated measures, including user administration, lawful configuration, endpoint security, data classification, and backup duties.

7. Subprocessors

The Customer gives general authorisation for subprocessors listed in the Subprocessor List. elyXion will impose data-protection obligations providing materially equivalent protection for relevant processing and remains responsible for subprocessor performance as required by law.

elyXion will give at least [SUBPROCESSOR NOTICE PERIOD] notice of a new subprocessor where reasonably possible. The Customer may object on reasonable data-protection grounds within [OBJECTION PERIOD]. The parties will seek a practical alternative. If none is reasonably available, either party may terminate the affected Service; refund or fee treatment follows the Agreement.

8. International transfers

elyXion will not transfer Customer Personal Data outside the EEA except under a valid GDPR Chapter V mechanism. Where required, the parties incorporate the European Commission Standard Contractual Clauses using the applicable module, with the DPA and annexes supplying required details. elyXion will support reasonable transfer assessments and supplementary measures.

Remote access from a third country may constitute a transfer and is treated accordingly.

9. Data-subject rights

Considering the nature of processing, elyXion will provide reasonable assistance for access, correction, deletion, restriction, portability, objection, and automated-decision requests. If elyXion receives a request directly relating to Customer Personal Data, it will not respond substantively except on Customer instruction or legal requirement and will forward it where identifiable.

Additional work beyond standard functionality may be chargeable unless caused by elyXion ‘s breach.

10. Personal Data Breaches

elyXion will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The initial notice may be phased and will include available information on nature, likely consequences, affected data and people, mitigation, and contact point.

elyXion will investigate, contain, remediate, preserve appropriate evidence, and cooperate reasonably. Notification is not an admission of fault. The Customer is responsible for deciding and making controller notifications to authorities and individuals, unless law assigns otherwise.

The contractual notification target, if any, is [BREACH NOTIFICATION TARGET]. It must not be described as a guarantee before operational validation.

11. DPIAs and Prior Consultation

elyXion will provide information reasonably available to help the Customer conduct data protection impact assessments and prior consultation related to the Services. elyXion does not provide legal advice or assume the Customer’s controller duties.

12. Records and Regulatory Cooperation

elyXion will maintain processor records required by law and cooperate with a competent supervisory authority as legally required. Each party is responsible for its own records and notices.

13. Audits

elyXion will make available information reasonably necessary to demonstrate Article 28 compliance. The Customer should first use current policies, questionnaires, independent reports, or remote evidence.

If additional audit is reasonably necessary, it will be conducted no more than once annually unless triggered by a material incident or authority; during business hours; with reasonable notice; by qualified, independent auditors bound by confidentiality; without accessing other customers’ information; and at the Customer’s cost unless the audit identifies elyXion ‘s material breach.

elyXion may redact security-sensitive information and provide alternative evidence.

14. Return and Deletion

At service end and on Customer choice, elyXion will return or delete Customer Personal Data, unless law requires retention. Standard export formats and timing depend on the Service. Data in backups is deleted through normal rotation and remains protected and unavailable for ordinary use.

The Customer must request exports before the stated offboarding deadline. elyXion may retain minimal legal, billing, security, and evidentiary records as an independent controller.

15. Government Requests

elyXion will assess legally binding requests, seek to limit overbroad demands, and notify the Customer where lawful. It will not voluntarily provide Customer Personal Data to authorities except for an emergency involving serious harm where law permits and appropriate review occurs.

16. Liability and Term

Liability under this DPA is subject to the Agreement except where mandatory law provides otherwise. This DPA lasts while elyXion processes Customer Personal Data.

ANNEX 1 — PROCESSING DETAILS

Item Description to complete
Subject matter Provision of [SERVICES]
Duur Agreement term plus agreed deletion/backup period
Nature and purpose Hosting, access, administration, monitoring, support, migration, security, integration, backup, reporting, and other documented operations
Data subjects Customer employees, contractors, users, clients, suppliers, patients, students, citizens, or others as specifically identified
Personal data Identity, contact, account, device, log, support, business, communications, and other categories specifically identified
Special categories [NONE EXPECTED / DESCRIBE AND SAFEGUARDS]
Criminal data [NONE EXPECTED / DESCRIBE AND SAFEGUARDS]
Processing frequency [CONTINUOUS / OCCASIONAL / PROJECT-BASED]
Retention [SCHEDULE]
Controller instructions Agreement, configuration, tickets, change approvals, and authorised written instructions

ANNEX 2 — BASELINE TECHNICAL AND ORGANISATIONAL MEASURES

2.1 Governance

  • Defined security and privacy responsibilities.
  • Risk-based policies and periodic review.
  • Confidentiality obligations and awareness.
  • Supplier due diligence proportionate to risk.

2.2 Identity and Access

  • Unique identities where practicable.
  • Multi-factor authentication for privileged and remote administrative access.
  • Role-based access and least privilege.
  • Joiner, mover, leaver processes and periodic access review.
  • Controlled privileged credentials and service principals.

2.3 Cryptography and Secrets

  • Encryption in transit using current supported protocols.
  • Encryption at rest where supported and appropriate.
  • Secrets kept out of source code and managed through approved stores.
  • Key and certificate lifecycle practices proportionate to service.

2.4 Infrastructure and Application Security

  • Secure configuration baselines.
  • Segmentation and restricted administrative interfaces where appropriate.
  • Patch and vulnerability management based on risk.
  • Change control, peer review, testing, and rollback for material changes.
  • Dependency and source-control practices for software delivery.

.

2.5 Logging and Monitoring

  • Security-relevant authentication and administrative logs.
  • Time synchronisation and restricted log access.
  • Alerting and investigation according to service scope.
  • Retention aligned with risk, purpose, and law.

2.6 Resilience

  • Backups where included, protected from ordinary modification.
  • Recovery and continuity procedures proportionate to service.
  • Periodic restoration or continuity testing according to plan.

2.7 Incident Management

  • Reporting, triage, containment, remediation, and lessons-learned process.
  • Evidence preservation and communication roles.
  • Personal-data-breach assessment and notification workflow.

2.8 Data Management

  • Data minimisation and environment separation where appropriate.
  • Controlled export, deletion, and media handling.
  • Test data selected to reduce unnecessary personal-data exposure.

ANNEX 3 — APPROVED SUBPROCESSORS

The current [Subprocessor List](subprocessors.md) is incorporated. Customer-specific additions may appear in the Order Form.

ANNEX 4 — INTERNATIONAL TRANSFER SETTINGS

Item Position
Primary EEA location [REGIONS]
Transfer mechanism Adequacy decision, SCCs, or other lawful mechanism
SCC module [MODULE 2 OR 3, AS APPLICABLE]
Docking clause Included where agreed
Supervisory authority Autoriteit Persoonsgegevens or other competent authority
Supplementary measures Encryption, access control, minimisation, transparency, and provider-specific measures as assessed
Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review