Data Processing Agreement

Last updated: 9 July 2026

This Data Processing Agreement (the "agreement") describes how Qfile B.V. processes personal data on behalf of the customer when using OurDigitalContract, in line with Article 28 of the EU General Data Protection Regulation (GDPR) and, where applicable, the Dutch GDPR Implementation Act (UAVG). It forms an integral part of the terms of service between the parties. In the event of any conflict between this agreement and the terms of service regarding the processing of personal data, this agreement prevails.

1. Parties and roles

The customer (the employer using OurDigitalContract) is the controller. Qfile B.V. is the processor and processes personal data solely on behalf of, and following the instructions of, the customer.

Details of the processor:

2. Subject matter and duration

The subject matter of the processing is the provision of OurDigitalContract: a service with which the customer drafts, sends, has signed and stores employment contracts and other HR documents. The processing lasts for as long as the customer uses the service and ends in accordance with section 12 (return or deletion). The term follows the term of the underlying agreement between the parties.

3. Nature and purpose of the processing

The processor processes personal data for the purpose of providing and securing the service. This includes, among other things: creating and managing documents, sending signing requests and reminders, recording and evidencing a valid signature, storing records, providing role-based and permission-based access, and carrying out security, back-up and support tasks. The processor does not use the data for its own purposes.

4. Categories of data subjects and personal data

Data subjects are the individuals whose data the customer enters or has signed, in particular the customer's employees, candidates and other signers.

Categories of personal data that may be processed, depending on what the customer enters:

The BSN is a national identification number for which additional safeguards apply under the Dutch UAVG. As the controller, the customer is responsible for ensuring that the BSN is only processed in the cases where this is legally permitted, for example for payroll administration. The processor processes the BSN solely on the customer's instructions and applies appropriate technical and organisational measures to it (see section 6).

5. Instructions of the controller

The processor processes the personal data solely on the documented instructions of the customer, including this agreement and the ordinary use of the service. The processor does not process the data for other purposes, unless required to do so by law; in that case the processor informs the customer beforehand, unless the law prohibits this. If the processor considers an instruction to be in breach of the GDPR or other data protection legislation, it notifies the customer.

6. Security measures

The processor takes appropriate technical and organisational measures to protect the personal data against loss or unlawful processing. The measures currently in place are:

The processor may adjust these measures as long as the level of security is not thereby reduced.

7. Confidentiality

The processor ensures that the persons authorised under its authority to access the personal data are bound to confidentiality, either by a statutory duty of confidentiality or by a contractual confidentiality commitment. Access is limited to what is necessary for the performance of their tasks.

8. Engaging sub-processors

The customer gives the processor general authorisation to engage sub-processors for the performance of the service. The current sub-processors are listed on our sub-processors page. The processor imposes on each sub-processor at least the same obligations as those set out in this agreement.

The processor informs the customer in advance where it intends to add or replace a sub-processor. The customer may object to a change within a reasonable period. If the parties cannot reach agreement, the customer may terminate the service for the part to which the objection relates.

9. Assistance with data subject rights

Data subjects can exercise their rights (access, rectification, erasure, restriction, objection and data portability) through the customer. The processor assists the customer, insofar as possible and with appropriate technical and organisational measures, in responding to those requests. If the processor receives a request directly from a data subject, it does not respond independently, but refers the data subject to the customer or forwards the request to the customer.

10. Data breaches

If the processor becomes aware of a personal data breach, it notifies the customer without undue delay, so that the customer, as controller, can meet the 72-hour notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and, where necessary, inform the data subjects. In doing so, the processor provides the information reasonably available to it and assists with the assessment and handling. The full procedure is set out in our data breach procedure.

11. Audit and duty to provide information

The processor makes available to the customer the information needed to demonstrate compliance with Article 28 GDPR. The customer may, no more than once a year and at its own expense, carry out (or have carried out) an audit, provided this is announced in advance and within a reasonable period and does not unnecessarily disrupt operations or the confidentiality owed to other customers. The processor may refer to available reports or statements that evidence the measures in place.

12. Return or deletion after the end of the agreement

After the account ends, the data remains available for a further 6 months, so that the customer can retrieve or export it. After that, the processor deletes or anonymises the personal data, unless the customer has requested its return or unless a statutory retention obligation requires longer storage (for example the tax retention obligation of 7 years). Contracts and records are retained in accordance with the applicable statutory periods. Data in secure back-ups is deleted in line with the regular back-up cycle.

13. International transfers

The personal data is stored and processed within the Netherlands and the European Union. Transfer to a country outside the EU/EEA only takes place where an appropriate safeguard applies, such as an adequacy decision or standard contractual clauses (SCCs). Currently, no transfer of personal data outside the EU/EEA takes place.

14. Liability

The liability regime in the terms of service between the parties applies to this agreement, including the limitations set out therein. See also our limitation of liability page.

15. Changes

We may amend this agreement when the service, the applicable laws and regulations, or the sub-processors engaged change. The current version is always available on this page.

Contact

Questions about this data processing agreement? Contact Qfile B.V. at info@ourdigitalcontract.com.