Data Processing Agreement
Last updated: 9 July 2026
This Data Processing Agreement (the "agreement") describes how Qfile B.V. processes personal data on behalf of the customer when using OurDigitalContract, in line with Article 28 of the EU General Data Protection Regulation (GDPR) and, where applicable, the Dutch GDPR Implementation Act (UAVG). It forms an integral part of the terms of service between the parties. In the event of any conflict between this agreement and the terms of service regarding the processing of personal data, this agreement prevails.
1. Parties and roles
The customer (the employer using OurDigitalContract) is the controller. Qfile B.V. is the processor and processes personal data solely on behalf of, and following the instructions of, the customer.
Details of the processor:
- Name: Qfile B.V.
- Address and Chamber of Commerce (KvK) number: see the Terms of Service.
- Contact for this agreement: Qfile B.V., info@ourdigitalcontract.com.
2. Subject matter and duration
The subject matter of the processing is the provision of OurDigitalContract: a service with which the customer drafts, sends, has signed and stores employment contracts and other HR documents. The processing lasts for as long as the customer uses the service and ends in accordance with section 12 (return or deletion). The term follows the term of the underlying agreement between the parties.
3. Nature and purpose of the processing
The processor processes personal data for the purpose of providing and securing the service. This includes, among other things: creating and managing documents, sending signing requests and reminders, recording and evidencing a valid signature, storing records, providing role-based and permission-based access, and carrying out security, back-up and support tasks. The processor does not use the data for its own purposes.
4. Categories of data subjects and personal data
Data subjects are the individuals whose data the customer enters or has signed, in particular the customer's employees, candidates and other signers.
Categories of personal data that may be processed, depending on what the customer enters:
- Name, address and contact details (email address, phone number).
- Date of birth.
- BSN (Dutch citizen service number).
- IBAN (bank account number).
- Job title, terms of employment and salary details.
- The contents of contracts and of uploaded personnel file documents.
- Signing data: the moment of signing, the IP address at the moment of signing, the one-time signing link and the associated attestation and audit log.
- Account and usage data of the customer's staff who operate the service (name, email address, role, login events).
The BSN is a national identification number for which additional safeguards apply under the Dutch UAVG. As the controller, the customer is responsible for ensuring that the BSN is only processed in the cases where this is legally permitted, for example for payroll administration. The processor processes the BSN solely on the customer's instructions and applies appropriate technical and organisational measures to it (see section 6).
5. Instructions of the controller
The processor processes the personal data solely on the documented instructions of the customer, including this agreement and the ordinary use of the service. The processor does not process the data for other purposes, unless required to do so by law; in that case the processor informs the customer beforehand, unless the law prohibits this. If the processor considers an instruction to be in breach of the GDPR or other data protection legislation, it notifies the customer.
6. Security measures
The processor takes appropriate technical and organisational measures to protect the personal data against loss or unlawful processing. The measures currently in place are:
- Encryption at rest of sensitive fields with AES-256-GCM, using a separate key per customer derived through HKDF with an integrity binding, so that an encrypted data block cannot be shifted to another customer.
- Passwords are stored as a bcrypt hash; email addresses in the central register are indexed through HMAC.
- Encryption in transit through HTTPS/TLS, with automatic certificates (Caddy).
- The session is stored in an HttpOnly and SameSite cookie; a strict Content Security Policy and additional security headers apply, and there is rate limiting on login.
- Audit logging, the ability to revoke sessions and deactivate accounts, and role-based access in which sensitive fields are masked for read-only roles.
- Back-ups of the database; the encryption key is stored separately and is deliberately not included in the back-ups.
- Hosting on a VPS at TransIP in the Netherlands (EU).
The processor may adjust these measures as long as the level of security is not thereby reduced.
7. Confidentiality
The processor ensures that the persons authorised under its authority to access the personal data are bound to confidentiality, either by a statutory duty of confidentiality or by a contractual confidentiality commitment. Access is limited to what is necessary for the performance of their tasks.
8. Engaging sub-processors
The customer gives the processor general authorisation to engage sub-processors for the performance of the service. The current sub-processors are listed on our sub-processors page. The processor imposes on each sub-processor at least the same obligations as those set out in this agreement.
The processor informs the customer in advance where it intends to add or replace a sub-processor. The customer may object to a change within a reasonable period. If the parties cannot reach agreement, the customer may terminate the service for the part to which the objection relates.
9. Assistance with data subject rights
Data subjects can exercise their rights (access, rectification, erasure, restriction, objection and data portability) through the customer. The processor assists the customer, insofar as possible and with appropriate technical and organisational measures, in responding to those requests. If the processor receives a request directly from a data subject, it does not respond independently, but refers the data subject to the customer or forwards the request to the customer.
10. Data breaches
If the processor becomes aware of a personal data breach, it notifies the customer without undue delay, so that the customer, as controller, can meet the 72-hour notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and, where necessary, inform the data subjects. In doing so, the processor provides the information reasonably available to it and assists with the assessment and handling. The full procedure is set out in our data breach procedure.
11. Audit and duty to provide information
The processor makes available to the customer the information needed to demonstrate compliance with Article 28 GDPR. The customer may, no more than once a year and at its own expense, carry out (or have carried out) an audit, provided this is announced in advance and within a reasonable period and does not unnecessarily disrupt operations or the confidentiality owed to other customers. The processor may refer to available reports or statements that evidence the measures in place.
12. Return or deletion after the end of the agreement
After the account ends, the data remains available for a further 6 months, so that the customer can retrieve or export it. After that, the processor deletes or anonymises the personal data, unless the customer has requested its return or unless a statutory retention obligation requires longer storage (for example the tax retention obligation of 7 years). Contracts and records are retained in accordance with the applicable statutory periods. Data in secure back-ups is deleted in line with the regular back-up cycle.
13. International transfers
The personal data is stored and processed within the Netherlands and the European Union. Transfer to a country outside the EU/EEA only takes place where an appropriate safeguard applies, such as an adequacy decision or standard contractual clauses (SCCs). Currently, no transfer of personal data outside the EU/EEA takes place.
14. Liability
The liability regime in the terms of service between the parties applies to this agreement, including the limitations set out therein. See also our limitation of liability page.
15. Changes
We may amend this agreement when the service, the applicable laws and regulations, or the sub-processors engaged change. The current version is always available on this page.
Contact
Questions about this data processing agreement? Contact Qfile B.V. at info@ourdigitalcontract.com.