Skip to content
  • Challenges
  • Solution
  • Working together
  • About us
  • Blog
NL EN Sales Diagnose
CRAFT THE NEXT BIG WIN.
  • 01 Challenges
  • 02 Solution
  • 03 Process
  • 04 About us
  • 05 Working together
  • 06 Dcraft Of Sales AI
  • 07 FAQ
  • 08 Service areas
  • 09 Blog
  • 10 The overview
  • 11 Careers
Book a free Sales Diagnose
Get in touch
Call directly +31 6 25538050 WhatsApp us +31 6 25538050
[email protected]
NL EN
Back to home

Legal

Data Processing Agreement

Last updated 22 August 2026

When we process personal data on a client’s behalf — for example, prospect and contact data in AI-driven lead generation — the client is the controller and we are the processor. Article 28 of the General Data Protection Regulation (GDPR) requires the parties to record that in writing.

This is the data processing agreement we use for that. It forms an integral part of every engagement in which we process personal data on the client’s behalf. Would you like a signed copy in your organization’s name? Request it at [email protected].

On this page

  1. Parties & order of precedence
  2. Subject matter & duration
  3. Nature & purpose of the processing
  4. Types of personal data & categories of data subjects
  5. Instructions
  6. Confidentiality
  7. Security measures
  8. Sub-processors
  9. Data subject rights
  10. Personal data breaches
  11. Audits & inspections
  12. Transfers outside the EEA
  13. Return & deletion at the end
  14. Liability
  15. Language: the Dutch text prevails
  16. Governing law & contact

1. Parties & order of precedence

This data processing agreement applies between Dcraft B.V., trading as Dcraft Of Sales, registered with the Dutch Chamber of Commerce (KvK) under number 99950197, establishment number 000064987671 ("we", "Processor") and the organization that engages our services ("Client", "Controller").

The Client determines the purposes and means of the processing and is the controller within the meaning of the GDPR. We process the personal data solely for the Client and on the Client’s instructions.

This agreement accompanies our Terms of Service and the applicable proposal or statement of work. Where this agreement and the Terms of Service conflict, this agreement prevails — but only in so far as the processing of personal data is concerned. The liability regime in the Terms of Service continues to apply in full.

2. Subject matter & duration

The subject matter of the processing is the personal data needed to deliver the agreed services: AI-driven lead generation, setting up and running outbound campaigns, designing and operating the sales process and its tooling, and reporting on all of it.

This agreement takes effect when the engagement is formed and runs for as long as we process personal data on the Client’s behalf. It does not end before all personal data has been returned or deleted in accordance with the article on return and deletion. Provisions that by their nature should survive — including confidentiality — remain in force afterward.

For the avoidance of doubt: the retention periods in our Privacy Policy apply to data we collect ourselves through our website. The personal data we process on your behalf is governed solely by your instructions and the article on return and deletion — you decide how long it is kept, not us.

3. Nature & purpose of the processing

The processing consists of collecting, recording, organizing, storing, consulting, enriching, using, disclosing to recipients designated by the Client, and ultimately erasing personal data. This happens by automated means and, where necessary, manually.

The purpose is always to carry out the Client’s engagement. Concretely:

  • compiling and enriching target lists of business contacts (the Client’s ideal customer profile);
  • drafting, personalizing and sending outbound messages, usually from the Client’s own name and domain;
  • recording and following up on replies, meetings and call outcomes in the Client’s tooling;
  • designing, operating and improving the sales process and the systems used for it;
  • producing reporting and analysis on campaign results.
  • We never use the Client’s personal data for our own purposes, not for our own commercial activities, and not to train AI models.

4. Types of personal data & categories of data subjects

We process only business contact data and data directly related to the sales process. The types of personal data are:

  • name and job title;
  • business contact details: email address, phone number, and the employer and location the person is associated with;
  • public professional profile data, such as a LinkedIn profile URL;
  • correspondence and call notes recorded as part of the sales process;
  • interaction data around outbound messages: sent, opened, clicked, replied, unsubscribed;
  • the data subject’s status in the Client’s pipeline.
  • Categories of data subjects: contacts and employees of the Client’s prospects, leads and customers, and employees of the Client itself who work with the systems we set up.
  • Excluded: we process no special categories of personal data (Article 9 GDPR), no criminal-offence data (Article 10 GDPR) and no Dutch citizen service numbers (BSN). The Client does not supply such data either. If it nonetheless appears unintentionally in supplied files, we report that and delete it.

5. Instructions

We process the personal data solely on the Client’s documented instructions. The engagement, the proposal and this agreement together constitute the complete instruction at the outset; later additional instructions are recorded in writing (email suffices).

We do not process the personal data for any other purpose, do not disclose it to third parties other than the sub-processors covered by this agreement, and never sell it.

If Union or Dutch law requires us to process beyond what the instruction allows, we inform the Client beforehand, unless that law prohibits such notification on important grounds of public interest.

If we believe an instruction infringes the GDPR or other data protection law, we notify the Client immediately and may suspend execution of that instruction until the Client has amended or confirmed it in writing.

The Client warrants that a valid legal basis exists for the processing, that data subjects have been informed in accordance with Articles 13 and 14 GDPR, and that the supplied data was collected lawfully. The Client indemnifies us against third-party claims arising from the absence of any of these.

6. Confidentiality

We keep the personal data confidential and do not disclose it to third parties, except to the sub-processors covered by this agreement, or where a legal obligation or an order from a competent authority compels us to. In the latter case we inform the Client beforehand, to the extent legally permitted.

Everyone under our authority who has access to the personal data — employees and the independent professionals we work with — is contractually bound to confidentiality and is granted access only to the extent needed for their task (need-to-know). That duty of confidentiality continues after the engagement ends.

7. Security measures

We implement appropriate technical and organizational measures within the meaning of Article 32 GDPR, calibrated to the nature of the data (business contact data) and the risks of the processing. Those measures include at least:

  • encryption of data in transit (TLS/HTTPS) and encrypted storage at our hosting and system providers;
  • need-to-know access control, with individual accounts, strong passwords and two-factor authentication on every system holding personal data;
  • logical separation of data per client, so that different clients’ data never mixes;
  • data minimization: we process only the fields the sales process needs, and delete what is superfluous;
  • backups of the systems we operate, with recovery procedures that are tested periodically;
  • a documented procedure for detecting, reporting and handling security incidents and personal data breaches;
  • confidentiality and security commitments from everyone under our authority who has access, plus periodic review and tightening of these measures.
  • We provide the Client with reasonable assistance in meeting its own obligations under Articles 32 to 36 GDPR, including a data protection impact assessment (DPIA) and any prior consultation with the supervisory authority.

8. Sub-processors

The Client gives us general written authorization to engage sub-processors. We engage only sub-processors that offer appropriate safeguards, and we impose on them contractually the same obligations as those set out in this agreement. We remain fully liable to the Client for the acts of our sub-processors.

As at this version, we work with the following categories of sub-processor:

  • our hosting and infrastructure provider, which runs the servers and the environments we operate;
  • Google, for business email, calendar and document storage;
  • our AI provider (currently Groq), for generating text within campaigns;
  • the providers of the sales and outbound tooling used in the specific engagement — which ones those are is agreed with the Client per engagement;
  • the independent professionals working on the engagement under our responsibility, bound by the same confidentiality and instructions.
  • A current list of the names and countries of establishment of the sub-processors engaged is provided on request at [email protected] .
  • If we wish to add or replace a sub-processor, we give at least thirty (30) days’ prior notice. Within that period the Client may object in writing on reasonable grounds related to data protection. If the parties cannot resolve the objection, the Client may terminate the part of the engagement that concerns that processing, without either party being in breach.

9. Data subject rights

Data subjects address their requests to the Client: the Client is the controller and answers them. If we receive a data subject request relating to processing for the Client, we do not answer it ourselves but forward it to the Client within five (5) business days.

Taking the nature of the processing into account, we give the Client all reasonable assistance needed to honor data subject requests. This covers at least the rights of access, rectification, erasure, restriction, objection and data portability, as well as the right to opt out of further outreach.

We carry out requests for correction, erasure or opt-out within ten (10) business days of the Client instructing us, and make sure the data subject does not re-enter a campaign afterward.

10. Personal data breaches

If we discover a personal data breach affecting the Client’s data, we report it without undue delay and in any event within twenty-four (24) hours of discovery, by email and by phone to the Client’s contact person.

We never report a breach to the Dutch Data Protection Authority or to data subjects ourselves: that assessment and that notification are for the Client as controller. We do supply all information needed for it, so that the Client can meet the statutory seventy-two (72) hour deadline in Article 33 GDPR.

Our report contains, in so far as known at that moment:

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned;
  • the time or period of the breach and the moment of discovery;
  • the likely consequences of the breach;
  • the measures we have taken or propose to take to address the breach and mitigate its effects;
  • the contact details of the person at our end from whom more information can be obtained.
  • If some information is not yet available, we report what we know and supplement it without delay. We document every incident and keep the Client informed until it is resolved.

11. Audits & inspections

We make available to the Client all information necessary to demonstrate compliance with the obligations in Article 28 GDPR, and we cooperate with audits and inspections by the Client or an independent auditor it appoints.

Practical arrangements: an audit takes place at most once every twelve months, is announced in writing at least thirty (30) days in advance, takes place during office hours, and disrupts our operations as little as possible. The auditor signs a confidentiality undertaking beforehand and may not be a direct competitor of ours.

The Client bears the cost of an audit, including reasonable compensation for the time we spend on it. If the audit shows that we are in material breach of this agreement, we bear the costs and remedy the shortcoming without delay at our own expense.

Outside the regular cycle, an audit is also possible after a breach affecting the Client’s data, or when a supervisory authority requests one.

12. Transfers outside the EEA

The starting point is that personal data is processed and stored within the European Economic Area (EEA).

If a transfer to a country outside the EEA is necessary — for example, because an engaged provider runs its services there — it takes place only where one of the conditions in Chapter V GDPR is met: an adequacy decision of the European Commission, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs), supplemented where necessary with additional technical and organizational measures following an assessment of the country concerned.

We inform the Client in advance of any new transfer outside the EEA and of the safeguard it relies on. The Client may object in the same way as for a new sub-processor.

13. Return & deletion at the end

At the end of the engagement — for any reason — the Client chooses whether we return or delete the personal data. The Client communicates that choice in writing within thirty (30) days of the end; absent a choice, we delete the data.

On return, we supply the personal data within thirty (30) days in a common, machine-readable format (for example, CSV or JSON), together with the accompanying documentation. We then delete our copies.

On deletion, we erase the personal data from our active systems within thirty (30) days and ensure our sub-processors do the same. Copies in routine backups expire automatically within the usual backup cycle; for as long as they exist they remain subject to the security and confidentiality provisions of this agreement and are not actively used.

We retain only what a legal obligation requires us to retain, and only for as long as that obligation lasts. On request, we confirm deletion in writing.

14. Liability

The liability regime in our Terms of Service applies to the parties’ liability under this agreement, including the caps and exclusions set out there. Mandatory law — including Article 82 GDPR in relation to data subjects — continues to apply in full.

Each party is responsible for meeting its own obligations under the GDPR. A fine or claim resulting from one party’s failure is borne by that party.

15. Language: the Dutch text prevails

This data processing agreement was drafted in Dutch. The English version on this website is a translation only. In the event of any difference in interpretation, meaning or wording between the two texts, the Dutch text is the only binding and decisive one.

16. Governing law & contact

This data processing agreement is governed exclusively by the laws of the Netherlands. Disputes are submitted to the competent court in the Netherlands, unless mandatory law designates another court.

Questions about this agreement, a request for a signed copy, the current sub-processor list, or a report of a possible data breach? Get in touch directly:

  • Dcraft B.V. (trading as Dcraft Of Sales) · KvK 99950197 · Establishment number 000064987671 · VAT number NL869200975B01
  • Email: [email protected]
  • Phone: +31 6 25538050
  • WhatsApp: +31 6 25538050

Book a free Sales Diagnose

CRAFT THE NEXT BIG WIN.

Dcraft Of Sales builds powerful sales and business automation, and puts a predictable sales organization around it — drawing on more than two decades of C-level experience in B2B sales.

Book a free Sales Diagnose

Navigate

  • Challenges
  • Solution
  • Working together
  • About us
  • Careers
  • The overview
  • Book a session
  • Service areas
  • Blog

Get in touch

  • +31 6 25538050
  • WhatsApp
  • [email protected]
  • LinkedIn

© 2026 Dcraft Of Sales. All rights reserved.

Dcraft B.V. — Dutch CoC 99950197 — VAT NL869200975B01

  • Privacy
  • Terms
  • Cookies
  • Data Processing Agreement