Data processing agreement
Our standard verwerkersovereenkomst under Article 28 GDPR — the same terms for every pilot company, published openly.
Version 0.1 · 14 July 2026 · Items in [square brackets] are being finalised. A signable copy of this agreement is available on request via the contact page; it forms part of every pilot agreement.
1. Parties and roles
This agreement is between the customer using Bifrost (the controller) and [Matsobi legal entity name and form], KvK [KvK number], [address], the Netherlands (the processor, "we"). It applies to all personal data we process on the customer's behalf in providing Bifrost.
2. What processing this covers
- Subject matter: providing the Bifrost service — a workspace for entering, validating and approving business reference data.
- Duration: the term of the pilot or service agreement, plus the deletion period in section 10.
- Nature and purpose: hosting, storing, displaying, validating and running approval workflows over data the customer's users enter.
- Types of personal data: account data of the customer's users (name, business email address, role assignments, and the audit trail of who entered or approved data); and any personal data the customer chooses to store in its tables — the customer determines that content.
- Categories of data subjects: the customer's employees and other users it invites; and individuals whose data the customer stores in its tables.
3. Instructions
We process personal data only on the customer's documented instructions. Normal use of the service constitutes those instructions. We will inform the customer if, in our view, an instruction violates the GDPR or other applicable data protection law.
4. Confidentiality
Only persons acting under our authority and bound by confidentiality obligations have access to personal data, and only to the extent needed to provide and support the service. We do not access customer table data except for support with the customer's permission, or where required by law.
5. Security (Article 32)
We implement the technical and organisational measures described on the security page, which we keep current as the measures evolve. They include TLS encryption in transit, encryption at rest, role-based access with separated entry and approval rights, tenant isolation per company, and automated backups with point-in-time restore.
6. Sub-processors
The customer authorises the sub-processors below. We will announce any intended addition or replacement at least 30 days in advance, giving the customer the opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft (Azure) | Application hosting and database services | West Europe region (Netherlands), EU |
| [Email provider, if configured] | Transactional email (e.g. password resets, notifications) | [Location] |
7. Data subject rights
If a data subject contacts us directly about data we process for the customer, we forward the request to the customer without undue delay. Taking into account the nature of the processing, we assist the customer with appropriate measures — the product's own export, correction and deletion functions are the first line of that assistance.
8. Personal data breaches
We notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, and provide the information reasonably needed for the customer's own notification duties under Articles 33 and 34 GDPR: the nature of the breach, the categories and approximate numbers involved, likely consequences, and the measures taken.
9. Assistance with DPIAs
We provide reasonable assistance with data protection impact assessments and prior consultations with the supervisory authority, insofar as they concern processing in Bifrost.
10. Deletion and return
During the agreement the customer can export its data at any time. After termination the customer has 30 days to export; we then delete the customer's personal data within 30 days, with copies in backups expiring automatically within the backup retention cycle of at most [35] days. On request we confirm deletion in writing.
11. Audits
We make available the information reasonably necessary to demonstrate compliance with this agreement. The customer may audit compliance at most once per year, on 30 days' notice, during business hours, without disrupting operations, at its own cost, and under confidentiality. We may satisfy an audit request with a recent independent report where one exists.
12. International transfers
We process and store personal data within the European Economic Area (Azure West Europe, Netherlands) and do not transfer it outside the EEA without the customer's prior consent and a valid transfer mechanism such as the EU standard contractual clauses.
13. Liability and governing law
Liability under this agreement follows the liability provisions of the terms of service or the signed pilot agreement. This agreement is governed by Dutch law; disputes go to the competent court in [Amsterdam], the Netherlands.