This data processing agreement is part of our terms of service and meets the requirements of article 28 of the General Data Protection Regulation (GDPR). The owner who creates a company account accepts it on behalf of the company. If you need a signed copy for your records, e-mail nickquispel@vargar.eu. If the English and Dutch versions differ, the Dutch version prevails.
1. Parties and roles
- The Customer (the company that uses Tradestack) is the controller.
- Vargar (Nick Quispel), Ram 11, 3225 EG Hellevoetsluis, KvK 83288198 ("Tradestack") is the processor.
Words such as "personal data", "processing" and "personal data breach" have the meaning given to them in the GDPR.
2. Subject and purpose
Tradestack processes personal data only to provide the Service described in the terms of service: work orders, planning, time and material registration, forms and reports, certificates, documents and the related notifications. Annex 1 describes the categories of data subjects and personal data.
3. Instructions
- Tradestack processes personal data only on documented instructions of the Customer. The terms of service, this agreement and the way the Customer configures and uses the Service form those instructions.
- Tradestack does not use the personal data for its own purposes.
- If an instruction in Tradestack's opinion infringes the GDPR, Tradestack informs the Customer immediately.
- If Tradestack is required by law to process personal data otherwise, it informs the Customer first, unless the law forbids that.
4. Confidentiality
Everyone at Tradestack who has access to the personal data is bound by confidentiality, and has access only to the extent needed for their work.
5. Security
Tradestack takes appropriate technical and organisational measures to protect the personal data against loss and unlawful processing, taking into account the state of the art, the costs and the risks. Annex 2 describes these measures. Tradestack may change them, as long as the level of security does not decrease.
6. Sub-processors
- The Customer gives general permission for the sub-processors listed in annex 3.
- Tradestack informs the Customer at least 30 days in advance, by e-mail or in the app, about a new or replaced sub-processor. The Customer can object on reasonable grounds. If the parties cannot find a solution, the Customer may terminate the Subscription with effect from the change, and Tradestack refunds the unused part of the prepaid period.
- Tradestack imposes the same data protection obligations on each sub-processor as this agreement imposes on Tradestack, and remains responsible for them.
7. Transfers outside the EEA
Tradestack stores the personal data in the European Economic Area (EEA). Personal data is only transferred to or accessed from countries outside the EEA if the requirements of chapter V of the GDPR are met, for example through an adequacy decision (such as the EU-US Data Privacy Framework) or the Standard Contractual Clauses.
8. Assistance
- Tradestack helps the Customer respond to requests from data subjects (such as access, correction or deletion). Much of this the Customer can do directly in the Service. If a data subject contacts Tradestack directly, Tradestack forwards the request to the Customer without answering it itself.
- Tradestack helps the Customer, within reason, with data protection impact assessments and prior consultation of the supervisory authority, as far as these concern the Service.
9. Personal data breaches
- Tradestack informs the Customer without undue delay, and in any case within 48 hours after discovering it, of a personal data breach that affects the Customer's data.
- Tradestack provides the information the Customer needs to report the breach to the supervisory authority and, where needed, to data subjects: what happened, which data and how many people are affected, the likely consequences and the measures taken. Information that is not yet available is provided as soon as possible.
- Tradestack takes the measures that can reasonably be expected to limit the consequences and prevent a repeat.
- Reporting to the supervisory authority and to data subjects is the responsibility of the Customer.
10. Information and audits
- Tradestack provides the Customer with the information needed to demonstrate compliance with this agreement.
- If that information is not sufficient, the Customer may have an audit carried out once a year by an independent, certified expert bound by confidentiality, announced at least 30 days in advance and without unreasonably disrupting Tradestack's operations. The Customer bears the costs, unless the audit shows that Tradestack seriously fails to comply with this agreement.
11. Return and deletion
During the Subscription and up to 30 days after it ends, the Customer can ask for an export of its data. Tradestack then deletes the personal data within 60 days after the end of the agreement, unless the law requires it to keep it. Deleted data disappears from the backups within another 14 days.
12. Liability
The limitation of liability in the terms of service also applies to this agreement, without prejudice to the liability that the GDPR itself imposes on each party.
13. Duration and priority
This agreement applies for as long as Tradestack processes personal data for the Customer. Obligations that by their nature continue after the end, such as confidentiality and deletion, remain in force. In matters of personal data, this agreement takes precedence over the terms of service.
Annex 1: Data subjects and personal data
Data subjects
- Users of the Customer: owners, admins, employees, field workers and subcontractors;
- the Customer's clients and their contact persons;
- other people whose data the Customer records, such as people present at a site, signatories of a completion report, attendees of a toolbox meeting and people involved in an incident.
Personal data
- identification and contact details: name, e-mail address, phone number, address and site address;
- work data: work orders, planning, assignments, hours, materials, notes and photos;
- signatures and names of signatories;
- certificates and qualifications: type, number, issue and expiry date and scans;
- forms and reports, such as LMRA checklists, toolbox meetings, completion reports and incident reports;
- account and technical data: role, language, login events, IP address, browser and device.
Special categories
The Service is not intended for special categories of personal data. However, an incident report may contain health data (such as an injury). The Customer limits this to what is necessary. The Customer does not upload copies of identity documents with a citizen service number (BSN).
Retention
The Customer decides how long the data is kept in the Service. After the agreement ends, article 11 applies.
Annex 2: Security measures
- Hosting in the EU; servers are reachable only through the web (HTTPS) and SSH with keys; firewall and automatic security updates.
- Encryption of all traffic (TLS). Passwords are stored as hashes (bcrypt) and sensitive settings such as e-mail credentials are encrypted.
- Separation of customers: all data belongs to one company and every request checks company membership and role.
- Private files (photos, signatures, certificates, documents) are only available through authenticated, company-bound links or signed links that expire after 10 minutes.
- Backups every night, encrypted and stored with a different provider, kept for 14 days; restores are tested.
- Access by Tradestack is limited to a small number of named people, for support and maintenance only.
- Logging: logins, failed logins and changes are logged and kept for 12 months.
- Misuse: rate limits on logging in, synchronising and downloads.
- Test environments never contain production data.
- Devices: data stored offline on a device is removed when the user signs out or another user signs in.
Annex 3: Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application and database | Germany |
| [provider] | Encrypted off-site backups | EU |
| Resend, Inc. | Sending e-mail (invitations, notifications) | EU (Ireland), company based in the USA |
Stripe processes payment data of the Customer as an independent controller and is therefore not a sub-processor for customer data.