Data processing agreement (verwerkersovereenkomst). This is the written agreement art. 28 lid 3 AVG requires whenever Ridoco handles personal data on your behalf. It forms part of the general terms and conditions and takes effect on the day the work starts. No signature is needed for it to apply. A countersigned copy is available on request.
1. Which jobs this covers, and which it does not
On the jobs below you are the controller (verwerkingsverantwoordelijke) and Ridoco is the processor (verwerker). You decide what happens to the data and why; Ridoco carries out the work you asked for.
- Maintenance and Care plans. Updates, backups, monitoring and fixes on a site that holds your customers' data.
- Hosting. A site Ridoco hosts for you on its own server.
- Building on live data. A build, a redesign or a migration where the existing site's database is copied, moved or edited.
- IT and security work. Remote or on-site work on your machines, mailboxes, network or accounts, including data recovery.
Two situations that look similar and are not covered:
- Your own relationship with Ridoco. Your account on this site, quotes, invoices, bookings and support tickets are Ridoco's own records. Ridoco is the controller for those and the privacy statement covers them.
- Design work with no personal data in it. A logo, a brand guide or artwork produced from material you supply falls outside this agreement unless that material contains personal data, in which case the whole of this agreement applies to it.
2. Subject matter and duration
Subject matter: the processing Ridoco carries out in order to deliver the job named on your quote.
Duration: from the start of the work until the job ends or the plan is cancelled, plus the wind-down period in article 10. This agreement lasts exactly as long as Ridoco holds any of your data.
3. Nature and purpose of the processing
The purpose is the delivery of the job, and nothing else. Ridoco does not use your data for its own analysis, its own marketing, or the training of any model.
In practice the processing consists of: reading and writing records in your site's database; restoring, copying and moving that database during a migration; opening files and mailboxes on your systems while diagnosing a fault; holding backups; reading server and application logs; and viewing whatever appears on screen during support.
4. Whose data, and what kind
Categories of data subjects: your customers, your website visitors, people who fill in your forms, your subscribers, your own staff, and anyone else whose data your systems hold.
Types of personal data: names, addresses, email addresses, telephone numbers, account credentials in hashed form, order and invoice records, message and form contents, uploaded files, IP addresses, and server log entries. The exact set is whatever your systems already contain. Ridoco does not choose it.
Special categories. The services are not designed for the data listed in art. 9 AVG or for criminal-offence data under art. 10 AVG. Do not put such data into a system Ridoco maintains without saying so in writing first, so that the extra measures art. 9 calls for can be agreed before the work starts. Where free text from your own users happens to contain it, you remain the controller and this agreement covers it like any other data.
5. Your instructions
- Ridoco processes your data only on your documented instructions. Your quote, your written brief, your ticket and your configuration of the systems are your instructions.
- An instruction given by phone or in a meeting is confirmed by email before it is acted on, so that both sides hold the same record of it.
- If Dutch or EU law obliges Ridoco to process something beyond your instructions, you are told before it happens, unless that same law forbids telling you.
- If an instruction appears to breach the AVG, Ridoco says so in writing and may hold it until you confirm.
- Nothing here permits Ridoco to transfer your data to anyone except the sub-processors in article 7.
6. Security (art. 32 AVG)
The measures in place on the work Ridoco carries out:
- every connection to the site and to the server runs over TLS;
- each site on the production server runs under its own operating system user and its own database user, so one site cannot read another's files;
- the application connects to its database as an application user and never as the database root user;
- administrative access to the production server is by SSH key only. Passwords do not open it;
- account passwords are stored as one-way hashes and cannot be read back;
- two-factor authentication is available on administrative accounts;
- files uploaded through the site are written outside the public web root and are reachable only through a route that checks who is asking;
- access to your production data is limited to the one person who runs Ridoco, under the confidentiality duty in article 8;
- dependency and vulnerability alerts on the software are monitored, and patches are applied when they are released;
- where Ridoco holds a backup of your site or your database, it is stored inside the EU, and it is covered by this agreement in the same way the live data is, including the erasure duty in article 10.
Art. 32 asks for measures appropriate to the risk. If your systems carry a risk that these do not answer, say so and the extra measures go on the quote before the work starts.
7. Sub-processors (art. 28 lid 2 and lid 4 AVG)
You give general written authorisation for the sub-processors below. Each is named because you cannot object to a party you have not been told the name of.
- netcup GmbH, Nuremberg, Germany. The server, its storage and its backups, for anything Ridoco hosts for you.
- Google Ireland Limited, Dublin, Ireland, for Google Workspace. The ridoco.com mailboxes. This one is reached only when your data arrives by email, such as an export you send, a screenshot attached to a fault report, or an address list handed over for a migration.
- Functional Software, Inc., trading as Sentry, San Francisco, United States, for error monitoring. The reports go to Sentry's European region and are stored in Frankfurt, Germany. This one is reached when the software fails, and on a sample of one request in five for timing. It receives the error, the stack trace, the address of the page with any token in it removed, the name of the matched route, and the shape of a database statement without the values in it. It is not sent names, email addresses, IP addresses, cookies, session tokens, or the contents of a form or a request body.
No other party is engaged. There is no analytics provider, no advertising network, no content delivery network and no AI provider in this chain. Payment providers ship in the platform and have no credentials on this install, so no payment provider receives anything either.
Your own suppliers are not sub-processors of Ridoco. Where the work runs on hosting, a domain registrar, a mail provider or plugin licences that stand in your name, those companies are your own processors under your own agreements with them. Ridoco uses the access you provide and adds nobody to that list.
Changing the list. Ridoco gives you at least 30 days written notice before adding or replacing a sub-processor. Within those 30 days you may object on reasonable data protection grounds. If the objection cannot be resolved, you may end the affected service without penalty and article 10 applies to the data. Every sub-processor is held to obligations no less protective than these, and Ridoco stays fully liable to you for what they do.
8. Confidentiality
Ridoco is one person and no staff, so the list of people with access to your data is one name. That person is bound to confidentiality on everything seen while carrying out the work, and the duty continues after the job ends and after this agreement ends. Anyone ever brought in to help is put under the same duty in writing before they are given access.
9. Requests from data subjects, and assistance (arts. 12 to 36 AVG)
A request under Chapter III AVG is yours to answer. Someone who contacts Ridoco directly is referred to you and their request is passed on to you the same working day it is recognised.
Ridoco helps you answer it with whatever technical work it takes: finding the records, exporting them, correcting them, restricting them or deleting them. That help is given inside your own art. 12 lid 3 deadline of one month, provided the request reaches Ridoco with time left on it.
Ridoco also assists you with arts. 32 to 36: the security measures, notification of a personal data breach, communication to affected people, and a data protection impact assessment where you have to carry one out.
Personal data breach. If a breach affects data Ridoco processes for you, Ridoco notifies you without undue delay after becoming aware of it, in line with art. 33 lid 2 AVG. The notification goes to the contact address on your quote and states what happened, which data and which people are affected as far as that is known, what has been done, and what is still being done. It is sent even when the picture is incomplete, so that your own 72 hour clock under art. 33 lid 1 can start on time. Ridoco does not report a breach to the Autoriteit Persoonsgegevens on your behalf. That decision is yours.
10. Return and erasure at the end
When the job ends, the plan is cancelled or this agreement ends, you choose within 30 days whether Ridoco returns your data or deletes it. Return is a database export and a copy of the files, handed over in a usable format at no charge.
Once you have chosen, Ridoco erases the remaining copies it holds, including working copies and backups, and confirms in writing that it has done so. Two exceptions, and they are the only two: anything Dutch or EU law requires Ridoco to keep, and Ridoco's own records of the transaction, which are invoices and correspondence covered by the privacy statement and not by this agreement.
If you make no choice within those 30 days, Ridoco asks once more in writing and then deletes.
11. Information and audit (art. 28 lid 3 onder h AVG)
On written request Ridoco provides the information you need to demonstrate that art. 28 is being complied with, including how the measures in article 6 are applied to your job. The target for a written answer is 30 days. It is a target and not a promised date, and where your own statutory deadline is shorter, say so in the request and the answer is worked to that deadline.
Where that information is not enough for your obligations, you may audit, or have an auditor audit on your behalf, once in any twelve month period, on 30 days notice, during business hours, under confidentiality, and without unreasonable disruption to other clients. You carry the cost unless the audit finds a material failure by Ridoco, in which case Ridoco carries it. A supervisory authority acting under its own powers is not limited by this article.
12. Where the data is
Your data is stored in the European Union. netcup GmbH and Google Ireland Limited are EU companies operating EU infrastructure. Sentry keeps the error reports in its European region in Frankfurt, and the company behind it is established in the United States. Its staff can reach that region to support and administer the service. That access runs under the European Commission's standard contractual clauses, and Sentry is certified under the EU-U.S. Data Privacy Framework. Apart from that access, no routine transfer outside the EEA takes place. Google's own onward transfers are governed by the Google Workspace data processing terms and their standard contractual clauses, which apply to the mailboxes and not to your hosted site.
If this ever changes, you are told before it changes, and the transfer mechanism is named at that point.
13. Liability, term and law
Each party carries its own liability under art. 82 AVG. Nothing in this agreement limits the rights of a data subject, and nothing in it may be read as shifting your responsibilities as controller onto Ridoco or the other way round.
This agreement runs for as long as Ridoco processes personal data on your behalf, and article 8 and article 10 survive its end. Where it conflicts with the general terms and conditions on a data protection point, this agreement prevails. Dutch law applies, and the court in Rechtbank Oost-Brabant has jurisdiction, exactly as under the general terms.
Changes to this document are published here with a revision date. A change that materially affects you is announced before it takes effect.
14. Contact
The processor under this agreement is Ridoco, an eenmanszaak established at De Nieuwe Erven 3-12572, 5431 NV Cuijk, Netherlands, entered in the Kamer van Koophandel under 95439609 and holding btw-identificatienummer NL005153257B49.
Everything this agreement asks you to put in writing goes to contact@ridoco.com: an instruction under article 5, an objection under article 7, a request for help under article 9, your choice under article 10, and an audit request under article 11.
Art. 37 AVG obliges three kinds of organisation to appoint a data protection officer, and a one-person web and IT business is none of the three. There is no officer to route a question to. It reaches the person who does the work.