Doorst.app — Data Processing Agreement (Verwerkersovereenkomst / DPA)

Version: 1.1 — Last updated: 18 August 2026

Parties

This Data Processing Agreement ("DPA") is entered into between:

1. The Customer — the agency or business that uses Doorst.app under our Terms of Service (the "Controller"); and 2. BTNG B.V., KvK 91214777, registered at Willem Roelofsstraat 3, 7424 GD Deventer, The Netherlands, operator of Doorst.app (the "Processor", "we", "us").

This DPA forms part of, and is governed by, the Terms of Service between the parties. It applies whenever we process personal data on the Customer's behalf in providing Doorst.app. It is concluded electronically when the Customer accepts the Terms or otherwise starts using Doorst to process personal data.

Where this DPA conflicts with the Terms of Service on the subject of data processing, this DPA prevails.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" have the meanings given in the GDPR (Regulation (EU) 2016/679 / AVG). "Applicable Data Protection Law" means the GDPR and the Dutch implementing law (UAVG).

2. Roles and scope

The Customer is the Controller and we are the Processor in respect of the personal data the Customer processes through Doorst about its own clients and their representatives ("Customer Personal Data").

We process Customer Personal Data only to provide the Service and only on the Customer's documented instructions, as set out in this DPA and Annex 1. The Customer is responsible for the lawfulness of the data it processes through Doorst and for having a valid legal basis.

(For clarity: data where we act as our own controller — for example the Customer's own account and billing data — is covered by our Privacy Policy, not by this DPA.)

3. Our obligations as Processor

We will:

a. process Customer Personal Data only on the Customer's documented instructions, including as to international transfers, unless required to do otherwise by EU or member-state law (in which case we will inform the Customer, unless the law forbids it);

b. ensure persons authorised to process the data are bound by confidentiality;

c. implement appropriate technical and organisational security measures as described in Annex 3 (Article 32 GDPR);

d. respect the conditions in Section 4 for engaging sub-processors;

e. taking into account the nature of the processing, assist the Customer with appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (Chapter III GDPR);

f. assist the Customer in ensuring compliance with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments), taking into account the information available to us;

g. at the Customer's choice, delete or return Customer Personal Data at the end of the provision of the Service, and delete existing copies, unless EU or member-state law requires storage (see Section 9 and the 7-year invoice-retention rule);

h. make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits as described in Section 7.

We will inform the Customer if, in our opinion, an instruction infringes Applicable Data Protection Law.

4. Sub-processors

The Customer gives general authorisation for us to engage sub-processors to provide the Service. Our current sub-processors are listed in Annex 2. Each sub-processor is bound by data-protection obligations no less protective than those in this DPA.

If we intend to add or replace a sub-processor, we will give the Customer prior notice (for example by email or in-app) and a reasonable period to object on reasonable data-protection grounds. If the Customer objects and we cannot offer a reasonable alternative, the Customer may terminate the affected part of the Service.

5. International transfers

We process Customer Personal Data primarily within the EU/EEA (see Annex 2). Hosting and primary storage are in Germany.

One sub-processor involves a transfer outside the EEA: Stripe, where the Customer connects a Stripe account to bill its clients. Stripe contracts in the EU through Stripe Payments Europe Ltd (Ireland) and processes within its group, including in the United States, under the Standard Contractual Clauses and its own certification under the EU-US Data Privacy Framework. This transfer only happens if the Customer chooses Stripe as its invoicing provider; Customers using Mollie or Moneybird stay within the EU.

Beyond that, we will not transfer Customer Personal Data outside the EEA without an appropriate safeguard under Chapter V GDPR (such as an adequacy decision or the Standard Contractual Clauses).

6. Data-subject requests

If we receive a request directly from a data subject relating to Customer Personal Data, we will not respond to the substance of the request ourselves (unless legally required) and will instead refer the data subject to the Customer and notify the Customer without undue delay. We will provide reasonable assistance to enable the Customer to respond, including through the access and deletion features in Doorst and, on request, an export of the Customer's data prepared by us (see Section 9).

7. Audits

On reasonable prior written request, and no more than once per year (unless required by a supervisory authority or following a breach), we will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR. Where an on-site audit is genuinely necessary, the parties will agree scope and timing in advance so as not to disrupt the Service, and the Customer bears its own costs.

8. Personal data breach

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information the Customer reasonably needs to meet its own notification obligations under Articles 33–34 GDPR. It remains the Customer's responsibility, as Controller, to notify the supervisory authority and/or data subjects where required.

9. Return and deletion of data

On termination of the Service, or on the Customer's earlier instruction, we will delete or return Customer Personal Data as the Customer chooses, and delete existing copies, except to the extent EU or member-state law requires retention. Where the Customer asks for a return, we provide the data in a structured, commonly used, machine-readable format (JSON and/or CSV) together with uploaded files, normally within 10 working days and at no charge. Data stays retrievable for at least 30 days after termination (the transition period in Section 13 of the Terms), after which it is erased. In particular, invoicing and accounting records are retained for the statutory period (currently 7 years under Dutch law). Doorst's built-in deletion features (workspace, company, client and task deletion, including associated files) implement this; backups are overwritten in the ordinary rotation.

10. Liability and term

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. This DPA takes effect when the Customer accepts the Terms or first processes personal data through Doorst, and continues for as long as we process Customer Personal Data.

11. Governing law

This DPA is governed by Dutch law, and disputes are subject to the competent Dutch court for the district of our registered office.


Annex 1 — Details of processing

Subject matter: provision of the Doorst.app subscription-management service to the Customer.

Duration: for the term of the Customer's subscription and until data is deleted or returned under Section 9.

Nature and purpose: hosting, storing, organising, displaying, invoicing on, and otherwise processing Customer Personal Data so the Customer can manage and bill its own clients through Doorst, including a client portal and task management.

Types of personal data:

  • the Customer's clients' contact data: names, email addresses;
  • billing data: billing addresses, VAT numbers, invoice details;
  • content the Customer or its clients enter into tasks, comments and uploaded files;
  • account/login data of the Customer's client-portal users (names, emails, hashed passwords);
  • where the Customer requires a signed client agreement: the signer's typed name, the date and time, the exact agreement text accepted, and the IP address the signature came from, retained as evidence of what was agreed;
  • technical/usage data (e.g. IP addresses, logs) relating to portal users.

Categories of data subjects:

  • the Customer's clients and their representatives/employees;
  • client-portal users invited by the Customer.

Special categories of data: none are required or intended. The Customer must not use Doorst to process special-category data (Article 9 GDPR) unless separately agreed in writing.

Annex 2 — Authorised sub-processors

Sub-processorPurposeLocation
MolliePayment processing (card data stored by Mollie)Netherlands (EU)
MoneybirdInvoicing / accountingNetherlands (EU)
StripeInvoicing and payment collection, where the Customer connects its own Stripe account to bill its clientsIreland (EU), with group processing in the United States
HetznerHosting and primary data storageGermany (EU)
CloudflareDNS, transactional email delivery, off-site encrypted backups (R2)EU / global infrastructure
Plausible AnalyticsCookieless, anonymous website analyticsEU

Not sub-processors under this DPA. Two services receive data but never Customer Personal Data held about the Customer's own clients beyond the single field named: the European Commission's VIES system receives a VAT number when we validate one, and the Dutch government's PDOK Locatieserver receives a postcode and house number (never a name) when a Dutch address is looked up. UserJot, our in-app feedback tool, is confined to the agency dashboard and receives only the agency user's own account details, never client data; it is covered by our Privacy Policy rather than by this DPA.

Annex 3 — Technical and organisational security measures

  • Tenant isolation: each agency's data is scoped to its own workspace; access controls prevent one agency from reading another's data, and the isolation is covered by automated tests.
  • Encryption: data encrypted in transit (TLS); passwords stored hashed.
  • Access control: role-based access; administrative access limited to authorised personnel, bound by confidentiality.
  • Support access: the administrative "view as agency" function, which lets us open a workspace to diagnose a fault, writes every use to an audit log (administrator, workspace, time) and runs on a shortened session.
  • Brute-force protection: failed sign-ins are rate-limited per account and per IP address.
  • Deletion / erasure: audited deletion paths for workspaces, companies, clients and tasks, including removal of associated uploaded files; an orphan-file sweep.
  • Backups: daily snapshots copied off-site to Cloudflare R2 over TLS and encrypted at rest by the storage provider; local copies rotate 7 daily / 4 weekly / 12 monthly; deleted data cycles out of backups. Backup-storage credentials are held separately from the application.
  • Logging and audit: security-relevant events (e.g. logins, deletions) are logged.
  • Sub-processor controls: sub-processors bound by Article 28-consistent terms; EU-first hosting.