Data Processing Agreement

DPA for business customers

This Data Processing Agreement (DPA) governs how MyCompanyDesk processes personal data on your behalf as a business customer, in accordance with GDPR Article 28 and the recommendations of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and the NLdigital Data Pro Code. You need this agreement as soon as you process personal data of your own customers through MCD.

Version 1.0, effective date 18 May 2026

Article 1

Parties and applicability

This Data Processing Agreement is concluded between MyCompanyDesk (processor) and you as a business customer (controller). By putting your MCD account into business use, you accept this DPA. The DPA forms an integral part of our terms and conditions.

Processor

MyCompanyDesk, sole proprietorship of Sil van Rijnberk, Chamber of Commerce (KVK) 42058784, Naxosdreef 161, 3562 JG Utrecht, the Netherlands. Contact: [email protected].

Controller

The business customer as registered in the MCD account (name, KVK number, registered address). You determine the purpose and means of processing the personal data that you manage through MCD.

Article 2

Subject matter, nature, purpose and duration

MCD processes personal data solely for the provision of the service described in the terms and conditions: invoicing, customer and project administration, time registration, expense tracking, contracts, email delivery and associated reporting. The processing continues for as long as you hold an active MCD account and ends as soon as you terminate the account, subject to Article 10 (return and deletion).

Categories of data subjects

Your own customers and contacts, your employees or team members, suppliers whose invoices or receipts you process, and subscribers to your newsletters within MCD.

Categories of personal data

Contact details (name, email address, telephone number, address), business identification (KVK and VAT number), financial identification (IBAN, payment status), the content of invoices, quotations, contracts and email correspondence, usage logs and IP addresses for security purposes.

Special categories

MCD is not designed for the processing of special categories of personal data (GDPR Article 9), such as health data. Do not knowingly store such data in the platform; if you do so regardless, you are yourself responsible for it.

Article 3

Obligations of the processor

MCD processes personal data solely on your documented instructions as set out in this DPA and the terms and conditions. MCD will notify you if, in its reasonable opinion, an instruction infringes the GDPR or other applicable laws and regulations.

Confidentiality

Everyone who has access to your personal data on behalf of MCD is bound by confidentiality, both during and after the collaboration.

No secondary use

MCD does not use your customer data for its own purposes, profiling, resale or the training of its own models. Aggregated, non-identifiable product statistics fall outside this scope.

Article 4

Sub-processors

MCD engages subprocessors for hosting, email delivery, payments, bank connections, AI and company lookups. The current list is in the privacy statement and is updated at least fourteen days in advance of any addition or replacement. You can object in writing within that period; if no solution can be reached, you have the right to cancel your MCD subscription with effect from the next billing period. MCD imposes on every subprocessor, through a back-to-back data processing agreement, the same obligations this DPA imposes on MCD (GDPR art. 28(4)). MCD remains fully liable to you for the acts or omissions of its subprocessors. Transfers outside the EEA take place solely under Standard Contractual Clauses or the EU-US Data Privacy Framework; customers can verify the current DPF certification status of US subprocessors at dataprivacyframework.gov/list.

Article 5

Security measures

MCD implements appropriate technical and organisational measures to protect personal data against loss, unauthorised access and unlawful processing, in accordance with GDPR Article 32. In concrete terms, this includes, among other things: TLS encryption for all connections, encrypted storage of OAuth tokens and TOTP secrets, bcrypt-hashed passwords, the strict limitation of administrative access with audit logging, optional two-factor authentication and WebAuthn, daily backups in eu-north-1, regular security reviews and automated scrubbing of personal data from error logs.

Article 6

Personal data breach notification

If MCD becomes aware of a personal data breach affecting your customers or employees, MCD will notify you without undue delay and within 48 hours at the latest, via the email address recorded in your account. The notification contains a description of the nature of the breach, which (categories of) data subjects and data it concerns, the likely consequences and the measures taken or proposed. MCD will support you with any notification to the Dutch Data Protection Authority and to data subjects, but the obligation to notify the supervisory authority rests with you as the controller.

Article 7

Assistance with data subject rights

MCD provides standard functionality within the application enabling you to handle access, rectification, erasure and data portability requests from your data subjects yourself, including a data export via /api/account/export and the permanent deletion of customer and invoice records. For requests that cannot be handled through the standard functionality, MCD provides you with technical support at cost price.

Article 8

Audits

You have the right, once per calendar year and following a written request with a period of thirty days, to carry out (or have carried out) an audit of compliance with this DPA. The audit takes place during office hours and may not reasonably hinder the operations of MCD. The auditing firm is bound by confidentiality. The costs of the audit are borne by you, unless a material shortcoming attributable to MCD is established.

Article 9

Liability

MCD's liability for damage arising from an attributable failure to perform this DPA is limited per calendar year to the amount you have paid to MCD in the twelve months preceding the event giving rise to the damage, up to a maximum of EUR 5,000. This limitation does not apply in the case of intent or deliberate recklessness. For the remainder, the parties adhere to the liability provisions in the terms and conditions.

Article 10

Return and deletion upon termination

Upon termination of the MCD subscription, you may still download a full data export via your account or via /api/account/export for up to thirty days after the end date. After that, MCD deletes your personal data within ninety days, subject to a statutory retention obligation (in particular the Dutch tax retention obligation of seven years for invoices and administration, AWR Article 52). Backups run on a rolling schedule (by default thirty backups, every six hours) and are therefore fully overwritten within seven and a half days.

Article 11

Governing law and disputes

This DPA is governed by Dutch law. Disputes are submitted exclusively to the competent court in the Midden-Nederland district, unless mandatory law designates a different court. Amendments are announced at least thirty days in advance via the email address recorded in your account and published on this page.

Questions about the DPA?

Send an email to [email protected] and we will respond within two business days.