SourcingFlow Data Processing Agreement
Version 1.0 — Last updated: 10 September 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the SourcingFlow Terms & Conditions between Spic&Scan B.V., established at Ambachtsweg 25, 5627 BZ Eindhoven, the Netherlands, registered with the Dutch Chamber of Commerce (KVK) under number 81100795 (“Processor”, “we”), and the customer that accepted those Terms (“Controller”, “you”). It applies whenever we process personal data on your behalf in connection with the SourcingFlow Service, as required by Article 28 of the General Data Protection Regulation (GDPR).
1. Roles
You are the controller of the personal data you or your users submit to the Service (for example, contact details of your own employees or of your suppliers). We are the processor: we process that data only on your documented instructions, as set out in this DPA and the Terms.
2. Subject matter, duration, nature and purpose
- Subject matter: personal data submitted to or generated within the Service by you or your authorized users.
- Duration: for the term of your subscription, and until deletion in accordance with Section 8.
- Nature and purpose: hosting, storing, and processing this data solely to provide, maintain, secure, and support the Service, and to fulfil our obligations under the Terms.
3. Categories of data and data subjects
- Categories of personal data: names, business email addresses, phone numbers, and job/company details of the individuals you record in the Service.
- Categories of data subjects: your own authorized users, and contact persons at your suppliers or other business relations that you choose to record in the Service.
4. Our obligations as processor
We will:
- process personal data only on your documented instructions, including regarding international transfers, unless required to do otherwise by EU or Member State law (in which case we will inform you beforehand, unless prohibited by law);
- ensure that persons authorized to process the data have committed themselves to confidentiality;
- implement appropriate technical and organizational security measures (Section 7);
- assist you, insofar as reasonably possible, in responding to requests from data subjects exercising their GDPR rights;
- assist you in ensuring compliance with your obligations regarding security of processing, breach notification, and data protection impact assessments, taking into account the information available to us;
- at your choice, delete or return all personal data to you at the end of the provision of the Service, and delete existing copies unless EU or Member State law requires storage;
- make available to you the information reasonably necessary to demonstrate compliance with this Article, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice and no more than once per year (except where triggered by a suspected data breach).
5. Sub-processors
As of the date of this DPA, we do not engage any sub-processors to process personal data under this DPA; the Service runs on our own infrastructure.
If this changes, we will inform you of the intended engagement of any new sub-processor with at least 30 days’ prior notice, giving you the opportunity to object on reasonable data-protection grounds. Where we do engage a sub-processor, we will impose the same data protection obligations on it as set out in this DPA, and we remain fully liable to you for that sub-processor’s performance.
6. Security measures
We apply, among others, the following measures: encrypted (SSL/TLS) transmission of data; SPF, DKIM, and DMARC email authentication; hosting on servers located in, and subject to the laws of, the Netherlands; and encrypted storage of passwords, which we cannot retrieve ourselves. We review these measures periodically and adjust them where reasonably necessary to maintain an appropriate level of security.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting data processed under this DPA, providing the information reasonably available to us to allow you to meet your own notification obligations.
8. Deletion and return of data
You may export or delete your data within the Service at any time. Upon termination of your subscription, we will delete your data in accordance with the Terms, subject to our standard backup retention period, after which it is permanently removed, unless we are legally required to retain it for longer.
9. International transfers
We do not transfer personal data processed under this DPA outside the European Economic Area. If this changes, we will ensure an appropriate transfer mechanism under GDPR is in place beforehand and will inform you accordingly.
10. Liability, term, and governing law
Liability under this DPA is subject to the limitation of liability set out in the Terms. This DPA takes effect when you accept the Terms, remains in effect for as long as we process personal data on your behalf, and is governed by the same governing law and jurisdiction as the Terms (the laws of the Netherlands; the competent court in ‘s-Hertogenbosch).
