Data Processing Agreement

Verwerkersovereenkomst pursuant to Article 28 GDPR

Last updated: August 26, 2026

This Data Processing Agreement (“DPA”) forms an integral part of the Terms & Conditions between:

Controller: The User of the GroomSome Service (“you” or “Controller”), being the grooming business that enters personal data of its clients into the Service; and

Processor: Cre8-it B.V., trading as GroomSome, registered with the Dutch Chamber of Commerce (KvK) under number 42147119, VAT NL869923651B01, with its place of business at Baron van Nagellstraat 136, 3771 LL Barneveld, the Netherlands (“GroomSome”, “we”, or “Processor”).

By using the GroomSome Service and entering personal data of your clients, you accept this DPA.

Article 1 — Definitions

Terms used in this DPA have the same meaning as defined in the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the GroomSome Terms & Conditions. In addition:

1.1 “Personal Data” means any personal data processed by the Processor on behalf of the Controller through the Service, as described in Annex 1.

1.2 “Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

1.3 “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

Article 2 — Scope and Purpose of Processing

2.1 The Processor processes Personal Data solely on behalf of and on the documented instructions of the Controller, for the purpose of providing the GroomSome Service as described in the Terms & Conditions.

2.2 The nature, purpose, duration, types of Personal Data, and categories of data subjects are described in Annex 1 to this DPA.

2.3 The Processor shall not process Personal Data for any purpose other than as set out in this DPA, unless required to do so by EU or Dutch law. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information.

2.4 Anonymous aggregated statistics. As a specific, documented instruction under Article 2.1, the Controller authorises the Processor to derive anonymous, aggregated statistics from Personal Data during the term of the Agreement, solely for the purposes of operating the Service, capacity planning, and product analytics and improvement. This authorisation is subject to all of the following conditions:

  1. before any use for these purposes, the data is irreversibly anonymised in accordance with the standards of the European Data Protection Board, so that neither the Controller, nor any data subject, nor any individual business can be identified or singled out;
  2. each statistic is computed as an aggregate across no fewer than twenty (20) customer accounts (companies);
  3. the Processor shall not attempt, and shall contractually prohibit any third party from attempting, to re-identify any person or business from such statistics;
  4. such statistics shall not be used to provide pricing recommendations, price benchmarking, or competitive insights about the Controller to any other customer of the Processor; and
  5. derivation from Personal Data takes place only during the term of the Agreement; after termination, the deletion obligations of Article 8 apply in full to all Personal Data.

2.5 The Controller may withdraw the authorisation in Article 2.4 at any time by written notice to the Processor, without affecting the provision of the Service. Withdrawal has effect for the future; statistics already irreversibly anonymised are no longer personal data.

2.6 Article 2.4 is severable. If it is held invalid or is not accepted by the Controller, the remainder of this DPA remains in full force, and the Processor shall not derive statistics from that Controller’s Personal Data.

Article 3 — Obligations of the Processor

3.1 The Processor shall:

  1. process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required by law;
  2. ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  3. implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2;
  4. assist the Controller, taking into account the nature of processing, by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising data subject rights (Chapter III GDPR);
  5. assist the Controller in ensuring compliance with obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor;
  6. at the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of the Service, and delete existing copies unless EU or Dutch law requires further storage;
  7. make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

3.2 The Processor shall immediately inform the Controller if, in its opinion, an instruction from the Controller infringes the GDPR or other EU or Dutch data protection provisions.

Article 4 — Sub-processors

4.1 The Controller provides general written authorisation for the Processor to engage Sub-processors. The current list of Sub-processors is set out in Annex 3 to this DPA.

4.2 The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors at least 30 days in advance, thereby giving the Controller the opportunity to object to such changes.

4.3 If the Controller objects to a new Sub-processor on reasonable grounds relating to the protection of Personal Data, the parties shall discuss the concern in good faith. If no resolution can be reached within 30 days, the Controller may terminate the Agreement with immediate effect.

4.4 Where the Processor engages a Sub-processor, the Processor shall impose the same data protection obligations as set out in this DPA on that Sub-processor by way of a contract. The Processor shall remain fully liable to the Controller for the performance of the Sub-processor’s obligations.

Article 5 — International Transfers

5.1 The Processor shall not transfer Personal Data to a country outside the European Economic Area (EEA) unless appropriate safeguards are in place as required by Chapter V of the GDPR, such as EU Standard Contractual Clauses (SCCs) or an adequacy decision by the European Commission.

5.2 The Processor shall inform the Controller of any transfers to third countries and the safeguards relied upon.

Article 6 — Data Breach Notification

6.1 The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Data Breach affecting Personal Data processed under this DPA, so that the Controller can meet its own notification obligations under Articles 33 and 34 GDPR.

6.2 The notification shall at minimum describe:

  1. the nature of the Data Breach, including where possible the categories and approximate number of data subjects and records concerned;
  2. the likely consequences of the Data Breach;
  3. the measures taken or proposed to address the Data Breach, including measures to mitigate its possible adverse effects.

6.3 The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Data Breach.

6.4 The notification of a Data Breach shall not be construed as an acknowledgement of fault or liability by the Processor.

Article 7 — Audits

7.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.

7.2 The Controller may conduct an audit of the Processor’s processing activities, or appoint an independent third-party auditor to do so, no more than once per calendar year. The Controller shall provide at least 30 days’ prior written notice. The audit shall be conducted during normal business hours and shall not unreasonably disrupt the Processor’s operations.

7.3 The costs of the audit shall be borne by the Controller, unless the audit reveals a material breach of this DPA by the Processor.

Article 8 — Data Retention and Deletion

8.1 Upon termination or expiry of the Agreement, the Processor shall make all Personal Data available for export by the Controller for a period of 30 days, in structured, commonly used, machine-readable formats (including XLSX and CSV), free of charge, in accordance with Article 8 of the Terms & Conditions and Regulation (EU) 2023/2854 (Data Act).

8.2 After the 30-day export period, the Processor shall delete all Personal Data from its active systems within 30 days and from backup systems within 90 days, unless EU or Dutch law requires further retention (e.g., financial records under the Dutch fiscal retention obligation).

8.3 The Processor shall provide written confirmation of deletion upon the Controller’s request.

Article 9 — Liability

9.1 The liability of the Processor under this DPA is subject to the liability provisions in the Terms & Conditions (Article 9).

9.2 Each party is liable for damages caused by processing that infringes the GDPR, in accordance with Article 82 GDPR.

Article 10 — Duration and Termination

10.1 This DPA enters into force upon your acceptance of the Terms & Conditions and remains in effect for the duration of the processing of Personal Data by the Processor.

10.2 Obligations that by their nature should survive termination (including Articles 3(f), 6, 7, 8, and 9) shall survive termination of this DPA.

Article 11 — Governing Law

11.1 This DPA is governed by the laws of the Netherlands.

11.2 Any disputes arising from this DPA shall be submitted to the competent court in the district of Gelderland (Rechtbank Gelderland).

Annex 1 — Description of Processing

Subject matterProcessing of personal data of the Controller’s clients (pet owners) through the GroomSome SaaS platform for the purpose of appointment management, customer relationship management, and pet grooming business operations.
DurationFor the term of the Agreement between Controller and Processor, plus the post-termination retention period described in Article 8.
Nature and purposeStorage, organisation, retrieval, and display of personal data entered by the Controller into the Service. Automated backup and replication for disaster recovery. Processing to provide appointment scheduling, customer management, and reporting features.
Categories of data subjectsClients (customers) of the Controller’s pet grooming business, i.e., pet owners.
Types of personal data
  • Names (pet owner)
  • Contact details (phone number, email address, postal address)
  • Pet information (name, breed, age, medical/grooming notes, photos)
  • Appointment history and preferences
  • Notes entered by the Controller
Sensitive dataNone expected. The Controller shall not enter special categories of personal data (Article 9 GDPR) into the Service.

Annex 2 — Technical and Organisational Measures

The Processor implements the following measures to protect Personal Data:

Encryption in transitAll data transmitted between users and the Service is encrypted using TLS 1.2 or higher.
Encryption at restData stored in Azure Cosmos DB and Azure Blob Storage is encrypted at rest using AES-256 encryption managed by Microsoft Azure.
AuthenticationUser authentication is handled by our own identity service (Duende IdentityServer), hosted by the Processor on Microsoft Azure in the EU, with support for multi-factor authentication (MFA).
Access controlRole-based access control (RBAC). Access to production systems and databases is limited to the Processor on a need-to-know basis.
InfrastructureHosted on Microsoft Azure, EU West Europe region (Netherlands). Azure provides physical security, network security, and environmental controls certified under ISO 27001, SOC 2, and other standards.
BackupAutomated daily backups with point-in-time restore capability. Backups are stored within the EU.
MonitoringApplication monitoring through PostHog (EU Cloud, Frankfurt, Germany) for error detection, crash reporting and product analytics. No personal data is intentionally sent to PostHog; error and crash reports may incidentally contain technical context. No session recording is used inside the application, and analytics events contain no client names, contact details, or notes (page URLs may include pseudonymous record identifiers).
Incident responseDocumented incident response procedure. Data Breaches are escalated and notified in accordance with Article 6 of this DPA.
Employee accessAccess to production data is limited to authorised personnel of the Processor on a need-to-know basis, under confidentiality obligations.
Data minimisationThe Service collects and processes only the data entered by the Controller. We do not enrich, profile, or otherwise process Customer Data beyond what is necessary to provide the Service and what is expressly authorised in Article 2.4 of this DPA.

Annex 3 — List of Sub-processors

The following Sub-processors are authorised to process Personal Data under this DPA. This list may be updated in accordance with Article 4.2.

Sub-processor Purpose Location Privacy / DPA
Microsoft Azure (Microsoft Corporation) Cloud hosting, database (Cosmos DB), blob storage, hosting of the Processor’s own identity service, AI processing (Azure AI Foundry, deployed in the EU — breed matching and paper card import; data is not used to train foundation models) EU West Europe (Netherlands) Microsoft DPA
Stripe (Stripe Payments Europe, Ltd.) Payment processing Ireland (EU) Stripe Privacy Policy
Microsoft Clarity (Microsoft Corporation) Website analytics and session recording (marketing site only, with consent) EU / Global Microsoft Privacy Statement
Bird (MessageBird B.V.) SMS and WhatsApp appointment reminders Netherlands (EU) Bird Privacy Policy
Resend (Resend, Inc.) Transactional email delivery US (SCCs in place) Resend DPA
Google Cloud Vision (Google LLC) Text recognition (OCR) of photographed customer cards for the paper import feature (user-initiated) EU/US (SCCs in place) Google Cloud DPA
PostHog (PostHog, Inc.) Product analytics, error monitoring and crash reporting (feature usage events, which may include pseudonymous record identifiers such as those in page URLs; no client names, contact details, or notes) EU Cloud — Frankfurt, Germany PostHog DPA
Google Firebase (Google LLC) Mobile push notifications EU/US (SCCs in place) Firebase Privacy
Google Calendar API (Google LLC) Calendar synchronization (opt-in by user) EU/US (SCCs in place) Google Privacy Policy

Contact

Cre8-it B.V., trading as GroomSome
Baron van Nagellstraat 136
3771 LL Barneveld, the Netherlands
KvK: 42147119
VAT: NL869923651B01
Phone: +31 6 19732457
Email: info@groomsome.app