Data Processing Agreement
Template in accordance with Article 28 GDPR · Version 2.0 · 17 April 2026
Parties
Data controller ("Client")
Company name:
Legal form:
Represented by:
Registered address:
Chamber of Commerce number:
Email:
Processor ("Alvoru")
Alvoru (sole proprietorship), owner Yousri
Established in Cuijk, the Netherlands
Email: info@alvoru.com · Phone: 06-34 78 39 29
Chamber of Commerce number: 42071779
Hereinafter jointly: "the Parties".
Whereas
- the Parties have concluded a main agreement under which Alvoru, as Processor, processes personal data on behalf of the Client (hereinafter: the "Main Agreement");
- pursuant to Article 28(3) GDPR a written data processing agreement is required setting out arrangements on how the Processor processes personal data;
- this data processing agreement (hereinafter: "DPA") forms an integral part of the Main Agreement.
Article 1 — Definitions
The capitalised terms used in this DPA have the meaning assigned to them in the GDPR, supplemented by the definitions in Alvoru's Terms and Conditions.
Article 2 — Subject matter and duration
2.1 This DPA governs the processing of personal data by Alvoru on behalf of the Client within the scope of the Main Agreement.
2.2 This DPA takes effect on the date on which the Main Agreement commences and ends by operation of law upon termination of the Main Agreement, without prejudice to those provisions which by their nature are intended to remain in force.
Article 3 — Nature and purpose of the processing
3.1 The nature and purpose of the processing consists of delivering the Service described in the Main Agreement (AI customer service, including chatbot, email and calendar).
3.2 Alvoru processes personal data solely on the documented instruction of the Client, save for deviating legal obligations (art. 28(3)(a) GDPR). In the latter case, Alvoru notifies the Client prior to the processing, unless that law prohibits this on important grounds.
Article 4 — Types of personal data and categories of data subjects
| Category of data subjects | Type of personal data |
|---|---|
| End users / customers of the Client | Name, email address, phone number, conversation content, booking details, IP address |
| Employees of the Client | Name, business email address, account details |
| Visitors to the customer portal | IP address, session data, cookie ID |
Special categories of personal data (art. 9 GDPR) and criminal-offence data (art. 10 GDPR) are not processed, unless additionally agreed in writing.
Article 5 — Obligations of the Processor
5.1 Alvoru processes personal data solely for the purposes set out in the Main Agreement and this DPA and on the written instruction of the Client.
5.2 Alvoru ensures that persons who process personal data are bound by a duty of confidentiality, whether by law or by contract.
5.3 Taking into account the nature of the processing, Alvoru provides the Client with reasonable assistance in responding to requests from data subjects exercising their rights under the GDPR.
5.4 Alvoru makes available to the Client all information necessary to demonstrate compliance with Article 28 GDPR.
5.5 AI training prohibition. Alvoru will never use the personal data it processes on behalf of the data controller to train, fine-tune or otherwise improve AI models, nor to develop its own or third-party AI applications.
Article 6 — Security measures (Article 32 GDPR)
Alvoru takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) and, where applicable, encryption at rest;
- Access control based on least privilege; two-factor authentication for administrators;
- Firewalls, fail2ban and intrusion monitoring;
- Daily encrypted backups with a retention period of at most 90 days;
- Restrictive file permissions (600) on configuration and data files;
- Logging and monitoring of access to production systems;
- Periodic evaluation and updating of security measures.
Article 7 — Sub-processors
7.1 The Client grants Alvoru a general written authorisation to engage sub-processors, provided that Alvoru complies with the other provisions of this article.
7.2 The currently engaged sub-processors are:
| Sub-processor | Purpose | Location / safeguard |
|---|---|---|
| Anthropic | AI text generation (primary) | US — SCCs |
| OpenAI | AI text generation (fallback) | US — DPF + SCCs |
| Resend | Transactional email | US — DPF |
| Hetzner Online | Hosting & storage | EU (DE/FI) |
| Cloudflare | CDN, DDoS protection, DNS & Email Routing | DPF + SCCs |
| Sentry | Error monitoring (technical logs) | EU (DE) |
| Meta Platforms Ireland | WhatsApp Business API (only if activated by the Client) | EU (IE) + US — SCCs + DPF |
| Google LLC | Workspace mail routing and Maps Platform | US — DPF + SCCs |
| Moneybird | Invoicing and accounting | EU (NL) |
| Mollie | Payment processing | EU |
7.3 Alvoru imposes on sub-processors the same data protection obligations as those set out in this DPA (Article 28(4) GDPR).
7.4 Alvoru will notify the Client at least 14 days in advance of any replacement or addition of sub-processors. The Client may raise a reasoned objection within that period. In the event of a well-founded objection, the Client has the right to terminate the Main Agreement free of charge.
Article 8 — Transfers outside the EEA
Transfers of personal data to a country outside the European Economic Area take place solely on the basis of an adequacy decision (Art. 45 GDPR), binding corporate rules, EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) or another safeguard provided for under the GDPR, supplemented by additional technical and organisational measures where required.
Article 9 — Rights of data subjects
9.1 Alvoru provides the Client with appropriate support in handling data subject requests (access, rectification, erasure, restriction, portability, objection) through technical functionality in the customer portal and, where necessary, additional assistance.
9.2 Alvoru forwards data subject requests received directly by Alvoru to the Client without delay.
Article 10 — Data breaches
10.1 Alvoru informs the Client without delay and no later than within 48 hours after becoming aware of a personal data breach (Art. 33(2) GDPR), so that the Client can meet its notification obligation to the supervisory authority within 72 hours in good time.
10.2 The notification includes at least: the nature of the breach, the categories and number of data subjects, the categories and number of records affected, the likely consequences and the measures taken or proposed.
10.3 Alvoru provides the Client with appropriate assistance in notifying the supervisory authority and, where relevant, the data subjects.
Article 11 — Audit
11.1 Once per calendar year, subject to at least 30 days' prior written notice and at its own expense, the Client may carry out (or have carried out) an audit of Alvoru's compliance with this DPA.
11.2 The audit is conducted by an independent auditor bound by confidentiality, during business hours and in a manner that does not disrupt Alvoru's normal operations.
11.3 Instead of an on-site audit, Alvoru may provide a current report from an independent third party (for example ISO 27001 or SOC 2), provided that this report offers reasonably sufficient assurance.
Article 12 — Termination and deletion of data
12.1 Upon termination of the Main Agreement, Alvoru will, at the Client's choice and on first written request, delete or return all personal data to the Client, in accordance with Article 28(3)(g) GDPR.
12.2 Such a request may be submitted within 60 days of termination. Failing that, data is automatically deleted after 60 days.
12.3 Offline backups are erased in accordance with the regular rotation schedule no later than 90 days after termination.
12.4 Data that Alvoru is legally required to retain is kept for the legally prescribed period.
Article 13 — Liability
13.1 Alvoru's liability under this DPA is included in and limited by the liability provisions of the Terms and Conditions accompanying the Main Agreement.
13.2 Mandatory provisions of the GDPR remain unaffected.
Article 13a — Record of processing activities
Alvoru maintains a record of processing activities in accordance with Article 30 GDPR. This record includes at least: the name and contact details of Alvoru as processor, the categories of processing carried out on behalf of Controllers, transfers to third countries and the safeguards applied, and a general description of technical and organisational security measures. The record is available to the supervisory authority on request.
Article 14 — Governing law and disputes
This DPA is governed by Dutch law. Disputes will be submitted to the Overijssel District Court, Almelo location.
Signing
On behalf of the Client
Name:
Role:
Date:
On behalf of Alvoru
Name: Yousri
Role: Owner
Date:
Send the signed version (scanned or digitally signed) to info@alvoru.com. Alvoru will return a counter-signed copy.