Data Processing Agreement
The standard data processing agreement (Article 28 GDPR) between the Client as controller and StarCore as processor, for hosted and maintained websites.
This Data Processing Agreement forms part of the General Terms and Conditions of StarCore (https://starcore.dev/terms) and automatically applies to every Agreement under which StarCore, the trade name of the sole proprietorship of Krzysztof Starostka (KvK 42094342, hereinafter "Processor"), processes personal data on behalf of the Client (hereinafter "Controller"). It has been drawn up in accordance with Article 28(3) of the General Data Protection Regulation (GDPR). Business Clients expressly accept this agreement when activating their account in the Panel; the acceptance is recorded with version number and time.
1. Definitions
Terms from the GDPR ("personal data", "processing", "data subject", "controller", "processor", "personal data breach") have the meaning given in Article 4 GDPR. Capitalised terms not defined here have the meaning given in the General Terms and Conditions. "Sub-processor" means a third party engaged by Processor that processes personal data for the performance of the Services.
2. Subject matter, nature and purpose of the processing
- Processor processes personal data solely for providing the Services to Controller: hosting, maintaining, securing, backing up, monitoring and supporting the Client Website and, where agreed, the associated e-mail and domain services. A further description is given in Annex A.
- Controller determines the purposes and means of the processing and warrants that it has a valid legal basis for the processing and that the processing, including the instructions to Processor, complies with the GDPR.
- Processor does not process the personal data for its own purposes and no longer or more extensively than necessary for the Services.
3. Instructions
- Processor processes personal data only on documented instructions from Controller. This Data Processing Agreement, the Agreement and the instructions given by Controller in the Panel or In Writing count as instructions.
- If, in Processor's opinion, an instruction infringes the GDPR or other legislation, Processor immediately informs Controller and may suspend performance until the instruction has been amended or confirmed.
- If Processor is required by EU or Dutch law to process or disclose personal data, Processor informs Controller of that requirement beforehand, unless that law prohibits this on important grounds of public interest.
4. Confidentiality
Processor binds everyone who processes personal data under its authority to confidentiality and limits access to persons for whom access is necessary. Processor is a sole proprietorship; access to personal data is in principle limited to the owner and, where necessary, to Sub-processors under the conditions of Chapter 6.
5. Security
- Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 GDPR). The measures are set out in Annex B. Processor may adjust the measures provided the level of security does not decrease.
- Controller assesses for itself whether the measures in Annex B are appropriate for the data it processes. For special categories of personal data (Article 9 GDPR) or large-scale processing, Controller consults Processor beforehand about any additional measures.
- Controller is responsible for the security of the components it manages itself, such as its users' login details and the Content, plug-ins or customisations it adds.
6. Sub-processors
- Controller gives Processor general authorisation to engage Sub-processors. The Sub-processors engaged at the time of entering into this agreement are listed in Annex C.
- Processor informs Controller at least 30 days before engaging a new Sub-processor or replacing an existing one, by e-mail and in the Panel. Controller may object with reasons within that period. If the parties do not reach a solution, Controller may terminate the Agreement for the part concerned as of the date on which the change takes effect, without notice period and with a pro rata refund of amounts paid in advance.
- Processor imposes In Writing on every Sub-processor the same obligations as in this agreement, in particular appropriate security measures, and remains fully liable towards Controller for the Sub-processor's performance.
7. Assistance with data subject rights
- Processor forwards requests from data subjects (access, rectification, erasure, restriction, portability, objection) that reach it directly to Controller within 5 working days and does not answer them substantively itself, other than by referring to Controller.
- Taking into account the nature of the processing, Processor provides reasonable assistance so that Controller can respond to data subject requests within the statutory time limits, for example by exporting or deleting data. Assistance that structurally requires more than two hours per month may be charged by Processor at the applicable hourly rate.
8. Personal data breaches
- Processor notifies Controller of a personal data breach that (potentially) affects Controller's data without undue delay and no later than 48 hours after becoming aware of it, by e-mail to the contact address specified in the Panel, and in the Panel.
- The notification contains, insofar as known: the nature of the breach, the (categories of) data subjects and data, the likely consequences, the measures taken and proposed, and a point of contact. Information not yet available is provided in phases as it becomes available.
- Processor provides reasonable assistance with notifying the breach to the Dutch Data Protection Authority (within 72 hours) and to data subjects, with carrying out data protection impact assessments and with prior consultation (Articles 33 to 36 GDPR). Processor does not itself notify the breach to the supervisory authority or to data subjects on Controller's behalf unless Controller requests this In Writing.
9. Transfers outside the EEA
Processor processes the personal data exclusively within the European Economic Area. Transfer to a country outside the EEA takes place only on Controller's prior Written instruction, and only with an appropriate instrument under Chapter V GDPR (adequacy decision or standard contractual clauses, with supplementary measures where necessary).
10. Audit and accountability
- Processor makes available all information necessary to demonstrate compliance with the obligations of Article 28 GDPR, including a description of the security measures (Annex B), the list of Sub-processors and the results of internal checks.
- Controller may, after a Written request and with 30 days' notice, have an audit carried out at most once a year (and additionally after a breach or at the request of a supervisory authority) by itself or by an independent auditor bound by confidentiality. The parties coordinate the scope and timing so that the service to other clients is not disrupted. Processor first answers Written questions; an on-site inspection takes place only if the Written information is reasonably insufficient. The costs of the audit are borne by Controller unless the audit reveals material shortcomings.
- Processor cooperates with investigations by the Dutch Data Protection Authority and informs Controller of this unless legally prohibited.
11. End of the processing
- After the end of the Agreement, Processor keeps the personal data for 30 days so that Controller can receive a complete export (files and database in a common, machine-readable format, free of charge on request). During that period Controller chooses return, deletion or both.
- After that period Processor deletes all personal data, including copies and backups (the latter no later than 35 days after the end of the retention period, according to the backup rotation), unless EU or Dutch law requires storage. On request, Processor confirms the deletion In Writing.
- Data that Processor keeps as an independent controller (such as invoices, contracts and acceptances relating to the Client itself) is governed by the Privacy Statement (https://starcore.dev/privacy), not by this Chapter.
12. Liability and indemnity
- Article 17 of the General Terms and Conditions applies to the parties' liability, on the understanding that the limitations do not apply insofar as Article 82 GDPR mandatorily provides otherwise.
- Controller indemnifies Processor against claims from data subjects and fines from supervisory authorities arising from processing for which Controller had no valid legal basis or from unlawful instructions.
13. Term, precedence and changes
- This Data Processing Agreement lasts as long as Processor processes personal data for Controller, including the retention period in Chapter 11.
- In the event of conflict between this Data Processing Agreement and the General Terms and Conditions or the Agreement, this Data Processing Agreement prevails where the processing of personal data is concerned.
- Changes follow Article 20 of the General Terms and Conditions. Changes required by amended legislation or guidance from supervisory authorities may take effect immediately.
- This Data Processing Agreement is governed by Dutch law.
Annex A – Description of the processing
| Item | Description |
|---|---|
| Subject matter | Hosting, maintenance, security, backup, monitoring and support of the Client Website; management of the domain name and SSL certificate; e-mail services where agreed |
| Duration | The term of the Agreement plus the 30-day retention period |
| Nature | Storing, hosting, displaying, backing up, restoring, technical maintenance, monitoring and, on instruction, exporting or deleting |
| Purpose | Keeping the Client Website available and functioning |
| Types of personal data | Depending on the Client Website, usually: contact details of visitors and customers (name, e-mail, phone, address), account details of users, content of forms and messages, order and booking data, technical data (IP address, browser, log files), and any other data Controller collects through its Website |
| Categories of data subjects | Visitors of the Client Website, customers and prospects of Controller, users with an account, employees of Controller |
| Special categories | Not intended. If Controller nevertheless processes these (for example health data on a practice website), it informs Processor beforehand (Chapter 5(2)) |
Annex B – Technical and organisational measures
- Access control: mandatory two-factor authentication for all administration and client accounts; role-based authorisation; segregation of client data at application and database level (row-level security); administrative access to servers exclusively with SSH keys, no password login, no remote root login.
- Encryption: TLS 1.2 or higher for all traffic (HSTS); encrypted storage of secrets and access credentials in the database; encrypted backups; encrypted disks at the storage supplier.
- Network and system security: firewall with only the required ports; automatic security updates of the operating system; isolated containers per service; limitation of login attempts and automatic lockout; security headers (CSP, HSTS, Permissions-Policy) on the web applications.
- Logging and monitoring: logging of security events (logins, failed attempts, changes of permissions) with a retention period of 12 months; availability monitoring every 5 minutes; alerts on anomalies.
- Backup and continuity: daily encrypted backups to a location outside the production server within the EEA; retention period 30 days; recovery tested at least once per quarter; recovery procedure documented.
- Development and change management: version control; automated tests and static analysis before deployment; separation of development, test and production environments; no production data in development environments (anonymised data only).
- Organisational: documented breach procedure; confidentiality; data minimisation in the software developed in-house; periodic review of the measures; data processing agreements with all Sub-processors.
- Physical security: the infrastructure runs in professional data centres of the Sub-processors in Annex C, with access control, fire protection and redundant power and network facilities.
Annex C – Sub-processors
| Sub-processor | Registered office | Processing location | Service |
|---|---|---|---|
| netcup GmbH | Karlsruhe, Germany | Germany (EU) | Virtual servers running the hosted websites, the panel and the database |
| Hetzner Online GmbH | Gunzenhausen, Germany | Germany / Finland (EU) | Object storage for files and encrypted backups outside the production server |
| TransIP B.V. | Leiden, Netherlands | Netherlands (EU) | E-mail sending from the application and, where agreed, e-mail and domain services |
This list is also available at https://starcore.dev/dpa; changes are announced in accordance with Chapter 6.
Write to us: info@starostkaweb.com