Data processing agreement
The article 28 processor agreement covering personal data inside customer websites, clause by clause against the article.
Published 1.0 · 2026-09-18
Effective date: 18 September 2026
Parties. This Agreement is between the Customer ("Controller") and JKC Software B.V., Philitelaan 57, 5617 AK Eindhoven, the Netherlands, KvK 42082783 ("Processor"). It forms part of the Terms of Service and is concluded by accepting them.
1. Subject matter and roles
1.1 The Processor operates WebCrew and, in doing so, processes personal data contained in or generated by the websites the Controller connects — for example user accounts in a WordPress database inside a backup, form submissions observed during journey testing, or personal data appearing in error logs.
1.2 The Controller determines the purposes and means. The Processor processes only on the Controller's documented instructions, which are: the Terms, this DPA, the policies and approvals the Controller configures in the product, and any further instruction the Controller gives in writing through the product or to privacy@webcrew.ai. The product's audit trail is the record of instructions executed.
1.3 The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or another data-protection provision, and may suspend execution of that instruction until it is withdrawn or amended. An instruction that falls outside the service as described may be refused, or accepted against the Processor's reasonable costs.
1.4 Where an instruction requires the Processor to process personal data for its own purposes, or the Processor does so, the Processor becomes a controller for that processing and its own privacy notice applies. The Processor does not do this for the data covered by this DPA.
1.5 The Processor does not sell personal data, does not use it for its own marketing, and does not train machine-learning models on the content of connected websites.
2. Duration, nature and purpose
Processing lasts for as long as the subscription runs, plus the deletion window in Annex B. The nature of the processing is hosting-adjacent operations work: backing up, restoring, updating, monitoring, testing and reporting on websites, including the storage, retrieval, transmission, alteration and erasure such work requires. The purpose is the maintenance, protection and reporting of those websites on the Controller's instruction. This DPA ends when the Terms end, except for the obligations that survive under clause 12.
3. Categories of data and data subjects
3.1 Because the Controller's websites determine the content, categories are defined broadly:
| Data subjects | Categories of personal data |
|---|---|
| Website end users and visitors | Identification and contact data, account credentials in hashed form, order and form-submission data, IP addresses and usage data, whatever else the website stores about them |
| The Controller's clients and their staff | Identification, contact and role data |
| The Controller's own users | Identification, contact and authentication data (also covered by the Processor's own privacy notice, in its controller role) |
3.2 The Controller warrants that it has a lawful basis for the personal data its websites hold, that it has given the required information to data subjects, and that it will not use WebCrew deliberately to process special categories of personal data (article 9) or criminal-offence data (article 10) beyond what the connected websites incidentally contain. Where such data is incidentally contained, the Processor applies the measures of Annex A to it without distinction.
4. Processor obligations
The Processor will:
- process only on documented instructions, including for transfers to a third country, unless required to do otherwise by Union or Member State law, in which case it informs the Controller first unless that law forbids it (art. 28(3)(a));
- ensure that persons authorised to process personal data are bound by confidentiality, whether by contract or by statutory duty (art. 28(3)(b));
- implement and maintain the technical and organisational measures of Annex A, taking account of the state of the art, the cost of implementation, and the risk to data subjects (arts. 28(3)(c) and 32);
- respect the subprocessor conditions of clause 5 (art. 28(3)(d));
- assist the Controller with appropriate technical and organisational measures, insofar as possible, to answer data-subject requests under Chapter III (art. 28(3)(e)), per clause 6;
- assist the Controller with the obligations of articles 32 to 36 — security, breach notification, impact assessments and prior consultation — taking into account the nature of the processing and the information available (art. 28(3)(f)), per clauses 7 and 8;
- delete or return personal data at the Controller's choice at the end of the services, and delete existing copies unless law requires storage (art. 28(3)(g)), per Annex B;
- make available all information necessary to demonstrate compliance with this clause and allow and contribute to audits (art. 28(3)(h)), per clause 9;
- keep a record of the categories of processing carried out on behalf of the Controller (art. 30(2)) and make it available to a supervisory authority on request.
5. Subprocessors
5.1 The Controller grants a general written authorisation for the subprocessors listed in the Subprocessor Register (Annex C, maintained at https://webcrew.ai/legal/subprocessors).
5.2 The Processor gives at least thirty days' notice of an intended addition or replacement. The Controller may object within that period on reasonable data-protection grounds. The parties then seek a solution in good faith; if none is found, the Controller may terminate the affected part of the service with a pro rata refund of prepaid fees, as its sole remedy.
5.3 The Processor imposes on every subprocessor, by contract, data-protection obligations that are materially equivalent to those in this DPA, and remains fully liable to the Controller for the subprocessor's performance of them.
6. Data-subject requests
6.1 If a data subject approaches the Processor directly about data processed for the Controller, the Processor does not answer the substance. It forwards the request to the Controller without undue delay and no later than five business days after receipt, and tells the data subject that it has done so.
6.2 The Processor assists the Controller in answering such requests through the product's search, export and deletion functions, and where those do not suffice, with reasonable manual assistance. Assistance that goes materially beyond the product's functions may be charged at the Processor's standard rates, notified in advance.
7. Security and personal data breaches
7.1 The Processor implements the measures of Annex A and reviews them at least annually and after any material change to the service or to the risk.
7.2 The Processor notifies the Controller of a personal data breach affecting the Controller's personal data without undue delay and no later than 48 hours after becoming aware of it. The notification describes, as far as known at the time and supplemented as it becomes known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point.
7.3 The Processor does not notify a supervisory authority or data subjects on the Controller's behalf unless the Controller instructs it to in writing. It does not make a public statement identifying the Controller without the Controller's consent, unless the law requires it.
7.4 The Processor documents every breach affecting the Controller's data, including the facts, effects and remedial action, and makes that documentation available to the Controller.
8. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, the Processor gives the Controller the information the Controller reasonably needs for a data protection impact assessment under article 35 or a prior consultation under article 36. The Security Overview, Annex A and the Subprocessor Register are the standing form of that assistance; anything beyond them may be charged at the Processor's standard rates, notified in advance.
9. Audit
9.1 The Processor supports audits first through documentation: the Security Overview, Annex A, the audit trail, and third-party attestations as they become available.
9.2 Where that does not satisfy a specific, reasoned concern, the Controller or an independent auditor it appoints — who must not be a competitor of the Processor and must be bound by confidentiality — may audit at most once per calendar year, on thirty days' written notice, during business hours, in a way that does not disrupt the service, and without access to other customers' data, to the Processor's own confidential information beyond the scope, or to multi-tenant systems in a way that would expose them. Each party bears its own costs; the Controller bears the Processor's reasonable costs for assistance exceeding one working day.
9.3 A supervisory authority exercising a statutory power is not subject to the limits in 9.2.
10. International transfers
Transfers of personal data outside the EEA occur only to recipients listed in the Subprocessor Register and only with a valid transfer mechanism: an adequacy decision under article 45, including the EU–US Data Privacy Framework where the recipient is certified, or the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) with a transfer impact assessment and supplementary measures where the assessment calls for them. Where the Standard Contractual Clauses apply, Module Two (controller to processor) is incorporated into this DPA, with Annex A of this DPA as their Annex II, the Subprocessor Register as their Annex III, Dutch law as the governing law and the Dutch courts as the forum.
11. Liability and precedence
11.1 The liability clause of the Terms applies to this DPA, subject to article 82 GDPR, which allocates liability towards data subjects between controller and processor by law and cannot be varied by contract.
11.2 Where this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. On all other matters, the Terms prevail.
12. End of the agreement
12.1 On termination of the Terms, Annex B governs deletion and return.
12.2 Clauses 4 (confidentiality), 7.4 (breach documentation), 11 and this clause survive termination for as long as the Processor holds any of the Controller's personal data, and the confidentiality obligation survives indefinitely.
Annex A — Technical and organisational measures (article 32)
Stated as they exist at the version date. Items marked (planned) are on the roadmap and dated in the trust centre rather than claimed here. Measures are reviewed at least annually under clause 7.1.
Pseudonymisation and encryption (art. 32(1)(a))
- TLS for all data in transit, including connector traffic.
- Backups encrypted at rest with per-workspace keys.
- Session records stored server-side as keyed hashes, never as usable tokens.
- Secrets held in an OS keychain rather than in configuration files. (A managed key service with envelope encryption is planned.)
Confidentiality, integrity, availability and resilience (art. 32(1)(b))
- Authentication through Google, GitHub or Microsoft with PKCE; WebCrew issues its own opaque sessions and never handles provider passwords.
- Roles are organisation-scoped; tenant isolation is enforced at the session layer and in every data query.
- The approval boundary: irreversible, high-risk and client-visible actions require explicit approval, and every action is written to an append-only audit trail with actor and timestamp.
- The connector authenticates with HMAC-SHA256-signed requests and least-privilege capabilities.
- Safe updates carry their own restore point; a failed health check rolls the site back automatically.
Restoring availability after an incident (art. 32(1)(c))
- Daily encrypted backups per plan retention, restorable by the Controller from the product. (Offsite replication activates with the storage subscription; measured RPO and RTO publish to the trust centre as restore drills accumulate.)
- The Business Continuity and Restore Runbook describes the procedure and the drill cadence.
Testing and evaluating effectiveness (art. 32(1)(d))
- Contract-first API with automated test suites, end-to-end coverage, and dependency audits with reasoned exceptions.
- Secret scanning in the build; a vulnerability disclosure policy with a published contact.
- (An independent penetration test is planned before general availability.)
Organisational measures
- Everyone with access to Controller data is bound by confidentiality in writing, and the list of who has access is short and reviewed.
- Individual named accounts, no shared credentials, access granted on need and withdrawn when the need ends. (A formal joiner–mover–leaver checklist is planned with the ISMS work.)
- Subprocessors are engaged only under article 28 terms and are listed in the register.
- The Incident Response Plan defines detection, classification, the 48-hour notification path and the post-incident review.
Annex B — Deletion and return
- Before termination takes effect, the Controller can export reports, evidence and backups through the product's export functions.
- At the Controller's choice, made in writing before termination, the Processor returns the personal data in a structured, commonly used, machine-readable format, or deletes it. Absent a choice, the Processor deletes.
- 30 days after termination, personal data and backups are deleted from active systems.
- Deletion from rotated backup media completes within the following 4-weekly backup cycle; until then the data remains encrypted, is not processed for any purpose, and remains subject to this DPA.
- The Processor retains audit and billing records where law requires it, for no longer than the law requires, and processes them for no other purpose.
- The Processor confirms deletion in writing on request.
Annex C — Subprocessor Register
Maintained as a standalone document (see the Subprocessor Register), whose contents as of this draft's date are incorporated here by reference. Changes follow clause 5.2.