This Data Processing Agreement (hereinafter: DPA) forms an integral part of the agreement between aiwerkers B.V. (trading as ai-werkers, having its registered office in Utrecht, the Netherlands, registered with the Dutch Chamber of Commerce under number 42114106, RSIN 869793627; the Processor) and the customer signing up for Vera (the Controller). By signing up you explicitly accept this DPA.
1. Definitions
- GDPR: Regulation (EU) 2016/679.
- Personal Data: any information relating to an identified or identifiable natural person.
- Processing: any operation on Personal Data as defined in Article 4(2) GDPR.
- Vera: the scheduling service provided by Processor via hallovera.nl.
2. Subject and purpose
Processor processes Personal Data solely for the provision of Vera: classifying inbound emails, drafting reply emails, booking meetings in the Controller's calendar, and related functionality. Processor never uses Personal Data for its own marketing, profiling, or AI model training.
3. Categories of data subjects and data
- Data subjects: Controller's employees who use Vera, and the contacts (customers/leads) Vera communicates with via the opt-in CC flow.
- Categories of Personal Data: name, email address, timezone, working hours, email content (encrypted at rest), meeting times, optionally phone number or location if contained in email text.
4. Processor responsibilities
- Process Personal Data only on documented instructions from Controller and in line with this DPA.
- Ensure persons authorised to process Personal Data have committed to confidentiality.
- Implement appropriate technical and organisational measures, see section 6.
- Maintain a record of processing activities per Article 30(2) GDPR.
- Provide reasonable assistance to Controller in handling data subject requests.
5. Sub-processors
Controller grants Processor general authorisation to engage the following sub-processors:
- Railway (US, EU region Frankfurt) — application and database hosting.
- Brevo (France, EU) — inbound and outbound email.
- Mistral AI (France, EU) — LLM classifier and drafter.
- Mollie (Amsterdam, NL) — billing and payments.
- Google — only when Controller connects their own Google Calendar; Processor acts on Controller's behalf via the Google Calendar API.
Changes to sub-processors will be announced at least 14 days in advance by email and/or dashboard banner, with the right to object.
6. Security measures
- EU data centres (Frankfurt).
- Encryption at rest with AES-256-GCM, TLS 1.3 in transit.
- Envelope encryption: one master key (KEK) wraps a per-tenant data key (DEK).
- HTTPS-only, HSTS, httpOnly + SameSite cookies.
- MFA mandatory for production accounts on Processor's side.
- Audit-trail logging, staff access on need-to-know basis.
- Regular backups, key rotation, periodic security reviews.
7. Data breach notification
Processor notifies Controller in writing of any Personal Data breach affecting Controller's data as soon as possible and in any case within 48 hours of discovery. The notification covers at minimum the nature of the breach, the categories of Personal Data affected, mitigations taken, and a contact point for follow-up.
8. Assistance with data subject rights
Processor provides Controller with reasonable assistance in handling data subject requests for access, rectification, restriction, portability or erasure. For many such rights Controller can use the Vera dashboard directly (delete account, export data).
9. Audit rights
Controller may, at its own cost, conduct (or have conducted) an audit of Processor's compliance with this DPA, up to once per year — or more often given a credible indication of a breach. Processor cooperates reasonably and may require at least 30 days' prior notice.
10. International transfers
Personal Data is transferred outside the EEA only under a valid Article 46 GDPR mechanism (typically Standard Contractual Clauses). None of the sub-processors in section 5 routinely transfer data out of the EEA; for those with a non-EU parent (Railway, Google), actual data storage remains in the EU.
11. Retention
- Account data: up to 30 days after cancellation.
- Email content and threads: 90-day rolling, unless Controller chooses otherwise.
- Audit log: 12 months, then aggregated.
- Billing data: 7 years (legal tax retention).
12. Termination
On termination of the main agreement Processor deletes all Personal Data within 30 days, unless legally required otherwise. During those 30 days Controller may request an export via privacy@ai-werkers.nl.
13. Liability
Liability for damages arising under this DPA follows the main agreement and statutory GDPR rules. Processor is not liable for damages resulting from Controller instructions that do not comply with the GDPR.
14. Governing law and jurisdiction
This DPA is governed by Dutch law. Disputes will be brought before the competent court in the district where Processor is established.
Contact
Questions about this DPA? privacy@ai-werkers.nl. We respond within 48 hours on business days.
Material changes to this DPA will be announced at least 14 days in advance.