This Data Processing Agreement (Article 28 GDPR) forms an integral part of the agreement between Ubicuto — a trading name of Maasbach Finance & Audit B.V. — (processor) and the customer (controller) and governs the processing of personal data contained in the administration data. A signed copy is available on request via privacy@ubicuto.com.
Subject matter and duration
We process personal data solely to provide the accounting service as described in the agreement, for the duration of that agreement. Categories of data subjects: the customer's buyers, suppliers and staff. Categories of data: names and addresses, order data, VAT numbers, bank and payment data.
Instructions
We process only on the customer's documented instructions, including the configuration made in the software. If we consider an instruction to infringe the GDPR, we notify the customer without delay.
Confidentiality and security
Persons with access to personal data are bound by confidentiality. We implement appropriate technical and organisational measures; the current overview is published in our Security Policy and includes encryption in transit and at rest, tenant isolation at database level and two-factor authentication.
Subprocessors
The customer grants general authorisation for the subprocessors on the published list. We announce changes at least 30 days in advance by email; the customer may object on reasonable grounds. We impose on subprocessors the same obligations as set out in this agreement.
Assistance
We assist the customer with data subject requests, data protection impact assessments and contacts with supervisory authorities. We notify the customer of a personal data breach without undue delay after becoming aware of it, providing the information needed for the customer's notification duties.
Audit
We make available the information necessary to demonstrate compliance and allow audits by or on behalf of the customer, at most once per year, upon reasonable notice and against reimbursement of reasonable costs.
Return and deletion
Upon termination the customer can export all data, including the audit file and source documents. We then delete all personal data within 30 days, unless we are subject to a statutory retention obligation.
Transfers
Processing takes place exclusively within the EEA. No transfers to third countries occur without the customer's prior written instruction and a valid transfer mechanism.