Home › Data processing agreement
Data processing agreement
Administering an ITSM environment inevitably brings us into contact with personal data. Every management contract therefore includes a data processing agreement under Article 28 GDPR. This is our standard version — so your procurement or privacy officer can read it in advance instead of waiting for it.
Version 1.0, effective 31 August 2026. In case of any discrepancy, the Dutch version prevails.
Have your own template? That is fine.
If your organisation works with its own template or a sector template — for example from Z-CERT, the VNG or the Dutch central government — we will sign that, provided it is workable for a remote administration partner. We would rather start from your template than from ours.
1. Parties and roles
The client is the controller: the client determines which personal data is recorded in the ITSM environment and for what purpose. Van Croonenburg IT-Consultancy B.V., trading as VCITC, is the processor and processes solely on instruction and in accordance with written instructions.
This agreement is inseparably connected to the underlying management contract and runs for as long as it does.
2. Subject matter, nature and purpose
Processing takes place in the context of functional and application management of the client's ITSM environment: configuring, changing, automating, testing, supporting and reporting on it. No processing takes place for the processor's own purposes.
3. Which data and whose
| Category of data subject | Data |
|---|---|
| Reporters and end users | Name, email address, telephone number, department, location, ticket content and attachments |
| Agents and administrators | Name, email address, role, permissions and roles, log of actions performed |
| Supplier contacts | Name, business email address, telephone number |
| Asset users | Name and link to assigned equipment or licences |
Special categories of personal data are not processed deliberately. Where they occur incidentally in the content of a ticket — in a healthcare environment, for instance — we treat them with the same confidentiality and flag it where the nature of the environment gives cause.
4. Instruction-bound processing
The processor processes solely on the basis of written instructions, including this agreement and the management contract. If the processor considers an instruction to be in breach of the GDPR, it reports this immediately and may suspend performance.
5. Security measures
- Access solely through personal, named accounts with two-factor authentication; never through shared administrator accounts, so the client's logging continues to show who did what.
- Access limited to what is necessary for the assignment, and revoked as soon as that necessity ends.
- Work takes place inside the client's environment; no data is exported to the processor's systems unless agreed in writing beforehand.
- Equipment has full-disk encryption, automatic locking and current updates.
- Connections are encrypted; no use of unsecured networks without a VPN.
- Confidentiality applies to everyone with access on behalf of the processor, including afterwards.
6. Sub-processors
The processor engages no sub-processors for the processing of data from the client's environment unless written consent has been obtained in advance. Where a sub-processor is engaged, the processor imposes the same obligations on it and remains fully liable.
If the client also uses AureaDesk, hosting for that is a separate service with its own annex, in which the hosting party involved and the location of the data are named explicitly.
7. Transfers outside the EEA
No transfer takes place to countries outside the European Economic Area. Should that become necessary in future, it will happen only after prior written consent and on the basis of a valid transfer mechanism.
8. Personal data breaches
The processor informs the client without undue delay and no later than within 24 hours of becoming aware of a personal data breach, with all information the client needs to assess its own notification obligation. The processor does not notify the Data Protection Authority itself; that is for the client.
9. Rights of data subjects
If the processor receives a request directly from a data subject, it refers that person to the client and informs the client. The processor provides reasonable assistance in handling requests for access, rectification, erasure and portability.
10. Audit and accountability
The client may verify compliance with this agreement once a year, and additionally following a data breach. This takes place after thirty days' notice, during office hours, by the client or by an independent auditor bound by confidentiality. The cost of the audit is borne by the client, unless material shortcomings are established.
11. Termination
On termination of the management contract, all of the processor's access rights are revoked by the client. Any copies of data held outside the client's environment with consent are deleted or returned within thirty days, at the client's choice, with written confirmation.
Documentation of the configuration remains in the client's environment and is explained free of charge during handover.
12. Liability and governing law
This agreement is governed by Dutch law and the court of Gelderland has jurisdiction. The liability provisions of the terms and conditions apply accordingly, on the understanding that statutory liability under the GDPR is not thereby limited where such limitation is not permitted.
A signed copy
Feel free to request a signed copy at info@vcitc.nl. When a management contract is concluded we send it as a matter of course, together with the annex naming the specific environment and the systems involved.