Data Processing Agreement
Last updated: August 2026 · Version 2026.08.1
1. Parties
DeskCare / Len Buckens (processor) and the customer (controller).
2. Scope
This agreement applies when DeskCare processes personal data for the customer in connection with websites, webshops, automation, dashboards, portals, custom software, IT support, maintenance, hosting or migration support.
3. Roles and customer obligations
The customer is the controller and remains responsible for relations with data subjects. The customer determines the purposes and means, ensures a valid legal basis and transparency, handles data-subject requests and provides lawful and complete instructions. DeskCare is the processor and does not independently determine the legal basis or purpose of customer processing.
4. Subject matter, nature and purpose
Performance of the assignment, technical support, maintenance, migration, monitoring and reporting.
5. Types of personal data
Contact and customer-service data, project and system data, technical logs, error messages, account, order and warranty information, and credentials where required for the assignment.
6. Categories of data subjects
Customers, end users, employees, suppliers or other people whose data the customer provides.
7. Duration
Processing continues for the assignment term. At the end, the choice and deletion duty in section 14 apply unless Union or Belgian law requires retention.
8. Documented instructions
DeskCare processes personal data only on documented instructions in the proposal, scope, email agreement or support assignment, including instructions concerning transfers outside the EU/EEA. Where Union or Belgian law requires processing without those instructions, DeskCare informs the customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. DeskCare immediately informs the customer if an instruction appears to infringe the GDPR or other applicable Union or Belgian data-protection law.
9. Confidentiality
People authorised to process personal data under DeskCare's authority are contractually or legally bound to confidentiality and receive access only where needed for the assignment.
10. Security
Taking account of the risks, DeskCare applies appropriate technical and organisational measures under Article 32 GDPR, including least-privilege access, data minimisation, secure password management and 2FA where available, temporary access, scoped updates and patches, secure transfer, logging where available and orderly access removal.
11. Sub-processors
The customer gives general written authorisation for the sub-processors named in the completed project appendix. DeskCare gives at least 30 calendar days' prior written notice of a proposed addition or replacement, including its name, location, service and applicable transfer mechanism.
The customer may object within that period on reasonable data-protection grounds. The parties then seek a reasonable alternative; if none is available, the affected service may be terminated. DeskCare imposes the same data-protection obligations on each sub-processor and remains fully liable to the customer for its performance.
12. International transfers
Personal data is not transferred outside the EU/EEA without a valid mechanism such as an adequacy decision, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses or another appropriate safeguard.
13. Assistance, rights and personal-data breaches
Taking account of the nature of processing and available information, DeskCare assists the customer with data-subject requests and compliance with Articles 32 to 36 GDPR, including security, breach notifications, data protection impact assessments and prior consultation.
DeskCare reports a personal-data breach without undue delay after becoming aware of it and, as information becomes available, provides its nature, affected categories and approximate numbers, a contact point, likely consequences and measures taken or proposed. Reasonable out-of-scope assistance costs require prior agreement and are not charged when the assistance is required because of DeskCare's breach.
14. Return or deletion
At the end of processing services, DeskCare, at the customer's choice, deletes all personal data or returns it to the customer. In both cases DeskCare deletes the remaining copies. Where Union or Belgian law requires retention, the affected data remains isolated for the legally required period.
15. Information and audits
DeskCare makes available all information needed to demonstrate Article 28 compliance and allows and contributes to audits and inspections by the customer or its independent auditor. The parties minimise disruption and protect confidential information. Reasonable costs for additional audits may be agreed in advance, but cannot block a legally required audit and are not charged where DeskCare's breach prompted the audit.
16. Liability
Each party is liable for its own failures within the applicable legal framework.
17. Precedence
This agreement prevails over conflicting contract documents, subject to mandatory law.
18. Contact
Questions: hello@deskcare.be.
Appendix 1 — Processing details
| Item | Description |
|---|---|
| Customer/controller | [complete] |
| Project/assignment | [complete] |
| Purpose of processing | Performance of the assignment, support, maintenance, migration, dashboards, portals, websites, webshops, automation, hardware/software installation or warranty follow-up. |
| Types of data | Contact data, account data, project data, technical logs, communications, device data, licence data, purchase or warranty data. |
| Categories of data subjects | Customers, prospects, employees, suppliers or end users. |
| Duration of processing | [complete the specific contract term and any statutory retention period] |
| Location/systems | According to the tools used, hosting, customer accounts and agreed scope. |
Appendix 2 — Security measures
- Access limited according to role and necessity
- Confidentiality obligations
- 2FA where available
- No permanent password storage
- Temporary access where feasible
- Secure file transfer
- Logging and incident records
- Removal/transfer of accounts at the end of the assignment
- Appropriately restricted handling of device, serial-number and licence data
Appendix 3 — Approved sub-processors
A dated, fixed appendix must be completed for each assignment. General categories or a changeable webpage are not a sufficient project list.
| Name | Location | Service and purpose | Transfer mechanism |
|---|---|---|---|
| [complete] | [complete] | [complete] | [EEA / adequacy / DPF / SCC / n/a] |