# Data processing agreement.

> The data processing agreement under article 28 GDPR between Dienox B.V. and its customers.

Source: https://dienox.com/data-processing-agreement  
Last updated: 2026-09-24

Last updated 24 September 2026 · Dienox B.V.

This data processing agreement (“DPA”) forms part of the [terms of service](https://dienox.com/terms) and applies automatically whenever Dienox B.V. processes personal data on behalf of a customer. Need a signed copy for your records? Write to [legal@dienox.com](mailto:legal@dienox.com).

## 1\. Parties and scope

The customer that uses the Dienox platform is the controller (“Customer”). Dienox B.V., Europalaan 400, 3526 KS Utrecht is the processor (“Dienox”). This DPA covers the personal data in Customer Content, as defined in the terms, that Dienox processes to provide the platform. Words defined in the General Data Protection Regulation (“GDPR”) have the same meaning here.

## 2\. Subject and duration

Dienox processes personal data only to provide the platform to the Customer, as described in the annex below, for as long as the Customer uses it, and afterwards only as long as needed to delete or return it under article 10.

## 3\. Instructions

Dienox processes personal data only on documented instructions of the Customer. The terms, this DPA and the Customer’s use and configuration of the platform are those instructions. Dienox does not process the data for its own purposes and does not use it to train AI models. If Dienox is required by law to process it otherwise, it informs the Customer beforehand unless the law forbids that. Dienox tells the Customer if it believes an instruction infringes the GDPR.

## 4\. Confidentiality

Everyone at Dienox with access to the personal data is bound to confidentiality, and has access only as far as their work requires.

## 5\. Security

Dienox takes appropriate technical and organisational measures under article 32 GDPR, including:

- encryption of all connections, and passwords stored only as secure hashes;
- strict separation between organisations: every request and every connection belongs to exactly one;
- permissions per role and per action, with short-lived, revocable access for AI tools;
- a complete, undoable history of every change to a knowledge base;
- hosting in the Netherlands, with daily backups;
- staff access to the admin console only with a fresh password confirmation, and logged;
- rate limits, security headers and dependency updates to protect against misuse.

More is on our [security page](https://dienox.com/security). Dienox may improve these measures, never lower their overall level.

## 6\. Subprocessors

The Customer gives general authorisation for Dienox to engage the following subprocessors:

| Company | What it does for us | Where |
| --- | --- | --- |
| DigitalOcean, LLC | Hosting of the platform, its database and its backups | Amsterdam, the Netherlands |
| Cloudflare, Inc. | Domain name service, encryption in transit and protection against attacks for dienox.com | Global network, EU and US |
| Laravel Holdings, Inc. (Laravel Forge) | Server management and deployment | United States |
| Resend, Inc. | Sending the platform’s emails: invitations, password resets, confirmations | United States |
| Anthropic, PBC | The AI model behind agents, jobs and imports that run on the platform itself | United States |
| Google LLC (Google Workspace) | Our own email on dienox.com, when you write to us | EU and United States |

Dienox binds each subprocessor to obligations no less protective than this DPA, and remains responsible for them. Dienox announces a new or replaced subprocessor by email to the Customer’s administrators at least 30 days in advance. The Customer may object on reasonable grounds within that period; if we cannot resolve the objection together, the Customer may end the agreement before the change takes effect.

## 7\. Transfers

Customer Content is stored in the Netherlands. Where a subprocessor processes personal data outside the European Economic Area, Dienox ensures a valid transfer mechanism: an adequacy decision such as the EU-US Data Privacy Framework, or the Standard Contractual Clauses with supplementary measures where needed.

## 8\. Assistance

Dienox helps the Customer, as far as reasonably possible, to answer requests from data subjects, and with data protection impact assessments and prior consultations. Most requests the Customer can handle itself on the platform: every file can be read, changed, deleted and exported there. If a data subject contacts Dienox directly about Customer Content, Dienox forwards the request to the Customer.

## 9\. Personal data breaches

Dienox informs the Customer without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting Customer Content. The notice describes what happened, the data and people likely affected, the likely consequences and the measures taken, as far as known at the time, and is completed as more becomes known. Dienox takes the measures needed to limit the consequences.

## 10\. Deletion and return

The Customer can export its Customer Content at any time. When the agreement ends, Dienox keeps it available for export for 30 days, then deletes it, including copies, within a further 60 days, except where the law requires Dienox to keep it. Backups rotate out on their own schedule and are not restored in the meantime.

## 11\. Audits

Dienox makes available the information needed to demonstrate compliance with this DPA. The Customer may have an audit carried out, at its own cost, by an independent auditor bound to confidentiality, at most once a year and with at least 30 days’ notice, unless a breach gives reason for more. The parties agree the scope together so the audit does not disrupt the platform or put other customers’ data at risk.

## 12\. Liability and precedence

The limitation of liability in the terms applies to this DPA. Where this DPA and the terms differ on the processing of personal data, this DPA prevails. It is governed by Dutch law.

## Annex: processing details

|  |  |
| --- | --- |
| **Nature and purpose** | Storing, organising, searching and presenting the Customer’s knowledge base; providing it to AI tools the Customer connects; running the agents and jobs the Customer sets up, including with AI models; keeping its history and backups. |
| **Types of personal data** | Whatever the Customer puts in its knowledge base, typically names, roles, contact details and work-related information about people, and the names and email addresses of its Users. |
| **Data subjects** | The Customer’s Users, employees, customers, suppliers and other contacts named in Customer Content. |
| **Special categories** | Not intended. The Customer does not put special categories of personal data on the platform unless agreed in writing. |
| **Duration** | As long as the Customer uses the platform, plus the deletion period in article 10. |
