This data processing agreement ("DPA") is part of every agreement for the CleverPrism subscription. It supplements Chapter 4 (Processing of personal data) of the NLdigital Terms 2025 and contains the arrangements required by Article 28(3) of the General Data Protection Regulation (GDPR). If this DPA and the NLdigital Terms 2025 conflict on the processing of personal data, this DPA prevails.
1Parties and roles
- The customer is the controller: it determines the purposes and means of the processing of personal data in its CleverPrism environment.
- CleverPrism B.V. (Eindhoven, KvK 42175200) is the processor: it processes these personal data only on behalf of the customer.
- This DPA applies for as long as CleverPrism processes personal data on behalf of the customer, including the 60-day retention period after the agreement ends.
2Subject, nature and purpose
- CleverPrism provides the customer with a private AI environment: a dedicated server with sandboxes, a password vault and an artifact server. The processing consists of storing, hosting, transmitting and, on the customer's instruction, deleting the data the customer and its users put into the environment; operating, monitoring and securing the environment; and providing support.
- CleverPrism processes the personal data only for providing the service. It does not look at the content of the environment, except when necessary for support the customer has asked for, for security or to comply with the law. It does not use the data for its own purposes and does not use it to train AI models.
3Personal data and data subjects
| Type of personal data | Data subjects |
|---|---|
| Account data: names and email addresses of users who may log in, and of password vault accounts | Employees and other users appointed by the customer |
| Content: all personal data in files, projects, messages to and from AI models, generated output and stored credentials. The customer decides what this includes. | Users, and anyone whose data the customer puts into the environment, such as its customers, suppliers and contacts |
| Technical data: IP addresses, timestamps, request and error logs of the environment. Prompts and AI answers are not collected in these logs. | Users and visitors of the environment and its shared links |
- The service is not designed for special categories of personal data, criminal data or national identification numbers (Article 28.6 NLdigital Terms 2025). If the customer wants to process such data, it agrees this with CleverPrism in writing first.
4Instructions
- CleverPrism processes personal data only on the customer's documented instructions. The agreement, this DPA and the way the customer configures and uses the environment are the customer's instructions.
- If CleverPrism is required by EU or Dutch law to process personal data otherwise, it informs the customer beforehand, unless that law prohibits this.
- CleverPrism informs the customer immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.
5Confidentiality and security
- Everyone at CleverPrism and its sub-processors who has access to the personal data is bound by a duty of confidentiality.
- CleverPrism takes appropriate technical and organisational measures as referred to in Article 32 GDPR, including:
- a separate, dedicated server for every customer, in a data centre in Eindhoven, the Netherlands;
- network separation and a firewall; administrative access only with SSH keys, from a limited number of known addresses;
- encrypted connections (TLS) for all access to the environment from the internet;
- credentials kept in a separate password vault, so AI agents do not see them in plain text;
- access for staff only when needed for their work, and changes to the platform recorded in version control;
- automatic security updates, and monitoring of availability and security events;
- technical logs kept for at most 90 days.
- CleverPrism may adapt these measures, as long as the level of security does not decrease.
6Sub-processors
- The customer gives general authorisation for the use of sub-processors. CleverPrism currently uses:
| Sub-processor | Service | Location |
|---|---|---|
| CleverIT B.V., Eindhoven (Clever group) | Data centre, network, email relay and internal tooling | The Netherlands |
| Cloudflare, Inc. and its affiliates | Secure tunnels, DNS and TLS for access to the environment from the internet | Global network; transfers outside the EEA based on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses |
- CleverPrism informs the customer by email at least 30 days before it adds or replaces a sub-processor. The customer may object on reasonable grounds within that period. If the parties cannot resolve the objection, the customer may terminate the agreement with effect from the date of the change.
- CleverPrism imposes the same data protection obligations on sub-processors as in this DPA and remains responsible to the customer for them.
- Not a sub-processor: the AI provider the customer connects with its own subscription or API key (for example Anthropic or OpenAI). The customer contracts with that provider directly and is responsible for that processing, including any transfer outside the EEA.
7Assistance to the customer
- The customer can access, correct and delete the data in its environment itself. Where that is not possible, CleverPrism helps the customer respond to requests from data subjects.
- CleverPrism helps the customer with its obligations under Articles 32 to 36 GDPR, such as security, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to CleverPrism.
- CleverPrism may charge its usual rates for assistance that goes beyond what is reasonable, in line with the NLdigital Terms 2025.
8Personal data breaches
- CleverPrism informs the customer without undue delay after discovering a personal data breach that affects the customer's data. It provides the information the customer needs to decide whether to notify the supervisory authority or data subjects, as far as available: what happened, which data and how many data subjects are affected, the likely consequences and the measures taken.
- Notifying the supervisory authority and data subjects is the customer's responsibility (Article 29 NLdigital Terms 2025).
9Transfers outside the EEA
- The environment and its data are hosted in the Netherlands. CleverPrism transfers personal data outside the European Economic Area only through the sub-processors listed above, and only with appropriate safeguards as referred to in Chapter V GDPR.
10End of the processing
- After the agreement ends, or after a sandbox is removed, CleverPrism keeps the data for 60 days. During that period the customer can ask for an export of its data in a common, machine-readable format.
- After these 60 days CleverPrism deletes the personal data, including copies, in such a way that they can no longer be used or accessed, unless EU or Dutch law requires CleverPrism to keep them.
11Information and audits
- CleverPrism provides the customer, on request, with the information needed to demonstrate compliance with Article 28 GDPR.
- The customer may have compliance audited by an independent auditor bound by confidentiality, at most once a year and with at least 30 days' notice, at its own expense. CleverPrism cooperates within reason. Audits take place in a way that does not affect the security of other customers.
12Liability and other provisions
- The limitation of liability in Article 15 of the NLdigital Terms 2025 applies to this DPA.
- This DPA is governed by Dutch law. Questions about this DPA: [email protected].