Data Processing Agreement
Version 1.6 September 2026
This data processing agreement is part of the agreement between Pluvo B.V. (“Processor”) and the customer (“Controller”), and will take effect on the date you accept this data processing agreement. You warrant that you are authorized to enter into this data processing agreement. If you do not have this authority, we request that you do not accept this agreement.”
The Parties take the following into consideration:
- The Controller is active in the field of training/education and makes use of the Processor in that context;
- The Processor provides the Service to the Controller as described in the Agreement, and in that capacity processes (special) personal data for the Controller;
- The Controller is to be regarded as a controller within the meaning of Article 4(7) of the General Data Protection Regulation (“GDPR”) with regard to the processing of personal data;
- The Parties wish – partly to implement the provisions of Article 28(3) of the GDPR – to set out in this Data Processing Agreement a number of conditions that apply to their relationship regarding the processing of personal data in the context of the aforementioned activities for and on behalf of the Controller.
- The Processor is to be regarded as a processor within the meaning of Article 4(8) of the GDPR with regard to the storage and processing of personal data for the Controller;
Agree as follows:
Article 1. Definitions
- In this Data Processing Agreement, the following terms, always capitalized, have the following meanings, regardless of whether they are used in the plural or singular:
Annex: appendix to the Data Processing Agreement, which forms an integral part of the Data Processing Agreement.
Agreement: the Pluvo Customer Contract concluded between the Controller and the Processor;
Personal data: all data that can be directly or indirectly traced back to a natural person as referred to in Article 4(1) of the GDPR;
Sub-processor: the subcontractor engaged by the Processor, who processes Personal Data in the context of this Data Processing Agreement on behalf of the Controller as referred to in Article 28(4) of the GDPR;
Processing: the processing of Personal Data as referred to in Article 4(2) of the GDPR;
Data Processing Agreement: this agreement, which forms part of the Agreement. - The provisions of the Agreement apply in full to the Data Processing Agreement. To the extent that the Agreement contains provisions regarding the processing of personal data, the provisions of this Data Processing Agreement shall prevail.
Article 2. Data Controller and Data Processor
- In the context of this Data Processing Agreement, the Processor undertakes to process Personal Data on behalf of the Controller. An overview of the types of Personal Data, the categories of data subjects, and the purposes for which the processing of Personal Data takes place is included in Annex 1.
- The Controller is liable for the processing of Personal Data in the context of the Agreement and guarantees that the instruction to process such Personal Data is in accordance with all applicable laws and regulations. The Controller indemnifies the Processor against all third-party claims, in particular those from the supervisory authority, which arise in any way from non-compliance with this guarantee.
- Processor processes the Personal Data solely on the basis of documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation. This Processor Agreement, the Agreement and its Annexes constitute the Controller’s documented instructions; any further instruction shall be given in writing.
Processor guarantees that, without the express written consent of the Controller, it will not make use of the Personal Data Processed under this Processor Agreement, unless a legal provision applicable to the Processor requires it to process. In that case, the Processor will inform the Controller of that legal requirement prior to Processing, unless that law prohibits such notice for important reasons of public interest. - Free-text input fields and special categories of personal data
- The Processor processes data entered via free-text input fields solely for the purpose of technically providing, hosting, storing, securing, backing up, and deleting that data. The Processor does not perform any substantive assessment or active review of the content entered via free-text input fields.
- Unless expressly agreed upon in writing, the Controller is not permitted to process special categories of personal data within the meaning of Article 9 of the GDPR or a national identification number (BSN) via free-text input fields. If the Controller does so, they must ensure a valid legal basis and appropriate additional safeguards, and must notify the Processor of this in writing in advance.
- Data that is temporarily stored in the context of system tasks (such as audit, export, or deletion procedures) is kept encrypted, logged, and automatically deleted upon completion of the task in accordance with Annex 2.
- The Processor facilitates configurations and UI alerts that notify the Controller of the prohibition or conditions regarding the entry of special categories of personal data via free-text fields.
- The Processor contractually imposes these obligations on any Sub-processors that have access to this data.
Article 3. Technical and organizational measures
- Taking into account the nature of the processing and as far as reasonably possible, the Processor shall assist the Controller in fulfilling its obligation under the GDPR to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures shall, taking into account the state of the art and the costs of implementation, ensure an appropriate level of security, having regard to the risks associated with the Processing and the nature of the data to be protected. In any event, the Processor shall take measures to protect Personal Data against accidental or unlawful destruction, accidental or intentional loss, alteration, unauthorized disclosure or access, or any other form of unlawful Processing.
- The technical and organizational measures taken by the Processor are described in Annex 2. The Controller acknowledges having taken note of these measures and, by signing this Data Processing Agreement, agrees to the measures taken by the Processor.
Article 4. Confidentiality
- The Processor shall require its employees involved in the execution of the Agreement to sign a confidentiality agreement—whether or not included in their employment contract—which states at a minimum that these employees must maintain confidentiality regarding the Personal Data.
Article 5. Data processing outside the Netherlands
- The transfer of Personal Data by the Processor outside the European Economic Area is only permitted in compliance with Chapter V of the GDPR.
Article 6. Third parties and subcontractors
- The Processor is permitted to use Sub-processors in the context of this Data Processing Agreement and the Agreement, as listed in Annex 3. If the Processor wishes to engage a different Sub-processor, the Processor shall inform the Controller of the intended changes. The Controller must object to these changes within 5 working days. The Processor shall respond to the Controller's objection within 4 working days.
- The Processor shall contractually oblige every Sub-processor to comply with the confidentiality obligations, notification obligations, and security measures regarding the Processing of Personal Data, which obligations and measures must at a minimum comply with the provisions of this Data Processing Agreement.
Article 7. Liability
- Regarding the Processor's liability under this Data Processing Agreement, as well as the indemnification obligations for the Processor included herein, the provisions on limitation of liability set out in Article 9 of the Agreement (among others) shall apply in full.
- Without prejudice to Article 7.1 of this Data Processing Agreement, the Processor is only liable for damage caused by the Processing if the Processor has failed to comply with obligations specifically directed at the Processor under the GDPR or if it has acted in breach of the Controller's lawful instructions.
Article 8. Incidents
- If the Processor becomes aware of an incident that may have a (material) impact on the security of Personal Data, it shall i) notify the Controller without undue delay and ii) take all reasonable measures to prevent or limit (further) violation of the GDPR.
- The Processor shall, to the extent reasonable, cooperate with and support the Controller in carrying out its legal obligations regarding the identified incident.
- The Processor shall, to the extent reasonable, support the Controller with the Controller's obligation to notify the supervisory authority (“AP”) and/or the data subject of a personal data breach, as referred to in Article 33(3) and Article 34(1) of the GDPR. The Processor is never required to independently notify the AP and/or the data subject of a personal data breach.
- The Processor is never liable for the (correct and/or timely execution of the) notification obligation incumbent upon the Controller as referred to in Articles 33 and 34 of the GDPR.
Article 9. Assistance to the Controller
- The Processor shall, to the extent reasonably possible, assist the Controller in fulfilling its obligation under the GDPR to respond to requests for exercising the data subject's rights, in particular the right of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), portability (Article 20 GDPR), and the right to object (Articles 21 and 22 GDPR). The Processor shall forward any complaint or request from a data subject regarding the Processing of Personal Data to the Controller as soon as possible, as the Controller is responsible for handling such requests. The Processor is entitled to charge the Controller for any costs associated with this assistance.
- The Processor shall, to the extent reasonably possible, assist the Controller in fulfilling its obligation under the GDPR to carry out a data protection impact assessment (Articles 35 and 36 GDPR).
- The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the Processor's obligations under the GDPR. Furthermore, the Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, upon the Controller's request. If the Processor believes that an instruction regarding the provisions of this article infringes the GDPR or other applicable data protection laws, the Processor shall immediately inform the Controller.
- The Processor is entitled to charge the Controller for any costs associated with the provisions of Article 9.3.
Article 10. Termination & Miscellaneous
- Regarding the termination and/or dissolution of this Data Processing Agreement, the specific provisions of the Agreement shall apply. Without prejudice to the specific provisions of the Agreement, the Processor shall, at the first request of the Controller, delete or return all Personal Data to them and delete existing copies, unless the Processor is legally required to continue storing (parts of) the Personal Data.
- The Controller shall adequately inform the Processor of any (legal) retention periods applicable to the Processor's processing of Personal Data.
- The Controller declares that they are authorized to enter into this Data Processing Agreement.
- The obligations under this Data Processing Agreement that are intended by their nature to survive termination shall remain in effect after the termination of this Data Processing Agreement.
- The choice of law and competent court are in accordance with the provisions of the Agreement.
- This Data Processing Agreement is published in Dutch, English and German. In the event of any discrepancy between the language versions, the Dutch text prevails; the English and German texts are translations provided for information purposes.
----------------------------
Annex 1. Overview of Personal Data
Type of personal data
The following categories of personal data may be processed by the Processor on behalf of the Controller:
- Basic Identification Information: Name, Email address, Profile picture
- Custom User Fields: Fields added by the Controller, specifically for their operational needs.
- Educational Data: Progress in course material, scores, and results of evaluations and tests
The Controller retains the autonomy to determine which personal data is processed via the Processor's software. This includes both basic identification information and specific custom fields relevant to their purposes.
Free-text fields – scope and limitations
Free-text fields can be configured by the Controller.
The Controller shall ensure that no special categories of personal data (Article 9 GDPR) or BSN (Citizen Service Number) are processed via these fields, unless a valid legal basis and additional safeguards exist and the Processor has been notified of this in advance.
In all cases, purpose limitation, data minimization, and the retention and deletion periods established in this Data Processing Agreement remain fully applicable.
Dynamic nature of data
Given the ability for the Controller to add custom fields, there is an inherently dynamic aspect to the types of personal data processed.
The Processor facilitates transparency by providing insight into the current set of processed personal data within the customer environment.
Data access
An up-to-date and complete overview of the processed personal data is accessible to the Controller after logging into the account within the Processor's provided software.
This access enables the Controller to regularly review the types of data collected and update them if necessary to ensure accuracy and relevance.
Transparency and Compliance
This specification of personal data is drawn up in the spirit of transparency and GDPR compliance, with privacy and the protection of user data as the top priority.
Purposes of Processing
The processing of personal data by the Processor takes place for specific purposes as determined by the Controller. These purposes concern personal data of natural persons (data subjects) who:
- a relationship have with the Controller (such as customers, members, students, employees, or participants);
- participate in training sessions or courses offered by the Controller.
These purposes include, among others:
- communication with data subjects;
- conducting research or evaluations;
- compliance with legal obligations;
- execution of agreements with data subjects.
Processing activities
The processing operations are carried out independently by the Controller or the data subject, using the Processor's systems. These activities include, but are not limited to:
- collecting, recording, organizing, segmenting, filtering, and structuring data;
- storing data, including email communication and chat logs;
- updating, modifying, synchronizing, enriching, and analyzing data;
- retrieving, consulting, using, sharing, disseminating, or otherwise making data available;
- aligning, combining, restricting, erasing, or destroying data.
This list provides a complete overview of the possible interactions with personal data within the Processor's systems and the diversity of the processing operations.
Use of AI functionality
When the Controller uses the AI functionality within the Pluvo platform (including the lesson module creator and automatic translation functionality), text entered by them or their users (“prompts”) may be temporarily processed by the sub-processor OpenAI LLC for the purpose of generating draft lesson material and/or translating existing lesson material.
Pluvo acts as a processor in this capacity. The Controller remains fully responsible for the lawfulness of the processing and for the content of the entered text, particularly if it contains personal data.
Annex 2. Security Specification
General Obligations
The Processor commits to taking all necessary technical and organizational security measures as required by the General Data Protection Regulation (GDPR), in particular Article 32 GDPR.
These measures are designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, as well as the nature, scope, context, and purposes of the processing and the risks to the rights and freedoms of natural persons.
Compliance with ISO/IEC 27001:2022
In addition to GDPR requirements, the Processor acts in accordance with the ISO/IEC 27001:2022 standard for information security management.
The Processor's Information Security Management System (ISMS) includes at least the following control measures:
- Risk Management – Regular identification, assessment, and treatment of information security risks.
- Security Policy – Maintenance of a formal and documented information security policy.
- Organization of Information Security – Established governance structure with defined roles and responsibilities.
- Human Resource Security – Employees are trained and contractually bound to confidentiality.
- Asset Management – Identification, classification, and protection of information assets.
- Access Management – Least-privilege principle; periodic review of access rights.
- Cryptography – Application of appropriate encryption techniques for the confidentiality and integrity of information.
- Physical and environmental security – Security of facilities and equipment.
- Operational security – Secure execution of processes and maintenance of log files.
- Communication security – Protection of information in networks and communication services.
- System development and maintenance – Integration of security into the design and development of IT systems.
- Supplier relationships – Contractual safeguards and oversight of sub-processors.
- Incident management – Rapid detection, reporting, and follow-up of information security incidents.
- Continuity management – Protection of business and IT process continuity.
- Compliance – Regular assessment of legal, statutory, regulatory, and contractual obligations.
Specific additional measures
- Encryption – TLS encryption in transit and encryption-at-rest for databases, temporary buffers, and backups; periodic evaluation of key management.
- Logging & monitoring – Audit logging of all relevant processing activities involving personal data, including entry into free-text fields, temporary storage, export, and deletion; log data is stored securely and periodically reviewed by the Security Officer.
- Data lifecycle management – Automatic retention timers and automated deletion of temporary data upon process completion; periodic restore tests of backups.
- Access management (operational) – Separation of development, testing, and production environments; administrative accounts are logged and reviewed at least annually.
- DLP alerts – UI alerts and optional pattern filters discourage the entry of sensitive or special categories of personal data via free-text fields.
- Change management – Changes to forms or field structures are subject to a formal change process, including a Data Protection Impact Assessment (DPIA).
----------------------------
Annex 3. Sub-processor Specification
The Processor may use the following categories and parties of sub-processors for the Processing:
Messagebird
https://bird.com
Processed data: First and last name; email address; email content data.
Purpose of processing: Messagebird is used for sending email communications. This includes transactional emails and other forms of email-based communication.
Processing activities: Sending emails to users based on provided lists; processing response data such as email open and click-through rates; maintaining email lists and unsubscribe requests.
Processing location: Data is processed in SparkPost data centers located in Europe.
Security measures: Messagebird implements industry-standard security protocols and encryption techniques to ensure the integrity and confidentiality of data.
Duration of processing: Data is processed for as long as necessary to perform email services, or until a user unsubscribes or requests the deletion of their data.
Regulatory compliance: Messagebird complies with the GDPR and other relevant privacy laws for the protection of personal data.
https://bird.com/legal/dpa
Amazon AWS
https://aws.amazon.com
Processed data: User names and email addresses; user profile pictures; additional fields added by the controller, which may vary depending on user requirements; user progress and scores in course materials and assessments; log files recording database changes; files stored on AWS S3, including any user data or course materials.
Purpose of processing: AWS is used to host and manage this data, with the goal of providing a scalable, reliable, and secure infrastructure for our services.
Processing activities: Storage and management of personal data and user profiles; hosting of educational content and tracking of user performance; maintenance and management of log files for security and monitoring; storage and management of files on AWS S3.
Processing location: Data is processed and stored in AWS data centers located in Frankfurt, Germany. For disaster recovery purposes, the database and file storage are replicated to AWS data centers in Dublin, Ireland. All processing remains within the EEA.
Security measures: AWS implements comprehensive security measures including network security, encryption, access control, and regular security audits, and complies with relevant industry standards and certifications such as ISO 27001, SOC 1, and SOC 2.
Duration of processing: Data is stored and processed for as long as necessary to provide the services.
Regulatory compliance: AWS complies with the GDPR and other relevant European and international privacy laws for the protection of personal data.
https://aws.amazon.com/compliance/gdpr-center/
OpenAI (AI functionality within the lesson module builder)
https://openai.com
Processed data: Text input entered into the AI module by the user or controller, including any personal data contained therein. Pluvo does not send or collect any other identifying data (such as user IDs, email addresses, or IP addresses) beyond the technical transmission.
Purpose of processing: Supporting AI functionality within the lesson module builder in the Pluvo platform, as well as automatically translating lesson materials into other languages. For this purpose, text entered by the controller ("prompt") may be temporarily forwarded to the OpenAI API environment to generate draft lesson materials or produce translations of existing lesson materials.
Processing activities: Processing of text input, calculation of model responses, and returning generated text to the Pluvo environment.
Processing location: Processing takes place within data centers managed by OpenAI. The contracting party for the EEA is OpenAI Ireland Limited; transfers to OpenAI entities outside the EEA are based on Standard Contractual Clauses (SCCs).
Security measures: Encryption during transit (TLS 1.2 or higher), authentication via secure API keys, and limitation of log retention to the functional duration of the session.
Duration of processing: Data is not stored by OpenAI beyond the duration of the API session, in accordance with their data processing policy.
Controller responsibility: The controller is responsible for the nature and lawfulness of the entered content. Entering personal data or other sensitive information into the AI module should only be done if there is a valid legal basis under the GDPR. Pluvo does not have access to, nor does it review, the content of the prompts entered.
Regulatory compliance: OpenAI acts as a sub-processor for Pluvo within the meaning of Article 28 of the GDPR. Pluvo has entered into an agreement with OpenAI ensuring that processing complies with applicable European data protection laws.
https://openai.com/policies/data-processing-addendum/
Crisp
https://crisp.chat
Processed data: Name, email address, the content of chat messages, and technical metadata (such as browser and device information) of users who contact us via chat.
Purpose of processing: Crisp is used for in-app chat and support functionality, allowing users and administrators to communicate directly with Pluvo.
Processing activities: Receiving, storing, and displaying chat messages and associated contact information; managing conversation history and support requests.
Location of processing: Data is processed in data centers within the European Union (France).
Security measures: Crisp uses encryption during transit (TLS) and at rest, with access restrictions and industry-standard security measures in place.
Duration of processing: Data is processed for as long as necessary for the support and communication service, or until a user requests deletion.
Regulatory compliance: Crisp is GDPR compliant. A Data Processing Agreement (DPA) has been signed with Crisp.
https://crisp.chat/en/privacy/
Sentry
https://sentry.io
Processed data: Technical error messages, stack traces, and application diagnostics, including a user ID to link errors to a session. IP addresses are not stored. Other identifying information (such as names and email addresses) is masked and minimized wherever possible via server-side data scrubbing.
Purpose of processing: Sentry is used for error and performance monitoring to ensure the stability, availability, and security of the platform and to investigate incidents.
Processing activities: Collecting, aggregating, and displaying error reports and technical diagnostics for the purpose of identifying and resolving issues.
Location of processing: Data is processed in Sentry's EU region (data center in Frankfurt, Germany). Transfers outside the EEA are not contractually excluded; the EU-US Data Privacy Framework and standard contractual clauses serve as safeguards for such transfers.
Security measures: Encryption in transit (TLS 1.2 or higher); server-side data scrubbing with standard filters that exclude passwords and credit card information; IP addresses are not stored; access is restricted to authorized developers. Sentry is ISO/IEC 27001 and SOC 2 certified.
Duration of processing: Error data is retained in accordance with the retention period configured in Sentry.
Regulatory compliance: Sentry is GDPR compliant. A data processing agreement (Data Processing Amendment v5.1.0) has been concluded with Sentry.
https://sentry.io/legal/dpa/
Bunny.net
https://bunny.net
Processed data: The video files uploaded within the academy, including the individuals recognizable or audible in them, and the technical data required to deliver a video to a viewer, including IP address and browser information. No account details, names, email addresses, results, or other academy data are provided to this party.
Purpose of processing: Bunny.net is used for storing and delivering video material within the academy, allowing users to play videos quickly and reliably.
Processing activities: Storing, transcoding, and delivering video files via a content delivery network, and maintaining technical playback and performance data to ensure service availability.
Location of processing: Video files are stored in Europe. Only bunny.net's EU pull zones are active for delivery, ensuring that playback also occurs via edge locations within the EEA. No data is transferred outside the EEA.
Security measures: Encryption in transit (TLS); access to the management panel is restricted to authorized administrators using multi-factor authentication. Bunny.net is ISO/IEC 27001 certified.
Duration of processing: Videos remain available as long as the controller keeps them in the academy. If the controller deletes a video, the file is removed from bunny.net. Upon termination of the agreement, the deletion period specified in Article 10 of this data processing agreement applies.
Regulatory compliance: Bunny.net is GDPR compliant. A data processing agreement (Data Processing Agreement v2) has been concluded with bunny.net.
https://bunny.net/privacy/
Rights and obligations
These provisions apply to all sub-processors mentioned above.
Audit rights: We reserve the right to inspect compliance regarding data security and privacy.
Data breach notification: The sub-processor must notify us immediately of any data breaches or security incidents that occur.
Sub-processors: The sub-processor is required to provide clarity regarding any additional sub-processors and must confirm whether data processing takes place within the European Union.