This is a translation for your convenience. In case of any difference, the Dutch version applies. Nederlands

All legal documents

Processing

Data processing agreement

Last updated: 2 August 2026, annex to every assignment

1. Parties and order of precedence

This data processing agreement forms part of the agreement between 8eonAI (Processor) and the client (Controller). In case of conflict, this data processing agreement prevails over the terms and conditions, insofar as the processing of personal data is concerned.

2. Subject matter and instructions

The Processor processes personal data solely on instruction and in accordance with the written instructions of the Controller, for building, running and maintaining dashboards, agents and automations. The Processor does not use the data not for its own purposes, not for training its own models, and not for other clients.

3. Nature of the processing

Category of data subjectsTypes of data
Clients of the ControllerName, email address, telephone number, address, order and payment details, support messages
Employees of the ControllerName, business email address, role, user account
Website visitors of the ControllerIP address, behavioural data, campaign and conversion data

There are no special categories personal data processed, unless agreed in writing in advance.

4. Sub processors

The Controller gives general authorisation for engaging sub processors. The Processor gives at least 30 days' notice of a new or replacement sub processor. The Controller may object on reasoned grounds and in that case has the right to terminate the agreement.

Sub processorRoleLocation
Cloud hostingRunning the environmentEU
OpenAI / Anthropic / Google / Microsoft AzureAI modelsEU or US, with standard contractual clauses
To be completed per assignmentConnections with the client's systemsn/a

5. Transfers outside the EEA

Transfers outside the European Economic Area take place solely on the basis of the European Commission's standard contractual clauses or an adequacy decision, with additional measures where necessary.

6. Security

  • Encryption of data in transit and at rest
  • Access strictly on the basis of role and necessity, with two factor authentication
  • Storage of API keys and login details in a secure password vault, never in source code or chat messages
  • Logging of access to the Controller's systems
  • Separate environments per client, so that client data never gets mixed up

7. Confidentiality

Everyone who has access to the data on behalf of the Processor is bound by confidentiality, including after the agreement ends.

8. Data breaches

The Processor reports a personal data breach within 24 hours after discovery to the Controller, with all information the Controller needs in order to report to the Dutch Data Protection Authority within 72 hours. The Processor does not itself report to the supervisory authority or to data subjects, unless requested to do so.

9. Rights of data subjects

If the Processor receives a request directly from a data subject, it forwards it within five working days and does not answer it itself. The Processor provides reasonable assistance in handling access, rectification and erasure requests.

10. Audit

The Controller may, no more than once a year and after a data breach, have compliance audited by an independent expert bound by confidentiality, with 30 days' notice. The costs are borne by the Controller, unless the audit shows that the Processor is in breach.

11. Return and deletion

On termination the Processor deletes all login details and API keys received within 30 days (in line with article 7.4 of the terms and conditions). Personal data held in the Controller's environment stays there. Data held by the Processor is returned or deleted on request, unless retention is legally required.

12. Term and liability

This data processing agreement runs for as long as the Processor processes personal data for the Controller. Liability follows the arrangement in article 10 of the terms and conditions, insofar as mandatory law permits.