Data Processing Agreement

D&V Global B.V. — Standard Data Processing Agreement
Effective date: 16 August 2026 | Version 2.1

1. Introduction and Incorporation

1.1. This Data Processing Agreement (“DPA“) applies where D&V Global B.V., registered in the Netherlands (KvK 69819718, VAT NL858025309B01), Microfoonstraat 10, 1322 BN Almere, the Netherlands, also trading as GETSERVERS.NL and SERVERSMART.NL (“D&V Global“, the “Processor“), processes personal data on behalf of a customer (the “Customer“, the “Controller“) in the course of providing services under the Terms & Conditions (the “Agreement“).

1.2. In accordance with Section 13.1 of the Terms & Conditions, this DPA forms an integral part of the Agreement and requires no separate signature. If the parties have executed an individually negotiated data processing agreement, that agreement prevails over this DPA.

1.3. Where the Customer acts as a processor for its own clients, the Customer warrants that it is authorized to engage D&V Global as a sub-processor, and references to “Controller” are read accordingly.

1.4. In the event of conflict between this DPA and the other parts of the Agreement with respect to the processing of personal data, this DPA prevails.

2. Definitions

The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, and “supervisory authority” have the meanings given in Article 4 GDPR. “GDPR” means Regulation (EU) 2016/679.

3. Scope and Role Clarification

3.1. The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex 1.

3.2. Role clarification per service model. For managed hosting and other services where D&V Global has logical access to Customer systems, D&V Global processes personal data contained in Customer Data as a processor. For colocation and self-managed (unmanaged) services, D&V Global has no logical access to the content of Customer systems in the normal course of business; its processing is limited to physical handling of equipment, network transport, and infrastructure-level metadata, and this DPA applies to that limited extent.

3.3. D&V Global processes personal data contained in Customer Data only for the purpose of providing the services and does not use such data for its own purposes.

4. Instructions

4.1. D&V Global processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by EU or Member State law to which D&V Global is subject; in that case, D&V Global informs the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.

4.2. The Agreement, the service configuration selected by the Customer (including data center location), and instructions given through the customer portal or support channels constitute the Customer’s documented instructions. Additional instructions require mutual written agreement and may be subject to reasonable fees if they exceed the agreed scope of services.

4.3. D&V Global informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law. D&V Global is not obliged to perform a legal review of the Customer’s instructions.

5. Confidentiality

D&V Global ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and receive appropriate data protection training. Access to personal data is limited to personnel who need it to perform the services.

6. Security

6.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks for data subjects, D&V Global implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures currently implemented are described in Annex 2.

6.2. D&V Global may update the measures in Annex 2 from time to time, provided the overall level of security is not materially reduced.

6.3. The Customer remains responsible for the security of systems and software under its own control (including operating systems and applications on self-managed servers, access credentials, and the lawfulness and accuracy of Customer Data).

7. Sub-processors

7.1. The Customer grants D&V Global general written authorization to engage sub-processors for the provision of the services, including data center operators, network carriers, and IT service vendors. The current list of sub-processors, including their locations and functions, is available on request via office@dv-global.nl.

7.2. Notice and objection. D&V Global gives the Customer at least 30 days’ prior notice of the addition or replacement of a sub-processor, by email or through the customer portal. The Customer may object within that period on reasonable data protection grounds. In that case, the parties will discuss a solution in good faith (such as a configuration change or alternative sub-processor). If no solution is found before the change takes effect, the Customer may terminate the affected services with effect from the date the change takes effect; prepaid fees for the period after termination are refunded pro rata.

7.3. D&V Global imposes on each sub-processor, by way of a written contract, data protection obligations that are at least as protective as those set out in this DPA, and remains fully liable to the Customer for the performance of the sub-processor’s obligations.

8. Assistance to the Controller

8.1. Taking into account the nature of the processing, D&V Global assists the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. If a data subject contacts D&V Global directly regarding Customer Data, D&V Global forwards the request to the Customer without undue delay and does not respond substantively, except as instructed by the Customer or required by law.

8.2. Taking into account the nature of the processing and the information available to it, D&V Global assists the Customer in ensuring compliance with the obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).

8.3. Assistance under this Section 8 is provided free of charge to the extent it involves no more than limited effort. For assistance exceeding that, D&V Global may charge reasonable fees at the rates agreed in the Agreement, communicated in advance.

9. Personal Data Breach

9.1. D&V Global notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer. The notification includes, to the extent then available, the information referred to in Article 33(3) GDPR (nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, and measures taken or proposed). Information may be provided in phases as it becomes available.

9.2. D&V Global takes reasonable measures to contain and remediate the breach and cooperates with the Customer’s reasonable requests in connection with the Customer’s notification obligations. Notification under this Section is not an acknowledgement of fault or liability.

10. International Transfers

10.1. Personal data is processed in the data center location(s) selected by the Customer in the order or service configuration. The Customer’s selection of a location outside the European Economic Area constitutes a documented instruction within the meaning of Section 4. Where processing in that location involves a restricted transfer to a recipient in a third country, D&V Global will not commence that transfer unless an applicable transfer mechanism under Chapter V GDPR (such as an adequacy decision or the European Commission’s Standard Contractual Clauses) and, where necessary, supplementary measures are in place. The Customer’s instruction does not relieve either party of its respective obligations under the GDPR.

10.2. D&V Global does not otherwise transfer personal data outside the EEA (including to sub-processors) unless an adequacy decision applies or appropriate safeguards within the meaning of Chapter V GDPR (in particular Standard Contractual Clauses) and, where necessary, supplementary measures are in place. The transfer mechanism applicable to each sub-processor is stated in the sub-processor list.

11. Audits and Information

11.1. D&V Global makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

11.2. Audits are subject to the following conditions: at least 30 days’ prior written notice; at most once per 12-month period (except after a personal data breach affecting the Customer or where required by a supervisory authority); during business hours; without unreasonable disruption to operations; under confidentiality obligations; and without access to data or systems of other customers. Each party bears its own costs. Where available, D&V Global may satisfy information requests by providing relevant third-party audit reports or certifications.

12. Return and Deletion

12.1. Upon termination of the services, the Customer may retrieve Customer Data during the 14-day retrieval period described in Section 11.5 of the Terms & Conditions.

12.2. After that period, D&V Global deletes Customer Data from active systems and allows residual backup copies to expire, in accordance with the time limits set out in the Data Destruction Policy, and sanitizes data-bearing media in accordance with that policy, unless EU or Member State law requires storage of the personal data. Until expiry, backup copies are isolated from ordinary use, remain protected by the measures in Annex 2, and are not restored except where necessary for disaster recovery; if a backup containing deleted Customer Data is restored, the applicable deletion is re-applied. Upon request, D&V Global confirms deletion in writing; for decommissioning engagements, a Certificate of Data Destruction is provided in accordance with the Data Destruction Policy.

13. Liability and Term

13.1. The liability of the parties under this DPA is governed by Section 16 of the Terms & Conditions and Article 82 GDPR.

13.2. This DPA applies for as long as D&V Global processes personal data on behalf of the Customer and remains in force with respect to obligations that by their nature survive (in particular Sections 5 and 12).

14. Governing Law

This DPA is governed by the laws of the Netherlands, in accordance with Section 22 of the Terms & Conditions.


Annex 1 — Description of Processing

Subject matter Provision of managed hosting, VPS, dedicated and cloud servers, colocation, infrastructure and migration services, server decommissioning, domain and email services
Duration The term of the Agreement, plus the retrieval and deletion periods described in Section 12
Nature and purpose Storage, hosting, transmission, backup (where ordered), migration, monitoring, technical support, and secure destruction of Customer Data as necessary to provide the services
Types of personal data Determined by the Customer. Typically: names, contact details, IP addresses, user account data, communication content, system logs, and any other personal data contained in Customer Data. The services are not intended for special categories of data (Art. 9 GDPR) unless expressly agreed or appropriate safeguards are implemented by the Customer
Categories of data subjects Determined by the Customer. Typically: the Customer’s employees, contractors, end users, and customers

Annex 2 — Technical and Organizational Measures

The following measures are implemented to the extent applicable to the ordered service model and configuration:

  • Physical security: services are provided from professional data centers with access control, video surveillance, and on-site security; access to equipment is restricted to authorized personnel.
  • Access control: role-based access, personal accounts, logging of administrative actions, revocation of access upon role change or departure.
  • Network security: network segmentation, firewalling, protection of management interfaces; DDoS mitigation measures where available for the relevant service.
  • Encryption: encryption of data in transit for management connections; encryption at rest available depending on the ordered service configuration.
  • Availability and resilience: redundant power, cooling, and network at data center level; high-availability clustering and resilient storage for applicable services; backup services where ordered; monitoring and incident response.
  • Security operations: hardening and patch management for systems under D&V Global’s management; centralized logging; malware and anomaly detection tooling.
  • Organizational measures: confidentiality undertakings and data protection training for personnel; least-privilege principle; documented incident response procedure; sub-processor due diligence; secure media sanitization and destruction in accordance with the Data Destruction Policy (NIST SP 800-88, current revision).

Annex 3 — Authorized Sub-processor Categories

Data center and colocation facility operators; internet and network carriers; hardware suppliers and maintenance vendors; software and platform vendors used in service delivery; secure destruction and recycling partners (for decommissioning). The current list of sub-processors with names, locations, and functions is available on request via office@dv-global.nl.