Data Processing Agreement (DPA)
Last Updated: 06.05.2025
This Data Processing Agreement ("Agreement") forms part of the overall agreement between Imperum B.V. ("Imperum") and the Customer ("you" or "Customer") regarding the processing of personal data in connection with the use of the Imperum Software.
By engaging with the Software and Services, you agree to the terms of this Agreement.
1. Definitions
- “Personal Data”: Any information relating to an identified or identifiable individual, as defined under applicable data protection laws, including GDPR.
- “Data Subject”: The individual to whom the personal data relates.
- “Controller”: The entity that determines the purposes and means of processing personal data.
- “Processor”: The entity that processes personal data on behalf of the Controller.
- “Subprocessor”: Any third-party entity engaged by the Processor to process personal data on its behalf.
- “Processing”: Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, storage, use, or deletion.
- “Data Protection Laws”: The applicable laws and regulations relating to the processing of personal data, including but not limited to the GDPR.
2. Purpose of Data Processing
Imperum will process personal data solely to provide and support the Software and Services, as instructed by the Customer.
3. Obligations of Imperum
- Process personal data only in accordance with the Customer's instructions
- Implement appropriate security measures to protect the data
- Assist the Customer with data subject requests
- Notify the Customer of any data breaches
4. Subprocessors
Imperum may use subprocessors to assist in providing the Software and Services. Any subprocessors will be engaged in accordance with the applicable data protection laws.
5. Data Subject Rights
Imperum will assist the Customer in responding to data subject requests, such as for access, correction or deletion of personal data.
6. Data Security
Imperum will implement technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction.
7. Data Transfers
If personal data is transferred outside the European Economic Area (EEA), such transfers will be in compliance with applicable data protection laws.
8. Termination
Upon termination of the services, Imperum will return or delete all personal data as requested by the Customer.
9. Governing Law
This Agreement is governed by the laws of the Kingdom of the Netherlands.
10. Contact Information
For questions about this Agreement, please contact: info@imperum.io