LEGAL
Data Processing Agreement
Standard Article 28 GDPR terms when NINAWA processes personal data on behalf of a client.
Last updated: 10 July 20261. Roles and instructions
The client is controller and NINAWA is processor for data handled solely to deliver the contracted service. NINAWA acts only on documented instructions unless EU or Belgian law requires otherwise.
2. Processing details
The proposal or project schedule records the subject, duration, purpose, data categories and data subjects. Typical data includes customer contact, request, booking or account information.
3. Confidentiality and security
Authorised people are bound by confidentiality. NINAWA applies proportionate controls including encrypted transport, access restriction, patching, backups, session protection and incident procedures.
4. Sub-processors
The client gives general authorisation for necessary hosting, email, monitoring and infrastructure providers. NINAWA imposes equivalent duties and informs the client of material changes.
5. Assistance
NINAWA reasonably assists with data-subject requests, security, breach assessment, impact assessments and supervisory-authority consultations, taking account of the service and information available.
6. Personal-data breaches
NINAWA informs the client without undue delay after becoming aware of a breach affecting client data and shares available information needed for assessment and notification.
7. Return and deletion
At the end of the service, client data is returned or deleted as instructed unless retention is legally required. Isolated backups expire through their normal cycle.
8. Audits
NINAWA makes information reasonably necessary to demonstrate Article 28 compliance available and supports proportionate audits subject to confidentiality, security and reasonable notice.
9. Transfers and precedence
Transfers outside the EEA require a lawful safeguard. If this DPA conflicts with the main agreement on data protection, this DPA prevails.