Legal
Data processing agreement
Does our assistant process personal data on your behalf? Then the GDPR requires us to set out agreements about that. They're right here. This data processing agreement forms part of our terms and conditions and applies automatically the moment you use the platform.
In short: you stay in charge of your visitors' data — we only process it to make your assistant work, secure it properly, bring in only carefully chosen sub-processors, and return or destroy everything at the end. We don't train any AI models on it and we don't sell anything on.
Last updated: 13 June 2026.
Article 1 · Parties
This data processing agreement applies between:
- you — the customer using the platform — as the controller; and
- De Codebrouwerij B.V., trading under the name Codebrouwerij, registered at Berndijksestraat 103 B, 5171 BB Kaatsheuvel, Chamber of Commerce 96285826 (hereinafter: "we" or "Codebrouwerij") as the processor.
You determine why and how the personal data is processed; we carry out that processing for you. Where this agreement differs from the terms and conditions, this agreement governs the processing of personal data.
Article 2 · Definitions
The terms from the GDPR (the General Data Protection Regulation) have the same meaning in this agreement. So by "personal data", "processing", "data subject", "sub-processor" and "data breach" we mean what the GDPR understands by those terms. By "end user" we mean the visitor who holds a conversation with your assistant.
Article 3 · Subject matter, nature and purpose
We process personal data solely to deliver the service to you: keeping your assistant(s) running, answering end users' questions based on your content, and making the inbox, analytics and management features available in the portal. The nature of the processing, the types of data and the categories of data subjects are set out in Annex A.
Article 4 · Our obligations
- We process the personal data only on your instruction and for the purposes above, unless the law obliges us to do otherwise — in which case we'll let you know beforehand, unless that law forbids it.
- The configuration you choose in the portal (sources, behaviour, retention periods, channels) counts as your instruction. You can give us additional instructions in writing.
- We do not use the data for our own purposes, don't sell it and don't use it to train AI models.
- We only let the data be processed by people or parties bound to confidentiality.
Article 5 · Security
We take appropriate technical and organisational measures to protect the data, in line with Article 32 of the GDPR. An up-to-date overview is set out in Annex C. In doing so we consider the state of the art, the cost of implementation and the risk to the data subjects. We may adjust measures, as long as the level of protection stays the same or improves.
Article 6 · Sub-processors
You grant us general authorisation to engage sub-processors to deliver the service. The sub-processors we currently use are listed in Annex B. With each sub-processor we make agreements that are at least as strict as this one.
If we add or replace a sub-processor, we'll let you know beforehand. If you have a well-founded objection relating to data protection, we'll discuss it with you; if we can't reach a solution, you may terminate the service in question.
Article 7 · Transfers outside the EEA
Some sub-processors — including the AI providers — process data outside the European Economic Area. In that case we ensure a valid basis for the transfer, such as the European Commission's standard contractual clauses, with additional safeguards where needed.
Article 8 · Assistance with data subject rights
If you receive a request from a data subject (access, correction, erasure and so on), we'll help you with it as far as is reasonable, insofar as it can only be done through us. If an end user addresses such a request to us directly, we'll forward it to you — where it concerns your processing — and won't handle it on our own.
Article 9 · Assistance with assessments
We'll help you, as far as is reasonable, with your obligations around the security of the processing, the reporting of data breaches, data protection impact assessments (DPIAs) and any consultation with the supervisory authority. We'll give you the information you reasonably need for that.
Article 10 · Data breaches
If we discover a data breach affecting your data, we'll report it without undue delay after becoming aware of it. We'll give you the information you need to meet your own duty to notify the supervisory authority and, where applicable, the data subjects, and we'll take reasonable measures to limit the impact. The notification to the Dutch Data Protection Authority and to data subjects is yours to make, as controller.
Article 11 · Audits
At your request we'll demonstrate that we comply with this agreement, for example with our documentation or a statement. If you want an audit, that's possible at most once a year (and otherwise if the supervisory authority or a serious suspicion calls for it), after reasonable prior consultation, during office hours and without disrupting the service for others. You bear the cost of an audit you request yourself, unless it shows we fell short.
Article 12 · Return and erasure
When the service ends, we'll delete the personal data we process on your behalf within a reasonable period, or return it to you if you ask before we erase it. You can request an export of your data in the portal. Data we are legally required to keep for longer, we keep solely for that purpose and continue to protect.
Article 13 · Liability
The limitations from our terms and conditions apply to liability under this agreement. The allocation of responsibility follows the GDPR: each party bears what falls to it under the law and this agreement.
Article 14 · Term and termination
This agreement takes effect as soon as you use the platform and runs for as long as we process personal data on your behalf. After it ends, the provisions that by their nature should continue — such as confidentiality and erasure — remain in force until they've been fulfilled.
Article 15 · Governing law
This agreement is governed by Dutch law. We'll bring disputes before the competent court in the district where De Codebrouwerij B.V. is established, unless the law mandatorily provides otherwise.
Annex A · Details of the processing
Subject matter: delivering the aqivo platform to the customer.
Purpose: answering end users' questions based on the customer's content, and providing the associated inbox, analytics and management features.
Duration: for as long as the agreement runs and, per conversation, according to the retention settings the customer chooses.
Categories of data subjects:
- end users who chat with a customer's assistant;
- the customer's staff who use the portal;
- people who appear in the content the customer connects.
Types of personal data:
- the content of chat messages and the assistant's replies;
- technical conversation data (such as time, language and a session identifier);
- data the customer supplies about a logged-in end user (such as a user ID or email address);
- any personal data shared within the connected content or by the end user themselves.
Special categories of personal data are not intended. Don't share those through the assistant, unless you have your own basis and appropriate measures for it.
Annex B · Sub-processors
At present we engage the following sub-processors for processing on the customer's behalf:
- OpenAI — language models (GPT) and making content searchable (embeddings). Processing partly outside the EEA, with appropriate safeguards. Under the business terms, does not use the data to train models.
- Anthropic — language models (Claude). Processing partly outside the EEA, with appropriate safeguards. Under the business terms, does not use the data to train models.
- Hosting & infrastructure — the servers on which the platform and the data run, within the EEA.
Which language model an assistant uses is your own choice in the portal. An up-to-date list of sub-processors can be requested via info@codebrouwerij.nl.
Annex C · Security measures
Among other things, we take the following measures (the overview may evolve with the technology):
- encrypted connections (TLS/HTTPS) for all traffic to and from the platform;
- shielded, role-based access to data, following the principle of least privilege;
- careful management of secrets, keys and passwords, separate from the application;
- separation of data per customer (multi-tenant with logical isolation);
- measures against misuse, such as rate limiting and blocking internal addresses during actions;
- logging and monitoring so incidents can be spotted and investigated;
- backups and recovery procedures for the continuity of the service.