Skip to content

Data Processing Agreement

Version 1.0 · last updated 2026-07-23

This Data Processing Agreement (hereinafter: DPA) forms an integral part of the agreement between aiwerkers B.V. (trading as ai-werkers, having its registered office in Utrecht, the Netherlands, registered with the Dutch Chamber of Commerce under number 42114106, RSIN 869793627; the Processor) and the customer signing up for Vera (the Controller). By signing up you explicitly accept this DPA.

1. Definitions

2. Subject and purpose

Processor processes Personal Data solely for the provision of Vera: classifying inbound emails, drafting reply emails, booking meetings in the Controller's calendar, and related functionality. Processor never uses Personal Data for its own marketing, profiling, or AI model training.

3. Categories of data subjects and data

4. Processor responsibilities

5. Sub-processors

Controller grants Processor general authorisation to engage the following sub-processors:

Changes to sub-processors will be announced at least 14 days in advance by email and/or dashboard banner, with the right to object.

6. Security measures

7. Data breach notification

Processor notifies Controller in writing of any Personal Data breach affecting Controller's data as soon as possible and in any case within 48 hours of discovery. The notification covers at minimum the nature of the breach, the categories of Personal Data affected, mitigations taken, and a contact point for follow-up.

8. Assistance with data subject rights

Processor provides Controller with reasonable assistance in handling data subject requests for access, rectification, restriction, portability or erasure. For many such rights Controller can use the Vera dashboard directly (delete account, export data).

9. Audit rights

Controller may, at its own cost, conduct (or have conducted) an audit of Processor's compliance with this DPA, up to once per year — or more often given a credible indication of a breach. Processor cooperates reasonably and may require at least 30 days' prior notice.

10. International transfers

Personal Data is transferred outside the EEA only under a valid Article 46 GDPR mechanism (typically Standard Contractual Clauses). None of the sub-processors in section 5 routinely transfer data out of the EEA; for those with a non-EU parent (Railway, Google), actual data storage remains in the EU.

11. Retention

12. Termination

On termination of the main agreement Processor deletes all Personal Data within 30 days, unless legally required otherwise. During those 30 days Controller may request an export via privacy@ai-werkers.nl.

13. Liability

Liability for damages arising under this DPA follows the main agreement and statutory GDPR rules. Processor is not liable for damages resulting from Controller instructions that do not comply with the GDPR.

14. Governing law and jurisdiction

This DPA is governed by Dutch law. Disputes will be brought before the competent court in the district where Processor is established.

Contact

Questions about this DPA? privacy@ai-werkers.nl. We respond within 48 hours on business days.

Material changes to this DPA will be announced at least 14 days in advance.