Data Processing Agreement
Last updated: 21 September 2026
This Data Processing Agreement ("DPA", in Dutch: verwerkersovereenkomst) forms part of the Terms of Service between you ("Customer", the controller) and Wurkspace Studios trading as suppp ("Processor"). It applies to all personal data the Processor processes on the Customer's behalf, as required by article 28 GDPR. Need a signed copy for your records? Email hello@suppp.chat.
1. Subject, duration and nature of processing
- Subject: providing the suppp customer-support platform (live chat widget, shared email inbox, team collaboration, optional AI assistance).
- Duration: for as long as the Customer uses the service, plus the deletion period in section 9.
- Nature and purpose: storing, displaying, organising, transmitting and (on request) analysing support conversations, solely to deliver the service.
- Data subjects: the Customer's end customers and website visitors, and the Customer's own team members.
- Categories of data: names, email addresses, conversation and email content, attachments, chat metadata (browser, time stamps), satisfaction ratings.
- Special categories: not intended. The Customer will not use the service to process special-category data (art. 9 GDPR) or criminal-offence data unless agreed in writing.
2. Instructions
The Processor processes personal data only on the Customer's documented instructions — this DPA, the Terms, and the Customer's configuration of the service — unless EU or Dutch law requires otherwise, in which case the Processor informs the Customer first unless the law forbids this. The Processor tells the Customer if it believes an instruction infringes the GDPR.
3. Confidentiality
Everyone at the Processor with access to personal data is bound by confidentiality and only accesses it where needed to provide support the Customer asked for, to keep the service running, or to comply with the law.
4. Security measures (art. 32)
- Hosting of database, file storage and application servers in the EU (Frankfurt).
- Encryption in transit (TLS 1.2+) and at rest; additional AES-256-GCM encryption of mailbox access tokens.
- Per-workspace isolation enforced in the database (row-level security), least-privilege access.
- Optional two-factor authentication for all users; signed, short-lived links for attachments.
- Sanitisation of inbound email content; blocking of executable attachments; rate limiting of public endpoints.
- Automatic dependency security updates; periodic security reviews; logging of security-relevant events.
- Documented incident and data-breach procedure.
The Processor may update these measures as long as the overall level of protection does not decrease.
5. Subprocessors
The Customer gives general authorisation for the subprocessors listed on the subprocessors page. The Processor imposes data-protection obligations on each subprocessor equivalent to this DPA and remains responsible for them. The Processor gives at least 30 days' notice of a new or replacement subprocessor; the Customer may object on reasonable grounds and, if no solution is found, terminate the affected service without penalty.
6. International transfers
Where a subprocessor processes data outside the EEA, the transfer is protected by an adequacy decision (including the EU-US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
7. Assistance with data-subject rights and compliance
The service lets the Customer export and erase a contact's data, set automatic retention periods, and delete a whole workspace. Where the Customer can't fulfil a request itself, the Processor assists within reasonable time. The Processor also helps with data-protection impact assessments and prior consultations where relevant to the service.
8. Personal data breaches
The Processor notifies the Customer without undue delay and in any case within 48 hours after becoming aware of a personal data breach affecting the Customer's data, with the information the Customer needs to assess it and, where required, notify the Autoriteit Persoonsgegevens within 72 hours and inform data subjects. The Processor takes immediate steps to contain the breach and keeps a record of all breaches.
9. Deletion and return of data
The Customer can export its data and delete its workspace at any time. When the Customer deletes its workspace or the agreement ends, the Processor deletes the Customer's personal data immediately from production systems; encrypted backups roll over within 30 days. Billing records are kept as required by Dutch tax law.
10. Audits
The Processor makes available the information needed to demonstrate compliance with this DPA — including a completed security questionnaire on request. The Customer may, at its own cost and with 30 days' notice, have an independent auditor bound by confidentiality verify compliance once per year, or after a breach.
11. Liability and governing law
The limitation of liability in the Terms of Service applies to this DPA, except where the GDPR prescribes otherwise. This DPA is governed by Dutch law; disputes are submitted to the competent court in the Netherlands. If this DPA conflicts with the Terms, this DPA prevails for matters of data protection.