Legal
Data Processing Agreement
The GDPR Article 28 terms under which Dexffo processes personal data on behalf of clients of the EUDR Due Diligence Statement platform.
Last updated:
1. Parties and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the client and Diego Ahumada, trading as Dexffo (eenmanszaak, Amsterdam, the Netherlands; KvK — registration pending).
- Controller (verwerkingsverantwoordelijke): the client (operator or trader), who determines the purposes and means of processing the producer and supply-chain data uploaded to the platform.
- Processor (verwerker): Dexffo, which processes that data solely on the client’s documented instructions.
2. Subject matter and nature of processing
Dexffo processes personal data exclusively to provide the EUDR compliance service: collection, validation, storage, structuring, transmission to the EU Information System, retention, and deletion of Due Diligence Statement (DDS) data under Regulation (EU) 2023/1115.
3. Duration
Processing lasts for the term of the service contract and for 5 years thereafter, as required by EUDR Art. 9(1) (record-keeping obligation). See Clause 9.
4. Categories of personal data and data subjects
- Producer / landowner identity (name) per production plot
- Plot geolocation (WGS84 coordinates, ≥6 decimals; points or polygons)
- Production data (commodity, species, quantities, dates)
- Legality documents (land titles, permits, licences, certifications)
- Operator/declarant details (legal name, EORI, address)
Data subjects: producers, authorised representatives, and the client’s employees.
5. Processor obligations
Dexffo, as processor, undertakes to:
- Process personal data only on the controller’s documented instructions;
- Ensure persons authorised to process the data are bound by confidentiality;
- Implement the technical and organisational measures in Clause 6;
- Assist the controller with data-subject requests and DPIAs (Art. 35–36);
- Notify the controller without undue delay of any personal-data breach;
- Delete or anonymise the data after the retention period (Clause 9).
6. Technical and organisational measures (Art. 32)
- Encryption in transit (TLS 1.3) and at rest (AES-256);
- Role-based access control and two-factor authentication for admin access;
- Immutable audit trail of data operations;
- Pseudonymisation where compatible with the EUDR purpose;
- Encrypted backups and a documented patching policy;
- Least-privilege access restricted to the data controller (Diego Ahumada).
7. Sub-processors
The controller authorises the following sub-processors. Dexffo will give 30 days’ notice of any intended change, during which the controller may object:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Portal database (PostgreSQL) and document storage | EU (eu-central-1, Frankfurt) |
| Vercel Inc. | Application hosting and edge functions | EU (Frankfurt) + US (SCCs) |
8. International transfers
Personal data is processed within the EEA by default. Where a transfer outside the EEA occurs (e.g. a US-based sub-processor), it is governed by the European Commission’s Standard Contractual Clauses (Decision 2021/914) and a transfer impact assessment.
9. Retention and deletion
Personal data is retained for a minimum of 5 years from the placing of the product on the market, on the legal basis of GDPR Art. 6(1)(c) in conjunction with EUDR Art. 9(1). This reconciles the GDPR data-minimisation principle (Art. 5(1)(e)) with the mandatory EUDR record-keeping obligation. After that period, data is anonymised or securely deleted (NIST SP 800-88), and a deletion certificate is available on request.
10. Audit rights
The controller may verify Dexffo’s compliance through documentary review, a security questionnaire, or — at most once per year — an on-site audit with reasonable notice. A recognised certification (e.g. ISO 27001, targeted Q4 2026) may be accepted in lieu of an on-site audit.
11. Personal-data breach notification
Dexffo will notify the controller within 72 hours of becoming aware of a personal-data breach, with the information required under GDPR Art. 33(2). The controller remains responsible for notifying the supervisory authority and data subjects where required.
12. Data Protection Officer and supervisory authority
DPO contact: dpo@dexffo.com. The competent supervisory authority is the Dutch Autoriteit Persoonsgegevens.
13. Governing law
This DPA is governed by Dutch law (Burgerlijk Wetboek). Disputes fall under the exclusive jurisdiction of the Rechtbank Amsterdam (Handelskamer). Where the SCCs apply, they prevail in case of conflict.
See also our Terms of Service and Privacy Policy.