Data processing agreement
Version 1 September 2026 · meerklussen.nl
We build your website and handle the follow-up on your requests. In doing that we process personal data belonging to your customers — on your instructions. The GDPR requires us to record how we handle that. This is where. This data processing agreement forms part of our terms and conditions and applies automatically as soon as you are a client.
Article 1 — Who is who
- Processor: Meerklussen.nl, a trading name of The Online Motion L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates (Trade License No. 2422590.01).
- Controller: you, the client. You decide why and how your customers' data is used; we carry that out.
- For the data you leave with us yourself (your name, phone number, email) *we* are the controller. Our privacy policy covers that.
Article 2 — What this covers
- We process personal data only in order to deliver the services in your package: the website, the advertising, the automated follow-up of requests and the reporting on all of it.
- We never use the data for our own purposes, we do not sell it, and we do not share it with anyone other than the sub-processors listed in Article 6.
- We process solely on your written instruction. If we believe an instruction breaks the law, we tell you.
Article 3 — Which data, and whose
| Category of people | Types of data | What for |
|---|---|---|
| People submitting a request through your website or ads | Name, phone number, email address, address or working area, description of the job, conversation history (WhatsApp, email), appointment times | Following up, qualifying and delivering requests to you |
| Visitors to your website | IP address, device and browser details, pages viewed (only with their consent) | Statistics and measuring advertising |
| Your staff with access to the system | Name, email address, phone number, login details | Granting access and being able to support the service |
We never ask for special category personal data (such as health, religion or criminal records) and do not knowingly process it. Please make sure it does not end up in free-text fields.
Article 4 — Security
We take appropriate technical and organisational measures (GDPR art. 32). Concretely, that means at least:
- Encrypted connections (HTTPS/TLS) for the website and every system
- Access only for people who need it, with personal accounts and two-factor authentication
- Passwords and keys stored encrypted, never in ordinary documents
- Regular backups and updates of the systems we use
- Suppliers who can demonstrably meet the GDPR themselves
Article 5 — Data breaches
- If we discover a data breach affecting your data, we tell you without undue delay, and at the latest within 48 hours of becoming aware of it.
- We report what happened, which data and how many people are affected, what the likely consequences are, and what we are doing about it.
- Reporting to the supervisory authority and to the people affected is your job, as controller. We supply all the information and help you need for it.
Article 6 — Sub-processors
You give us permission to use these sub-processors. We have a data processing agreement in place with each of them:
| Party | What for | Location |
|---|---|---|
| HubSpot | Customer management and forms | EU / US (Data Privacy Framework) |
| LeadConnector (GoHighLevel) | Follow-up, WhatsApp and email | US (Data Privacy Framework) |
| Tag Manager, Analytics, Ads | EU / US (Data Privacy Framework) | |
| Microsoft | Clarity — usage analysis | EU / US (Data Privacy Framework) |
| Meta | Advertising | EU / US (Data Privacy Framework) |
| Hostinger | Website hosting | EU |
If we want to add or replace a sub-processor, we let you know at least 30 days in advance. If you disagree, you may cancel the agreement effective from the date of the change.
Article 7 — Transfers outside the EEA
Some of these parties process data outside the European Economic Area, mainly in the United States. That happens on the basis of the EU-US Data Privacy Framework and/or the European Commission's standard contractual clauses, on top of the measures in Article 4.
Article 8 — Rights of the people involved
- If we receive a request from someone who wants to see, correct, delete or take their data with them, we forward it to you within 3 working days. We do not answer it ourselves.
- We help you carry out such a request free of charge — by looking data up, exporting it or deleting it, for example.
- The same goes for your obligations around a data protection impact assessment (DPIA) and consultation with the supervisory authority.
Article 9 — Confidentiality
Everyone on our side who works with your data is bound to confidentiality — during and after the collaboration. We give data to no one else, unless the law obliges us to. If that happens, we tell you, unless we are legally not allowed to.
Article 10 — Audits
- You may check once a year whether we are keeping to these arrangements. We first supply the information and statements we already hold.
- If that is not enough, an independent auditor may carry out an audit. You announce it at least 30 days in advance and the auditor signs a non-disclosure agreement.
- The cost of such an audit is yours, unless it shows that we have not kept to this agreement.
Article 11 — Ending and returning data
- This data processing agreement runs for as long as we deliver services to you.
- When it ends you get your data back in a common file format, or we delete it — your choice. If we hear nothing within 30 days, we delete it.
- Statutory retention duties take precedence: data the law requires us to keep (invoices, for example) we keep for as long as we must, and no longer.
Article 12 — Finally
- Where they conflict, this data processing agreement takes precedence over the terms and conditions, but only on the point of processing personal data.
- Dutch law applies to this agreement.
- Questions or a request? Email info@meerklussen.nl.
meerklussen