Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Stijn Benjamin, trading as BoxSight (KvK 85508365, established at Hoogstraat 19 A, 3011 PD Rotterdam, the Netherlands) ("Processor") and the customer organization using the Service ("Controller"). It applies to all personal data the Controller stores or processes in BoxSight ("Customer Personal Data") and implements art. 28 GDPR. No separate signature is required; by using the Service the Controller accepts this DPA.
1. Subject matter, duration, nature and purpose
The Processor processes Customer Personal Data solely to provide the BoxSight service: hosting, displaying and processing the Controller's CRM and logistics data (customers, leads, contacts, containers, depots, factories, shipping lines) on an interactive map, including imports, integrations and status tracking. Processing lasts as long as the Controller has an account, plus the deletion period in Section 9.
2. Categories of data subjects and personal data
- Data subjects: the Controller's (prospective) customers and their contact persons, contacts at depots, factories and shipping lines, and the Controller's own team members with a BoxSight seat.
- Personal data: business contact details such as names, email addresses, phone numbers, job-related information and business addresses. The Service is not intended for special categories of personal data (art. 9 GDPR) and the Controller agrees not to store such data in it.
3. Instructions
The Processor processes Customer Personal Data only on documented instructions from the Controller, as laid down in the Terms, this DPA and the Controller's use of the Service's features, unless EU or member state law requires otherwise (in which case the Processor informs the Controller before processing, unless that law prohibits it). The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
Persons authorized to process Customer Personal Data are bound by confidentiality, contractually or by law, and process it only to the extent needed to provide the Service.
5. Security (art. 32 GDPR)
Taking into account the state of the art and the nature of the data, the Processor implements appropriate technical and organizational measures, including:
- Encryption of data in transit (TLS) and at rest.
- Strict logical separation of data per organization, enforced in the application layer on every query.
- Authentication via signed tokens (JWT) verified against the identity provider; role-based access within an organization.
- Access to production systems restricted to the minimum necessary, with secrets managed in a dedicated secrets manager rather than in code.
- Regular automated backups of the database.
- Error and security monitoring of the production environment.
6. Subprocessors
The Controller grants general written authorization for the subprocessors below. The Processor imposes data protection obligations on each subprocessor equivalent to this DPA and remains fully liable for their performance.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU (AWS eu-west-1) |
| DigitalOcean | Application hosting | EU |
| Vercel | Frontend hosting | EU/US (global CDN) |
| Stripe | Payments (billing contact data only) | EU/US |
| Resend | Transactional email | EU/US |
| Sentry | Error monitoring | EU/US |
Integrations the Controller connects itself (such as ActiveCampaign, HubSpot or carrier APIs) are engaged by the Controller and are not subprocessors of the Processor.
The Processor announces intended additions or replacements at least 30 days in advance by email. The Controller may object on reasonable data protection grounds; if no solution is found, the Controller may terminate the affected service.
7. International transfers
Customer Personal Data is stored in the EU. Where a subprocessor processes personal data outside the EEA, the transfer is safeguarded by an adequacy decision (such as the EU-US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
8. Assistance and personal data breaches
Taking into account the nature of the processing, the Processor assists the Controller with data subject requests (art. 12-23 GDPR) and with the Controller's obligations under art. 32-36 GDPR. The Service's export and delete functions are the primary means of assistance; additional assistance is provided on request.
The Processor notifies the Controller without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting Customer Personal Data, providing the information reasonably needed for the Controller's notification duties.
9. Deletion and return
Upon termination of the Service, the Controller can export Customer Personal Data for 30 days. After that period the Processor deletes all Customer Personal Data, including backups within the backup rotation cycle, unless EU or member state law requires longer storage.
10. Audits
The Processor makes available the information reasonably necessary to demonstrate compliance with art. 28 GDPR. The Controller may, at most once per year and at its own cost, conduct an audit (by itself or an independent auditor bound by confidentiality) with at least 30 days notice, during business hours and without unreasonable disruption to the Processor's operations.
11. Liability and precedence
The liability provisions of the Terms apply to this DPA. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.
12. Contact
Stijn Benjamin, trading as BoxSight
Hoogstraat 19 A, 3011 PD Rotterdam, the Netherlands
KvK: 85508365 · VAT: NL004106731B83
hello@boxsight.app