Data Processing Agreement
This is a translation of the Dutch version. In the event of any discrepancy, the Dutch version prevails: Verwerkersovereenkomst (Dutch).
Version 2026-07-28
Parties
Controller the association, foundation or owners' association that uses Ledenboek, hereinafter "the association".
Processor Vuurpijl Beheer B.V., KvK 34108141, established at Lagedijk 11A, 2064 KV Spaarndam, hereinafter "Ledenboek".
This data processing agreement belongs to the general terms and conditions of Ledenboek and forms an integral part of them.
Article 1: Subject matter and duration
1.1 Ledenboek processes personal data solely for the purpose of the service: keeping the membership, financial and board administration of the association.
1.2 The association determines the purpose and means of the processing. Ledenboek processes solely on the basis of written instructions from the association. Use of the service counts as such an instruction.
1.3 This agreement runs for as long as the agreement between the parties lasts, and ends with it.
Article 2: Types of data and data subjects
2.1 Data subjects: members and former members of the association, their family members or housemates insofar as recorded, board members, committee members, participants in events and business contacts of the association.
2.2 Categories of personal data: name, address, town or city, email address, telephone number, date of birth, membership number, start and end date of the membership, bank account number and direct debit mandate details, payment history, custom fields set up by the association itself, and data that members enter themselves in the member portal.
2.3 The association does not place special categories of personal data within the meaning of Article 9 GDPR, such as health data, in the service, unless it has a valid legal basis for doing so and informs Ledenboek of this in advance. If the association sets up custom fields for this purpose, it is itself responsible for them.
Article 3: Obligations of Ledenboek
3.1 Ledenboek does not process the personal data for its own purposes and does not disclose it to third parties, except to the sub-processors listed in Article 6 and except where required by a legal obligation. In the latter case, Ledenboek informs the association in advance, unless the law prohibits this.
3.2 Ledenboek never uses the data of members to contact them itself, and does not sell or rent it out.
3.3 Persons who have access to the data on behalf of Ledenboek are bound by confidentiality.
3.4 Ledenboek provides the association with reasonable assistance in carrying out a data protection impact assessment and in prior consultation with the Autoriteit Persoonsgegevens.
Article 4: Security
4.1 Ledenboek takes appropriate technical and organisational measures as referred to in Article 32 GDPR. These include in any case:
- encrypted connections (TLS) for all traffic with the service;
- access to the data of an association solely for users who have been authorised by
that association, with rights per role;
- encrypted storage of passwords and of keys for connected services;
- daily backups;
- logging of access and changes;
- two-factor authentication available for administrators.
4.2 The association is itself responsible for handling login details with care and for granting the correct rights to its board members.
Article 5: Personal data breaches
5.1 Ledenboek notifies the association of a personal data breach without undue delay, and in any event within 24 hours of Ledenboek becoming aware of it.
5.2 The notification contains at least: the nature of the breach, the categories of data and data subjects concerned insofar as known, the likely consequences and the measures that have been or will be taken.
5.3 The association itself assesses whether notification to the Autoriteit Persoonsgegevens or to the data subjects is required. Ledenboek provides the assistance reasonably required for this.
5.4 Notifications are to be sent to info@ledenboek.nl.
Article 6: Sub-processors
6.1 The association authorises Ledenboek to engage the sub-processors listed below:
| Sub-processor | Purpose | Data location |
| Hetzner Online GmbH | hosting of the application and the database | Germany (EU) |
| Mollie B.V. | processing of payments and direct debits from members | Netherlands (EU) |
| Euromailing | sending email to members | Netherlands (EU) |
| Stripe Payments Europe Ltd. | invoicing of the association's own subscription | Ireland (EU) |
| PostHog | usage statistics and error reports of the application | EU (`eu.i.posthog.com`) |
6.2 Ledenboek imposes on each sub-processor the same obligations as those set out in this agreement.
6.3 If Ledenboek wishes to add or replace a sub-processor, it gives notice of this at least 30 days in advance. If the association objects in writing, stating its reasons, within that period, it may terminate the agreement with effect from the date on which the change takes effect.
6.4 Processing takes place within the European Economic Area. Where processing takes place outside it, this is done solely on the basis of an adequacy decision or standard contractual clauses of the European Commission.
Article 7: Rights of data subjects
7.1 If a data subject contacts Ledenboek directly with a request for access, rectification, erasure, restriction, objection or data portability, Ledenboek refers them to the association and informs the association accordingly.
7.2 Ledenboek provides the association with the assistance needed to handle such requests. The association can itself view, amend, export and delete the data of a data subject in the service.
Article 8: Return and deletion
8.1 The association can export its data to Excel or CSV itself at any time during the term. No costs or conditions are attached to this.
8.2 After termination of the agreement, the data remains available for export for 60 days. After that, Ledenboek deletes it from the active systems.
8.3 Backups that still contain data are overwritten in accordance with the regular backup schedule, at the latest within 35 days of deletion.
8.4 Data that Ledenboek is required by law to retain, such as invoices to the association, is retained for the statutory period.
Article 9: Audit
9.1 The association may request Ledenboek no more than once a year to demonstrate that it complies with this agreement.
9.2 Ledenboek in principle meets this request by providing written information. If this is demonstrably insufficient, the association may, at its own expense, have an independent expert carry out an inspection, subject to at least 30 days' notice and without disrupting the provision of the service.
Article 10: Liability and final provisions
10.1 The limitation set out in the general terms and conditions of Ledenboek applies to liability under this agreement, insofar as permitted by law.
10.2 In the event of any conflict between this agreement and the general terms and conditions, this agreement prevails insofar as it concerns the processing of personal data.
10.3 This agreement is governed by Dutch law.
Questions about this? Email info@ledenboek.nl.